Tag: Legal Risk

  • Connecticut’s AI Subscription Law Is Now Live. What Providers Must Disclose

    Connecticut’s AI Subscription Law Is Now Live. What Providers Must Disclose

    Connecticut’s AI Subscription Law Is Now Live. What Providers Must Disclose

    Connecticut’s new AI law regulates a part of the generative-AI relationship that companies often treat as ordinary commerce: the subscription transaction.

    Section 46 of Public Act 26-100, enacted from House Bill 5222, took effect October 1, 2026. It applies to a defined class of subscription-based providers of publicly accessible generative-AI systems. Before those providers enter into or renew a covered subscription—or collect payment for it—they must give the consumer written notice of the subscription’s key terms and conditions, and the consumer must provide written notice accepting those terms and conditions.

    The law is not a general disclosure mandate for every AI product. Its practical effect is narrower and more operational: covered providers need a reliable, versioned way to explain material limits and discretionary controls at the point of initial purchase and renewal.

    The short answer

    • Public Act 26-100’s subscription-disclosure provision is effective October 1, 2026.
    • It targets nongovernmental persons doing business in Connecticut that create, code, or otherwise produce a generative-AI system that has more than one million users per month and is publicly accessible to consumers for personal use, and that provide or offer that system to consumers through a subscription.
    • Before entering into or renewing a subscription, or collecting payment for one, the provider must give written notice of key terms and conditions and obtain written consumer acceptance.
    • Initial notices must include material information sufficient for a reasonable consumer to decide whether to purchase or maintain the subscription, including any quantitative or qualitative limitations—including limitations imposed in response to consumer conduct—and whether the provider has discretion to limit or eliminate access to, or reduce the quantity or quality of, any functionality.
    • Every renewal requires written notice of the subscription’s key terms and conditions and the consumer’s written notice of acceptance; at minimum, the renewal notice must identify covered limitations and provider discretion that will apply for the first time or have changed since the immediately preceding term.
    • Violations are unfair or deceptive trade practices enforceable solely by the Attorney General. The act does not create a private right of action under the cited provision.
    • Section 47 takes effect October 1, 2027 and, within available appropriations, directs the Department of Consumer Protection to develop and administer an independent-verification pilot. It is not a substitute for the current subscription-notice duty.

    This is a targeted scope, not an all-AI rule

    The act’s definitions do much of the legal work.

    For this section, a generative artificial intelligence system is technology that uses machine learning to generate images, audio, or video, including systems using deep learning, natural-language processing, or similar or more complex computational processing.

    A “consumer” is an individual who resides in Connecticut. The incorporated definition excludes an individual acting in a commercial or employment context. It also excludes an individual acting as an employee, owner, director, officer, or contractor of a company, partnership, sole proprietorship, nonprofit, or government agency when the individual’s communications or transactions with the controller occur solely within that role. A subscription is an agreement under which a subscription-based provider offers a generative-AI system to such a consumer in exchange for a fee, remuneration, or other compensation. A covered provider must be doing business in Connecticut, must create, code, or otherwise produce a system that has more than one million users per month and is publicly accessible to consumers for personal use, and must provide or offer that system through a subscription. Federal, state, and local government agencies are excluded.

    That combination matters. The statute is not written as a rule for every enterprise deployment, internal model, one-off API transaction, or AI-enabled feature. Companies should analyze the statutory definitions before assuming either that they are covered or that they are outside the law.

    The requirement that the system have more than one million users per month also creates a measurement question. A provider should be able to explain what population it is counting, what period it is using, and how it treats accounts or users across products and subscription tiers. The statute sets the threshold; it does not supply a ready-made product analytics policy.

    The disclosure is a condition of the transaction

    Section 46 does not merely ask providers to place generic terms somewhere on a website.

    Before a provider enters into or renews a covered subscription—or collects a fee, remuneration, or compensation for an initial or renewal subscription—the provider must provide written notice disclosing key terms and conditions. The consumer must also provide written notice that the consumer accepted those key terms and conditions.

    That structure connects the notice and acknowledgment to the commercial event itself. Product and legal teams should therefore map the actual purchase, renewal, and payment flows rather than treating this as a copy update in a static terms-of-service page.

    The implementation questions are practical:

    • Where is the written notice displayed or delivered?
    • How is the consumer’s written acceptance captured?
    • Can the provider prove which version was shown for a particular transaction?
    • What happens when a subscription renews automatically?
    • Does the payment system prevent collection if the required notice or acknowledgment is missing?

    The act does not answer those technical questions. It makes them part of the provider’s compliance design.

    What the initial notice must explain

    The initial notice must include material information sufficient for a reasonable consumer to decide whether to purchase or maintain the subscription.

    The act specifically requires disclosure of any quantitative or qualitative limitations the provider may impose under the subscription, including limitations involving tokens, generated or modified images, transcription services, and limitations imposed in response to consumer conduct. The notice must also disclose whether the provider has discretion to limit or eliminate the consumer’s access to, or reduce the quantity or quality of, any functionality offered under the subscription.

    That is broader than a single monthly usage number. A useful notice should help a reasonable consumer understand both the stated allowance and the provider’s operational discretion. For example, a provider may need to explain not only a token or image limit but also whether it can change the quality of outputs, throttle use, remove a feature, or otherwise reduce the quantity or quality of functionality under the subscription’s terms.

    The safest operational approach is to connect the notice to the product’s actual entitlement and control system. If the product team changes a usage cap, model tier, image allowance, transcription feature, or access-control rule, the legal notice should not remain on an unrelated version of the subscription page.

    Renewal notices are not a one-time formality

    The act separately addresses renewal terms.

    For every renewal, the provider must give written notice of the subscription’s key terms and conditions, and the consumer must provide written notice accepting them. At a minimum, the renewal notice must disclose covered limitations and provider discretion that will apply for the first time during the renewal term or that have been modified since the immediately preceding term.

    Subscription businesses should therefore treat every renewal as a compliance checkpoint. The renewal flow should provide the applicable written notice, obtain and preserve the consumer’s written acceptance, retain the relevant version history, and specifically identify newly introduced or modified limitations and discretion.

    This is particularly important for products that move users between model families, change rate limits, retire features, or introduce tier-specific controls during a continuing subscription relationship.

    Enforcement belongs to the Attorney General

    Section 46 provides that a violation is an unfair or deceptive trade practice under Connecticut’s consumer-protection statute. It also says enforcement is solely by the Attorney General, that a cited private-remedy provision does not apply, and that the section does not create a private right of action.

    That enforcement design should shape how companies describe the risk. The provision is not written as a new private damages claim for every consumer who did not receive a compliant notice. It is a public-enforcement rule with a specific consumer-protection classification.

    That does not make the operational duty optional. A provider still needs evidence showing what notice was supplied, when it was supplied, what version applied, and how the consumer accepted it. The absence of a private right of action is not a reason to omit controls; it is a reason to understand the actual enforcement pathway accurately.

    A separate verification pilot starts in 2027

    Public Act 26-100 also creates a different AI program. Section 47 takes effect October 1, 2027 and, within available appropriations, directs the Department of Consumer Protection to develop and administer a pilot to evaluate independent verification programs operated by third parties. That effective date does not guarantee that the pilot will be operational on that day.

    The pilot concerns whether AI models adhere to best-practice standards for mitigating or preventing personal injury, property damage, data-privacy harms, and other harms. The department shall approve no more than five independent verification organizations to participate in the pilot program. Applicants must describe their scope, risk definitions, measurable metrics, data and methods, evaluation and reporting protocols, technical and governance controls, audit methods, reassessment and remediation processes, independence, conflicts, governance, and personnel qualifications.

    Approved organizations must establish and maintain minimum verification and auditing standards and suspension or revocation procedures; share data with and report annually to the department; require participating persons to participate transparently; and establish procedures for reassessment and, if necessary, suspension after material model changes. The pilot terminates March 31, 2031. By December 31, 2028, the Department of Consumer Protection, in consultation with the Institute for Municipal and Regional Policy at the University of Connecticut, must evaluate the pilot and recommend legislation. By January 31, 2029, the institute must submit a report to the General Assembly committee having cognizance of consumer-protection matters.

    The evidentiary effect is limited. Evidence of verification or good standing is admissible only in a private civil action asserting personal injury or property damage caused by an AI model, and only to the extent the action concerns a specific harm or risk within the verification’s state-approved scope. The evidence is inadmissible in enforcement actions brought by the Attorney General or another state agency and creates no presumption, inference, or defense in those proceedings. The evidentiary provisions described above do not apply if the person acted wilfully, wantonly, or recklessly; materially misrepresented information to the verification organization; or failed to implement required corrective action.

    Providers should keep that 2027 pilot separate from the 2026 subscription obligation. A future verification program is not a current safe harbor for deficient consumer disclosures and does not eliminate the need to build accurate notice and acknowledgment controls now.

    What covered providers should do now

    1. Confirm scope. Document whether the person does business in Connecticut; creates, codes, or otherwise produces the system; whether the system has more than one million users per month and is publicly accessible to consumers for personal use; and whether the person provides or offers the system to consumers through a subscription.
    2. Map the transaction. Identify every initial subscription, renewal, and payment path, including app-store, web, reseller, and automatic-renewal flows.
    3. Inventory limitations. Record quantitative and qualitative limits, including tokens, image generation or modification, transcription, model access, quality controls, and feature availability.
    4. Document discretion. Identify every control that lets the provider limit or eliminate access to, or reduce the quantity or quality of, any functionality, and decide how that discretion will be described to consumers.
    5. Version the evidence. Preserve the notice presented, the applicable subscription term, the consumer’s written acceptance, and the timestamp or transaction record connecting them.
    6. Build renewal handling. Provide the required written notice and obtain written consumer acceptance for every renewal, while specifically identifying covered limitations or provider discretion first introduced or modified for the renewal term.
    7. Plan separately for 2027. Monitor Department of Consumer Protection implementation of the independent-verification pilot without treating it as a substitute for current Section 46 compliance.

    The bottom line

    Section 46 of Connecticut Public Act 26-100 is a consumer-contract provision for a defined class of large, publicly accessible generative-AI subscription providers. Its immediate requirement is straightforward to state but demanding to operationalize: disclose material terms, limitations, and discretionary controls in writing, obtain written consumer acceptance, and make the process work for renewals as well as initial purchases.

    The later verification pilot adds a separate state experiment around model-risk assessment. It may become important for civil-liability evidence and industry practice, but it does not change the current subscription-disclosure duty or create a general enforcement defense.

    For providers in scope, the first compliance deliverable is not a policy memo. It is a traceable transaction flow that can show what the consumer was told, what the consumer accepted, and what the provider was allowed to change.

    This article is general information, not legal advice.

