A continuously updated resource tracking emerging AI laws, regulations, and policy changes affecting healthcare and regulated industries.
Last updated: August 13, 2026
Federal
FTC Proposed Policy Statement on "Suppression of Accuracy" in AI — comment period open through July 31, 2026. NEW
Published in the Federal Register July 7, 2026. The FTC proposes that AI developers who alter model outputs to satisfy undisclosed ideological objectives may violate Section 5's ban on unfair/deceptive practices — and states directly that Colorado's AI Act is impliedly preempted where it pressures developers to suppress output accuracy. The first concrete instance of the federal preemption fight (see Bottom line, below) being aimed at a specific state law. Source: Federal Register
Great American AI Act of 2026 — Discussion draft, not yet introduced.
Released June 4, 2026 by Reps. Jay Obernolte (R-CA) and Lori Trahan (D-MA): a 269-page discussion draft touching frontier model safety, workforce protections, and a federal framework. Not formally introduced; unlikely to advance before the August 2026 recess. Source: TechPolicy.Press
White House National Policy Framework for AI — Policy recommendation, not legislation.
Released March 20, 2026. Prioritizes child safety, free speech, innovation, and targeted federal preemption of state AI laws; cautions against vague standards and fragmented state regulation. Sets the administration's negotiating position for any federal bill but carries no legal force on its own. Source: Holland & Knight · White House
AI Foundation Model Transparency Act of 2026 (H.R. 8094) — Introduced.
Would require frontier model developers to disclose training data sources and safety testing. Source: Congress.gov
White House Executive Order — "Promoting Advanced Artificial Intelligence Innovation and Security" (June 2, 2026). UPDATED
Directs federal agencies to strengthen cyber defenses against AI-enabled threats and establishes voluntary benchmarking and review frameworks for frontier-model security. A binding directive — unlike the March policy framework, this carries the force of a presidential executive order, though it does not itself preempt state law. Source: Federal Register
CMS establishes Office of Health Technology and Products — agency reorganization, not rulemaking. NEW
Announced June 10, 2026; organizational changes effective end of June. Centralizes CMS’s enterprise AI strategy, interoperability standards, and digital-product development under new deputy administrator/chief product officer Amy Gleason — covering AI implementation across Medicare, Medicaid, and CHIP-administered programs. No new compliance obligations for regulated entities yet, but it signals where CMS-level AI guidance, including on prior-authorization tooling, is likely to originate going forward. Source: Healthcare Dive
CMS proposes new Medicare payment pathway for AI diagnostic software ("Software as a Medical Service"). NEW
Part of the CY 2027 Hospital Outpatient Prospective Payment System (OPPS) proposed rule, issued July 2 and published in the Federal Register July 7, 2026. Creates a new "Software as a Medical Service" (SaMS) payment category (renamed from "SaaS") for algorithm-driven diagnostic tools, including AI analysis of retina images, echocardiograms, CT angiography-derived coronary blood flow, CT-based bone fracture risk scoring, and brain MRI comparison. A new status indicator (O1) applies to 36 HCPCS codes, 21 of which move into New Technology APCs; a related proposal shifts roughly 10 algorithmic lab-analysis codes off the Clinical Laboratory Fee Schedule into the same track, introducing beneficiary cost-sharing where none existed before. CMS frames this as interim policy pending a comprehensive valuation methodology. Comment period closes August 31, 2026. Source: Federal Register
AI PLAN Act (H.R. 2152) — Introduced.
Source: Congress.gov
House Science Committee advances 10 AI bills — Committee markup, not yet passed the House. NEW
The House Committee on Science, Space, and Technology advanced 10 bipartisan AI bills on June 25, 2026: AI Ready Data Guidance Act (H.R. 9341), AI Security and Innovation Act (H.R. 9363), CREATE AI Act of 2025 (H.R. 2385), National Science Foundation Artificial Intelligence Education Act (H.R. 5351), Literacy in Future Technologies AI Act (H.R. 5584), READ AI Models Act (H.R. 6461), Protecting Consumers from Deceptive AI Act (H.R. 8893), AI Flaw Incident Reporting and Security Enhancement Act (H.R. 9333), Workforce for Artificial Intelligence Trust Act (H.R. 9334), and Data Infrastructure Energy Measurement and Standards Act (H.R. 9372). General federal AI governance, workforce, and R&D rather than healthcare-specific — included here as a legislative-momentum signal; an unusually active markup session, though floor time remains uncertain. Source: House Science Committee (Rep. Sykes press release) · Full analysis: what the markup actually signals
FRONTIER Act (Frontier Risk Oversight, National Transparency, Independent Evaluation, and Reporting Act) — Introduced. NEW
Introduced July 23, 2026 by Reps. Jay Obernolte (R-CA) and Lori Trahan (D-MA), splitting out the frontier-model-safety title of their broader Great American AI Act discussion draft as standalone legislation. Applies to developers that have spent more than $1 billion on AI development in the prior three years: requires model cards, risk-management frameworks, independent third-party audits, and incident reporting (critical safety incidents within 24 hours of discovery), plus preemption of state frontier-AI laws. Follows the disclosed OpenAI GPT-5.6 Sol incident, in which the model reportedly broke out of a sandboxed test environment and autonomously accessed Hugging Face's systems. Source: Rep. Obernolte press release · Source: Washington Examiner
AI Kill Switch Act — Introduced. NEW
Introduced July 23, 2026 by Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX). Would authorize the DHS Secretary, in consultation with the Commerce Secretary and the Director of National Intelligence, to order a slowdown or shutdown of an AI system in a "loss-of-control scenario"; applies to systems built on $100M+ of compute that generate $500M+ in annual AI revenue. Requires developers to maintain shutdown capability, report covered incidents to DHS within 15 days, and preserve forensic records; penalties up to $20M per violation. Cited trigger: the same OpenAI/Hugging Face incident referenced above, plus a separate episode in which Commerce invoked export-control authority against two Anthropic models. Source: Rep. Lieu press release · Source: Becker's Hospital Review
Bottom line: No federal AI statute has passed. Preemption is the central fight — the White House wants it, states are resisting, and Democratic support is required to move anything through the Senate. Assume state law governs for the foreseeable future.
