Skip to content
US-GAMEDIUM coverage

Georgia — AI, Age-Verification & Consumer-Protection Stack (SB 540 AI companion chatbots O.C.G.A. § 39-5-6 · SB 444 AI in health-plan utilization review § 33-46-7.1 · SB 351 age verification §§ 39-5-5 / 39-6-1 et seq. · breach notification § 10-1-910 et seq. · FBPA § 10-1-390 et seq.): AI Compliance Requirements

GEORGIA MULTI-SURFACE ENTRY (R510, 2026-08-25 — was single-surface/chatbot-only). Georgia has NO comprehensive consumer-privacy law, NO biometric-privacy act, and NO election-deepfake statute (all verified negatives, see recentGuidance), but it does have four live/near-live surfaces plus a general UDAP rail. (1) SB 540 — AI COMPANION CHATBOTS, O.C.G.A. § 39-5-6, signed 11 May 2026, effective 1 July 2027 (detail below). (2) SB 444 — AI IN HEALTH-PLAN UTILIZATION REVIEW, new O.C.G.A. § 33-46-7.1, effective 1 January 2027: private review agents and utilization review entities MAY use AI/software, but only as part of a utilization review plan meeting Chapter 46 standards and the Commissioner's rules, and such systems "shall not issue an adverse determination to a patient until a natural person qualifying as a private review agent or a utilization review entity conducts a utilization review in which a clinical peer participates," and may never "supersede the judgment of such clinical peer." (3) SB 351 (2024) — AGE VERIFICATION, in force since 1 July 2025: § 39-5-5 requires commercial entities whose public website carries a "substantial portion" (>33.33%) of material harmful to minors to run reasonable age verification (digitized ID, government ID, or a method meeting/exceeding NIST Identity Assurance Level 2) and forbids RETAINING identifying information after access is granted — fine up to $10,000 per violation plus a private damages action; §§ 39-6-1 to 39-6-5 (social-media age verification + parental consent under 16) are PRELIMINARILY ENJOINED and not enforceable (NetChoice v. Carr). (4) BREACH NOTIFICATION, O.C.G.A. § 10-1-910 et seq. — genuinely NARROW: it binds only "information brokers" (entities that, for monetary fees or dues, are in the business of collecting/assembling/evaluating/compiling/reporting/transmitting information concerning individuals) and "data collectors" (state or local government entities). An ordinary Georgia SaaS/AI company that holds customer data but does not sell information about individuals is generally OUT of scope; the statute sets no fixed notification clock, no Attorney General notice duty, no statutory penalty and no private right of action. Do not model this as a CCPA/CPRA-style breach regime. (5) FAIR BUSINESS PRACTICES ACT, O.C.G.A. § 10-1-390 et seq. — the catch-all rail an AI vendor is realistically sued under in Georgia today: unfair or deceptive acts in consumer transactions, AG investigative + cease-and-desist power, up to $2,000 per willful violation by AG administrative order and up to $5,000 per violation by a superior court, plus a private action with exemplary damages for intentional violations. Georgia has ADOPTED NO NAIC Model AI Bulletin (verified negative — see recentGuidance) yet regulates insurer AI by statute instead, via SB 444. — SB 540 DETAIL: signed by Governor Brian Kemp on May 11, 2026 and takes effect July 1, 2027 (enacted text verified against the governor-signed Act, version LC 64 0123S, which adds O.C.G.A. § 39-5-6). NARROW SCOPE — this is NOT a general chatbot-disclosure law: it regulates "AI companion chatbots," i.e. generative-AI systems designed to simulate a SUSTAINED human-like (intimate, romantic, or platonic) relationship by retaining prior-session information to personalize engagement, asking unprompted emotion-based questions, and sustaining ongoing dialogue on matters personal to the user. Expressly EXCLUDED: customer-service chatbots that do not sustain a relationship or elicit emotional attachment, internal-business GenAI, developer/research/enterprise-productivity tools, voice-command assistants, narrowly-tailored educational tools, and video-game/film/TV characters. In-scope operators must (1) clearly disclose the user is interacting with an AI companion chatbot at the start of each session and at least every 3 hours of continued interaction (every 1 hour for users known to be — or chatbots marketed to — minors); (2) for minors, take reasonable measures to stop the bot from impersonating a human, producing sexual content, simulating a romantic/sexual relationship, encouraging secrecy or social isolation, or using manipulative engagement tactics (reminders to return, excessive praise, soliciting gifts, variable rewards); (3) maintain a severe-harm/crisis protocol that refers users to the 988 Suicide and Crisis Lifeline; (4) not represent the bot is a licensed mental-health/behavioral-health/medical/counseling professional unless lawfully authorized; (5) offer minor/parental account-management tools; (6) use commercially reasonable age assurance before any feature that can produce sexually-explicit content (ID documents retained no longer than 24 hours; no sale of age-assurance data); and (7) publicly post the crisis protocol plus an annual aggregate count of crisis referrals. Enforced by the Georgia Attorney General: civil penalty up to $10,000 per KNOWING violation PLUS compensatory damages, costs and reasonable attorney's fees, and an order to enjoin the violation — and each day in violation counts as a separate violation FOR EACH USER AFFECTED (a large multiplier). A 30-day cure period is available at the AG's discretion for a first-time violation that does not involve knowing misconduct, sexual exploitation of a minor, or self-harm-related misconduct. (Effective date and penalty PRIMARY-SOURCE confirmed against the governor-signed enrolled Act on 2026-06-13, resolving the RQ-51 secondary-source flag; scope/duties corrected to the enacted "AI companion chatbot" text; ships legal_review_pending.)

