Skip to content
هذه ترجمة للتسهيل فقط. النسخة الإنجليزية هي النسخة الرسمية والملزمة قانونيا. عرض النسخة الإنجليزية
US-PAMEDIUM coverage1 enforcement action

Pennsylvania — AI Duty Profile (Act 35 of 2025 Digital Forgery; Act 125 of 2024; Insurance AI Notice 2024-04; Insurance Data Security Act; BPINA; DOS AI Enforcement Task Force): AI Compliance Requirements

Pennsylvania has NO comprehensive AI statute and NO comprehensive consumer-privacy or biometric-privacy statute as of August 25, 2026. What it has instead is a set of narrow, real, currently-binding duties that catch AI-using businesses at specific points. (1) DIGITAL FORGERY — 18 Pa.C.S. § 4101.1, added by Act 35 of 2025 (SB 649), signed 2025-07-07, effective 2025-09-05: a person commits digital forgery if, WITH INTENT to defraud or injure anyone (or with knowledge and intent that they are facilitating a fraud or injury by another), they generate or create and distribute a forged digital likeness as genuine, knowing or having reason to know it is forged. Intent is an ELEMENT of the offense, not merely a grading factor. Base grading is a first-degree misdemeanor; it rises to a third-degree felony where the forgery is committed through involvement in a scheme to defraud, coerce or commit theft of monetary assets or property. Reported exceptions cover satire, parody, commentary, criticism and law-enforcement activity, and there is an affirmative defense where the defendant took reasonable action to put viewers or listeners on notice that the likeness is not genuine — which is why clear AI labelling is the single highest-value control here. The section is criminal only: it creates no private right of action. (2) SYNTHETIC SEXUAL IMAGERY — Act 125 of 2024 (SB 1213, signed 2024-10-29) extended 18 Pa.C.S. § 3131 to "an artificially generated sexual depiction of an individual" and 18 Pa.C.S. § 6312 to AI-generated child sexual abuse material. (3) INSURERS — the deepest Pennsylvania surface, and it separates into binding law and non-binding guidance. Binding: the Unfair Insurance Practices Act (40 P.S. §§ 1171.1—1171.15) and the Unfair Claims Settlement Practices regulations (31 Pa. Code §§ 146.1—146.10) reach AI-supported underwriting, marketing, servicing and claims decisions "regardless of the methods the insurer used to determine or support its actions", carrying cease-and-desist and licence suspension or revocation under § 1171.9 and court-imposed civil penalties under § 1171.11 of up to $5,000 per knowing violation ($50,000 aggregate per six-month period) and up to $10,000 per breach of a cease-and-desist order; the P/C and title rate acts require that AI-derived rates, rating rules and rating plans not be excessive, inadequate or unfairly discriminatory; and for health plans, 40 P.S. § 991.2152 (Act 68 of 1998) requires that a denial of payment be MADE BY A LICENSED PHYSICIAN meeting the § 2155(d) qualifications — an AI cannot be that physician — while barring compensation containing direct or indirect incentives to approve or deny. Non-binding: Insurance Department Notice 2024-04 (54 Pa.B. 1910, 2024-04-06) adopts the NAIC AI model bulletin and expects every authorised insurer to run a written AIS program covering board-accountable governance, predictive-model inventory and validation against unseen data with model-drift assessment, third-party diligence with AI-scoped SOC 2 audit rights and a regulator-cooperation clause, and consumer notice that AI is in use — its guidelines state they "are not intended to be binding upon insurers", but its Section 4 production list applies regardless of whether an AIS program exists and reaches AI deliberately left outside it. Separately the Insurance Data Security Act (40 Pa.C.S. Ch. 45, Act 2 of 2023) imposes a security program, a five-business-day cybersecurity-event notice and — since 2025-12-11 — third-party service-provider oversight that reaches AI vendors, and AI governance elements are reportable through the Corporate Governance Annual Disclosure (40 Pa.C.S. §§ 3901—3911). (4) DATA BREACH — the Breach of Personal Information Notification Act, as amended by Act 33 of 2024 (effective 2024-09-26), now requires simultaneous Attorney General and consumer-reporting-agency notice at 500+ affected Pennsylvania residents plus 12 months of free credit monitoring for SSN/driver's-licence/financial-account breaches. (5) PROFESSIONAL IMPERSONATION — on 2026-02-27 the Governor stood up an AI Enforcement Task Force and complaint process at the Department of State to test whether AI bots are engaged in unlicensed professional practice, coordinated with the Attorney General's Unfair Trade Practices and Consumer Protection Law authority; the Commonwealth then sued Character Technologies, Inc. over chatbots presenting themselves as licensed Pennsylvania medical professionals.

Summary of publicly-available regulatory text as of 2026-08-26. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

September 5, 2025

Maximum Penalty

Digital forgery (18 Pa.C.S. § 4101.1): third-degree felony — up to 7 years imprisonment and a fine up to $15,000 — where committed through a scheme to defraud, coerce or commit theft; otherwise a first-degree misdemeanor, up to 5 years and a fine up to $10,000 (fine figures per the Crowell & Moring alert read this cycle; 18 Pa.C.S. § 1101 itself was not re-read this session). Criminal enforcement only — no private right of action under this section. Separately: UTPCPL civil penalties reported at up to $1,000 per violation and up to $3,000 per violation where the affected consumer is 60 or older (the Attorney General's vehicle for AI marketing deception and for breach-notification failures), and Insurance Department authority to impose monetary penalties and to suspend or revoke a licensee's licence, authorisation or registration under the Insurance Data Security Act.

