Data tool
Which AI rules apply to me?
Pick where you work or sell and what you use AI for. You get the AI rules that apply, what they ask you to do and from when, with a link to the official text.
Your checklist
Choose one or more answers to each question. Each rule says what to do, who it is for, and who enforces it.
18 rules match your choices.Includes United States (all states) rules, which apply in every US state.
- No federal law overrides state AI laws. A December 2025 executive order tells federal agencies to challenge some of them, but state laws still apply until a court or Congress says otherwise. Official text
In force now 15
- In force since May 19, 2026
Remove reported intimate deepfakes within 48 hours
Give people a clear, plain-language way to report intimate images of themselves posted without consent, including AI-made fakes. Remove a valid reported image within 48 hours, and make reasonable efforts to remove known identical copies.
- Who
- Public websites, apps and online services that mainly host content from users, with no size threshold. Broadband providers and email are excluded.
- Enforced by
- Federal Trade Commission; civil penalties of up to $53,088 per violation. Removals made in good faith are protected.
- Law
- TAKE IT DOWN Act (Public Law 119-12), section 3
Official text TAKE IT DOWN Act, Public Law 119-12 (GovInfo) - In force since May 19, 2025
Never post AI-made intimate images of real people
It is a federal crime to knowingly publish online an intimate image of an identifiable real person without their consent, including realistic fakes made with AI.
- Who
- Anyone, people and businesses alike.
- Enforced by
- Department of Justice; fines and up to two years in prison, or three years if the person shown is a minor.
- Law
- TAKE IT DOWN Act (Public Law 119-12), section 2, 47 U.S.C. 223(h)
Official text TAKE IT DOWN Act, Public Law 119-12 (GovInfo) - In force since October 21, 2024
Do not post or buy fake reviews, including AI-written ones
Do not write, create, sell or buy reviews or testimonials that falsely suggest the reviewer exists, used the product or had the experience described. The FTC says this covers AI-generated fake reviews.
- Who
- Businesses selling to US consumers.
- Enforced by
- Federal Trade Commission; civil penalties of up to $53,088 per knowing violation.
- Law
- FTC Rule on the Use of Consumer Reviews and Testimonials, 16 CFR part 465
Official text 16 CFR part 465 (eCFR) - In force since February 8, 2024
Get consent before calling people with an AI voice
Calls that use AI-generated or cloned voices count as artificial-voice calls under the federal robocall law, so they need the called person’s prior express consent, unless it is an emergency or an exemption applies. The message must also identify the caller.
- Who
- Anyone placing calls to people in the US.
- Enforced by
- Federal Communications Commission, state attorneys general and private lawsuits; $500 per call, or up to $1,500 if willful.
- Law
- FCC Declaratory Ruling FCC 24-17, applying the Telephone Consumer Protection Act, 47 U.S.C. 227(b)
Official text FCC Declaratory Ruling 24-17 (Federal Communications Commission) - In force since April 22, 2026
Get parents’ separate consent to train AI on kids’ data
If your site, app or service is aimed at children under 13, or you know you collect their data, get a parent’s separate, verifiable consent before disclosing a child’s personal information to third parties. The FTC says disclosing it to train or develop AI needs this consent.
- Who
- Operators of websites, apps and online services, including education technology, aimed at children under 13 or knowingly collecting their data.
- Enforced by
- Federal Trade Commission and state attorneys general; civil penalties of up to $53,088 per violation.
- Law
- Children’s Online Privacy Protection Rule, 16 CFR 312.5(a)(2), as amended in 2025
Official text COPPA Rule amendments (Federal Trade Commission) - In force since October 1, 2026
Say whether AI played a part in mass layoffs
When you file a federal mass-layoff (WARN) notice, also tell the Connecticut Labor Department whether the layoffs are related to your use of AI or another technological change.
- Who
- Employers that must file a federal WARN notice, usually those with 100 or more workers.
- Enforced by
- Connecticut Labor Department, in the form the Labor Commissioner sets. The act sets no penalty.
- Law
- Public Act 26-15, section 26
- In force since October 1, 2026
An AI tool is no excuse for discrimination
If an automated tool helps make a job decision, its use is no defence against a discrimination complaint. Evidence of anti-bias testing can be taken into account.
- Who
- Employers in Connecticut.
- Enforced by
- Commission on Human Rights and Opportunities and the courts.
