Data tool
Which AI rules apply to me?
Pick where you work or sell and what you use AI for. You get the AI rules that apply, what they ask you to do and from when, with a link to the official text.
Your checklist
Choose one or more answers to each question. Each rule says what to do, who it is for, and who enforces it.
11 rules match your choices.Includes United States (all states) rules, which apply in every US state.
- No federal law overrides state AI laws. A December 2025 executive order tells federal agencies to challenge some of them, but state laws still apply until a court or Congress says otherwise. Official text
In force now 10
- In force since May 19, 2026
Remove reported intimate deepfakes within 48 hours
Give people a clear, plain-language way to report intimate images of themselves posted without consent, including AI-made fakes. Remove a valid reported image within 48 hours, and make reasonable efforts to remove known identical copies.
- Who
- Public websites, apps and online services that mainly host content from users, with no size threshold. Broadband providers and email are excluded.
- Enforced by
- Federal Trade Commission; civil penalties of up to $53,088 per violation. Removals made in good faith are protected.
- Law
- TAKE IT DOWN Act (Public Law 119-12), section 3
Official text TAKE IT DOWN Act, Public Law 119-12 (GovInfo) - In force since May 19, 2025
Never post AI-made intimate images of real people
It is a federal crime to knowingly publish online an intimate image of an identifiable real person without their consent, including realistic fakes made with AI.
- Who
- Anyone, people and businesses alike.
- Enforced by
- Department of Justice; fines and up to two years in prison, or three years if the person shown is a minor.
- Law
- TAKE IT DOWN Act (Public Law 119-12), section 2, 47 U.S.C. 223(h)
Official text TAKE IT DOWN Act, Public Law 119-12 (GovInfo) - In force since October 21, 2024
Do not post or buy fake reviews, including AI-written ones
Do not write, create, sell or buy reviews or testimonials that falsely suggest the reviewer exists, used the product or had the experience described. The FTC says this covers AI-generated fake reviews.
- Who
- Businesses selling to US consumers.
- Enforced by
- Federal Trade Commission; civil penalties of up to $53,088 per knowing violation.
- Law
- FTC Rule on the Use of Consumer Reviews and Testimonials, 16 CFR part 465
Official text 16 CFR part 465 (eCFR) - In force since February 8, 2024
Get consent before calling people with an AI voice
Calls that use AI-generated or cloned voices count as artificial-voice calls under the federal robocall law, so they need the called person’s prior express consent, unless it is an emergency or an exemption applies. The message must also identify the caller.
- Who
- Anyone placing calls to people in the US.
- Enforced by
- Federal Communications Commission, state attorneys general and private lawsuits; $500 per call, or up to $1,500 if willful.
- Law
- FCC Declaratory Ruling FCC 24-17, applying the Telephone Consumer Protection Act, 47 U.S.C. 227(b)
Official text FCC Declaratory Ruling 24-17 (Federal Communications Commission) - In force since April 22, 2026
Get parents’ separate consent to train AI on kids’ data
If your site, app or service is aimed at children under 13, or you know you collect their data, get a parent’s separate, verifiable consent before disclosing a child’s personal information to third parties. The FTC says disclosing it to train or develop AI needs this consent.
- Who
- Operators of websites, apps and online services, including education technology, aimed at children under 13 or knowingly collecting their data.
- Enforced by
- Federal Trade Commission and state attorneys general; civil penalties of up to $53,088 per violation.
- Law
- Children’s Online Privacy Protection Rule, 16 CFR 312.5(a)(2), as amended in 2025
Official text COPPA Rule amendments (Federal Trade Commission) - In force since November 5, 2025
Add crisis help and “not human” notices to AI companions
If your chatbot acts as an ongoing AI companion, it must detect signs of suicidal thoughts or self-harm and refer users to crisis services such as the 988 line. It must also tell users clearly that they are not talking to a human, at the start of a conversation and at least every three hours while it continues.
- Who
- Businesses that offer AI companions to people in New York for personal use: AI that remembers past chats, asks unprompted emotional questions and keeps up personal conversations. Customer-service, productivity and research tools are excluded.
- Enforced by
- Attorney General; civil penalties of up to $15,000 a day, paid into a suicide prevention fund.
- Law
- General Business Law, article 47 (sections 1700 to 1704), added by Chapter 58 of 2025, Part U
Official text General Business Law, article 47 (New York State Senate) - In force since July 8, 2025
Label prices set by an algorithm using personal data
If an algorithm uses a customer’s personal data to set the price you offer them, show this notice clearly next to the price: “THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA”.
- Who
- Businesses offering personalised algorithmic prices to New York consumers. Insurers, financial institutions under the federal Gramm-Leach-Bliley Act, and lower prices for existing subscriptions are excluded.
- Enforced by
- Attorney General, enforcing since November 10, 2025: a cease-and-desist letter first, then court fines of up to $1,000 per violation. A federal court upheld the law in October 2025, and an appeal is pending.
- Law
- Algorithmic Pricing Disclosure Act, General Business Law section 349-a (Chapter 58 of 2025, Part X)
Official text General Business Law section 349-a (New York State Senate) - In force since June 9, 2026
Disclose AI-generated performers in your ads
If you make an ad and know it includes a synthetic performer, a realistic human made with AI or other software who is not a real, recognisable person, say so clearly in the ad.
