← All Reports

Proposed, Not Passed: How States Are Approaching AI Consumer Protection

Cara Sherpa is a graduate research assistant with the Center for Analytics and Innovation with Data (CAID) at the University of Denver's Daniels College of Business. In this invited post, Cara uses data from CAID's State AI Policy Tracker to examine how state legislatures are approaching AI consumer protection and what the patterns in proposed bills reveal about the direction of the policy debate.

While reviewing state legislation for CAID's AI Policy Tracker, I noticed that many states aren't trying to regulate every aspect of AI through one large bill. Instead, lawmakers are focusing on specific situations where AI could mislead people, use their personal information without permission, or cause harm. One approach found across several bills is disclosure. The basic idea is that people should know when they are interacting with an AI system rather than a person. Alabama HB 325, introduced in 2026, would require businesses using AI chatbots in commercial transactions to tell consumers that they are communicating with a chatbot. If they fail to provide that notice, it could be treated as an unfair or deceptive trade practice. Alabama HB 325 died in committee, but it shows how disclosure can serve as one possible first layer of consumer protection.

New Mexico HB 28, the Artificial Intelligence Transparency Act, would have taken a broader approach. The bill would have required notice when AI was used in certain consequential decisions involving employment, education, housing, financial services, insurance, healthcare, and legal services. The bill was postponed indefinitely and didn't become law. Still, bills like this show that transparency can be a starting point for AI consumer protection. As AI-generated conversations and content become more realistic, people may not always realize when AI is involved. Requiring a disclosure gives consumers information that could help them decide whether they want to continue with an interaction or rely on the information given by the AI system. However, disclosure itself doesn't answer every question. Knowing that AI is being used doesn't necessarily tell someone what information the system collected, how it reached its answer, or what they can do if the result is wrong. Disclosure may also be ineffective if it's hidden in terms of service or written in a way that most people won't understand.

A narrower version of this issue also appears at the federal level. Unlike the state bills discussed above, the FTC proposal is not generally about telling consumers when AI is being used. Instead, the agency's July 2026 proposed policy statement focuses specifically on AI companies that manipulate their systems' outputs to advance undisclosed ideological objectives. The FTC argues that this could be deceptive if consumers reasonably expect the systems to provide objective and accurate responses. Although its focus differs from the state disclosure bills, the proposal raises a related concern about whether companies are being transparent about how their AI systems operate.

Another pattern I noticed involves consent and personal identity, although the bills address different types of harm. New Mexico HB 22 focused on sensitive and deepfake images. It would have expanded protections against the unauthorized distribution of sensitive images to include sensitive deepfake images. Idaho HB 744 addressed a separate issue: the commercial collection and use of biometric identifiers. It would have required businesses to notify people and obtain their consent before collecting this information. Both proposals died, but they show why consent matters in different ways. People should have control over how their identity is represented and how businesses collect or use their biometric information. This is especially important because people can't simply replace their face or voice in the same way they can change their password.

The bills also show that lawmakers are paying closer attention to AI used in sensitive services. Florida HB 281, considered during the 2026 legislative session, would have restricted the use of AI in psychology, clinical social work, marriage and family therapy, and mental health counseling. However, it was not a complete ban. The bill would have allowed AI for certain administrative and support tasks, as well as recording or transcription with advance written consent. In these situations, disclosure alone may not be enough. If someone is seeking mental health support, they may reasonably expect a trained professional to remain responsible for the guidance they receive. The bill died in committee.

Overall, the bills I reviewed show that lawmakers are approaching AI consumer protection piece by piece. Some bills focus on chatbots, while others deal with consequential decisions, personal information, digital replicas, or professional services. The approaches are different, but they are responding to many of the same concerns. Because none of these proposals became law, they reveal the direction of the policy debate more than the protections consumers currently have. What stood out to me is that disclosure may be a starting point, but it is not the end of the conversation. As AI becomes part of everyday services, lawmakers will also have to think about consent, privacy, human responsibility, and what happens when consumers are harmed. Using AI shouldn't remove a company's responsibility to communicate honestly, protect personal information, and be accountable to the people using its products.

Explore the tracker

Open Dashboard →