- Law
- Public Act 26-15, sections 13 and 14 (amending C.G.S. 46a-60(b)(1) and 46a-81c)
- In force since October 1, 2026
Do not punish staff who warn about catastrophic AI risks
Do not adopt or enforce any policy or contract that lets you punish staff for reporting a specific and substantial danger from catastrophic AI risk, or for whistleblowing to authorities, and tell your risk staff their rights. Developers with over $500 million in yearly revenue need an anonymous internal reporting channel by January 1, 2027.
- Who
- Frontier AI developers doing business in Connecticut: those training models with more than 10²⁶ operations.
- Enforced by
- Attorney General; civil penalty of up to $1,000 per violation.
- Law
- Public Act 26-15, section 2
- In force since October 1, 2026
Spell out the terms before charging for an AI subscription
Before you start or renew an AI subscription, give the customer a written notice of the key terms, including usage limits and any right to cut features, and get their written acceptance.
- Who
- Anyone selling AI subscriptions to Connecticut residents.
- Enforced by
- Attorney General, as an unfair trade practice; customers cannot sue under this section.
- Law
- Public Act 26-15, section 1
- In force since October 1, 2026
Add provenance data to AI images, audio and video
Where commercially and technically reasonable, embed provenance data in images, audio and video your AI creates or materially alters, and make it hard to remove, for example with the C2PA standard.
- Who
- Makers of generative AI systems for images, audio or video that the public can use for personal purposes and that have more than one million users a month. Business-to-business tools, games, and pure upscaling or compression tools are excluded.
- Enforced by
- Attorney General, as an unfair trade practice; no private lawsuits.
- Law
- Public Act 26-15, section 15
- In force since October 1, 2026
Label prices raised by algorithms using personal data
If an automated process uses a customer’s personal data to set a price shown online, and the price is not a discount, show the notice “THIS PRICE WAS INCREASED BY A PRICE SETTING DEVICE USING YOUR PERSONAL DATA”. Retailers and delivery apps may not set personal prices from tracking data at all, except for cost differences, supply and demand, and open discount or loyalty schemes.
- Who
- Businesses selling to people in Connecticut, for the label; retailers and delivery apps, for the ban. Insurers, banks and other financial institutions are excluded.
- Enforced by
- Attorney General only, as an unfair trade practice; no private lawsuits.
- Law
- Public Act 26-64, section 11
Official text Public Act 26-64 (Connecticut General Assembly) - In force since October 1, 2026
Remove intimate deepfakes in 48 hours, or face state fines
Set up a written process, explained in a plain-language notice on your platform, for victims or the Attorney General to report synthetic intimate images. Remove a valid report within 48 hours and make reasonable efforts to remove copies.
- Who
- Public websites and apps that mainly host content shared by users, as defined in the federal TAKE IT DOWN Act.
- Enforced by
- Attorney General, in court; civil penalties of up to $25,000 a day for each person harmed.
- Law
- Public Act 26-55, section 2
Official text Public Act 26-55 (Connecticut General Assembly) - In force since July 1, 2026
Let people challenge automated profiling decisions
Let people opt out of profiling used for automated decisions with legal or similarly significant effects. If you made such a decision, where feasible let them question the result, tell them the reason and let them review their data; for housing decisions, let them correct the data and get the decision re-evaluated. Do an impact assessment for such profiling.
- Who
- Businesses covered by the Connecticut Data Privacy Act: those serving people in Connecticut that handle the data of at least 35,000 consumers, process sensitive data, or sell personal data. It protects people as consumers, not as workers.
- Enforced by
- Attorney General only, as an unfair trade practice; no private lawsuits.
- Law
- Connecticut Data Privacy Act, C.G.S. 42-518 and 42-522, as amended by Public Act 25-113 (impact assessments for processing from August 1, 2026)
Official text Public Act 25-113 (Connecticut General Assembly) - In force since July 1, 2026
Say in your privacy notice if you train AI on personal data
Your privacy notice must state whether you collect, use or sell personal data to train large language models.
- Who
- Businesses covered by the Connecticut Data Privacy Act: those serving people in Connecticut that handle the data of at least 35,000 consumers, process sensitive data, or sell personal data. It protects people as consumers, not as workers.
- Enforced by
- Attorney General only, as an unfair trade practice; no private lawsuits.
- Law
- Connecticut Data Privacy Act, C.G.S. 42-520, as amended by Public Act 25-113
Official text Public Act 25-113 (Connecticut General Assembly) - In force since October 1, 2026
Post signs if you use face recognition on your premises
If you use face recognition on your premises against security threats, fraud or crime, match faces only against your own database. Post clearly legible signs at each public entrance saying it is in use, with a link or QR code to your face recognition policy, which must give the Attorney General’s contact details.