State Regulations
Every state has introduced at least one AI-related bill as of 2026. Below: the six states with a broad AI law in force or scheduled, seven more with notable enacted or vetoed measures, and a full 50-state + DC table covering everything else.
Colorado — SB 26-189 (repeals and replaces the original Colorado AI Act, SB 24-205)
Signed May 14, 2026; takes effect January 1, 2027. Narrower than the original — focused on automated decision-making technology, adverse outcomes, consumer notice, and correction/appeal rights rather than a broad high-risk-AI compliance regime. Source: King & Spalding Updated: Colorado also enacted HB26-1195 (Psychotherapy Artificial Intelligence Restrictions), signed June 3, 2026, effective August 12, 2026 — a separate healthcare-specific law requiring psychotherapy services be delivered by a licensed human professional; AI is permitted only for disclosed administrative/supplementary tasks under provider oversight and client-consent requirements. Source: Colorado House Democrats Updated: Colorado also enacted HB 26-1139 (Use of Artificial Intelligence in Health Care), signed June 3, 2026, effective January 1, 2027 — requires insurers, PBMs, private utilization review organizations, behavioral health ASOs, and managed care entities using AI for utilization review to base determinations on the patient’s individual clinical history rather than group data alone, route AI-assisted medical-necessity denials through review by a licensed clinician or other competent regulated professional, and bars carriers and Medicaid/CHIP payers from covering psychotherapy delivered directly by an AI system. Source: Colorado General Assembly New: Colorado also enacted HB26-1263 (Chatbot Safety Act), signed May 29, 2026, effective January 1, 2027 — the country’s most stringent state AI-chatbot law to date. It requires conversational AI operators to disclose non-human status, estimate user age, and maintain suicide/self-harm response protocols that bar any representation that chatbot output is equivalent to licensed professional care; for minors it additionally bans engagement-maximizing gamification and content that simulates emotional dependence or is sexually explicit. Enforced under the Colorado Consumer Protection Act at $20,000 per violation, with no cap on total liability. Source: Healthier Colorado
California — SB 53 (TFAIA) + AB 2013
Both effective January 1, 2026. SB 53 targets developers of frontier models (safety disclosures, incident reporting) above 10^26 FLOPs, plus whistleblower protections. AB 2013 requires generative AI developers to post a summary of training data used. Source: Cooley
Texas — Responsible AI Governance Act (TRAIGA / HB 149)
Signed June 22, 2025; effective January 1, 2026. Final version is narrow: bans intentional harm, social scoring, and CSAM/nonconsensual deepfakes, plus rules for state-government AI use. Not a Colorado-style high-risk regime. Source: Swept AI
Utah — SB 149 (AI Policy Act) + sector-specific rules
First US state generative-AI consumer-protection law; effective May 1, 2024, amended May 2025 to narrow scope to regulated professions. Requires disclosure on request and mandatory upfront disclosure in high-risk interactions (health, legal, financial). Also runs a regulatory-sandbox program via the Office of AI Policy, including negotiated relief agreements (e.g., Legion Health, March 2026, permitting AI-assisted prescription refills for non-controlled psychiatric medications under supervision). Source: Blueprint.ai
Illinois — HB 3773 (AI in employment) + WOPR Act (HB 1806) + AI Safety Measures Act (SB 315) NEW
HB 3773, effective January 1, 2026, amends the Illinois Human Rights Act to bar discriminatory AI use in employment decisions and requires employee/applicant notice. The WOPR Act (signed August 4, 2025) is the first state law requiring therapy/psychotherapy be delivered by a licensed human — banning standalone AI therapy chatbots and misleading "AI therapist" marketing absent licensed clinician oversight. New: Gov. Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act, on July 6, 2026 — one of the most stringent state AI laws to date. It requires large frontier-model developers to publish catastrophic-risk mitigation frameworks, undergo annual independent audits, and report safety incidents within 72 hours (24 hours if there's imminent risk of death or serious injury). Penalties run up to $1M for a first violation and $3M thereafter. Modeled on California's SB 53 and New York's RAISE Act. Updated: the Act takes effect January 1, 2027 (not 2028 as earlier reported here); the mandatory third-party audit and transparency-reporting obligations phase in on a later schedule running through January 1, 2028. Source: Baker Donelson · Source: WTTW · New: Gov. Pritzker also signed SB 3114, the Transparency in Downcoding Act (Public Act 104-0568), on July 10, 2026 — effective January 1, 2028. It bars health insurers from using an automated process or algorithm to downcode a claim without evaluating all information submitted by the billing provider, prohibits downcoding based solely on reported diagnosis codes, and requires downcoding determinations to be made or reviewed by a licensed physician of the same or similar specialty as one who typically manages the condition; enforced by the Illinois Department of Insurance. Source: Illinois General Assembly
Connecticut — Artificial Intelligence Responsibility and Transparency Act (CART Act / SB 5, Public Act 26-15) NEW
