Provider

actoraccountability
51sources
36 highly relevant
7 moderately relevant
8 somewhat relevant
2022 – 20255 jurisdictions

Etymology

Highly Relevant

Texas Responsible AI Governance Act

United States · Dec 23, 2024 · Bill

Highly RelevantDefinition 1 of 3

" ... Sec. 551.003. DEVELOPER DUTIES.

(a) A developer of a high-risk artificial intelligence system shall use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of the high-risk artificial intelligence system.

(b) Prior to providing a high-risk artificial intelligence system to a deployer, a developer shall provide to the deployer, in writing, a High-Risk Report that consists of:
(1) a statement describing how the high-risk artificial intelligence system should be used or not be used;
(2) any known limitations of the system that could lead to algorithmic discrimination, the metrics used to measure the system's performance, which shall include at a minimum, metrics related to accuracy, explainability, transparency, reliability, and security set forth in the most recent version of the "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile" published by the National Institute of Standards and Technology, and how the system performs under those metrics in its intended use contexts;
(3) any known or reasonably foreseeable risks of algorithmic discrimination, arising from its intended or likely use;
(4) a high-level summary of the type of data used to program or train the high-risk artificial intelligence system;
(5) the data governance measures used to cover the training datasets and their collection, and the measures used to examine the suitability of data sources and prevent unlawful discriminatory biases; and
(6) appropriate principles, processes, and personnel for the deployers' risk management policy.

(c) If a high-risk artificial intelligence system is intentionally or substantially modified after a developer provides it to a deployer, a developer shall make necessary information in subsection (b) available to deployers within 30 days of the modification.







(d) If a developer believes or has reason to believe, that it deployed a high-risk artificial intelligence system that does not comply with a requirement of this chapter, the developer shall immediately take the necessary corrective actions to bring that system into compliance, including by withdrawing it, disabling it, and recalling it, as appropriate. Where applicable, the developer shall inform the distributors or deployers of the high-risk artificial intelligence system concerned.

(e) Where the high-risk artificial intelligence system presents risks of algorithmic discrimination, unlawful use or disclosure of personal data, or deceptive manipulation or coercion of human behavior and the developer knows or should reasonably know of that risk, it shall immediately investigate the causes, in collaboration with the deployer, where applicable, and inform the attorney general in writing of the nature of the non-compliance and of any relevant corrective action taken.

(f) Developers shall keep detailed records of any generative artificial intelligence training data used to develop a generative artificial intelligence system or service, consistent with the suggested actions under GV-1.2-007 of the "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile" by the National Institute of Standards and Technology, or any subsequent versions thereof."

Texas
Highly RelevantDefinition 2 of 3

" ... "Developer" means a person doing business in this state that develops a high-risk artificial intelligence system or substantially or intentionally modifies an artificial intelligence system."

Texas
Highly RelevantDefinition 3 of 3

" ... Any distributor or deployer, shall be considered to be a developer of a high-risk artificial intelligence system for the purposes of this chapter and shall be subject to the obligations and duties of a developer under this chapter in any of the following circumstances: (1) they put their name or trademark on a high-risk artificial intelligence system already placed in the market or put into service; (2) they intentionally and substantially modify a high-risk artificial intelligence system that has already been placed in the market or has already been put into service in such a way that it remains a high-risk artificial intelligence system under this chapter; or (3) they modify the intended purpose of an artificial intelligence system which has not previously been classified as high-risk and has already been placed in the market or put into service in such a way that the artificial intelligence system concerned becomes a high-risk artificial intelligence system in accordance with this chapter of a high-risk artificial intelligence system."

Texas
Highly Relevant

Colorado AI Act (SB 205)

United States · May 17, 2024 · Bill

Highly RelevantDefinition 1 of 5

" ... 6-1-1702. Developer duty to avoid algorithmic discrimination - required documentation.

(1) ON AND AFTER FEBRUARY 1, 2026, A DEVELOPER OF A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM SHALL USE REASONABLE CARE TO PROTECT CONSUMERS FROM ANY KNOWN OR REASONABLY FORESEEABLE RISKS OF ALGORITHMIC DISCRIMINATION ARISING FROM THE INTENDED AND CONTRACTED USES OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM. IN ANY ENFORCEMENT ACTION BROUGHT ON OR AFTER FEBRUARY 1, 2026, BY THE ATTORNEY GENERAL PURSUANT TO SECTION 6-1-1706, THERE IS A REBUTTABLE PRESUMPTION THAT A DEVELOPER USED REASONABLE CARE AS REQUIRED UNDER THIS SECTION IF THE DEVELOPER COMPLIED WITH THIS SECTION AND ANY ADDITIONAL REQUIREMENTS OR OBLIGATIONS AS SET FORTH IN RULES PROMULGATED BY THE ATTORNEY GENERAL PURSUANT TO SECTION 6-1-1707."

Colorado
Highly RelevantDefinition 2 of 5

" ... (2) ON AND AFTER FEBRUARY 1, 2026, AND EXCEPT AS PROVIDED IN SUBSECTION (6) OF THIS SECTION, A DEVELOPER OF A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM SHALL MAKE AVAILABLE TO THE DEPLOYER OR OTHER DEVELOPER OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM:

(a) A GENERAL STATEMENT DESCRIBING THE REASONABLY FORESEEABLE USES AND KNOWN HARMFUL OR INAPPROPRIATE USES OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM;

(b) DOCUMENTATION DISCLOSING:

(I) HIGH-LEVEL SUMMARIES OF THE TYPE OF DATA USED TO TRAIN THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM;

(II) KNOWN OR REASONABLY FORESEEABLE LIMITATIONS OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM, INCLUDING KNOWN OR REASONABLY FORESEEABLE RISKS OF ALGORITHMIC DISCRIMINATION ARISING FROM THE INTENDED USES OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM;

(III) THE PURPOSE OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM;

(IV) THE INTENDED BENEFITS AND USES OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM; AND

(V) ALL OTHER INFORMATION NECESSARY TO ALLOW THE DEPLOYER TO COMPLY WITH THE REQUIREMENTS OF SECTION 6-1-1703;

(c) DOCUMENTATION DESCRIBING:

(I) HOW THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM WAS EVALUATED FOR PERFORMANCE AND MITIGATION OF ALGORITHMIC DISCRIMINATION BEFORE THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM WAS OFFERED, SOLD, LEASED, LICENSED, GIVEN, OR OTHERWISE MADE AVAILABLE TO THE DEPLOYER;

(II) THE DATA GOVERNANCE MEASURES USED TO COVER THE TRAINING DATASETS AND THE MEASURES USED TO EXAMINE THE SUITABILITY OF DATA SOURCES, POSSIBLE BIASES, AND APPROPRIATE MITIGATION;

(III) THE INTENDED OUTPUTS OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM;

(IV) THE MEASURES THE DEVELOPER HAS TAKEN TO MITIGATE KNOWN OR REASONABLY FORESEEABLE RISKS OF ALGORITHMIC DISCRIMINATION THAT MAY ARISE FROM THE REASONABLY FORESEEABLE DEPLOYMENT OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM; AND

(V) HOW THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM SHOULD BE USED, NOT BE USED, AND BE MONITORED BY AN INDIVIDUAL WHEN THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IS USED TO MAKE, OR IS A SUBSTANTIAL FACTOR IN MAKING, A CONSEQUENTIAL DECISION; AND

(d) ANY ADDITIONAL DOCUMENTATION THAT IS REASONABLY NECESSARY TO ASSIST THE DEPLOYER IN UNDERSTANDING THE OUTPUTS AND MONITOR THE PERFORMANCE OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM FOR RISKS OF ALGORITHMIC DISCRIMINATION.