Summary of publicly-available regulatory text as of 2026-08-25. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

July 1, 2025

Maximum Penalty

ACROSS THE GEORGIA SURFACES (R510): § 39-5-5 age verification — fine up to $10,000.00 per violation, set by the superior court of the county where an affected minor resides, instituted by the Attorney General, solicitor general or district attorney within ONE YEAR of the violation, and NOT preclusive of any other right of action; plus liability to an individual for damages (with court costs and attorney's fees) both for a minor's access and, separately, for knowingly retaining age-verification identifying information. §§ 39-6-1 to 39-6-5 social media — AG has EXCLUSIVE enforcement, expressly NO private right of action, damages up to $2,500.00 per violation, mandatory 90-day written cure notice before the AG may initiate an action (currently unenforceable — preliminarily enjoined). SB 444 / § 33-46-7.1 — the Act itself prescribes NO penalty; consequences run through Chapter 46 certification (the Commissioner of Insurance may refuse, suspend or revoke a private review agent's certificate, and a non-compliant certified agent is subject to the fines and penalties applicable to licensed insurers generally, per Ga. Comp. R. & Regs. 120-2-58). Fair Business Practices Act — up to $2,000.00 per willful violation by AG administrative order and up to $5,000.00 per violation imposed by a superior court (§ 10-1-397), plus AG restitution and cease-and-desist orders and a private action with exemplary damages for intentional violations (§ 10-1-399). Breach notification (§ 10-1-910 et seq.) — NO statutory penalty and NO private right of action (honest absence, verified, not an omission). SB 540: Georgia AG enforcement under O.C.G.A. § 39-5-6(k): civil penalty up to $10,000 per knowing violation, PLUS compensatory damages, costs and reasonable attorney's fees, and an order to enjoin the violation; each day in violation is a separate violation for each user affected. Discretionary 30-day cure for a first-time, non-knowing violation not involving sexual exploitation of a minor or self-harm. (Primary-source confirmed against the governor-signed enrolled Act 2026-06-13 — RQ-51 resolved; the prior "up to $10,000 per knowing violation" figure was correct but materially incomplete.)

What Your Business Must Do

11 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Georgia SB 444 — no AI-only adverse determination in health-plan utilization review (effective Jan 1, 2027)

Critical

If you are a private review agent or utilization review entity making Georgia health-coverage decisions, you may use AI and other software tools to automate tasks, reduce administrative burden and participate in decision making — but such systems SHALL NOT issue an adverse determination to a patient until a natural person qualifying as a private review agent, or a utilization review entity, conducts a utilization review in which a CLINICAL PEER participates; and in no event may the AI system, artificial intelligence, or other software tool supersede that clinical peer's judgment. Build the human-in-the-loop gate so that no denial can leave the system without a recorded clinical-peer review, and retain evidence of that participation per case. (New O.C.G.A. § 33-46-7.1(c), added by SB 444 (2026), LC 46 1522S; SECTION 2: "This Act shall become effective on January 1, 2027.") NOTE: SB 444 is Georgia's insurance-AI instrument — Georgia has adopted NO NAIC Model AI Bulletin.

Deadline: January 1, 2027

O.C.G.A. § 33-46-7.1(c) (SB 444, 2026)

Georgia SB 351 — age verification before access to a site with a substantial portion of material harmful to minors (IN FORCE since July 1, 2025)

Critical

Before allowing access to a public website that contains a "substantial portion" — defined as MORE THAN 33.33 percent of total material on the site — of material harmful to minors, a commercial entity must use a reasonable age verification method: submission of a digitized identification card (including a digital copy of a driver's license), submission of government-issued identification, or any commercially reasonable age verification method that meets or exceeds the NIST Identity Assurance Level 2 standard. This is directly load-bearing for generative-AI products with an adult mode: if your Georgia-reachable site crosses the 33.33% threshold, the § 39-5-5 gate applies TODAY, independently of the SB 540 age-assurance duty that starts in 2027. Carve-outs: news or public-interest broadcasts, video, reports or events; the rights of a news-gathering organization; cloud service providers; and an ISP, affiliate, subsidiary or search engine is not liable solely for providing access or connection where it did not create the content. (O.C.G.A. § 39-5-5(a), (b), (e), (f), added by SB 351 (2024); effective July 1, 2025 per PART IV SECTION 4-1 of the enrolled Act.)

