New Mexico 2025 Regular Session Status: In Committee 5 D cosponsors

HB 60 — ARTIFICIAL INTELLIGENCE ACT

Last action — action postponed indefinitely

  1. ✓
    Introduced
  2. 2
    In Committee
  3. 3
    Passed House
  4. 4
    Passed Senate
  5. 5
    To Executive
  6. 6
    Enacted

This bill died with 2025 Regular Session. It reached “In Committee” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.

This bill is no longer active — its legislative session has ended, so there are no live odds of enactment. It would have to be reintroduced in the current session to move again.

Bill Text

What changed in the latest version

793 added · 702 removed

Plain-language change summary

The amendment to HB 60 clarified the definition of an "artificial intelligence system" by specifying that it is a machine learning-based system rather than any machine-based system. This change emphasizes the focus on advanced, learning-enabled technologies and how they interact with issues of diversity and discrimination. Overall, this is important because it narrows the scope of the bill to better address the complexities and risks associated with high-risk AI systems.

→
Previous
Latest
HOUSE BILL 60 57TH LEGISLATURE -STATEOFNEWMEXICO- FIRST SESSION, 2025 INTRODUCED BY Christine Chandler and Andrea Romero and Debra M.
HOUSE JUDICIARY COMMITTEE SUBSTITUTE FOR HOUSE BILL 60 57 TH LEGISLATUR- STATE OF NEW MEXICO - FIRST SESSIO, 2025 4 6 8 10 AN ACT RELATING TO ARTIFICIAL INTELLIGENCE;
Sariñana and Linda M.
Trujillo and Heather Berghmans 7 9 AN ACT RELATING TO ARTIFICIAL INTELLIGENCE;
"algorithmic discrimination" means any condition u [ in which the use of an artificial intelligence system results .228797.3 in an unlawful differential treatment or impact that disfavors a person on the basis of the person's actual or perceived age, color, disability, ethnicity, gender, genetic information, proficiency in the English language, national origin, race, religion, reproductive health, veteran status or other status protected by state or federal law, but does not include:
"algorithmic discrimination" means any condition u [ in which the use of an artificial intelligence system results .230826.6 HJC/HB 60 in an unlawful differential treatment or impact that disfavors a person on the basis of the person's actual or perceived age, color, disability, ethnicity, gender, gender identity, genetic information, proficiency in the English language, national origin, race, religion, reproductive health, veteran status or other status protected by the New Mexico Civil Rights Act or federal law, but does not include:
or (2) an act or omission by or on behalf of a e t 17 private club or other entity that is not open to the public w l n d 18 pursuant to federal law;
or e t 17 (2) an act or omission by or on behalf of a w l n d 18 private club or other entity that is not open to the public = = 19 pursuant to federal law;
= = 19 a l B.
a l i a e r 20 B.
"artificial intelligence system" means any i a e r 20 machine-based system that for an explicit or implicit objective a t m m 21 infers from the inputs the system receives how to generate d r e 22 outputs, including content, decisions, predictions or c e s k 23 recommendations, that can influence physical or virtual e a n b 24 environments;
"artificial intelligence system" means a:
u [ C.
a t m m 21 (1) machine learning-based system that, for an d r e 22 objective, infers from the inputs the system receives how to c e s k 23 generate outputs, including content, decisions, predictions and e a n b 24 recommendations, that can influence physical or virtual u [ environments;
"consequential decision" means a decision that .228797.3 - 2 - has a material legal or similarly significant effect on the provision or denial to a consumer of or the cost or terms of:
or .230826.6 - 2 - HJC/HB 60 (2) system that a developer markets or describes in its technical documentation as using artificial intelligence or machine learning;
(1) education enrollment or an educational opportunity;
C.
"consequential decision" means a decision that has a material legal or similarly significant effect on the provision or denial to a consumer of or the cost or terms of:
(1) education enrollment;
"deploy" means to use an artificial intelligence system;
"department" means the state department of justice;
F.
e t 17 F.
"deployer" means a person who deploys an artificial intelligence system;
"deploy" means to put into effect, host or w l n d 18 otherwise commercialize an artificial intelligence system;
G.
= = 19 G.
"developer" means a person who develops or e t 17 intentionally and substantially modifies an artificial w l n d 18 intelligence system;
"deployer" means a person or public entity that a l i a e r 20 deploys or uses a high-risk artificial intelligence system to a t m m 21 make a consequential decision affecting a consumer in New d r e 22 Mexico;
= = 19 a l H.
c e s k 23 H.
"health care services" means treatment, services i a e r 20 or research designed to promote the improved health of a a t m m 21 person, including primary care, prenatal care, dental care, d r e 22 behavioral health care, alcohol or drug detoxification and c e s k 23 rehabilitation, hospital care, the provision of prescription e a n b 24 drugs, preventive care or health outreach;
"developer" means a person or entity doing e a n b 24 business in New Mexico that:
u [ I.
u [ (1) makes an artificial intelligence system .230826.6 - 3 - HJC/HB 60 publicly available for use in New Mexico;
"high-level summary" means information about the .228797.3 - 3 - data and data sets used to train the high-risk artificial intelligence system, including:
(2) intentionally and substantially modifies a high-risk artificial intelligence system that is used in New Mexico;
(1) the sources or owners of the data sets and whether the data sets were purchased or licensed by the developer;
or (3) intentionally and substantially modifies a non-high-risk artificial intelligence system so that it becomes a high-risk artificial intelligence system that is used in New Mexico;
(2) the factors in the data, including attributes or other information about a consumer, that the system uses to produce its outputs, scores or recommendations;
I.
(3) the demographic groups represented in the data sets and the proportion of each age, ethnic, gender or racial group in each dataset;
"health care services" means treatment or services designed to maintain and promote the improved health of a person, including primary care, prenatal care, dental care, behavioral health care, alcohol or drug detoxification and rehabilitation, enrollment in a clinical trial or similar activity, hospital care, hospice care, the provision of prescription drugs, preventive care or health outreach;
(4) a description of the types of data points within the data sets, including, for data sets that include labels, a description of the types of labels used;
(5) whether the data sets include any data protected by copyright, trademark or patent or whether the data e t 17 sets are entirely in the public domain;
w l n d 18 (6) whether there was any cleaning, processing = = 19 a l or other modification to the data sets by the developer, i a e r 20 including the intended purpose of those efforts in relation to a t m m 21 the high-risk artificial intelligence system;
d r e 22 (7) the time period during which the data in c e s k 23 the data sets were collected, including a notice when data e a n b 24 collection is ongoing;
u [ (8) the geographical regions or jurisdictions .228797.3 - 4 - in which the data sets were collected, including whether the data sets were collected solely in New Mexico, solely in other states or in New Mexico in combination with other states;
and (9) other information as required by the state department of justice by rule;
"high-risk artificial intelligence system" means any artificial intelligence system that when deployed makes or is a substantial factor in making a consequential decision, but does not include:
"high-level summary" means information about the e t 17 data and data sets used to train a high-risk artificial w l n d 18 intelligence system, including:
(1) an artificial intelligence system intended to:
= = 19 (1) the sources or owners of the data sets and a l i a e r 20 whether the data sets were purchased or licensed by the a t m m 21 developer;
(a) perform a narrow procedural task;
d r e 22 (2) the factors in the data, including c e s k 23 attributes or other information about a consumer, that the e a n b 24 system uses to produce its outputs, scores or recommendations;
or (b) detect decision-making patterns or deviations from prior decision-making patterns and is not intended to replace or influence a previously completed human assessment without sufficient human review;
u [ (3) the demographic groups represented in the .230826.6 - 4 - HJC/HB 60 data sets and the proportion of each age, ethnic, gender or racial group in each dataset;
or e t 17 (2) the following technologies, unless the w l n d 18 technologies make or are a substantial factor in making a = = 19 a l consequential decision when the technologies are deployed:
(4) a description of the types of data points within the data sets, including, for data sets that include labels, a description of the types of labels used;
i a e r 20 (a) anti-fraud technology that does not a t m m 21 use facial recognition technology;