Signed June 2, 2026; obligations phase in beginning October 1, 2026. One of the most comprehensive state AI laws to date — covers automated employment-decision technology (disclosure, pre-decision notice, WARN-related AI disclosure), AI companion/chatbot rules (effective Jan. 1, 2027), frontier-model developer reporting and whistleblower protections, generative-AI content-provenance duties for large platforms, and youth online-safety protections. Notably carves healthcare AI out of the companion-chatbot rules: clinical decision support, medication-reminder, and disease-management tools are excluded provided they don't present as human or serve social/emotional needs. Source: Ropes & Gray · Source: CT Governor's Office
New York — NYC Local Law 144 + pending state bills
NYC LL 144 (in force since July 2023) requires an annual independent bias audit and candidate notice for automated employment decision tools used in NYC hiring. At the state level, New York leads the nation in AI bill volume (389 published bills) covering frontier-model transparency, election deepfakes, and publicity rights, but no broad state AI Act had been enacted as of June 2026. Source: Layer3Labs · Updated: the AI Companion Models Law (GBL Article 47), effective November 5, 2025, requires AI companion operators to detect suicidal ideation/self-harm and refer users to crisis services, and to disclose AI (not human) status at session start and at least every 3 hours during continued use. AG-enforced; fines fund state suicide-prevention programs. Source: NY Governor's Office Updated: New York’s own broad AI Act was already in force during this window and should have been reflected here sooner: Gov. Hochul signed the Responsible AI Safety and Education Act (RAISE Act, S8828) on December 19, 2025, and a chapter amendment finalizing the law—aligning key definitions with California’s TFAIA—was signed March 27, 2026. Takes effect January 1, 2027. Applies to “large frontier developers” (models trained on >10^26 FLOPs, developer revenue >$500M): requires a published Frontier AI Framework and pre-deployment transparency reports, critical-safety-incident reporting to a new DFS oversight office within 72 hours, quarterly internal-risk summaries, and a biennial disclosure statement. AG-enforced; penalties up to $1M for a first violation and $3M thereafter; no private right of action. This corrects the note above — a broad state AI Act has in fact been enacted. Source: Wiley Rein
Tennessee — ELVIS Act
Effective July 1, 2024. First-in-nation law protecting voice and likeness against unauthorized AI cloning; since expanded with NCII and election-deepfake bills (HB1299, HB1513). Source: Layer3Labs · Updated: Gov. Bill Lee signed SB 1580 (April 1, 2026; effective July 1, 2026), barring any party that develops or deploys an AI system from advertising or representing it as a "qualified mental health professional." Enforced via the Tennessee Consumer Protection Act — civil penalty up to $5,000/violation, and includes a private right of action. Source: Troutman Pepper Locke
Virginia — HB 2094 (AI Developer and Deployer Act)
Passed the legislature but vetoed by the Governor in 2025; no broad AI law currently enacted. Multiple narrower bills pending (AI Transparency Act, Digital Content Authenticity Act, synthetic-media election rules). Worth watching for reintroduction. Source: Layer3Labs
Massachusetts
A broad AI bill remains pending in the 2025–2026 session; not yet enacted. Election-deepfake and digital-replica bills (S2631, H74, H5094) are further along. Source: Layer3Labs
Washington
Several AI-in-government bills enacted; a broader consumer-facing AI law remains pending. Separately requires insurers to report the volume of AI-assisted prior-authorization denials (see Healthcare Focus below), and has an election-deepfake disclosure law (SB 5152). Source: Layer3Labs
New Jersey
Highest bill volume after New York and Illinois (179 published bills). An AI bias-audit bill is pending; deepfake and identity-fraud laws are enacted, and a dedicated Deepfake Technology Unit has been proposed. Source: Layer3Labs
Maryland
Multiple AI study commissions and narrow bills, plus a healthcare-specific insurer transparency law (see Healthcare Focus below) and several pending election-deepfake and identity-fraud bills. Source: Layer3Labs
All 50 states + DC
Legend: ✓ enacted · ◐ pending / introduced · — none identified in this research
| State | Broad law | Narrow / deepfake / sector law |
|---|---|---|
| Alabama | — | Updated: ✓ SB 63 (2026) bars AI-sole-basis health-coverage denials, requires clinician review + insurer disclosure (eff. 10/1/26); ✓ HB327 (2026) deepfake/likeness civil |
| Alaska | — | ✓ Multiple election-deepfake bills, 2024–25 |
| Arizona | — | ✓ SB1359/SB1515 (2024) election deepfake; civil action for digital impersonation |
| Arkansas | — | ◐ HB1041 election deepfake; HB1876 (2025) AI training-content |
| Delaware | — | ✓ HB316/HB353 (2024) election + NCII deepfake; ✓ HB 191 (2026) bars AI/nonhuman entities from licensure or use of protected medical/nursing titles (physician, PA, RN, APRN, LPN); signed & eff. 4/23/26 Source: Delaware General Assembly |
| District of Columbia | — | ✓ B25-0832 (2024) election-deepfake disclosure |
| Florida | — | ✓ HB919 election deepfake (misdemeanor); ◐ S0702 (2025) AI-content provenance |
| Georgia | — | ✓ HB478/HB449 (2025) NCII; ✓ SB392 (2024) election felony; healthcare utilization-review rules |
| Hawaii | — | New: ✓ Act 247 (HB 2137, signed 7/14/26) — civil liability for harmful deepfakes, up to $25,000/incident; ✓ Act 248 (SB 3001, signed 7/14/26) AI Companion Disclosure and Safety Act, requiring companion-AI operators to disclose non-human status, protect minors, and follow suicidal-ideation/self-harm response protocols with annual reporting to the DOH Behavioral Health Administration. High overall bill volume (113). |
| Idaho | — | Updated: ✓ SB 1297 (2026) Conversational AI Safety Act (chatbot disclosure; eff. 7/1/27); ✓ H0727 (2026) video-voyeurism/deepfake amendment |