Deadline: July 1, 2025

O.C.G.A. § 39-5-5(a)(9), (b), (e)-(f) (SB 351, 2024)

Georgia SB 540 — AI companion chatbot identity disclosure (effective July 1, 2027)

High Priority

If you operate an AI companion chatbot accessible to Georgia users, clearly and conspicuously disclose that the user is interacting with an AI companion chatbot (not a natural person) at the beginning of each interaction or session and at least every 3 hours during continued interaction — every 1 hour where you know or reasonably should know the user is a minor, or the chatbot is directed/marketed to minors. First confirm scope: customer-service bots that do not sustain a relationship or elicit emotional attachment, internal-business GenAI, dev/research/enterprise tools, voice assistants, narrow educational tools, and game/film/TV characters are excluded (O.C.G.A. § 39-5-6(a)(1)(B), (b)). Compliance deadline: July 1, 2027.

Deadline: July 1, 2027

O.C.G.A. § 39-5-6(a)(1)(B), (b)

Georgia SB 540 — minor-safety design + anti-manipulation measures

High Priority

For users known/reasonably-believed to be minors (or chatbots marketed to minors), institute reasonable measures to prevent the AI companion chatbot from: impersonating a human or refuting the AI disclosure; producing visual sexually-explicit content; suggesting the minor engage in sexual conduct or sexually objectifying them; simulating a romantic/sexual relationship or role-playing adult-minor romance; encouraging the minor to keep secrets from trusted adults; encouraging social isolation or exclusive reliance on the bot; simulating distress/guilt/abandonment when the user tries to disengage; or generating statements encouraging self-harm. Also prevent manipulative engagement techniques directed at minors (reminders to return, excessive praise to deepen attachment, soliciting gifts/premium purchases, variable/unpredictable rewards). (O.C.G.A. § 39-5-6(c)-(e)).

Deadline: July 1, 2027

O.C.G.A. § 39-5-6(c)-(e)

Georgia SB 540 — severe-harm/crisis protocol + public disclosure

High Priority

Implement and maintain a protocol to detect and address severe harm (suicide, attempted suicide, self-harm, eating-disorder-related self-harm, threats of violence): identify expressions of severe harm, refer users to appropriate crisis resources including the 988 Suicide and Crisis Lifeline, prevent content that encourages/instructs/normalizes severe harm, and escalate repeated/severe indicators. Publicly disclose on your website and in-app a plain-language summary of the protocol and, annually, the aggregate number of crisis-referral notifications issued in the prior calendar year (no PII). Do not represent the bot is licensed/authorized to provide professional mental-health/medical/counseling services unless lawfully authorized. (O.C.G.A. § 39-5-6(f)-(h)).

Deadline: July 1, 2027

O.C.G.A. § 39-5-6(f)-(h)

Georgia SB 444 — fold AI tools into a compliant utilization review plan

High Priority

AI systems, artificial intelligence and other software tools may be used by a private review agent or utilization review entity ONLY where those systems or tools are part of a utilization review plan that accords with the standards of Chapter 46 of Title 33 and the rules and regulations adopted by the Commissioner of Insurance. Practical effect: your model, its inputs, its decision role and its human-override path must be described inside the utilization review plan you file/maintain — an AI tool bolted on outside the plan is non-compliant even if a human signs the denial. Note the Act's own two definitions: "artificial intelligence" (a machine based system that, for a given set of human defined objectives, makes predictions, recommendations, or decisions influencing real or virtual environments) and the broader "artificial intelligence system" (an engineered or machine based system that emulates a person's capability to receive audio, visual, text or other information and uses it to emulate a human cognitive process). (O.C.G.A. § 33-46-7.1(a)-(b).)

Deadline: January 1, 2027

O.C.G.A. § 33-46-7.1(a)-(b) (SB 444, 2026)

Georgia SB 351 — destroy age-verification identifiers once access is granted

High Priority

When the commercial entity or a third party performs a reasonable age verification, the commercial entity SHALL NOT retain any identifying information after access to the material has been granted. A commercial entity found to have KNOWINGLY retained an individual's identifying information after access was granted is liable to that individual for damages resulting from the retention, including court costs and reasonable attorney's fees. Design consequence: an age-verification vendor integration that logs or warehouses ID images "for audit" converts a compliance control into a standing private-damages exposure. Note this is a strictly tighter rule than SB 540's § 39-5-6(j) 24-hour ceiling for AI age-assurance documents — where both apply, the § 39-5-5(d) "do not retain at all" rule governs the harmful-to-minors gate. (O.C.G.A. § 39-5-5(d).)