(5) whether the data sets include any data protected by copyright, trademark or patent or whether the data sets are entirely in the public domain;
d r e 22 (b) anti-malware;
(6) whether there was any cleaning, processing or other modification to the data sets by the developer, including the intended purpose of those efforts in relation to the high-risk artificial intelligence system;
c e s k 23 (c) antivirus;
(7) the time period during which the data in the data sets were collected, including a notice when data collection is ongoing;
e a n b 24 (d) artificial-intelligence-enabled u [ video games;
(8) the geographical regions or jurisdictions e t 17 in which the data sets were collected, including whether the w l n d 18 data sets were collected solely in New Mexico, solely in other = = 19 states or in New Mexico in combination with other states;
.228797.3 - 5 - (e) calculators;
and a l i a e r 20 (9) other information as required by the a t m m 21 department by rule;
Show all 274 changed rows (234 more)
Previous
Latest
(f) cybersecurity;
d r e 22 K.
(g) databases;
"high-risk artificial intelligence system" means c e s k 23 any artificial intelligence system that when deployed makes or e a n b 24 is a substantial factor in making a consequential decision, but u [ does not include:
(h) data storage;
.230826.6 - 5 - HJC/HB 60 (1) anti-fraud technology;
(i) firewalls;
(2) anti-malware technology;
(j) internet domain registration;
(3) antivirus technology;
(k) internet website loading;
(4) cybersecurity technology;
(l) networking;
(5) databases;
(m) spam and robocall filtering;
(6) database, spreadsheet or other technology that does no more than organize data already in possession of a deployer;
(n) spell checking;
(7) data storage;
(o) spreadsheets;
(8) firewall technology;
(p) web caching;
(9) internet domain registration;
(q) web hosting or similar technology;
(10) internet website loading;
or (r) technology that communicates with consumers in natural language for the purpose of providing e t 17 users with information, making referrals or recommendations and w l n d 18 answering questions and is subject to an accepted use policy = = 19 a l that prohibits generating content that is discriminatory or i a e r 20 harmful;
(11) networking;
a t m m 21 K.
(12) spam and robocall filtering;
"intentional and substantial modification" and d r e 22 "intentionally and substantially modifies" means a deliberate c e s k 23 change made to an artificial intelligence system that results e a n b 24 in a new reasonably foreseeable risk of algorithmic u [ discrimination, but does not include a change made to a high- .228797.3 - 6 - risk artificial intelligence system or the performance of a high-risk artificial intelligence system when:
(13) spell checking technology;
(14) transcription and transition technology;
e t 17 (15) web caching;
w l n d 18 (16) web hosting or similar technology;
or = = 19 (17) technology that communicates with a l i a e r 20 consumers solely in spoken or written natural language for the a t m m 21 purpose of providing consumers with information, making d r e 22 referrals or recommendations and answering questions:
c e s k 23 (a) subject to the deployer's accepted e a n b 24 use policy as explicitly accepted by the consumer that may u [ prohibit generation of specific content by the technology;
and .230826.6 - 6 - HJC/HB 60 (b) that is not used to take any autonomous action without consumer intervention;
L.
"intentional and substantial modification" and "intentionally and substantially modifies" means a deliberate and material change made to an artificial intelligence system that results in a new reasonably foreseeable risk of algorithmic discrimination, but does not include a change made to a high-risk artificial intelligence system or the performance of a high-risk artificial intelligence system when:
(2) the change is made as a result of system learning after being made available to a deployer or being deployed;
(2) the change is made as a result of system learning after being made available to a deployer or being e t 17 deployed;
(3) the change was predetermined by the deployer or a third party contracted by the deployer when the deployer or third party completed an impact assessment of the high-risk artificial intelligence system pursuant to Section 6 of the Artificial Intelligence Act;
w l n d 18 (3) the change was predetermined by the = = 19 deployer or a third party contracted by the deployer when the a l i a e r 20 deployer or third party completed an impact assessment of the a t m m 21 high-risk artificial intelligence system pursuant to Section 6 d r e 22 of the Artificial Intelligence Act;
or (4) the change is included in technical e t 17 documentation for the high-risk artificial intelligence system;
or c e s k 23 (4) the change is included in technical e a n b 24 documentation for the high-risk artificial intelligence system;
w l n d 18 L.
u [ M.
"offered or made available" includes a gift, = = 19 a l lease, sale or other conveyance of an artificial intelligence i a e r 20 system to a recipient deployer or a developer other than the a t m m 21 original system developer;
"machine learning" means the development and .230826.6 - 7 - HJC/HB 60 incorporation of algorithms to build data-derived statistical models that are capable of drawing inferences from previously unseen data without explicit human instruction;
d r e 22 M.
N.
"recipient" means a deployer who has received an c e s k 23 artificial intelligence system from a developer or a developer e a n b 24 who has received an artificial intelligence system from another u [ developer;
"offered or made available" includes a gift, lease, sale or other conveyance of an artificial intelligence system to a recipient deployer or a developer other than the original system developer;
.228797.3 - 7 - N.
"risk incident" means an incident when a developer discovers or receives a credible report from a deployer that a high-risk artificial intelligence system offered or made available by the developer has caused or is reasonably likely to have caused algorithmic discrimination;
"substantial factor" means:
"recipient" means a deployer who has received an artificial intelligence system from a developer or a developer who has received an artificial intelligence system from another developer;
(1) a factor that:
P.
(a) assists in making a consequential decision;
"risk incident" means an incident when a developer discovers or receives a credible report from a deployer that a high-risk artificial intelligence system offered or made available by the developer has caused or is reasonably likely to have caused algorithmic discrimination;
(b) is capable of altering, advising or influencing the outcome of a consequential decision;
e t 17 Q.
and (c) is generated by an artificial intelligence system;
"substantial factor" means a decision, score, w l n d 18 label, prediction or recommendation generated by an artificial = = 19 intelligence system that is used as a basis or partial basis to a l i a e r 20 make a consequential decision;
or (2) content, decisions, labels, predictions, recommendations or scores generated by an artificial intelligence system concerning a consumer that are used as a e t 17 basis, partial basis or recommendation to make a consequential w l n d 18 decision concerning the consumer;
and a t m m 21 R.
and = = 19 a l P.
"trade secret" means information, including a d r e 22 formula, pattern, compilation, program, device, method, c e s k 23 technique or process, that:
"trade secret" means information, including a i a e r 20 formula, pattern, compilation, program, device, method, a t m m 21 technique or process, that:
e a n b 24 (1) derives independent economic value, actual u [ or potential, from not being generally known to and not being .230826.6 - 8 - HJC/HB 60 readily ascertainable by proper means by other persons who could obtain economic value from the information's disclosure or use;
d r e 22 (1) derives independent economic value, actual c e s k 23 or potential, from not being generally known to and not being e a n b 24 readily ascertainable by proper means by other persons who u [ could obtain economic value from the information's disclosure .228797.3 - 8 - or use;
(1) a general summary describing the reasonably foreseeable uses and known harmful or inappropriate uses of the system;
(1) a general summary describing the e t 17 reasonably foreseeable uses and known harmful or inappropriate w l n d 18 uses of the system;
and e t 17 (2) documentation disclosing:
and = = 19 (2) documentation disclosing:
w l n d 18 (a) the purpose, intended uses and = = 19 a l benefits of the system;
a l i a e r 20 (a) the purpose, intended uses and a t m m 21 benefits of the system;
i a e r 20 (b) a high-level summary of the type of a t m m 21 data used to train the system;
d r e 22 (b) a high-level summary of the types of c e s k 23 data used to train the system;
d r e 22 (c) known or reasonable foreseeable c e s k 23 limitations of the system, including the risk of algorithmic e a n b 24 discrimination arising from the intended use of the system;
e a n b 24 (c) known or reasonable foreseeable u [ limitations of the system, including the risk of algorithmic .230826.6 - 9 - HJC/HB 60 discrimination arising from the intended use of the system;
u [ (d) how the system was evaluated for .228797.3 - 9 - performance and mitigation of algorithmic discrimination prior to being offered or made available to the deployer, including:
(d) how the system was evaluated for performance and mitigation of algorithmic discrimination prior to being offered or made available to the deployer, including:
(e) the measures governing the data sets used to train the system, the suitability of data sources, possible biases and bias mitigation;
(e) the data governance measures used to cover the training datasets and the measures used to examine the suitability of data sources, possible biases and bias mitigation;
(g) the measures the developer has taken to mitigate known or reasonably foreseeable risks of algorithmic discrimination that are reasonably foreseeable from the use of the system;
(g) the measures the developer has taken to mitigate known or reasonably foreseeable risks of e t 17 algorithmic discrimination that are reasonably foreseeable from w l n d 18 the use of the system;
(h) how the system should be used and e t 17 monitored by the deployer;
= = 19 (h) how the system should be used and a l i a e r 20 monitored by the deployer;
w l n d 18 (i) any additional information that is = = 19 a l reasonably necessary to assist the deployer in understanding i a e r 20 the outputs and monitoring the performance of the system for a t m m 21 risks of algorithmic discrimination;
a t m m 21 (i) any additional information that is d r e 22 reasonably necessary to assist the deployer in understanding c e s k 23 the outputs and monitoring the performance of the system for e a n b 24 risks of algorithmic discrimination;
and d r e 22 (j) any other information necessary to c e s k 23 allow the deployer to comply with the requirements of this e a n b 24 section;
and u [ (j) any other information necessary to .230826.6 - 10 - HJC/HB 60 allow the deployer to comply with the requirements of the Artificial Intelligence Act;
u [ C.
C.
except for information excluded pursuant to .228797.3 - 10 - Subsection C of Section 4 of the Artificial Intelligence Act, to the extent feasible make available to the recipient the necessary information to conduct an impact assessment as required pursuant to Section 6 of the Artificial Intelligence Act.
except for information excluded pursuant to Subsection C of Section 4 of the Artificial Intelligence Act, to the extent feasible, make available to the deployer the necessary information to conduct an impact assessment as required pursuant to Section 6 of the Artificial Intelligence Act.
Such information shall include model cards, dataset cards or previous impact assessments relevant to the system, its development or use;
The information shall include comprehensive information about the high-risk artificial intelligence system, including:
D.
(1) the name, version and a brief description of the system;
post on the developer's website in a clear and readily available manner a statement or public-use case inventory that summarizes:
(2) the intended use of the system;
(1) the types of high-risk artificial intelligence systems that the developer has developed or intentionally and substantially modified and currently offers or makes available to recipients;
(3) information about the data set used to train the system, including all model input data and training data, demographic composition, data collection methods, data sources, preprocessing steps, potential biases and known e t 17 limitations;
and (2) how the developer manages known or reasonably foreseeable risks of algorithmic discrimination that e t 17 may arise from the use or intentional and substantial w l n d 18 modification of the systems listed on the developer's website = = 19 a l pursuant to this subsection;
w l n d 18 (4) limitations or risks associated with the = = 19 system's use;
and i a e r 20 E.
and a l i a e r 20 (5) previous impact assessments relevant to a t m m 21 the system, its development or use;
ensure that the statement or public-use case a t m m 21 inventory posted pursuant to this section remains accurate and d r e 22 is updated within ninety days of an intentional and substantial c e s k 23 modification of a high-risk artificial intelligence system e a n b 24 offered or made available by the developer to recipients.
d r e 22 D.
u [ SECTION 4.
post on the developer's website in a clear and c e s k 23 readily available manner a statement or public-use case e a n b 24 inventory that summarizes:
[NEW MATERIAL] RISK INCIDENTS--REQUIRED .228797.3 - 11 - DISCLOSURE AND SUBMISSION--EXCEPTIONS.-- A.
u [ (1) the types of high-risk artificial .230826.6 - 11 - HJC/HB 60 intelligence systems that the developer has developed or intentionally and substantially modified and currently offers or makes available to recipients;
Within ninety days of a risk incident and in a form and manner prescribed by the state department of justice, a developer shall disclose to the department and all known recipients of the high-risk artificial intelligence system that is the basis of the risk incident the known and foreseeable risks of algorithmic discrimination that may arise from the intended uses of the system.
and (2) how the developer manages known or reasonably foreseeable risks of algorithmic discrimination that may arise from the use or intentional and substantial modification of the systems listed on the developer's website pursuant to this subsection;
B.
and E.
Within ninety days of a request by the state department of justice, a developer shall submit to the department a copy of the summary and documentation the developer has made available to recipients pursuant to Section 3 of the Artificial Intelligence Act.
ensure that the statement or public-use case inventory posted pursuant to this section remains accurate and is updated within ninety days of an intentional and substantial modification of a high-risk artificial intelligence system offered or made available by the developer to recipients.
A developer may designate the summary or documentation as including proprietary information or a trade secret.
SECTION 4.
To the extent that information contained in the summary or documentation includes information e t 17 subject to attorney-client privilege or work-product w l n d 18 protection, compliance with this section does not constitute a = = 19 a l waiver of the privilege or protection.
[NEW MATERIAL] RISK INCIDENTS--REQUIRED DISCLOSURE AND SUBMISSION--EXCEPTIONS.-- A.
i a e r 20 C.
Within ninety days of a risk incident and in a e t 17 form and manner prescribed by the department, a developer shall w l n d 18 disclose to the department and all known recipients of the = = 19 high-risk artificial intelligence system that is the basis of a l i a e r 20 the risk incident the known and foreseeable risks of a t m m 21 algorithmic discrimination that may arise from the intended d r e 22 uses of the system.
As part of a disclosure, notice or submission a t m m 21 pursuant to the Artificial Intelligence Act, a developer shall d r e 22 not be required to disclose a trade secret, information c e s k 23 protected from disclosure by state or federal law or e a n b 24 information that would create a security risk to the developer.
c e s k 23 B.
u [ Such disclosure, notice or submission shall be exempt from .228797.3 - 12 - disclosure pursuant to the Inspection of Public Records Act.
Within ninety days of a request by the e a n b 24 department, a developer shall submit to the department a copy u [ of the summary and documentation the developer has made .230826.6 - 12 - HJC/HB 60 available to recipients pursuant to Section 3 of the Artificial Intelligence Act.
A developer may designate the summary or documentation as including a trade secret.
To the extent that information contained in the summary or documentation includes information subject to attorney-client privilege or work- product protection, compliance with this section does not constitute a waiver of the privilege or protection.
C.
As part of a disclosure, notice or submission pursuant to the Artificial Intelligence Act, a developer shall not be required to disclose a trade secret, information protected from disclosure by state or federal law or information that would create a security risk to the developer.
Such disclosure, notice or submission shall be exempt from disclosure pursuant to the Inspection of Public Records Act.
[NEW MATERIAL] DEPLOYER RISK-MANAGEMENT POLICY REQUIRED.-- A.
[NEW MATERIAL] DEPLOYER RISK-MANAGEMENT POLICY REQUIRED.-- e t 17 A.
A deployer shall use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination.
A deployer shall use reasonable care to protect w l n d 18 consumers from known or reasonably foreseeable risks of = = 19 algorithmic discrimination.
B.
a l i a e r 20 B.
A deployer shall implement a risk management policy and program to govern the deployer's deployment of a high-risk artificial intelligence system.
A deployer shall implement a risk management a t m m 21 policy and program to govern the deployer's deployment of a d r e 22 high-risk artificial intelligence system.
The risk management policy and program shall:
The risk management c e s k 23 policy and program shall:
(1) specify and incorporate the principles, processes and personnel that the deployer uses to identify, document and mitigate known or reasonably foreseeable risks of algorithmic discrimination;
e a n b 24 (1) specify and incorporate the principles, u [ processes and personnel that the deployer uses to identify, .230826.6 - 13 - HJC/HB 60 document and mitigate known or reasonably foreseeable risks of algorithmic discrimination;
and (2) be an iterative process planned, implemented and regularly and systematically updated over the e t 17 life cycle of a high-risk artificial intelligence system and w l n d 18 include regular systematic review and updates.
and (2) be an iterative process planned, implemented and regularly and systematically updated over the life cycle of a high-risk artificial intelligence system and include regular systematic review and updates.
= = 19 a l C.
C.
A risk management policy shall meet standards i a e r 20 established by the state department of justice by rule.
A risk management policy shall meet standards established by the department by rule.
a t m m 21 SECTION 6.
SECTION 6.
[NEW MATERIAL] DEPLOYER IMPACT ASSESSMENTS.-- d r e 22 A.
[NEW MATERIAL] DEPLOYER IMPACT ASSESSMENTS.-- A.
Except as provided in Subsections D, E and H of c e s k 23 this section, a deployer shall conduct an impact assessment for e a n b 24 any high-risk artificial intelligence system deployed by the u [ deployer:
Except as provided in Subsections D, E and H of this section, a deployer shall conduct an impact assessment for any high-risk artificial intelligence system deployed by the deployer:
.228797.3 - 13 - (1) annually;
(1) annually;
B.
e t 17 B.
An impact assessment of a high-risk artificial intelligence system completed pursuant to this section shall include, to the extent reasonably known by or available to the deployer:
An impact assessment of a high-risk artificial w l n d 18 intelligence system completed pursuant to this section shall = = 19 include, to the extent reasonably known by or available to the a l i a e r 20 deployer:
(1) a statement of the intended uses, deployment contexts and benefits of the system;
a t m m 21 (1) a statement of the intended uses, d r e 22 deployment contexts and benefits of the system;
(2) an analysis of any known or reasonably foreseeable risks of algorithmic discrimination posed by the system, and when a risk exists, the nature of the algorithmic discrimination and the steps that have been taken to mitigate the risk;
c e s k 23 (2) an analysis of any known or reasonably e a n b 24 foreseeable risks of algorithmic discrimination posed by the u [ system and when:
(3) a description of the categories of data the system processes as inputs and the outputs the system e t 17 produces;
.230826.6 - 14 - HJC/HB 60 (a) a risk exists, the nature of the algorithmic discrimination and the steps that have been taken to mitigate the risk;
w l n d 18 (4) a summary of categories of any data used = = 19 a l to customize the system;
(b) the impact assessment is dependent on developer information outside of the deployer's control, include a statement detailing that dependence;
i a e r 20 (5) the metrics used to evaluate the a t m m 21 performance and known limitations of the system, including:
and (c) the deployer has cause to believe algorithmic discrimination exists, the deployer shall use reasonable efforts to mitigate the impacts of such discrimination;
d r e 22 (a) whether the evaluation was carried c e s k 23 out using test data;
(3) a description of the categories of data the system processes as inputs and the outputs the system produces;
e a n b 24 (b) whether the test data sets were u [ collected solely in New Mexico, solely in other states or in .228797.3 - 14 - New Mexico in combination with other states;
(4) a summary of categories of any data used to customize the system;
(c) the demographic groups represented in the test data sets and the proportion of each age, ethnic, gender or racial group in each data set;
(5) the metrics used to evaluate the e t 17 performance and known limitations of the system, including:
and (d) any independent studies carried out to evaluate the system for performance and risk of discrimination and whether the studies are publicly available or peer-reviewed;
w l n d 18 (a) whether the evaluation was carried = = 19 out using test data;
a l i a e r 20 (b) whether the test data sets were a t m m 21 collected solely in New Mexico, solely in other states or in d r e 22 New Mexico in combination with other states;
c e s k 23 (c) the demographic groups represented e a n b 24 in the test data sets and the proportion of each age, ethnic, u [ gender or racial group in each data set;
and .230826.6 - 15 - HJC/HB 60 (d) any independent studies carried out to evaluate the system for performance and risk of discrimination and whether the studies are publicly available or peer-reviewed;
e t 17 C.
C.
An impact assessment conducted due to an w l n d 18 intentional and substantial modification of a high-risk = = 19 a l artificial intelligence system shall include a disclosure of i a e r 20 the extent to which the system was used in a manner consistent a t m m 21 with, or that varied from, the developer's intended uses of the d r e 22 system.
An impact assessment conducted following an intentional and substantial modification of a high-risk artificial intelligence system shall include a disclosure of the extent to which the system was used in a manner consistent e t 17 with, or that varied from, the developer's intended uses of the w l n d 18 system.
c e s k 23 D.
= = 19 D.
A deployer may use a single impact assessment to e a n b 24 address a set of comparable high-risk artificial intelligence u [ systems.
A deployer may use a single impact assessment to a l i a e r 20 address a set of comparable high-risk artificial intelligence a t m m 21 systems.
.228797.3 - 15 - E.
d r e 22 E.
An impact assessment conducted for the purpose of complying with another applicable law or rule shall satisfy the requirement of this section when the assessment:
An impact assessment conducted for the purpose c e s k 23 of complying with another applicable law or rule shall satisfy e a n b 24 the requirement of this section when the assessment:
(1) meets the requirements of this section;
u [ (1) meets the requirements of this section;
and (2) is reasonably similar in scope and effect to an assessment that would otherwise be conducted pursuant to this section.
.230826.6 - 16 - HJC/HB 60 and (2) is reasonably similar in scope and effect to an assessment that would otherwise be conducted pursuant to this section.
On or before March 1, 2027, a deployer shall review each high-risk artificial intelligence system that the e t 17 deployer has deployed to ensure that the system is not causing w l n d 18 algorithmic discrimination.
One hundred twenty days after the department has promulgated rules pursuant to Section 14 of the Artificial Intelligence Act, a deployer shall review each high-risk artificial intelligence system that the deployer has deployed to ensure that the system is not causing algorithmic discrimination.
= = 19 a l H.
e t 17 H.
i a e r 20 (1) a deployer using a high-risk artificial a t m m 21 intelligence system:
w l n d 18 (1) a deployer using a high-risk artificial = = 19 intelligence system:
d r e 22 (a) employs fewer than fifty full-time c e s k 23 employees;
a l i a e r 20 (a) impacts fewer than fifty consumers;
e a n b 24 (b) does not use the deployer's own data u [ to train the system;
a t m m 21 (b) does not use the deployer's own data d r e 22 to train the system;
.228797.3 - 16 - (c) uses the system solely for the system's intended uses as disclosed by a developer pursuant to the Artificial Intelligence Act;
c e s k 23 (c) uses the system solely for the e a n b 24 system's intended uses as disclosed by a developer pursuant to u [ the Artificial Intelligence Act;
and (d) makes any impact assessment of the system that has been provided by the developer pursuant to the Artificial Intelligence Act available to consumers;
and .230826.6 - 17 - HJC/HB 60 (d) makes any impact assessment of the system that has been provided by the developer pursuant to the Artificial Intelligence Act available to consumers;
I.
A deployer may supply documentation provided by a developer to complete the requirements for an item pursuant to Subsection B of this section;
provided that the deployer has not modified the item.
(1) a summary of the types of high-risk artificial intelligence systems that the deployer currently deploys and how known or reasonably foreseeable risks of algorithmic discrimination from the deployment of each system e t 17 are managed;
(1) a summary of the types of high-risk artificial intelligence systems that the deployer currently deploys and how known or reasonably foreseeable risks of e t 17 algorithmic discrimination from the deployment of each system w l n d 18 are managed;
and w l n d 18 (2) a detailed explanation of the nature, = = 19 a l source and extent of the information collected and used by the i a e r 20 deployer.
and = = 19 (2) a detailed explanation of the nature, a l i a e r 20 source and extent of the information collected and used by the a t m m 21 deployer.
a t m m 21 B.
d r e 22 B.
At a minimum, a deployer shall update the d r e 22 information posted on its website pursuant to this section c e s k 23 annually and when the deployer deploys a new high-risk e a n b 24 artificial intelligence system.
At a minimum, a deployer shall update the c e s k 23 information posted on its website pursuant to this section e a n b 24 annually and when the deployer deploys a new high-risk u [ artificial intelligence system.
u [ SECTION 8.
.230826.6 - 18 - HJC/HB 60 SECTION 8.
