| Momentum Bucket | Early Stage |
| Legal Title | AN ACT Relating to regulating high-risk artificial intelligence system development, deployment, and use; |
| Bill Description | Regulating high-risk artificial intelligence system development, deployment, and use. |
|
What this bill does
Powered by Legitron |
This bill creates a new chapter in Title 19 RCW establishing a regulatory framework for "high‑risk" artificial intelligence systems. It imposes civil obligations and procedures on developers and deployers: developers must disclose intended uses, known limitations and risks of algorithmic discrimination, summaries of predeployment evaluation and mitigation steps, and make available documentation to enable deployers or their contractors to complete impact assessments. Deployers must adopt risk management policies and programs, complete impact assessments before initial use and before significant updates, retain impact assessments and related records for specified periods, disclose to consumers at the time of AI interaction (including that an AI was used, its purpose, and key data and human oversight elements), and transmit consequential decisions to consumers without undue delay.
The bill defines key terms (including algorithmic discrimination, consequential decision, developer, deployer, high‑risk AI system, generative AI, facial recognition, and others) and sets timing rules and presumptions: developers must update disclosures within 90 days after an intentional and substantial modification and deployers must update disclosures within 30 days after notification; compliance with certain provisions creates a rebuttable presumption of reasonable care in civil actions; conformity with the NIST AI risk management framework, ISO/IEC 42001, or equivalent frameworks is presumed to satisfy related requirements. It also requires identification of outputs of high‑risk generative AI where applicable, exempts trade secrets and security‑sensitive information from disclosure, lists numerous statutory and sectoral exemptions (including certain federal agency approvals, regulated financial institutions and insurers, HIPAA-covered uses, sanctioned research sandboxes, and law‑enforcement uses), allocates the burden to claim exemptions, and includes severability.
This is a procedural and regulatory change (not a new criminal offense or explicit penalty change in the provided text): it creates new civil duties, documentation and transparency requirements, recordkeeping obligations, and civil‑law presumptions. The act takes effect January 1, 2027. The extracted materials do not include complete text for some developer disclosure items, the full language of section 3 (impact assessment mechanics), specific RCW section numbers for the new chapter, or any enforcement mechanisms or penalties beyond the rebuttable civil presumptions.
|
|
Why it matters
Powered by Legitron |
If enacted, the law would force companies that build or supply AI systems used to make important decisions in Washington to produce and update detailed documentation about how those systems are meant to be used, their known limits and discrimination risks, and the steps taken to test and mitigate those risks; generative systems that create images, audio, or video would generally need to mark outputs so people can tell they are synthetic. Businesses in Washington that actually use those systems would have to adopt formal risk-management programs, run written impact assessments before deployment and after significant changes, keep assessment records for at least three years, notify consumers when they are interacting with an AI and explain how a consequential decision was reached, and forward consequential decisions to consumers promptly. Following recognized risk-management frameworks like NIST or ISO is treated as meeting many requirements, and complying gives developers and deployers a rebuttable presumption of reasonable care and a 45-day window to cure discovered violations.
The groups most affected are AI developers who do business in Washington and earn more than $100,000, and any Washington business that deploys AI that substantially influences legal, financial, housing, employment, health, education, or similar consequential decisions; these actors will likely face added compliance costs for documentation, testing, monitoring, labeling, staff time, and legal review, and may change procurement or product design to avoid covered “high-risk” uses. Consumers should see more transparency and potential safeguards, while some entities—federally regulated agencies, many financial institutions and insurers subject to existing supervision, certain healthcare and approved research uses, and narrowly defined other exemptions—would face fewer new obligations. The extracted text leaves out the full list of required disclosures and the enforcement or penalty details, so the exact scope of compliance costs and legal risk is uncertain.
|
| Official Documents | View Full Bill Text |