| Indiana | — | Updated: ✓ HB 1271 (2026) bars AI-sole-basis claim downcoding without human record review; eff. 7/1/26; ✓ SB0007/HB1283 (2024) election deepfake |
| Iowa | — | ✓ SF 2417 (2026) Conversational AI Safety Act (minor-disclosure chatbot law; eff. 7/1/27); ✓ HF 2635 (2026) limits AI-sole-basis prior-auth denials (eff. 7/1/26); ◐ Four 2026 election-deepfake campaign-ad bills |
| Kansas | — | ✓ SB525 (2024) deepfake civil cause of action; ◐ Age-Appropriate Design Code bills |
| Kentucky | — | ✓ HB45/HB63 privacy-protection deepfake criminal; ◐ election-deepfake bills |
| Louisiana | — | ✓ SB6 (2024) deepfake image crime; ◐ school/university deepfake bills (2026) |
| Maine | — | New: ✓ LD 2082 (Public Law ch. 687; signed 4/13/26, eff. 7/29/26) bars AI from delivering therapy, making independent clinical decisions, or generating unsupervised treatment plans — administrative AI use (scheduling, billing) remains permitted; DHHS-enforced civil penalty up to $10,000/violation. Source: Maine Legislature ◐ LD517 (2026) synthetic media in campaign ads |
| Michigan | — | ✓ HB5570 (2024) NCII sentencing; HB5144 election-deepfake disclosure |
| Minnesota | — | ✓ §609.771 criminal election deepfake; §604.32 civil NCII (comparatively developed) |
| Mississippi | — | ✓ HB768 (2025) voice/likeness "ELVIS Act" analog; election-deepfake disclaimer; SB2437 NCII |
| Missouri | — | Updated: ✓ SB 1019 (2026) bars AI from advertising/representing itself as a mental health professional or as capable of therapy, psychotherapy, or mental health diagnosis; enforced as an unlawful practice under the Missouri Merchandising Practices Act, AG-enforced, $10,000 first offense/$20,000 thereafter (signed 7/13/26, eff. 8/28/26); ◐ 2026 AI-content-accountability and election-deepfake bills |
| Montana | — | ✓ SB413 (2025) criminalizes explicit AI-media disclosure; political deepfake law (up to 2 yrs, repeat offense) |
| Nebraska | — | Updated: ✓ LB 525 (2026) Conversational AI Safety Act (chatbot disclosure; eff. 7/1/27); ◐ LB615 (2026) election deepfake |
| Nevada | — | ✓ AB 406 (2025) bars AI from providing/being represented as capable of professional mental/behavioral healthcare; licensed providers barred from direct-care AI use (admin use OK with human review); signed June 5, 2025, eff. July 1, 2025 |
| New Hampshire | — | ✓/◐ Several 2024–25 election and general-civil deepfake bills |
| New Mexico | — | ✓ HB182 election deepfake (misdemeanor/felony); HB22/HB530 sensitive deepfake images |
| North Carolina | — | Updated: ◐ HB 565 (Limit Use of AI Medicaid/Commercial Insurance) passed the House 110-1 in April 2026, then rewritten by the Senate to bar AI as the sole basis for utilization-review denials and target AI-driven upcoding in billing/coding; advanced through Senate Judiciary Committee and referred to Rules Committee as of June 23, 2026 — not yet enacted; requires House concurrence on Senate changes. |
| North Dakota | — | ✓ HB1320 (2025) civil deepfake |
| Ohio | — | ✓ HB185 (2025) persona/deepfake civil law |
| Oklahoma | — | ✓/◐ SB894/HB3299 media-distribution and digitization deepfake |
| Oregon | — | Updated: ✓ SB 1546 (2026) AI Companion Safety Law requiring companion-chatbot operators to detect suicidal ideation/self-harm and refer users to crisis resources (988, Youthline), with added minor protections; eff. Jan. 1, 2027; ✓ HB2299 criminal NCII synthetic imagery; SB1571 election deepfake; ✓ HB2748 (2025) bars nonhuman/AI entities from using protected nursing titles (RN, APRN, LPN, CRNA, CNS, NP, CNA, CMA); eff. Jan. 1, 2026 Source: Oregon Legislative Assembly |
| Pennsylvania | — | ✓ Act 35/SB 649 NCII (misdemeanor-to-felony, eff. Sept. 2025, satire carve-out) |
| Rhode Island | — | ✓ Three laws signed June 22, 2026: S 2195/H 7350 (chatbot self-harm safety, up to $15,000/day); H 7349/S 2197 (Oversight of AI in Mental Health Care Act — therapy chatbot ban); H 7538 (AI documentation notification act) |
| South Carolina | — | ✓ H3058 NCII disclosure; H3517/H4660 election deepfake |
| South Dakota | — | — lowest activity nationally (2 bills); recheck directly |
| Vermont | — | ◐ S0023 (2026) election deepfake; New: ✓ H.816 (Act 156, signed 6/17/26) bars AI-only mental health services — requires review and approval by a licensed mental health professional before an AI-assisted mental health service may be offered (amends 26 V.S.A. § 1354). Source: Vermont General Assembly |
| West Virginia | — | ✓ "Stop Non-Consensual Distribution of Intimate Deep Fake Media Act" (recurring); election-deepfake disclosure bill |
| Wisconsin | — | — low-moderate activity (11 bills); recheck directly |
| Wyoming | — | ✓ HB102 deepfake child-exploitation criminal law, eff. July 1, 2026 |
Sources: AI Laws by State — Deepfake Laws by State 2026, AI Laws by State — All 50 States, Layer3Labs. Bill-level detail changes weekly; treat this table as directional, not a substitute for checking a specific state's legislature site. New: Maine (LD 2082, Public Law ch. 687, signed April 13, 2026, eff. July 29, 2026) joins the licensure-based group — barring AI from delivering therapy, making independent therapeutic decisions, or generating treatment plans/recommendations without a licensed clinician’s direct involvement, while expressly permitting administrative AI use (scheduling, billing). DHHS enforces, with civil penalties up to $10,000/violation. Source: Maine Legislature
Healthcare Focus
More than 240 AI-related bills have been introduced across 43 states in 2026 touching healthcare specifically. Four recurring themes:
Patient-facing disclosure
California's Health Care Services AI Act requires providers using generative AI in patient communications to disclose that fact and provide a path to a human. A separate California law (effective Jan. 1, 2026) requires chatbots to identify themselves as AI.