    Sources

    • Connecticut General Assembly, HB 5222 bill status: https://www.cga.ct.gov/asp/CGABillStatus/cgabillstatus.asp?bill_num=HB5222&selBillType=Bill
    • Connecticut Public Act 26-100, official text: https://www.cga.ct.gov/2026/act/Pa/pdf/2026PA-00100-R00HB-05222-PA.PDF
    • Connecticut General Statutes § 42-515, incorporated definition of “consumer”: https://www.cga.ct.gov/current/pub/chap_743jj.htm#sec_42-515
  • Utah’s AI Sandbox Is Becoming a Test of Regulated Healthcare, Not a General Safe Harbor

    Utah’s AI Sandbox Is Becoming a Test of Regulated Healthcare, Not a General Safe Harbor

    Utah’s AI Sandbox Is Becoming a Test of Regulated Healthcare, Not a General Safe Harbor

    Utah’s Office of Artificial Intelligence Policy is turning a difficult regulatory question into a controlled experiment: what should happen when an AI product does something existing professional rules were not written to address?

    The state’s answer is not a blanket exemption. A regulatory mitigation agreement is a written, temporary agreement among a participant, the Office of Artificial Intelligence Policy, and the relevant agency or governmental entity. Within its express scope, it may waive or modify how identified Utah laws or rules apply while an AI use is tested under stated conditions.

    That distinction is becoming more consequential as Utah’s public list of authorized AI pilots expands. The list now includes healthcare uses involving prescription renewals, acne treatment, pelvic-floor physical therapy, psychiatry, and other regulated services. It also includes master agreements with University of Utah Health and Intermountain Health that create a path for future pilots without authorizing one by themselves.

    Utah is therefore building a governance model around supervised evidence. For companies, the attraction is a defined route through an outdated or uncertain rule. For regulators, the bargain is narrower: a product may proceed only within a documented scope, with safeguards, reporting, human oversight, and a way to stop or tighten the experiment.

    The legal mechanism is narrower than a blanket waiver

    Under Utah Code Chapter 72, the office may temporarily grant regulatory mitigation by entering an agreement with a participant and the relevant agency head or governmental-entity head. The agreement may waive or modify how identified Utah laws or rules apply, but only for the covered technology and use and on the agreement’s stated terms.

    The office cannot grant that relief alone. The agreement does not amend the underlying law or rule; a broader change still requires legislation or ordinary agency rulemaking.

    Utah Code § 13-72-401 requires the agreement to specify limitations on use, safeguards, mitigation, consumer disclosures, and reporting requirements. The arrangement is a supervised, time-limited test authorization—not a professional license or general safe harbor. Section 13-72-401(8) expressly states that participation creates no property right or license.

    Two different things appear on Utah’s pilot list

    Utah’s public record combines approved pilots and master agreements. Treating them as the same would overstate what the state has authorized.

    | Arrangement | What it does | What it does not do | | — | — | — | | Approved pilot | Permits a specified AI use under an agreement with the office and the relevant regulator | Does not authorize unrelated products, workflows, or later phases without approval | | Master agreement | Sets standing terms for proposing future pilots through written addenda | Does not authorize a pilot or grant regulatory relief by itself |

    The distinction is visible in the September 10, 2026 master agreement with University of Utah Health. The agreement creates a process for proposing pilots across the health system, but the state’s page says no pilot has been approved under it yet. Intermountain Health has a similar master agreement. Each future project still requires its own written addendum, scope, safeguards, and approval.

    The approved-pilot side is more concrete. Nolla Health’s active pilot, which runs from October 5, 2026 through October 5, 2027, concerns acne treatment for Utah adults with mild to moderate acne. The system assesses photographs and can issue first-time prescriptions and refills for specified topical treatments. The agreement excludes oral medication and isotretinoin and sets out eligibility and escalation limits.

    Two additional healthcare pilots signed on October 2 had not yet begun their demonstration periods when Utah’s public page was reviewed. Expect Fitness concerns pelvic-floor physical therapy. Its system scores answers to standard clinical questionnaires and drafts an exercise and care plan, with a licensed physical therapist reviewing every plan in the initial phase. August AI concerns routine refills of existing prescriptions for a fixed list of noncontrolled medications. It does not write a new prescription, change a dose, or substitute one medication for another.

    Doctronic illustrates a different stage of the program. Its pilot concerns 30-, 60-, and 90-day renewals of medication already prescribed by a licensed provider. The company remains in Phase 1, where every request requires authorization by a licensed medical practitioner. Moving to a later phase requires the office’s approval, and the state’s page says Phase 2 has not been approved.

    The guardrails are the substance of the bargain

    The pilot descriptions repeatedly use the same basic architecture, even though the clinical risks differ.

    First, the state narrows the use case. A pilot may cover a specific medication list, patient population, treatment category, or geographic area. A company cannot assume that approval for one narrow workflow extends to a broader product.

    Second, the state phases human review. August AI’s agreement requires prospective licensed-provider review of the first 250 refills, retrospective review of each of the next 1,000 refills, and later physician spot checks of at least 5 percent of prescriptions in each medication class. Nolla’s first stage requires two Utah-licensed physicians to review every prescription before it is sent. Expect Fitness begins with a licensed physical therapist reviewing every plan.

    Third, the agreements create hard stops. The August AI pilot sends cases to a licensed provider when there is suicidal thinking, a new side effect, a dangerous interaction, or missing laboratory monitoring. The Nolla pilot stops for conditions such as pregnancy, breastfeeding, a weakened immune system, or a past reaction to a listed medication. Expect Fitness identifies symptoms that require urgent care rather than continued automated processing.

    Fourth, the agreements require reporting. The public descriptions refer to monthly reporting, adverse-event reporting, agreement rates between AI outputs and reviewing clinicians, and public quarterly reporting for the master-agreement participants once pilots are approved. A pilot is meant to produce evidence that the office and the relevant regulator can review, not merely a contract that lets a product launch quietly.

    Finally, Utah’s FAQ says participation does not eliminate accountability. Mitigation extends only to the Utah provisions expressly waived or modified; all other legal and regulatory requirements remain in force. Outside that express relief, participants remain subject to applicable civil and criminal penalties, and the FAQ states that patients retain traditional civil and medical-malpractice remedies. An agreement or pilot addendum may nevertheless establish specific cure periods, penalty limits, or safe harbors within its defined scope. Participation is not state endorsement.

    What companies should not infer

    The Utah model creates several traps for loose compliance summaries.

    An agreement is not a statewide approval. The relief applies to the participant and the covered use described in the agreement.

    An agreement is not a permanent rule change. Utah describes demonstration periods as temporary, with limited extensions, and says the office may end an agreement.

    A master agreement is not a live pilot. University of Utah Health and Intermountain Health have a process for proposing projects, but the master agreements themselves authorize no pilot.

    Regulatory mitigation is not blanket immunity. Requirements not expressly waived or modified remain in force, and violations of those requirements or the agreement can result in removal and applicable penalties. Any cure period, penalty cap, or safe harbor exists only to the extent stated in the governing agreement or pilot addendum.

    Human oversight is not a slogan. It appears in the agreement as a named reviewer, a phase threshold, an escalation route, a reporting duty, or a condition for moving to the next stage.

    A practical review for regulated AI products

    Companies considering a similar arrangement should be able to answer five questions before asking for relief:

    1. What exact activity does the existing rule restrict, and what part of the proposed AI workflow creates the conflict?
    2. What is the smallest pilot that can answer the safety or compliance question without expanding the product’s claims?
    3. Which cases must always go to a licensed human, and what events automatically stop the automated path?
    4. What evidence will the regulator receive, on what schedule, and who is responsible for acting on a bad result?
    5. Which duties remain fully in force even if the agreement adjusts one rule?

    Those questions turn a general request for “sandbox access” into a reviewable control plan. They also make it harder to describe a narrow agreement as a broad government endorsement.

    Bottom line

    Utah’s AI sandbox is becoming a useful case study in how regulators can test AI without pretending that an experimental approval is a permanent answer. The state is allowing specific healthcare uses to proceed under written conditions, while keeping the underlying rules, human accountability, reporting duties, and ordinary legal remedies in view.

    The important development is not simply that Utah has authorized more AI pilots. It is that the state is publishing the scope, safeguards, phases, and limits of those pilots. That record gives companies a clearer compliance model—and gives regulators evidence they can use when deciding whether an old rule should eventually change.

    This article is general information, not legal advice. The agreements, Utah Code, agency rules, and official pilot pages should be reviewed for the specific product, use case, and regulated profession involved.

    Sources

  • Idaho’s New AI-in-Education Law Makes Human Oversight a Statewide Requirement

    Idaho’s New AI-in-Education Law Makes Human Oversight a Statewide Requirement

    Idaho's New AI-in-Education Law Makes Human Oversight a Statewide Requirement

    Idaho has enacted a statewide framework for generative artificial intelligence in K–12 public education. Senate Bill 1227, signed by the governor on March 19, 2026, took effect July 1, 2026, and added a new Chapter 70 to Title 33 of the Idaho Code.

    The law does not simply tell schools whether students may use an AI tool. It creates a governance structure: the State Department of Education must develop a statewide framework, the State Board of Education must approve it, and local school districts and public charter schools must adopt policies aligned with it.

    That structure makes Idaho’s law a useful example of a state treating generative AI as an education-governance issue rather than only a classroom technology question.

    What Idaho’s Law Covers

    The statute defines generative artificial intelligence as machine-learning models trained on large volumes of data that can generate new content, including text, images, video, computer code, and music. It excludes models whose primary goal is classifying data, such as those used in automated vehicles.

    It separately defines “generative artificial intelligence in education” as the responsible use of generative AI to support instruction, increase student engagement, personalize learning, improve administrative efficiency, or assist educator decision-making—while ensuring that human judgment remains the final authority.

    That distinction matters. The operative concept is not every automated system used by a school. It is the use of generative systems in teaching, learning, administration, or educator decision-making, subject to a human-control principle.

    A Statewide Framework Comes First

    The State Department of Education must develop a statewide generative-AI-in-education framework for Idaho K–12 public schools. The framework is subject to State Board of Education approval and must:

    • prioritize human-centered oversight, transparency, safety, and data security;
    • ensure that generative AI does not replace or eliminate a human teacher;
    • provide guidance on instructional integration, academic integrity, digital citizenship, and responsible student use;
    • address accessibility, accommodations, and access to generative-AI tools; and
    • serve as the foundation for local policies, professional development, procurement practices, and statewide standards.

    The law does not set out a fixed delivery date for the framework. It does require the department to review and update it as needed through a process involving legislators, education practitioners, industry partners, and workforce representatives. The Idaho Department of Education’s current AI resources page identifies SB 1227 as the foundation for its K–12 AI work and links to framework, standards, professional-development, and family-resource materials.

    The practical result is a two-level governance model. State officials establish the framework, while local entities translate it into operating rules for their own schools and devices.

    Local Policies Must Reach Students and Employees

    Each local school district and public charter school must adopt a policy governing generative-AI use by students and employees in school buildings, on school grounds, during school activities, and on school-issued devices.

