US State Privacy Laws (AI provisions) carries 13 tracked obligations for companies in scope. This guide lists who is covered, the duty tiers, and every obligation with its deadline and statutory citation — all from Shieldra's versioned regulation pack, verified 2026-09-09.
What are the duty tiers under US State Privacy Laws (AI provisions)?
Profiling and automated-decision duties apply (State privacy laws — profiling opt-out and data protection assessments (VA, CO, CT, OR, TX, MT, DE, NH, NJ, NE, TN, IN, KY, RI, MN, MD; CA via 11 CCR §§7200–7222))
Citation: State privacy laws — profiling opt-out and data protection assessments (VA, CO, CT, OR, TX, MT, DE, NH, NJ, NE, TN, IN, KY, RI, MN, MD; CA via 11 CCR §§7200–7222) — https://www.venable.com/insights/publications/2026/07/2026-mid-year-state-privacy-law-update
You use personal data in decisions with legal or similarly significant effects in at least one state that regulates it. Expect opt-out rights, pre-processing assessments, and in Minnesota and Connecticut a right to question the result. California's specific automated-decision duties apply from 1 January 2027.
AI data-handling duties apply (CCPA risk assessments (11 CCR §7150); Illinois BIPA (740 ILCS 14); Washington MHMDA (RCW 19.373); state sensitive-data consent rules)
Citation: CCPA risk assessments (11 CCR §7150); Illinois BIPA (740 ILCS 14); Washington MHMDA (RCW 19.373); state sensitive-data consent rules — https://www.law.cornell.edu/regulations/california/11-CCR-7051
No significant-decision profiling, but the data your AI uses — training data, sensitive categories, biometrics, health inferences, minors' data, or vendor training rights — triggers consent, assessment, contract, or retention duties.
General state privacy duties (State comprehensive privacy laws (19 in force))
Citation: State comprehensive privacy laws (19 in force) — https://www.venable.com/insights/publications/2026/07/2026-mid-year-state-privacy-law-update
A state privacy law reaches you but your AI use does not trigger its profiling or AI-data provisions. The general duties — notices, rights requests, vendor contracts, reasonable security — still apply and are listed below; re-screen when you add profiling, model training, or sensitive-data processing.
What should you do about each obligation?
Privacy-law contract terms with every AI vendor and processor (11 CCR §7051 (CCPA service-provider contract terms); Va. Code §59.1-579 and the equivalent processor provisions in each state law)
Put a written contract in place with every AI vendor or processor that carries the required terms: the specified business purpose; no selling or sharing; no use outside the direct relationship; no combining with data from other sources; CCPA-level protection; assistance with consumer rights requests; notice if the vendor can no longer comply; and your audit and remediation rights (the nine CCPA §7051 terms). Every other state law requires instructions, confidentiality, deletion or return at the end of service, sub-processor flow-down, and audit rights, and Maryland and Minnesota require documented assessments per processing activity. Processors: keep to the controller's instructions, flow the terms down to your own sub-processors, and support rights requests and assessments.
Privacy notice covers AI uses, profiling, and model training (Conn. Gen. Stat. §42-520 as amended by SB 1295 (2025); Cal. Civ. Code §1798.100; Connecticut AG AI guidance (25 Feb. 2026))
State in your privacy notice that personal data is used for AI features, profiling, or automated decisions, the categories involved, the purposes, retention, and the third parties (including AI vendors) that receive it. Connecticut residents must be told whether their personal data is used to train large language models (SB 1295, from 1 July 2026), and the Connecticut Attorney General's February 2026 guidance adds that third-party training data must have been disclosed at collection and that material changes need fresh notice and a way to withdraw consent. California's Attorney General (January 2025 advisory) treats AI training data, inputs, outputs, and inferences as personal information subject to the 'reasonably necessary and proportionate' standard. Minnesota residents may request the list of specific third parties that received their data.
Honor opt-outs from profiling used in significant decisions (Va. Code §59.1-577(A)(5) and equivalents; 11 CCR §7221 (CCPA ADMT opt-out); Conn. Gen. Stat. §42-518 as amended)
Give consumers a working way to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects, and stop such profiling for those who do. Sixteen states require it today (all the opt-out states screened here plus Connecticut, Minnesota, and Maryland); Connecticut's amended definition reaches decisions with human involvement from 1 July 2026. California's version arrives on 1 January 2027 for automated decision-making technology used in significant decisions, with exceptions where you offer a human appeal. Utah and Iowa have no such right.