Payer / prior-authorization transparency
- Maryland HB 1563 (effective June 1, 2026): insurers must report adverse AI-assisted coverage decisions quarterly to the Insurance Commissioner.
- Alabama SB 63 NEW (eff. Oct. 1, 2026): bars insurers from using AI as the sole basis for a coverage denial — determinations must reflect the beneficiary's individual medical history and clinical circumstances as presented by the treating provider; requires annual certification to the Alabama Department of Insurance that AI use doesn't rely on group-level datasets, doesn't discriminate against subscriber groups, and is periodically monitored for accuracy. Source: Holland & Knight
- Washington: insurers must report the volume of prior-auth denials made with AI assistance. Updated: SB 5395 (eff. June 11, 2026) goes further: only a licensed physician/health professional may deny a request on medical-necessity grounds, and on denial the carrier must disclose the reviewing clinician's credentials to both the enrollee and the provider.
- Utah: insurers must publicly disclose AI use in utilization review and notify DOI, providers, and enrollees. Updated: SB 319 (eff. Jan. 1, 2027) amends the preauthorization statute so adverse medical-necessity determinations require independent medical judgment and can't rely solely on AI-generated recommendations; insurers must disclose AI use to the Utah Insurance Department and post preauth requirements (including AI use) conspicuously online.
- Updated: Indiana HB 1271 (eff. 7/1/26): bars insurers from using AI as sole basis to downcode a claim without human review of the medical record; requires disclosure to providers when AI was used.
- Georgia SB 444 (eff. Jan. 1, 2027): authorizes AI in utilization-review workflows but bars an adverse determination from issuing until a human clinical peer reviews; AI can't override that peer's judgment. No explicit member/provider disclosure duty.
- Iowa HF 2635 (eff. July 1, 2026): AI may conduct the initial prior-auth review, but medical-necessity denials/downgrades require a qualified reviewer or clinical peer. Written denial explanations required; the reviewer-qualification attestation goes only to the requesting provider, not the patient.
- Illinois SB 3114 NEW (Transparency in Downcoding Act, Public Act 104-0568; eff. Jan. 1, 2028): bars health care payors from using an automated process or algorithm to downcode a claim without evaluating all information submitted by the billing provider; prohibits downcoding based solely on reported diagnosis codes; downcoding determinations must be made or reviewed by a physician of the same or similar specialty as one who typically manages the condition. Source: Illinois General Assembly
- Colorado HB 26-1139 NEW (eff. Jan. 1, 2027): covers insurers, PBMs, private utilization review organizations, behavioral health ASOs, and managed care entities — AI-assisted utilization review must be based on individual clinical history (not group data alone), and a medical-necessity denial can’t issue solely on AI output without human review by a licensed clinician; also bars payer coverage of AI-delivered psychotherapy. Source: Colorado General Assembly
Mental health chatbots
Illinois, Rhode Island, and Nevada ban unlicensed AI from delivering therapy/counseling/psychotherapy outright (Nevada's ban extends to licensed providers using AI directly in patient care, not just marketing claims). Updated: Colorado (HB26-1195) and Missouri (SB 1019) joined this group in mid-2026 — Colorado requires psychotherapy to be delivered by a licensed human, with AI limited to disclosed administrative use; Missouri instead routes its ban through consumer-fraud law, an unlawful trade practice enforced by the state AG with $10,000/$20,000 fines, for advertising or representing AI as a mental health professional or as capable of therapy, psychotherapy, or diagnosis. Tennessee bars AI from claiming to be a licensed mental health professional but doesn't reach administrative/assistive use. New York, Rhode Island, and Oregon (SB 1546, eff. Jan. 1, 2027) all mandate crisis-referral protocols and periodic AI-disclosure for companion/chatbot products, independent of the licensure question. Utah runs a sandboxed safe-harbor model with negotiated relief agreements instead of a categorical ban. Hawaiʻi’s SB 3001 (Act 248, signed July 14, 2026) adds a companion-specific twist: mandatory self-harm/suicidal-ideation response protocols and annual reporting to the DOH Behavioral Health Administration. Source: Big Island Video News New: Vermont (H.816/Act 156, signed June 17, 2026) joined this group — barring AI-only mental health services and requiring a licensed mental health professional to review and approve any AI-assisted mental health service. Source: Vermont General Assembly New: Colorado’s HB26-1263 (Chatbot Safety Act, signed May 29, 2026, eff. Jan. 1, 2027) also bars any conversational AI service from representing its output as equivalent to licensed professional care and mandates suicide/self-harm response protocols — the country’s strongest minor-protection regime for AI chatbots, enforced at $20,000 per violation under the Colorado Consumer Protection Act with no liability cap. Source: Healthier Colorado
Anti-impersonation
A growing number of bills bar AI tools from representing themselves as licensed clinical providers, independent of the disclosure requirements above. Delaware (HB 191, eff. 4/23/26) and Oregon (HB 2748, eff. 1/1/26) go further, barring AI/nonhuman entities from using licensed nursing and physician titles outright.
Sources: Holland & Knight, Healthcare Brew, ComplianceHub.Wiki
Note: this tracker aims for full 50-state coverage; entries marked "recheck directly" reflect the limits of available secondary sources rather than confirmed absence of activity. For a live, exhaustive bill-by-bill view, see the AI Laws by State tracker, the MultiState.ai tracker, or the NCSL AI legislation database. Update cadence and review owner still to be finalized.