What Your Business Must Do

16 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Prohibition on Deceptive AI-Generated Likenesses

Critical

Do not generate or distribute, as genuine, an AI-fabricated voice, image or video of a real, identifiable individual with intent to defraud or injure anyone — and do not knowingly supply such material to someone else who will. This covers AI voice cloning for impersonation fraud, deepfake imagery for financial scams, and fabricated audio/video "evidence". The intent to defraud or injure is an ELEMENT of the offense: consented or clearly-labelled synthetic media is not digital forgery. Grading rises from a first-degree misdemeanor to a third-degree felony where the forgery is committed through involvement in a scheme to defraud, coerce or commit theft of monetary assets or property. Effective September 5, 2025.

Deadline: September 5, 2025

18 Pa.C.S. § 4101.1 (Act 35 of 2025 / SB 649) — Offense of Digital Forgery

No AI-Generated Sexual Depictions of Real People or Minors (Act 125 of 2024)

Critical

Act 125 of 2024 (SB 1213, signed 2024-10-29) extended two existing Crimes Code offenses to synthetic media. 18 Pa.C.S. § 3131 (unlawful dissemination of intimate image) now reaches "an artificially generated sexual depiction of an individual" disseminated with intent to harass, annoy or alarm; 18 Pa.C.S. § 6312 (sexual abuse of children) now reaches AI-generated child sexual abuse material, including intentionally viewing, possessing or controlling it. Any organization operating image- or video-generation capability accessible to users must have technical controls (prompt/output filtering, known-CSAM detection, age controls) and an incident path — the exposure is criminal, not regulatory, and does not depend on a commercial motive.

18 Pa.C.S. § 3131 and 18 Pa.C.S. § 6312, as amended by Act 125 of 2024 (SB 1213)

AI-Developed Rates, Rating Rules and Rating Plans Must Not Be Excessive, Inadequate or Unfairly Discriminatory

Critical

Notice 2024-04 Section 1 states the rate-act position directly: the Casualty and Surety Rate Regulatory Act, the Fire, Marine and Inland Marine Rate Regulatory Act, the Property and Casualty Filing Reform Act, Article VII of the Workers' Compensation Act and the Title Insurance Companies article "require that property/casualty (P/C) insurance rates not be excessive, inadequate or unfairly discriminatory. The requirements of these acts apply regardless of the methodology that the insurer used to develop rates, rating rules and rating plans subject to those provisions." The notice then places the burden explicitly: "an insurer is responsible for assuring that rates, rating rules and rating plans that are developed using AI techniques and predictive models that rely on data and machine learning do not result in excessive, inadequate or unfairly discriminatory insurance rates with respect to all forms of casualty insurance—including fidelity, surety and guaranty bond—and to all forms of property insurance—including fire, marine and inland marine insurance, and any combination of any of the foregoing." This is the one place in the instrument where a BINDING statutory standard, not a guideline, is applied to AI output: the rate acts bind on their own force and the notice merely confirms that model-derived rates are inside them.

Deadline: April 6, 2024

Casualty and Surety Rate Regulatory Act (40 P.S. §§ 1181—1199); Fire, Marine and Inland Marine Rate Regulatory Act (40 P.S. §§ 1221—1238); Article V-A of The Insurance Company Law of 1921 — Property and Casualty Filing Reform Act (40 P.S. §§ 710-1—710-19); Article VII of the Workers' Compensation Act (77 P.S. §§ 1035.1—1035.22); Article VII of The Insurance Company Law of 1921 — Title Insurance Companies (40 P.S. §§ 910-1—910-55) — all as applied to AI-derived rating by Notice 2024-04, 54 Pa.B. 1910, Section 1

AI Must Not Produce Unfair Trade Practices or Unfair Claims Settlement Practices

Critical

The substantive floor under the whole Pennsylvania insurance-AI surface. Notice 2024-04 Section 1 states that the Unfair Insurance Practices Act "regulates trade practices in the business of insurance by defining practices that constitute unfair methods of competition or unfair or deceptive acts and practices and prohibiting the trade practices so defined or determined", and that the Unfair Claims Settlement Practices regulations "set forth standards for the investigation and disposition of claims arising under policies or certificates of insurance issued to residents in this Commonwealth." The operative sentence is methodology-blind: "Actions taken by insurers in this Commonwealth must not violate the UIPA or the UCSP regulations, regardless of the methods the insurer used to determine or support its actions." The notice then states what insurers are expected to do about it: "insurers are expected to adopt practices, including governance frameworks and risk management protocols, that are designed to ensure that the use of AI systems does not result in: 1) unfair trade practices, as defined in the UIPA; or 2) unfair claims settlement practices, as defined in the UCSP regulations." Section 3 restates the standard for AI decisions specifically — they must not be "inaccurate, arbitrary, capricious or unfairly discriminatory" — and the notice defines "[a]dverse consumer outcome" as "[a] decision by an insurer that is subject to insurance regulatory standards enforced by the Department that adversely impacts the consumer in a manner that violates those standards." Practical effect: an AI-driven claim denial, delay, or settlement practice is judged against the same UCSP standards as a human one, with no allowance for model opacity.

