State Legislatures Continued Their Focus on Public Sector AI Use and Expanded Attention to Risk Management Practices During the 2025 Legislative Session
Throughout the 2025 legislative session, state lawmakers continued their focus on establishing safeguards around public sector uses of AI, alongside efforts to regulate the use of AI in education and address the privacy of administrative data. Last year, CDT published an analysis of state bills focused on public sector uses of AI from the 2024 legislative session, finding that state legislators introduced 43 such bills, including 12 of which were passed into law. In 2025, lawmakers continued this strong bipartisan trend, introducing an even greater number of bills specifically designed to regulate public sector AI, resulting in 50 total bills introduced across 20 states including 15 passed into law.
This brings the total number of states that have passed legislation that specifically addresses the use of AI by government agencies to 19, up from 16 last year (which includes several states that have multiple public sector AI laws on the books). These numbers only represent legislation that is specifically focused on government agencies’ use of AI and do not include automated decision-making bills, comprehensive AI governance bills (which can often apply to public agencies), or bills focused on banning the use of AI tools developed by other countries (such as China), meaning the total number of bills impacting government agencies is larger. In addition to continued action at the state level, local governments are taking action on public sector AI. For example, the New York City Council passed a package of three bills designed to regulate uses of AI by city agencies.
Compared to 2024, state public sector AI proposals remained focused on many of the same categories, with risk management practices emerging as the largest area of interest. Several promising proposals were enacted into law that can serve as models for state lawmakers heading into the 2026 legislative session.
Trends in 2025 State Public Sector AI Bills
Since last year, the areas of focus across public sector AI legislative proposals have shifted slightly, with some categories (like pilot programs) receiving no attention and others (like risk management practices) receiving increased attention. Among the 50 public sector AI legislative proposals from the 2025 session, bills generally fell into the following three areas:
Risk management, especially requiring the implementation of new practices aimed at preventing harms of high-impact AI uses and imposing new procurement requirements around AI used by the public sector;
AI governance, particularly creating tasks forces and studies to oversee public sector AI use, as well as establishing centralized leadership of AI use, often through designating an individual office and/or chief AI officer; and
Transparency, like publishing public-facing inventories of how public agencies use AI.
Risk Management
Within the proposals focused on risk management, bills most often sought to implement a broad set of risk management practices or to impose new procurement requirements for AI tools.
Implement Risk Management Practices
Twenty-five proposed bills, including ten that became law, would require public agencies to implement safeguards when using AI tools, rising to the largest category of public sector AI bills during the 2025 session. While the bills within this category vary between proposals, they generally impose safeguards such as acceptable use policies, impact assessments, notice and disclosure obligations, and human oversight mandates.
Some of these proposals would implement comprehensive government-wide requirements or direct a centralized office to issue government-wide standards and guidance. For example, Alaska’s SB 2 would have required all state agencies to conduct impact assessments for generative AI tools, Illinois’ SB 1366 would have directed the state Department of IT to establish policies on state agencies’ use and development of AI, and Rhode Island’s HB 5123 would have required the state Department of Administration to create policies on the use and procurement of AI by state agencies, including impact assessments. By contrast, a number of other bills target specific agencies or would impose a more targeted subset of safeguards. For instance, Nevada’s AB 537 would have imposed notification requirements that only apply to the Department of Taxation, Texas’ HB 3512 establishes AI training requirements for state employees, and California’s SB 833 would have required agencies that are in charge of critical infrastructure to implement human oversight for AI tools.
Impose New Procurement Requirements
Six bills, none of which became law, would create risk management requirements for AI tools that are procured by state agencies, a similar amount of focus as during the 2024 session. Some bills offered standalone proposals that focus exclusively on procurement, such as New York’s AB A5216 which would have required that any AI system purchased by a state agency adhere to a set of responsible AI standards. Other proposals address AI procurement as part of a larger set of actions, such as Illinois’ SB 2117 which would have directed the Generative AI and Natural Language Processing Task Force to issue recommended policies on state AI procurement in addition to a host of other areas of inquiry.
AI Governance
Of the legislative proposals addressing governance, bills tended to focus on creating task forces and studies or on establishing centralized leadership structures.
Create Task Forces and Studies
Sixteen bills, including four that became law, would create task forces or studies to evaluate current and future uses of AI by public agencies. In 2024, this was the largest category of public sector AI bills, and it continued to receive significant attention from lawmakers this session. While somewhat varied, the bills in this category generally direct a state technology agency or a task force to conduct evaluations of the use and impact of AI on state agencies and to provide recommended courses of action and potential state policies. These include Illinois’ SB 2117, which would have directed the state’s existing IT Task Force to develop recommended policies on the use and procurement of AI by state agencies, and Hawaii’s HB 1384, which would have established a state AI Advisory Council to develop an action plan on the responsible use of AI in state government.