[NEW MATERIAL] USE OF ARTIFICIAL INTELLIGENCE .228797.3 - 17 - SYSTEMS WHEN MAKING CONSEQUENTIAL DECISIONS--DIRECT NOTICE TO AFFECTED CONSUMERS--ADVERSE DECISIONS--OPPORTUNITY FOR APPEAL.-- A.
[NEW MATERIAL] USE OF ARTIFICIAL INTELLIGENCE SYSTEMS WHEN MAKING CONSEQUENTIAL DECISIONS--DIRECT NOTICE TO AFFECTED CONSUMERS--ADVERSE DECISIONS--OPPORTUNITY FOR APPEAL.-- A.
(b) the purpose of the system and the nature of the consequential decision being made;
(b) the purpose of the system and the e t 17 nature of the consequential decision being made;
and e t 17 (c) the deployer's contact information.
and w l n d 18 (c) the deployer's contact information.
w l n d 18 B.
= = 19 B.
Except as provided in Subsection E of this = = 19 a l section, when a high-risk artificial intelligence system has i a e r 20 been used to make or has been a substantial factor in making a a t m m 21 consequential decision concerning a consumer that is adverse to d r e 22 the consumer, the deployer shall provide directly to the c e s k 23 consumer:
Except as provided in Subsection E of this a l i a e r 20 section, when a high-risk artificial intelligence system has a t m m 21 been used to make or has been a substantial factor in making a d r e 22 consequential decision concerning a consumer that is adverse to c e s k 23 the consumer, the deployer shall provide directly to the e a n b 24 consumer:
e a n b 24 (1) a statement explaining:
u [ (1) a statement explaining:
u [ (a) the principal reason or reasons for .228797.3 - 18 - the decision;
.230826.6 - 19 - HJC/HB 60 (a) the principal reason or reasons for the decision;
and (3) an opportunity to appeal the adverse decision except in instances where an appeal is not in the best interest of the consumer, such as creating a delay that may pose a risk of life or safety to the consumer.
and (3) an opportunity to appeal the adverse decision except in instances where an appeal may pose a risk of life or safety to the consumer.
w l n d 18 (1) in plain language and in all languages in = = 19 a l which the deployer in the ordinary course of business provides i a e r 20 contracts, disclaimers, sale announcements and other a t m m 21 information to consumers;
w l n d 18 (1) in plain language and in all languages in = = 19 which the deployer in the ordinary course of business provides a l i a e r 20 contracts, disclaimers, sale announcements and other a t m m 21 information to consumers;
When a deployer is unable to provide u [ information, notice or a statement required pursuant to this .228797.3 - 19 - section directly to a consumer, the deployer shall make such information, notices or statements available in a manner that is reasonably calculated to ensure that the consumer receives the information, notice or statement.
When a deployer is unable to provide u [ information, notice or a statement required pursuant to this .230826.6 - 20 - HJC/HB 60 section directly to a consumer, the deployer shall make such information, notices or statements available in a manner that is reasonably calculated to ensure that the consumer receives the information, notice or statement.
[NEW MATERIAL] USE OF HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM--NOTICE AND DISCLOSURE TO THE STATE DEPARTMENT OF JUSTICE--INSPECTION OF PUBLIC RECORDS ACT EXEMPTION.-- A.
[NEW MATERIAL] USE OF HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM--NOTICE AND DISCLOSURE TO THE DEPARTMENT--INSPECTION OF PUBLIC RECORDS ACT EXEMPTION.-- A.
When a deployer discovers that a high-risk artificial intelligence system that has been used has caused algorithmic discrimination, the deployer shall as expeditiously as possible but at a maximum within ninety days notify the state department of justice of the discovery.
When a deployer discovers that a high-risk artificial intelligence system that has been used has caused algorithmic discrimination, the deployer shall as expeditiously as possible but at a maximum within ninety days notify the department of the discovery.
Upon request by the state department of justice, a deployer shall within ninety days submit to the state e t 17 department of justice any risk management policy, impact w l n d 18 assessment or records conducted, implemented, maintained or = = 19 a l received pursuant to the Artificial Intelligence Act.
Upon request by the department, a deployer shall within ninety days submit to the department any risk management policy, impact assessment or records conducted, implemented, e t 17 maintained or received pursuant to the Artificial Intelligence w l n d 18 Act.
The i a e r 20 submission shall be in a form and manner prescribed by the a t m m 21 department.
The submission shall be in a form and manner prescribed = = 19 by the department.
d r e 22 C.
a l i a e r 20 C.
The state department of justice may evaluate c e s k 23 risk management policies, impact assessments or records e a n b 24 submitted pursuant to this section for compliance with the u [ Artificial Intelligence Act.
The department may evaluate risk management a t m m 21 policies, impact assessments or records submitted pursuant to d r e 22 this section for compliance with the Artificial Intelligence c e s k 23 Act.
.228797.3 - 20 - D.
e a n b 24 D.
A risk management policy, impact assessment or record submitted to the state department of justice pursuant to this section is exempt from disclosure pursuant to the Inspection of Public Records Act.
As part of a disclosure, notice or submission u [ pursuant to the Artificial Intelligence Act, a deployer shall .230826.6 - 21 - HJC/HB 60 not be required to disclose a trade secret, information protected from disclosure by state or federal law or information that would create a security risk to the deployer.
Such a disclosure, notice or submission shall be exempt from disclosure pursuant to the Inspection of Public Records Act.
In a submission pursuant to this section, a deployer may designate a portion of the submission as including proprietary information or a trade secret and to the extent that a submission contains information subject to attorney- client privilege or work-product protection, the submission does not constitute a waiver of the privilege or protection.
Within ninety days of a request by the department, a developer shall submit to the department a copy of the summary and documentation the developer has made available to recipients pursuant to Section 3 of the Artificial Intelligence Act.
A developer may designate the summary or documentation as including a trade secret.
To the extent that information contained in the summary or documentation includes information subject to attorney-client privilege or work-product protection, compliance with this section does not constitute a waiver of the privilege or protection.
[NEW MATERIAL] INTERACTION OF ARTIFICIAL INTELLIGENCE SYSTEM WITH CONSUMERS--REQUIRED DISCLOSURE.--A developer that offers or makes available an artificial intelligence system intended to interact with consumers shall ensure that a consumer is informed that the consumer is interacting with an artificial intelligence system.
[NEW MATERIAL] INTERACTION OF ARTIFICIAL e t 17 INTELLIGENCE SYSTEM WITH CONSUMERS--REQUIRED DISCLOSURE.-- w l n d 18 A.
This e t 17 section does not apply when it would be obvious to a reasonable w l n d 18 person that the consumer is interacting with an artificial = = 19 a l intelligence system.
A developer or a deployer that offers or makes = = 19 available an artificial intelligence system intended to a l i a e r 20 interact with consumers shall ensure that a consumer is a t m m 21 informed that the consumer is interacting with an artificial d r e 22 intelligence system.
i a e r 20 SECTION 11.
c e s k 23 B.
[NEW MATERIAL] EXEMPTION FROM DISCLOSURE-- a t m m 21 TRADE SECRETS AND OTHER INFORMATION PROTECTED BY LAW--NOTICE TO d r e 22 CONSUMER.-- c e s k 23 A.
Prior to deploying a high-risk artificial e a n b 24 intelligence system to make, or be a substantial factor in u [ making, a consequential decision concerning a consumer, a .230826.6 - 22 - HJC/HB 60 deployer shall notify the consumer that the high-risk artificial intelligence system is being deployed and of the system's role in making the consequential decision.
Nothing in the Artificial Intelligence Act shall e a n b 24 require a deployer or developer to disclose a trade secret or u [ other information protected from disclosure by state or federal .228797.3 - 21 - law.
SECTION 11.
[NEW MATERIAL] EXEMPTION FROM DISCLOSURE-- TRADE SECRETS AND OTHER INFORMATION PROTECTED BY LAW--NOTICE TO CONSUMER.-- A.
Nothing in the Artificial Intelligence Act shall require a deployer or developer to disclose a trade secret or other information protected from disclosure by state or federal law.
To the extent that a deployer or developer withholds information pursuant to this section that would otherwise be part of a disclosure pursuant to the Artificial Intelligence Act, the deployer or developer shall notify a consumer and provide a basis for the withholding.
To the extent that a deployer or developer withholds information pursuant to this section that would otherwise be part of a disclosure pursuant to the Artificial Intelligence Act, the deployer or developer shall notify all affected consumers, provide a basis for the withholding and include all information not protected as a trade secret e t 17 pursuant to the Uniform Trade Secrets Act or other state or w l n d 18 federal law.
SECTION 12.
= = 19 SECTION 12.
[NEW MATERIAL] APPLICABILITY EXEMPTIONS-- OTHER LAW--SECURITY AND TESTING--FEDERAL USE--INSURANCE PROVIDERS.-- A.
[NEW MATERIAL] APPLICABILITY EXEMPTIONS-- a l i a e r 20 OTHER LAW--SECURITY AND TESTING--FEDERAL USE--INSURANCE a t m m 21 PROVIDERS.-- d r e 22 A.
No provision of the Artificial Intelligence Act shall be construed to restrict a person's ability to:
No provision of the Artificial Intelligence Act c e s k 23 shall be construed to restrict a person's ability to:
(1) comply with federal, state or municipal laws or regulations;
e a n b 24 (1) comply with federal, state or municipal u [ laws or regulations;
(2) comply with a civil, criminal or regulatory inquiry, investigation, subpoena or summons by a governmental authority;
.230826.6 - 23 - HJC/HB 60 (2) comply with a civil, criminal or regulatory inquiry, investigation, subpoena or summons by a governmental authority;
e t 17 (3) cooperate with a law enforcement agency w l n d 18 concerning activity that the person reasonably and in good = = 19 a l faith believes may violate other laws or regulations;
(3) cooperate with a law enforcement agency concerning activity that the person reasonably and in good faith believes may violate other laws or regulations;
i a e r 20 (4) defend, exercise or investigate legal a t m m 21 claims;
(4) defend, exercise or investigate legal claims;
d r e 22 (5) act to protect an interest that is c e s k 23 essential for the life or physical safety of a person;
(5) act to protect an interest that is essential for the life or physical safety of a person;
e a n b 24 (6) by means other than the use of facial u [ recognition technology:
(6) by any means:
.228797.3 - 22 - (a) detect, prevent, protect against or respond to deceptive, illegal or malicious activity, fraud, identity theft, harassment or security incidents;
(a) detect, prevent, protect against or respond to deceptive, illegal or malicious activity, fraud, identity theft, harassment or security incidents;
or (b) investigate, prosecute or report persons responsible for the actions listed in Subparagraph (a) of this paragraph;
or (b) investigate, prosecute or report persons responsible for the actions listed in Subparagraph (a) e t 17 of this paragraph;
(7) preserve the integrity or security of artificial intelligence, computer, electronic or internet connection systems;
w l n d 18 (7) preserve the integrity or security of = = 19 artificial intelligence, computer, electronic or internet a l i a e r 20 connection systems;
(8) engage in public or peer-reviewed scientific or statistical research that adheres to and is conducted in accordance with applicable federal and state law;
a t m m 21 (8) engage in public or peer-reviewed d r e 22 scientific or statistical research, including clinical trials, c e s k 23 that adheres to and is conducted in accordance with applicable e a n b 24 federal and state law;
(9) engage in pre-market testing other than testing conducted under real-world conditions, including development, research and testing of artificial intelligence systems;
u [ (9) engage in pre-market testing other than .230826.6 - 24 - HJC/HB 60 testing conducted under real-world conditions, including development, research and testing of artificial intelligence systems;
or e t 17 (10) assist another person with compliance w l n d 18 with the Artificial Intelligence Use Act.
or (10) assist another person with compliance with the Artificial Intelligence Act.
= = 19 a l B.
B.
No provision of the Artificial Intelligence Act i a e r 20 shall be construed to restrict:
No provision of the Artificial Intelligence Act shall be construed to restrict:
a t m m 21 (1) a product recall;
(1) a product recall;
or d r e 22 (2) identification or repair of technical c e s k 23 errors that impair the functionality of an artificial e a n b 24 intelligence system.
or (2) identification or repair of technical errors that impair the functionality of the artificial intelligence system.
u [ C.
C.
The Artificial Intelligence Act shall not apply .228797.3 - 23 - in circumstances where compliance would violate an evidentiary privilege pursuant to law.
The Artificial Intelligence Act does not apply in circumstances in which compliance would violate an evidentiary privilege pursuant to law.
No provision of the Artificial Intelligence Act shall be construed so as to limit a person's rights to free speech or freedom of the press pursuant to the first amendment to the United States constitution or Article 2, Section 17 of the constitution of New Mexico.
No provision of the Artificial Intelligence Act shall be construed so as to limit the rights of a person, e t 17 including the rights to free speech or freedom of the press w l n d 18 pursuant to the first amendment to the United States = = 19 constitution or Article 2, Section 17 of the constitution of a l i a e r 20 New Mexico.
E.
a t m m 21 E.
The Artificial Intelligence Act shall not apply to a developer, deployer or other person who:
The Artificial Intelligence Act does not apply d r e 22 to a developer, deployer or other person who:
(1) uses or intentionally and substantially modifies a high-risk artificial intelligence system that:
c e s k 23 (1) uses or intentionally and substantially e a n b 24 modifies a high-risk artificial intelligence system that:
(a) has been authorized by a federal agency in accordance with federal law;
u [ (a) has been authorized by a federal .230826.6 - 25 - HJC/HB 60 agency in accordance with federal law;
and (b) is in compliance with standards established by a federal agency in accordance with federal law when such standards are substantially equivalent or more e t 17 stringent than the requirements of the Artificial Intelligence w l n d 18 Act;
and (b) is in compliance with standards established by a federal agency in accordance with federal law when such standards are substantially equivalent or more stringent than the requirements of the Artificial Intelligence Act;
= = 19 a l (2) conducts research to support an i a e r 20 application for certification or review by a federal agency a t m m 21 pursuant to federal law;
(2) conducts research to support an application for approval, certification or review by a federal agency pursuant to federal law;
d r e 22 (3) performs work under or in connection with c e s k 23 a contract with a federal agency, unless the work is on a high- e a n b 24 risk artificial intelligence system used to make or as a u [ substantial factor in making a decision concerning employment .228797.3 - 24 - or housing;
or (3) performs work under or in connection with a contract with a federal agency, unless the work is on a high- risk artificial intelligence system used to make or as a substantial factor in making a decision concerning employment or housing.
or (4) is a covered entity pursuant to federal health insurance law and is providing health care recommendations:
(a) generated by an artificial intelligence system;
(b) that require a health care provider to take action to implement the recommendations;
and (c) that are not considered to be high risk.
The Artificial Intelligence Act shall not apply to an artificial intelligence system acquired by the federal government, except for a high-risk artificial intelligence system used to make or as a substantial factor in making a decision concerning employment or housing.
The Artificial Intelligence Act does not apply to an artificial intelligence system to the extent the system e t 17 is used by the federal government, except for a high-risk w l n d 18 artificial intelligence system used to make or as a substantial = = 19 factor in making a decision concerning employment or housing.
G.
a l i a e r 20 G.
A financial institution or affiliate or e t 17 subsidiary of a financial institution that is subject to w l n d 18 prudential regulation by another state or by the federal = = 19 a l government pursuant to laws that apply to the use of high-risk i a e r 20 artificial intelligence systems shall be deemed to be in a t m m 21 compliance with the Artificial Intelligence Act when the d r e 22 applicable laws:
A financial institution, an affiliate or a a t m m 21 subsidiary of a financial institution or a service provider d r e 22 that is subject to prudential regulation by another state or by c e s k 23 the federal government pursuant to laws that apply to the use e a n b 24 of high-risk artificial intelligence systems shall be deemed to u [ be in compliance with the Artificial Intelligence Act when the .230826.6 - 26 - HJC/HB 60 applicable laws:
c e s k 23 (1) impose requirements that are substantially e a n b 24 equivalent to or more stringent than the requirements imposed u [ by the Artificial Intelligence Act;
(1) impose requirements that are substantially equivalent to or more stringent than the requirements imposed by the Artificial Intelligence Act;
and .228797.3 - 25 - (2) at a minimum, require the financial institution to:
and (2) at a minimum, require the financial institution, affiliate or service provider to:
(a) regularly audit the institution's use of high-risk artificial intelligence systems for compliance with state and federal antidiscrimination laws;
(a) notify consumers subject to the high-risk artificial intelligence system of the system's use and its role in consequential decisions;
and (b) mitigate any algorithmic discrimination caused by the use of a high-risk artificial intelligence system.
(b) regularly audit the institution's use of high-risk artificial intelligence systems for compliance with state and federal antidiscrimination laws;
and (c) mitigate any algorithmic discrimination caused by the use of a high-risk artificial intelligence system.
As used in this section, "financial institution" means an insured state or national bank, a state or federal savings and loan association or savings bank, a state or federal credit union or authorized branches of each of the foregoing.
A developer, deployer or other person who e t 17 engages in an action pursuant to an exemption set forth in this w l n d 18 section shall bear the burden of demonstrating that the action = = 19 qualifies for the exemption.
I.
a l i a e r 20 I.
A developer, deployer or other person who engages in an action pursuant to an exemption set forth in this section shall bear the burden of demonstrating that the action e t 17 qualifies for the exemption.
As used in this section, "financial institution" a t m m 21 means an insured state or national bank, a state or federal d r e 22 savings and loan association or savings bank, a state or c e s k 23 federal credit union or authorized branches of each of the e a n b 24 foregoing.
w l n d 18 SECTION 13.
u [ SECTION 13.
[NEW MATERIAL] ENFORCEMENT--STATE DEPARTMENT = = 19 a l OF JUSTICE--CONSUMER CIVIL ACTIONS.-- i a e r 20 A.
[NEW MATERIAL] ENFORCEMENT--DEPARTMENT-- .230826.6 - 27 - HJC/HB 60 OPPORTUNITY TO CURE--CONSUMER CIVIL ACTIONS.-- A.
Upon the promulgation of rules pursuant to a t m m 21 Section 14 of the Artificial Intelligence Act:
Upon the promulgation of rules pursuant to Section 14 of the Artificial Intelligence Act:
d r e 22 (1) the state department of justice shall have c e s k 23 authority to enforce that act;
(1) the department shall have authority to enforce that act;
and e a n b 24 (2) a consumer may bring a civil action in u [ district court against a developer or deployer for declaratory .228797.3 - 26 - or injunctive relief and attorney fees for a violation of that act.
and (2) a consumer may bring a civil action in district court against a developer or deployer for declaratory or injunctive relief and attorney fees for a violation of that act.
In an action by the state department of justice to enforce the Artificial Intelligence Act, it is an affirmative defense when:
Prior to the promulgation of rules by the department pursuant to Section 14 of the Artificial Intelligence Act, the department shall issue a notice to a prospective defendant prior to initiating an action for violation of the act.
(1) the developer, deployer or other person discovers and cures a violation of the Artificial Intelligence Act as a result of:
The notice shall include a detailed description of the alleged violation and the actions required to cure the violation.
(a) feedback that the developer, deployer or other person encourages the deployer or users to provide;
The prospective defendant shall have e t 17 ninety days from the receipt of the notice to submit evidence w l n d 18 satisfactory to the department that the violation has been = = 19 cured.
or (b) adversarial testing, red teaming or an internal review process;
Ninety-one days after the prospective defendant has a l i a e r 20 received the notice, if the department has not received a t m m 21 satisfactory evidence that the violation has been cured, the d r e 22 department may file an action in district court for the c e s k 23 violation.
and (2) the developer, deployer or other person is in compliance with a risk management framework for artificial intelligence systems designated by the state department of e t 17 justice by rule.
e a n b 24 C.
w l n d 18 C.
For one calendar year from the date the u [ department promulgates rules pursuant to Section 14 of the .230826.6 - 28 - HJC/HB 60 Artificial Intelligence Act, it shall be an affirmative defense in an action brought by the department to enforce the Artificial Intelligence Act when:
In an action by the state department of justice = = 19 a l to enforce the Artificial Intelligence Act, the developer, i a e r 20 deployer or other person who is the subject of the enforcement a t m m 21 shall bear the burden of demonstrating that the requirements d r e 22 for an affirmative defense pursuant to this section have been c e s k 23 met.
(1) the developer, deployer or other person discovers a violation of the Artificial Intelligence Act as a result of adversarial testing, red teaming or an internal review process;
e a n b 24 D.
(2) the developer, deployer or other person reports the violation to the department and cures the violation within seven days of the violation;
Nothing within the Artificial Intelligence Act, u [ including the enforcement authority granted to the state .228797.3 - 27 - department of justice pursuant to this section, preempts or otherwise affects any right, claim, remedy, presumption or defense available in law or equity.
(3) the developer, deployer or other person is in compliance with a risk management framework for artificial intelligence systems designated by the department by rule;
(4) the deployer is dependent on documentation from the developer to cure or otherwise resolve a violation and the deployer complies with the requirements in Paragraph (2) of e t 17 Subsection B of Section 6 of the Artificial Intelligence Act;
w l n d 18 and = = 19 (5) the developer, deployer or other person a l i a e r 20 demonstrates that the violation was inadvertent, affected fewer a t m m 21 than one hundred consumers and could not have been discovered d r e 22 through reasonable diligence.
c e s k 23 D.
After one calendar year from the date the e a n b 24 department promulgates rules pursuant to Section 14 of the u [ Artificial Intelligence Act, a deployer, developer or other .230826.6 - 29 - HJC/HB 60 person subject to enforcement for a violation of that act shall have no right to cure the violation or an affirmative defense pursuant to this section.
An affirmative defense or rebuttable presumption established by the Artificial Intelligence Act applies only to an enforcement action by the state department of justice and does not apply to any right, claim, remedy, presumption or defense available in law or equity.
In an action by the department to enforce the Artificial Intelligence Act, the developer, deployer or other person who is the subject of the enforcement shall bear the burden of demonstrating that the requirements for an affirmative defense pursuant to this section have been met.
A violation of the Artificial Intelligence Act is an unfair practice and may be enforced pursuant to the Unfair Practices Act.
Nothing in the Artificial Intelligence Act, including the enforcement authority granted to the department pursuant to this section, preempts or otherwise affects any right, claim, remedy, presumption or defense available in law or equity.
An affirmative defense presumption established by the Artificial Intelligence Act applies only to an enforcement action by the department and does not apply to any e t 17 right, claim, remedy, presumption or defense available in law w l n d 18 or equity.
= = 19 H.
A violation of the Artificial Intelligence Act a l i a e r 20 is an unfair practice and may be enforced pursuant to the a t m m 21 Unfair Practices Act.
d r e 22 I.
(1) "adversarial testing" means to proactively try to break an application by providing it with data most likely to elicit problematic output, or as defined by the state department of justice by rule;
c e s k 23 (1) "adversarial testing" means to proactively e a n b 24 try to break an application by providing it with data most u [ likely to elicit problematic output, or as defined by the .230826.6 - 30 - HJC/HB 60 department by rule;
and e t 17 (2) "red teaming" means the practice of w l n d 18 simulating attack scenarios on an artificial intelligence = = 19 a l application to pinpoint weaknesses and plan preventive measures i a e r 20 or as defined by the state department of justice by rule.
and (2) "red teaming" means the practice of simulating attack scenarios on an artificial intelligence application to pinpoint weaknesses and plan preventive measures or as defined by the department by rule.
a t m m 21 SECTION 14.
SECTION 14.
[NEW MATERIAL] RULEMAKING.--On or before d r e 22 January 1, 2027, the state department of justice shall c e s k 23 promulgate rules to implement the Artificial Intelligence Act e a n b 24 and shall post them prominently on the state department of u [ justice's website.
[NEW MATERIAL] RULEMAKING.-- A.
.228797.3 - 28 - SECTION 15.
On or before January 1, 2027, the department shall promulgate rules to implement the Artificial Intelligence Act and shall post them prominently on the department's website.
EFFECTIVE DATE.--The effective date of the provisions of this act is July 1, 2026.
B.
- 29 - 5 7 9 11 13 15 e t 17 w l n d 18 = = 19 a l i a e r 20 a t m m 21 d r e 22 c e s k 23 e a n b 24 u [ .228797.3
The department shall consult artificial intelligence experts, academic researchers, civil rights organizations, deployers, developers, labor unions and organizations representing the interests of consumers when developing the rules to be promulgated pursuant to the Artificial Intelligence Act.
e t 17 SECTION 15.
EFFECTIVE DATE.--The effective date of the w l n d 18 provisions of this act is July 1, 2026.
= = 19 - 31 - a l i a e r 20 a t m m 21 d r e 22 c e s k 23 e a n b 24 u [ .230826.6
View plain text versions (2)

Action History

  1. action postponed indefinitely

  2. DO NOT PASS, replaced with committee substitute

  3. DO PASS committee report adopted

  4. Sent to House Consumer & Public Affairs Committee & House Judiciary Committee

  5. Sent to House Pre-file

Sponsors

Sponsorship breakdown

Export CSV (upgrade) →

5 sponsors · 0 co-sponsors · 107 not signed on

Sponsors (5)

Co-sponsors (0)

None.

Not signed on (107)

107 members have not signed on to this bill.

Show all 107 →

"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.

Whip count is in markup. Polling the chamber and every recorded vote this session. Only the first open is slow. It’s instant for you after this. Calling the roll · Tallying · Engrossing

Subjects

Cross-referencing the record. Reading this bill against every other bill in the corpus by meaning, not keywords. Only the first open is slow. It’s instant for you after this. Matching · Ranking · Engrossing

Frequently asked questions

Who sponsors HB 60?
HB 60 is sponsored by Heather Berghmans (Democrat), Linda M. Trujillo (Democrat), Debra M. Sariñana (Democrat), Christine Chandler (Democrat), and Andrea Romero (Democrat).
What is the current status of HB 60?
This bill died with 2025 Regular Session. It reached “In Committee” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.
Where can I track HB 60?
Track HB 60 free on One Click Politics — get push/email alerts when it moves.

Make your voice heard on HB 60

Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.

Stay ahead of HB 60

Last checked for changes 2 months ago · updated continuously

One Click Politics tracks every bill in Congress and all 50 states.

Track this bill →