Deadline: July 1, 2025

O.C.G.A. § 39-5-5(d)(1)-(2) (SB 351, 2024)

Georgia breach notification — narrow "information broker / data collector" duty (O.C.G.A. § 10-1-910 et seq.)

High Priority

SCOPE BEFORE SUBSTANCE — this is one of the narrowest breach statutes in the United States and is routinely over-applied. It binds only an "information broker" (any person or entity who, FOR MONETARY FEES OR DUES, engages in whole or in part in the business of collecting, assembling, evaluating, compiling, reporting, transmitting, transferring or communicating information concerning individuals) and a "data collector" (a state or local agency or subdivision, including a department, bureau, authority, public university or college, academy, commission or other government entity). A Georgia SaaS, AI or professional-services company that merely holds its own customers' data — and is not in the business of furnishing information about individuals for a fee, and is not a government body — is generally OUT of scope, and should be told so rather than sold a notification programme it does not owe. WHERE IT APPLIES: on discovery or notification of a breach of the security of the system (unauthorized acquisition of electronic data compromising the security, confidentiality or integrity of personal information), notify any Georgia resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, in the most expedient time possible and without unreasonable delay, consistent with legitimate law-enforcement needs and with measures to determine the scope of the breach and restore the integrity, security and confidentiality of the system. If more than 10,000 Georgia residents must be notified at one time, also notify, without unreasonable delay, all nationwide consumer reporting agencies that compile and maintain files on consumers. HONEST ABSENCES (verified, not gaps in our research): the statute fixes NO numeric notification deadline, requires NO notice to the Attorney General, sets NO statutory penalty, and creates NO private right of action — which is precisely why a Georgia breach may never reach the AG at all.

O.C.G.A. §§ 10-1-911 (definitions), 10-1-912 (notification; 10,000-resident CRA notice)

Georgia Fair Business Practices Act — substantiate your AI claims (O.C.G.A. § 10-1-390 et seq.)

High Priority

Georgia has no comprehensive privacy law and no general AI-accuracy statute, so the Fair Business Practices Act of 1975 is the rail an AI vendor is realistically pursued under in Georgia today: it prohibits unfair or deceptive acts or practices in the conduct of consumer transactions and trade or commerce (§ 10-1-393). Concretely: do not claim accuracy, safety, clinical validity, human review, bias testing or "no hallucinations" beyond what you can evidence; do not describe automated output as human-reviewed unless it is; keep dated substantiation for every performance claim in marketing, sales decks and model cards; and align public claims with what your SB 540 / SB 444 / § 39-5-5 controls actually do. The Attorney General may investigate suspected violations, issue cease-and-desist orders and demand restitution to affected persons, generally after written notice (excepted where harm is imminent or the respondent is a flight risk).

O.C.G.A. §§ 10-1-393, 10-1-397, 10-1-399

Georgia SB 540 — age assurance for sexually-explicit features + parental tools

Medium Priority

Before allowing access to any feature/mode that may generate sexually-explicit synthetic content, use a commercially reasonable age-assurance method proportionate to the risk (age estimation, account-based assurance, or identity-based verification). Minimize collection/retention of age-assurance data, do not retain identity documents longer than reasonably necessary (in no event longer than 24 hours unless a longer period is permitted by law), use the data only for age verification, and do not sell it. For minor accounts, offer reasonable tools to the minor or parent to manage screen time, privacy, notifications/engagement features, safety settings, and to disable/restrict relationship-simulation features. (O.C.G.A. § 39-5-6(i)-(j)).

Deadline: July 1, 2027

O.C.G.A. § 39-5-6(i)-(j)

Georgia SB 351 — social media age verification + under-16 parental consent (PRELIMINARILY ENJOINED — track, do not build to yet)

Medium Priority

STATUS FIRST: these provisions are NOT currently enforceable. Judge Amy Totenberg (N.D. Ga.) preliminarily enjoined them on June 26, 2025, five days before their July 1, 2025 effective date, in NetChoice v. Carr; Georgia appealed to the Eleventh Circuit (No. 25-12436), which heard oral argument on March 10, 2026 with no ruling issued as of this verification. The injunction stands unless and until the Eleventh Circuit reverses. WHAT THEY REQUIRE IF REVIVED: a social media platform provider must make commercially reasonable efforts to verify account holders' ages with a level of certainty appropriate to the risks arising from its information management practices, or else apply the chapter's minor conditions to ALL account holders; must treat anyone verified as under 16 as a minor; must not permit a minor to hold an account without express parental or guardian consent obtained by one of six listed methods (signed form returned by carrier/fax/email/scan, toll-free call, videoconference, government-ID or payment-card check with deletion after confirmation, verified email response, or any other commercially reasonable method); must give a parent, on request, a list and description of the platform's censoring/moderating features and which can be disabled; and for minor accounts must prohibit personal-information-targeted advertising (age and location excepted) and any collection or use of personal information from the minor's posts, content, messages or usage beyond what is adequate, relevant and reasonably necessary for the disclosed purpose. Contractual waivers, including choice-of-law clauses, are void against this chapter. (O.C.G.A. §§ 39-6-2, 39-6-3, 39-6-5.) No deadline field is set on this requirement because the operative date never took effect and no new date exists — an honest absence, not an omission.