Establish Centralized Leadership Through a Designated Office and/or Chief AI Officer
Nine bills, including one that became law, would establish executive leadership or centralized oversight offices focused on the use of AI within state governments. This grew as an area of interest for lawmakers during the 2025 session. As compared to last year, states built off of proposals to hire or appoint Chief AI Officers by introducing bills that would dedicate entire offices to AI governance practices. For example, Maine’s LD 872 would have directed the Office of Information Technology to act as the entity within state government responsible for overseeing the use and procurement of AI, New York’s SB 933 would have established an Office of AI within the Office of Information Technology to be led by a Chief AI Officer, and Texas’ HB 2818 creates an AI Division within the Department of Information Resources.
Transparency
Like last year, bills on transparency primarily focused on establishing inventories of the AI systems used by public agencies.
Publish AI Inventories
Eight bills, including two that became law, would impose requirements for state agencies to create AI inventories. This continued as a main area of focus for lawmakers, though with fewer proposals than 2024. However, this is likely due to the fact that a growing number of states have already implemented requirements for AI inventories.
Like 2024, the proposed bills in this category vary in terms of their scope, frequency, and detail. For instance, Georgia’s HB 147 would have required the state Technology Authority to conduct annual inventories of public agencies’ AI tools, North Carolina’s SB 747 would have required state agencies to conduct a one-time inventory of all AI systems actively used or in consideration by state agencies, and Alaska’s SB 2 would have required all state agencies to create inventories of generative AI tools every two years.
Strong Examples
State lawmakers considering passing their own legislation on public sector uses of AI should consider several strong examples from the 2025 session, which were all passed into law. In particular, three proposals emerge as key standouts that, while differing in approaches, each institute a relatively strong set of guardrails around how public agencies use and oversee AI technologies:
Kentucky’s SB 4 provisions related to state agencies’ use of AI establish a comprehensive approach to public sector AI governance. These requirements include directing the Office of Technology to establish standards for the responsible use of AI (including risk management policies for high-risk AI systems), establishing an AI Governance Committee, requiring agencies to publicly disclose their use of AI, and creating an AI inventory.
Texas’ SB 1964 is part of a slate of bills the legislature passed focused on public sector uses of AI. SB 1964 creates a strong government-wide framework for public sector AI use and oversight. The bill’s provisions require the Department of Information Resources to inventory AI systems deployed by state agencies, require state agencies to adopt risk management and governance standards for high-risk AI systems, and direct the Department to establish an AI code of ethics that addresses human oversight, accuracy, privacy, and security.
Montana’s HB 178, while not as comprehensive as the other two, establishes some key safeguards around how public agencies use AI. This includes requirements for government agencies to disclose the use of AI, human review obligations for high-risk systems, and a prohibition on the use of AI by government agencies’ for cognitive manipulation, social classification, deception, and surveillance in public spaces.
Conclusion
Public agencies are continuing to expand their adoption and use of AI across the country, making this an important area for lawmakers to continue to address through legislation, especially given the significant consequences and harms that can occur when public sector AI projects fail. As state lawmakers now head into the 2026 legislative session, they should look to the strong examples from the past year as potential models for passing their own laws to govern and oversee how public agencies use AI, ensuring that these tools are used safely and benefit the public.
Coalition Urges Senate Not to Let Companies Waive Financial Regulations for AI
CDT joined AI Now Institute, American Civil Liberties Union, and several organizations dedicated to tech policy, consumer protection, and civil rights in a letter to Senate leadership and the Senate Banking, Housing, and Urban Affairs Committee opposing the “AI Innovation Labs” language in Sec. 10509 of the CLARITY Act.
As concern about risks and harms related to AI systems continue to grow, a growing chorus of policymakers, industry leaders, and advocates have called for independent AI assessments. This explainer provides an overview of recent proposals for third-party assessment in the United States, including state and federal legislation, executive actions, and industry proposals.
Having third parties assess AI systems might seem like common sense, but crafting effective policies toward this goal can be devilishly tricky. A poorly-constructed ecosystem for third-party assessment could easily fail to consider the most consequential mechanisms of risk, neglect the AI harms that most impact people, or do more to protect AI companies than people.
Not All Guardrails Are Created Equal: Comparing Content Safety and Copyright Filtering
As courts and policymakers work through questions about chatbot liability, they should be wary of analogies that flatten meaningful technical differences. Copyright filtering and safety intervention share real challenges around ambiguity and evasion, but they diverge in what each control must assess, how each manifests over the course of a conversation, and how much can be verified from the outside.