- Who
- Anyone who produces or creates commercial ads. Audio-only ads, ads for films, TV shows and video games, and AI used only to translate a real performer’s speech are excluded; outlets that only publish ads are exempt.
- Enforced by
- $1,000 for a first violation and $5,000 for each later one; the law does not name the enforcer.
- Law
- General Business Law section 396-b, as amended by Chapter 617 of 2025
Official text General Business Law section 396-b (New York State Senate) - In force since December 11, 2025
Get consent before using a dead performer’s AI replica
Before you use a digital replica, a realistic computer-made voice or likeness, of a deceased performer in an audiovisual work, a sound recording or a live musical performance, get consent from whoever holds their publicity rights, usually the heirs. A disclaimer is no longer enough.
- Who
- Anyone using a replica of a performer who lived in New York when they died, on or after May 29, 2021, such as studios, labels, advertisers and AI companies.
- Enforced by
- No regulator; the rights holders can sue for $2,000 or their damages, whichever is greater, plus the profits made from the use.
- Law
- Civil Rights Law section 50-f, as amended by Chapter 616 of 2025
Official text Civil Rights Law section 50-f (New York State Senate) - In force since January 1, 2025
Spell out digital replica terms in performer contracts
A contract clause can let you use a digital replica of a person’s voice or likeness instead of work they would have done in person. Such a clause is void if it does not describe the intended uses reasonably specifically, unless the person had a lawyer or a union contract covering such replicas.
- Who
- Any business contracting with a person for personal or professional services in New York, such as actors, voice artists and creators. It applies to contracts made or changed from January 1, 2025.
- Enforced by
- No regulator or fine; such a clause cannot be enforced.
- Law
- General Obligations Law section 5-302
Official text General Obligations Law section 5-302 (New York State Senate)
Coming up 1
- Starts January 1, 2027
Report frontier AI incidents within 72 hours
If you develop frontier AI models, trained with more than 10²⁶ operations, publish a transparency report when you release a new model. Report critical safety incidents to a new office at the Department of Financial Services within 72 hours, or within 24 hours to an authority such as the police if lives are at risk. Developers with over $500 million in yearly revenue must also write, follow and publish a frontier AI safety framework and file disclosures with that office.
- Who
- Frontier AI developers whose models are developed, deployed or operated at least partly in New York. Accredited universities doing academic research are exempt.
- Enforced by
- Attorney General; up to $1 million for a first violation and $3 million for each later one. No private lawsuits.
- Law
- RAISE Act, General Business Law article 44-B, as replaced by Chapter 96 of 2026
Official text S8828, RAISE Act amendments (New York State Senate)
Next deadlines
The next rules to start, everywhere we track.
- European UnionDo not offer or use AI that makes sexual deepfakes
- European UnionPlatforms: keep humans in charge of algorithmic management
- CaliforniaSay in layoff notices when AI caused the cuts
- CaliforniaNo surveillance tools in workplace bathrooms
- CaliforniaDo not use AI to read workers’ emotions or neural data
- CaliforniaBig platforms must show whether content is AI-made
What this checker covers
We aim to list every rule that fits the scope below, and we say openly what is not in it yet.
Covered
- Binding laws and regulations about AI, automated decisions, AI-made content, chatbots and AI developers.
- Rules already in force, and rules that are law with a set start date.
- Duties for businesses, employers, platforms and AI makers in the places listed above.
- For Germany, France and Hungary: national rules that add to EU law, and who enforces the AI Act there.
- A few general laws that are the main rule for an AI use in a country, marked “General law”.
Not covered yet
- Rules for a single sector, such as health care, insurance, banking, elections or law firms.
- Rules that bind only public bodies, such as government agencies, state schools or public broadcasters.
- Bills that have not passed, official guidance and voluntary codes.
- Most general laws that are not about AI but still apply to it, such as data protection, anti-discrimination or consumer law.
- Other US states, and countries not listed above, including the United Kingdom.
- National laws of EU countries other than Germany, France and Hungary.
How we check these rules
We read each rule in the official text, the law itself or the regulator’s own page, and link it. Where an earlier summary disagrees with the signed text, we follow the signed text. We last checked all 96 rules, from 69 official sources, on October 1, 2026.
Two notes on dates. California laws that set no start date of their own take effect on January 1 of the next year, so we list the bills signed in September 2026 from January 1, 2027. The EU dates follow the European Commission’s timeline, which includes the changes made by the 2026 Digital Omnibus; the article pages we link still show the 2024 wording.
One note on sources. Illinois’s legislature website could not be reached when we checked, so the Illinois entries rest on official summaries by the Governor, the Attorney General and state agencies. We will check them against the law texts as soon as the site is reachable.
For every AI law, bill, order and court ruling we have covered, including ones that are not yet in force, see the AI laws tracker and the AI calendar.
This is a plain-language guide, not legal advice. Laws have exceptions and details we leave out, and they change. Check the official text, or ask a lawyer, before you act. If you spot a mistake, tell us through the corrections policy.