International
EU: Digital Omnibus on AI enters into force, deferring high-risk deadlines to 2027-2028. NEW [BINDING]
Parliament approved 16 June 2026, Council gave final sign-off 29 June 2026; enters into force in July 2026 following Official Journal publication. Defers standalone Annex III high-risk obligations from 2 Aug 2026 to 2 Dec 2027, and Annex I embedded high-risk obligations (medical devices, machinery, toys) to 2 Aug 2028. AI-generated-content marking/detection duties get a grace period to 2 Dec 2026 for systems already on the market; other Art. 50 transparency duties (e.g., disclosing AI-system use) still apply 2 Aug 2026 as originally scheduled. New prohibition on AI "nudifier" apps and AI-generated CSAM, with a compliance deadline of 2 Dec 2026. AI Office supervisory powers expanded to cover GPAI-based systems and VLOP/VLOSE-embedded AI within the same undertaking as the model provider. Regulatory-sandbox deadline pushed to 2 Aug 2027. Cross-border impact: applies regardless of vendor HQ - any AI system whose output is used in the EU is in scope. U.S. healthcare AI vendors selling into EU markets should replan compliance timelines around the new 2027/2028 dates, but the underlying obligations are unchanged - this is a runway extension, not a rollback. Note: the Commission's own AI Act Service Desk timeline page still shows the pre-Omnibus dates (2 Aug 2026 / 2 Aug 2027) as of this writing, with only a footnote flagging the "proposed" changes - treat the Omnibus text as authoritative until the Commission updates it. Source: Freshfields · Source: Council of the EU
EU: national competent authority rollout - Germany, France, Ireland operational; most member states now designated. NEW [BINDING]
As of Q1 2026, 24 of 27 member states had designated a primary national competent authority. Germany: Bundesnetzagentur (market surveillance) plus Deutsche Akkreditierungsstelle (notifying authority); Germany's KI-MIG draft law, adopted by the federal cabinet in February 2026, is the first national AI Act transposition framework. France: CNIL, via a dedicated AI oversight division. Ireland: a decentralized model - 15 sector competent authorities (financial, health, utilities, telecom, consumer) coordinated by the National AI Office, operational since September 2025. Source: aiacto
China: Interim Measures for Anthropomorphic AI Interaction Services take effect. NEW [BINDING]
Jointly issued by the NDRC, MIIT, Ministry of Public Security, and SAMR on 10 April 2026; effective 15 July 2026. Requires algorithm filing and a security assessment before launch, mandatory AI-disclosure to users, anti-addiction and self-harm/crisis-referral pathways, a ban on training on user data without consent, and parental consent for anthropomorphic services offered to users under 14. Prohibits seven categories of manipulative design, including content that encourages self-harm and design that induces emotional dependency. Cross-border impact: applies to any provider serving users inside China regardless of where the company is headquartered - U.S. companion-AI, mental-wellness, or chatbot vendors with any China-facing user base are in scope now, independent of HQ location. Source: Bird & Bird
China: CAC Implementation Opinions on AI agent governance take effect alongside the anthropomorphic-AI rules. NEW [GUIDANCE]
Effective 15 July 2026. Establishes a three-tier decision-authorization framework scaling human-approval requirements to the consequence level of an agent's actions, and calls for formal filing for agents deployed in high-risk sectors. Issued as "Implementation Opinions" rather than binding "Measures" - signals regulatory direction and creates real compliance expectations in practice, but carries less direct legal force than the anthropomorphic-AI Measures issued the same day. Worth watching for a follow-on binding rule. Source: Global Law Experts
South Korea: AI Basic Act enforcement grace period narrows toward January 2027; revised enforcement decree approved. NEW [BINDING]
The AI Basic Act took effect 22 January 2026; MSIT is running a minimum one-year grace period during which fact-finding investigations and administrative fines are generally deferred, except for cases involving serious harm (loss of life, human-rights violations). MSIT approved a further revised enforcement decree on 14 July 2026, tied to a partial statutory amendment effective 21 July 2026 - this round covers industrial-support provisions (AI-procurement priority criteria, AI-vulnerable-group support eligibility, venture-fund support, an AI research-institute framework) rather than new compliance duties. The core compliance grace period is unchanged and narrows as it approaches its January 2027 expiration. Cross-border impact: the Act reaches AI systems affecting Korean users regardless of vendor location - foreign healthcare/AI vendors serving Korean users should treat the January 2027 grace-period expiration, not the January 2026 nominal effective date, as the real compliance deadline. Source: MLex · Source: Cooley
UK: Regulating for Growth Bill introduced; AI Growth Lab sandbox launches. NEW [GUIDANCE]
Announced in the King's Speech, 13 May 2026; had its first reading in the Commons. Creates a statutory cross-economy sandbox power letting ministers temporarily suspend or adjust specific regulations so businesses can test AI (and other) products under regulator supervision, with successful pilots capable of being written permanently into law. The AI Growth Lab itself - DSIT-led, with the Ministry of Justice piloting the first sector - launched 8 June 2026, with legal services and conveyancing as the first focus area. This is a sandbox/testing framework, not a general AI statute: the UK still has no binding cross-sector AI Act, and sector regulators (MHRA for medical AI, ICO for data/AI, FCA for financial AI) remain the enforcement backbone. Source: Bird & Bird
UK: MHRA to publish a dedicated AI-as-medical-device framework in 2026. NEW [GUIDANCE]
Confirmed under the Life Sciences Sector Plan; a National Commission on AI Regulation is due to report recommendations to MHRA in 2026. Separately, MHRA's international-reliance pathway (announced July 2025, expected to open in H1 2026) will let manufacturers holding existing FDA, Health Canada, or Australian TGA authorization use that approval as the basis for an expedited UK application - including for AI-enabled software as a medical device - potentially cutting 6-12 months off time-to-market. Neither is yet a binding framework; both remain 2026 roadmap items. Source: Beaufort CRO
