| Momentum Bucket | Early Stage |
| Legal Title | AN ACT Relating to regulating high-risk artificial intelligence system development, deployment, and use; |
| Bill Description | Regulating high-risk artificial intelligence system development, deployment, and use. |
|
What this bill does
Powered by Legitron |
This bill creates a new chapter in Title 19 RCW (new state law, effective January 1, 2027) establishing duties for developers and deployers of "high-risk" artificial intelligence systems—defined as systems intended to autonomously make, or be a substantial factor in making, consequential decisions affecting consumers. It requires developers (doing business in Washington who meet the revenue threshold) to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination and to provide specified disclosures and documentation to deployers or other developers about intended uses, limitations, evaluation and mitigation of discrimination risks, and guidance on proper use. Compliance with the developer and deployer duties creates a rebuttable presumption of reasonable care in any civil action under the chapter.
The bill imposes parallel duties on deployers (persons doing business in Washington who use high-risk systems to make consequential decisions): design and implement a risk management policy and program (with presumptive compliance if aligned with NIST AI RMF or ISO/IEC 42001), complete predeployment impact assessments before initial use and before significant updates, retain assessments and related records for at least three years, disclose to consumers that they are interacting with an AI system and provide detailed plain-language disclosures about the system, and transmit consequential decisions to consumers without undue delay. Impact assessments must include the system’s purpose, foreseeable discrimination risks and mitigations, data categories and metrics used, monitoring and safeguards, and related elements.
The bill addresses generative AI by requiring developers of high-risk generative systems that produce synthetic content to ensure outputs are identifiable or detectable by consumers at the time generated (with specified exceptions), and sets timelines for updating disclosures after intentional and substantial modifications (developers: within 90 days; deployers: update disclosures within 30 days after notification). It enumerates many statutory and sectoral exemptions and limits (for example, certain federal systems, financial institutions subject to federal credit laws, HIPAA-covered entities, regulated insurers, sanctioned research sandboxes), preserves trade secret and security protections, and places the burden on a party claiming an exemption to demonstrate it. Enforcement is civil: a person may sue a developer or deployer for violations; courts may enjoin violations and award reasonable attorneys’ fees and costs, and an affirmative defense is available if a violator cures the violation within 45 days of discovery and notifies the plaintiff with evidence.
The extracted text is incomplete in places: a prohibition in Sec. 2(2) is cut off, section 3 is referenced but not fully included here, Sec. 6 is incomplete, and the exact new chapter number in Title 19 RCW is not shown. Other enforcement details or any criminal penalties beyond the civil remedies described are not present in the provided material.
|
|
Why it matters
Powered by Legitron |
If enacted, Washington businesses that develop or use AI systems that drive major decisions will need to spend time and money documenting and managing discrimination risks, follow recognized risk-management frameworks (like NIST or ISO), and give detailed disclosures to downstream users and consumers. Developers who make high‑risk systems (including those earning more than $100,000 annually) must provide intended‑use statements, known limitations and mitigation steps, update those disclosures within 90 days after major changes, and ensure generative outputs are identifiable when required; deployers must run and keep impact assessments before initial use and significant updates, retain records for three years, notify consumers when they are interacting with AI, and explain adverse consequential decisions including the AI’s role.
The parties most affected are AI developers and organizations that deploy AI to make consequential decisions in Washington; they will likely face higher compliance costs, new documentation and monitoring responsibilities, and increased legal risk because consumers can sue and courts can award injunctions and fees (developers/deployers get a limited defense only if they cure violations and notify plaintiffs within 45 days). The law creates narrow exemptions for certain federally regulated activities, banks, insurers, HIPAA-covered entities, approved federal systems, and sanctioned research, and those claiming exemptions must prove and notify when they withhold information; some enforcement and definitional details are missing from the provided text, so how regulators will implement and interpret several obligations is uncertain.
|
| Official Documents | View Full Bill Text |
| Date Introduced | 01/27/2026 |
| Originating Chamber | House |
| Biennium | 2025-26 |
| Total Campaign Dollars Backing Bill | $5,666,335.00 |
| BUSINESSES |
| Hearing | House Technology, Economic Development, & Veterans (Public) |
| Hearing | House Technology, Economic Development, & Veterans (Executive) |