Providing consumer protections for artificial intelligence systems.
What changed between versions
The definition of 'high-risk artificial intelligence system' was changed to require 'meaningful human consideration' to avoid being classified as high-risk, and the definition of 'substantial factor' was updated to focus on factors generated by AI.
New definitions were added for 'meaningful human consideration' and 'consumer' (limiting it to individual/household contexts, excluding commercial use).
Exemptions were expanded to include developers with fewer than 50 employees and deployers who do not use their own data to train the system.
Risk management policy requirements were restructured to apply separately to both developers and deployers, with specific criteria for each.
New requirements were added for insurers and financial institutions, including specific exemptions for those regulated by the Insurance Commissioner.
The disclosure requirement for AI interactions was updated to remove the specific prohibition on 'high-risk' systems, applying broadly to all AI interactions with consumers.
Enforcement was centralized under the Attorney General with a new provision allowing a 60-day cure period for the first violation.
The expiration date for the AI task force was extended from June 30, 2027, to June 30, 2028.