Data protection assessment before profiling for significant decisions (Va. Code §59.1-580 and equivalents; Md. Com. Law §14-4607; Conn. SB 1295 (2025) impact assessments; Ky. KCDPA (assessments from 1 June 2026))
Before using profiling in significant decisions, complete and retain a data protection assessment weighing benefits against risks to consumers and the safeguards applied: purpose, data, foreseeable risks of unfair or unlawful disparate impact (Kentucky names it), and mitigations. Maryland requires an assessment for each algorithm used; Connecticut adds separate impact assessments for covered profiling from 1 August 2026, with a consumer right to know the reasons for a decision, review and correct the inputs, and have the decision re-run. Attorneys general can demand the assessment; it is your first response to an inquiry.
CCPA risk assessment for automated decisions, sensitive data, and model training (11 CCR §§7150–7157 (CPPA regulations approved 22 Sept. 2025))
Complete a documented risk assessment before selling or sharing personal information, processing sensitive personal information, using automated decision-making technology for a significant decision, profiling employees, students, or people in publicly accessible places, or using personal information to train ADMT for significant decisions or to train facial-recognition, emotion-assessment, or identity-verification technology (§7150(b)(6) — training is a trigger on its own, before any deployment). Cover purpose, data categories, benefits, negative impacts, safeguards, and whether to proceed; retain for five years; submit an attestation and summary to the CPPA by 1 April 2028 covering 2026–2027. Cybersecurity audit certifications follow by revenue tier from 1 April 2028. The CPPA and Attorney General have been active: Honda, Todd Snyder, Tractor Supply (2025), PlayOn Sports, Ford, Disney, and GM ($12.75M, 8 May 2026 — the first data-minimization case) in 2026.
CCPA automated decision-making: pre-use notice, opt-out, and access (11 CCR §§7200–7222 (CPPA ADMT regulations))
For technology that processes personal information to replace or substantially replace human decision-making in a significant decision (financial or lending services, housing, education, employment or independent-contracting opportunities and compensation, health care), provide a pre-use notice describing the purpose and the consumer's rights; offer an opt-out unless an exception applies (for example, a human appeal to a reviewer who can change the decision); and on request explain the logic, the key parameters, and how the output was used. The definition has a real exit: if a human reviewer can interpret the output, analyze the information, and change the decision, the tool is not ADMT. Advertising was dropped from the significant-decision list in the final rules.
Let consumers question profiling results, see the data used, and get a re-evaluation (Minnesota, Connecticut) (Minn. Stat. §325O.05, subd. 1(f); Conn. Gen. Stat. §42-518 as amended by SB 1295 (2025))
When profiling contributes to a decision with legal or similarly significant effects, give the consumer on request the reason for the result, the categories of personal data used, a way to review and correct that data, and a re-evaluation of the decision on the corrected data. Minnesota created the right (in force since 31 July 2025) and also requires a documented privacy program and data inventory; Connecticut adopted it from 1 July 2026 and applies it to decisions with human involvement, not only fully automated ones. Build the review path once and it satisfies both, and it doubles as the human-appeal exception under California's 2027 ADMT rules.
Maryland: strict data minimization and no sale of sensitive data (Md. Com. Law §§14-4601 to 14-4613 (Maryland Online Data Privacy Act))
Collect personal data only where reasonably necessary and proportionate to the product or service the consumer requested; process sensitive data only where strictly necessary; never sell sensitive data (no consent exception); do not sell or use for targeted advertising the data of consumers you know or should know are under 18; and run and retain a data protection assessment for each algorithm used in profiling. The threshold is 35,000 consumers a year (10,000 with more than 20% of revenue from sales). AI features that hoover up 'nice-to-have' data fail the necessity test; scope collection to the feature.
