Virginia AI Regulations

Last verified: March 24, 2026

Regulatory Status

HB-2094

High-Risk Artificial Intelligence Developer and Deployer Act

vetoed

Passed by the Virginia General Assembly on February 20, 2025, but VETOED by Governor Glenn Youngkin on March 24, 2025. Would have made Virginia the second U.S. state to enact comprehensive AI regulation. The bill targeted machine-learning-based AI systems used as the principal basis for consequential decisions — defined as decisions with material legal or similarly significant effects on consumers regarding education, employment, financial services, health care, housing, insurance, legal services, or marital status. Developers would have been required to exercise a reasonable duty of care against algorithmic discrimination and provide deployers with documentation on system performance and limitations. Deployers would have been required to implement risk management programs, conduct algorithmic impact assessments before deployment and after significant updates, and disclose AI use to affected consumers with an opportunity to correct inaccuracies or appeal adverse decisions. Enforcement by the Virginia Attorney General with fines of $1,000 per violation and up to $10,000 for willful violations, with a 45-day right-to-cure period. Governor Youngkin vetoed citing burdens on small businesses and startups. Delegate Maldonado has indicated plans to reintroduce narrower legislation targeting healthcare in a future session.

Effective: View Bill Text →

Key Requirements

Developer Duty of Care Developers must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from intended and contracted uses of high-risk AI systems
Developer Documentation Developers must provide deployers with documentation describing system performance evaluation, intended outputs, risk mitigation measures, proper use, prohibited uses, and monitoring requirements
Synthetic Content Detection Developers must ensure AI-generated synthetic material can be detected using industry-standard tools or tools provided by the developer
Deployer Risk Management Program Deployers must devise and implement a risk management policy and program specific to each high-risk AI system they deploy
Algorithmic Impact Assessment Deployers must complete an impact assessment before deployment and before significant updates, covering system purpose, discriminatory risks, and mitigation steps; records retained for the longer of deployment duration plus 3 years
Consumer Disclosure Deployers must disclose to consumers when a high-risk AI system made or substantially influenced a consequential decision affecting them, including principal reasons for the decision
Consumer Correction and Appeal Rights Deployers must provide consumers an opportunity to correct inaccurate personal data used in consequential decisions and to appeal adverse decisions

Insurance Implications