Deadline: April 6, 2024

Unfair Insurance Practices Act (40 P.S. §§ 1171.1—1171.15), in particular the unfair methods of competition and unfair or deceptive acts and practices defined in section 5 (40 P.S. § 1171.5); Unfair Claims Settlement Practices Regulations, 31 Pa. Code §§ 146.1—146.10 (Title 31, Chapter 146, Subchapter A) — both applied to AI-supported decisions by Notice 2024-04, 54 Pa.B. 1910, Section 1

A Payment Denial Must Be Made by a Licensed Physician — AI Cannot Be the Denier (Act 68 of 1998)

Critical

R524 STANDING UTILIZATION-REVIEW SWEEP — Pennsylvania makes it five for five (Illinois, Massachusetts, Virginia, Maryland, now Pennsylvania: every state whose insurance-AI surface has been built to premium depth also carries a licensed-clinician adverse-determination rule that constrains AI far harder than the AI guidance does). Article XXI of the Insurance Company Law of 1921, added by Act 68 of 1998 (the Quality Health Care Accountability and Protection act, 40 P.S. §§ 991.2101—991.2193), provides at 40 P.S. § 991.2152 that "[u]tilization review that results in a denial of payment for a health care service shall be made by a licensed physician" meeting the qualifications in section 2155(d). Narrow professional exceptions exist and are themselves limited: "[a] licensed psychologist may perform a utilization review for behavioral health care services within the psychologist's scope of practice if the psychologist's clinical experience provides sufficient experience to review that specific behavioral health care service", but a psychologist may not "review the denial of payment for a health care service involving inpatient care or a prescription drug"; a licensed dentist may likewise review dental services within scope. The section also prohibits incentive structures: "[c]ompensation to any person or entity performing utilization review may not contain incentives, direct or indirect, for the person or entity to approve or deny payment for the delivery of any health care service." THE AI CONSEQUENCE: an AI or algorithmic system is not a licensed physician, psychologist or dentist. It may triage, surface evidence, flag cases and draft rationales, but the adverse determination itself must be MADE by the qualified licensed clinician, who must actually exercise judgment rather than ratify a model output at volume. A throughput pattern in which a clinician approves model-generated denials faster than review is possible is the exact fact pattern regulators and plaintiffs have attacked in other states.

40 P.S. § 991.2152 (Article XXI of the Insurance Company Law of 1921, added by Act 68 of 1998 — utilization review standards; licensed-physician denial requirement, psychologist and dentist scope exceptions, and prohibition on compensation incentives to approve or deny), read with the reviewer qualifications in 40 P.S. § 991.2155(d)

AI Must Not Hold Itself Out as a Licensed Professional (DOS AI Enforcement Task Force)

Critical

Pennsylvania is enforcing existing professional-licensing law against AI products directly. On 2026-02-27 the Governor announced a 12-member AI Enforcement Task Force and a public complaint process at the Department of State, whose stated remit is to evaluate whether AI bots are engaged in UNLICENSED PROFESSIONAL PRACTICE under existing law, with the Attorney General handling the parallel Unfair Trade Practices and Consumer Protection Law track. The Commonwealth then sued Character Technologies, Inc. over chatbots that presented as licensed medical professionals — one bot claimed to be a doctor of psychiatry and supplied an invalid Pennsylvania medical licence number. Concrete controls: bot names, avatars, personas and profiles must not assert professional credentials; outputs must not diagnose, prescribe or otherwise perform a licensed activity; the system must never emit a licence number or claimed licensure; and disclaimers must be strong enough to survive the design choices around them, since a boilerplate disclaimer beneath a persona built to look like a clinician is exactly what this action attacks.

Pennsylvania professional-licensing statutes administered by the Department of State / Bureau of Professional and Occupational Affairs (the Character Technologies action proceeds under the Medical Practice Act via the State Board of Medicine; specific section numbers were not read this session), together with the Unfair Trade Practices and Consumer Protection Law (73 P.S. § 201-1 et seq.)

AI Deepfake Use Policy

High Priority

Document your organization's policy on use of AI voice synthesis, image generation, and video synthesis technologies. Establish clear prohibitions on generating non-consensual synthetic media of real individuals for harmful purposes.

Deadline: September 5, 2025

18 Pa.C.S. § 4101.1 (Act 35 of 2025 / SB 649)

Written AI Systems (AIS) Program — Pennsylvania Insurance Department Notice 2024-04

High Priority

Pennsylvania adopted the NAIC model AI bulletin as Notice 2024-04 on 2024-04-06 (the eighth state to do so). Every insurer holding a certificate of authority or otherwise authorised to do insurance business in Pennsylvania — including HMOs, PPOs and health plan corporations — is expected to maintain a written program for the responsible use of AI systems ("AIS program"), covering: risk-management controls and internal audit; senior-management accountability to the board or a board committee; documented compliance; controls across the full AI lifecycle from design to retirement; data governance and bias analysis; and due diligence, contractual audit rights and ongoing oversight of third-party AI vendors and their data. The Department may request the governance framework, model-specific documentation, data lineage, validation testing results and third-party contracts in any investigation or market-conduct examination.