- Who
- Businesses covered by the Connecticut Data Privacy Act: those serving people in Connecticut that handle the data of at least 35,000 consumers, process sensitive data, or sell personal data. It protects people as consumers, not as workers.
- Enforced by
- Attorney General only, as an unfair trade practice; no private lawsuits.
- Law
- Public Act 26-64, section 16 (C.G.S. 42-524)
Official text Public Act 26-64 (Connecticut General Assembly)
Coming up 3
- Starts January 1, 2027
AI companions must say they are not human and handle crises
An AI companion needs a published protocol that detects talk of suicide, self-harm or violence and refers users to help such as the 988 line, and it must not claim to be human. If it could be mistaken for a person, show a clear AI notice: always visible, or at the start of each day’s first chat and then hourly for minors and every three hours for adults.
- Who
- Operators of AI companion chatbots used in Connecticut.
- Enforced by
- Attorney General only, as an unfair trade practice; no private lawsuits.
- Law
- Public Act 26-15, sections 4 to 6
- Starts January 1, 2027
Protect minors who use your AI companion
If you know or have reason to believe a user is under 18, use measures that meet industry standards to keep your AI companion safe for them. It must not encourage self-harm, suicide, violence, disordered eating or drug use, discourage seeking help, engage in romantic or sexual talk, or use manipulative engagement tactics. Give minors and parents tools to manage screen time and account settings.
- Who
- Operators of AI companions used in Connecticut; customer-service, game, voice-assistant and narrow-task bots are excluded.
- Enforced by
- Attorney General only, as an unfair trade practice; no private lawsuits.
- Law
- Public Act 26-15, section 6
- Starts October 1, 2027
Tell people when an AI tool helps decide about their job
If an automated tool is a substantial factor in a job decision, give the person a written notice before the decision. Tell people in plain language when they are interacting with such a tool.
- Who
- Businesses in Connecticut, such as employers, recruiters and staffing firms, that use automated tools in job decisions about Connecticut staff or applicants. Developers of tools sold for job decisions must give users the information they need.
- Enforced by
- Attorney General only, as an unfair trade practice. For violations up to December 31, 2027, the Attorney General may first give 60 days to fix them. No private lawsuits.
- Law
- Public Act 26-15, sections 7 to 12
Next deadlines
The next rules to start, everywhere we track.
- European UnionDo not offer or use AI that makes sexual deepfakes
- European UnionPlatforms: keep humans in charge of algorithmic management
- CaliforniaSay in layoff notices when AI caused the cuts
- CaliforniaNo surveillance tools in workplace bathrooms
- CaliforniaDo not use AI to read workers’ emotions or neural data
- CaliforniaBig platforms must show whether content is AI-made
What this checker covers
We aim to list every rule that fits the scope below, and we say openly what is not in it yet.
Covered
- Binding laws and regulations about AI, automated decisions, AI-made content, chatbots and AI developers.
- Rules already in force, and rules that are law with a set start date.
- Duties for businesses, employers, platforms and AI makers in the places listed above.
- For Germany, France and Hungary: national rules that add to EU law, and who enforces the AI Act there.
- A few general laws that are the main rule for an AI use in a country, marked “General law”.
Not covered yet
- Rules for a single sector, such as health care, insurance, banking, elections or law firms.
- Rules that bind only public bodies, such as government agencies, state schools or public broadcasters.
- Bills that have not passed, official guidance and voluntary codes.
- Most general laws that are not about AI but still apply to it, such as data protection, anti-discrimination or consumer law.
- Other US states, and countries not listed above, including the United Kingdom.
- National laws of EU countries other than Germany, France and Hungary.
How we check these rules
We read each rule in the official text, the law itself or the regulator’s own page, and link it. Where an earlier summary disagrees with the signed text, we follow the signed text. We last checked all 96 rules, from 69 official sources, on October 1, 2026.
Two notes on dates. California laws that set no start date of their own take effect on January 1 of the next year, so we list the bills signed in September 2026 from January 1, 2027. The EU dates follow the European Commission’s timeline, which includes the changes made by the 2026 Digital Omnibus; the article pages we link still show the 2024 wording.
One note on sources. Illinois’s legislature website could not be reached when we checked, so the Illinois entries rest on official summaries by the Governor, the Attorney General and state agencies. We will check them against the law texts as soon as the site is reachable.
For every AI law, bill, order and court ruling we have covered, including ones that are not yet in force, see the AI laws tracker and the AI calendar.
This is a plain-language guide, not legal advice. Laws have exceptions and details we leave out, and they change. Check the official text, or ask a lawyer, before you act. If you spot a mistake, tell us through the corrections policy.