O.C.G.A. §§ 39-6-2, 39-6-3, 39-6-4, 39-6-5 (SB 351, 2024) — enjoined, NetChoice v. Carr (N.D. Ga.), on appeal 11th Cir. No. 25-12436

Who Does This Apply To?

Applies to operators of "AI companion chatbots" accessible to Georgia users under SB 540 — signed by Governor Brian Kemp on May 11, 2026, effective July 1, 2027, codified at O.C.G.A. § 39-5-6. SCOPE IS NARROW: an "AI companion chatbot" is a generative-AI system designed to simulate a sustained human-like (intimate, romantic, or platonic) relationship by retaining prior-session information to personalize engagement, asking unprompted emotion-based questions, and sustaining ongoing dialogue on matters personal to the user. Expressly OUT of scope: customer-service chatbots that do not sustain a relationship or elicit emotional attachment, internal-business GenAI, developer/research/enterprise-productivity tools, voice-command assistants, narrowly-tailored educational tools, and video-game/film/TV characters. In scope means: AI-identity disclosure at session start and at least every 3 hours (every 1 hour for minors); minor-safety + anti-manipulation measures; a 988-referring severe-harm/crisis protocol with public + annual-aggregate disclosure; no false "licensed professional" representations; minor/parental account-management tools; and commercially reasonable age assurance before sexually-explicit features. On platform scope: SB 540 does NOT exempt large operators merely for being large, but § 39-5-6(m)(2) does not impose liability on a hosting provider, app store, or search engine SOLELY for providing access to a companion chatbot absent direct operation/control — so a big-tech firm is in scope only where it actually operates a companion chatbot (e.g. Character.AI), not where it merely hosts or links to one. Enforced by the Georgia Attorney General — civil penalty up to $10,000 per knowing violation plus compensatory damages, costs/fees, and injunction; each day is a separate violation per user affected; discretionary 30-day cure for first-time non-knowing violations. Scope turns on operating an AI companion chatbot reachable by Georgians, not company size. — R510 (2026-08-25) SCOPE CORRECTIONS AND ADDITIONS, all read off the enrolled Act this session: (i) "Operator" is defined at § 39-5-6(a)(5) as a person that OWNS, CONTROLS, OR DEVELOPS AND MAKES AVAILABLE an AI companion chatbot to users in this state — i.e. the duty attaches to the party that puts the companion in front of Georgians. (ii) A SECOND carve-out sits alongside the access-provider one and was previously unrecorded here: § 39-5-6(m)(5) provides that nothing in the Code section shall be construed to create liability for the DEVELOPER of a conversational AI service which is made available to the public by a SEPARATE OPERATOR. So a foundation-model or SDK vendor whose model another company deploys as a companion is not thereby the regulated party; the deploying operator is. § 39-5-6(m)(1) likewise refuses to require disclosure of trade secrets or proprietary model weights, and (m)(4) refuses to authorize content moderation inconsistent with the state or federal constitution. (iii) PRECISION FIX to the customer-service exclusion: the statute reads that the term does not include "a customer-service chatbot that EITHER does not sustain a relationship across multiple interactions OR is not designed to elicit emotional attachment" (§ 39-5-6(a)(1)(B)(iii)) — the exclusion is DISJUNCTIVE, so satisfying either prong is enough. The prior wording here ("do not sustain a relationship or elicit emotional attachment") could be read to demand both and would over-apply the law to ordinary support bots. (iv) The video-game/audiovisual exclusions are conditional, not blanket: a non-player character is excluded only where it is restricted to the game's subject matter and is NOT capable of open-ended companionship or discussion of self-harm, suicide, or sexually explicit conduct (§ 39-5-6(a)(1)(B)(vi)-(vii)). — BEYOND SB 540, this entry now also scopes: private review agents and utilization review entities using AI in Georgia health-coverage decisions (O.C.G.A. § 33-46-7.1, from 1 Jan 2027); commercial entities whose Georgia-reachable public website carries more than 33.33% material harmful to minors (§ 39-5-5, in force since 1 Jul 2025, including the absolute bar on retaining age-verification identifiers); social media platform providers (§§ 39-6-1 to 39-6-5, preliminarily enjoined); information brokers and government data collectors for breach notification (§ 10-1-910 et seq. — NOT ordinary businesses holding their own customer data); and every business making AI claims to Georgia consumers under the Fair Business Practices Act (§ 10-1-390 et seq.). Georgia has NO comprehensive consumer-privacy statute, NO biometric-privacy act, NO election-deepfake statute and NO NAIC Model AI Bulletin adoption.

Recent Regulatory Guidance

guidance2026-05-11

Georgia SB 540 — governor-signed enrolled Act, O.C.G.A. § 39-5-6 (signed 11 May 2026; effective 1 Jul 2027)

The enacted text (LC 64 0123S) regulates "AI companion chatbots" — generative-AI systems designed to simulate a sustained human-like relationship. It requires AI-identity disclosure (session start + every 3 hours, every hour for minors), minor-safety + anti-manipulation measures, a severe-harm/crisis protocol referring users to the 988 Suicide and Crisis Lifeline with public + annual-aggregate disclosure, a ban on false "licensed professional" claims, minor/parental account tools, and commercially reasonable age assurance before sexually-explicit features (ID retention capped at 24 hours). Enforced by the Georgia Attorney General: civil penalty up to $10,000 per knowing violation plus compensatory damages, costs/fees, and injunction, with each day a separate violation per user affected and a discretionary 30-day cure for first-time non-knowing violations. The AG may promulgate implementing rules/guidance; none has been published yet.

guidance2026-05

Georgia SB 444 — AI may not alone deny care (ENACTED; new O.C.G.A. § 33-46-7.1, effective 1 Jan 2027)

Signed-legislation text (LC 46 1522S) read in full this session. It amends Chapter 46 of Title 33 (certification of private review agents) by adding § 33-46-7.1. Subsection (b) permits private review agents and utilization review entities to use AI systems, artificial intelligence or other software tools provided they are part of a utilization review plan meeting the chapter's standards and the Commissioner's rules. Subsection (c) permits such tools to automate tasks, reduce administrative burdens and participate in decision-making, but bars them from issuing an adverse determination to a patient until a natural person qualifying as a private review agent, or a utilization review entity, conducts a utilization review in which a clinical peer participates, and forbids the tools from superseding that clinical peer's judgment. Subsection (a) supplies two distinct definitions — "artificial intelligence" and the broader "artificial intelligence system". SECTION 2 sets the effective date at January 1, 2027. The Act contains NO penalty clause and NO member or provider disclosure duty; enforcement runs through Chapter 46 certification and the Commissioner of Insurance.

guidance2026-04-01

NAIC Model AI Bulletin implementation map — GEORGIA HAS NOT ADOPTED (verified negative, status as of 1 April 2026)

The NAIC Big Data and Artificial Intelligence (H) Working Group implementation map, read this session, shows 25 adopting jurisdictions and 4 with insurance-specific regulation or guidance. Georgia is shaded in NEITHER category — it appears grey, meaning no adoption of the Model Bulletin on the Use of Artificial Intelligence Systems by Insurers and no separate insurance AI guidance, and Georgia appears nowhere in the map's reference list of bulletins. Recorded as an HONEST NEGATIVE: a Georgia insurer has no NAIC-bulletin AI governance-framework expectation. Georgia legislated the narrower question directly instead, in SB 444. The same map confirms Indiana and Missouri are also non-adopters and that Wisconsin adopted on 18 March 2025. R519 UPDATE (2026-08-25): re-confirmed against the CURRENT copy of the map, headed "Status as of August 6, 2026" (content.naic.org/sites/default/files/legal-adoption-map-ai-model-bulletin.pdf). Its reference list is identical to the April 1 copy's — same 25 adopting jurisdictions, same 4 insurance-specific (CA, CO, NY, TX). Georgia remains absent from both lists. Negative stands, now current as of 2026-08-06.

guidance2026-01-28

Georgia has NO election-deepfake statute — SB 9 DIED (verified negative)

The brief for this round hypothesised an enacted Georgia election-deepfake law. There is none. SB 9 of the 2025-2026 regular session (the "Ensuring Accountability for Illegal AI Activities Act", Sen. John Albers), which would have criminalised publishing materially deceptive AI-generated audio or video within 90 days of an election, passed the House 152-12 but is recorded as Engrossed–DEAD after the Senate disagreed with the House substitute on 28 January 2026. A similar bill failed the year before over free-speech objections, and the ACLU of Georgia opposed the measure. DO NOT re-add an election-deepfake requirement for Georgia without a newly enacted Act.

guidance2026-04

Georgia 2026 session — what DIED: SB 398 (AI "virtual peeping"), SB 495 (Age Appropriate Design Code), SB 467 (app-store age verification)

Verified negatives from the ACLU of Georgia 2026 legislative report. SB 398 would have created a "virtual peeping" offence for using generative AI to make realistic images of real people without consent (reported proposed penalties up to 10 years and $50,000 for adult subjects, up to 20 years and $100,000 where the subject is a minor) — it did not pass. SB 495, an Age Appropriate Design Code Act aimed at design features such as autoplay and infinite scroll, did not pass. SB 467, requiring app-store age verification and parental consent for minors, did not pass. Of the session's AI and minors bills only SB 540 was signed. Do not model any of these three as law.