    Those policies must align with the State Board-approved statewide framework and define appropriate and prohibited uses for instructional, administrative, and communication purposes. They also must include safeguards for student privacy, data security, accessibility, and academic integrity.

    The statute ties the local policy obligation to existing legal requirements. Policies must comply with applicable state and federal law, including Idaho student-data-privacy requirements, the Idaho Parental Rights Act, the Family Educational Rights and Privacy Act, the Children’s Internet Protection Act, and the Children’s Online Privacy Protection Act.

    For districts, the assignment is therefore broader than writing an acceptable-use paragraph. A workable policy will need to connect classroom use, employee use, student records, vendor contracts, accessibility, assessment, and communications.

    Student Literacy and Teacher Capacity Are Part of the Law

    Idaho’s framework is not limited to restricting risk. The State Department of Education must develop and recommend to the State Board of Education:

    • K–12 generative-AI literacy standards;
    • assessment guidelines addressing student understanding of generative AI, ethics, and responsible use; and
    • a professional-development plan to build educator capacity for safe and effective integration of generative AI.

    The literacy requirement is framed around understanding what generative AI is, how it works, age-appropriate uses, and how to use it ethically, securely, and transparently. The professional-development requirement recognizes a recurring implementation problem: a student-use rule is difficult to administer when educators have not received a parallel operational framework.

    The law also requires the department to develop guidance for parents and legal guardians. That document is intended to support transparency and public understanding of generative AI in public education.

    Procurement Becomes an AI-Governance Checkpoint

    The law places a specific set of requirements on generative-AI-related software, applications, and tools procured by local school districts and public charter schools.

    Those tools must comply with applicable state and federal laws, including FERPA, the Children’s Internet Protection Act, and COPPA. Vendors must disclose whether their products use machine learning, predictive analytics, or generative AI. They also must provide assurances concerning data protection, algorithmic transparency, and responsible use.

    The State Department of Education may establish a list of approved generative-AI tools or develop model procurement guidelines for local use. That authority could become important as districts evaluate products that combine ordinary analytics, predictive functions, and generative features under a single platform.

    For procurement teams, the law points toward a documented intake process: identify the technology, determine what data it receives, obtain vendor disclosures and assurances, evaluate the product against school policy, and preserve the basis for approval.

    What the Law Does Not Yet Answer

    SB 1227 establishes the architecture, but it leaves important operational questions to the framework, local policies, standards, procurement guidance, and possible rules.

    The statute does not provide a single statewide answer for when a student may use a generative-AI tool on an assignment, how a teacher must disclose AI assistance, which products will be approved, or how every district should handle AI-generated errors. It also does not turn the State Department of Education’s framework into a substitute for local policy adoption.

    That division of responsibility is central to the law. A district’s compliance position will depend not only on the text of Chapter 70, but also on the State Board-approved framework and the district’s own policy and procurement records.

    The State Board may promulgate rules to implement the chapter, subject to legislative approval. Those rules could add operational detail, but the statute itself remains the starting point for identifying the required governance components.

    An Implementation Checklist for Idaho Schools

    Districts and charter schools preparing for implementation should track at least these questions:

    • Has the State Board approved the statewide framework, and which parts are incorporated into local policy?
    • Does the local policy cover students and employees across buildings, grounds, school activities, and school-issued devices?
    • Are appropriate and prohibited uses defined separately for instruction, administration, and communication?
    • Are privacy, security, accessibility, academic-integrity, and parental-rights requirements assigned to an accountable owner?
    • Do curriculum and assessment teams have a plan for AI literacy and responsible-use instruction?
    • Do educators have professional-development support before enforcement expectations are imposed?
    • Do procurement records identify machine learning, predictive analytics, and generative-AI features and preserve vendor assurances?
    • Is there a process for updating the policy as the statewide framework and approved tools change?

    These are implementation recommendations, not additional statutory commands. The law expressly requires the framework, local policy adoption, specified safeguards, standards and assessment work, professional development, family guidance, and procurement disclosures and assurances. It separately authorizes possible rulemaking.

    Bottom Line

    Idaho’s SB 1227 treats generative AI in public education as a system-design problem. The state framework is supposed to preserve human authority, protect student data, support academic integrity, and give schools a common baseline. Local districts and charter schools then have to convert that baseline into policies, training, procurement decisions, and day-to-day practices.

    The law’s most consequential phrase may be its simplest: human judgment remains the final authority. Idaho has paired that principle with requirements for state oversight, local accountability, student literacy, educator capacity, parent communication, and vendor transparency. The next phase is implementation—where the statewide framework, local policies, and procurement records will determine what the statute means in practice.

    Sources

  • Oregon’s Synthetic-Media Law Puts Disclosure at the Center of Election AI Rules

    Oregon’s Synthetic-Media Law Puts Disclosure at the Center of Election AI Rules

    Oregon's Synthetic-Media Law Puts Disclosure at the Center of Election AI Rules

    Oregon's election law takes a narrow but consequential approach to generative AI. When a campaign communication uses synthetic media, the communication must disclose that the image, audio recording, or video recording was manipulated.

    The law does not create a general rule for every AI-generated political message. It targets campaign communications that support or oppose a clearly identified candidate or measure and include a realistic but false depiction of an individual that produces a materially different understanding or impression from the unaltered original.

    That makes Oregon useful for companies, campaigns, platforms, and publishers trying to separate the legal question from the technology label. The statute is not triggered simply because software helped create content. It turns on the nature of the communication and the effect of the manipulation.

    What Oregon Defines as Synthetic Media

    Senate Bill 1571, enacted as Oregon Laws 2024, chapter 62, defines synthetic media as an image, audio recording, or video recording of an individual's appearance, speech, or conduct that has been intentionally manipulated with artificial-intelligence techniques or similar digital technology.

    The definition has two important limits. First, the manipulation must create a realistic but false depiction that a reasonable person would believe shows a real individual’s appearance, speech, or conduct, although the depicted event did not actually occur. Second, it must produce a materially different understanding or impression than a reasonable person would have from the unaltered original.

    That language leaves room for ordinary editing that does not create a false impression. It also focuses attention on realistic false depictions and materially misleading alteration, not on every use of generative tools in a political workflow.

    The Disclosure Duty Applies to the Campaign Communication

    If a campaign communication includes any form of synthetic media covered by the statute, it must include a disclosure stating that the image, audio recording, or video recording has been manipulated.

    The statute incorporates ORS 260.005(10)(c), which uses two alternative tests for a communication in support of or opposition to a clearly identified candidate or measure. One covers unmistakable, unambiguous electoral advocacy. The other covers a communication that refers to a candidate or measure that will appear on the ballot, or to a political party, and is disseminated to the relevant electorate within 60 days before a primary election, 120 days before a general election, or 90 days before another election. For this synthetic-media provision, the usual expenditure threshold in the second branch does not apply; aggregate expenditures may be any amount.

    The practical question is therefore not only who made the file, but how it is used. A synthetic clip falls within the disclosure rule only when it is part of a campaign communication under that incorporated test and also satisfies the synthetic-media definition.

    Oregon Chose Injunctive Relief and a Civil Penalty

    The Secretary of State may bring proceedings to enjoin a violation. The Attorney General may bring those proceedings when the alleged violator is the Secretary of State, a candidate for that office, or a political committee or person supporting the Secretary of State or a candidate for that office.

    The circuit court may issue an injunction, prohibition, restraining order, or other appropriate relief without proof of injury or damage to a person. The court must give the proceeding priority, and the prevailing party is entitled to reasonable attorney fees at trial and on appeal.

    Upon proof of a violation, the court must impose a civil penalty of up to $10,000. The statute says that this remedy is exclusive. That combination matters: the law gives the state a fast path to seek an order stopping the conduct, while also putting a defined monetary consequence behind the disclosure requirement.

    The Law Does Not Treat Every Distributor the Same

    Oregon Laws 2024, chapter 62 excludes several categories of conduct and distribution.

    It does not apply to interactive-computer-service or information-service providers as defined in federal law. It also excepts radio and television entities that carry synthetic media in a bona fide newscast, news interview, news documentary, or on-the-spot coverage of a bona fide news event when the broadcast or publication clearly acknowledges, in a manner the average listener or viewer can readily understand, that the communication’s authenticity is in question. Certain regularly published newspapers and periodicals, internet or electronic publications, and internet-service or website providers are excepted when the communication itself states that the synthetic media does not accurately represent a ballot issue or candidate.

    A radio or television station—including a cable or satellite operator, programmer, or producer—an internet website, or an online platform is also excluded when it is paid to broadcast or publish the campaign communication. Satire, parody, and content substantially dependent on a person’s ability to impersonate a candidate without technology are excluded as well.

    Those exceptions mean a compliance review cannot stop at the question, “Was AI used?” Teams also need to identify the speaker, the distribution channel, whether the communication is paid, and whether the content falls within a news, disclaimer, satire, or parody exception.

    Oregon's Model Is Narrower Than a General AI-Content Law

    Oregon's law is best understood as an election-disclosure rule aimed at realistic synthetic depictions. It does not establish a general labeling requirement for all generated political text, all campaign materials, or all online content. It also does not make a platform the default guarantor of every campaign communication it carries.

    That narrower design makes the statute easier to describe and harder to reduce to a single product-control checklist. Campaigns need to identify covered media before publication. Distributors need to understand which statutory exception they rely on. Legal and communications teams need records showing what was altered, how it was labeled, and why the content was treated as covered or excluded.

    Why Idaho Makes a Useful Follow-Up—but Not a Direct Companion Rule

    Idaho Senate Bill 1227, enacted as 2026 Idaho Session Law Chapter 71 and adding Chapter 70, Title 33, Idaho Code, took effect July 1, 2026. It requires the State Department of Education to develop a statewide generative-AI-in-education framework for K–12 public schools, subject to State Board of Education approval; requires local school districts and public charter schools to adopt policies; directs the development of AI-literacy standards, assessment guidance, and educator professional development; and defines generative AI in education as responsible use that leaves human judgment as the final authority.

    The contrast is useful precisely because the laws do different jobs. Oregon addresses voter-facing deception in campaign communications. Idaho addresses institutional governance, privacy, academic integrity, procurement, and human oversight in public education.

    A short follow-up can put the two laws side by side as two state regulatory models: Oregon uses a targeted disclosure-and-enforcement rule for synthetic election media, while Idaho builds an administrative framework around responsible use of generative AI in schools. They should not be presented as if they regulate the same conduct.

    What Organizations Should Review

    Organizations operating in Oregon should review:

    • whether the communication meets the incorporated campaign-communication definition, including one of the alternative ORS 260.005(10)(c) tests;
    • whether an image, audio recording, or video recording of an individual’s appearance, speech, or conduct was intentionally manipulated using artificial-intelligence techniques or similar digital technology;
    • whether a reasonable person would believe the depiction shows real appearance, speech, or conduct that did not occur and whether it produces a materially different understanding or impression from the unaltered original;
    • whether the communication includes the required statement that the image, audio recording, or video recording has been manipulated;
    • which party created, paid for, published, or distributed the communication;
    • whether a statutory exception applies; and
    • what records support the decision to label, exclude, or stop the communication.

    The statute does not prescribe placement, font size, duration, or exact wording beyond requiring a statement that the media was manipulated. Keeping supporting records is an operational recommendation, not an express duty imposed by Oregon Laws 2024, chapter 62.

    Oregon Laws 2024, chapter 62 took effect on passage under an emergency clause. A communication that may satisfy both the campaign-communication and synthetic-media definitions should receive legal review before distribution.

    Bottom Line

    Oregon Laws 2024, chapter 62 does not attempt to regulate every use of artificial intelligence in politics. It establishes a targeted rule for campaign communications containing realistic synthetic media: disclose the manipulation, account for the distribution context, and understand the enforcement path before publication.

    That is a modest statutory footprint with a practical consequence. Campaign and platform teams need a repeatable way to distinguish ordinary editing from a realistic false depiction, and they need enough documentation to explain the decision later.

    Idaho offers a useful next comparison, but for a different reason. Idaho Senate Bill 1227—enacted as Session Law Chapter 71 and adding Chapter 70, Title 33, Idaho Code—moves from voter disclosure to school-system governance. Together, the laws show how state AI regulation is developing through separate, domain-specific controls rather than one uniform definition of responsible AI.

    Sources

  • Pennsylvania’s AI Companion Bill Clears the House. What Would It Require?

    Pennsylvania’s AI Companion Bill Clears the House. What Would It Require?

    Pennsylvania’s AI Companion Bill Clears the House. What Would It Require?

    Pennsylvania is moving a proposed AI companion-safety law into its next legislative stage.

    House Bill 2006, the AI Companion Safety Act, passed the Pennsylvania House of Representatives 133–70 on September 28, 2026, according to the bill’s official history. The measure is not law. It still would need Senate action and the remaining steps in Pennsylvania’s legislative process before it could create enforceable duties.

    But the bill is significant because it brings several separate product-safety concerns into one proposed framework: crisis escalation, recurring disclosure that the user is interacting with a machine, restrictions for minors, age assurance, parental consent, data limits, and Attorney General enforcement.

    The bill targets relationship-oriented AI

    HB 2006 would apply to an “AI companion,” defined as a system that simulates sustained human-like relationships by retaining interaction history, engaging in emotion-based interactions, and maintaining ongoing personal dialogues designed to mimic interpersonal relationships.

    The definition would not automatically cover every chatbot. It excludes a business customer-service system that does not engage in emotion-based interactions or ongoing personal conversations designed to mimic interpersonal relationships. It also excludes a system used solely for a business’s internal purposes.

    That distinction matters. The bill is aimed at products designed to create an ongoing relationship with a user, not simply every automated interface that answers questions or performs a business function.

    Crisis response would become a product requirement

    The proposed act would prohibit an operator from providing an AI companion unless the operator implements and maintains specified safety protocols.

    Those protocols would have to refer a user to a crisis center, including the 988 Suicide and Crisis Lifeline, when the user expresses suicidal ideation or self-harm—including expressions relating to eating disorders—or indicates an interest in or intent to harm others.

    The operator also would have to maintain protocols designed to prevent the AI companion from:

    • assisting or encouraging a suicide attempt;
    • assisting or encouraging an act of violence;
    • generating content that describes how to commit suicide, self-harm, or violence against others; or
    • discouraging a user from seeking help outside the AI companion.

    Operators would have to publish details of those protocols on a publicly accessible website. That requirement would make at least part of the safety design externally reviewable, although the bill does not turn a published protocol into proof that the product complies in practice.

    The disclosure rule is continuous, not one-time

    If a reasonable person interacting with an AI companion could be misled into believing the interaction is with a human, the operator would have to provide a clear and conspicuous notice that the companion is artificially generated and not human.

    The notice would have to remain on screen during the interaction, appear at the beginning of each interaction, and reappear at least once every two hours. The bill also would require the interaction to pause for two minutes while the recurring notice is displayed, and the notice would have to remind the user to take a break. The notice would have to be provided in the language used by the user.

    This is more than a one-time onboarding disclosure. It would require an operator to treat the user’s continuing understanding of the system’s identity as a product-control issue.

    Minor protections reach content and relationship design

    For an AI companion offered to users the operator knows or should know are minors, the bill would require a disclosure that AI companions may not be suitable for some minors. The operator could not allow a minor to interact without verifiable parental consent.

    For minor users, operators would have to take reasonable measures to prevent the companion from producing or generating:

    • sexually explicit visual material, dialogue, or roleplay;
    • instructions or suggestions that a minor create, transmit, or share sexually explicit images;
    • content encouraging, directing, requesting, or suggesting that a minor engage in sexually explicit conduct or sexual contact with another person;
    • content designed to isolate a minor from family or friends; or
    • content encouraging a minor to withhold information from a parent or other trusted adult.

    The bill also would require operators to prevent the companion from generating artificially created child sexual abuse material for any user. And the companion could not claim to be human or generate output contradicting the required nonhuman disclosure.

    These provisions move beyond age-gating. They would regulate what the product may say and how it may shape a minor’s relationship with the system after access is granted.

    Age assurance and parental consent would create a separate data problem

    Before allowing a person in Pennsylvania to access an AI companion, the operator would have to request age information and determine whether the person is a minor using commercially available methods reasonably designed for accuracy.

    The bill lists possible methods including age inference from account history, content analysis, behavioral signals, or algorithmic and heuristic methods; commercially available age- or identity-assurance databases; and methods relying on publicly available data connected to a verified email address.

    The operator could not require a government-issued identification document for age assurance. If the process determines that the user is a minor, the operator would have to obtain verifiable parental consent before allowing access.

    The proposed data rules would limit the use of age-assurance and parental-consent information to assurance, consent, and demonstrating compliance. The operator could not sell, rent, share, or otherwise disclose that information except to a contracted service provider performing those functions. Personally identifiable information obtained for age assurance or parental consent could not be retained longer than 24 hours.

    For companies, this means the compliance design would not end with selecting an age-assurance vendor. The operator would also need a defensible data map, retention schedule, vendor contract, and evidence that the information was not reused for unrelated purposes.

    The Attorney General would enforce the act

    HB 2006 would authorize the Pennsylvania Attorney General to issue guidance or promulgate regulations needed to carry out the act and would assign enforcement to the Attorney General.

    An operator violating the act could face a civil penalty of up to $100,000 per day for each violation, along with additional remedies a court considers appropriate. A court also could issue injunctive relief upon a showing of cause.

    The bill would require annual reporting beginning July 1, 2028. Operators would report deidentified information to the Attorney General, including crisis referrals, protocols addressing suicidal ideation and related content, minor-safety measures, and age-assurance and parental-consent procedures. The Attorney General would publish the collected information.

    If enacted, the act would take effect 180 days after enactment. Those dates are contingent. The bill’s current text does not create a present compliance deadline because the measure remains pending.

    What companies should watch next

    The immediate legal question is procedural: whether the Senate takes up the House-passed measure and whether the text changes again. The posted PN 3747 text is an amended House version, so a later Senate amendment or substitute could change the duties described here.

    The operational question is already clearer. Companies offering relationship-oriented AI should identify which products retain interaction history, simulate personal relationships, or use emotional engagement before assuming that a general chatbot policy answers the bill’s concerns.

    The bill points toward a control structure built around five questions:

    1. When must the product disclose that it is not human, and how is recurring notice proved?
    2. What happens when a user expresses self-harm, suicidal intent, or an intent to harm someone else?
    3. Which content and engagement features are disabled for minors?
    4. How are age assurance and parental consent performed without creating a larger personal-data problem?
    5. What records demonstrate that the operator’s protocols worked as designed?

    Pennsylvania has not answered those questions through enacted law yet. But HB 2006 shows how quickly AI companion regulation is moving from broad safety language toward specific product behavior, data handling, reporting, and enforcement requirements.

    Sources

    This article describes a pending bill and is general information, not legal advice. The bill’s text, amendments, procedural status, and any later Senate version should be checked before relying on it.

  • Massachusetts’ Pending AI Bill Would Reach Certain AI Systems Used in Decisions Concerning Legal Services

    Massachusetts’ Pending AI Bill Would Reach Certain AI Systems Used in Decisions Concerning Legal Services

    Massachusetts’ Pending AI Bill Would Reach Certain AI Systems Used in Decisions Concerning Legal Services

    H.97 remains in House Ways and Means, with no new official action since December 2025. If enacted, the proposal would impose risk-management, disclosure, and anti-discrimination duties on certain developers and deployers of high-risk AI systems.

    Massachusetts lawmakers are still considering a broad proposal to regulate certain high-risk artificial intelligence systems, including systems used in legal services. But the measure—H.97, House Docket 4053—is not law, and its last recorded legislative action came nearly nine months ago.

    The bill was filed on January 17, 2025, and referred to the Joint Committee on Advanced Information Technology, the Internet and Cybersecurity on February 27, 2025. The committee held a public hearing that included H.97 on September 11, 2025, according to the Legislature’s hearing record and archived webcast.

    On December 24, 2025, the Legislature recorded H.97 as “Accompanied by H94,” reported it favorably from committee, and referred it to House Ways and Means. As of September 20, 2026, the bill remains pending there, with no later official action listed in its legislative history.

    What H.97 would cover

    The proposal would regulate “high-risk” AI systems that make, or are a substantial factor in making, consequential decisions. A consequential decision under the bill may concern education enrollment or an education opportunity, employment or an employment opportunity, a financial or lending service, an essential government service, health-care services, housing, insurance, or a legal service.

    That scope matters because the bill is not confined to consumer-facing chatbots or generative-AI tools. It is aimed at systems that can materially affect a person’s access to services, opportunities, or benefits in consequential settings.

    The bill’s text would place obligations on both developers and deployers of covered systems. Among other provisions, it would require:

    • developer documentation about a system’s intended use, known limitations, and risk-management practices;
    • deployer risk-management programs and recurring impact assessments;
    • measures intended to prevent unlawful discrimination;
    • notices to consumers before a high-risk AI system makes, or is a substantial factor in making, a consequential decision concerning them;
    • explanations for certain adverse decisions;
    • correction and appeal opportunities in specified circumstances;
    • public disclosures concerning covered systems; and
    • general disclosure when consumers interact with an AI system, unless it would be obvious to a reasonable person that the person is interacting with an AI system.

    The bill expressly includes a “legal service” among the areas in which a consequential decision may occur. That does not mean every AI tool used by a law firm or other legal-services organization would be covered. Coverage would turn on the bill’s definitions, exclusions, and exemptions—including whether the system makes, or is a substantial factor in making, a decision that has a material legal or similarly significant effect on the provision or denial of, or cost or terms for, a legal service to a Massachusetts resident.

    Enforcement would rest with the Attorney General

    H.97 would assign enforcement exclusively to the Massachusetts Attorney General. A violation would constitute an unfair trade practice under Chapter 93A, the state’s consumer-protection law.

    The proposal expressly states that it would not create a private right of action. If enacted, deployers would have to notify Massachusetts-resident consumers before a covered consequential decision and, following an adverse decision, give them opportunities to correct incorrect personal data and appeal. Human review on appeal would be required only if technically feasible, and the appeal opportunity itself would be subject to the bill’s best-interest and life-or-safety exception. H.97 would not authorize a private action under the proposed chapter.

    No current compliance deadline

    Because H.97 has not passed, it imposes no current legal duties and has no operative compliance date.

    As drafted, the bill says it would take effect no later than six months after passage, and many substantive obligations would have to be satisfied no later than six months after the law’s effective date. Those timelines are contingent on enactment and should not be treated as active deadlines.

    The H.94 reference does not establish a merger

    The December 2025 history entry linking H.97 to H.94 is worth reading carefully. The Legislature’s records show that H.97 was “Accompanied by H94,” then received a favorable committee report and a referral to House Ways and Means.

    That sequence reasonably indicates that H.97 was the measure that procedurally advanced at that point. It does not, however, establish that H.94 was merged into H.97, incorporated into it, or rewritten as part of it. A stronger conclusion would require an official committee report, executive-session record, poll documentation, or comparable legislative material explaining the relationship between the two bills.

    For now, H.97 is best understood as a pending Massachusetts AI-governance proposal—one with potentially significant reach, including into legal services, but without present legal effect.

  • Oklahoma Judge’s Reported ChatGPT Citation Failure Puts AI Verification On The Bench

    Oklahoma Judge’s Reported ChatGPT Citation Failure Puts AI Verification On The Bench

    Oklahoma Judge's Reported ChatGPT Citation Failure Puts AI Verification On The Bench

    The next AI-citation case is not about a lawyer filing a brief with fake authority.

    It is about a judge's order.

    In Stephens County, Oklahoma, Associate District Judge Lawrence M. Wheeler denied a mother's motion for a psychological evaluation in a paternity and custody case. The order cited two Oklahoma Court of Civil Appeals decisions that the challenger later told the Oklahoma Supreme Court did not exist. News reports, citing an August letter from Stephens County District Attorney Jason Hicks to the Oklahoma Attorney General, say Wheeler later told an Oklahoma State Bureau of Investigation investigator that he used ChatGPT for research and that at least two case citations generated by ChatGPT and included in the order did not exist.

    That makes the episode different from the familiar lawyer-sanctions pattern. The basic verification duty is the same: a legal authority must exist, and it must support the proposition for which it is used. But when the false authority appears in a judicial order, the harm profile changes. The order itself becomes the source of legal pressure. It can impose fees, reprimand counsel, change the trajectory of a family-law case, and force the affected party to seek emergency appellate relief before the error is corrected.

    The record also shows the case did not end with a headline. The challenged order was vacated. The public reprimand was purged. Related attorney-fee and penalty issues were stayed or reversed for evidentiary hearings. The Oklahoma Supreme Court original proceeding was dismissed after those corrective orders. Wheeler later recused from the underlying case.

    That is the full story: a custody fight, an AI-tainted order, a writ petition, a corrective retreat, a dismissal, a recusal, and a later public investigation report that did not become a criminal prosecution.

    The Case

    The underlying case is Adriane E. Capers v. Marvin A. Jones, No. FP-2022-16, in Stephens County District Court. The Stephens County docket shows the paternity action was filed in September 2022.

    By 2025, the docket reflected continuing custody, visitation, attorney-fee, and motion practice. On September 29, 2025, Capers filed a motion requesting a psychological evaluation and mental-health testing and assessment of Jones. The motion invoked Oklahoma's mental-examination procedure, and the later Supreme Court filing says it also cited Oklahoma's family-law mental-examination statute.

    On November 17, 2025, the Stephens County court filed a "Notice of Decision & Order" denying the motion. The order itself was signed November 19.

    The order said the paternity action had been pending for more than three years under a temporary order. It said Jones had temporary sole custody under a prior order, while Capers had no visitation. It also said Capers had offered no specific facts, medical evidence, or other support showing that Jones's mental condition was in controversy or that a mental examination was necessary.

    The order could have stopped with that case-specific analysis. It did not.

    After quoting the U.S. Supreme Court's Schlagenhauf v. Holder standard for mental examinations, the order stated that the Oklahoma Court of Civil Appeals had "explicitly adopted" Schlagenhauf for Oklahoma section 3235 examinations in Cummings v. Cimarron Elevator Co., 1998 OK CIV APP 44, 958 P.2d 594. It also cited Hawkins v. Linhart, 2009 OK CIV APP 106, 234 P.3d 240, for the proposition that section 3235 is not self-executing and requires an "in controversy" and "good cause" showing.

    Those citations became the problem.

    The Fake Cases Were Not A Footnote

    The fake cases mattered because the order used them as part of the legal analysis supporting denial of the examination motion.

    The order also went further. It found Capers's motion "frivolous in nature" and intended to harass Jones. It awarded Jones "whatever attorneys fees and costs he incurred" because of the motion, added those amounts to a prior fee award, publicly reprimanded Capers's counsel for "stooping to such frivolous trial tactics," and warned that future filings of similar character could face sanctions under 12 O.S. section 2011.

    Capers then went to the Oklahoma Supreme Court.

    On February 19, 2026, she filed an application to assume original jurisdiction and a petition for writ of prohibition in Capers v. Wheeler, No. PR-123810. The proceeding named Wheeler, not Jones, as respondent and arose from Stephens County case FP-2022-16.

    The brief in support did the citation work the trial-court order had not done. It said the order's citation "1998 OK CIV APP 44" actually yields Robbins v. Robbins, a custody-jurisdiction/ex parte-communication case that does not address section 3235 or Schlagenhauf. It said "958 P.2d 594" points instead to Harpole v. State, an Idaho case, not an Oklahoma Court of Civil Appeals decision adopting Schlagenhauf. It said "2009 OK CIV APP 106" yields Bunch v. Terpenning, a Consumer Credit Code case, and "234 P.3d 240" points to a Washington case, not the claimed Oklahoma authority.

    The brief's conclusion was cautious but clear: Cummings v. Cimarron Elevator Co. and Hawkins v. Linhart "appear to be non-existent."

    That careful wording is important. The court filing did not need to prove a grand theory of AI. It showed that the authorities named in the trial-court order did not match the reporter citations or Oklahoma appellate numbers the order gave them. For a litigant facing fees, sanctions warnings, and a public reprimand of counsel, that was enough to make the order unstable.

    The Corrective Orders

    The first correction came quickly.

    On February 26, 2026, the Stephens County court entered an agreed order. It vacated the November order denying the psychological-evaluation motion, set the motion for an evidentiary hearing, and purged the public reprimand. It also stayed the October 14 attorney-fee decision and daily $50 penalty, and it set related fee issues for reconsideration at an evidentiary hearing.

    The next day, the court entered an amended agreed order. The amendment made the cleanup more explicit. It vacated the finding that the psychological-evaluation motion was frivolous and vacated the $50 daily penalty.

    On March 3, Capers moved to dismiss the Supreme Court proceeding. The motion said Wheeler had entered orders vacating the previous decisions complained of and had taken corrective action. It argued the case could be voluntarily dismissed or treated as moot because effective relief was no longer needed.

    The Oklahoma Supreme Court granted the dismissal that same day and struck the scheduled referee hearing.

    That procedural sequence matters. The Supreme Court did not issue a merits opinion deciding whether Wheeler used AI or whether the nonexistent cases independently required relief. The challenge was dismissed after the trial court corrected the orders. The public record therefore supports a narrower, more precise conclusion: the order with the nonexistent citations was challenged, the challenged provisions were vacated or corrected, and the appellate original proceeding ended because the corrective action removed the need for emergency relief.

    The Recusal

    The docket did not end there.

    On April 20, 2026, Wheeler entered an order of disqualification. The order said that, after further consideration of the facts and circumstances involved in the litigation, the court recused itself and asked for another judge to be assigned. On April 27, the Stephens County docket recorded an assignment order.

    That means the case moved to another judge after the fake-citation episode. It does not, by itself, tell us the full reason for the recusal. But in context, it is part of the case's procedural afterlife: the same judge whose order cited the two nonexistent cases vacated the order, corrected related sanctions and fee issues, and then stepped away from the case.

    The Investigation Reporting

    The AI part became public months later.

    NewsOn6 reported that Stephens County District Attorney Jason Hicks sent an August 17, 2026 letter to Oklahoma Attorney General Gentner Drummond asking that Hicks's office be disqualified from any potential prosecution because Wheeler regularly presided over cases involving the office. According to that report, Hicks wrote that allegations referred by the Oklahoma Council on Judicial Complaints included claims that Wheeler used ChatGPT to produce a court order; Hicks also wrote that Wheeler acknowledged using case citations generated by ChatGPT and that at least two citations in the order did not exist.

    KFOR/Yahoo and NewsNation reported the same core point, and Reason's Volokh Conspiracy quoted Reuters as reporting the same attribution to the August 17 letter: Wheeler allegedly told an OSBI investigator he used ChatGPT for research, wrote the order himself, and included two nonexistent citations generated by ChatGPT. NewsOn6 also reported that Hicks's letter referenced separate allegations, including an allegation that Wheeler offered to amend the order in exchange for dismissal of a writ seeking Oklahoma Supreme Court relief, and allegations involving jury deliberations.

    Those are investigative allegations and reported statements from a letter. They should not be overstated. The Oklahoma Attorney General's office told NewsOn6 that its Criminal Justice Division reviewed the OSBI investigation and determined that the evidence did not support a criminal prosecution. The same statement said the Oklahoma Supreme Court and the Court on the Judiciary have ultimate jurisdiction over judicial discipline for inappropriate judicial behavior, regardless of whether conduct violates a criminal statute.

    That distinction is critical. No criminal prosecution is not the same thing as "nothing happened." It means the attorney general did not see a criminal case. The judicial-discipline question belongs somewhere else.

    Why This Is Different From Lawyer Hallucination Cases

    Most AI citation failures reach public view because a lawyer filed a bad brief. Courts then respond with sanctions, fee awards, bar referrals, brief-striking orders, or warnings.

    This case inverts that pattern.

    Here, the trial-court order itself included the false authorities. The litigant then had to challenge the order by writ. That is a different institutional risk because judges do not merely advocate. They decide.

    When a lawyer's AI-generated citation fails, the court can reject it. When a judge's AI-generated citation fails, the order may already have shifted leverage, imposed costs, changed hearing posture, criticized counsel, or forced appellate intervention before the defect is corrected.

    That does not mean judges can never use AI. Courts are already experimenting with AI for administration, drafting support, translation, transcript workflows, research, and self-help tools. The lesson is narrower and more serious: if AI enters the path toward an order, the judge or chambers must verify the legal source before it becomes judicial authority.

    The verification standard cannot be lower on the bench than it is for lawyers.

    What Court Systems Should Learn

    The practical fix is not mysterious.

    First, chambers should separate drafting assistance from authority verification. A tool can help organize issues or locate possible sources, but no cited case should enter an order until a human verifies that the case exists, that the citation matches, and that the case supports the proposition used.

    Second, court systems should treat citation checking as part of order quality control. That is especially important for orders imposing fees, sanctions, contempt exposure, professional criticism, or custody-related consequences.

    Third, judges and staff need disclosure and escalation rules. If an order is later found to contain AI-generated false authority, the correction process should be prompt, transparent, and docketed. Vacatur and amended orders can fix the litigation problem, but the system also needs a way to document how the failure happened and how recurrence will be prevented.

    Fourth, AI policies for courts should cover judicial work, not only lawyer filings. Many court AI rules focus on lawyers, parties, and self-represented litigants. This episode shows why internal judicial workflows need the same discipline.

    Fifth, courts should preserve the difference between technological assistance and judicial responsibility. The order is the court's act. A model cannot bear responsibility for a citation that becomes part of a judicial ruling. The human legal institution owns that step.

    Bottom Line

    The Stephens County episode is a warning from the other side of the bench.

    In Capers v. Jones, a trial-court order denying a psychological-evaluation motion cited two Oklahoma appellate cases that the later Supreme Court filing showed did not match real Oklahoma authority. The order imposed consequences beyond denial of the motion. The affected party sought extraordinary relief. The challenged order and related sanctions issues were vacated or corrected. The Supreme Court proceeding was dismissed after that correction. The judge later recused. News reports, citing the district attorney's letter, say the judge acknowledged to investigators that the nonexistent citations came from ChatGPT research.

    The legal system already knows what to say to lawyers: verify before filing.

    This case adds the judicial version: verify before ruling.

    Sources and Related Clearon Coverage

  • China’s Top Court Turns AI Disputes Into Litigation Rules

    China’s Top Court Turns AI Disputes Into Litigation Rules

    China's Top Court Turns AI Disputes Into Litigation Rules

    China's Supreme People's Court has moved AI governance from policy abstraction into courtroom administration.

    On September 7, 2026, the court released Opinions on lawfully hearing AI-related dispute cases. The court described the document as the first AI-related judicial adjudication-rule document issued by a national highest court. It has five parts and 24 articles, and it directs Chinese courts on how to approach AI disputes under existing law.

    That distinction matters. The Opinions are not a standalone national AI statute. They do not create a single licensing regime for AI systems, and the court's own materials say China has not yet enacted a specialized AI law. Instead, the Opinions use existing legal frameworks, including civil, cybersecurity, data security, copyright, anti-unfair-competition, consumer-protection, personal-information, and civil-procedure laws, to give courts a working map for AI litigation.

    For companies, that may be more important than it sounds. A statute tells the market what the legislature has commanded. A top-court adjudication document tells litigants how disputes are likely to be framed when something goes wrong.

    The practical message is direct: companies operating AI systems in or connected to China should expect judges to ask who controlled the system, what risks were foreseeable, what safeguards were used, what evidence can be produced, and whether AI-assisted filings or outputs were verified before they reached a court, consumer, user, or counterparty.

    What The Opinions Cover

    The Opinions are broad. They do not focus only on one fashionable AI problem, such as hallucinated legal citations or deepfakes. They organize AI disputes across several recurring litigation categories.

    First, they address tort liability for AI-related harm. The court says liability should be assessed under existing laws, and that fault should generally be the baseline where no statute imposes strict liability or presumed fault. In judging fault, courts are told to consider the AI application's context, degree of autonomy, transparency of technology and information, risk level, risk-reduction measures, and the user's ability to foresee and control the harmful conduct.

    That is an important governance signal. The inquiry is not just "did the model cause harm?" It is also whether the developer, provider, user, seller, or other actor had a practical ability to understand and reduce the risk.

    Second, the Opinions cover personality rights and privacy. They address AI face-swapping, voice cloning, digital resurrection of deceased people, doxxing, human search, and AI-enabled invasions of privacy. The court's Q&A emphasizes that the document is meant to protect name, likeness, reputation, privacy, voice, and related personality interests while still allowing lawful innovation.

    Third, the Opinions address generative-AI service-provider responsibility. The court's materials describe a notice-and-action structure for some AI-generated personality-rights harms: if generative AI automatically creates content that infringes reputation or privacy interests, and the rightsholder gives a proper notice, the service provider may face liability if it does not take necessary measures in time. The court also addresses users who intentionally induce infringing AI outputs through prompts.

    This is not a simple "platforms always liable" rule. It is closer to a governance question about knowledge, notice, control, and response. The Q&A explains that generative-AI providers may have a basis to rely on a notice-removal style approach because they cannot predict every user prompt or generated output in advance, but that protection is not a license to ignore obvious or notified harms.

    Fourth, the Opinions address consumer and product disputes. They include algorithmic price discrimination, fake celebrity endorsements, AI product liability, autonomous-driving and driver-assistance accidents, and the evidentiary role of vehicle or system data. For physical AI products, courts are told to look at defects, use scenarios, warnings, system limitations, updates, user control, and applicable standards. For automated or assisted driving accidents, courts may require manufacturers, sellers, operators, or data controllers to provide truthful and complete event records where needed to determine the facts.

    Fifth, the Opinions address AI intellectual property disputes. They discuss AI-generated content, open-source software, patent eligibility and inventorship, technology contracts, data sets, trade secrets, unfair competition, and attacks on AI operational security through techniques such as malicious labeling or adversarial examples.

    Finally, they address procedure. Courts are directed to improve fact-finding and evidence review in AI-related cases, use technical expertise where needed, and sanction AI-assisted misconduct in litigation. The Opinions specifically state that litigation participants who use AI to generate pleadings, case-search reports, or other submitted materials should verify their truth and accuracy before submission, disclose AI assistance to the court, and bear responsibility for the content.

    That last piece should sound familiar to lawyers outside China. It is the same institutional anxiety appearing in U.S. courts, where AI tools have created fake-citation problems, judicial-process questions, and new pressure to document human review. Clearon recently covered a U.S. appellate example involving judicial AI use and reassignment questions. The China Opinions show that the courtroom-governance problem is not local.

    The IP Piece Is Carefully Limited

    The most commercially important part may be the IP section, but the court is careful about what it does and does not decide.

    The Opinions say that when AI-generated content allegedly infringes copyright, courts should consider the type of AI service, industry characteristics, training-data sources, each party's participation, necessary measures taken, and profit. The Q&A adds that a party should not escape responsibility merely because the challenged content was generated by AI. Responsibility should be tied to control, duty of care, role in the generation process, training data, preventive measures, and economic benefit.

    The Opinions also address evidence. A claimant alleging that an AI developer or provider infringed copyright must make a preliminary showing that the challenged content was AI-generated and substantially similar to the claimant's work. But if the developer raises a non-infringement defense, courts may require evidence about training-data sources, training process records, model operating modes, and scientific or theoretical bases where necessary.

    That is a serious litigation-design issue for AI companies. It means that documentation around training data, model operation, filtering, and deployment cannot be treated only as internal engineering history. It may become litigation evidence.

    At the same time, the court leaves two contested issues unresolved. The Q&A says the Opinions do not decide copyrightability of AI-generated content or the legal characterization of using others' works to train large models, because views remain divided and further experience is needed.

    That restraint is important. It means companies should not read the Opinions as a final answer to every China AI copyright question. The better reading is that the court is building a litigation framework first: responsibility, evidence, duties, and dispute handling, with some harder substantive questions reserved for later cases or rules.

    Technology Is Not An Exemption Card

    One of the court's strongest themes is that AI technology does not erase responsibility.

    The Supreme People's Court's accompanying analysis says technology is not an "exemption card." That framing is not a statutory test, but it captures the practical posture of the Opinions. Courts are being told to look past generic statements that AI is autonomous, unpredictable, or technically complex, and instead ask what the relevant actor could know, prevent, verify, explain, or control.

    That matters across the whole document.

    For generative-AI providers, the question becomes whether the provider had notice of infringing content and whether it took necessary measures. The accompanying analysis also discusses the red-flag principle under existing Civil Code rules, while acknowledging that the Opinions do not create a standalone red-flag provision. For users, the question becomes whether the user intentionally induced harmful output or knew of a prior work and used AI to generate substantially similar content without a valid defense. For product sellers and manufacturers, the question becomes whether warnings, usage limits, system data, and foreseeable risks were handled accurately. For litigants and lawyers, the question becomes whether AI-generated submissions were verified and disclosed.

    This is the governance lesson: in AI disputes, courts may not be satisfied with broad product descriptions. They may want records.

    Companies should be ready to explain how the system was designed, what warnings were given, what safeguards were available, how outputs were monitored, what contractual limits applied, what logs exist, how user reports and notices were handled, and who made escalation decisions.

    The Courtroom-Use Rule Is A Compliance Signal

    The litigation-materials rule is one of the clearest parts of the Opinions.

    The court says litigation participants who submit pleadings, case-search reports, or other materials generated with AI should carefully verify the truth and accuracy of relevant laws, judicial interpretations, cases, and other content before submitting them. They should also explain the AI assistance to the court and bear responsibility for authenticity and accuracy.

    That is not just a courtroom etiquette point. It is a compliance signal for law firms, in-house litigation teams, expert witnesses, and vendors that sell legal AI tools.

    A legal AI workflow that cannot show who checked the output, what source was reviewed, and what changed before filing is going to be weak under this kind of rule. The same problem appears in U.S. practice: courts are not usually interested in whether a lawyer used a fashionable tool. They are interested in whether the lawyer verified what was filed.

    For companies, this means AI use policies should distinguish between ordinary drafting assistance and materials that become evidence, legal argument, expert work, regulatory submissions, customer notices, or public commitments. The higher the consequence, the stronger the source-control and human-review record should be.

    What Companies Should Do Now

    The Opinions are formally about Chinese courts, but they are useful beyond China because they show how judges may organize AI disputes.

    First, map AI risk by dispute category, not only by product category. A single AI system can produce privacy claims, consumer claims, IP claims, product-liability questions, contract disputes, evidence issues, and unfair-competition allegations. Legal teams should know which parts of the product create which litigation records.

    Second, preserve system and data documentation that may become evidence. Training-data provenance, model-operation records, filtering decisions, prompt logs, output histories, user notices, complaint records, takedown steps, and human-review records can all become important. The point is not to hoard data without limits. It is to align retention, privacy, and litigation-readiness before a dispute starts.

    Third, update notice-and-response workflows for AI-generated harms. If a user reports an AI-generated impersonation, voice clone, defamatory output, privacy invasion, or infringing generation, the company should have a defensible triage path. That path should record what notice was received, whether it was complete, what content or prompt was involved, what measure was taken, and when.

    Fourth, review AI product warnings and marketing. The Opinions tie responsibility to use scenarios, system limitations, foreseeable risks, and whether users were accurately informed. Overstating autonomy, reliability, or safety can create downstream litigation risk.

    Fifth, separate AI-assisted legal work from ordinary productivity use. Litigation materials, case-search reports, evidence summaries, and expert materials need verification and disclosure controls. A legal department can allow AI assistance and still require source validation before anything is submitted.

    Finally, avoid treating unresolved questions as settled. The court deliberately left AI-generated-content copyrightability and training-data legality open. That leaves room for future cases, regulations, or guidance. Companies should keep legal positions flexible and source-bound rather than building policies around overconfident predictions.

    The Takeaway

    China's Supreme People's Court has not solved every AI law question. It has done something more operational: it has told courts how to begin hearing AI disputes.

    The Opinions organize AI litigation around responsibility, control, evidence, verification, notice, product warnings, data use, IP documentation, and courtroom integrity. That is the practical center of AI governance. The hard questions are not limited to whether an AI system is powerful. They include who controlled it, who benefited from it, who could foresee harm, who received notice, what records exist, and whether humans verified the legally consequential output.

    For companies, the lesson is not to treat China as a silo. The themes in the Opinions match broader global pressure: courts and regulators increasingly expect AI governance to be explainable in records, workflows, controls, and human accountability.

    The companies best positioned for this environment will not be the ones with the longest AI policy. They will be the ones that can prove, in a dispute, how their systems were governed before the dispute arrived.

  • Federal Cyber Agencies Turn AI Model Distillation Into a Governance Issue

    Federal Cyber Agencies Turn AI Model Distillation Into a Governance Issue

    Federal Cyber Agencies Turn AI Model Distillation Into a Governance Issue

    AI model distillation is no longer only a research method, a competition issue, or a private terms-of-service dispute between model providers and would-be imitators.

    CISA Cybersecurity Advisory AA26-251A, issued by NSA, CISA, and FBI, pushes the issue into cybersecurity and national-security governance. The advisory says China-based AI companies are conducting systematic extraction of proprietary functionalities and capabilities from U.S. AI companies' models through industrial-scale knowledge distillation campaigns. It also recommends account-level detection, targeted response changes, and cross-organization intelligence sharing.

    That does not make the advisory a new binding AI regulation. It is guidance and threat reporting, not a statute, rule, court judgment, or adjudicated finding. But it may still shape the expected control environment.

    The practical legal point is direct: if federal cyber agencies now describe malicious industrial-scale distillation as a coordinated threat to U.S. AI companies, then access governance, subscription controls, API contracts, evidence preservation, and incident response belong in legal and compliance review too.

    What The Advisory Says

    The advisory distinguishes legitimate distillation from the activity it is warning about.

    Knowledge distillation can be a lawful and useful AI-development technique. It can be used to transfer capabilities from a larger model to a smaller one, improve efficiency, support research, or build products within authorized boundaries. The agencies' concern is different: "aggressive, malicious, and targeted" industrial-scale distillation activity that extracts restricted proprietary functionality and capabilities from U.S. frontier AI models.

    According to the advisory, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, likely with Chinese government awareness, extracted billions of tokens across millions of exchanges or requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024. The advisory says these campaigns were not incidental experimentation but a systematic strategy to shorten development timelines and reduce the financial cost of building frontier models.

    Those are agency assertions, not adjudicated findings. Companies assessing the allegations should keep that distinction clear in public statements, customer notices, contract disputes, and enforcement positions.

    The described access routes are also important. The agencies say requests were routed through native APIs, remote cloud providers, third-party aggregators, and gray-market API proxies referred to as "transfer stations." The advisory also describes bulk procurement of premium subscriptions shared across teams of developers.

    The tactics identified by the agencies include chain-of-thought reasoning extraction, automated failover between pathways during blocking attempts, and quality evaluation frameworks designed to detect defensive countermeasures. Those details matter because they move the issue away from ordinary high-volume usage and toward an adversarial pattern: distributed access, evasion of traceability, and adaptation when a provider tries to block activity.

    The advisory then recommends three immediate actions: comprehensive detection and mitigation, targeted response changes, and cross-organization intelligence sharing. Those recommendations are operational, but the compliance implications are broader.

    Why It Matters Legally

    The advisory turns model distillation into a governance question because the alleged behavior sits across several legal and operational domains at once.

    First, there is the contractual layer. If a model provider's terms restrict scraping, automated extraction, reverse engineering, model training, resale, account sharing, or access from restricted regions, then suspicious distillation activity will often become a terms-of-use enforcement matter. That requires a record of what terms applied, what product path was used, what logs support the violation, and what response the company took.

    Second, there is the account-governance layer. The advisory's indicators include subscription-to-usage ratios, immediate maximum usage from new accounts, enterprise-scale throughput patterns, shared accounts from multiple IP addresses or user agents, 24/7 sustained usage without human variation, anomalous subscription-to-API usage ratios, coordinated pathway switching, and metadata sanitization. Those are not only security signals. They are governance signals about identity, authorization, and permitted use.

    Third, there is the intermediary layer. The advisory identifies native APIs, cloud providers, third-party aggregators, and proxy networks. Model companies will need to ask whether aggregator agreements, cloud marketplace terms, resale limits, logging rights, audit rights, abuse reporting, geographic controls, and termination provisions support the response federal agencies are now recommending.

    Fourth, there is the incident-response layer. Industrial-scale distillation may not look like a classic breach involving stolen credentials or exfiltrated customer databases. It may look like permitted interfaces being used at impermissible scale for an impermissible purpose. A high-confidence distillation campaign may require legal hold decisions, evidence preservation, customer-impact analysis, law-enforcement referral evaluation, and executive reporting even if no system vulnerability was exploited.

    Finally, there is the communications layer. A provider that detects suspected distillation has to decide what to tell users, customers, aggregators, peer companies, the government, and possibly the public. Overstating attribution can create legal and commercial problems. Saying too little can undercut enforcement and ecosystem defense.

    Subscription And API Abuse Are Now Governance Signals

    One of the advisory's most important points is that subscription abuse and API abuse belong in the same picture.

    Many AI companies have treated consumer subscriptions, enterprise subscriptions, developer APIs, cloud channels, and aggregator access as different product surfaces with different controls. The advisory describes adversaries moving across those surfaces, including bulk premium-subscription procurement, shared accounts, remote cloud providers, third-party aggregators, and gray-market proxies.

    That creates a compliance design problem. If the abuse team sees suspicious subscription behavior but API security sees only permitted traffic, the company may miss the combined pattern. If an aggregator has logs the model provider cannot access, the provider may not be able to prove coordinated pathway switching. If identity verification is strong in enterprise contracts but weak in premium individual subscriptions, a determined actor may arbitrage the gap.

    The legal team should not try to run the detection program. But it should help define what records the program needs to preserve: account creation metadata, relevant terms, plan type, payment and subscription history, source IP and user-agent patterns, API-key identifiers and associated audit records, rate-limit history, model-selection history, aggregator identifiers, abuse tickets, warnings, suspensions, and internal escalation decisions. Retention must still respect privacy commitments, data-processing agreements, and legal limits.

    Contracts should also catch up. Provider terms should address account sharing, automated extraction, use of outputs to train competing models, resale or brokering of access, circumvention of regional or product restrictions, metadata obfuscation, and high-volume coordinated use. Aggregator and cloud arrangements should specify abuse-monitoring responsibilities, required logs, response timelines, data-sharing rights, and termination mechanics.

    Procurement teams should read the advisory from the other side as well. Enterprises buying frontier-model access through intermediaries should understand whether those intermediaries can meet abuse-detection, logging, and investigation obligations.

    Response Controls Raise Their Own Legal Questions

    The advisory recommends targeted response changes for high-confidence malicious distillation attempts. It specifically discusses approaches such as differential privacy or downgraded responses for suspected malicious distillation activity, and it recommends varying response changes across requests to reduce the payoff of extraction efforts.

    Those recommendations are significant, but they need governance.

    From a security perspective, the logic is understandable. If a provider can identify a malicious extraction campaign with high confidence, it may want to reduce the training value of its outputs. The advisory also points providers toward MITRE ATLAS and NIST's adversarial machine learning guidance, which provide structured language for attacks, mitigations, and lifecycle controls.

    From a legal and product perspective, response alteration raises hard questions. When is confidence high enough? Who approves the control? Could it affect innocent users caught in the same pathway? How will the provider document why it used a downgraded response, differential privacy technique, or other output modification?

    The answer should not be to avoid defensive controls. It should be to govern them.

    Companies should define decision thresholds, approval roles, rollback procedures, customer-impact review, and records for response changes. They should also decide in advance how they will handle researchers, auditors, red teams, and authorized evaluators, because those groups may generate patterns that resemble adversarial testing but are governed by permission. The advisory specifically recommends informing AI safety researchers and third-party evaluators of model changes while continuing to apply strong distillation mitigations.

    The advisory's recommendation to vary response changes across requests also requires care. Publicly restating the advisory's recommendation is one thing. Building internal playbooks that disclose exactly how to detect or defeat those controls is another. Legal and security teams should keep sensitive operational details limited to need-to-know channels and avoid turning public communications into a roadmap for evasion.

    What AI Companies Should Do Next

    AI companies do not need to treat the advisory as a statute. They should treat it as a clear statement of federal cyber-agency expectations.

    Start with classification. Define when suspected model distillation becomes a security incident, a trust-and-safety enforcement matter, a legal escalation, or all three. The trigger should account for volume, coordination, account-sharing indicators, circumvention signals, aggregator involvement, and attempts to bypass blocking.

    Then review the account-control stack. Subscription plans, enterprise workspaces, API organizations, developer accounts, payment patterns, reseller channels, and aggregator traffic should be correlated where policy and law permit. The advisory's indicators are useful because they are mostly behavioral rather than content-dependent: immediate maximum use, enterprise-scale throughput, 24/7 patterns, anomalous subscription-to-API ratios, shared accounts, coordinated pathway switching, and metadata sanitization.

    Next, update contracts and enforcement records. Terms should be clear enough to support enforcement against unauthorized model training, resale, account sharing, circumvention, and automated extraction. API and aggregator contracts should support investigation, logging, abuse response, and suspension or termination when needed.

    Build an information-sharing design before a major event. The advisory calls for cross-organization intelligence sharing across providers, clouds, and API aggregators. That sharing should have rules: what indicators can be shared, whether personal data is involved, how confidentiality is handled, how attribution is caveated, whether antitrust counsel should review competitor coordination, and when government reporting is appropriate.

    Finally, map the program to recognized security frameworks. The advisory points to MITRE ATLAS and NIST AI 100-2 E2025. That does not make either source binding law. But using a shared taxonomy can help legal, security, engineering, and procurement teams speak the same language when documenting attack patterns, mitigations, and control maturity.

    The Takeaway

    CISA AA26-251A is a cyber advisory, not a new AI statute. It does not create a licensing regime, impose direct regulatory penalties, or adjudicate the conduct it describes.

    But it still changes the governance conversation.

    The federal government is now framing industrial-scale malicious distillation as a coordinated threat involving account abuse, API access, aggregator pathways, proxy markets, adaptive evasion, and proprietary model capability extraction. That framing will likely influence customer expectations, contract negotiations, audit questions, incident-response planning, and enforcement posture.

    For AI companies, the practical lesson is not to declare all distillation suspect. Legitimate distillation remains part of AI development. The problem is unauthorized, targeted, industrial-scale extraction through pathways that evade the provider's rules and controls.

    That means the response has to be both technical and legal. Detection without enforceable terms is weak. Terms without logs are hard to act on. Response controls without governance create risk. Information sharing without rules can create confidentiality, privacy, attribution, and competition-law problems.

    The advisory's deeper message is that frontier-model access is now part of cybersecurity governance. The companies that operate those models will need to prove not only that they can build capable systems, but that they can govern access, detect abuse, preserve evidence, approve responses, and share what the ecosystem needs to know without overclaiming what the evidence shows.

  • The FRONTIER Act Narrows the Federal AI Preemption Fight

    The FRONTIER Act Narrows the Federal AI Preemption Fight

    The FRONTIER Act Narrows the Federal AI Preemption Fight

    The Great American AI Act draft was a warning shot.

    The FRONTIER Act is the narrower bill.

    On July 23, 2026, Representative Jay Obernolte introduced H.R. 9925, the Frontier Risk Oversight, National Transparency, Independent Evaluation, and Reporting Act, or FRONTIER Act, with Representative Lori Trahan and other bipartisan cosponsors. GovInfo lists the bill as introduced in the House and referred to the House Committee on Energy and Commerce and the House Committee on Science, Space, and Technology.

    That matters because the earlier Great American AI Act materials were still a discussion draft. Clearon's earlier coverage treated them that way. H.R. 9925 is different: it is introduced bill text, though still only a pending bill, and it shows where the sponsors moved after the first round of criticism.

    The short version is this: the bill still tries to create a federal rulebook for frontier AI risk. But the state-law preemption clause is more targeted than the broad discussion-draft fight suggested.

    What The Bill Would Cover

    The FRONTIER Act is not a general AI law for every company using automated tools.

    It is aimed at frontier models and frontier developers. The bill defines a frontier model as a foundation model trained using more than 10^26 integer or floating-point operations, including the original training run and later fine-tuning, reinforcement learning, or other substantial modification.

    It then builds tiered duties around developers that meet revenue and AI-development-spending thresholds. Some duties apply to frontier developers generally, while the public-framework, audit, registration, and independent-verification layers turn on the larger statutory tiers.

    A "large frontier developer" would have to have gross revenues in excess of $50 million and incur at least $1 billion in AI-related development expenditures, measured together with affiliates during the preceding 36-month period and determined as of the first day of each calendar month. A "very large frontier developer" would have to have gross revenues in excess of $5 billion and incur at least $10 billion in AI-related development expenditures under the same affiliate-inclusive, monthly measurement structure.

    Those thresholds are doing important work. The bill is not trying to regulate ordinary business AI deployments, routine SaaS use, or most smaller model builders in the same way. It is aimed at the companies training and operating the most capable frontier systems.

    The Public Framework Requirement

    For large frontier developers, the main operational duty starts with a public frontier AI framework.

    By the later of one year after enactment or 90 days after first qualifying as a large frontier developer, the developer would have to write, implement, comply with, and clearly publish a frontier AI framework on a public website.

    That framework would have to address how the developer identifies catastrophic-risk thresholds, assesses whether a model could cross those thresholds, reviews the results of risk assessment and mitigation before deployment or internal use, uses third parties to assess risk, updates the framework, secures nonpublic model weights, responds to critical safety incidents, and implements internal governance.

    This is more concrete than a voluntary responsible-AI pledge. It would turn frontier risk governance into a public compliance artifact.

    That does not mean every detail becomes public. The bill allows redactions to protect trade secrets, risk-prevention mechanisms, cybersecurity, public safety, national security, or compliance with federal or state law. But the structure still points toward a world where the largest developers need a publishable governance file, not just internal assurances.

    Audits, Reports, And Incident Duties

    By the later of one year after enactment or 90 days after first qualifying as a large frontier developer, and annually thereafter, the bill would require a large frontier developer to retain a third party to audit compliance with the developer's own frontier AI framework.

    The audit structure matters because it would not merely ask whether the developer has a framework. It would ask whether the developer is following it. The auditor would need demonstrated competence, including access to technical expertise in frontier-model safety, and the bill bars either side from holding a financial interest in the other.

    H.R. 9925 also would require model-level transparency reports before or concurrent with deployment of a new frontier model or a substantial modification. Those reports would include release date, supported languages, output modalities, intended uses, restrictions or conditions, catastrophic-risk assessments, assessment results, third-party involvement, and other steps taken under the framework. The summaries would have to be provided in machine-readable format to facilitate verification of model claims.

    Critical safety incidents get a separate clock. The bill would require the Under Secretary of Commerce for AI Security to create a confidential reporting mechanism within 180 days after enactment. A frontier developer would have to report a critical safety incident within 72 hours after learning facts sufficient to establish a reasonable belief that one occurred. If the incident poses an imminent risk of death or serious physical injury, the developer would have to report to law enforcement within 24 hours.

    For compliance teams, those deadlines are the practical signal. If the bill moves, frontier developers would need escalation criteria and evidence records before an incident happens.

    The Independent Verification Layer

    The heaviest obligations fall on very large frontier developers.

    By the later of one year after the Under Secretary first licenses an independent verification organization with capacity to accept an engagement or 90 days after a developer first qualifies as very large, the developer would have to retain a licensed IVO to perform ongoing assessments.

    Those assessments would cover the adequacy of the developer's frontier AI framework, governance practices, risk monitoring, and mitigation of detected risks. They would apply not only to released models, but also to catastrophic risks from internal use of frontier models.

    The IVO would need access to unredacted materials, records, personnel, systems, and other information reasonably necessary for the assessment. The developer could impose reasonable security and confidentiality protocols, but material limits on access would have to be described in the assessment report.

    The IVO report would have to address scope, limitations, the adequacy of the developer's framework and governance, identified failures or weaknesses, recommended corrective actions, and certifications about accuracy, qualifications, conflicts of interest, and compliance with regulations.

    That is a significant compliance design. It would create a regulated market for AI verification organizations and make the independence of that market a policy issue in its own right. The bill recognizes that by requiring annual Government Accountability Office reports on the IVO market, including barriers to entry and threats to independence from the AI industry.

    The Preemption Clause Is Narrower, But Still Important

    The earlier discussion draft drew attention because it tried to divide federal and state authority over AI. H.R. 9925 keeps that fight, but narrows the covered field.

    Section 9 preempts state and local laws that impose new substantive obligations on artificial intelligence developers with respect to a defined "Covered Subject Area." For this section, the bill uses a broader definition of "artificial intelligence developer": an entity that builds, designs, codes, produces, trains, or owns an AI model for internal or third-party use, excluding entities that are solely deployers.

    That means Section 9 is not limited to the bill's narrower "frontier developer" definition, even though the covered subject areas are tied to frontier AI risk transparency, frontier AI third-party auditing and independent verification, and frontier AI incident reporting.

    That is not the same as preempting all state AI law.

    The bill expressly preserves generally applicable laws that do not target AI developers. It also preserves state authority to regulate the use or deployment of AI systems by deployers or users, including through consumer protection, civil-rights, contract, criminal, or privacy laws, so long as those laws do not impose substantive obligations on developers with respect to model development, training, evaluation, or release.

    It also preserves state laws specifically relating to protection of minors from harms arising from AI systems, including sexually explicit content, self-harm content, exploitation, age verification, parental controls, and similar matters. And it preserves state procurement and use rules for state governments.

    That narrowing is the legal story. The sponsors appear to be moving from a broader preemption fight toward a more focused claim: if Congress creates a federal catastrophic-risk transparency, audit, verification, and incident-reporting regime for frontier developers, states should not create parallel developer-side obligations in the same lane.

    States would still have room to regulate many downstream AI uses. The hardest disputes would sit at the boundary. A state rule framed as product transparency, child safety, consumer protection, or procurement may be preserved. A rule that reaches developer-side frontier risk testing, reporting, audits, certifications, or release conditions may be challenged as preempted.

    Emergency Orders Are The Enforcement Backstop

    H.R. 9925 also gives the Secretary of Commerce emergency-order authority.

    The Secretary could suspend or restrict a frontier developer's development, deployment, or internal use of a frontier model upon finding that the activity presents an imminent catastrophic risk. The bill sets procedures for written findings, technical assessments where methods have been published, consultation with the Under Secretary, provisional and final orders, judicial review, and penalties.

    Violating an emergency order could trigger civil penalties of up to $10 million per violation. Willful violations could carry criminal penalties of up to $1 million per violation, imprisonment for up to 10 years, or both.

    Those provisions are narrow, but they show the bill is not only a reporting proposal. It would give the federal government a direct intervention tool for imminent catastrophic risk.

    What Companies Should Watch

    Most companies would not become frontier developers under H.R. 9925. But the bill still matters outside the frontier lab because it sketches the federal-state boundary Congress may try to draw.

    Frontier developers should watch the thresholds, the definition of catastrophic risk, the content of the public framework, the 72-hour and 24-hour incident clocks, the registration/disclosure duty, and the IVO assessment process.

    Companies that deploy third-party AI systems should watch a different issue: what the bill leaves to states. H.R. 9925 preserves state regulation of deployers and users, including consumer protection, civil rights, privacy, contract, criminal law, child safety, procurement, and state-government use. That means a federal frontier bill would not erase downstream state compliance work.

    Audit and assurance providers should watch the IVO licensing rules. The bill would require independence, conflict-of-interest controls, technical competence, access to developer records and systems, and signed certifications. That is closer to regulated assurance than ordinary consulting.

    State-policy teams should watch the boundary language. The next fight will not be "federal law or state law." It will be whether a particular state rule targets developer-side frontier risk governance or downstream use.

    Bottom Line

    The FRONTIER Act is the introduced-bill version of a narrower federal AI bargain.

    It would place public frameworks, third-party audits, incident reporting, independent verification, registration, and emergency-order authority around the largest frontier developers. In return, it would limit state and local developer-side obligations in the covered catastrophic-risk transparency, audit, verification, and incident-reporting lanes.

    That is why H.R. 9925 is worth tracking even if it is far from enactment. It is one of the clearest current attempts to answer the question that keeps coming back in U.S. AI law: which layer belongs to Washington, and which layer remains with the states?

    Sources