(3)(a) EXCEPT AS PROVIDED IN SUBSECTION (6) OF THIS SECTION, A DEVELOPER THAT OFFERS, SELLS, LEASES, LICENSES, GIVES, OR OTHERWISE MAKES AVAILABLE TO A DEPLOYER OR OTHER DEVELOPER A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM ON OR AFTER FEBRUARY 1, 2026, SHALL MAKE AVAILABLE TO THE DEPLOYER OR OTHER DEVELOPER, TO THE EXTENT FEASIBLE, THE DOCUMENTATION AND INFORMATION, THROUGH ARTIFACTS SUCH AS MODEL CARDS, DATASET CARDS, OR OTHER IMPACT ASSESSMENTS, NECESSARY FOR A DEPLOYER, OR FOR A THIRD PARTY CONTRACTED BY A DEPLOYER, TO COMPLETE AN IMPACT ASSESSMENT PURSUANT TO SECTION 6-1-1703(3).

(b) A DEVELOPER THAT ALSO SERVES AS A DEPLOYER FOR A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IS NOT REQUIRED TO GENERATE THE DOCUMENTATION REQUIRED BY THIS SECTION UNLESS THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IS PROVIDED TO AN UNAFFILIATED ENTITY ACTING AS A DEPLOYER."

Colorado
Highly RelevantDefinition 3 of 5

" ... (4)(a) ON AND AFTER FEBRUARY 1, 2026, A DEVELOPER SHALL MAKE AVAILABLE, IN A MANNER THAT IS CLEAR AND READILY AVAILABLE ON THE DEVELOPER'S WEBSITE OR IN A PUBLIC USE CASE INVENTORY, A STATEMENT SUMMARIZING:

(I) THE TYPES OF HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEMS THAT THE DEVELOPER HAS DEVELOPED OR INTENTIONALLY AND SUBSTANTIALLY MODIFIED AND CURRENTLY MAKES AVAILABLE TO A DEPLOYER OR OTHER DEVELOPER; AND

(II) HOW THE DEVELOPER MANAGES KNOWN OR REASONABLY FORESEEABLE RISKS OF ALGORITHMIC DISCRIMINATION THAT MAY ARISE FROM THE DEVELOPMENT OR INTENTIONAL AND SUBSTANTIAL MODIFICATION OF THE TYPES OF HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEMS DESCRIBED IN ACCORDANCE WITH SUBSECTION (4)(a)(I) OF THIS SECTION.

(b) A DEVELOPER SHALL UPDATE THE STATEMENT DESCRIBED IN SUBSECTION (4)(a) OF THIS SECTION:

(I) AS NECESSARY TO ENSURE THAT THE STATEMENT REMAINS ACCURATE; AND

(II) NO LATER THAN NINETY DAYS AFTER THE DEVELOPER INTENTIONALLY AND SUBSTANTIALLY MODIFIES ANY HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM DESCRIBED IN SUBSECTION (4)(a)(I) OF THIS SECTION.

(5) ON AND AFTER FEBRUARY 1, 2026, A DEVELOPER OF A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM SHALL DISCLOSE TO THE ATTORNEY GENERAL, IN A FORM AND MANNER PRESCRIBED BY THE ATTORNEY GENERAL, AND TO ALL KNOWN DEPLOYERS OR OTHER DEVELOPERS OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM, ANY KNOWN OR REASONABLY FORESEEABLE RISKS OF ALGORITHMIC DISCRIMINATION ARISING FROM THE INTENDED USES OF THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM WITHOUT UNREASONABLE DELAY BUT NO LATER THAN NINETY DAYS AFTER THE DATE ON WHICH:

(a) THE DEVELOPER DISCOVERS THROUGH THE DEVELOPER'S ONGOING TESTING AND ANALYSIS THAT THE DEVELOPER'S HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM HAS BEEN DEPLOYED AND HAS CAUSED OR IS REASONABLY LIKELY TO HAVE CAUSED ALGORITHMIC DISCRIMINATION; OR

(b) THE DEVELOPER RECEIVES FROM A DEPLOYER A CREDIBLE REPORT THAT THE HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM HAS BEEN DEPLOYED AND HAS CAUSED ALGORITHMIC DISCRIMINATION."

Colorado
Highly RelevantDefinition 4 of 5

" ... "DEVELOPER" MEANS A PERSON DOING BUSINESS IN THIS STATE THAT DEVELOPS OR INTENTIONALLY AND SUBSTANTIALLY MODIFIES AN ARTIFICIAL INTELLIGENCE SYSTEM."

Colorado
Highly RelevantDefinition 5 of 5

" ... "INTENTIONAL AND SUBSTANTIAL MODIFICATION" OR "INTENTIONALLY AND SUBSTANTIALLY MODIFIES" MEANS A DELIBERATE CHANGE MADE TO AN ARTIFICIAL INTELLIGENCE SYSTEM THAT RESULTS IN ANY NEW REASONABLY FORESEEABLE RISK OF ALGORITHMIC DISCRIMINATION."

Colorado
Highly Relevant

EU AI Act

International · Mar 13, 2024 · Bill

Highly RelevantDefinition 1 of 5

" ... Article 25: Responsibilities along the AI value chain.

Any distributor, importer, deployer or other third-party shall be considered to be a provider of a high-risk AI system for the purposes of this Regulation and shall be subject to the obligations of the provider under Article 16, in any of the following circumstances:

(a) they put their name or trademark on a high-risk AI system already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated;

(b) they make a substantial modification to a high-risk AI system that has already been placed on the market or has already been put into service in such a way that it remains a high-risk AI system pursuant to Article 6;

(c) they modify the intended purpose of an AI system, including a general-purpose AI system, which has not been classified as high-risk and has already been placed on the market or put into service in such a way that the AI system concerned becomes a high-risk AI system in accordance with Article 6.

Where the circumstances referred to in paragraph 1 occur, the provider that initially placed the AI system on the market or put it into service shall no longer be considered to be a provider of that specific AI system for the purposes of this Regulation. That initial provider shall closely cooperate with new providers and shall make available the necessary information and provide the reasonably expected technical access and other assistance that are required for the fulfilment of the obligations set out in this Regulation, in particular regarding the compliance with the conformity assessment of high-risk AI systems. This paragraph shall not apply in cases where the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system and therefore does not fall under the obligation to hand over the documentation.

In the case of high-risk AI systems that are safety components of products covered by the Union harmonisation legislation listed in Section A of Annex I, the product manufacturer shall be considered to be the provider of the high-risk AI system, and shall be subject to the obligations under Article 16 under either of the following circumstances:

(a) the high-risk AI system is placed on the market together with the product under the name or trademark of the product manufacturer;

(b) the high-risk AI system is put into service under the name or trademark of the product manufacturer after the product has been placed on the market.

The provider of a high-risk AI system and the third party that supplies an AI system, tools, services, components, or processes that are used or integrated in a high-risk AI system shall, by written agreement, specify the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable the provider of the high-risk AI system to fully comply with the obligations set out in this Regulation. This paragraph shall not apply to third parties making accessible to the public tools, services, processes, or components, other than general-purpose AI models, under a free and open-source licence.

The AI Office may develop and recommend voluntary model terms for contracts between providers of high-risk AI systems and third parties that supply tools, services, components or processes that are used for or integrated into high-risk AI systems. When developing those voluntary model terms, the AI Office shall take into account possible contractual requirements applicable in specific sectors or business cases. The voluntary model terms shall be published and be available free of charge in an easily usable electronic format.

Paragraphs 2 and 3 are without prejudice to the need to observe and protect intellectual property rights, confidential business information and trade secrets in accordance with Union and national law."

European Union
Highly RelevantDefinition 2 of 5

" ... Article 16: Obligations of Providers of High-Risk AI Systems. Providers of high-risk AI systems shall:

(a) ensure that their high-risk AI systems are compliant with the requirements set out in Section 2;

(b) indicate on the high-risk AI system or, where that is not possible, on its packaging or its accompanying documentation, as applicable, their name, registered trade name or registered trade mark, the address at which they can be contacted;

(c) have a quality management system in place which complies with Article 17;

(d) keep the documentation referred to in Article 18;

(e) when under their control, keep the logs automatically generated by their high-risk AI systems as referred to in Article 19;

(f) ensure that the high-risk AI system undergoes the relevant conformity assessment procedure as referred to in Article 43, prior to its being placed on the market or put into service;


(g) draw up an EU declaration of conformity in accordance with Article 47;

(h) affix the CE marking to the high-risk AI system or, where that is not possible, on its packaging or its accompanying documentation, to indicate conformity with this Regulation, in accordance with Article 48;

(i) comply with the registration obligations referred to in Article 49(1);

(j) take the necessary corrective actions and provide information as required in Article 20;

(k) upon a reasoned request of a national competent authority, demonstrate the conformity of the high-risk AI system with the requirements set out in Section 2;

(l) ensure that the high-risk AI system complies with accessibility requirements in accordance with Directives (EU) 2016/2102 and (EU) 2019/882."

European Union
Highly RelevantDefinition 3 of 5

" ... ‘provider’ means a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge; ... "

European Union
Highly RelevantDefinition 4 of 5

" ... ‘operator’ means a provider, product manufacturer, deployer, authorised representative, importer or distributor; ... "

European Union
Somewhat RelevantDefinition 5 of 5

" ... ‘post-market monitoring system’ means all activities carried out by providers of AI systems to collect and review experience gained from the use of AI systems they place on the market or put into service for the purpose of identifying any need to immediately apply any necessary corrective or preventive actions; ... "

European Union
Highly Relevant

California AB 1018 (Automated Decision Systems)

California · Sep 5, 2025 · Bill

" ... “Developer” means a person, partnership, state or local government agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces an automated decision system that makes or facilitates a consequential decision."

California Legislature
Highly Relevant

California AB 412 (Generative artificial intelligence: training data: copyrighted materials)

United States · Jul 9, 2025 · Document

" ... “Developer” means a business, person, partnership, corporation, or other entity that designs, codes, produces, or substantially modifies a GenAI model and that does either of the following: (1) Uses the GenAI model commercially in California. (2) Makes the GenAI model available to Californians for use."

California
Highly Relevant

Leading Ethical AI Development (LEAD) for Kids Act April 2025

United States · Apr 23, 2025 · Bill

" ... (j) “Developer” means a person, partnership, state or local governmental agency, corporation, or deployer that designs, codes, substantially modifies, or otherwise produces a covered product."

California
Highly Relevant

Virginia HB2094 (High-Risk Artificial Intelligence Developer And Deployer Act)

United States · Mar 24, 2025 · Bill

" ... "Developer" means any person doing business in the Commonwealth that develops or intentionally and substantially modifies a high-risk artificial intelligence system that is offered, sold, leased, given, or otherwise made available to deployers or consumers in the Commonwealth."

Virginia
Highly Relevant

New York A6453 (RAISE Act)

United States · Mar 5, 2025 · Bill

" ... "Large developer" means a person that has trained at least one frontier model and has spent over one hundred million dollars in compute costs in aggregate in training frontier models. Accredited colleges and universities shall not be considered large developers under this article to the extent that such colleges and universities are engaging in academic research. If a person subsequently transfers full intellectual property rights of the frontier model to another person (including the right to resell the model) and retains none of those rights for themself, then the receiving person shall be considered the large developer and shall be subject to the responsibilities and requirements of this article after such transfer."

New York
Highly Relevant

Illinois HB 3506 (AI Safety and Security Protocol Act)

United States · Feb 18, 2025 · Bill

" ... "Developer" means a person that has trained at least one foundation model with a quantity of computational power that costs at least $100,000,000 when measured using prevailing market prices of cloud computing."

Illinois
Highly Relevant

New Mexico AI Act

United States · Jan 22, 2025 · Bill

Highly RelevantDefinition 1 of 3

" ... "intentional and substantial modification" and "intentionally and substantially modifies" means a deliberate change made to an artificial intelligence system that results in a new reasonably foreseeable risk of algorithmic discrimination, but does not include a change made to a high-risk artificial intelligence system or the performance of a high-risk artificial intelligence system when: (1) the high-risk artificial intelligence system continues to learn after the system is: (a) offered, sold, leased, licensed, given or otherwise made available to a deployer; or (b) deployed; (2) the change is made as a result of system learning after being made available to a deployer or being deployed; (3) the change was predetermined by the deployer or a third party contracted by the deployer when the deployer or third party completed an impact assessment of the high-risk artificial intelligence system pursuant to Section 6 of the Artificial Intelligence Act; or (4) the change is included in technical documentation for the high-risk artificial intelligence system; ... "

New Mexico
Highly RelevantDefinition 2 of 3

" ... "developer" means a person who develops or intentionally and substantially modifies an artificial intelligence system; ... "

New Mexico
Highly RelevantDefinition 3 of 3

" ... SECTION 3. [NEW MATERIAL] DUTY OF CARE--DISCLOSURE OF RISK POTENTIAL--PROVISION OF DOCUMENTATION.--A developer shall:

A. use reasonable care to protect consumers from known or foreseeable risks of algorithmic discrimination arising from intended and contracted uses of a high-risk artificial intelligence system;

B. except for information excluded pursuant to Subsection C of Section 4 of the Artificial Intelligence Act, make the following available to a recipient of the developer's high-risk artificial intelligence system:

(1) a general summary describing the reasonably foreseeable uses and known harmful or inappropriate uses of the system; and

(2) documentation disclosing: (a) the purpose, intended uses and benefits of the system; (b) a high-level summary of the type of data used to train the system; (c) known or reasonable foreseeable limitations of the system, including the risk of algorithmic discrimination arising from the intended use of the system; (d) how the system was evaluated for performance and mitigation of algorithmic discrimination prior to being offered or made available to the deployer, including: 1) the metrics of performance and bias that were used; 2) how the metrics were measured; 3) any independent studies carried out to evaluate the system for performance and risk of discrimination; and 4) whether the studies are publicly available or peer-reviewed; (e) the measures governing the data sets used to train the system, the suitability of data sources, possible biases and bias mitigation; (f) the intended outputs of the system; (g) the measures the developer has taken to mitigate known or reasonably foreseeable risks of algorithmic discrimination that are reasonably foreseeable from the use of the system; (h) how the system should be used and monitored by the deployer; (i) any additional information that is reasonably necessary to assist the deployer in understanding the outputs and monitoring the performance of the system for risks of algorithmic discrimination; and (j) any other information necessary to allow the deployer to comply with the requirements of this section;

C. except for information excluded pursuant to Subsection C of Section 4 of the Artificial Intelligence Act, to the extent feasible make available to the recipient the necessary information to conduct an impact assessment as required pursuant to Section 6 of the Artificial Intelligence Act. Such information shall include model cards, dataset cards or previous impact assessments relevant to the system, its development or use;

D. post on the developer's website in a clear and readily available manner a statement or public-use case inventory that summarizes: (1) the types of high-risk artificial intelligence systems that the developer has developed or intentionally and substantially modified and currently offers or makes available to recipients; and (2) how the developer manages known or reasonably foreseeable risks of algorithmic discrimination that may arise from the use or intentional and substantial modification of the systems listed on the developer's website pursuant to this subsection; and

E. ensure that the statement or public-use case inventory posted pursuant to this section remains accurate and is updated within ninety days of an intentional and substantial modification of a high-risk artificial intelligence system offered or made available by the developer to recipients."

New Mexico
Highly Relevant

New York 2025-A768 (NY AI Consumer Protection Act)

United States · Jan 8, 2025 · Bill

Highly RelevantDefinition 1 of 3

" ... "Intentional and substantial modification": (a) shall mean any deliberate change made to: (i) an artificial intelligence decision system that results in any new reasonably foreseeable risk of algorithmic discrimination; or (ii) a general-purpose artificial intelligence model that: (A) affects compliance of the general-purpose artificial intelligence model; (B) materially changes the purpose of the general-purpose artificial intelligence model; or (C) results in any new reasonably foreseeable risk of algorithmic discrimination; and (b) shall not include any change made to a high-risk artificial intelligence decision system, or the performance of a high-risk artificial intelligence decision system, if: (i) the high-risk artificial intelligence decision system continues to learn after such high-risk artificial intelligence decision system is: (A) offered, sold, leased, licensed, given or otherwise made available to a deployer; or (B) deployed; and (ii) such change: (A) is made to such high-risk artificial intelligence decision system as a result of any learning described in subparagraph (i) of this paragraph; (B) was predetermined by the deployer, or the third party contracted by the deployer, when such deployer or third party completed the initial impact assessment of such high-risk artificial intelligence decision system pursuant to subdivision three of section one thousand five hundred fifty-two of this article; and (C) is included in the technical documentation for such high-risk artificial intelligence decision system."

New York
Highly RelevantDefinition 2 of 3

" ... "Developer" shall mean any person doing business in this state that develops, or intentionally and substantially modifies, an artificial intelligence decision system."

New York
Highly RelevantDefinition 3 of 3

" ... § 1551. Required documentation. 1. (a) Beginning on January first, two thousand twenty-seven, each developer of a high-risk artificial intelligence decision system shall use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of a high-risk artificial intelligence decision system. In any enforcement action brought on or after such date by the attorney general pursuant to this article, there shall be a rebuttable presumption that a developer used reasonable care as required pursuant to this subdivision if:

(i) the developer complied with the provisions of this section; and

(ii) an independent third party identified by the attorney general pursuant to paragraph (b) of this subdivision and retained by the developer completed bias and governance audits for the high-risk artificial intelligence decision system."

New York
Highly Relevant

New York S1169 (New York AI Act)

United States · Jan 8, 2025 · Bill

Highly RelevantDefinition 1 of 7

" ... "DEVELOPER" MEANS A PERSON, PARTNERSHIP, OR CORPORATION THAT DESIGNS, CODES, OR PRODUCES AN AI SYSTEM, OR CREATES A SUBSTANTIAL CHANGE WITH RESPECT TO AN AI SYSTEM, WHETHER FOR ITS OWN USE IN THE STATE OF NEW YORK OR FOR USE BY A THIRD PARTY IN THE STATE OF NEW YORK."

New York
Highly RelevantDefinition 2 of 7

" ... § 86-A. Deployer and developer obligations. 3. The deployer or developer of a high-risk AI system is legally responsible for quality and accuracy of all consequential decisions made, including any bias, algorithmic discrimination, and/or misinformation resulting from the operation of the AI system."

New York
Highly RelevantDefinition 3 of 7

" ... § 86. Unlawful discriminatory practices. It shall be an unlawful discriminatory practice:

For a developer or deployer to use, sell, or share a high-risk AI system or a product featuring a high-risk AI system that produces algorithmic discrimination; or

For a developer to use, sell, or share a high-risk AI system or a product featuring a high-risk AI system that has not passed an independent audit, in accordance with section eighty-seven of this article, that has found that the product does not in fact produce algorithmic discrimination."

New York
Highly RelevantDefinition 4 of 7

" ... § 89. Risk management policy and program. 1. Each developer or deployer of high-risk AI systems shall plan, document, and implement a risk management policy and program to govern development or deployment, as applicable, of such high-risk AI system. The risk management policy and program shall specify and incorporate the principles, processes, and personnel that the deployer uses to identify, document, and mitigate known or reasonably foreseeable risks of algorithmic discrimination covered under subdivision one of section eighty-six of this article. The risk management policy and program shall be an iterative process planned, implemented, and regularly and systematically reviewed and updated over the life cycle of a high-risk AI system, requiring regular, systematic review and updates, including updates to documentation. A risk management policy and program implemented and maintained pursuant to this section shall be reasonable considering:

(A) the guidance and standards set forth in version 1.0 of the "Artificial Intelligence Risk Management Framework" published by the National Institute of Standards and Technology in the United States Department of Commerce, or the latest version thereof if at least as stringent;

(B) the size and complexity of the developer or deployer;

(C) the nature, scope, and intended uses of the high-risk AI system developed or deployed; and

(D) the sensitivity and volume of data processed in connection with the high-risk AI system."

New York
Highly RelevantDefinition 5 of 7

" ... § 88. High-risk AI system reporting requirements. 1. Every developer and deployer of a high-risk AI system shall comply with the reporting requirements of this section. Regardless of final findings, reports shall be filed with the attorney general prior to deployment of a high-risk AI system and then annually, or after each substantial change to the system, whichever comes first.

Together with each report required to be filed under this section, developers and deployers shall file with the attorney general a copy of the last completed independent audit required by this article and a legal attestation that the high-risk AI system: (A) does not violate any provision of this article; or (B) may violate or does violate one or more provisions of this article, that there is a plan of remediation to bring the high-risk AI system into compliance with this article, and a summary of such plan of remediation.

Developers of high-risk AI systems shall file with the attorney general a report containing the following:

(A) a description of the system including:

(i) a description of the system's software stack;

(ii) the purpose of the system;

(iii) the system's use to end users; and

(iv) reasonably foreseeable uses outside of the current or intended uses;

(v) how the system should be used or not used;

(B) the intended outputs of the system and whether the outputs can be or are otherwise appropriate to be used for any purpose not previously articulated;

(C) the methods for training of their models including:

(i) any pre-processing steps taken to prepare datasets for the training of a model underlying a high-risk AI system;

(ii) datasheets comprehensively describing the datasets upon which models were trained and evaluated, how and why datasets were collected, how that training data will be used and maintained going forward through the development cycle; and

(iii) steps taken to ensure compliance with privacy, data privacy, data security, and copyright laws;

(D) detailed use and data management policies;

(E) any other information necessary to allow the deployer to understand the outputs and monitor the system for compliance with this article;

(F) any other information necessary to allow the deployer to comply with the requirements of subdivision four of this section; and

(G) for any high-risk AI system that is a substantial factor in making a consequential decision:

(i) a detailed description of the proposed uses of the system, including what consequential decisions the system will support;

(ii) a detailed description of the system's capabilities and any developer-imposed limitations, including capabilities outside of its intended use, when the system should not be used, any safeguards or guardrails in place to protect against unintended, inappropriate, or disallowed uses, and testing of any such safeguards or guardrails;

(iii) an internal risk assessment including documentation and results of testing conducted to identify all reasonably foreseeable risks related to algorithmic discrimination, accuracy and reliability, privacy and autonomy, and safety and security, as well as actions taken to address those risks, and subsequent testing to assess the efficacy of actions taken to address risks; and

(iv) whether the system should be monitored, and if so, how such system should be monitored."

New York
Highly RelevantDefinition 6 of 7

" ... § 87. Audits. 1. Prior to deployment of a high-risk AI system, six months after deployment, and at least every eighteen months thereafter for each calendar year a high-risk AI system is in use after the first post-deployment audit, every developer or deployer of a high-risk AI system shall cause to be conducted at least one third-party audit in compliance with the provisions of this section to ensure that the product does not produce algorithmic discrimination and complies with the provisions of this article. Regardless of final findings, the deployer or developer shall deliver all audits conducted under this section to the attorney general.

A deployer or developer may hire more than one auditor to fulfill the requirements of this section.

The audit shall include the following:

(A) an analysis of data management policies including whether personal or sensitive data relating to a consumer is subject to data security protection standards that comply with the requirements of section eight hundred ninety-nine-bb of the general business law;

(B) an analysis of the system accuracy and reliability according to each specified use case listed in the entity's reporting document filed by the developer or deployer under section eighty-eight of this article;

(C) disparate impacts and a determination of whether the product produces algorithmic discrimination in violation of this article by each intended and foreseeable identified use as identified by the deployer and developer;

(D) analysis of how the technology complies with existing relevant federal, state, and local privacy and data privacy laws; and

(E) an evaluation of the developer's or deployer's documented risk management policy and program required under section eighty-nine of this article for conformity with subdivision one of such section eighty-nine."

New York
Moderately RelevantDefinition 7 of 7

" ... "DEVELOPER-EMPLOYER" MEANS A DEVELOPER THAT IS AN EMPLOYER."

New York
Highly Relevant

Artificial Intelligence Research, Innovation, and Accountability Act of 2023

United States · Jan 3, 2025 · Bill

" ... The term “developer” means an entity that—(A) designs, codes, produces, or owns an artificial intelligence system for internal use or for use by a third party as a baseline model; and (B) does not act as a deployer of the artificial intelligence system described in subparagraph (A)."

United States Congress
Highly Relevant

Preserving American Dominance in Artificial Intelligence Act of 2024

United States · Jan 3, 2025 · Bill

Highly RelevantDefinition 1 of 2

" ... The term “covered frontier artificial intelligence model developer” means a person who develops, trains, pre-trains or fine-tunes, or creates a covered frontier artificial intelligence model, including by taking steps to initiate a training run of the covered frontier artificial intelligence model."

United States Congress
Moderately RelevantDefinition 2 of 2

" ... The term “infrastructure-as-a-service provider” means a person who sells or makes otherwise available to customers infrastructure-as-a-service products or services that provide cloud-based processing, storage, networks, or other fundamental computing resources, and with which the consumer is able to deploy and run software that is not predefined, including operating systems and applications."

United States Congress
Highly Relevant

Protecting AI and Cloud Competition in Defense Act of 2024

United States · Jan 3, 2025 · Bill

Highly RelevantDefinition 1 of 2

" ... The term “covered provider” means any cloud provider, data infrastructure provider, or foundation model provider that has entered into contracts with the Department of Defense totaling at least $50,000,000 in any of the 5 previous fiscal years."

United States Congress
Highly RelevantDefinition 2 of 2

" ... The term “foundation model provider” means any company engaged in the provision, sale, or licensing of foundation models to customers, including individuals and businesses."

United States Congress
Highly Relevant

Securing Elections From AI Deception Act

United States · Jan 3, 2025 · Bill

" ... The term “developer” means any person that designs, codes, customizes, or produces a covered algorithm, or substantially modifies a covered algorithm, whether for its own use or for use by a third party."

United States Congress
Highly Relevant

VET Artificial Intelligence Act

United States · Jan 3, 2025 · Bill

" ... The term “developer”— (A) means an entity that builds, designs, codes, produces, trains, or owns an artificial intelligence system for internal use or for use by a third party; and (B) does not include an entity that is solely a deployer of the artificial intelligence system."

United States Congress
Highly Relevant

California AB 2013 (AI Training Data)

United States · Sep 28, 2024 · Document

Highly RelevantDefinition 1 of 2

" ... “Developer” means a person, partnership, state or local government agency, or corporation that designs, codes, produces, or substantially modifies an artificial intelligence system or service for use by members of the public. For purposes of this subdivision, “members of the public” does not include an affiliate as defined in subparagraph (A) of paragraph (1) of subdivision (c) of Section 1799.1a, or a hospital’s medical staff member."

California
Highly RelevantDefinition 2 of 2

" ... “Substantially modifies” or “substantial modification” means a new version, new release, or other update to a generative artificial intelligence system or service that materially changes its functionality or performance, including the results of retraining or fine tuning."

California
Highly Relevant

California AI Transparency Act (2024)

United States · Sep 20, 2024 · Bill

" ... “Covered provider” means a person that creates, codes, or otherwise produces a generative artificial intelligence system that has over 1,000,000 monthly visitors or users and is publicly accessible within the geographic boundaries of the state."

California
Highly Relevant

Artificial Intelligence Law Proposal (Turkish Parliament)

Other Countries · Jun 24, 2024 · Document

" ... Provider: Refers to natural or legal persons who develop, produce, and market artificial intelligence systems."

Government of Turkey
Highly Relevant

Colorado HB 1468 (Artificial Intelligence Impact Task Force)

United States · Jun 6, 2024 · Bill

" ... "DEVELOPER" MEANS A PERSON DOING BUSINESS IN THIS STATE THAT DEVELOPS OR INTENTIONALLY AND SUBSTANTIALLY MODIFIES AN ARTIFICIAL INTELLIGENCE SYSTEM OR AUTOMATED DECISION SYSTEM."

Colorado
Highly Relevant

AB-331 Automated decision tools

United States · Jan 31, 2024 · Document

Highly RelevantDefinition 1 of 6

" ... “Developer” means a person, partnership, state or local government agency, or corporation that designs, codes, or produces an automated decision tool, or substantially modifies an artificial intelligence system or service for the intended purpose of making, or being a controlling factor in making, consequential decisions, whether for its own use or for use by a third party."

California
Highly RelevantDefinition 2 of 6

" ... 22756.7. (a) Within 60 days of completing an impact assessment required by this chapter, a deployer or a developer shall provide the impact assessment to the Civil Rights Department.

(b) (1) A deployer or developer who violates this section shall be liable for an administrative fine of not more than ten thousand dollars ($10,000) per violation in an administrative enforcement action brought by the Civil Rights Department. (2) Each day on which an automated decision tool is used for which an impact assessment has not been submitted pursuant to this section shall give rise to a distinct violation of this section.

(c) The Civil Rights Department may share impact assessments with other state entities as appropriate."

California
Highly RelevantDefinition 3 of 6

" ... 22756.3. (a) A developer shall provide a deployer with a statement regarding the intended uses of the automated decision tool and documentation regarding all of the following:

(1) The known limitations of the automated decision tool, including any reasonably foreseeable risks of algorithmic discrimination arising from its intended use.

(2) A description of the type of data used to program or train the automated decision tool.

(3) A description of how the automated decision tool was evaluated for validity and explainability before sale or licensing.

(b) This section does not require the disclosure of trade secrets, as defined in Section 3426.1 of the Civil Code."

California
Highly RelevantDefinition 4 of 6

" ... (b) On or before January 1, 2025, and annually thereafter, a developer of an automated decision tool shall complete and document an assessment of any automated decision tool that it designs, codes, or produces that includes all of the following:

(1) A statement of the purpose of the automated decision tool and its intended benefits, uses, and deployment contexts.

(2) A description of the automated decision tool’s outputs and how they are used to make, or be a controlling factor in making, a consequential decision.

(3) A summary of the type of data collected from natural persons and processed by the automated decision tool when it is used to make, or be a controlling factor in making, a consequential decision.

(4) An analysis of a potential adverse impact on the basis of sex, race, color, ethnicity, religion, age, national origin, limited English proficiency, disability, veteran status, or genetic information from the deployer’s use of the automated decision tool.

(5) A description of the measures taken by the developer to mitigate the risk known to the developer of algorithmic discrimination arising from the use of the automated decision tool.

(6) A description of how the automated decision tool can be used by a natural person, or monitored when it is used, to make, or be a controlling factor in making, a consequential decision.

(c) A deployer or developer shall, in addition to the impact assessment required by subdivisions (a) and (b), perform, as soon as feasible, an impact assessment with respect to any significant update."

California
Highly RelevantDefinition 5 of 6

" ... 22756.4. (a) (1) A deployer or developer shall establish, document, implement, and maintain a governance program that contains reasonable administrative and technical safeguards to map, measure, manage, and govern the reasonably foreseeable risks of algorithmic discrimination associated with the use or intended use of an automated decision tool.

(2) The safeguards required by this subdivision shall be appropriate to all of the following: (A) The use or intended use of the automated decision tool. (B) The deployer’s or developer’s role as a deployer or developer. (C) The size, complexity, and resources of the deployer or developer. (D) The nature, context, and scope of the activities of the deployer or developer in connection with the automated decision tool. (E) The technical feasibility and cost of available tools, assessments, and other means used by a deployer or developer to map, measure, manage, and govern the risks associated with an automated decision tool.

(b) The governance program required by this section shall be designed to do all of the following: (1) (A) Designate at least one employee to be responsible for overseeing and maintaining the governance program and compliance with this chapter. (B) (i) An employee designated pursuant to this paragraph shall have the authority to assert to the employee’s employer a good faith belief that the design, production, or use of an automated decision tool fails to comply with the requirements of this chapter. (ii) An employer of an employee designated pursuant to this paragraph shall conduct a prompt and complete assessment of any compliance issue raised by that employee. (2) Identify and implement safeguards to address reasonably foreseeable risks of algorithmic discrimination resulting from the use or intended use of an automated decision tool. (3) If established by a deployer, provide for the performance of impact assessments as required by Section 22756.1. (4) If established by a developer, provide for compliance with Sections 22756.2 and 22756.3. (5) Conduct an annual and comprehensive review of policies, practices, and procedures to ensure compliance with this chapter. (6) Maintain for two years after completion the results of an impact assessment. (7) Evaluate and make reasonable adjustments to administrative and technical safeguards in light of material changes in technology, the risks associated with the automated decision tool, the state of technical standards, and changes in business arrangements or operations of the deployer or developer.

(c) This section does not apply to a deployer with fewer than 25 employees unless, as of the end of the prior calendar year, the deployer deployed an automated decision tool that impacted more than 999 people per year."

California
Highly RelevantDefinition 6 of 6

" ... 22756.5. A deployer or developer shall make publicly available, in a readily accessible manner, a clear policy that provides a summary of both of the following:

(a) The types of automated decision tools currently in use or made available to others by the deployer or developer.

(b) How the deployer or developer manages the reasonably foreseeable risks of algorithmic discrimination that may arise from the use of the automated decision tools it currently uses or makes available to others."

California
Highly Relevant

Interim Measures for the Management of Generative Artificial Intelligence Services

China · Jul 10, 2023 · Document

Highly RelevantDefinition 1 of 2

" ... "Generative AI service providers" refers to organizations and individuals that use generative AI technology to provide generative AI services (including providing generative AI services through programmable interfaces and other means)."

Chinese Central Government
Highly RelevantDefinition 2 of 2

" ... The providers of generative AI services (hereinafter “providers”) shall carry out pre-training, optimization training, and other activities handling training data in accordance with law."

Chinese Central Government
Highly Relevant

Brazil Federal Senate Bill of Law No. 2338, of 2023

· May 3, 2023 · Bill

Highly RelevantDefinition 1 of 2

" ... artificial intelligence system provider: natural or legal person, public or private, who develops an artificial intelligence system, directly or by order, with a view to its placement on the market or its application in a service provided by it, under its own name or brand, for a fee or free of charge; ... "

Other Authorities
Highly RelevantDefinition 2 of 2

" ... Art. 20
In addition to the measures indicated in art. 19, artificial intelligence agents who provide or operate high-risk systems shall adopt the following governance measures and internal processes:

I - documentation, in the format appropriate to the development process and the technology used, regarding the operation of the system and the decisions involved in its construction, implementation and use, considering all relevant stages in the life cycle of the system, such as design, development, evaluation, operation and discontinuation of the system;

II - use of automatic logging tools for the operation of the system, in order to allow the evaluation of its accuracy and robustness and to ascertain potential discriminatory effects, and implementation of the adopted risk mitigation measures, with special attention to adverse effects;

III - conducting tests to assess appropriate levels of reliability, according to the sector and type of application of the artificial intelligence system, including robustness, accuracy, precision and coverage tests;

IV - data management measures to mitigate and prevent discriminatory biases, including:
a) evaluation of the data with appropriate measures to control human cognitive biases that may affect the collection and organization of the data and to avoid the generation of biases due to problems in classification, failures or lack of information regarding affected groups, lack of coverage or distortions in representativeness, according to the intended application, as well as corrective measures to avoid the incorporation of structural social biases that may be perpetuated and amplified by technology; and

b) composition of an inclusive team responsible for the design and development of the system, guided by the pursuit of diversity.

V - adoption of technical measures to enable the explainability of the results of artificial intelligence systems and measures to make available to operators and potentially impacted individuals general information about the functioning of the artificial intelligence model employed, explaining the logic and relevant criteria for producing results, as well as, upon request by the interested party, providing adequate information that allows the interpretation of the concretely produced results, respecting industrial and commercial secrecy."

Other Authorities
Highly Relevant

Measures for the Management of Generative Artificial Intelligence Services (Draft for Comment)

China · Apr 11, 2023 · Document

" ... Organizations or individuals that use generative AI to provide services such as chat, text, image, or audio generation (hereinafter referred to as “providers”); including providing programmable interfaces [i.e., APIs] and other means which support others to themselves generate text, images, audio, etc.; bear responsibility as the producer of the content generated by the product."

Chinese Central Government
Highly Relevant

California SB 53 September 2025 (Artificial intelligence models: large developers)

United States · Sep 29, 2025 · Document

Highly RelevantDefinition 1 of 6

" ... (j) “Large frontier developer” means a frontier developer that together with its affiliates collectively had annual gross revenues in excess of five hundred million dollars ($500,000,000) in the preceding calendar year."

California
Highly RelevantDefinition 2 of 6

" ... “Frontier developer” means a person who has trained, or initiated the training of, a frontier model, with respect to which the person has used, or intends to use, at least as much computing power to train the frontier model as would meet the technical specifications found in subdivision (i)."

California
Moderately RelevantDefinition 3 of 6

" ... “Frontier developer” has the meaning defined in Section 22757.11 of the Business and Professions Code."

California
Moderately RelevantDefinition 4 of 6

" ... “Large frontier developer” has the meaning defined in Section 22757.11 of the Business and Professions Code."

California
Somewhat RelevantDefinition 5 of 6

" ... “Large frontier developer” so that it applies to well-resourced frontier developers."

California
Somewhat RelevantDefinition 6 of 6

" ... “Frontier developer” so that it applies to developers of frontier models who are themselves at the frontier of artificial intelligence development."

California
Highly Relevant

California SB 53 March 2025 (CalCompute and Whistleblowers)

United States · Jan 7, 2025 · Document

" ... “Developer” means a person that has trained at least one foundation model with a quantity of computational power that costs at least one hundred million dollars ($100,000,000) when measured using prevailing market prices of cloud compute."

California
Highly Relevant

Texas Responsible AI Governance Act (2025 Update) (HB 149)

United States · Jun 22, 2025 · Bill

" ... "Developer" means a person doing business in this state that develops an artificial intelligence system."

Texas
Highly Relevant

Massachusetts HD 4053 (protecting consumers in interactions with AI systems)

United States · Jan 17, 2025 · Bill

Highly RelevantDefinition 1 of 5

" ... (d) (1) Not later than 6 months after the effective date of this act, a developer shall make available, in a manner that is clear and readily available on the developer's website or in a public use case inventory, a statement summarizing:

(i) the types of high-risk artificial intelligence systems that the developer has developed or intentionally and substantially modified and currently makes available to a deployer or other developer; and

(ii) how the developer manages known or reasonably foreseeable risks of algorithmic discrimination that may arise from the development or intentional and substantial modification of the types of high-risk artificial intelligence systems described in accordance with subsection (d)(1)(i) of this section.

(2) a developer shall update the statement described in subsection (d)(1) of this section:

(i) as necessary to ensure that the statement remains accurate; and

(ii) no later than ninety days after the developer intentionally and substantially modifies any high-risk artificial intelligence system described in subsection (d)(1)(i) of this section.

(e) Not later than 6 months after the effective date of this act, a developer of a high-risk artificial intelligence system shall disclose to the attorney general, in a form and manner prescribed by the attorney general, and to all known deployers or other developers of the high-risk artificial intelligence system, any known or reasonably foreseeable risks of algorithmic discrimination arising from the intended uses of the high-risk artificial intelligence system without unreasonable delay but no later than ninety days after the date on which:

(1) the developer discovers through the developer's ongoing testing and analysis that the developer's high-risk artificial intelligence system has been deployed and has caused or is reasonably likely to have caused algorithmic discrimination; or

(2) the developer receives from a deployer a credible report that the high-risk artificial intelligence system has been deployed and has caused algorithmic discrimination.

(f) nothing in subsections (b) to (e) of this section requires a developer to disclose a trade secret, information protected from disclosure by state or federal law, or information that would create a security risk to the developer.

(g) Not later than 6 months after the effective date of this act, the attorney general may require that a developer disclose to the attorney general, no later than ninety days after the request and in a form and manner prescribed by the attorney general, the statement or documentation described in subsection (b) of this section. The attorney general may evaluate such statement or documentation to ensure compliance with this chapter, and the statement or documentation is not subject to disclosure under the “Massachusetts Public Records Law”, chapter 66, section 10 of the General Laws. In a disclosure pursuant to this subsection (g), a developer may designate the statement or documentation as including proprietary information or a trade secret. To the extent that any information contained in the statement or documentation includes information subject to attorney-client privilege or work-product protection, the disclosure does not constitute a waiver of the privilege or protection."

Massachusetts
Highly RelevantDefinition 2 of 5

" ... (b) Not later than 6 months after the effective date of this act, and except as provided in subsection (f) of this section, a developer of a high-risk artificial intelligence system shall make available to the deployer or other developer of the high-risk artificial intelligence system:

(1) a general statement describing the reasonably foreseeable uses and known harmful or inappropriate uses of the high-risk artificial intelligence system;

(2) documentation disclosing:

(i) high-level summaries of the type of data used to train the high-risk artificial intelligence system;

(ii) known or reasonably foreseeable limitations of the high-risk artificial intelligence system, including known or reasonably foreseeable risks of algorithmic discrimination arising from the intended uses of the high-risk artificial intelligence system;

(iii) the purpose of the high-risk artificial intelligence system;

(iv) the intended benefits and uses of the high-risk artificial intelligence system; and

(v) all other information necessary to allow the deployer to comply with the requirements of section 3;

(3) documentation describing:

(i) how the high-risk artificial intelligence system was evaluated for performance and mitigation of algorithmic discrimination before the high-risk artificial intelligence system was offered, sold, leased, licensed, given, or otherwise made available to the deployer;

(ii) the data governance measures used to cover the training datasets and the measures used to examine the suitability of data sources, possible biases, and appropriate mitigation;

(iii) the intended outputs of the high-risk artificial intelligence system;

(iv) the measures the developer has taken to mitigate known or reasonably foreseeable risks of algorithmic discrimination that may arise from the reasonably foreseeable deployment of the high-risk artificial intelligence system; and

(v) how the high-risk artificial intelligence system should be used, not be used, and be monitored by an individual when the high-risk artificial intelligence system is used to make, or is a substantial factor in making, a consequential decision; and

(4) any additional documentation that is reasonably necessary to assist the deployer in understanding the outputs and monitor the performance of the high-risk artificial intelligence system for risks of algorithmic discrimination.

(c) (1) except as provided in subsection (f) of this section, a developer that offers, sells, leases, licenses, gives, or otherwise makes available to a deployer or other developer a high-risk artificial intelligence system not later than 6 months after the effective date of this act, shall make available to the deployer or other developer, to the extent feasible, the documentation and information, through artifacts such as model cards, dataset cards, or other impact assessments, necessary for a deployer, or for a third party contracted by a deployer, to complete an impact assessment pursuant to section 3 (c).

(2) a developer that also serves as a deployer for a high-risk artificial intelligence system is not required to generate the documentation required by this section unless the high-risk artificial intelligence system is provided to an unaffiliated entity acting as a deployer.

(d) (1) Not later than 6 months after the effective date of this act, a developer shall make available, in a manner that is clear and readily available on the developer's website or in a public use case inventory, a statement summarizing:

(i) the types of high-risk artificial intelligence systems that the developer has developed or intentionally and substantially modified and currently makes available to a deployer or other developer; and

(ii) how the developer manages known or reasonably foreseeable risks of algorithmic discrimination that may arise from the development or intentional and substantial modification of the types of high-risk artificial intelligence systems described in accordance with subsection (d)(1)(i) of this section.

(2) a developer shall update the statement described in subsection (d)(1) of this section:

(i) as necessary to ensure that the statement remains accurate; and

(ii) no later than ninety days after the developer intentionally and substantially modifies any high-risk artificial intelligence system described in subsection (d)(1)(i) of this section.

(e) Not later than 6 months after the effective date of this act, a developer of a high-risk artificial intelligence system shall disclose to the attorney general, in a form and manner prescribed by the attorney general, and to all known deployers or other developers of the high-risk artificial intelligence system, any known or reasonably foreseeable risks of algorithmic discrimination arising from the intended uses of the high-risk artificial intelligence system without unreasonable delay but no later than ninety days after the date on which:

(1) the developer discovers through the developer's ongoing testing and analysis that the developer's high-risk artificial intelligence system has been deployed and has caused or is reasonably likely to have caused algorithmic discrimination; or

(2) the developer receives from a deployer a credible report that the high-risk artificial intelligence system has been deployed and has caused algorithmic discrimination.

(f) nothing in subsections (b) to (e) of this section requires a developer to disclose a trade secret, information protected from disclosure by state or federal law, or information that would create a security risk to the developer.

(g) Not later than 6 months after the effective date of this act, the attorney general may require that a developer disclose to the attorney general, no later than ninety days after the request and in a form and manner prescribed by the attorney general, the statement or documentation described in subsection (b) of this section. The attorney general may evaluate such statement or documentation to ensure compliance with this chapter, and the statement or documentation is not subject to disclosure under the “Massachusetts Public Records Law”, chapter 66, section 10 of the General Laws. In a disclosure pursuant to this subsection (g), a developer may designate the statement or documentation as including proprietary information or a trade secret. To the extent that any information contained in the statement or documentation includes information subject to attorney-client privilege or work-product protection, the disclosure does not constitute a waiver of the privilege or protection."

Massachusetts
Highly RelevantDefinition 3 of 5

" ... Section 2. Developer duty to avoid algorithmic discrimination - required documentation.

(a) Not later than 6 months after the effective date of this act, a developer of a high-risk artificial intelligence system shall use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination arising from the intended and contracted uses of the high-risk artificial intelligence system. In any enforcement action brought not later than 6 months after the effective date of this act, by the attorney general pursuant to section 6, there is a rebuttable presumption that a developer used reasonable care as required under this section if the developer complied with this section and any additional requirements or obligations as set forth in rules promulgated by the attorney general pursuant to section 7."

Massachusetts
Highly RelevantDefinition 4 of 5

" ... "Developer" means a person doing business in this state that develops or intentionally and substantially modifies an artificial intelligence system."

Massachusetts
Highly RelevantDefinition 5 of 5

" ... "Intentional and substantial modification" or "intentionally and substantially modifies" means a deliberate change made to an artificial intelligence system that results in any new reasonably foreseeable risk of algorithmic discrimination.

"Intentional and substantial modification" or "intentionally and substantially modifies" does not include a change made to a high-risk artificial intelligence system, or the performance of a high-risk artificial intelligence system, if:

(1) the high-risk artificial intelligence system continues to learn after the high-risk artificial intelligence system is:

(i) offered, sold, leased, licensed, given, or otherwise made available to a deployer; or

(ii) deployed;

(2) the change is made to the high-risk artificial intelligence system as a result of any learning ... "

Massachusetts
Highly Relevant

Safe and Secure Innovation for Frontier AI Act (SB 1047)

United States · Sep 30, 2024 · Bill

" ... “Developer” means a person that performs the initial training of a covered model either by training a model using a sufficient quantity of computing power and cost, or by fine-tuning an existing covered model or covered model derivative using a quantity of computing power and cost greater than the amount specified in subdivision (e)."

California
Highly Relevant

Provisions on the Administration of Deep Synthesis Internet Information Services

China · Nov 25, 2022 · Document

" ... "deep synthesis service providers“ refers to organizations and individuals providing deep synthesis services."

Chinese Central Government
Highly Relevant

Artificial Intelligence Civil Rights Act of 2024

United States · Jan 3, 2025 · Bill

" ... SEC. 201. Covered algorithm standards.
(a) Covered algorithm use.—A developer or deployer shall do the following:

(1) Take reasonable measures to prevent and mitigate any harm identified by a pre-deployment evaluation described in section 102(a) or an impact assessment described in section 102(b).

(2) Take reasonable measures to ensure that an independent auditor has all necessary information to complete an accurate and effective pre-deployment evaluation described in section 102(a) or an impact assessment described in section 102(b).

(3) With respect to a covered algorithm, consult stakeholders, including any communities that will be impacted by the covered algorithm, regarding the development or deployment of the covered algorithm prior to the deploying, licensing, or offering the covered algorithm.

(4) With respect to a covered algorithm, certify that, based on the results of a pre-deployment evaluation described in section 102(a) or an impact assessment described in section 102(b)—

(A) use of the covered algorithm is not likely to result in harm or disparate impact in the equal enjoyment of goods, services, or other activities or opportunities;

(B) the benefits from the use of the covered algorithm to individuals affected by the covered algorithm likely outweigh the harms from the use of the covered algorithm to such individuals; and

(C) use of the covered algorithm is not likely to result in deceptive practices.

(5) Ensure that any covered algorithm of the developer or deployer functions—

(A) at a level that would be considered reasonable performance by an individual with ordinary skill in the art; and

(B) in a manner that is consistent with its expected and publicly-advertised performance, purpose, or use.

(6) Ensure any data used in the design, development, deployment, or use of the covered algorithm is relevant and appropriate to the deployment context and the publicly-advertised purpose or use.

(7) Ensure use of the covered algorithm as intended is not likely to result in a violation of this Act.

(b) Deceptive marketing of a product or service.—It shall be unlawful for a developer or deployer to engage in false, deceptive, or misleading advertising, marketing, or publicizing of a covered algorithm of the developer or deployer.

(c) Off-Label use.—

(1) DEVELOPERS.—It shall be unlawful for a developer to knowingly offer or license a covered algorithm for any consequential action other than those evaluated in the pre-deployment evaluation described in section 102(a).

(2) DEPLOYERS.—It shall be unlawful for a deployer to knowingly use a covered algorithm for any consequential action other than a use evaluated in the pre-deployment evaluation described in section 102(a), unless the deployer agrees to assume the responsibilities of a developer required by this Act."

United States Congress
Highly Relevant

DIFC Data Protection Regulations, Regulation 10

Other Countries · Sep 1, 2023 · Regulation

" ... “Provider” means a natural or legal person that develops a System, or procures that a System is developed for or on behalf of such person, in each case with a view to providing, commercialising or otherwise making such System available to Operators or Deployers."

Government of the United Arab Emirates
Highly Relevant

Massachusetts HD396 (An Act to ensure accountability and transparency in artificial intelligence systems)

United States · Jan 8, 2025 · Bill

" ... (5) Developer: An entity or individual developing, modifying, or making AI systems available in Massachusetts."

Massachusetts
Highly Relevant

PREPARED for AI Act

United States · Jan 3, 2025 · Bill

" ... The term “developer” means an entity that designs, codes, produces, or owns artificial intelligence."

United States Congress
Highly Relevant

TRAIN Act

United States · Jan 3, 2025 · Bill

" ... The term ‘model developer or deployer’ means a person that develops or deploys a generative artificial intelligence model."

United States Congress
Moderately Relevant

Basic Safety Requirements for Generative Artificial Intelligence Services (National Standard - Draft for Feedback)

China · May 17, 2024 · Document

" ... Service Provider

An organization or individual that provides generative AI services in the form of interactive interfaces, programmable interfaces, etc."

Chinese Central Government
Moderately Relevant

Artificial Intelligence Law of the People’s Republic of China (Scholars' Draft)

China · Mar 16, 2024 · Document

Moderately RelevantDefinition 1 of 2

" ... “AI providers” means individuals and organizations that provide AI products and services; ... "

Other Authorities·Chinese Legal Scholarship
Moderately RelevantDefinition 2 of 2

" ... “AI developers” means individuals and organizations engaged in the development of AI products and services; ... "

Other Authorities·Chinese Legal Scholarship
Moderately Relevant

Basic Safety Requirements for Generative Artificial Intelligence Services (Technical Documentation)

China · Feb 29, 2024 · Document

" ... 3.2 Service Provider
An organization or individual that provides generative AI services in the form of interactive interfaces, programmable interfaces, etc."

Chinese Central Government
Moderately Relevant

AI Cloud KYC Proposed Rule (Department of Commerce)

United States · Apr 29, 2024 · Document

" ... United States Infrastructure as a Service provider or U.S. IaaS provider means any United States person that offers any Infrastructure as a Service product."

Department of Commerce
Moderately Relevant

Illinois HB 4875 (Publicity Act)

United States · Aug 9, 2024 · Bill

Moderately RelevantDefinition 1 of 3

" ... "Cloud service provider" means a cloud service provider as defined by 6 U.S.C. 650."

Illinois
Somewhat RelevantDefinition 2 of 3

" ... "Service provider" means any entity offering broadband service as that term is used in Section 10 of the Broadband Advisory Council Act, a wireless carrier as defined by 47 U.S.C. 615b(4), or a telecommunication carrier as that term is used in Section 13-202 of the Public Utilities Act."

Illinois
Somewhat RelevantDefinition 3 of 3

" ... "Application software provider" means a person providing a digital distribution service for other software applications and that allows users to search for and download such applications."

Illinois
Moderately Relevant

Hawaii SB 2687 (Deceptive Media)

United States · Jul 3, 2024 · Document

" ... "Cloud service provider" means a third-party company that provides scalable computing resources that businesses can access on demand over a network, including cloud-based computing, storage, platform, and application services."

Hawaii
Moderately Relevant

Stop Discrimination by Algorithms Act of 2023

United States · Feb 10, 2023 · Bill

" ... “Service provider” means any entity that performs algorithmic eligibility determinations or algorithmic information availability determinations on behalf of another entity."

District of Columbia
Somewhat Relevant

General Purpose AI Code of Practice, Transparency Chapter

International · Jul 10, 2025 · Bill

" ... In order to fulfil the obligations in Article 53(1), points (a) and (b), AI Act, Signatories commit to drawing up and keeping up-to-date model documentation in accordance with Measure 1.1, providing relevant information to providers of AI systems who intend to integrate the general-purpose AI model into their AI systems (‘downstream providers’ hereafter), and to the AI Office upon request."

European Union
Somewhat Relevant

Kids Online Safety Act, Sec. 13 ("Filter Bubble Transparency")

United States · Jan 3, 2025 · Bill

" ... The term “downstream provider” means, with respect to a search syndication contract, the person that receives access to an index of web pages on the internet from an upstream provider under such contract."

United States Congress
Somewhat Relevant

Know Your App Act

United States · Jan 3, 2025 · Bill

" ... The term “developer” means a person that creates, owns, or controls an application and is responsible for the design, development, maintenance, and distribution of the application to end users through an application store."

United States Congress
Somewhat Relevant

Blueprint for an AI Bill of Rights

United States · Oct 1, 2022 · Bill

" ... Designers, developers, and deployers of automated systems should take proactive and continuous measures to protect individuals and communities from algorithmic discrimination and to use and design systems in an equitable way.

Designers, developers, and deployers of automated systems should seek your permission and respect your decisions regarding collection, use, access, transfer, and deletion of your data in appropriate ways and to the greatest extent possible; where not possible, alternative privacy by design safeguards should be used.

Designers, developers, and deployers of automated systems should provide generally accessible plain language documentation including clear descriptions of the overall system functioning and the role automation plays, notice that such systems are in use, the individual or organization responsible for the system, and explanations of outcomes that are clear, timely, and accessible."

Executive Office of the President
Somewhat Relevant

Regulations for the Promotion of the Development of the AI Industry in Shanghai Municipality

China · Oct 1, 2022 · Regulation

" ... Entities that use biometric recognition technology to provide services and entities that provide corresponding technical support (hereinafter referred to as biometric service providers) shall adopt secure and controllable technical safeguard measures and establish sound algorithm management systems."

Chinese provincial and local governments
Somewhat Relevant

Google DeepMind Frontier Safety Framework Version 2.0

· Feb 4, 2025 · Document

" ... For each deceptive alignment risk, AI developers should: - Develop a safety case based on the model’s capabilities and the mitigations applied and tested. Such safety cases would make the case that the likelihood of deceptive alignment risk would be low enough for safe deployment, even if the model were trying to meaningfully undermine human control. - Test the mitigations applied to models via red-teaming protocols called “control evaluations,” to determine whether they meet the requirements of the safety case."

Private Sector
Somewhat Relevant

Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (EO 14110)

United States · Jan 20, 2025 · Executive Order

" ... The terms “Infrastructure as a Service Product,” “United States Infrastructure as a Service Product,” “United States Infrastructure as a Service Provider,” and “Infrastructure as a Service Account” each have the respective meanings given to those terms in section 5 of Executive Order 13984."

Executive Office of the President
Somewhat Relevant

AI Liability Directive

International · Mar 3, 2022 · Directive

" ... ‘provider’ means a provider as defined in [Article 3 (2) of the AI Act]; ... "

European Union