Tag: AI Governance

  • Kohls v. Ellison Did Not End Minnesota’s Election AI Law Fight on the Merits

    Kohls v. Ellison Did Not End Minnesota’s Election AI Law Fight on the Merits

    Kohls v. Ellison Did Not End Minnesota's Election AI Law Fight on the Merits

    Minnesota is easy to misread if you look only at the result.

    The challengers in Kohls v. Ellison did not win preliminary relief against Minnesota's election deepfake statute. The Eighth Circuit affirmed the district court, and rehearing was later denied.

    That can sound like a clean appellate approval of the law. It was not.

    The more careful description is that the Eighth Circuit affirmed without resolving the underlying constitutional merits of the statute itself. That makes Minnesota an important but limited precedent in the growing fight over election-related AI laws.

    The statute sits in the same field, but the case is different

    The operative law is Minn. Stat. § 609.771, titled "Use of deep fake technology to influence an election."

    Minnesota therefore belongs in the same general field as California, Hawaii, New Mexico, Arizona, and other states regulating synthetic election media in some form. But its litigation story is procedurally different from the Babylon Bee cases.

    That difference is the whole point.

    What happened on appeal

    The Eighth Circuit appeal in No. 25-1300 came from the district court's denial of preliminary relief.

    The appellate docket shows that judgment was entered on February 9, 2026, affirming in accordance with the panel opinion. Later entries show that the appellants sought rehearing and rehearing en banc, and that both requests were denied on March 31, 2026.

    That gives Minnesota a firmer appellate procedural history than some other election-AI cases now cited around the country. But it does not mean the Eighth Circuit gave the statute a sweeping constitutional endorsement.

    Why the merits limitation matters

    The best way to describe Minnesota's significance is narrow.

    A lot of commentary collapses "the plaintiffs lost the injunction appeal" into "the law was upheld." Those are not always the same thing. A court can deny preliminary relief without giving the state a full merits victory on the substance of the First Amendment challenge.

    That is what makes Minnesota useful but incomplete as precedent.

    What Minnesota does tell other states

    Minnesota still carries real lessons.

    First, plaintiff-specific delay matters. The Eighth Circuit treated Mary Franson's insufficiently explained sixteen-month delay as fatal to the irreparable-harm showing required for preliminary relief.

    Second, standing still does real work in this area. The court held that Christopher Kohls had not established standing on the preliminary-injunction record, while Franson had standing to press her own challenge.

    Third, the absence of preliminary merits relief does not eliminate litigation risk for similar statutes elsewhere. It means only that the Minnesota challengers did not obtain the procedural posture they needed.

    Why Minnesota still matters for New Mexico and the Bee cases

    Minnesota is not a Babylon Bee case, and that distinction matters.

    The Bee cases put pressure on satire, parody, and compelled-warning issues in a specific way. Minnesota's appeal posture is most useful for a different lesson: a state can survive the preliminary-injunction stage without obtaining a full appellate ruling that its law is constitutional.

    So if the point is that challengers can lose early because one plaintiff lacked standing and another waited too long to show urgency, Minnesota helps. If the point is that an appellate court has already blessed the constitutional merits of a state election-AI law, Minnesota does not support that proposition.

    Bottom line

    Kohls v. Ellison did not end Minnesota's election-AI fight with a sweeping merits decision.

    What it shows instead is how much election-law procedure can shape outcomes. The Eighth Circuit affirmed the denial of preliminary relief, rehearing was denied, and the district case remained alive afterward.

    The cleaner takeaway is narrower but still important: Minnesota shows that a state can survive an early challenge without receiving a full appellate ruling on whether its election-AI law ultimately survives First Amendment scrutiny.

    This article summarizes a pending election-law challenge and related procedural rulings. It does not provide legal advice.

  • Babylon Bee v. Bonta Shows Why California’s Election AI Laws Cannot Be Treated as One Thing

    Babylon Bee v. Bonta Shows Why California’s Election AI Laws Cannot Be Treated as One Thing

    Babylon Bee v. Bonta Shows Why California's Election AI Laws Cannot Be Treated as One Thing

    California is still the most useful comparison state for the New Mexico Babylon Bee case. But it only helps if it is described carefully.

    Too much commentary treats California's election-AI fight as though one law did all the work. That is not the cleanest way to understand the dispute. California enacted two related 2024 measures, and they do not handle platform duties, satire, parody, and compelled treatment of election content in the same way.

    That distinction matters because Babylon Bee v. Bonta is not just a story about whether California may regulate deceptive election media. It is also a story about how statutory design changes the constitutional analysis.

    California enacted two different measures

    The relevant California measures are AB 2655 and AB 2839.

    AB 2655, chaptered as Chapter 261 on September 17, 2024, added Elections Code provisions beginning at Section 20510 under the "Defending Democracy from Deepfake Deception Act of 2024" and took effect on January 1, 2025.

    AB 2839, chaptered the same day as Chapter 262, added Elections Code Section 20012 and took effect immediately as an urgency measure. Its legislative topic line is "Elections: deceptive media in advertisements."

    That is the first point lawyers should keep straight. California did not enact one broad election-AI law. It enacted at least two separate measures in the same policy lane, with different structures and different constitutional pressure points.

    The litigation split mattered too

    The Bee plaintiffs sought immediate preliminary relief against AB 2839 in October 2024. California officials later agreed the statute could not be enforced against ADF's clients after the court in Kohls v. Bonta concluded it likely violated the First Amendment.

    The bigger district-court turning points came in August 2025, and they were not the same ruling.

    On August 20, 2025, the court entered final judgment and a permanent injunction as applied to X and Rumble as to AB 2655 on Section 230 preemption grounds. A later stipulation and order extended non-enforcement protection to other providers of interactive computer services, unless that judgment is vacated on appeal.

    On August 29, 2025, the court granted summary judgment and permanently enjoined enforcement of AB 2839 against the named plaintiffs on First Amendment grounds.

    That distinction matters because AB 2655 did not fall on a single broad holding that every part of it was unconstitutional. The platform-duty regime was treated as preempted by the Communications Decency Act, while the AB 2839 ruling squarely addressed the First Amendment.

    Why the statutory split matters

    California is a bad comparison state if it is used sloppily.

    AB 2655 is the platform-duty statute in the California pair, even though it also contains an express satire/parody exemption. AB 2839 is the more direct speaker-and-distributor statute, and its treatment of satire and parody still turns on disclosure mechanics.

    That difference matters because a court may respond differently to a large-platform removal and labeling regime than to a law that directly regulates political speakers and distributors.

    California's litigation value is not just that "California lost." Its value is that the case shows how much constitutional weight can turn on the exact way a legislature writes a synthetic-media rule.

    Why California still matters for New Mexico

    New Mexico's case is narrower than the full California fight, but California remains the nearest high-profile comparison.

    The Bee's New Mexico complaint is mainly aimed at the year-round advertisement-disclaimer regime in HB 182, not every part of the statute's separate ninety-day prohibition structure. That makes California especially relevant because California's dispute also placed heavy pressure on election-related speech rules touching political memes, parody, and compelled treatment of synthetic media.