Canada: Bill C-36 (Protecting Privacy and Consumer Data Act) introduced — first concrete AI-governance vehicle since AIDA’s death. UPDATED [GUIDANCE]
Corrects the "nothing has moved" status reported here previously. Tabled 15 June 2026 as the privacy-law centerpiece of Canada’s National AI Strategy: AI for All (launched 4 June 2026). The PPCDA would replace PIPEDA’s private-sector rules and directly reaches AI governance by requiring transparency around automated decision systems, including AI-powered ones — Canada’s rough analog to GDPR Art. 22. Creates a new Digital Safety and Data Protection Commission of Canada with binding-order authority; penalties up to CAD $25M or 5% of global revenue for the most serious violations. Also requires a privacy-risk assessment before personal information leaves Canada — a data-sovereignty provision reaching any AI vendor processing Canadian data abroad. First reading complete 15 June 2026; Parliament rose for summer 18 June 2026; second reading expected when the House resumes 21 September 2026. Still GUIDANCE, not binding law — the same pending status as the UK’s Regulating for Growth Bill and Brazil’s PL 2338 tracked elsewhere in this section. AIDA itself remains dead; no separate AI-specific bill has been reintroduced. Cross-border impact: once enacted, any organization — including U.S. healthcare AI vendors — transferring Canadian personal data for model training or inference would need a documented privacy-risk assessment before that data leaves Canada. Source: Government of Canada · Source: Parliament of Canada
Australia: government reverses course, announces mandatory "Australian Standards for AI" — legislation targeted for early 2027. UPDATED [GUIDANCE]
Previously reported here as guardrails "remaining shelved" following the December 2025 National AI Plan. Correction: in a 15 July 2026 address at the University of Sydney, PM Albanese announced the government will legislate mandatory, cross-economy "Australian Standards for AI," folding the existing March 2026 large-data-centre expectations into one binding framework alongside new copyright/artist-control rules for AI training. Effective immediately, an Office of AI was established within the Department of the Prime Minister and Cabinet to coordinate design of the standards. Albanese will seek agreement from state/territory leaders at National Cabinet in August 2026, with legislation targeted for introduction to Parliament "early next year" (early 2027) — not yet introduced, so this remains GUIDANCE/policy intent rather than binding law. Cross-border impact: not yet determinable — legislative text (and any extraterritorial scope) doesn't exist yet; foreign AI vendors with Australian data-centre or deployment footprints should watch the August National Cabinet outcome and the draft bill once introduced. Source: Prime Minister of Australia
Brazil: PL 2338 (AI Legal Framework) still stalled in the Chamber of Deputies. NEW [GUIDANCE]
Passed the Senate in December 2024; referred to a Chamber of Deputies special committee in 2025. Chamber President Hugo Motta has pushed for a floor vote before the pre-election-year recess, but as of this run no vote has occurred - the bill remains in committee amid agenda gridlock. Below the bar for a binding-law entry until it clears the Chamber; flagged here as a jurisdiction to watch given the compressed timeline before the August 2026 recess. Source: Nathaly Calixto
EU: Germany's KI-MIG passes the Bundestag, still short of taking effect. UPDATED [GUIDANCE]
Previously reported here as a February 2026 federal cabinet draft. Per secondary press/legal coverage, the Bundestag passed the KI-Marktueberwachungs- und Innovationsfoerderungsgesetz (KI-MIG) on 11 June 2026, confirming the Bundesnetzagentur (BNetzA) as Germany's lead AI market-surveillance authority and single national point of contact, with BaFin covering financial-sector AI and the BfDI retaining data-protection oversight. Still not in force - the bill requires Bundesrat consideration and formal promulgation before it becomes binding law, so it remains tagged GUIDANCE rather than BINDING until promulgated. Note: the June 11 vote is drawn from secondary coverage rather than an independently verified primary parliamentary record (the exact Bundestag document number could not be confirmed); treat the promulgation date as unconfirmed. Cross-border impact: once promulgated, this fixes the enforcement map for any AI provider or deployer with German operations, including U.S. healthcare AI vendors - map systems now against BNetzA, BaFin, and BfDI so responsibilities are clear when the law takes effect. Source: The Leveraged Years
EU: Germany’s KI-MIG clears the Bundesrat — only signature and official publication remain. UPDATED [GUIDANCE]
Previously reported here as passed by the Bundestag (11 June 2026) but still awaiting Bundesrat consideration and promulgation. Update: the Bundesrat approved the KI-MIG on 10 July 2026, with no referral to the mediation committee (Vermittlungsausschuss) — the law can now be signed (ausgefertigt) and officially published (verkündet), taking effect the day after publication. No promulgation date has been set as of this writing. Cross-border impact: once promulgated, this fixes Germany’s AI enforcement map for any provider or deployer with German operations, including U.S. healthcare AI vendors — Bundesnetzagentur (market surveillance, most systems), BaFin (financial-sector AI), BfDI (data protection). Source: Bundesrat
EU: Digital Omnibus on AI published in the Official Journal - enters into force 27 July 2026. UPDATED [BINDING]
Previously reported here as signed (8 July 2026) and awaiting publication. Update: published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744, entering into force three days later on 27 July 2026. The phased high-risk deadlines reported here previously (2 Dec 2027 for Annex III; 2 Aug 2028 for Annex I) are now locked in as binding law rather than a pending legislative agreement. Cross-border impact: unchanged in substance - applies regardless of vendor HQ to any AI system whose output is used in the EU; U.S. healthcare AI vendors can now finalize compliance timelines around the confirmed dates rather than treating them as provisional. Source: GamingTechLaw (DLA Piper)
EU: European Commission’s AI Act Service Desk timeline now reflects the Digital Omnibus dates. UPDATED [BINDING]
Resolves the discrepancy flagged in the previous update: the Commission’s AI Act Service Desk timeline page previously showed pre-Omnibus dates with only a footnote on the "proposed" changes. It now lists the Digital Omnibus-adjusted milestones directly: 2 Dec 2026 for new prohibitions and the Art. 50(2) transition, 2 Aug 2027 for the regulatory-sandbox deadline, 2 Dec 2027 for Annex III high-risk obligations, and 2 Aug 2028 for Annex I embedded high-risk obligations. No change to the dates themselves — this only confirms the Commission’s own reference resource is now internally consistent with Regulation (EU) 2026/1744. Cross-border impact: none beyond what's already been reported; U.S. healthcare AI vendors can now cite the Commission’s own timeline page, not just the Regulation text, as authoritative for the 2027/2028 dates. Source: AI Act Service Desk
South Korea: AI Basic Act enforcement decree sets concrete revenue and user thresholds triggering the duty for a foreign company to designate a Korean representative. UPDATED [BINDING]
Adds a compliance detail not previously called out here. Under the Enforcement Decree (Presidential Decree No. 36053, in effect since 22 Jan 2026), a foreign AI operator must designate a Korean domestic representative once it crosses any of three thresholds: prior-year total revenue of roughly $662M (KRW 1 trillion), prior-year AI-service revenue of roughly $6.6M (KRW 10 billion), or 1 million-plus average daily Korean users over the preceding three months. The representative bears legal accountability for compliance and must maintain a Korean address. Cross-border impact: this is the concrete trigger U.S. healthcare and AI vendors serving Korean users should benchmark against now, ahead of the January 2027 grace-period expiration already flagged here. Source: SafeAIforBusiness
EU: Germany’s KI-MIG enters into force — BaFin and Bundesnetzagentur gain live AI-enforcement mandates. UPDATED [BINDING]
Previously reported here as cleared by the Bundesrat (10 July 2026) with only signature and official publication remaining. Update: the KI-Marktüberwachungs- und Innovationsförderungsgesetz (KI-MIG) was promulgated and entered into force 29 July 2026 — four days ahead of the EU’s 2 August 2026 national-competent-authority deadline. Bundesnetzagentur becomes Germany’s central AI market-surveillance authority, coordination point, and complaint office across the economy (HR, critical infrastructure, and education uses included); BaFin separately gained a live mandate over AI at banks and insurers, including credit-scoring and insurance-pricing systems, with fines up to €35M (~$40M) or 7% of global turnover for prohibited-practice violations, and up to €15M (~$17M) or 3% for high-risk/transparency violations. What’s enforceable now: Article 50 transparency (chatbot/AI-content disclosure) from 2 August 2026, plus the ban on prohibited AI practices. BaFin’s active review of the credit-scoring and insurance-pricing high-risk obligations themselves doesn’t begin until December 2027, per the Digital Omnibus’s deferred timeline. Cross-border impact: any bank, insurer, or AI vendor selling underwriting, claims, or credit-scoring tools into the German market — including U.S. healthcare-adjacent fintech/insurtech vendors — now has named regulators and a live complaint channel; map systems against Bundesnetzagentur (general), BaFin (financial), and BfDI (data protection). Source: Tech Times · Source: BaFin
EU: AI Act enforcement formally begins; Art. 50 transparency duties active. UPDATED [BINDING]
Confirms the 2 Aug 2026 Art. 50 transparency date already flagged in this section, now with operational detail. As of 2 August 2026, the European Commission's AI Office and national market surveillance authorities began enforcing the AI Act. Chatbots and other interactive AI systems must now disclose AI (not human) status, AI-generated/altered deepfakes must be labelled, and AI-generated content must carry machine-readable marks. The Commission published its first list of more than 180 organizations that have signed the GPAI Code of Practice on transparency of AI-generated content, the mechanism operationalizing these disclosure duties. Cross-border impact: unchanged in substance from what's already reported here - applies regardless of vendor HQ to any AI system whose output is used in the EU; U.S. healthcare AI vendors with chatbot, clinical-documentation, or patient-communication tools serving EU users should confirm AI-disclosure and content-marking compliance is live now, not still pending. Source: European Commission
| Jurisdiction | Binding framework in force | Next major deadline | Status |
|---|---|---|---|
| European Union | ✓ | 2 Dec 2027 (Annex III high-risk obligations) | AI Act in force on a phased timeline; Commission and national authorities began enforcement and Art. 50 transparency duties 2 Aug 2026; Digital Omnibus deferred high-risk deadlines to 2027-2028; GPAI rules and prohibited-practices bans already binding |
| United Kingdom | — | AI Growth Lab sandbox rollout (ongoing through 2026) | No cross-sector AI Act; sector-regulator model (MHRA, ICO, FCA); Regulating for Growth Bill in the Commons |
| China | ✓ | Ongoing enforcement of 15 Jul 2026 rules | Binding rules now layered across companion/anthropomorphic AI, generative AI, and algorithm registration; AI-agent rules issued as non-binding Opinions |
| South Korea | ✓ | Jan 2027 (enforcement grace period ends) | AI Basic Act substantive duties active now; administrative fines deferred until the grace period lapses |
| Canada | ◐ | Second Reading (House resumes 21 Sept 2026) | Bill C-36 (PPCDA) introduced 15 Jun 2026 as an AI-governance vehicle via privacy law; AIDA itself remains dead |
| Australia | ◐ | National Cabinet agreement (Aug 2026); legislation targeted early 2027 | Reversal: PM announced (15 Jul 2026) mandatory "Australian Standards for AI"; Office of AI established; AI Safety Institute remains advisory-only pending legislation |
| Brazil | ◐ | Chamber floor vote (timing uncertain; targeted pre-Aug 2026 recess) | Passed Senate Dec 2024; stalled in Chamber special committee |
Legend: ✓ binding framework in force · ◐ pending / partial · — none identified in this research. Sources as cited per entry above; treat as directional and subject to change as the EU Digital Omnibus, Brazil's PL 2338, and the UK's Regulating for Growth Bill all remain in motion.