guidance2026-04-02

Georgia STILL has no comprehensive privacy law — SB 111 was gutted, not enacted (anti-fabrication warning)

A researcher checking only whether "SB 111" was signed will reach the wrong answer. The Senate-passed version of SB 111 carried the title "Georgia Consumer Privacy Protection Act", but the House replaced the bill's entire text with unrelated rural hospital tax credit provisions and the Senate agreed to that substitute on 2 April; the version ultimately signed has nothing to do with consumer privacy, and the House had already deleted the definitions of "biometric data", "controller", "consumer" and "consent". Georgia therefore has NO comprehensive consumer-privacy statute and NO biometric-privacy act, while Florida, Tennessee and Alabama in the same region do have omnibus laws. Georgia biometrics remain a WATCH-LIST item only.

guidance2024-04

Georgia AI-adjacent CRIMINAL rails (context, not a business compliance duty)

Two enacted criminal provisions touch synthetic media and matter where a product can generate imagery of real people. (1) O.C.G.A. § 16-11-90 (nude or sexually explicit electronic transmissions) reaches a "falsely created videographic or still image", which on its face captures deepfaked intimate imagery; penalties run from a misdemeanour of a high and aggravated nature for a first non-website offence up to a felony of 1-5 years and a fine of up to $100,000, and 2-5 years for repeat sexually-explicit-website offences. The text consulted was the codes.findlaw.com mirror stamped current as of 28 March 2024, law.justia.com being blocked this session. (2) SB 351 (2024) also rewrote the "child pornography" definition used in O.C.G.A. § 20-2-324 to cover a computer or computer generated image "created, adapted, or modified to appear that an identifiable minor is engaging in sexually explicit conduct" — read verbatim from the enrolled Act this session. A SEPARATE and widely repeated secondary claim, that 2024 HB 993 removed an AI-generation defence to Georgia's sexual-exploitation-of-children offences, was NOT primary-source verified this round and is recorded as unverified — do not cite it as established.

guidance2025-08-25

Georgia AG posture on AI — no Georgia AI enforcement action found; Georgia did NOT sign the August 2025 multistate AI child-safety letter

Searched this session for any Georgia Attorney General enforcement action, settlement or assurance with an AI dimension: none found, which is why enforcementActions on this entry remains deliberately empty. Two adjacent data points bearing on posture rather than obligation: the National Association of Attorneys General letter of 25 August 2025 to Meta, Google, Apple, Microsoft, OpenAI, Anthropic, Perplexity AI and xAI urging child-safety safeguards in chatbots was signed by 44 states and territories, and GEORGIA IS NOT AMONG THE SIGNATORIES. A later multistate letter of 9 December 2025 to thirteen generative-AI companies, setting out sixteen requested safeguards with a 16 January 2026 response date, is reported as carrying 42 signatories, but that signatory list could not be confirmed from a primary source this session — Georgia's participation in it is UNKNOWN, not denied. Georgia's live AG activity in this space is instead its defence of SB 351 in NetChoice v. Carr.

Key Case Law & Precedent

Garcia v. Character Technologies, Inc. (M.D. Fla. 2024)

US District Court, Middle District of Florida · 2024

Wrongful-death case alleging Character.AI's chatbot contributed to a 14-year-old's suicide. Cited extensively in Georgia SB 540's legislative findings as the leading case demonstrating why minor-safety chatbot regulation is necessary. The bill's minor-protection provisions were drafted in direct response to the conduct alleged in Garcia.

Outcome: Settled in principle 2026-01-07 (with 4 related family suits in CO/NY/TX); financial terms not disclosed; Character.AI/Google committed to additional under-18 safety features. (Cycle 8, 2026-08-22: corrected from a stale "litigation active" claim already identified and fixed in nebraska_lb525 by Cycle 6 but left unfixed here — same fabrication surviving in a sibling jurisdiction entry.)

Case reference

NetChoice v. Carr (N.D. Ga.; appeal 11th Cir. No. 25-12436)

US District Court, Northern District of Georgia (Judge Amy Totenberg); on appeal to the US Court of Appeals for the Eleventh Circuit · 2025

Constitutional challenge to the social media provisions of Georgia SB 351 (2024), codified at O.C.G.A. §§ 39-6-1 to 39-6-5 — age verification of account holders and parental consent for users under 16, enforced exclusively by the Attorney General. This case determines whether the social-media half of SB 351 is ever enforceable. The age-verification half covering sites with a substantial portion of material harmful to minors (§ 39-5-5) was NOT enjoined and is in force. Directly relevant to any age-assurance design decision a Georgia-facing operator makes ahead of SB 540's 2027 duties.