    California therefore supplies at least three useful questions for New Mexico:

    1. How closely will a court read the exact statutory text instead of the state's general anti-deception rationale?
    2. Will the court treat satire and parody as clearly protected in practice, not just in theory?
    3. When a law forces labels, removals, or other compelled treatment of political content, how much tailoring is enough?

    What California does not prove

    California should not be overstated.

    The district-court result does not automatically decide what happens in New Mexico or elsewhere. California sits in the Ninth Circuit. New Mexico sits in the Tenth. The statutes are not identical, and neither is the procedural posture.

    California also does not prove that every election-related AI disclosure statute is unconstitutional. What it shows is narrower and more useful: courts can treat these laws as serious burdens when they impose platform duties, compelled labels, or other direct treatment of political satire and parody.

    Bottom line

    Babylon Bee v. Bonta matters because California's election-AI laws cannot be analyzed as one undifferentiated package.

    The state enacted AB 2655 and AB 2839 as separate measures. The litigation then turned California into the clearest live example of how statutory design, platform duties, satire treatment, and compelled-speech problems can collide in this area.

    For lawyers watching New Mexico and other state election-AI fights, California is still the comparison state that deserves the closest reading. It just should not be flattened into a one-law story.

    This article summarizes enacted California measures and related litigation materials. It does not provide legal advice.

  • Selected US State AI Election Law Comparison: A Working Memo on Enacted Laws, Disclaimers, Satire, and Litigation

    Selected US State AI Election Law Comparison: A Working Memo on Enacted Laws, Disclaimers, Satire, and Litigation

    Selected US State AI Election Law Comparison: A Working Memo on Enacted Laws, Disclaimers, Satire, and Litigation

    This is a selected-state comparison memo, not a final 50-state survey.

    As of June 23, 2026, the National Conference of State Legislatures said 31 states had enacted some form of election-related AI or synthetic-media law. That NCSL count is the baseline. This article reviews a smaller enacted subset closely enough to compare the main statutory models and the litigation issues now surfacing in the New Mexico, California, Hawaii, and Minnesota disputes.

    That distinction matters. The article is meant to clarify the main models in the field, not to claim that only a handful of states have acted.

    1. Start with enacted laws, not just litigated laws

    The enacted-law field is broader than the states already in court.

    From the materials verified for this memo, the enacted set clearly includes at least Alabama, Arizona, California, Colorado, Florida, Hawaii, Idaho, Indiana, Mississippi, New Mexico, New York, Oregon, Utah, and Wisconsin, alongside other states included in the NCSL total.

    That means New Mexico is not operating in a narrow outlier group. It is part of a substantial and still-growing state-law field.

    2. One common model is disclosure

    Under the disclosure model, a state permits election-related synthetic media at least in some circumstances but requires the speaker to add a warning or disclosure. The trigger often turns on timing, medium, or whether the content depicts a candidate or ballot issue.

    The directly verified examples reviewed for this memo include:

    • Colorado: candidate-election deepfake disclosures with enforcement and private-cause-of-action features.
    • Florida: disclaimers for certain political advertisements, electioneering communications, and related ads that use AI.
    • Indiana: disclaimer requirement when campaign communication includes fabricated media depicting a candidate.
    • New York: political communications using materially deceptive media must carry the statute's disclosure language.
    • Oregon: campaign communications using synthetic media must say the content has been manipulated.
    • Utah: synthetic audio and visual election communications must carry prescribed words.
    • Wisconsin: AI-generated audio or video political ads require disclosure.

    Some statutes sit near the line because they use prohibition language while also tying lawful distribution or exceptions from liability to disclosure mechanics. That overlap matters because it shows why simple labels can hide meaningful structural differences.

    3. Another model is prohibition plus disclosure or safe harbor

    A second model uses prohibition language aimed at deceptive or materially deceptive election media, often with a disclosure safe harbor or adjacent exception. These are not pure bans in the ordinary sense. They are hybrid statutes.

    The verified examples reviewed for this memo include:

    • Alabama: makes certain materially deceptive election communications criminal when distributed to influence an election, subject to statutory exceptions.
    • Arizona: bars deceptive synthetic media close to an election unless the required disclosure is included.
    • Hawaii: reaches reckless distribution of materially deceptive media in candidate elections, subject to listed exclusions and defenses.
    • New Mexico: uses a ninety-day rule tied to knowledge, intent to mislead voters, and likelihood of that result, with a disclaimer safe harbor.

    This is where precision matters for New Mexico. Section 1-19-26.8 is the ninety-day prohibition provision. The Bee's complaint, however, principally challenges the separate year-round advertisement-disclaimer provisions in Section 1-19-26.4.

    4. Satire and parody are the real fault line

    Satire and parody are the hardest comparison point because state laws handle them in very different ways.

    The safest framework is to separate three possibilities:

    • Express carveout: the statute excludes satire or parody from the operative restriction.
    • Conditional carveout: the statute mentions satire or parody but still conditions lawful use on a disclaimer or other required treatment.
    • No clear carveout: the statute does not clearly spare satire or parody, or the exception is too uncertain to summarize confidently from the available text.

    Arizona belongs in the express-carveout bucket. Colorado, New York, and Oregon also use express satire/parody exclusions in the enacted measures cited for this memo.

    California should not be treated as a single blended model. Enacted AB 2655 contains an express satire/parody exemption, while enacted AB 2839 uses a disclosure-conditioned exception that still ties lawful use to label mechanics.

    New Mexico fits the conditional-carveout bucket for purposes of the Bee's complaint because the Bee argues the statute does not truly exempt satire and parody from the challenged ad-disclaimer rule.

    Hawaii is different again. In The Babylon Bee v. Lopez, the district court concluded the law lacked an explicit or implicit satire/parody exception sufficient to save it.

    That is why Arizona, California, Hawaii, and New Mexico are useful comparison points. They do not use the same carveout model.

    5. The litigation cluster still centers on four states

    As of August 12, 2026, the clearest litigation cluster remains:

    • California: AB 2839 and related AB 2655 litigation, with district-court summary-judgment and permanent-injunction relief on key claims and an active Ninth Circuit appeal.
    • Hawaii: Act 191 / S 2687, where the district court entered a permanent injunction and the case later closed without an appeal after a fee settlement.
    • Minnesota: Minn. Stat. § 609.771, where the district court denied preliminary relief and the Eighth Circuit affirmed that denial without reaching the constitutional merits, relying on standing and delay.
    • New Mexico: HB 182, with the Bee's complaint filed on August 11, 2026.

    Litigation status is useful, but it is not a complete proxy for statutory strength. Some laws remain untested because no plaintiff has brought the right case yet.

    Working takeaways

    Several points are already clear.

    First, election-related AI laws are now common enough that New Mexico cannot be treated as a one-off.

    Second, the most important split is not disclosure versus prohibition in the abstract. Many states combine both techniques.

    Third, the key pressure point in the Bee cases is how a statute treats satire and parody. That is where Arizona, California, Hawaii, and New Mexico become especially useful comparison states.

    Fourth, New Mexico's lawsuit should be described carefully. The Bee is not challenging every moving part of HB 182. The complaint is aimed mainly at the year-round advertisement-disclaimer regime, while the statute separately contains a ninety-day prohibition rule.

    Bottom line

    New Mexico sits inside a larger and still-growing state-law field, even if this article only closely reviews a selected subset.

    The most useful comparison question for the current litigation is narrower than a full 50-state inventory. It is whether courts will treat required AI warnings on political satire as a permissible election safeguard or as an unconstitutional burden on protected speech.

    This article is a selected-state comparison memo based on enacted statutes and current litigation materials. It does not provide legal advice.

  • Babylon Bee’s New Mexico Lawsuit Tests the State’s AI Ad Disclaimer Rule

    Babylon Bee’s New Mexico Lawsuit Tests the State’s AI Ad Disclaimer Rule

    Babylon Bee's New Mexico Lawsuit Tests the State's AI Ad Disclaimer Rule

    The Babylon Bee has opened another front in the fight over state election-deepfake laws, this time in New Mexico.

    On August 11, 2026, the Bee sued members of the New Mexico State Ethics Commission in federal court. The case is The Babylon Bee, LLC v. Castillo, No. 1:26-cv-02628, in the District of New Mexico.

    The complaint does not attack every part of HB 182. Its main target is the law's year-round disclaimer regime for certain covered political advertisements. The Bee argues that those provisions force protected satire and parody to carry a government-prescribed AI warning.

    That framing matters because New Mexico's statute has more than one moving part, and the lawsuit is aimed chiefly at one of them.

    What New Mexico's law does

    New Mexico's 2024 HB 182 amended the Campaign Reporting Act in two different ways relevant here.

    First, Section 1-19-26.4 imposes disclaimer rules on certain election-related advertisements containing materially deceptive media. The required disclaimer format varies by image, video, audio, or mixed media.

    Second, Section 1-19-26.8 creates a separate ninety-day prohibition. It makes it unlawful to distribute materially deceptive media when the speaker knows the media falsely represents the depicted individual, distributes it within ninety days before an election, intends to alter voting behavior by misleading voters, and the distribution is reasonably likely to do so. That provision includes its own disclaimer safe harbor and criminal penalties for willful and knowing violations.

    Those sections are related, but they are not interchangeable. The Bee's complaint is principally aimed at the advertisement-disclaimer provisions, not the separate ninety-day prohibition.

    HB 182 defines "materially deceptive media" as image, video, or audio that depicts an individual engaged in speech or conduct in which the person did not engage, was publicly distributed without the depicted individual's consent, and was produced in whole or in part using artificial intelligence.

    Why the Bee says the law is unconstitutional

    The Bee does not frame the case as a defense of deceptive campaign tricks in general. The complaint alleges compelled speech, overbreadth, vagueness, and content-, viewpoint-, and speaker-based discrimination, both facially and as applied.

    The core theory is that satire, parody, cartoons, and memes often rely on exaggeration, inversion, and literal falsity to make a political point. The Bee says forcing a prescribed AI disclaimer onto that type of expression alters the message and undercuts the joke.

    The complaint also emphasizes that New Mexico did not exempt satire and parody from the challenged disclaimer requirement. It distinguishes between the statute's exclusion for news stories or editorials from the definition of "advertisement" and a separate safe harbor for broadcasters carrying covered material during bona fide news programming.

    Why California and Hawaii matter

    The New Mexico case fits a growing pattern of First Amendment challenges to state election-synthetic-media laws.

    In California, the Bee and related plaintiffs obtained district-court relief against AB 2839, the state's deceptive-media-in-advertisements law. That ruling is part of the larger Babylon Bee v. Bonta litigation, and the California appeal remains active in the Ninth Circuit.

    In Hawaii, the Bee won a permanent injunction against Act 191 in The Babylon Bee v. Lopez. The district court enjoined enforcement in January 2026, and the case later ended without an appeal after a fee settlement.

    Those rulings do not control a federal court in New Mexico. They do, however, show that courts have already treated some state election-synthetic-media laws as serious First Amendment problems when the rules reach political satire or impose broad compelled disclosures.

    Why this case matters beyond the Bee

    As of June 23, 2026, the National Conference of State Legislatures said 31 states had enacted some form of election-related AI or synthetic-media law. The policy trend is real.

    The harder question is how far states may go when regulating content that includes protected political expression, including parody, caricature, ridicule, and political memes.

    That is why the New Mexico case matters beyond one plaintiff. It puts pressure on a common legislative strategy: permit the speech but require a disclosure label when the content falls within the statute's definition of materially deceptive media.

    What to watch next

    Three issues are likely to matter most.

    First, how tightly the court defines the challenged provisions. The case may turn less on the broad idea of election deepfakes and more on whether New Mexico can apply its ad-disclaimer rule to satire and parody.

    Second, whether the state can meaningfully distinguish its statute from the California and Hawaii laws. The text differences matter, and so does the separation between New Mexico's ad-disclaimer regime and its ninety-day prohibition.

    Third, how the court treats the relationship between satire and deception. The Bee's position is that protected satire can depict events that did not happen while still conveying an obvious political message in context. New Mexico will likely argue that the statute targets voter deception, not humor as such.

    Bottom line

    This case chiefly concerns HB 182's advertisement-disclaimer regime, not every part of the law or its separate ninety-day prohibition.

    Its broader significance is where courts draw the constitutional line when election-AI disclosure rules reach protected satire and parody.

    This article summarizes a newly filed federal complaint and related constitutional issues. It does not provide legal advice.

  • Seventh Circuit Says Citation Verification Is Not Just the Filer’s Problem

    Seventh Circuit Says Citation Verification Is Not Just the Filer’s Problem

    Seventh Circuit Says Citation Verification Is Not Just the Filer's Problem

    The Seventh Circuit added an important wrinkle to the growing line of AI-citation cases. The filing lawyer still owns the duty to verify authorities and quotations. But the court also suggested that opposing counsel may face criticism for failing to identify serious citation defects and bring them to the court's attention.

    That is the practical lesson from Dec v. Mullin, a March 30, 2026 immigration decision. The underlying appeal was not about AI. The warning came from the briefing.

    Petitioner's counsel cited two nonexistent cases and included a false quotation in the standard-of-review section. At oral argument, counsel denied using AI. A later letter said she had presumably copied and pasted the language from another brief she could not locate and had failed to verify the citations.

    The Seventh Circuit admonished counsel but stopped short of stronger sanctions. The court emphasized that the errors appeared unintentional, counsel was contrite, and the fabricated authorities were used to support an undisputed legal standard rather than a contested merits issue.

    The more interesting point was about the other side

    The court repeated the familiar rule that trained lawyers must verify the citations and quotations in their own filings. But it then added that opposing counsel's failure to catch the defects and bring them to the court's attention also gave it pause, even if to a lesser degree.

    That is not the same thing as announcing a free-standing duty to audit every sentence in an adversary's brief. The panel did not create such a rule. Still, the signal is clear. When serious authority defects are discovered, courts may expect someone on the other side to raise the problem rather than let it slide.

    Why this matters

    Most sanctions coverage still focuses on the lawyer who filed the defective brief. That remains the main risk, and Dec does not change it.

    What the case adds is a response-side lesson. Citation verification is not just a filing control. It is also part of litigation hygiene once the defect is visible.

    If opposing counsel discovers a nonexistent case, a quotation that does not appear in the source, or a proposition that does not match the cited authority, waiting until oral argument or final disposition may not be the safest choice. The better course may be to raise it promptly through a procedurally appropriate channel.

    That framing fits the broader case pattern. In United States v. Farris, the Sixth Circuit focused on the filing lawyer's failure to verify quotations and case descriptions generated through Westlaw CoCounsel. In Lnu v. Blanche, the Ninth Circuit treated candor after discovery of the error as a major part of the discipline analysis. Dec does not conflict with those cases. It rounds them out.

    A better litigation response pattern

    Law firms do not need a broad new doctrine to act on this. They need a cleaner escalation rule.

    When an adversary filing appears to contain fabricated or materially inaccurate authority, teams should:

    • verify the cited source directly before making the accusation;
    • preserve the defective language and the source comparison;
    • decide quickly whether the issue should be raised through a letter, motion, meet-and-confer process, or the next scheduled hearing;
    • avoid overclaiming if the problem is sloppiness rather than fabrication; and
    • treat the issue as a filing-integrity problem, not a chance for rhetorical theater.

    Bottom line

    Dec v. Mullin does not create a formal duty to re-edit the other side's brief. It does something more practical. It suggests that when serious authority defects are discovered, courts may expect somebody on the other side to say so.

    The filing lawyer still has the primary burden. But the safest appellate posture now looks broader than that: verify your own filing, and if the other side's filing contains serious authority defects, do not assume the court will be impressed if nobody raises them.

    This article summarizes a published appellate decision and related litigation-risk implications. It does not provide legal advice.

  • The EU AI Act’s Enforcement Phase Is Here. What Can Your Company Prove?

    The EU AI Act’s Enforcement Phase Is Here. What Can Your Company Prove?

    The EU AI Act's Enforcement Phase Is Here. What Can Your Company Prove?

    August 2, 2026, was not the day the entire EU AI Act suddenly switched on. It was the day regulators began enforcing the provisions already in application, while Article 50's transparency duties took effect.

    That distinction matters because many internal summaries still collapse the timeline into a single compliance date. The real question is narrower and more useful: can the company identify the systems it provides or uses in the EU, assign the correct legal role, map the applicable duty, and produce evidence that the control actually works?

    August 2 was an enforcement milestone, not a universal deadline

    Regulation (EU) 2026/1744 reset the timetable for major high-risk obligations, but it did not postpone Article 50. Nor did August 2 place every AI Act issue in the AI Office's hands. Enforcement remains divided, with national authorities handling much of the current supervision and the AI Office holding direct powers in narrower areas such as general-purpose AI models.

    The timeline is easier to manage when separated into the parts that are already active and the parts that are still ahead:

    • February 2, 2025: Article 4's AI-literacy duty took effect.
    • August 2, 2026: Article 50 transparency duties took effect, and authorities began enforcing rules already in application.
    • December 2, 2026: the limited transition ends for certain pre-August-2 systems subject to Article 50(2)'s marking and detection duty.
    • December 2, 2027: the main Annex III high-risk requirements move into application under the amended schedule.
    • August 2, 2028: high-risk requirements for AI embedded in regulated products move into application.

    A company that says only that "the AI Act applies from August 2" is missing the structure regulators will expect it to understand.

    The first regulator-facing question is evidence

    The practical challenge is no longer whether the legal team can summarize the timetable. It is whether the business can produce system-level evidence on demand.

    For each material system or model, a company should be able to identify:

    • the system or model;
    • the legal entity responsible;
    • the company's role as provider, deployer, importer, distributor, or more than one;
    • when the system or model was placed on the EU market or put into service;
    • which provisions are currently applicable; and
    • the factual basis for any exclusion, exception, or transition period.

    A spreadsheet that labels something "out of scope" without an explanation is not an evidence file. It is a conclusion.

    Article 50 controls have to work in the real workflow

    Article 50 reaches visible behavior and published outputs. Depending on the system and the party's role, it may require notice of AI interaction, machine-readable marking of certain generated or manipulated content, notice for emotion-recognition or biometric-categorization exposure, deepfake labels, and disclosure of certain AI-generated or manipulated public-interest text.

    The compliance question is not whether those requirements appear in a memo. It is whether they appear where users actually encounter the system and whether they survive the real publishing or product workflow.

    Teams should be able to show the notice, label, or marking method; the system version it covers; the test results; any technical limits; and the owner of exceptions or edge cases. For deepfakes and public-interest text, they should also be able to show whether the label survives publication and redistribution.

    Article 4 needs more than a generic training slide deck

    Article 4 is easy to reduce to annual training. Its amended text points to something more context-specific.

    A marketing team using generative AI for copy, a recruiting team using AI in hiring, and a trust-and-safety team reviewing user content do not present the same literacy needs or the same risk. A regulator may want to know who was covered, what guidance they received, when it was updated, and what changed after incidents or audits.

    That means AI literacy needs its own record, not just a reference in a general compliance presentation.

    Enforcement authority is divided, and the file should reflect that

    National market surveillance authorities are the main enforcers of Articles 4 and 50. The European Data Protection Supervisor enforces Article 50 for AI systems used by EU institutions, bodies, and agencies. The AI Office's Article 50 role is narrower, while its powers over general-purpose AI models are more direct.

    One generic "EU regulator" folder is likely to create confusion. The stronger approach is to identify the likely authority for each product, model, or deployment and index the evidence file accordingly.

    The practical file companies should have now

    The most useful near-term deliverable is a compact enforcement file for each material system or model. It should contain:

    • the system and role classification;
    • the applicable-duty and transition-date analysis;
    • the named business, legal, and technical owners;
    • the control description and implementation evidence;
    • testing results, known limitations, and approved exceptions;
    • AI-literacy records relevant to the system;
    • vendor documents and contract rights relevant to the duty; and
    • a retrieval index showing where the current records live.

    The goal is not to predict the first headline enforcement action. It is to answer a focused regulatory question without opening an internal investigation just to locate the facts.

    Bottom line

    August 2 did not activate the entire AI Act. It moved the rules already in force into a more concrete enforcement phase.

    Companies should separate active duties from delayed high-risk requirements, map the correct authority, and test whether their evidence can be retrieved at the level of a specific system, model, version, and workflow.

    The best measure of readiness is not whether the company has an AI Act slide deck. It is whether it can prove what control applied to a specific system and whether that control actually worked.

    Sources and Related Clearon Coverage

    This article summarizes the current EU AI Act enforcement timeline and related transparency duties. It does not provide legal advice.

  • If AI Helps Build the Layoff List, Employers Need an Audit Trail

    If AI Helps Build the Layoff List, Employers Need an Audit Trail

    A new lawsuit against Meta asks a question many employers have managed to postpone: what happens when employees say AI helped decide who lost a job, while the employer says humans made the decisions without AI scoring or ranking?

    Twenty-six current and former Meta employees allege that the company used internal AI systems, activity-monitoring data, productivity measures, AI-token consumption, and algorithmically assisted rankings to select workers for a May 2026 reduction in force. The plaintiffs say the process penalized employees who had taken protected medical, parental, pregnancy-related, caregiver, or family leave.

    Meta denies using AI to make the selections. In a declaration filed with the court, a Meta human-resources director said human business leaders made the decisions using documented criteria and that there was no AI-assisted scoring or ranking related to employee performance.

    The case is Does 1 Through 26 v. Meta Platforms, Inc., No. 3:26-cv-07122-WHO, filed July 13 in the Northern District of California. The court has denied the employees' request for a temporary restraining order, but it did not resolve the underlying claims. U.S. District Judge William Orrick found "serious questions going to the merits" and said discovery in arbitration would be needed to test Meta's account.

    That dispute is what makes the case useful. It shows the evidentiary problem employers will increasingly face when workforce decisions sit near performance systems, activity data, AI tools, dashboards, and human approvals. The central issue may be less about one identifiable algorithm than whether the employer can prove what did and did not affect the result.

    What The Employees Allege

    The complaint says Meta began notifying about ten percent of its workforce on May 20 that they had been selected for termination.

    According to the plaintiffs, managers who knew the employees' work did not assemble the termination list through individualized judgment. They allege that Meta used a group of internal tools and data sources that included:

    • "Metamate," described as an internal large-language-model assistant;
    • employee-trained "second brain" agents that ingested communications and work documents;
    • keystroke, screen-content, mouse, browser-history, and other activity data;
    • dashboards showing employee-level AI-token consumption;
    • productivity, output, performance, and calibration measures; and
    • algorithmically assisted rankings, including what the complaint calls an "AI-native" rating.

    Those details are allegations, not established findings. They still illustrate why a modern workforce case may be hard to explain through a conventional account of one supervisor making one decision.

    The plaintiffs' central theory is that the system rewarded signals employees could accumulate only while actively working. Someone on protected leave could not generate code commits, output volume, AI-tool usage, roadmap ownership, or similar measures at the same rate as an employee who was present throughout the measurement period.

    The complaint alleges that Meta failed to neutralize protected-leave periods, remove affected employees from the comparison group, or require an individualized review that accounted for leave and accommodations. The employees claim those omissions turned apparently neutral productivity signals into negative factors tied to protected activity or disability.

    The complaint brings claims under federal and state employment laws, including the Family and Medical Leave Act, the Americans with Disabilities Act, the Pregnancy Discrimination Act, and the Pregnant Workers Fairness Act. It also invokes laws in several states and the District of Columbia.

    What The Court Has Said So Far

    The July 17 temporary-restraining-order decision gives both sides something to point to.

    Meta submitted a declaration stating that human business leaders made the selections using criteria such as job profile, level, historical and recent performance ratings, tenure, location, job function, specialized skills, and organizational structure. The declaration said no plaintiff was selected because of leave, disability, or another protected characteristic and that AI made no selection decision.

    The employees submitted declarations describing their understanding of Meta's growing use of AI in performance reviews and internal employee classifications. But the judge noted that they were not present when the reduction-in-force decisions were made and did not yet have evidence rebutting Meta's direct account.

    Judge Orrick found that the employees had raised serious questions but had not shown a likelihood of success on the existing record. He denied emergency relief largely because most claimed harms, including lost employment, benefits, leave, and equity, could be addressed through damages or relief in arbitration.

    The order did identify a narrower concern. Four plaintiffs held Meta-sponsored employment visas, and the judge said the potential loss of immigration status likely could constitute irreparable harm. He directed Meta to submit declarations explaining how and why those four employees were selected. The preliminary-injunction hearing is scheduled for August 24.

    The order did not decide whether Meta used AI improperly or violated employment law. It framed the proof question: the employees suspect that AI-related systems affected the result; Meta says they did not; and the relevant records are largely controlled by Meta.

    The Hard Question Is How The Decision Was Made

    Companies often describe AI as advisory. A manager still approves the result, so the company may believe that a human remains responsible for the decision.

    That description does not resolve the legal or factual problem.

    If an algorithm determines which employees receive scrutiny, converts workplace activity into a score, sets a comparative ranking, or supplies the recommended list, the later human approval may carry less weight than the company assumes. The quality of the human review matters more than the existence of a final click.

    An employer defending this kind of case may need to show:

    • what systems and data affected the decision;
    • which metrics were calculated and over what period;
    • how leave, disability accommodations, and missing data were treated;
    • whether managers could change a recommendation;
    • what information managers saw before approving it;
    • how often managers overrode the system; and
    • whether anyone tested the process for distorted or discriminatory results.

    A human signature at the end of the process does not answer those questions.

    Measurement Windows Can Become Legal Risk

    The complaint focuses attention on a basic design choice: the measurement window.

    A productivity system can appear neutral while treating absence as poor performance. That risk grows when the system relies on volume measures such as messages sent, code committed, documents produced, hours active, or AI tokens consumed.

    The problem is not limited to formal leave. Disability accommodations may change how or when an employee works. Pregnancy-related restrictions may reduce certain kinds of activity. Caregiving leave can create gaps that a ranking system reads as lower output. A system trained on uninterrupted work histories may treat legally protected circumstances as performance signals unless the employer deliberately changes the design.

    Governance teams should therefore ask a more precise question than whether a model uses protected characteristics. They should ask whether the system uses proxies or measurement rules that systematically encode the effects of protected leave, disability, pregnancy, or accommodation.

    Employers Need A Decision Record, Not Just An AI Policy

    Most AI policies say that people must remain involved in consequential decisions. That is a useful principle, but it is not a litigation record.

    For workforce decisions, employers need documentation tied to the actual event. A defensible record should identify the system version, input fields, relevant dates, scoring logic, exclusions, adjustments, reviewers, overrides, and final reasons for each decision.

    That record should also explain how the employer handled protected leave and accommodations. If a measurement period overlapped with leave, the company should be able to show whether it adjusted the denominator, removed the affected period, used a different comparison, or excluded the metric.

    The same principle applies to vendors. A company may use a third-party model, but the employment decision remains the company's. Contract language should provide access to the documentation, testing information, logs, and technical support needed to investigate a challenged result.

    Discovery Will Reach Beyond The Final Layoff Spreadsheet

    The complaint also shows how quickly an employment dispute can become an AI-governance and data-preservation matter.

    Relevant evidence may include:

    • prompts and outputs from internal assistants;
    • model and scoring documentation;
    • employee-level dashboards;
    • activity-monitoring records;
    • calibration materials;
    • communications about metric selection;
    • bias, validation, and impact testing;
    • manager instructions and override records; and
    • records showing when employees requested leave or accommodations.

    Legal holds written for ordinary personnel files may miss much of that material. Some records may sit in analytics platforms, model logs, collaboration systems, or vendor environments with short retention periods.

    Employment counsel, privacy teams, and technical owners should decide in advance who can preserve those records and how quickly preservation can begin.

    What Companies Should Review Now

    Employers do not need to wait for a ruling in the Meta case to examine their own processes.

    Start with an inventory of every system that can affect selection for promotion, discipline, performance management, restructuring, or termination. Include systems described internally as analytics, productivity, workflow, or decision support. Labels do not determine whether a tool influences an employment decision.

    Then map the inputs. Look specifically for measures that fall when an employee is absent or working under an accommodation. Test whether protected leave changes an employee's score, rank, comparison group, or likelihood of additional review.

    Finally, inspect the human-review step. Reviewers need enough information and authority to identify a distorted recommendation. A process that asks a manager to approve hundreds of names without explaining the underlying data is not meaningful review.

    The Larger Lesson

    The Meta lawsuit may succeed, fail, or narrow as the employees pursue their claims in arbitration. Their allegations have not been proven, and Meta has submitted a direct factual denial.

    The governance problem exists either way. Employers are combining workplace monitoring, productivity analytics, internal AI assistants, performance ratings, and ranking systems. When those systems affect a termination decision, the company needs to reconstruct the path from raw data to final outcome.

    If AI helps build the layoff list, an employer should be ready to show what the system measured, what it ignored, who reviewed the result, and how legally protected circumstances were kept from becoming negative signals.

    Without that record, "a human made the final decision" may be a conclusion the evidence cannot support.

    Sources and Related Clearon Coverage

  • The EU’s Final Article 50 Guidance Is Here. The Omnibus Did Not Delay Transparency Duties.

    The EU’s Final Article 50 Guidance Is Here. The Omnibus Did Not Delay Transparency Duties.

    The last major excuse for waiting is gone.

    The European Commission has now adopted final Article 50 transparency guidelines. At nearly the same time, the EU's Digital Omnibus was published in the Official Journal and made parts of the AI Act's high-risk timetable final law.

    Those two developments belong in the same article because plenty of teams are going to misread them together.

    The easiest mistake now is to assume the Omnibus delayed the whole AI Act rollout. It did not. The amended high-risk dates are now final law, but the Article 50 transparency duties still apply on August 2, 2026.

    That means companies no longer need to guess whether practical Commission guidance will arrive before the deadline. It arrived. They also should stop telling themselves that the new Omnibus timing buys them more time on transparency. It does not.

    For broader tracking context, see Clearon's Laws, Bills & Regulations page.

    What Changed This Week

    Three separate EU developments now need to be read together.

    First, the Commission adopted final practical guidelines on Article 50 transparency obligations for providers and deployers of AI systems. The guidance covers direct AI interactions, machine-readable marking of AI-generated or AI-manipulated content, deepfake labelling, certain public-interest text disclosures, and notice duties for emotion-recognition and biometric-categorisation systems.

    Second, the Digital Omnibus was officially published as Regulation (EU) 2026/1744. That matters because it turns the revised high-risk timetable into final law instead of a politically agreed future change.

    Third, the EU also published Commission Implementing Regulation (EU) 2026/1755 on procedural arrangements for Commission evaluations of general-purpose AI models. That is not an Article 50 rule, but it shows the wider AI Act implementation machinery is moving from policy talk into formal instruments.

    The practical result is simple. The EU implementation picture is now clearer, not blurrier.

    What The Omnibus Actually Changed

    The Omnibus matters. It just does not matter in the way some summaries will imply.

    The new regulation changes parts of the AI Act's high-risk timetable. According to the official publication, the relevant Annex III high-risk regime now moves to December 2, 2027, and product-embedded high-risk systems move to August 2, 2028.

    That is real law now.

    But the Omnibus did not postpone Article 50. The transparency obligations still apply from August 2, 2026. If a company walks away from this week thinking "the EU delayed AI Act deadlines," that company may be calm about exactly the wrong deadline.

    This distinction matters because Article 50 sits in a very different lane from the high-risk regime. The high-risk rules are about system categories, lifecycle controls, and sector-specific obligations. Article 50 is about transparency in actual outputs and interactions. For many companies, Article 50 hits public-facing content and product workflows much sooner than the heavier high-risk framework ever will.

    Why The Final Guidelines Matter

    Until now, some teams could say they understood the direction of travel but were still waiting for final Commission guidance on scope and implementation.

    That position is much harder to defend now.

    The Commission has moved Article 50 guidance from pending to final. The guidance is still nonbinding. Article 50 itself remains the binding law. But final Commission guidance changes the planning posture in at least three ways.

    First, it narrows the room for pretending that core implementation questions are still too unsettled to begin workflow changes.

    Second, it gives legal and compliance teams a better basis for making near-term judgments about which products, interfaces, and publishing flows are in scope.

    Third, it raises the standard for companies that want to reject the Commission-backed path and rely on a custom approach instead. That choice is still available. It is just easier to scrutinize now.

    The earlier milestones already pointed in this direction. The Commission had published the transparency Code of Practice, said it adequately covers Articles 50(2), (4), and (5), and publicly identified signatories to the broader GPAI Code structure. The final guidelines now add the missing implementation layer many organizations said they were waiting for.

    The Rule Is Binding. The Guidance Is Not. That Distinction Still Matters.

    This is where companies can still trip over their own summaries.

    The legal obligation comes from Article 50. The final guidelines do not replace the statute and do not create a new binding act. They are implementation guidance.

    The Code of Practice is different again. It remains voluntary even after the Commission's adequacy assessment and public signatory list.

    So there are three separate layers:

    • Article 50 is binding law.
    • The final guidelines are nonbinding Commission guidance.
    • The transparency Code is a voluntary compliance path.

    That separation matters because teams need to know what they must do, what the Commission recommends, and what route they may choose to use as evidence of compliance.

    It also matters for anyone writing internal updates. If a business memo says "the Commission finalized Article 50 rules," it risks flattening together the law, the guidance, and the Code in a way that creates confusion later.

    What Companies Should Be Doing Right Now

    The final guidelines do not eliminate every edge case. They do make it harder to justify delay in the parts of the work that were always operational.

    That work starts with inventory.

    Companies should identify which products and workflows may trigger Article 50 analysis. That includes customer-facing AI systems, media-generation tools, marketing and communications pipelines, newsroom or publishing processes, synthetic audio and video workflows, public-facing text generation, and interfaces where a user may need to be told they are interacting with AI.

    Then comes role mapping.

    Many organizations will be both providers and deployers depending on the product or workflow. That cannot be solved once at the company level and forgotten. It has to be mapped feature by feature and channel by channel.

    Then comes scope mapping.

    Teams need working rules for when content qualifies as AI-generated or AI-manipulated, when it becomes a deepfake, when text is published to inform the public on a matter of public interest, and when direct AI interaction notices are required.

    Then comes control testing.

    The key question is not whether a label can be drafted. It is whether the notice, marker, metadata, or disclosure actually survives the channels where people encounter the content. Web pages, mobile surfaces, PDFs, screenshots, syndicated content, reposted clips, social snippets, image exports, and partner distribution all deserve testing.

    Then comes evidence.

    If a company is ever asked what it did before August 2, it should be able to show role assignments, workflow decisions, scope calls, implementation dates, exception handling, and testing results. A last-minute label pasted onto content with no decision trail behind it is weak compliance hygiene.

    Where The Hard Questions Still Sit

    The public conversation around Article 50 still overfocuses on labels.

    The harder questions are mostly underneath the label:

    • Who decides when a piece of content is in scope?
    • Who owns the distinction between provider and deployer in mixed workflows?
    • How will machine-readable marking behave when content is clipped, embedded, reformatted, or redistributed?
    • What counts as enough disclosure when AI-generated text is part of a broader edited publication?
    • How will product, legal, trust and safety, editorial, and communications teams avoid giving different answers to the same question?

    The final guidelines help. They do not remove the need for judgment.

    That is why the next two weeks matter more than the next abstract policy debate. Most organizations do not need another conceptual conversation about transparency. They need ownership, workflow decisions, and testing.

    Why The New GPAI Evaluation Rule Still Belongs In The Background

    The new implementing regulation on evaluations of general-purpose AI models is not the headline for most readers of this article.

    It still matters.

    It shows that the EU is not only publishing speeches, FAQs, and voluntary frameworks. It is also putting binding procedural instruments in place for the Commission's evaluation and enforcement architecture.

    That broader context should affect how companies read Article 50. Even though Article 50 is about transparency rather than GPAI model evaluations, both developments point the same way: the implementation phase is now real enough to change legal and product behavior, not just policy slide decks.

    A Better Internal Message Than “The EU Delayed Things”

    If you need a one-line summary for management, this is the better one:

    The EU clarified and formalized more of the AI Act this week, but it did not delay the Article 50 transparency duties that matter on August 2.

    That framing is closer to the truth than the broader and sloppier claim that the EU "pushed back AI Act deadlines."

    Some deadlines did move. This one did not.

    That matters because Article 50 is likely to hit public-facing workflows sooner than many teams expect. It is not mainly a frontier-model issue. It is a publishing, product, disclosure, and recordkeeping issue.

    Bottom Line

    The final Article 50 guidance is here.

    The Omnibus is now final law.

    Neither development gives companies a reason to delay transparency work.

    The opposite is true. The Commission has made the implementation picture clearer, and the new Omnibus publication removes one source of confusion while creating another for anyone who reads it carelessly. The high-risk timetable changed. The Article 50 date did not.

    If teams are still waiting for the right moment to move Article 50 from policy discussion into operational compliance, this was that moment.

    Sources

    Sources and Related Clearon Coverage

  • Why I Built a State AI Companion Chatbot Law Guide

    Why I Built a State AI Companion Chatbot Law Guide

    I started looking more closely at Hawaii’s new conversational-AI law because it seemed familiar.

    Act 248 requires AI disclosures, suicide and self-harm protocols, protections for minor account holders, and annual reports to the state Behavioral Health Administration. Violations can be treated as unfair or deceptive practices.

    California, New York, Oregon, Washington, Connecticut, Colorado, Idaho, Iowa, Nebraska, Georgia, and Rhode Island have enacted laws that reach parts of the same product category. Once those statutes are placed next to one another, the overlap is obvious. So are the differences.

    I could not find a useful way to explain that in a short state update. So I built a State AI Companion and Conversational Chatbot Law Guide for Clearon.

    A State Count Does Not Tell You What To Build

    “Similar laws” is a fair description. Product and legal teams still need the differences before they can decide what to build.

    One state may require recurring disclosures. Another may focus on the start of the interaction. Some regulate crisis referrals for every user. Others add detailed restrictions for minors involving sexual content, emotional dependence, reward systems, secrecy, isolation, or spending pressure.

    The reports go to different places. Hawaii uses its Behavioral Health Administration. California uses its Office of Suicide Prevention. Rhode Island requires reports to the Attorney General. Oregon has a separate reporting structure.

    The remedies differ too. Some statutes rely on state consumer-protection enforcement. Oregon provides a private action for ascertainable harm. California includes a separate limited civil remedy. Idaho and Nebraska say their laws do not create a private right of action.

    Those choices affect product design, recordkeeping, contracts, and litigation risk.

    What The Guide Covers

    The guide compares enacted laws in twelve jurisdictions that directly regulate companion or conversational AI:

    • California
    • Colorado
    • Connecticut
    • Georgia
    • Hawaii
    • Idaho
    • Iowa
    • Nebraska
    • New York
    • Oregon
    • Rhode Island
    • Washington

    For each jurisdiction, the guide identifies the law and operative date, then compares disclosure, crisis response, protections for minors, reporting, and enforcement.

    The guide keeps related laws in a separate section. Broader children’s online-safety statutes, therapy-bot restrictions, and narrowly targeted criminal provisions may belong in the same risk review, but they do not regulate the same products in the same way.

    Pending bills stay in a separate section. Legislative passage is not enactment, and a proposal does not create a current compliance duty.

    The Repeated Requirements

    The statutes keep returning to four practical questions.

    Does the user know this is AI? A notice may be required at the start of an interaction, during a long session, or more often when a minor is involved.

    What happens when a user expresses suicidal thoughts or an intent to self-harm? The answer has to work inside the product. It also has to be tested and documented.

    What changes for minors? The newer laws reach the conversation and the engagement design. They address sexual content, simulated dependence, isolation from trusted adults, rewards, and emotional pressure to keep using the product.

    Can the company prove what happened? Annual reports, Attorney General inquiries, and private claims all depend on records. A company may need to show which notice appeared, how the system handled a crisis signal, and which safeguards were active for a minor account.

    Hawaii Shows Why A Multistate Map Is Necessary

    Act 248 sits near the center of this group. It combines disclosure, crisis protocols, minor protections, reporting, and consumer-protection enforcement. It still falls short as a national template.

    A company could satisfy Hawaii’s reporting route and miss California’s reporting details. It could comply with one state’s disclosure language and miss another state’s frequency requirement. It could maintain a general minor-safety policy without addressing Washington’s or Idaho’s more specific engagement restrictions.

    I think a control matrix is more useful than twelve isolated memos. Each duty can be assigned to a product owner and matched with an effective date, a technical or operational control, and evidence that the control works.

    This Will Need Maintenance

    The guide is dated and was last reviewed July 29, 2026.

    Several laws have 2027 operative dates. Colorado rulemaking is still developing. New York has a separate minor-safety bill that passed both chambers but had not been confirmed as enacted when the guide was prepared. Other states are considering their own measures.

    I drew a firm line between enacted duties and pending proposals. A state will move into the main table only after enactment can be confirmed through an official source.

    Blending bills, signed laws, effective requirements, investigations, and enforcement findings produces a misleading picture of what companies must do now.

    Companion chatbot regulation has become a multistate compliance issue.

    The statutes share a basic structure: nonhuman notice, crisis response, protections for minors, reporting, and enforcement. The legal work is in the differences.

    Read the new State AI Companion and Conversational Chatbot Law Guide for the comparison table, source links, and practical review questions.

    Sources

  • State AI Companion and Conversational Chatbot Law Guide

    State AI Companion and Conversational Chatbot Law Guide

    States are starting to regulate companion and conversational AI around the same basic concerns: users mistaking a bot for a person, chatbots mishandling signs of self-harm, and minors being exposed to sexual or manipulative interactions.

    The statutes take different routes. Definitions, effective dates, reporting duties, content restrictions, and remedies vary from state to state. Compliance with one law does not necessarily cover another.

    This guide tracks enacted state laws that directly regulate conversational or companion AI. It separates those laws from broader children’s online-safety statutes, mental-health practice restrictions, and pending bills.

    Last reviewed: July 29, 2026.

    Quick Comparison

    State Law Status or operative date AI disclosure Suicide or self-harm protocol Minor-specific protections Reporting Enforcement
    California SB 243, Chapter 677 (2025) Effective January 1, 2026; annual reports begin July 1, 2027 Yes; recurring notice for known minors Yes Break reminders and restrictions on sexually explicit outputs to known minors Annual report to Office of Suicide Prevention Public enforcement plus a limited private civil action for injury in fact
    Colorado HB 26-1263 Signed May 29, 2026; effective August 12, 2026, with operative duties beginning January 1, 2027 Yes for covered minor interactions Yes Parental tools; restrictions involving sexual content, emotional dependence, and gamified engagement Safety and self-harm reporting provisions; rulemaking underway Attorney General under state consumer-protection law
    Connecticut SB 5, Public Act 26-15 Companion provisions begin January 1, 2027 Yes when a reasonable user could mistake the system for a human Yes, including crisis-resource referral Additional safeguards involving violence, disordered eating, substances, sexual exploitation, and parental management Recordkeeping and related statutory duties vary by provision Attorney General; unfair-trade-practice framework
    Georgia SB 540 Effective January 1, 2027 Yes Yes Restrictions and privacy tools for minor users No general annual agency report identified Attorney General; civil penalties
    Hawaii SB 3001, Act 248 Enacted and effective July 14, 2026 Yes Yes Additional protections for minor account holders Annual reports to the Behavioral Health Administration Violations treated as unfair or deceptive practices
    Idaho S 1297, Conversational AI Safety Act Effective July 1, 2027 Yes Yes Restrictions on addictive rewards, sexual content, simulated emotional dependence, and certain role play; privacy tools No general annual agency report identified in the enacted act Attorney General; no private right of action
    Iowa SF 2417 Effective July 1, 2027 Yes Yes Minor protections and restrictions on presenting the service as professional mental or behavioral health care No general annual agency report identified Attorney General and civil penalties
    Nebraska LB 525, Conversational Artificial Intelligence Safety Act Effective July 1, 2027 Yes Yes Restrictions on rewards, sexual content, sentience or human claims, emotional dependence, and adult-minor romantic role play; privacy tools No general annual agency report identified Attorney General; no private right of action; model-developer limitation for third-party operator conduct
    New York General Business Law Article 47 In effect Yes; recurring notice every three hours of continued use Yes The enacted Article 47 framework is less prescriptive than several 2026 minor-safety laws Operator records support Attorney General oversight Attorney General; civil penalties support suicide-prevention programs
    Oregon SB 1546, Chapter 85 Effective January 1, 2027 Yes Yes Additional protocols when the operator has reason to believe the user is a minor Annual reporting concerning crisis-resource referrals Private right of action for ascertainable harm, damages, and injunctive relief
    Rhode Island S 2195/H 7350 companion measures Effective January 1, 2027 The principal enacted measure centers on crisis response rather than a broad recurring disclosure regime Yes, including possible physical harm to others Limited compared with states that regulate minor-facing engagement design Annual reports to the Attorney General; aggregate publication Attorney General; penalties up to $15,000 per day
    Washington HB 2225 Effective January 1, 2027 Yes Yes Restrictions on sexual content and manipulative engagement, including emotional dependence, isolation, secrecy, and spending pressure Public safety-protocol reporting requirements State consumer-protection enforcement and statutory remedies

    The table is a screening tool, not a substitute for reading the statute. Coverage can turn on how a service is marketed, whether it sustains a relationship across interactions, whether the operator knows or should know that a user is a minor, and whether an ordinary transactional chatbot is excluded.

    What These Laws Have In Common

    Most states start with nonhuman notice

    Most of the laws require some form of clear notice that the user is interacting with AI rather than a person. The timing differs. Some states focus on the beginning of the interaction. Others require repeated notices, especially for minors or extended sessions.

    Writing the notice is the easy part. Companies still need to decide which products qualify, where the notice appears, whether it follows the user across devices, and what records show that it was delivered.

    Crisis response is now part of product compliance

    Hawaii joins a growing group of states requiring protocols for suicidal ideation or self-harm. These provisions commonly require the operator to identify covered expressions and direct the user to an appropriate crisis service.

    The statutes do not all use the same trigger or prescribe the same response. A national program needs a documented detection standard, escalation logic, referral content, testing process, and review owner.

    The minor protections reach beyond age gates

    Several 2026 laws regulate what the chatbot may say or do after a minor enters the product. Common subjects include sexually explicit material, simulated romantic or dependent relationships, addictive reward systems, isolation from family or friends, secrecy, spending pressure, and design intended to prolong use.

    Age assurance is one part of the problem. Operators also need a defensible way to apply the correct experience when they know, or have reason to know, that a user is a minor.

    Reporting and remedies vary sharply

    Hawaii requires annual reporting to its Behavioral Health Administration. California, Oregon, and Rhode Island also use reporting mechanisms, but the recipients and required data differ. New York relies on Attorney General enforcement. Oregon adds a private action. California provides a separate limited civil remedy. Idaho and Nebraska expressly reject a private right of action.

    These differences affect records, litigation exposure, incident review, and contract allocation. A generic safety policy will not cover all of them.

    Why Hawaii Act 248 Matters

    Hawaii’s Act 248 puts several recurring duties in one law: nonhuman disclosure, suicide and self-harm protocols, protections for minor account holders, annual reporting, and unfair-or-deceptive-practice enforcement.

    Hawaii also shows how far this issue has moved beyond California and New York. A company offering one national product may face similar duties through different state statutes, agencies, and enforcement routes.

    Laws That Are Related But Not Direct Equivalents

    Several enacted laws belong in the same risk review without fitting neatly into the main comparison:

    • New York’s Safe By Design Act addresses child accounts on online platforms and disables integrated AI chatbots by default, subject to parental controls.
    • South Carolina’s H 3431 is a broader minors’ online-safety and reasonable-care statute rather than a dedicated companion-chatbot law.
    • Wyoming’s HB 102 targets intentionally designed or distributed systems involving specified self-harm promotion and sexual deepfake harms, with a narrower and more punitive structure.
    • Maine and Utah regulate aspects of AI-delivered therapy, mental-health representations, or professional services.
    • Rhode Island separately enacted restrictions involving AI and mental-health care.

    These measures can affect the same product or vendor review, but they should not be described as interchangeable with Hawaii’s Act 248.

    Pending Measures

    Pending bills belong in a separate watchlist. They do not create current compliance duties.

    New York’s S 9051-B/A 10379 passed both legislative chambers in 2026 and would impose additional minor-facing companion safeguards. Its provisions should not be treated as enacted unless the governor signs it or it otherwise becomes law.

    Other states continue to consider bills addressing age assurance, parental consent, sexual content, emotional dependence, professional impersonation, and crisis response. This guide will move a state into the main table only after enactment can be confirmed through an official source.

    A Practical Multistate Review

    Companies offering emotionally responsive, relationship-oriented, or highly personalized conversational AI should be able to answer:

    1. Which products fall within each state’s companion or conversational-AI definition?
    2. Which ordinary business, customer-service, productivity, or professional tools are excluded?
    3. Where and how often does the product disclose that it is AI?
    4. How does the product detect and respond to suicide, self-harm, or threats of violence?
    5. What changes when the user is known or reasonably believed to be a minor?
    6. Which engagement, sexual-content, role-play, or spending features must be disabled?
    7. What must be reported, to whom, and on what schedule?
    8. Which duties belong to the operator, model developer, distributor, or contracting customer?
    9. What evidence shows that safeguards were tested and notices were delivered?
    10. Which states permit private claims in addition to government enforcement?

    Start with a product inventory tied to the state definitions. Then build a control matrix that assigns each duty to an owner and records the supporting evidence, effective date, and reporting deadline.

    Sources

    This guide is general information, not legal advice. Statutory text, amendments, effective dates, rules, and official guidance should be checked for each product and jurisdiction.