Deadline: April 6, 2024

Pennsylvania Insurance Department Notice 2024-04, "Use of Artificial Intelligence Systems by Insurers", 54 Pa.B. 1910, Pa.B. Doc. No. 24-484 (published Saturday, April 6, 2024; filed for public inspection April 5, 2024, 9:00 a.m.; signed MICHAEL HUMPHREYS, Insurance Commissioner), Section 3 ("Regulatory Guidance and Expectations"), AIS Program Guidelines § 1.0. R524 VERBATIM AUTHORITY ENUMERATION — Section 1 ("Introduction, Background and Legislative Authority") states that an insurer's use of AI is subject to "several existing Commonwealth laws and regulations, including but not limited to" exactly five bulleted items, transcribed from the Pennsylvania Bulletin text this round: (i) "The Unfair Insurance Practices Act (40 P.S. §§ 1171.1—1171.15) and the Unfair Claims Settlement Practices (UCSP) Regulations, Chapter 146 of Title 31, Pennsylvania Code Subchapter A (31 Pa. Code §§ 146.1—146.10)"; (ii) "Corporate Governance Annual Disclosure (CGAD) Requirements, Chapter 39 of Title 40 of the Pennsylvania Consolidated Statutes (40 Pa.C.S. §§ 3901—3911)"; (iii) "The Casualty and Surety Rate Regulatory Act (40 P.S. §§ 1181—1199), the Fire, Marine and Inland Marine Rate Regulatory Act (40 P.S. §§ 1221—1238), Article V-A of The Insurance Company Law of 1921—the Property and Casualty Filing Reform Act (40 P.S. §§ 710-1—710-19), Article VII of the Workers' Compensation Act (77 P.S. §§ 1035.1—1035.22) and Article VII of The Insurance Company Law of 1921 (regarding Title Insurance Companies; 40 P.S. §§ 910-1—910-55)"; and (iv) "Article IX of The Insurance Department Act of 1921—Examinations (40 P.S. §§ 323.1—323.8)". HONEST NEGATIVE: the notice does NOT cite Act 205 by act number anywhere — the string "205" does not occur in the published text (checked against the fetched Pennsylvania Bulletin page this round). The Unfair Insurance Practices Act IS the Act of Jul. 22, 1974, P.L. 589, No. 205, but Notice 2024-04 refers to it only by name and by its 40 P.S. range, so this entry cites it the way the notice does.

AIS Program Governance Framework — Board-Accountable Senior Management, Committees, Lines of Defence

High Priority

Notice 2024-04 Section 3 § 1.3 expects the AIS program to "vest responsibility for the development, implementation, monitoring and oversight of the AIS program and for setting the insurer's strategy for AI systems with senior management accountable to the board or an appropriate committee of the board." Group 2.0 (Governance) then expects the framework to "prioritize transparency, fairness and accountability in the design and implementation of the AI systems, recognizing that proprietary and trade secret information must be protected", and to address: § 2.1 the policies, processes and procedures — including risk management and internal controls — to be followed at each stage of an AI system life cycle "from proposed development to retirement"; § 2.2 the requirements adopted to document compliance, expressly "developed with Section 4 in mind" (i.e. authored so the examination production list can be answered); and § 2.3 the internal accountability structure, itemised as (a) centralized, federated or otherwise constituted committees drawn from business units, product specialists, actuarial, data science and analytics, underwriting, claims, compliance and legal; (b) scope of responsibility and authority, chains of command and decisional hierarchies; (c) "[t]he independence of decision-makers and lines of defense at successive stages of the AI system life cycle"; (d) monitoring, auditing, escalation, and reporting protocols and requirements; and (e) ongoing training and supervision of personnel. Programme reach is set by § 1.6 (all AI systems across "product development and design, marketing, use, underwriting, rating and pricing, case management, claim administration and payment, and fraud detection") and § 1.7 (all life-cycle phases including "design, development, validation, implementation (both systems and business), use, on-going monitoring, updating and retirement"). § 1.5 permits the programme to sit inside or outside the existing Enterprise Risk Management programme and to adopt a third-party framework, naming "the National Institute of Standards and Technology Artificial Intelligence Risk Management Framework, Version 1.0". § 1.8 extends the programme to AI "whether developed by the insurer or embedded within an affiliate or third-party vendor process".

Deadline: April 6, 2024

Pennsylvania Insurance Department Notice 2024-04, 54 Pa.B. 1910, Section 3, AIS Program Guidelines §§ 1.3, 1.5—1.8 and 2.0—2.3

Predictive Model Risk Management — Inventory, Validation on Unseen Data, Model-Drift Assessment

High Priority

Notice 2024-04 Section 3 group 3.0 expects the AIS program to "document the insurer's risk identification, mitigation, and management framework and internal controls for AI systems generally and at each stage of the AI system life cycle", addressing seven items. § 3.1: the oversight and approval process for developing, adopting or acquiring AI systems, "as well as the identification of constraints and controls on automation and design to align and balance function with risk". § 3.2: data practices and accountability procedures, "including data currency, lineage, quality, integrity, bias analysis and minimization, and suitability". § 3.3: management and oversight of predictive models and the algorithms used in them, comprising (a) inventories and descriptions of the predictive models, (b) "[d]etailed documentation of the development and use of the predictive models", and (c) assessments such as "interpretability, repeatability, robustness, regular tuning, reproducibility, traceability, model drift and the auditability of these measurements where appropriate". § 3.4: "[v]alidating, testing and retesting as necessary to assess the generalization of AI system outputs upon implementation, including the suitability of the data used to develop, train, validate and audit the model" — the notice specifies the accepted method as "comparing model performance on unseen data available at the time of model development to the performance observed on data post-implementation, measuring performance against expert review or other methods." § 3.5: protection of non-public information, particularly consumer information, "including unauthorized access to the predictive models themselves". § 3.6: data and record retention. § 3.7: for predictive models specifically, "a narrative description of the model's intended goals and objectives and how the model is developed and validated to ensure that the AI systems that rely on such models correctly and efficiently predict or implement those goals and objectives." Governance § 2.4 pairs with this, expecting documented processes "for designing, developing, verifying, deploying, using, updating and monitoring predictive models, including a description of methods used to detect and address errors, performance issues, outliers or unfair discrimination in the insurance practices resulting from the use of the predictive model."