Consent and use limits for sensitive data in AI processing (Va. Code §59.1-578(A)(5) and equivalents; Cal. Civ. Code §1798.121; N.J.S.A. 56:8-166.4 et seq. (2026 amendment))
Obtain opt-in consent before processing sensitive data in the Virginia-model states, Connecticut, Maryland, and Minnesota; in California honor the right to limit use and disclosure of sensitive personal information to the enumerated purposes, and treat inferences drawn from sensitive data as sensitive; in New Jersey do not sell sensitive data at all since 30 June 2026; in Maryland never sell it. Neural data is sensitive in California, Colorado, and Connecticut; precise geolocation sales are banned in Oregon (since 1 January 2026), Virginia (1 July 2026), and Connecticut (1 October 2026). AI models that infer sensitive attributes from ordinary data create sensitive data and inherit these rules.
Biometric identifiers: written consent, policy, and retention schedule (IL, TX, WA, CO) (740 ILCS 14 (BIPA); Tex. Bus. & Com. Code §503.001 (CUBI); RCW 19.375; Colo. Rev. Stat. §6-1-1314 (HB 24-1130))
Before creating or collecting a face template, voiceprint, or other biometric identifier: publish a written retention and destruction policy; give notice of the purpose and retention period; obtain a written release (Illinois) or consent (Texas, Washington); never sell or profit from the identifier; destroy it when the purpose ends or within the statutory period (Colorado: the earliest of purpose satisfied, 24 months after last interaction, or 45 days after no longer needed). Illinois carries a private right of action at $1,000 or $5,000 per violation, now one recovery per person per collection method after the 2024 amendment; the 2025–2026 wave targets AI meeting assistants (Otter.ai, Fireflies, Microsoft) and, in May 2026, nine coordinated class actions over voiceprints extracted from public audio to train voice models. Texas is Attorney-General-only at $25,000 per violation (Google, $1.375B, May 2025) and, after TRAIGA, exempts biometric data used only to train AI unless the system uniquely identifies a person. Colorado applies to any controller regardless of size, including employers, and bars conditioning employment on biometrics for emotion tracking, location, or performance analysis. Maryland separately requires a signed waiver before facial recognition in job interviews.
Consumer health data outside HIPAA: consent, no sale without authorization, no geofencing (WA, NV) (RCW 19.373 (My Health My Data Act); Nev. Rev. Stat. ch. 603A as amended by SB 370 (2023))
Treat any information that identifies a consumer's physical or mental health status — including inferences your AI draws from non-health data — as consumer health data: publish a separate consumer health data privacy policy, obtain consent to collect or share it beyond what the consumer requested, obtain a separate signed authorization before selling it, honor deletion requests, and never geofence health facilities. Washington's law carries a private right of action through its Consumer Protection Act (first class action, Maxwell v. Amazon, filed February 2025 and pending); Nevada's is enforced by the Attorney General. Where you hold personal health records as a non-HIPAA app, the FTC's Health Breach Notification Rule treats an unauthorized disclosure to an AI or ad vendor as a breach with 60-day notice duties.
Treat vendor model-training on your data as a sale or share with opt-outs (Cal. Civ. Code §1798.140(ad), (ah); 11 CCR §7051; state 'sale' definitions)
Either contractually prohibit the vendor from using your data to improve its own models — which keeps it a service provider or processor — or accept that the transfer is a 'sale' or 'share': post the 'Do Not Sell or Share' link, honor Global Privacy Control signals, obtain opt-in for known under-16s (California) and never sell known minors' data in Connecticut, Maryland, or Oregon, and disclose the vendor as a recipient. Enterprise and API tiers of the major AI providers disable training by default; consumer tiers do not. Under the CCPA a vendor that trains on your data cannot be a service provider regardless of what the contract says.
Minors' data: no sale or targeted advertising to known minors; heightened design duties (Conn. SB 3 (2023) and SB 1295 (2025); Md. Com. Law §14-4607(a)(3); Or. Rev. Stat. §646A.578 (2025 amendment); Neb. Age-Appropriate Design Code Act)
Do not sell the personal data of, or serve targeted advertising to, consumers you know or should know are minors in Connecticut, Maryland, or Oregon (under 16), regardless of consent; in Connecticut avoid design features that maximize engagement or that would cause a heightened risk of harm to minors, and run the required assessments; in Nebraska apply the age-appropriate design code (penalties from 1 July 2026); in Vermont the design code applies from 1 January 2027. Companion-chatbot duties for minors are in the state AI packs; under-13 users are governed by federal COPPA.