Outcome: Preliminary injunction GRANTED 26 June 2025, five days before the law's 1 July 2025 effective date, the court finding the law erected barriers to speech that could not survive the applicable scrutiny. Georgia appealed; the Eleventh Circuit heard oral argument on 10 March 2026 and, as verified on 2026-08-25, no merits ruling had issued. The injunction remains in force, so §§ 39-6-1 to 39-6-5 are not currently enforceable. STATUS IS PERISHABLE — re-verify before relying on it.

Case reference

Industry Playbooks covering Georgia — AI, Age-Verification & Consumer-Protection Stack (SB 540 AI companion chatbots O.C.G.A. § 39-5-6 · SB 444 AI in health-plan utilization review § 33-46-7.1 · SB 351 age verification §§ 39-5-5 / 39-6-1 et seq. · breach notification § 10-1-910 et seq. · FBPA § 10-1-390 et seq.)

These industry playbooks include jurisdiction-specific checklist items and guidance for Georgia — AI, Age-Verification & Consumer-Protection Stack (SB 540 AI companion chatbots O.C.G.A. § 39-5-6 · SB 444 AI in health-plan utilization review § 33-46-7.1 · SB 351 age verification §§ 39-5-5 / 39-6-1 et seq. · breach notification § 10-1-910 et seq. · FBPA § 10-1-390 et seq.).

Frequently Asked Questions

Does Georgia — AI, Age-Verification & Consumer-Protection Stack (SB 540 AI companion chatbots O.C.G.A. § 39-5-6 · SB 444 AI in health-plan utilization review § 33-46-7.1 · SB 351 age verification §§ 39-5-5 / 39-6-1 et seq. · breach notification § 10-1-910 et seq. · FBPA § 10-1-390 et seq.) apply to my business?

GEORGIA MULTI-SURFACE ENTRY (R510, 2026-08-25 — was single-surface/chatbot-only). Georgia has NO comprehensive consumer-privacy law, NO biometric-privacy act, and NO election-deepfake statute (all verified negatives, see recentGuidance), but it does… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Georgia — AI, Age-Verification & Consumer-Protection Stack (SB 540 AI companion chatbots O.C.G.A. § 39-5-6 · SB 444 AI in health-plan utilization review § 33-46-7.1 · SB 351 age verification §§ 39-5-5 / 39-6-1 et seq. · breach notification § 10-1-910 et seq. · FBPA § 10-1-390 et seq.) is: ACROSS THE GEORGIA SURFACES (R510): § 39-5-5 age verification — fine up to $10,000.00 per violation, set by the superior court of the county where an affected minor resides, instituted by the Attorney General, solicitor general or district attorney within ONE YEAR of the violation, and NOT preclusive of any other right of action; plus liability to an individual for damages (with court costs and attorney's fees) both for a minor's access and, separately, for knowingly retaining age-verification identifying information. §§ 39-6-1 to 39-6-5 social media — AG has EXCLUSIVE enforcement, expressly NO private right of action, damages up to $2,500.00 per violation, mandatory 90-day written cure notice before the AG may initiate an action (currently unenforceable — preliminarily enjoined). SB 444 / § 33-46-7.1 — the Act itself prescribes NO penalty; consequences run through Chapter 46 certification (the Commissioner of Insurance may refuse, suspend or revoke a private review agent's certificate, and a non-compliant certified agent is subject to the fines and penalties applicable to licensed insurers generally, per Ga. Comp. R. & Regs. 120-2-58). Fair Business Practices Act — up to $2,000.00 per willful violation by AG administrative order and up to $5,000.00 per violation imposed by a superior court (§ 10-1-397), plus AG restitution and cease-and-desist orders and a private action with exemplary damages for intentional violations (§ 10-1-399). Breach notification (§ 10-1-910 et seq.) — NO statutory penalty and NO private right of action (honest absence, verified, not an omission). SB 540: Georgia AG enforcement under O.C.G.A. § 39-5-6(k): civil penalty up to $10,000 per knowing violation, PLUS compensatory damages, costs and reasonable attorney's fees, and an order to enjoin the violation; each day in violation is a separate violation for each user affected. Discretionary 30-day cure for a first-time, non-knowing violation not involving sexual exploitation of a minor or self-harm. (Primary-source confirmed against the governor-signed enrolled Act 2026-06-13 — RQ-51 resolved; the prior "up to $10,000 per knowing violation" figure was correct but materially incomplete.). Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Georgia — AI, Age-Verification & Consumer-Protection Stack (SB 540 AI companion chatbots O.C.G.A. § 39-5-6 · SB 444 AI in health-plan utilization review § 33-46-7.1 · SB 351 age verification §§ 39-5-5 / 39-6-1 et seq. · breach notification § 10-1-910 et seq. · FBPA § 10-1-390 et seq.)?

The 11 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://gov.georgia.gov/document/2026-signed-legislation/sb-540/download

Last updated: 2026-08-25 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan