Category: AI Policy & Regulation

Analysis of AI legislation, regulation, government policy, compliance requirements, and effective dates.

  • California’s AI Employment Bills Reach Enrolled Status With Human Review and Displacement Notice Rules

    California’s AI Employment Bills Reach Enrolled Status With Human Review and Displacement Notice Rules

    California now has two AI employment bills at enrolled status.

    That matters because the pair does not try to regulate workplace AI as one abstract category. It targets two concrete points where automation changes employment power: discipline or termination decisions, and workforce reductions caused by AI or other automated technology.

    SB 947 would bar employers from relying solely on automated decision systems to discipline or fire workers and would require human review when an employer primarily relies on automated decision system output. SB 951 would add AI-driven or automation-driven displacement information to California's mass-layoff notice framework when a covered Cal-WARN notice is already required.

    Both bills are still awaiting executive action. They are not enacted law yet. But the official California records show both measures enrolled on September 4, 2026, after final Senate concurrence votes on August 31. That makes this a live compliance-planning moment, not another introduced-bill story.

    For companies using workforce AI, the direction is clear enough already. California is moving from "should employers use AI carefully?" to "who reviews the automated output, what must the worker be told, and what public records will exist when automation displaces jobs?"

    What Changed This Week

    The official California bill records show SB 947 and SB 951 both reached enrolled status on September 4, 2026.

    SB 947, titled "Employment: automated decision systems," passed after Assembly amendments were concurred in by the Senate on August 31 by a 28-10 vote. The official Legislative Counsel's Digest says the bill would add a new Labor Code part beginning July 1, 2027.

    SB 951, titled "Employment: technological displacement: notice," also reached enrolled status on September 4 after Senate concurrence in Assembly amendments on August 31, by a 29-10 vote.

    Those statuses matter because the legislative question has narrowed. The bills are no longer merely concepts being debated in committee. They are passed measures awaiting executive action.

    That does not make them binding yet. It does make them serious enough that companies should begin mapping whether their workforce systems would fall within the rules if the bills are signed.

    SB 947 Is About AI in Discipline and Termination

    SB 947 is the more direct "robo boss" bill.

    The official digest says the bill would, beginning July 1, 2027, prohibit an employer from using an automated decision system to perform certain functions and limit the purposes for and way in which such a system may be used. It would also create employee rights around the data used by the system when the employer primarily uses an automated decision system to make a disciplinary or termination decision.

    The bill is more than a ban on a fully automated firing button. It is also a documentation and notice bill.

    When an employer primarily uses an automated decision system to make a disciplinary or termination decision, the bill would allow the affected employee to request a description of the employee's own data primarily used by the system. It would also require a written post-use notice when an employer primarily relied on an automated decision system to make the decision.

    The author's office frames the bill more plainly. Senator Jerry McNerney's announcement says SB 947 would bar employers from relying solely on automated decision systems to fire or discipline workers, require human oversight and verification when such systems assist those decisions, and require employers to inform workers if an automated decision system was used.

    The enforcement structure also matters. The official digest says the Labor Commissioner could enforce the bill and a public prosecutor could bring a civil enforcement action. The author's announcement says the bill does not provide a private right of action.

    For employers, that combination points to a regulatory file rather than just a lawsuit file. If the bill is signed, companies will need to show how the human review worked, what notice was given, what data description can be produced, and why the automated system was not treated as the final unreviewed decision maker.

    SB 951 Is About AI-Driven Job Displacement

    SB 951 addresses a different problem: not the individual disciplinary decision, but the larger workforce event.

    The official status page describes SB 951 as a bill on "Employment: technological displacement: notice." The bill text would amend California's mass-layoff notice framework so that, when an employer is already required to issue notice for a mass layoff, relocation, or termination, and that event is caused in whole or in substantial part by an AI system or other automated technology replacing or automating employment positions, the notice must include additional information.

    That information would include:

    • the number, classification or occupation, and work location of layoffs substantially due to replacement or automation by AI or other automated technology;
    • the job functions performed by the replaced workers that will be automated;
    • the specific category or type of AI system or other automating technology that substantially resulted in technological displacement; and
    • a statement at the top of the notice saying, "This notice is for a technology displacement."

    The bill would also require California's Employment Development Department, as part of regular Cal-WARN Act data reporting, to publish a summary of notices received under the new technological-displacement subdivision and post quarterly statewide summaries of reported technology displacements.

    That is a major practical point. SB 951 would add a public reporting trail about AI-related and automation-related displacement.

    For companies, that means the decision to attribute a layoff to AI or automation may become visible outside the company. For policymakers, researchers, unions, journalists, and competitors, the same notices could become a data source about where automation is actually replacing jobs.

    The Two Bills Should Be Read Together

    SB 947 and SB 951 are stronger together than either bill is alone.

    SB 947 focuses on decision quality and worker process when an automated decision system is used in discipline or termination. SB 951 focuses on transparency when technology changes the structure of the workforce.

    One is about the affected worker asking: was an automated system used against me, and what data did it rely on?

    The other is about the affected workforce, government, and public asking: are jobs being eliminated because AI or automation is replacing them, and where is that happening?

    That is the real story. California is moving beyond product-level workplace AI regulation and into the evidence trail around workplace AI.

    Employers will not be able to treat these questions as purely internal design choices if the bills are signed. The practical burden will sit in HR, legal, compliance, procurement, data governance, labor relations, and workforce planning.

    This Fits a Broader State Pattern

    California is not moving in isolation.

    Colorado's 2026 automated decision-making technology law, which replaces the state's earlier high-risk AI framework, also turns on notice, explanations, data correction, and meaningful human review. Illinois already regulates certain employment uses of artificial intelligence through amendments to the Illinois Human Rights Act. New York City has had its automated employment decision tool law in force for several years.

    The California bills would add a different kind of pressure.

    SB 947 would push into discipline and termination, beyond the hiring focus of many employment-AI laws. SB 951 would push into displacement reporting through Cal-WARN notices. Together, they would make employment AI governance a continuing operational requirement rather than a one-time vendor review.

    That matters because many organizations still treat AI employment risk as a hiring-screening issue. The newer pattern is broader. It covers who is evaluated, who is disciplined, who is terminated, who is replaced, and what records prove the company did not let automated systems quietly make the real decision.

    What Companies Should Do Before Signature

    Companies do not need to wait for final enactment to start the useful work.

    The first step is inventory. Employers should identify systems that rank, score, recommend, flag, classify, monitor, or otherwise influence discipline, performance management, termination, layoffs, redeployment, or workforce planning.

    The second step is role mapping. A tool that merely stores employee records is different from a tool that recommends termination, flags productivity concerns, scores performance, identifies positions for elimination, or produces a workforce-reduction plan.

    The third step is human-review design. If a system can affect discipline or termination, the company should be able to say who reviews the output, what information the reviewer sees, what discretion the reviewer has, and how the company records the human judgment.

    The fourth step is notice and data-description readiness. If a worker can ask for a meaningful, objective description of the employee's own data that the system primarily used, the company needs to know whether that description can be produced without exposing unrelated confidential or third-party information.

    The fifth step is displacement classification. If AI or automated technology contributes to layoffs or job eliminations, the company should decide how it will determine whether the technology caused the event "in whole or in substantial part." That phrase is likely to do a lot of work if SB 951 becomes law.

    What Not To Overstate

    There are three cautions.

    First, neither bill is enacted yet. The Governor can still sign, veto, or otherwise affect the final posture. The right status today is enrolled and awaiting executive action.

    Second, SB 947 should not be described as banning all AI use in employment decisions. The official materials point to limits, human oversight, worker notice, and data-description rights around covered uses, especially discipline and termination.

    Third, SB 951 is not a general anti-automation law. It is a notice and reporting bill tied to covered Cal-WARN mass-layoff and related events caused in whole or in substantial part by AI systems or other automated technology.

    Those limits make the bills more useful, not less. They show where the compliance work will actually sit.

    Bottom Line

    California's latest AI employment package is about control and records.

    SB 947 asks whether a human really reviewed the automated decision system output that helped discipline or fire a worker, and whether the worker gets notice and a meaningful description of the employee data primarily used around that use. SB 951 asks whether AI or automation materially contributed to displacement in a covered Cal-WARN event and whether that fact will be reported through the state's layoff-notice system.

    If both bills are signed, California will add another important layer to workplace AI governance: whether the company can show who relied on the tool, who reviewed its output, what the worker was told, and what the public record says when technology replaces jobs.

    That is a much harder problem than updating an AI policy. It is a workflow problem. Companies that use automated systems in employment decisions should treat it that way now.

    Sources and Related Clearon Coverage

  • Courts and AI

    Courts and AI

    Courts and AI

    Courts and AI

    Court rules, standing orders, sanctions rulings, privilege and work-product decisions, protective-order restrictions, and tribunal guidance on AI use.

    This page tracks what courts and tribunals are requiring, permitting, warning about, and sanctioning. It is about rules and rulings, not the broader universe of AI-related lawsuits.

    44tracked court-rule and ruling developments
    13jurisdictions and tribunal categories
    5views for rules, rulings, tribunals, and bar guidance
    242026-dated tracker updates

    Featured alert: AI court rules and rulings

    Courts are moving from general warnings about artificial intelligence to concrete filing certifications, protective-order restrictions, privilege rulings, and sanctions frameworks. There is still no single national rule, but there is now a growing body of court-specific requirements and decisions.

    Bottom line: This page is a court-rules-and-rulings tracker. It focuses on what judges, courts, and tribunals are saying and doing, not on the full field of AI-related lawsuits.

    What this page covers

    Court rules and standing orders

    Forum-specific filing certifications, AI disclosure rules, sanctions warnings, and state court policies.

    Privilege, work product, and protective orders

    Early decisions on AI-assisted filings and advocacy preparation, tool identity, discovery confidentiality, and open AI restrictions.

    Patent practice moved

    Patent-office guidance and AI inventorship now live on a separate Patent Practice page, not in this court-rules-and-rulings tracker.

    State court and bar guidance

    State court policies, local administrative orders, and state or local bar guidance verified against primary sources.

    Featured developments

    Category Development Practice point
    Privilege / work product United States v. Heppner and Warner v. Gilbarco reached different results on AI-related work product. AI use does not create one uniform privilege rule; counsel direction, platform type, confidentiality, and procedural posture matter.
    Protective orders Morgan v. V2X and Jeffries v. Harcros Chemicals restricted AI use with confidential or discovery material. Protective orders should address open vs. closed AI tools, training, retention, deletion, and disclosure.
    Filing rules Florida and New York now show two statewide approaches: Florida requires signer certification that cited authorities exist and are accurately cited; New York permits AI-assisted submissions without systemwide disclosure but requires independent verification. Lawyers should treat verification as the baseline obligation even when disclosure is not required.
    Sanctions / local counsel The Ninth Circuit’s Lnu v. Blanche order and the Northern District of Mississippi’s Withers v. City of Aberdeen sanctions order show courts escalating remedies for AI-fabricated authorities. Candor, signer review, local-counsel supervision, and prompt correction can matter as much as the original AI use.
    Patent practice moved Patent-office guidance and AI inventorship have been moved off this page and are tracked separately on the Patent Practice page. Use this page for court rules, rulings, sanctions, privilege, and protective-order developments rather than USPTO, PTAB, or TTAB practice.
    Evidence Proposed Federal Rule of Evidence 707 would address machine-generated evidence. AI evidence issues may move from filing guidance into admissibility doctrine.

    AI court rules and rulings tracker

    Search court rules, standing orders, sanctions decisions, protective-order rulings, administrative tribunal guidance, and bar guidance that shape how lawyers can use AI before courts and tribunals.

    Last updated 2026-08-12
    44published tracker rows
    13jurisdictions and tribunal categories
    21court-rule and standing-order items
    15rulings and sanctions items
    Date / Type Jurisdiction / Authority Development Requirement or Outcome Practice Takeaway Source Status
    2026-02-17Cases Federal
    S.D.N.Y.
    United States v. Heppner
    Privilege; work product
    Attorney-client privilege and work-product protection denied Consumer AI use outside counsel direction is high risk for privilege and work-product claims primary order
    2026-02-10Cases Federal
    E.D. Mich.
    Warner v. Gilbarco Inc.
    Work product
    AI-related litigation materials protected as work product; defendants’ motion to compel denied in relevant part AI use does not automatically waive work product in civil litigation when disclosure is not likely to reach an adversary primary order
    2026-03-30Cases Federal
    D. Colo.
    Morgan v. V2X Inc.
    Work product; tool identity; protective order
    Work product reportedly protected but AI tool identity had to be disclosed; protective order amended Tool identity may be discoverable even when AI-assisted mental impressions remain protected primary order
    2025-10-30Cases Federal
    E.D. Mich.
    Warner v. Gilbarco Inc. protective-order amendment
    Protective order
    Court modified Rule 26(c) protective order so documents marked confidential shall not be uploaded onto any AI platform Protective orders can impose broad AI-upload bans for confidential discovery primary order
    2026-03-25Cases Federal
    D. Kan.
    Jeffries v. Harcros Chemicals Inc.
    Protective order
    Court granted motion to amend protective order and entered defendants’ proposed language restricting open AI tools for discovery materials Discovery orders may restrict public AI based on retention training deletion clawback privacy and security risks primary order
    2026-06-15Court Rules Florida
    Supreme Court of Florida
    In re Amendments to Florida Rule of General Practice and Judicial Administration 2.515
    Court filing certification; sanctions
    Signer represents cited legal authorities exist and are accurately cited; sanctions expressly authorized after notice and opportunity to be heard Statewide uniform rule replaces varied circuit AI disclosure and certification requirements; comments due 2026-08-11 primary administrative order
    2026-01-01Court Rules Federal
    U.S. Bankruptcy Court S.D. Cal.
    General Order 210 and CSD 5013
    Court filing disclosure and certification
    Disclosure and certification required through local form CSD 5013; filer identifies AI program and certifies factual/legal accuracy check outside AI Useful model for courtwide filing-attestation process primary order
    2026-01-28Court Rules Federal
    D. Kan.
    Standing Order 26-01 Use of Artificial Intelligence in Preparing Court Filings
    Court filing verification; sanctions
    Litigants remain responsible for verifying AI-assisted content; court may strike filings impose sanctions or require sworn AI-use statements Good example of districtwide caution plus discretionary case-specific disclosure primary order
    2025-12-01Court Rules Federal
    D. Colo. Judge Nina Y. Wang
    Standing Order Regarding Use of Generative AI in Court Filings
    Court filing certification; client consent
    Every filing must include AI certification; if AI used counsel must certify human review and client consent Judge-specific orders may go beyond Rule 11 by requiring AI-use certifications in every filing primary order
    2024-10-21Court Rules Federal
    D. Colo. Magistrate Judge Susan Prose
    Standing Order Requiring Certification Re Use of AI in Filings
    Court filing certification
    Specified motions must certify AI use or non-use; noncompliant filings may be stricken Certification requirements may be limited by motion type and referral posture primary order
    2023-06-06Court Rules Federal
    E.D. Pa. Judge Michael M. Baylson
    Standing Order Re Artificial Intelligence in Cases Assigned to Judge Baylson
    Court filing disclosure and certification
    AI use must be disclosed in a plain factual statement and citations must be certified as verified Early judge-specific model for AI disclosure and citation verification primary order
    2023-06-08Court Rules Federal
    U.S. Court of International Trade Judge Stephen Vaden
    Order on Artificial Intelligence
    Confidentiality; court filing disclosure
    Parties using generative AI must disclose program and AI-drafted text and certify no unauthorized disclosure of confidential or business proprietary information Important confidentiality-focused court order for AI use in litigation filings primary order
    2025-06-10Proposed Rules Federal
    Judicial Conference Advisory Committee on Evidence Rules
    Proposed Federal Rule of Evidence 707
    Machine-generated evidence; admissibility
    Would require Rule 702-style reliability showing when machine-generated evidence would be subject to Rule 702 if testified to by a witness Track as systemic evidence-rule development separate from filing-certification standing orders primary committee report
    2024-06-10Court Rules Federal
    U.S. Court of Appeals for the Fifth Circuit
    Decision not to adopt proposed AI briefing rule
    Appellate filing certification
    Court declined to adopt a special AI rule at that time Important negative datapoint: existing certification and accuracy duties may be viewed as sufficient at appellate level primary court rule-change page
    2023-11-13Court Rules Federal
    D. Haw.
    General Order 23-1 re In re Use of Unverified Sources
    Court filing disclosure; unverified sources
    Requires a Reliance on Unverified Source declaration when counsel or a pro se party submits filing material generated by an unverified source; excludes basic research tools such as Westlaw Lexis Fastcase Bloomberg Law Westlaw Edge Lexis+ or similar reliable legal sources Useful district-wide model treating generative AI output as an unverified source primary order
    2024-12-01Court Rules Federal
    D. Neb.
    Nebraska Civil Rule 7.1(d) Generative AI and Certificate of Compliance
    Court filing certification; Rule 11
    Requires certificate stating no generative AI was used or that a human verified all generated text citations and legal authority Notable district-wide local rule rather than individual standing order primary local rules
    2025-09-02Court Rules Federal
    N.D. Tex.
    Local Civil Rule 7.2(f) and Local Criminal Rule 47.2(e) AI disclosure
    Court filing disclosure
    A brief prepared using generative AI must disclose this fact on the first page under the heading Use of Generative Artificial Intelligence; no disclosure certifies no generative AI was used Track as district-wide local-rule approach primary court rule page
    2025-09-01Court Rules California
    Judicial Council of California
    California Rule of Court 10.430 and Standard of Judicial Administration 10.80
    Judicial-branch generative AI policy
    Courts that allow generative AI must adopt a use policy or prohibit use; Standard 10.80 provides guidance for judicial officers acting in an adjudicative role Statewide court-system governance model rather than attorney filing-disclosure rule primary rule
    2025-01-01Court Rules Illinois
    Supreme Court of Illinois
    Illinois Supreme Court Policy on Artificial Intelligence
    Court and litigation AI use; existing-rule sufficiency
    Policy permits AI use subject to existing legal ethical and court rules and says existing rules are sufficient Important contrast to jurisdictions adopting new disclosure mandates primary court announcement
    2025-08-01Court Rules Louisiana
    Louisiana Legislature
    Louisiana Code of Civil Procedure article 371(C)
    Evidence authenticity; AI evidence
    Requires reasonable diligence regarding authenticity of evidence before offering it to the court Track as evidence/authenticity rule rather than filing-certification rule primary act text
    2024-03-05Other New Mexico
    New Mexico Legislature
    HB 182 amendments to the Campaign Reporting Act
    1-19-26.8
    State law regulates AI-generated election-related ads and separately prohibits certain knowingly deceptive AI media distributed within ninety days of an election unless statutory disclaimer conditions are met Enacted law requires disclaimers for covered AI-generated political advertisements and creates civil/criminal enforcement around materially deceptive media; The Babylon Bee sued on 2026-08-11 arguing the disclaimer regime is unconstitutional as applied to satire and parody https://www.nmlegis.gov/sessions/24%20Regular/final/HB0182.PDF
    2025-08-08Tribunals Federal administrative
    Executive Office for Immigration Review
    Policy Memorandum 25-40 guidance on generative AI in immigration proceedings
    Administrative tribunal filings; hallucinated citations
    No blanket ban or mandatory disclosure; adjudicators may address inaccurate AI-assisted filings through existing authorities Useful admin-tribunal example focused on verification and discipline rather than blanket prohibition primary policy memo
    2025-06-05Court Rules Arkansas
    Supreme Court of Arkansas
    Proposed Arkansas Supreme Court Administrative Order No. 25 Artificial Intelligence
    Court-system AI policy; confidential court data
    Proposed administrative order published for comment addressing generative AI use with confidential court data State supreme court-level AI governance proposal focused on confidentiality and court data primary court proposal
    2026-05-20Court Rules Florida
    Eleventh Judicial Circuit of Florida Miami-Dade County
    Administrative Order 26-15 re use of AI in court filings by attorneys and self-represented litigants
    Court filing disclosure and verification
    Requires disclosure of generative AI use and verification that the filing was independently checked Local Florida circuit order aligned with Broward and later superseding earlier Miami-Dade AO 26-04 primary court announcement
    2026-01-26Court Rules Florida
    Seventeenth Judicial Circuit of Florida Broward County
    Administrative Order 2026-03-Gen use of AI in court filings
    Court filing disclosure and certification
    Requires disclosure/certification when generative AI is used in court filings and emphasizes accuracy confidentiality candor diligence and procedural-rule compliance Local Florida circuit order requiring AI-use certification in filings primary order
    2025-12-08Court Rules North Carolina
    Superior Court of Cabarrus County
    Revised Administrative Order re Artificial Intelligence in Superior Court Proceedings
    Court filing disclosure; AI-generated content; pro se and attorney filings
    Revised local administrative order governs AI use in superior court proceedings and supersedes prior Cabarrus order County-level state court AI order; useful as an early state trial-court model primary order
    2024-01-19Bar Guidance Florida
    The Florida Bar
    Florida Bar Ethics Opinion 24-1 Lawyers’ Use of Generative Artificial Intelligence
    Lawyer ethics; competence; confidentiality; supervision; fees; advertising
    Lawyers may use generative AI if they comply with existing ethics obligations including confidentiality competence supervision candor fees and advertising duties State bar ethics guidance should be tracked separately from court filing orders primary bar ethics opinion
    2023-11-16Bar Guidance California
    State Bar of California
    Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law
    Lawyer ethics; competence; confidentiality; supervision; billing; candor
    Applies existing California professional duties to generative AI use and flags confidentiality competence supervision candor and billing risks State bar practical guidance complements California court-system Rule 10.430 but serves a different audience primary bar guidance
    2024-03-28Bar Guidance Michigan
    State Bar of Michigan
    Transforming the Legal Profession in the Age of AI report and resources
    Lawyer ethics; competence; confidentiality; unauthorized practice; access to justice
    State Bar of Michigan identifies ethical considerations and lawyer obligations to understand AI’s benefits and risks Useful Michigan-specific bar source for ethics and practice training rather than a binding court order primary bar resource
    2024-08-07Bar Guidance New York
    New York City Bar Association
    Formal Opinion 2024-5 Generative AI in the Practice of Law
    Lawyer ethics; confidentiality; competence; candor; supervision; fees
    Opinion identifies existing professional duties implicated by generative AI use including confidentiality competence diligence candor supervision and client communication Use as New York ethics guidance; do not label as statewide court rule primary bar ethics opinion
    2026-06-04Cases Oregon
    Oregon Supreme Court
    Aldridge v. Tussing
    Fabricated authorities; sanctions; pro se filings
    Court struck petition and show-cause response and dismissed proceeding Repeating fabricated-authority misconduct after a direct warning can convert a filing error into case-ending sanctions primary order
    2026-06-04Cases Oregon
    Oregon Supreme Court
    Witkin v. McGreevy
    Fabricated authorities; sanctions; certification; pro se filings
    Court struck response imposed $500 sanction and allowed corrected filing with source-existence certification Prompt compliance and acceptance of responsibility may mitigate sanctions but do not excuse an unverified filing primary order
    2026-03-23Cases Federal
    District of Oregon
    Couvrette v. Wisnovsky
    Fabricated authorities; Rule 11; local counsel; fee shifting
    Court finalized $94,704.38 fee-and-cost award allocated 85% to lead counsel and 15% to local counsel after earlier sanctions and dismissal with prejudice Local counsel and supervising lawyers cannot treat filing and pro hac vice responsibilities as merely administrative primary order
    2026-06-03Cases Federal
    Ninth Circuit
    Lnu v. Blanche
    Fabricated authorities; inaccurate authorities; candor; appellate discipline
    Court imposed $2500 on each lawyer six-month suspensions broad notice duties two-year AI disclosure and verification requirements and licensing-authority referrals Candor after discovery of an AI-assisted error can materially affect discipline and firm policies do not replace personal verification primary published order
    2026-06-01Court Rules New York
    New York State Unified Court System
    Part 161 Use of Artificial Intelligence Technology
    Court filing verification; AI use; sanctions
    AI use is permitted without systemwide mandatory disclosure but users must understand tool limits and independently verify papers contain no fabricated or fictitious cases statutes or other material New York chose a verification-first statewide rule while allowing individual judges to adopt additional part rules primary rule
    2026-06-08Cases Federal
    N.D. Miss.
    Withers v. City of Aberdeen
    Fabricated authorities; Rule 11; local counsel; pro hac vice; disqualification
    Court disqualified all four lawyers from the case revoked two pro hac vice admissions barred those lawyers from appearing in the district for two years imposed fines and referred the order to disciplinary authorities Local counsel and sponsoring counsel face personal risk when they act as a rubber stamp for AI-assisted filings prepared by others primary docket; secondary order copy
    2026-06-16Bar Guidance California
    State Bar of California
    Proposed Amendments to the Rules of Professional Conduct Related to Artificial Intelligence
    Lawyer ethics; competence; confidentiality; supervision; agentic AI
    State Bar seeks public comment on proposed amendments addressing AI use in legal practice California may move from practical AI guidance toward binding professional-conduct language including agentic-AI issues primary bar proposal
    2026-06-11Cases Federal
    E.D. Tex.
    McCormick v. Texakoma Financial Inc.
    Fabricated authorities; Rule 11; attorney supervision; verification certification
    Court sanctioned attorney Amy L.B. Ginsburg publicly reprimanded her required CLE required review of 2026 filings for authority accuracy and imposed a certification-of-verification requirement for future filings Wrong-draft and staff-blame explanations are unlikely to mitigate if counsel cannot show personal verification of authorities quotes and the filed version primary docket; secondary summary
    2026-03-20Cases Ohio
    Ohio Court of Appeals Eleventh Appellate District
    State v. Coleman
    Fabricated record quotations; sanctions; nonlawyer supervision; duty to correct
    Court imposed a $2000 sanction credited against settlement payment referred counsel to disciplinary authorities struck the application removed counsel required CLE required apologies and imposed two-year court-notice and filing-certification obligations AI supervision failures are not limited to fake case citations; fabricated record quotations and failure to correct after notice can trigger broad protective sanctions primary opinion
    2026-04-01Bar Guidance Ohio
    Ohio Board of Professional Conduct
    Ohio Ethics Guide Artificial Intelligence for Lawyers and Judicial Officers
    Lawyer and judicial ethics; competence; confidentiality; supervision; candor; judicial decision-making
    Nonbinding Board staff guide applies existing Ohio professional-conduct and judicial-conduct duties to AI use including independent verification confidentiality safeguards supervision fee reasonableness candor and judicial nondelegation Track separately from court filing rules because it is nonbinding ethics guidance but it is a useful Ohio-specific synthesis for lawyers and judges primary ethics guide
    2026-04-03Cases Federal
    Sixth Circuit
    United States v. Farris
    Fabricated quotations; inaccurate authorities; CJA counsel; legal AI product
    Court denied CJA compensation forwarded opinion for disciplinary review served district court and bar authorities and separately removed counsel and ordered new briefing Legal AI tools from established providers can still produce false quotations or misleading case descriptions; attorney verification remains nondelegable primary published opinion
    2026-03-30Cases Federal
    Seventh Circuit
    Dec v. Mullin
    Fabricated authorities; inaccurate quotations; appellate briefing; opposing counsel vigilance
    Court admonished counsel but declined further sanctions because the errors were unintentional and counsel was contrite while also criticizing opposing counsel for failing to catch the errors The verification burden remains on the filer but courts may expect opposing counsel to raise obvious fabricated-authority problems once they are noticed primary opinion mirror
    2026-06-17Cases Michigan
    Michigan Court of Appeals
    Barber v. Morawa
    Fabricated authorities; unsupported citations; sanctions; grievance referral
    Court affirmed denial of new trial but held counsel violated MCR 7.216(C)(1) and MCR 1.109(E)(5) remanded for actual damages and reasonable fees payable personally by counsel and forwarded opinion to the Attorney Grievance Commission Published Michigan appellate authority confirms AI-related citation failures can trigger personal fee exposure and disciplinary referral primary published opinion
    2026-04-28Court Rules Oregon
    Oregon Court of Appeals
    Notice Regarding Court Imposition of Sanctions for Submission of Fabricated Authority Produced by AI
    Fabricated authorities; court notice; sanctions warning
    Fabricated authority can support striking a filing monetary sanctions payable to the court attorney-fee awards to opposing parties and dismissal of the appeal Oregon appellate courts are moving from case-by-case sanctions to broader public notice of verification obligations primary court notice

    No tracker rows match the current filters.

    Publication policy: rows are sourced to primary court, agency, legislature, or bar materials where available. Secondary trackers are used for lead generation and are not treated as final authority.

    What lawyers and court-facing teams should do now

    • Review judge-specific standing orders, local rules, state court policies, and tribunal guidance before major filings.
    • Verify every citation, quotation, record reference, legal proposition, and factual assertion in AI-assisted work.
    • Do not treat a no-disclosure rule as a no-review rule; court rules increasingly focus on whether the filing was independently verified.
    • Do not upload confidential discovery, privileged material, trade secrets, protected health information, export-controlled information, or business proprietary information into public AI tools.
    • Confirm whether any protective order permits closed enterprise AI tools and whether the tool contract addresses training, retention, disclosure, and deletion.
    • Treat AI-generated evidence differently from AI-assisted drafting. Evidence still must be authentic, admissible, and tied to real-world facts.

    Source note: Clearon gives preference to primary court, agency, legislature, and bar sources. Secondary trackers are used as leads, not as final authority.

  • Colorado Replaced Its Landmark AI Act. The New Law Is About Notice, Explanations, and Human Review

    Colorado Replaced Its Landmark AI Act. The New Law Is About Notice, Explanations, and Human Review

    Colorado did more than amend its first AI law. It replaced the law's operating model.

    The 2024 statute was built around high-risk AI systems, algorithmic-discrimination duties, risk-management programs, impact assessments, and a reasonable-care standard. Senate Bill 26-189 repealed and reenacted that framework in May 2026.

    The replacement law uses a different center of gravity. It regulates automated decision-making technology that materially influences consequential decisions. Its main requirements concern notices, technical documentation, explanations after adverse outcomes, correction of inaccurate personal data, and meaningful human review.

    The new law takes effect January 1, 2027. It is narrower in some important ways, but it is not light-touch. Companies still need to know which systems are covered, who is acting as developer or deployer, what role the technology played in a decision, and whether a human reviewer can reconsider the result in a meaningful way.

    The Short Answer

    • Colorado replaced the original "high-risk AI system" framework with a law covering automated decision-making technology, or ADMT, that materially influences consequential decisions.
    • The replacement removes the original law's broad duty-of-care, risk-management, impact-assessment, and algorithmic-discrimination structure.
    • Developers must provide deployers with technical documentation, known limitations, appropriate-use instructions, and human-review guidance.
    • Deployers must give notice at the point of interaction and explain the role of covered ADMT after an adverse outcome.
    • Consumers may request correction of inaccurate personal data and meaningful human review and reconsideration.
    • The Colorado Attorney General has exclusive enforcement authority under the Colorado Consumer Protection Act. The law creates no new private right of action.

    From "High-Risk AI" to Covered ADMT

    The change in terminology is substantive.

    SB 26-189 defines ADMT as technology that processes personal data and uses computation to generate output used to make, guide, or assist a decision about an individual. The output can include a prediction, recommendation, classification, ranking, score, or other information.

    The law applies when ADMT is used to "materially influence" a consequential decision. Covered domains include:

    • education;
    • employment and compensation;
    • housing;
    • financial and lending services;
    • insurance;
    • health-care services; and
    • essential government services and public benefits.

    That framing puts the decision process ahead of the product label. A tool does not become covered simply because a vendor calls it artificial intelligence. A company also cannot assume a system falls outside the law because it uses an older statistical method or carries no AI branding. The relevant questions are whether the technology processes personal data, produces computational output, and materially influences a covered decision.

    The statute excludes several categories of tools, including specified cybersecurity and fraud-prevention technologies, basic spreadsheets that require human analysis, and tools that merely communicate, organize, or summarize information for later human review. Those exclusions make the boundary around "materially influence" especially important. A system that only organizes information may be outside the definition. A system that ranks candidates or recommends a denial may be doing much more.

    What Colorado Removed

    The 2024 law asked developers and deployers of high-risk AI systems to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. It offered a rebuttable presumption of reasonable care for companies that followed a detailed compliance structure.

    For deployers, that structure included a risk-management policy, impact assessments, annual reviews, public disclosures about high-risk systems, and reporting certain algorithmic-discrimination risks to the Attorney General.

    SB 26-189 does not carry that architecture forward.

    The replacement law removes the general reasonable-care duty tied to algorithmic discrimination. It also removes the statutory risk-management-program and impact-assessment requirements that made the original Colorado law resemble an enterprise AI governance regime.

    That is a major narrowing. It matters for both compliance costs and the pending constitutional dispute over the earlier framework.

    It does not mean discrimination risk disappeared. Existing civil-rights and antidiscrimination laws still apply. SB 26-189 also addresses how fault may be allocated between developers and deployers in civil actions alleging unlawful discrimination under existing law. What changed is the AI statute's own regulatory mechanism.

    What Developers Must Provide

    Starting January 1, 2027, a developer of covered ADMT must provide deployers with technical documentation. The documentation must address subjects that a deployer needs in order to use the system appropriately, including:

    • intended uses;
    • categories of training data;
    • known limitations;
    • instructions for appropriate use; and
    • instructions for human review.

    Developers must also notify deployers of material updates or modifications.

    This creates a practical supply-chain obligation. A deployer cannot provide a useful explanation or conduct a meaningful review if the developer supplies only a marketing deck and a generic assurance that the model is compliant.

    Contracts should identify who will provide the required documentation, how updates will be communicated, and what information the deployer will receive about limitations and review. Procurement teams should also check whether the vendor's documentation is specific enough to support a real decision workflow.

    Both developers and deployers must retain records needed to show compliance for at least three years.

    What Deployers Must Tell People

    The replacement law places much of the consumer-facing work on deployers.

    A deployer must provide clear and conspicuous notice at the point where a consumer interacts with covered ADMT. If the ADMT materially influences a consequential decision that produces an adverse outcome, the deployer must provide a plain-language description within 30 days.

    That description must explain the consequential decision and the role the covered ADMT played. The law also requires a process through which the consumer can request more information and exercise the rights provided by the statute.

    This is not satisfied by a general privacy notice that says the company "may use automated tools." The required explanation is tied to an actual adverse decision and the technology's role in it.

    Companies will need to preserve enough decision-level information to answer questions such as:

    • Which model or system version was used?
    • What data about the individual entered the process?
    • What output did the system produce?
    • Who received that output?
    • How did the output affect the final decision?
    • Could a human decision-maker depart from it?

    Without those records, a 30-day explanation requirement can turn into an expensive reconstruction exercise.

    Correction Rights and Meaningful Human Review

    Consumers affected by an adverse outcome may request access to personal data and correction of factually incorrect or materially inaccurate personal data used in the decision. They may also request meaningful human review and reconsideration.

    The word "meaningful" should do real work.

    Review cannot amount to routing the same data through the same system and returning the same answer. A reviewer should have enough authority, information, and time to evaluate the decision. The process should show what the reviewer considered and whether the reviewer could change the result.

    For employers, lenders, insurers, health-care organizations, and government programs, this raises an operational question that should be answered before launch: who can actually reconsider an adverse outcome?

    A policy that promises human review without assigning a qualified reviewer or giving that person authority to act will be hard to defend.

    Enforcement and the Cure Period

    The Colorado Attorney General enforces SB 26-189 through the Colorado Consumer Protection Act. A violation is treated as a deceptive trade practice.

    The statute does not create a new private right of action. Before bringing an enforcement action prior to January 1, 2030, the Attorney General must provide 60 days' notice and an opportunity to cure when a cure is possible.

    The cure period reduces immediate enforcement pressure, but it is not a substitute for implementation. Some failures can be fixed prospectively. Missing decision records, inadequate notices, or a review process that never existed may be much harder to repair after an adverse outcome.

    What the Replacement Means for the xAI Case

    xAI filed its federal lawsuit against the original Colorado law in April 2026. The United States later intervened. Their constitutional claims targeted the earlier statute's algorithmic-discrimination and risk-governance structure.

    SB 26-189 changes the object of that fight.

    The federal court's April 27 order anticipated that possibility. It covers SB 24-205 and legislation enacted during the 2026 session that replaces or amends it. The order also allows xAI to amend its complaint, if necessary, after Colorado adopts final implementing rules. The Attorney General agreed not to enforce covered violations occurring on or before 14 days after the court rules on the forthcoming preliminary-injunction motion.

    There is no final merits ruling. It is also too early to say which constitutional claims will remain live against the replacement law. Removing the earlier algorithmic-discrimination duty may narrow some arguments, while notice, documentation, and decision-review requirements could generate different ones.

    For now, the litigation affects timing and uncertainty. It does not erase the January 1, 2027 statutory effective date or the need to prepare for the final rules.

    What Companies Should Do Before 2027

    Companies can start with the decision process rather than attempting a company-wide inventory of anything labeled AI.

    First, identify systems that use personal data to rank, score, recommend, classify, or otherwise influence decisions in the covered domains.

    Second, document why each system does or does not materially influence the decision. That boundary judgment may become important later.

    Third, map developer and deployer roles. The same company may be a deployer for purchased software and a developer for internally built or substantially modified tools.

    Fourth, test whether vendor documentation covers intended uses, training-data categories, limitations, updates, and human review. Add contract terms where the documentation or update process is weak.

    Fifth, build the adverse-outcome workflow. Decide who sends the explanation, where the decision record lives, how correction requests are handled, and who performs reconsideration.

    Finally, test the human-review process with a real example. A written promise of review is not enough if the reviewer cannot understand the system's contribution or change the outcome.

    Bottom Line

    Colorado's replacement law is less focused on enterprise-wide AI governance and more focused on what happens around an individual decision.

    The central compliance questions are concrete. Was the technology covered? Did it materially influence the outcome? Was the person notified? Can the company explain what happened? Can inaccurate data be corrected? Can a human reviewer reconsider the decision?

    SB 26-189 removed some of the most demanding parts of Colorado's original AI Act. It replaced them with obligations that depend on reliable decision records and working review procedures.

    Companies have until January 1, 2027 to build those procedures. The systems, contracts, and records needed to make them work should be addressed well before then.

    Sources and Related Clearon Coverage

  • DOJ and xAI Turn Colorado’s AI Law Into a Federal Constitutional Fight

    DOJ and xAI Turn Colorado’s AI Law Into a Federal Constitutional Fight

    Colorado’s AI law is no longer only a compliance project.

    It is also becoming one of the first serious constitutional test cases for a state AI statute.

    xAI sued Colorado over the state’s algorithmic-discrimination framework. Then the U.S. Department of Justice intervened on xAI’s side. Meanwhile, the Colorado Attorney General opened pre-rulemaking on the state’s revised ADMT law and related chatbot legislation.

    That combination matters because it puts three different pressures on the same legal framework at once:

    • compliance design,
    • rulemaking detail, and
    • constitutional attack.

    For companies that may be covered by Colorado’s law, the practical problem is not just what the statute says on paper. It is what survives litigation, what gets clarified in rulemaking, and what obligations companies may need to build toward while the fight is still unresolved.

    The Short Answer

    • xAI’s case is a constitutional challenge to Colorado’s algorithmic-discrimination framework, not a ruling that the law is invalid.
    • DOJ’s intervention matters because it turns the case from a private company challenge into a federal-backed attack on the state’s theory.
    • The case is procedurally important even before a merits ruling because enforcement was stayed pending the forthcoming preliminary-injunction sequence tied to final rulemaking.

    What xAI Is Challenging

    The Clearinghouse summary describes the case as a challenge to Colorado’s law regulating high-risk AI systems and requiring reasonable care to prevent so-called algorithmic discrimination against protected groups.

    According to the Clearinghouse summary, xAI filed suit in April 2026 and asserted multiple constitutional claims, including theories under the First Amendment, Commerce Clause, Due Process Clause, and Equal Protection Clause.

    The core political and legal complaint is familiar by now. xAI argues that Colorado’s framework does not simply prohibit unlawful discrimination. It pressures AI developers and deployers to adjust systems around demographic outcomes and, in xAI’s view, embeds a race-conscious and ideologically loaded compliance model.

    That does not mean xAI is right on the merits. It does mean the fight is not a narrow technical dispute about one reporting field or one definition.

    It is a broad challenge to whether a state can regulate algorithmic discrimination in a way that requires ongoing risk monitoring, compliance controls, and corrective action without crossing constitutional lines.

    Why DOJ’s Intervention Matters

    The DOJ press release is the signal that makes this more than an ordinary private challenge.

    DOJ said it intervened in xAI’s lawsuit challenging Colorado’s algorithmic-discrimination requirements. The department’s position, as described in its announcement, is that the law violates the Equal Protection Clause by requiring companies to prevent unintentional disparate impact based on protected characteristics while exempting some discrimination aimed at increasing diversity or redressing historical discrimination.

    That is not a final court holding. It is DOJ’s theory.

    But DOJ participation changes the weight of the case in two ways.

    First, it increases the chance that the litigation will be treated as a national policy fight, not just a Colorado-specific dispute.

    Second, it gives other states and regulated companies a clearer preview of the arguments likely to be made against future state AI discrimination statutes.

    If a state wants to regulate discriminatory AI outcomes, this is the line of attack it should now expect:

    • the law is too vague,
    • the law pressures companies into demographic calibration,
    • the law burdens speech or model design,
    • the law disrupts interstate commerce, or
    • the law uses protected-characteristic logic in a way that creates its own constitutional problem.

    Even if some of those theories fail, they are now part of the real operating environment for state AI law.

    The Stay Matters More Than It Sounds

    One of the most practical parts of the case is procedural.

    The Clearinghouse docket summary and docket entries show that the court granted a joint motion staying enforcement by the Colorado Attorney General for alleged violations of SB24-205, or any replacing or amending legislation from that session, occurring on or before 14 days after a ruling on xAI’s forthcoming preliminary-injunction motion.

    The same order tied xAI’s preliminary-injunction motion deadline to the final adoption of implementing rulemaking.

    That is a big deal.

    It means the rulemaking is not happening off to the side while litigation proceeds independently. The final implementing rules are part of the path toward the preliminary-injunction fight.

    So the rulemaking record may influence:

    • how burdensome the law appears,
    • how concrete or vague the obligations look,
    • whether the court sees the law as manageable or indeterminate, and
    • how sharply the constitutional arguments land.

    That is why companies should not assume the stay makes Colorado irrelevant for now. It may make the current rulemaking stage even more important.

    This Is Bigger Than One Colorado Statute

    The broader significance is not just Colorado.

    State lawmakers, attorneys general, and privacy or civil-rights regulators have been experimenting with different ways to govern AI discrimination, consequential decision systems, explainability, review rights, and chatbot safeguards.

    Colorado is one of the first places where those ideas are being tested all at once:

    • a live statute,
    • live pre-rulemaking,
    • a live constitutional challenge, and
    • direct federal intervention.

    That makes the case useful even for companies outside Colorado.

    If a court eventually narrows or blocks core parts of the Colorado regime, other states may rewrite future AI laws differently. If Colorado survives the attack, that may embolden other states to move faster with similar frameworks.

    Either way, the litigation is helping define the limits of state AI governance.

    What Companies Should Do Now

    Companies should avoid two bad instincts.

    The first is panic. There is no merits ruling yet, and the current fight does not mean every algorithmic-discrimination law will collapse.

    The second is complacency. The stay does not mean the underlying compliance and governance questions disappeared.

    A useful response now includes:

    • mapping which systems may materially influence consequential decisions;
    • separating developer and deployer roles across the AI supply chain;
    • tracking Colorado’s final rulemaking closely;
    • reviewing whether current governance depends on outcome monitoring tied to protected characteristics;
    • pressure-testing documentation, notice, review, and adverse-outcome workflows; and
    • watching how constitutional objections may affect future state-law design in other jurisdictions.

    For companies likely to operate under more than one emerging state AI framework, the real question is no longer just "what does Colorado require?"

    It is also "which parts of this model are likely to survive?"

    Bottom Line

    DOJ and xAI are turning Colorado’s AI law into an early constitutional test case for state AI governance.

    The result is not in yet. But the structure of the dispute is already clear.

    Colorado is trying to operationalize AI discrimination rules through legislation and rulemaking. xAI is trying to stop that framework on constitutional grounds. DOJ is now backing part of that attack. And the court has linked the enforcement and preliminary-injunction timeline to final rulemaking.

    That makes Colorado one of the most important places to watch if you want to understand what state AI law may look like after the first serious round of litigation.

    Sources

  • What Companies Should Do When AI Rules Are Fragmented Across States, Agencies, and Courts

    What Companies Should Do When AI Rules Are Fragmented Across States, Agencies, and Courts

    A lot of companies are still waiting for AI law to become neat.

    They want one federal statute, one regulatory framework, one court doctrine, and one checklist that settles the problem.

    That is not the environment they have.

    The real operating environment is fragmented across states, agencies, courts, sector rules, contract demands, and product-specific risk.

    That fragmentation is frustrating. It is also manageable if companies stop treating AI compliance as a search for one master rule and start treating it as a workflow problem.

    The Short Answer

    • AI law is fragmenting across multiple legal systems at once: state consumer-protection law, federal agency action, court decisions, sector-specific rules, and non-U.S. frameworks.
    • Companies that wait for one unified AI rulebook may fall behind the actual risk.
    • The practical response is not to memorize every rule. It is to build a repeatable intake, classification, review, documentation, and escalation process that can absorb changing legal inputs.

    The Real Problem Is Not Just Volume

    Most companies describe the issue as too many AI rules.

    That is true, but incomplete.

    The harder problem is that the rules are coming from different places and asking different kinds of questions.

    One state may focus on automated decision-making and bias risk.

    Another may focus on chatbot safety, youth access, or emotionally manipulative design.

    The FTC may focus on deception, hidden model steering, or unsupported accuracy claims.

    State attorneys general may focus on product design, vulnerable users, and public-facing marketing.

    Courts may focus on sanctions, privilege, work product, or protective-order restrictions.

    The EU may focus on transparency, labeling, governance, and deployer obligations.

    Patent offices may focus on inventorship and filing practices.

    This is not one compliance lane. It is a stack of overlapping ones.

    The Wrong Response Is To Build A Law List Without A Workflow

    A lot of organizations react by creating a giant AI law tracker and then stopping there.

    Tracking is necessary. It is not enough.

    A list of developments does not tell the company:

    • which products are in scope;
    • which claims matter most;
    • which teams own the response;
    • when an issue should escalate to legal;
    • what documentation should be preserved;
    • how vendor risk connects to product risk; or
    • what happens when two legal signals point in different directions.

    That is why companies with impressive issue tracking can still be weak operationally.

    They know what changed. They do not have a consistent way to act on it.

    Fragmentation Usually Shows Up In Five Operational Problems

    1. No Clear AI Intake Function

    Many organizations still do not have one reliable way for teams to flag:

    • a new AI product feature;
    • a vendor purchase;
    • a model change;
    • a high-risk use case;
    • a public marketing claim;
    • or a new jurisdictional issue.

    Without intake, the company never gets a clean first look at what needs review.

    2. No Risk Tiering

    Not every AI use case needs the same level of scrutiny.

    An internal summarization tool is not the same as a public-facing chatbot for teenagers. A marketing-assist tool is not the same as an automated HR workflow. A contract-analysis system is not the same as a medical advice assistant.

    If the company does not tier AI uses by risk, it will either over-review low-risk tools or under-review the ones that matter most.

    3. No Cross-Functional Owner

    Fragmented law creates fragmented internal ownership unless someone is responsible for pulling the pieces together.

    Legal may track statutes. Privacy may track data use. Security may track model exposure. Product may control deployment. Marketing may control claims. Procurement may control vendor intake.

    That structure is normal. It still needs a coordination point.

    Otherwise the legal risk lives in the gaps between teams.

    4. Weak Documentation

    Fragmented law increases the need for records because the company may later need to explain:

    • why a system was classified one way instead of another;
    • why a disclosure was used;
    • why a vendor was approved;
    • why a feature launched despite known limitations; or
    • why one jurisdictional rule was treated as controlling.

    If those judgments are not documented, later review becomes much harder.

    5. Overreliance On Vendor Assurances

    Many AI compliance gaps start with vendor language.

    A vendor says its product is compliant, enterprise safe, explainable, unbiased, privacy preserving, or ready for regulated use. The buyer takes that statement at face value because the vendor sounds sophisticated and the market is moving fast.

    That is dangerous in a fragmented legal environment because the buyer may still bear downstream risk even when the vendor caused the original representation problem.

    The Better Approach Is A Governance Workflow

    Companies do not need a perfect unified AI law map before they can act.

    They need a usable governance workflow.

    That workflow should do at least six things.

    1. Create One AI Intake Path

    There should be one standard route for teams to raise:

    • new AI features;
    • material model changes;
    • new vendors;
    • sensitive use cases;
    • customer requests involving AI claims or commitments; and
    • incidents or complaints tied to AI outputs.

    The key is consistency, not bureaucracy.

    2. Classify The Use Case

    Every material AI use should be classified by factors such as:

    • internal or external use;
    • consumer-facing or enterprise-facing;
    • use by minors or vulnerable users;
    • impact on employment, health, finance, education, housing, or legal rights;
    • use of sensitive data;
    • degree of autonomy;
    • marketing sensitivity; and
    • jurisdictional footprint.

    This helps decide which legal lanes matter most.

    3. Tie Review To Risk, Not Buzzwords

    Legal review should not be triggered only because something is labeled AI.

    It should be triggered by what the system actually does, what data it touches, what claims are being made, and what decisions may flow from it.

    That keeps the review grounded in real exposure instead of branding alone.

    4. Preserve The Decision Record

    For material deployments, companies should preserve:

    • what the tool or feature was meant to do;
    • what risks were identified;
    • what testing occurred;
    • what mitigations were added;
    • what claims were approved;
    • which jurisdictions or legal frameworks were considered; and
    • who approved the decision.

    That record becomes valuable fast if the system is later challenged.

    5. Review Public And Customer-Facing Claims Separately

    A lot of AI risk is created not by the technical system itself but by the way the system is described.

    Claims about safety, objectivity, transparency, compliance, age appropriateness, human oversight, and accuracy should get their own pass, not just a product review pass.

    6. Build An Escalation Rule

    Some AI issues should escalate automatically.

    For example:

    • systems affecting minors or vulnerable users;
    • high-impact decision systems;
    • products using sensitive personal data;
    • systems marketed as safe, objective, or compliant;
    • incidents involving self-harm, dangerous instructions, or severe output failure;
    • and any state, agency, or court demand tied to AI conduct.

    Companies do not need to improvise those escalation rules in the middle of a problem.

    What Companies Should Do Now

    If the company is already feeling the fragmentation problem, the most useful next steps are practical:

    • create one intake form or intake workflow for material AI uses and changes;
    • define a small number of AI risk tiers instead of trying to classify everything from scratch each time;
    • assign one cross-functional owner or review group for material AI decisions;
    • inventory current public claims about AI safety, accuracy, oversight, and compliance;
    • map which jurisdictions and agency frameworks matter most for the company's actual products;
    • review vendor AI questionnaires and procurement language for overpromising;
    • create an escalation trigger list for high-risk AI incidents and launches; and
    • make sure review decisions are being saved somewhere retrievable.

    This will not eliminate legal fragmentation.

    It will make the company much better at operating inside it.

    Bottom Line

    AI rules are fragmented across states, agencies, courts, sectors, and jurisdictions. That is not a temporary drafting glitch. It is the real operating environment right now.

    The companies that handle it best will not be the ones waiting for a clean universal AI rulebook.

    They will be the ones that build a workable compliance process around intake, classification, review, documentation, and escalation.

    Fragmented law is annoying. Fragmented internal workflow is what turns it into a real problem.

    Sources

  • UK Clinical AI Liability Still Starts With The Clinician

    UK Clinical AI Liability Still Starts With The Clinician

    The UK government has not said existing law is broken for clinical AI. It has said something more careful, and more useful for risk planning: existing legal and regulatory frameworks provide a basis for allocating responsibility, but clinicians remain responsible for patient-care decisions when they use AI tools.

    That answer came in response to a written parliamentary question about whether existing liability and regulatory frameworks adequately allocate responsibility for harm arising from AI tools in NHS clinical decision-making.

    The Department of Health and Social Care pointed to clinical negligence law, professional standards, product-liability regimes, and oversight by regulators including the MHRA, the Care Quality Commission, the Information Commissioner's Office, and NICE. It also said that responsibility for patient-care decisions remains with clinicians, who must exercise professional judgment when using AI tools.

    That is not the final answer to the AI liability problem. The Department also acknowledged that AI introduces novel questions about how responsibility should be distributed among manufacturers, software licensors, and users. It said NHS Resolution has been commissioned to assess how existing liability frameworks apply to AI use cases and provide greater clarity.

    For now, the practical message is direct: clinical AI may involve many actors, but a clinician using the tool is not relieved of judgment.

    The Government's Current Position

    The parliamentary answer does three things at once.

    First, it resists the idea that there is currently a liability vacuum. The Department says existing frameworks provide a strong basis for allocating responsibility for potential harms.

    Second, it keeps clinicians in the center of the decision-making chain. AI may assist with diagnosis, triage, prioritization, imaging, documentation, or treatment recommendations. But when it is used in clinical decision-making, the clinician remains responsible for exercising professional judgment.

    Third, it leaves room for future clarification. The answer recognizes that clinical AI may involve multiple parties, including manufacturers, software licensors, providers, and users. In the event of an incident, responsibility may be apportioned according to the circumstances.

    That is a familiar posture in emerging technology. The government is not freezing adoption while a perfect liability model is designed. It is relying on existing frameworks while commissioning work to clarify how they apply.

    The MHRA Commission Is Looking At The Same Problem

    The MHRA's National Commission into the Regulation of AI in Healthcare is examining whether the UK's framework for regulating AI in healthcare is sufficient and how it may need to improve.

    The Commission's call for evidence asked about safe access to AI medical devices, post-market safety checks, and how responsibility and liability should be managed between the different parties involved in deploying AI medical devices.

    The call-for-evidence page was updated on June 11, 2026, to say findings and a wider research-and-engagement report had been published. The Commission's recommendations are expected in 2026.

    That matters because clinical AI liability is not only a courtroom issue. It is a product-governance issue, a medical-device regulation issue, a clinical oversight issue, and a procurement issue.

    Medical Protection Warns Of A Liability Gap

    Medical Protection has taken a sharper view. It warned that a widening gap between AI use and liability law could leave the NHS and clinicians exposed to claims.

    Its concern is that AI systems are not clearly defined as products under the existing product-liability framework. If a patient is harmed after a clinician relies on an AI system that suggested a diagnosis or treatment plan, Medical Protection says the default path may be a clinical negligence claim against the end user rather than a product-liability claim against the developer, manufacturer, or supplier.

    Medical Protection has called for legislation clearly classifying AI systems as products, arguing that responsibility for defective systems should be distributed more fairly.

    That is not a binding legal rule. It is a stakeholder position. But it identifies the risk healthcare organizations already need to manage: if responsibility is unclear, claims may follow the party closest to the patient.

    What Health AI Companies Should Hear

    For AI developers and suppliers, the lesson is not that liability can be pushed downstream forever.

    Procurement teams, regulators, insurers, and courts will ask how the product was validated, what the tool was intended to do, what warnings were given, how performance was monitored, how updates were controlled, and how foreseeable misuse was addressed.

    Contracts may allocate risk between supplier and customer, but they will not necessarily answer patient-facing questions after an incident. Product documentation, post-market monitoring, audit trails, incident-response procedures, and human-factors design will matter.

    If a supplier wants clinicians to trust a tool, the supplier should be able to explain what the tool is for, what it is not for, when a human must override it, and how errors will be detected.

    What Clinical Governance Teams Should Do Now

    Healthcare organizations should assume that AI use will be judged through existing duties unless and until a more specific framework changes the answer.

    That means clinical governance should address:

    • intended use and limits of each AI tool;
    • whether the tool is regulated as a medical device;
    • clinician training and supervision;
    • how recommendations are documented in the patient record;
    • when clinicians must independently verify or override AI output;
    • incident reporting and escalation;
    • supplier obligations for monitoring, updates, security, and performance drift;
    • patient communication where AI materially affects care; and
    • insurance and indemnity allocation for AI-related incidents.

    The key is to avoid treating AI as either an autonomous decision-maker or a harmless administrative aid. Clinical AI may sit somewhere between those poles, and governance should match the actual use case.

    Bottom Line

    The UK's clinical AI liability position is still developing, but the current operating rule is clear enough: clinicians remain responsible for patient-care decisions when using AI tools.

    That does not mean developers, licensors, providers, and healthcare organizations avoid responsibility. It means the liability analysis will likely be shared, fact-specific, and built from existing frameworks unless reform changes the allocation.

    For now, health AI governance should be designed for that world: human clinical judgment at the point of care, supplier accountability upstream, and enough documentation to explain both if something goes wrong.

    Sources

  • Colorado’s AI Law Is Now a Rulemaking and a Court Fight

    Colorado’s AI Law Is Now a Rulemaking and a Court Fight

    Colorado's AI law is no longer just a statute on a compliance calendar. It is now moving on three tracks at once.

    The state has enacted a revised automated decision-making law. It has enacted a separate chatbot safety law. And the Colorado Attorney General has opened pre-rulemaking for both, with informal public input due July 13, 2026.

    At the same time, xAI is challenging Colorado's AI framework in federal court, and the U.S. Department of Justice has intervened against the state law. That means Colorado is becoming the first major test of what happens when state AI governance, federal constitutional objections, and practical compliance rulemaking all collide before the operative date.

    For companies, the practical point is simple: the January 1, 2027 compliance date still matters, but the rules that will define the day-to-day obligations are being shaped now.

    What Colorado Is Rulemaking

    The Colorado Attorney General's office is seeking input on rules under two laws:

    • Senate Bill 26-189, the Automated Decision-Making Technology Act.
    • House Bill 26-1263, the Chatbot Safety Act.

    SB26-189 repeals and reenacts Colorado's earlier AI framework with new requirements for automated decision-making technology used to materially influence consequential decisions. The statute defines automated decision-making technology, or ADMT, as technology that processes personal data and uses computation to generate outputs such as predictions, recommendations, classifications, rankings, scores, or other information used to make, guide, or assist a decision about an individual.

    The covered decision domains include education, employment, housing, financial or lending services, insurance, health-care services, and essential government services and public benefits.

    Starting January 1, 2027, developers of covered ADMT must provide deployers with technical documentation about intended uses, training-data categories, known limitations, and instructions for appropriate use and human review. Developers and deployers must also retain records needed to demonstrate compliance for at least three years.

    Deployers will have consumer-facing obligations too. They must provide notice at the point of interaction with covered ADMT. If a covered ADMT materially influences a consequential decision that results in an adverse outcome, the deployer must provide a plain-language post-adverse-outcome explanation within 30 days. Consumers also receive rights to request personal data, correct factually incorrect personal data used by the covered ADMT, and request meaningful human review and reconsideration.

    The Attorney General must adopt rules by January 1, 2027 to clarify post-adverse-outcome disclosures and meaningful human review. The statute also gives the Attorney General broader discretionary rulemaking authority, including the ability to clarify "materially influence."

    That phrase is likely to become one of the central compliance questions. The pre-rulemaking paper specifically asks for objective indicators that could distinguish material influence from de minimis or otherwise non-material use.

    The Chatbot Law Is Broader Than Disclosure

    HB26-1263 addresses publicly available conversational AI services that simulate human conversation through text, visual, or audio communications.

    Beginning January 1, 2027, operators must disclose that users are interacting with AI. They must use commercially reasonable or generally accepted methods to estimate user age. If an operator knows that a user or account holder is a minor, the law imposes additional duties, including restrictions on engagement incentives, safeguards against sexually explicit content and simulated emotional dependence, suicide and self-harm response protocols, privacy and account-setting tools, and annual reporting to the Attorney General.

    The law also prohibits operators from representing chatbot outputs as equivalent to services provided by specified licensed or certified professionals.

    The Chatbot Safety Act does not itself require rulemaking in the same way the ADMT Act does. But the Attorney General says rulemaking would help clarify compliance obligations, including the annual reporting requirement and any additional metrics necessary to assess safeguards and response protocols.

    That makes the rulemaking important for more than high-risk decision systems. Any company operating a public-facing conversational AI service with Colorado users should be watching the chatbot questions too.

    The Attorney General's Five Principles

    The pre-rulemaking paper says the Department of Law will use five principles:

    • Promote consumer rights.
    • Clarify ambiguities.
    • Facilitate efficient and expeditious compliance.
    • Harmonize with other state, national, and international frameworks.
    • Allow for innovation.

    That list matters because Colorado is trying to solve two problems at once. It wants enforceable consumer protections, but it also knows vague rules can make implementation harder and litigation more likely.

    The most important open questions include:

    • When does an ADMT "materially influence" a consequential decision?
    • What tools qualify as ADMT, and what tools merely summarize, organize, or present information?
    • How should the rules distinguish developers, deployers, and other participants in an AI supply chain?
    • What should post-adverse-outcome disclosures include in different sectors?
    • What does meaningful human review require in practice?
    • What metrics should chatbot operators report to the Attorney General?
    • How should Colorado's rules interoperate with other state, federal, and international AI, privacy, discrimination, and consumer-protection frameworks?

    Those are not abstract questions. They will determine whether the Colorado framework becomes a manageable compliance regime or a source of recurring uncertainty.

    The Litigation Shadow

    The rulemaking is happening while Colorado's AI law is under active federal challenge.

    xAI sued Colorado Attorney General Phil Weiser in April 2026, challenging the state's algorithmic-discrimination framework. DOJ later moved to intervene, arguing that the Colorado law violates the Equal Protection Clause by requiring AI companies to prevent unintentional disparate impact based on protected characteristics while exempting some discrimination designed to advance diversity or redress historic discrimination.

    The DOJ intervention is significant even apart from the merits. It shows federal willingness to participate directly in litigation over state AI laws, especially where the federal government views state requirements as conflicting with national AI policy, constitutional limits, or innovation priorities.

    Separately, the docket reflects a procedural stay of Colorado Attorney General enforcement pending the preliminary-injunction sequence. That does not resolve the merits. It also does not make the rulemaking irrelevant. To the contrary, the preliminary-injunction schedule appears tied to final implementing rules, which makes the rulemaking record part of the litigation landscape.

    For covered companies, the wrong lesson would be to assume the lawsuit eliminates the need to prepare. The better reading is that the rulemaking record may define the obligations, the compliance burden, and the constitutional stakes.

    What Companies Should Do Now

    Companies do not need to wait for final regulations to start the useful work.

    First, inventory systems that may materially influence decisions about education, employment, housing, lending, insurance, health care, or government benefits. The key question is not whether a system is branded as AI. It is whether computation using personal data produces an output used to make, guide, or assist a decision about an individual.

    Second, map the supply chain. Colorado separates developer and deployer obligations, but many commercial arrangements are messier than that. Vendors, customers, integrators, model providers, and internal teams may all contribute to the final decision process.

    Third, test existing documentation against Colorado's likely documentation topics: intended uses, training-data categories, known limitations, appropriate use, human review, material updates, and compliance records.

    Fourth, design adverse-outcome workflows before the final rule lands. A deployer that cannot explain the role of ADMT in a specific adverse decision will struggle to meet a 30-day disclosure requirement.

    Fifth, review chatbot operations for minor-facing risk. Age estimation, recurring AI disclosure, self-harm escalation, emotional-dependence safeguards, privacy tools, and professional-services disclaimers are design and governance issues, not just legal copy.

    Finally, consider commenting before July 13. The Attorney General is asking for concrete feedback on ambiguity, unintended consequences, compliance burdens, sector-specific examples, and interoperability. Companies that wait for formal draft rules may miss the best chance to shape the starting point.

    Bottom Line

    Colorado is becoming an early operational test for state AI governance.

    The state is trying to turn broad statutes into working rules. The federal government is challenging parts of the framework. Companies are trying to build notices, documentation, review rights, and chatbot safeguards before January 2027.

    That makes the current pre-rulemaking window more than a routine comment period. It is an early chance to shape what compliance may look like when consequential-decision systems and conversational AI services are regulated in practice.

    Sources

    Sources

  • Trump’s New AI Executive Order Turns Frontier Models Into a Cybersecurity Priority

    Trump’s New AI Executive Order Turns Frontier Models Into a Cybersecurity Priority

    President Donald Trump signed a new artificial intelligence executive order on June 2, 2026, and the center of gravity is clear: cybersecurity, critical infrastructure, and the most capable frontier models.

    The order, titled "Promoting Advanced Artificial Intelligence Innovation and Security," does not create a broad AI licensing regime. It expressly says it should not be read to authorize mandatory preclearance, licensing, or permitting for the release of new AI models. But it still gives the federal government a more formal role near the front end of model release: identifying high-capability frontier models and arranging early, secure access before those models are shared more widely with trusted partners.

    This is not a general-purpose AI rulebook. It is a national-security and cybersecurity order. Advanced AI is treated as both a defensive asset and a possible accelerant for cyber risk.

    What the Order Does

    Four pieces do most of the work.

    First, it directs federal cybersecurity leaders to prioritize AI-enabled cyber defense across national security systems, Department of War systems, and civilian federal government systems. Within 30 days, CISA, in consultation with OMB and other White House cyber and national-security officials, is directed to issue binding operational directives and other guidance where appropriate.

    Second, it creates an AI cybersecurity clearinghouse. Treasury, the Department of War through NSA, DHS through CISA, and the National Cyber Director are directed to form a voluntary clearinghouse with AI companies and critical-infrastructure operators. The goal is to coordinate vulnerability scanning, validation, remediation, and patch distribution.

    Third, it directs federal officials to develop a classified benchmarking process for advanced cyber capabilities in AI models. That process will help determine when an AI model should be treated as a "covered frontier model" under the order.

    Fourth, it calls for a voluntary framework under which AI developers can work with the federal government to determine whether models under development meet the covered-frontier-model threshold. Developers may then give the government secure access to covered models, with confidentiality, cybersecurity, insider-risk, intellectual-property, and nondisclosure protections, for up to 30 days before release to other trusted partners.

    That is the legal story for AI companies. The order does not say, "submit your model for approval." It says the federal government wants a structured way to spot advanced cyber capability, review certain models before broader trusted-partner release, and coordinate deployment where national cybersecurity interests are implicated.

    Why It Matters

    The order keeps the administration's pro-innovation posture, but it also shows where federal oversight is likely to harden first. Not around generalized consumer AI rules, at least not here. Around cybersecurity, national security, critical infrastructure, and model capability thresholds.

    That should get the attention of several groups.

    AI developers will need to assess whether their model-development processes can support secure government engagement without compromising trade secrets, release timelines, or customer commitments. Even a voluntary framework can become practically significant when major labs, cloud platforms, federal contractors, or critical-infrastructure vendors are involved.

    Federal contractors and regulated entities should watch the CISA and OMB guidance that follows. The order directs action on federal systems, but it also points to access for state and local authorities and operators of critical infrastructure, including rural hospitals, community banks, and local utilities. That suggests downstream cybersecurity expectations may reach beyond Washington.

    Legal and compliance teams should also pay attention to the documentation burden. If a model could plausibly fall within a classified benchmarking process, companies will want a defensible internal record of model capabilities, cyber-risk testing, access controls, deployment plans, and third-party release decisions.

    The Frontier-Model Piece

    "Covered frontier model" may be the most consequential phrase in the order.

    The order directs federal officials to build a classified benchmarking process to assess advanced cyber capabilities and identify the threshold for that designation. The designation decision is assigned to NSA leadership in consultation with the National Cyber Director, the Assistant to the President for Science and Technology, CISA, and Department of War representatives.

    That approach keeps the most sensitive capability assessment out of public view. It also means companies may never get a clean public checklist for what makes a model covered. They may instead be dealing with a government-facing process built around classified benchmarks, agency judgment, and secure communications with federal officials.

    From a legal-risk perspective, this creates several practical questions:

    • How will a company determine whether to initiate voluntary engagement?
    • What internal evidence should support the company's view that a model is or is not likely to meet the threshold?
    • How will pre-release access be governed contractually?
    • How will intellectual property, model weights, system prompts, evaluations, logs, and vulnerability findings be protected?
    • What happens if a company disagrees with the government's assessment?

    The order does not answer those questions. It starts the process that will create them.

    Not a Licensing Regime, But Not Nothing

    The anti-licensing language is not throwaway. It appears designed to reassure industry that the administration is not recreating a mandatory pre-release approval system for frontier AI.

    But legal teams should not mistake that reassurance for irrelevance. Voluntary frameworks can still shape market expectations, procurement preferences, liability arguments, insurance underwriting, and board-level risk controls. If the federal government creates a recognized process for secure early access and frontier-model cyber benchmarking, companies that ignore it may eventually have to explain why.

    That is especially true in sectors where AI models are deployed into cybersecurity products, vulnerability detection, incident response, financial services, health systems, utilities, or other sensitive environments.

    The Altman-Musk Divide

    The industry's early reaction shows why that anti-licensing language was probably necessary.

    OpenAI has publicly embraced the final order's basic structure. Sam Altman reportedly said the order "gets the balance right," and OpenAI's chief global affairs officer, Chris Lehane, framed the issue as one for democratic institutions, technical experts, and public stakeholders. That fits OpenAI's broader posture: accept government-informed safety testing and standards for high-capability systems, while resisting a regime that turns every major model release into a permission slip.

    Elon Musk and xAI appear to be in a different, more skeptical lane. Axios reported that Musk, along with Meta's Mark Zuckerberg and White House AI adviser David Sacks, spoke with President Trump before an earlier version of the order was delayed. The final version that emerged was narrower: voluntary rather than mandatory, built around a 30-day pre-release access window, and explicit that it does not authorize preclearance, licensing, or permitting for new AI models.

    That does not mean xAI is rejecting federal testing. In May, xAI, Google, and Microsoft agreed to give the federal AI Safety Institute, now CAISI, access to models for security testing before release. The better reading is narrower: xAI appears willing to participate in government model testing, while the Axios reporting suggests Musk was part of the industry pushback against a heavier pre-release review regime.

    For legal teams, that distinction is useful. The frontier labs are not simply dividing into "regulated" and "unregulated" camps. They are drawing boundaries around the legal character of the process: voluntary cooperation, safety benchmarking, and secure government access on one side; mandatory licensing, public approval gates, and open-ended release delays on the other.

    Enforcement Against AI-Enabled Cybercrime

    The order also directs the Attorney General to prioritize enforcement against people who use AI to unlawfully access or damage computer systems, steal data, or facilitate other crimes. It specifically references federal computer crime and fraud statutes, including 18 U.S.C. 1028, 1030, and 1343.

    That section is short, but it does some work. It frames AI-enabled cyber misuse as an enforcement priority rather than a wholly new legal category. The administration appears to be saying that existing criminal laws already reach many AI-assisted cyber offenses, and DOJ should treat AI use as a reason to prioritize those cases.

    Companies should read that as a controls issue. AI agents, autonomous scanning tools, security research workflows, and employee use of AI in technical environments all need clear authorization boundaries. A tool that accelerates defensive work can also create evidence problems if it is used the wrong way.

    What To Watch Next

    The next 30 to 60 days will tell us more than the headline did.

    CISA guidance and any binding operational directives will show how federal agencies are expected to use AI-enabled cyber tools and whether contractors will see new expectations in security programs. Treasury, NSA, DHS, and the National Cyber Director's clearinghouse work will show how much private-sector coordination the government can realistically achieve. The classified benchmarking process will determine whether "covered frontier model" becomes a narrow national-security category or a broader marker for advanced AI cyber capability.

    The order is not a comprehensive AI law. It is not a privacy law, a copyright law, or a civil-liability framework. It does show where federal AI governance may harden first: cybersecurity.

    For AI companies and the organizations that rely on them, the practical takeaway is direct: model capability, cybersecurity readiness, release governance, and critical-infrastructure impact now belong in the same review process.

    Editorial Notes

    Suggested dek: The June 2 order does not create a mandatory AI licensing system, but it does create a federal path for frontier-model cyber benchmarking, secure early access, and AI-enabled cyber defense.

    Suggested social: The new AI executive order is not a broad licensing regime. It is something more targeted: a cybersecurity and national-security framework for frontier-model capability, pre-release access, and critical infrastructure defense.

    Related follow-ons:

    • What AI companies should document before engaging with the voluntary frontier-model framework.
    • Why CISA's next AI guidance may matter more than the executive order itself.
    • How AI-enabled cybercrime enforcement could affect companies using autonomous agents.

    Sources

  • The UK Is Moving Automated Decision-Making Away From the EU Model

    The UK Is Moving Automated Decision-Making Away From the EU Model

    The UK's recent data-law changes matter for AI governance because they suggest a real break from the EU approach to automated decision-making.

    If you want the official legislation, the UK law is here: Data (Use and Access) Act 2025.

    Under section 80 of the Data (Use and Access) Act, the UK has replaced the old Article 22 framework with a more permissive structure: automated decision-making with safeguards, rather than a prohibition-first starting point.

    This is a real shift

    Under the classic Article 22 model, the analysis usually began with a restriction. The UK's newer approach is more operational and less categorical. The question becomes less "is this forbidden unless an exception applies?" and more "what safeguards, transparency, and review rights are required when this happens?"

    That may sound subtle, but it matters. It gives companies more room to deploy automated systems, while also increasing pressure to justify how those systems are used.

    What multinational teams should watch

    A lot of organizations still hope they can run one clean global policy for AI-enabled decision-making. The UK’s move makes that harder. If the EU and UK keep drifting apart here, legal teams may need separate assessments for profiling, scoring, and model-driven recommendations that affect individuals.

    That does not just affect flashy AI products. It can reach ordinary systems used in employment, insurance, financial services, fraud detection, customer eligibility, and prioritization workflows.

    The takeaway

    The UK is not abandoning regulation. It is choosing a different posture. A permission-with-safeguards model still requires governance, and in some ways it requires better governance because companies have more room to act.

    Cross-border AI compliance is starting to look less like one policy problem and more like jurisdiction management. That is the part legal teams should plan around now.

  • Illinois Is Turning AI in Employment Into a Notice and Recordkeeping Problem

    Illinois Is Turning AI in Employment Into a Notice and Recordkeeping Problem

    Illinois is becoming one of the clearest examples of where employment AI regulation is heading: notice, documentation, and practical scrutiny of how tools influence decisions.

    If you want the official bill history, Illinois’s law is here: HB 3773. The Illinois Department of Human Rights also has a direct summary page here: Artificial Intelligence in Employment.

    Recent draft rules from the Illinois Department of Human Rights would implement the state's newer restrictions on AI discrimination in employment. The bigger point is the compliance model taking shape around them.

    The trigger looks broad

    The reported standard is not limited to futuristic hiring bots. The rules would apply when AI is used “to influence or facilitate” covered employment decisions, including recruiting, hiring, promotion, discipline, discharge, training selection, and terms or conditions of employment.

    That deserves attention because the notice trigger may be broader than many employers expect. If AI is involved in screening resumes, targeting job ads, evaluating candidates, analyzing interviews, or helping shape employment outcomes, notice may be required even if the employer did not intend discrimination.

    Employment AI is becoming an operations issue

    The trend line is clear: employment AI law is moving away from “prove the tool caused unlawful bias first” and toward “tell people when the tool is in the process, document what it is doing, and be ready to defend the workflow.”

    That is why legal teams need a real inventory of where AI shows up in the employment stack, not just in one recruiting product. AI can appear in sourcing, ranking, interview analytics, assessments, chatbots, promotion systems, and workforce-monitoring features.

    The takeaway

    The answer is not to ban every automated feature. It is to map the tools, define which ones influence covered decisions, and decide where notice, contract review, testing, and documentation are required.

    Illinois is sending a simple message: if AI helps shape employment outcomes, silence is not a compliance strategy.