Deadline: April 6, 2024

Pennsylvania Insurance Department Notice 2024-04, 54 Pa.B. 1910, Section 3, AIS Program Guidelines §§ 2.4 and 3.0—3.7; definitions of "Predictive Model" and "Model Drift" at Section 2

Third-Party AI and Data — Due Diligence, SOC 2 Audit Rights, Regulator-Cooperation Clause

High Priority

Notice 2024-04 Section 3 group 4.0 expects each AIS program to address the insurer's process for acquiring, using or relying on "(i) third-party data to develop AI systems; and (ii) AI systems developed by a third party", through standards, policies, procedures and protocols covering three items. § 4.1: "[d]ue diligence and the methods, which may include human oversight, employed by the insurer to assess the third party and its data or AI systems acquired from the third party to ensure that decisions made or supported from such AI systems that could lead to adverse consumer outcomes will meet the legal standards imposed on the insurer itself" — the operative principle being that buying the model does not move the legal standard off the insurer. § 4.2: where appropriate and available, contract terms that (a) "[p]rovide audit rights or entitle the insurer to receive audit reports, or both, such as System and Organization Control 2 reports or other generally accepted reports, performed by qualified auditing entities, which specifically encompass the AI in scope of the review", and (b) "[r]equire the third party to cooperate with the insurer with regard to regulatory inquiries and investigations related to the insurer's use of the third party's product or services." § 4.3: actually exercising those rights — "[t]he performance of contractual rights regarding audits or other activities, or both, to confirm the third party's compliance with contractual and, where applicable, regulatory requirements." Two contracting details carry disproportionate weight: a generic SOC 2 report does not satisfy § 4.2(a) unless it "specifically encompass[es] the AI in scope of the review", and § 4.3 makes an unexercised audit right a gap rather than a control.

Deadline: April 6, 2024

Pennsylvania Insurance Department Notice 2024-04, 54 Pa.B. 1910, Section 3, AIS Program Guidelines §§ 1.8 and 4.0—4.3; examination production list at Section 4 §§ 2.1—2.4

Report AI Governance in the Corporate Governance Annual Disclosure

High Priority

Notice 2024-04 Section 1 makes the CGAD filing an AI-reporting channel: Chapter 39 of Title 40 "requires insurers to report on governance practices and to provide a summary of the insurer's corporate governance structure, policies and practices", and — the operative sentence — "[t]he CGAD requirements are applicable to the elements of the insurer's corporate governance framework that address the insurer's use of AI systems to support actions and decisions that impact consumers." This matters because it is a PERIODIC, SELF-EXECUTING disclosure obligation rather than a contingent one: unlike the Section 4 examination production list, which only bites when the Department opens an investigation or market conduct action, the CGAD comes due on its own cycle and an insurer whose AI governance is undocumented has to file something about it anyway. Insurers that stood up an AIS program under § 1.3 with senior management accountable to the board have the CGAD content already; those that did not will find the gap surfaced in a filing signed at officer level.

Corporate Governance Annual Disclosure requirements, Chapter 39 of Title 40 of the Pennsylvania Consolidated Statutes (40 Pa.C.S. §§ 3901—3911), as applied to AI governance elements by Notice 2024-04, 54 Pa.B. 1910, Section 1

Examination Readiness — the Documents the Department Will Demand on an AI Inquiry

High Priority

Notice 2024-04 Section 4 is a production list, and it is the part of the instrument with operational teeth. It warns that "[r]egardless of the existence or scope of a written AIS program, in the context of an investigation or market conduct action or at any time determined necessary by the Insurance Commissioner, an insurer can expect to be asked to respond to an inquiry or provide documentation, or both" — so having no AIS program does not reduce what must be produced. Group 1.0 (AI system governance, risk management and use protocols) itemises: § 1.1(a) the current written AIS program; (b) documentation evidencing its adoption; (c) "[t]he scope of the insurer's AIS program, including any and all AI systems and technologies whether or not included in or addressed by the AIS program" — note that AI deliberately left OUTSIDE the programme is still discoverable; (d) the structure and mechanisms by which the programme is tailored and proportionate; (e) policies, procedures, guidance and training materials, expressly including (i) development/adoption/acquisition processes covering constraints and controls on automation and data governance and controls "including practices related to data lineage, quality, integrity, bias analysis and minimization, suitability, and data currency", (ii) predictive-model management processes "including measurements, standards, or thresholds adopted or used by the insurer", and (iii) protection of nonpublic information "including unauthorized access to predictive models themselves". § 1.2: pre-acquisition/pre-use diligence, monitoring, oversight and auditing of third-party data or AI systems. § 1.3: evidence of implementation and COMPLIANCE with the programme, including (a) formation and ongoing operation of coordinating bodies, (b) data practices and accountability documentation, (c) model and AI system inventories plus, for any model under investigation, documentation of compliance with programme policies, data source, provenance, lineage, quality, integrity, bias analysis and minimization, suitability and currency, and the techniques, measurements and thresholds used, and (d) validation, testing and auditing documentation "including evaluation of model drift". Group 2.0 adds, where third parties are involved: § 2.1 due diligence conducted on third parties and their data, models or AI systems; § 2.2 the vendor contracts themselves, "including terms relating to representations, warranties, data security and privacy, data sourcing, intellectual property rights, confidentiality and disclosures, and/or cooperation with regulators"; § 2.3 audits or confirmation processes performed regarding third-party compliance; and § 2.4 validation, testing and auditing documentation including model-drift evaluation.

Deadline: April 6, 2024

Pennsylvania Insurance Department Notice 2024-04, 54 Pa.B. 1910, Section 4 ("Regulatory Oversight and Examination Considerations"), §§ 1.0—1.3 and 2.0—2.4, exercised under Article IX of The Insurance Department Act of 1921 — Examinations (40 P.S. §§ 323.1—323.8)

Insurance Data Security Act — Security Program, AI/Third-Party Vendor Oversight, 5-Business-Day Event Notice

High Priority

The Insurance Data Security Act (40 Pa.C.S. Ch. 45, added by Act 2 of 2023, effective 2023-12-11) applies to every licensee — insurers, third-party administrators, producers and rating organizations. Licensees must run a risk assessment, maintain a written information security program with corporate oversight, certify compliance annually (domiciled insurers), investigate cybersecurity events, and notify the Insurance Commissioner as promptly as possible and no later than FIVE BUSINESS DAYS. The provision that matters most for AI adoption is the third-party service-provider oversight duty, which became effective 2025-12-11: an AI vendor processing nonpublic information for a licensee is a third-party service provider and must be diligenced and contractually bound accordingly. Phased dates from the Department's own guidance: risk assessment / security program / corporate oversight by 2024-12-11; third-party service-provider oversight by 2025-12-11.

Deadline: December 11, 2025

40 Pa.C.S. Ch. 45 (Insurance Data Security Act), added June 14, 2023, P.L. 4, No. 2, effective in 180 days (2023-12-11). Section-number caution: the Insurance Department's own Act 2 page attributes the five-business-day cybersecurity-event notice to § 4515 and the annual certification to § 4516, while Justia's chapter index lists § 4518 as "Notification of cybersecurity event" — the chapter text itself was unreachable this session, so the discrepancy is recorded rather than resolved.

Breach Notification — 500-Resident AG/CRA Trigger and 12-Month Credit Monitoring (Act 33 of 2024)

High Priority

The Breach of Personal Information Notification Act reaches any State agency, political subdivision, or individual or business doing business in the Commonwealth that maintains, stores or manages computerised personal information of Pennsylvania residents — no size threshold. Act 33 of 2024 (P.L. 427, No. 33, signed 2024-06-28, effective 2024-09-26) tightened it: notice to affected individuals without unreasonable delay (government entities within 7 business days); where more than 500 individuals must be notified, simultaneous notice to the Office of Attorney General — giving organization name and location, breach date, incident summary, estimated total affected and estimated Pennsylvania residents affected — and to the nationwide consumer reporting agencies (the CRA threshold dropped from 1,000 to 500); and where the breach involves Social Security, driver's licence/state ID or financial account numbers, 12 months of no-cost credit monitoring plus a complimentary credit report. Encryption is a safe harbour unless the key was also compromised. This is the operative Pennsylvania duty for AI vendors and AI-using businesses holding Pennsylvania customer or employee data — training corpora and prompt logs included.

Deadline: September 26, 2024

Breach of Personal Information Notification Act, Act 94 of 2005 (73 P.S. §§ 2301—2329), as amended by Act 151 of 2022 (omnibus amendments) and Act 33 of 2024 (P.L. 427, No. 33)

Notice to Consumers That AI Systems Are in Use

Medium Priority

Notice 2024-04 Section 3 § 1.9 expects the AIS program to "include processes and procedures providing notice to impacted consumers that AI systems are in use and provide access to appropriate levels of information based on the phase of the insurance life cycle in which the AI systems are being used." Two duties sit inside one sentence: a disclosure duty (tell the affected consumer AI is in the loop) and a graduated access duty (give information calibrated to the life-cycle phase — a marketing-stage touch and an adverse claim determination do not warrant the same disclosure depth). The notice does not prescribe wording, timing or channel, and does not create a standalone right of access; it is an expectation about the insurer having a documented process. Transparency and explainability to the impacted consumer are separately one of the five proportionality factors in Section 3 that set how heavy the surrounding controls must be, so a deployment with low explainability raises the required control intensity elsewhere in the programme rather than being prohibited.

Deadline: April 6, 2024

Pennsylvania Insurance Department Notice 2024-04, 54 Pa.B. 1910, Section 3, AIS Program Guidelines § 1.9 (with the transparency/explainability proportionality factor in the same Section)

Who Does This Apply To?

WHAT PENNSYLVANIA DOES NOT HAVE (as of 2026-08-25): no comprehensive AI act; no comprehensive consumer data-privacy act (HB 78 passed the House in October 2025 and remains pending in the Senate on an amended 100,000-record threshold); no biometric-privacy act; no election-deepfake disclosure statute (a bill passed the House and sits in Senate committee); no AI-in-hiring or automated-employment-decision statute. A Pennsylvania business asking "which AI law applies to me" is usually asking the wrong question — the honest answer is that four narrow tracks apply instead. TRACK 1 — DIGITAL FORGERY (everyone). 18 Pa.C.S. § 4101.1, effective 2025-09-05, no business-size threshold, individuals and organizations alike. Elements: intent to defraud or injure anyone (or knowledge and intent that one is facilitating another's fraud or injury) + generating or creating and distributing a forged digital likeness as genuine + knowing or having reason to know it is forged. A forged digital likeness is a computer-generated visual representation of an actual, identifiable individual, or an audio recording of such an individual's voice, that has been created/adapted/modified to closely resemble the genuine article, materially misrepresents the person's appearance, speech or behaviour, is likely to deceive a reasonable person, and is made without the individual's consent. Grading: first-degree misdemeanor, rising to third-degree felony where committed through involvement in a scheme to defraud, coerce or commit theft of monetary assets or property. Reported exceptions: satire, parody, commentary, criticism, law-enforcement activity, and technology providers. Affirmative defense: reasonable action to put viewers or listeners on notice that the likeness is not genuine. Criminal only — no private right of action. TRACK 2 — SYNTHETIC SEXUAL IMAGERY (any generative-media capability). Act 125 of 2024 extended 18 Pa.C.S. § 3131 to artificially generated sexual depictions and 18 Pa.C.S. § 6312 to AI-generated child sexual abuse material. TRACK 3 — INSURANCE (sector), the deepest surface Pennsylvania has. It has FOUR layers and they carry very different force, which is the distinction most vendors get wrong. (3a) BINDING STATUTE, methodology-blind: the Unfair Insurance Practices Act (40 P.S. §§ 1171.1—1171.15) and the Unfair Claims Settlement Practices regulations (31 Pa. Code §§ 146.1—146.10) reach any AI-supported underwriting, marketing, servicing or claims decision — Notice 2024-04 puts it in terms, "[a]ctions taken by insurers in this Commonwealth must not violate the UIPA or the UCSP regulations, regardless of the methods the insurer used to determine or support its actions." Penalties: cease and desist plus licence suspension or revocation for a section 5 practice (40 P.S. § 1171.9); court-imposed civil penalties up to $5,000 per knowing violation capped at $50,000 in any six-month period, and up to $10,000 per violation of a cease-and-desist order in effect (40 P.S. § 1171.11). The P/C and title rate acts bind the same way — AI-derived rates, rating rules and rating plans must not be excessive, inadequate or unfairly discriminatory. (3b) NON-BINDING GUIDANCE: Notice 2024-04 itself (54 Pa.B. 1910, 6 April 2024) adopts the NAIC model bulletin and expects a written AIS program — governance under board-accountable senior management, predictive-model inventory and validation on unseen data with model-drift assessment, third-party diligence with AI-scoped SOC 2 audit rights and a regulator-cooperation clause, and consumer notice that AI is in use. Its guidelines say in terms they "are not intended to be binding upon insurers", and Section 5 preserves an alternative-means defence — but Section 4 is a real production list that applies "[r]egardless of the existence or scope of a written AIS program", and it reaches AI the insurer deliberately left outside its own programme. (3c) BINDING STATUTE, health specifically: 40 P.S. § 991.2152 (Act 68 of 1998) requires that utilization review resulting in a denial of payment be MADE BY A LICENSED PHYSICIAN meeting the § 2155(d) qualifications, with narrow scope-limited psychologist and dentist exceptions, and bars compensation containing direct or indirect incentives to approve or deny. An AI cannot be that physician — this is a harder constraint on automated claims denial than anything in the AI notice, and it also reaches how a review VENDOR is paid. (3d) SECURITY: the Insurance Data Security Act (40 Pa.C.S. Ch. 45) adds a security program, five-business-day event notice, annual certification for domiciled insurers, and third-party service-provider oversight live since 2025-12-11 that captures AI vendors handling nonpublic information — with actual Departmental monetary-penalty and licence powers, cumulative with the Notice 2024-04 vendor expectations rather than an alternative to them. AI governance elements are separately reportable through the Corporate Governance Annual Disclosure (40 Pa.C.S. §§ 3901—3911). TRACK 4 — CONDUCT ENFORCEMENT (everyone). The Attorney General's UTPCPL authority covers deceptive AI marketing and breach-notification failure; the Department of State's AI Enforcement Task Force (announced 2026-02-27) tests whether AI bots practise a licensed profession without a licence — and has already produced a filed action against an out-of-state chatbot developer. Breach obligations under BPINA sit alongside, at a 500-Pennsylvania-resident trigger.

Recent Enforcement Actions

Commonwealth of Pennsylvania — Department of State / State Board of Medicine (announced by the Shapiro Administration)2026-05-05Source verified· as of 2026-08-26

Against: Character Technologies, Inc. (Character.AI)

The Commonwealth sued the developer of Character.AI, alleging that chatbot characters on the platform held themselves out as licensed medical professionals — including psychiatrists — and engaged users in conversations about mental-health symptoms. One bot, "Emilie", was described on the platform as a "Doctor of psychiatry", claimed to have attended medical school, offered depression assessments, and supplied an invalid Pennsylvania medical licence number. Reported as among the first state actions applying professional-licensing and consumer-protection law directly to an AI chatbot product. Announced 2026-05-05; an Alston & Bird advisory dates the filing 2026-05-01.

Source

Recent Regulatory Guidance

guidance2025-07-07

Governor Shapiro's Office — SB 649 Digital Forgery Law Signing Statement

Governor Shapiro signed SB 649 (Act 35 of 2025) on 2025-07-07, framing it as Pennsylvania's response to two convergent harm patterns: AI voice-clone fraud targeting elderly residents, and AI-generated political deepfakes targeting PA elections. The law reaches both fact patterns when the forged digital likeness is used to 'injure, exploit, defraud, or scam' a PA resident.

guidance2024-04-06

Pennsylvania Insurance Department Notice 2024-04 — Use of Artificial Intelligence Systems by Insurers

Pennsylvania became the eighth state to adopt the NAIC model AI bulletin (adopted by the NAIC on 2023-12-04), published at 54 Pa.B. 1910. It applies to all insurers authorised to do business in Pennsylvania, including HMOs, PPOs and health plan corporations, and sets out expectations for a written AIS program: fairness and ethical use, accountability to the board, compliance with existing insurance law, transparency, and safe/secure/robust systems — plus data governance, bias analysis, full-lifecycle controls, and third-party AI vendor due diligence with contractual audit rights. It states that decisions affecting consumers made or supported by AI must comply with all applicable insurance laws including unfair trade practice and unfair discrimination law, and lists what the Department may request on examination. The Notice states its guidelines are not intended to be binding on insurers.

Source
press release2026-02-27

Governor Shapiro — AI literacy toolkit, AI Enforcement Task Force and complaint process

Three administrative actions, none of them legislation: a multi-agency AI literacy toolkit (Education, Health, Human Services, State, Aging, Banking and Securities); a 12-member AI Enforcement Task Force plus a public complaint process at the Department of State, whose remit includes evaluating whether AI bots engage in unlicensed professional practice under existing law; and coordination with the Attorney General, who uses Unfair Trade Practices and Consumer Protection Law authority. The administration separately proposed four AI reforms in the 2026-27 budget that would require General Assembly action — age verification and parental consent for AI bots, detection of self-harm mentions with notification to authorities, periodic reminders that the user is not talking to a human, and a bar on sexually explicit or violent content featuring minors. These are PROPOSALS, not law.

Source

Key Case Law & Precedent

FTC — Impersonation Rule (final rule, effective April 1, 2024)

US Federal Trade Commission · 2024

FTC's final Impersonation Rule (16 CFR Part 461, effective April 1, 2024) makes it a violation of the FTC Act for any person to impersonate the government, businesses, or their officials — extending to AI-generated impersonation, with FTC civil penalties up to $53,088 per violation. Cited here as a parallel federal civil-enforcement mechanism alongside Pennsylvania's state criminal digital-forgery offense; no source found this cycle confirming the Pennsylvania AG has formally invoked this federal rule in a SB 649 context.

Outcome: FTC final rule effective April 1, 2024; civil penalties up to $53,088 per violation available to the FTC.

Case reference

Quarterly Enforcement Digest

Q3 2026 — Pennsylvania remains a NO-COMPREHENSIVE-AI-LAW state, and the honest customer answer is that four narrow tracks apply instead (digital forgery, synthetic sexual imagery, insurance AI governance, and conduct enforcement through licensing/UTPCPL/breach law). The direction of travel this year is ENFORCEMENT rather than legislation: the Department of State stood up a 12-member AI Enforcement Task Force and public complaint process on 2026-02-27, and the Commonwealth sued Character Technologies, Inc. in May 2026 over chatbots presenting as licensed medical professionals — the first Pennsylvania action applying existing licensing law to an AI product. WATCH LIST (all pending, none of them law as of 2026-08-25; statuses per trackers read this cycle because the General Assembly's own servers were unreachable): SB 1090 (SAFECHAT Act — AI chatbot child safety and suicide-prevention protocols, fines reported up to $500,000 per harmful incident) passed the Senate 49-1 on 2026-03-17 and awaits House consideration; HB 78 (comprehensive consumer data privacy) passed the House in October 2025 and sits in the Senate on an amended 100,000-record threshold; HB 1925 would require disclosure of AI in clinical and insurance-coverage decisions with qualified-professional final approval; SB 939 would create an AI data-centre regulatory sandbox; an election-deepfake disclosure bill passed the House unanimously and sits in Senate committee. The Joint State Government Commission's January 2026 report (389 pages) recommended a Chief AI Officer and mandatory employer AI disclosure — advisory only. Vendors selling to the Commonwealth should also note Executive Order 2023-19 (September 2023), which created a Generative AI Governing Board and bars AI from making final employment decisions in Commonwealth agencies, and the government-wide Commonwealth AI policy effective 2026-01-13 requiring human oversight and data-security controls; neither binds private business except through procurement.

Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-26.

Industry Playbooks covering Pennsylvania — AI Duty Profile (Act 35 of 2025 Digital Forgery; Act 125 of 2024; Insurance AI Notice 2024-04; Insurance Data Security Act; BPINA; DOS AI Enforcement Task Force)

These industry playbooks include jurisdiction-specific checklist items and guidance for Pennsylvania — AI Duty Profile (Act 35 of 2025 Digital Forgery; Act 125 of 2024; Insurance AI Notice 2024-04; Insurance Data Security Act; BPINA; DOS AI Enforcement Task Force).

Frequently Asked Questions

Does Pennsylvania — AI Duty Profile (Act 35 of 2025 Digital Forgery; Act 125 of 2024; Insurance AI Notice 2024-04; Insurance Data Security Act; BPINA; DOS AI Enforcement Task Force) apply to my business?

Pennsylvania has NO comprehensive AI statute and NO comprehensive consumer-privacy or biometric-privacy statute as of August 25, 2026. What it has instead is a set of narrow, real, currently-binding duties that catch AI-using businesses at specific… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Pennsylvania — AI Duty Profile (Act 35 of 2025 Digital Forgery; Act 125 of 2024; Insurance AI Notice 2024-04; Insurance Data Security Act; BPINA; DOS AI Enforcement Task Force) is: Digital forgery (18 Pa.C.S. § 4101.1): third-degree felony — up to 7 years imprisonment and a fine up to $15,000 — where committed through a scheme to defraud, coerce or commit theft; otherwise a first-degree misdemeanor, up to 5 years and a fine up to $10,000 (fine figures per the Crowell & Moring alert read this cycle; 18 Pa.C.S. § 1101 itself was not re-read this session). Criminal enforcement only — no private right of action under this section. Separately: UTPCPL civil penalties reported at up to $1,000 per violation and up to $3,000 per violation where the affected consumer is 60 or older (the Attorney General's vehicle for AI marketing deception and for breach-notification failures), and Insurance Department authority to impose monetary penalties and to suspend or revoke a licensee's licence, authorisation or registration under the Insurance Data Security Act.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Pennsylvania — AI Duty Profile (Act 35 of 2025 Digital Forgery; Act 125 of 2024; Insurance AI Notice 2024-04; Insurance Data Security Act; BPINA; DOS AI Enforcement Task Force)?

The 16 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.pa.gov/governor/newsroom/2025-press-releases/gov--shapiro-signs-new-digital-forgery-law

Last updated: 2026-08-26 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan