Skip to content
US-OHMEDIUM coverage1 enforcement action

Ohio — State Law (Social Media Parental Notification Act, Data Protection Act safe harbour, School AI Policy Mandate, OCSPA) + Federal AI Compliance Profile: AI Compliance Requirements

Ohio has NO comprehensive AI statute and NO comprehensive consumer-privacy statute as of 2026-08-25 — both negatives re-verified this round (the Ohio Personal Privacy Act, HB 345 of the 135th GA, was referred to Government Oversight 2023-12-06 and died there; it has not been re-enacted). But "no AI law" is NOT the same as "no state law": Ohio binds private business through four distinct enacted surfaces modelled in this entry. (1) The Parental Notification by Social Media Operators Act, H.B. 33 of the 135th GA, codified at ORC § 1349.09 — verifiable parental consent for under-16 account creation, with AG-exclusive civil penalties escalating to $10,000/day. Its litigation posture is decisive and is stated exactly below: the S.D. Ohio permanently enjoined it 2025-04-16; the Sixth Circuit REVERSED and remanded with instructions to enter judgment for the State on 2026-06-18 (NetChoice, LLC v. Yost, No. 25-3371); the court then STAYED ITS MANDATE on 2026-08-17 while NetChoice seeks Supreme Court review, so the Act is NOT presently enforceable but is one denial of certiorari away from being so. (2) The Ohio Data Protection Act, ORC §§ 1354.01-1354.05 (eff. 2018-11-02) — a voluntary written-cybersecurity-program safe harbour that yields an affirmative defence to Ohio tort claims alleging a breach was caused by unreasonable security; note that the qualifying framework list at § 1354.03 does NOT include the NIST AI RMF, so AI-specific governance alone does not earn the defence. (3) ORC § 3301.24 (Am. Sub. H.B. 96, 136th GA) — the first-in-the-nation STATUTORY duty for every Ohio school district, community (charter) school and STEM school to adopt an AI-use policy, deadline 2026-07-01 (now passed). (4) ORC §§ 1349.19/1349.192 breach notification (45 days) and the Ohio Consumer Sales Practices Act, ORC § 1345.02, enforced by the AG under § 1345.07 — the operative hook for AI-generated deception, chatbots that conceal their nature, and unverifiable AI marketing claims. PENDING, not law: SB 163 (AI-generated CSAM, watermarking, AI voice/likeness identity fraud) passed the Senate unanimously 2026-05-20 and sits in House Technology and Innovation (referred 2026-05-27) with no reported House hearing in the three months since — HIGH-PRIORITY WATCH, still not enacted; HB 469 (declare AI nonsentient, bar AI legal personhood, introduced 2025-09-23, referred to the same committee 2025-10-01) also remains in committee. Ohio's AG is Andy Wilson, sworn in as the state's 52nd Attorney General on 2026-06-08 after Dave Yost resigned; the Yost-era case caption survives on the pending Supreme Court petition. Federal law supplies the rest of the AI perimeter: FTC Act § 5, Title VII / ADA, FCRA, HIPAA, COPPA — material given Ohio's manufacturing (Honda, GM, Ford, P&G), financial-services (Nationwide, Progressive, Huntington, KeyBank) and healthcare (Cleveland Clinic, OhioHealth, University Hospitals) concentrations.

Summary of publicly-available regulatory text as of 2026-08-25. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

November 2, 2018

Maximum Penalty

Ohio state exposure (not zero — the prior "No state AI penalty" framing understated it): ORC § 1349.09(I) social-media operator penalties escalate up to $1,000/day (days 1-60), up to $5,000/day (days 61-90), up to $10,000/day (day 91+), AG-exclusive — currently unenforceable only because the Sixth Circuit stayed its mandate 2026-08-17. ORC § 1349.192 breach-notification penalties run on the identical $1,000/$5,000/$10,000-per-day escalator for intentional or reckless non-compliance. OCSPA: up to $5,000 per day of violation under ORC § 1345.07(A)(2)(b)(i), $5,000-$15,000 per day where the violation is of § 1345.02 or § 1349.81, and up to $25,000 under § 1345.07(D) where a prior court determination or a pre-existing AG rule made the conduct deceptive. Federal: FTC up to $53,088 per violation of a final order or rule (16 CFR Part 1, 2025 figure); HIPAA up to $2,190,294 per violation category per calendar year.

What Your Business Must Do

10 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

ORC § 1349.09 — Parental Notification by Social Media Operators Act (verifiable parental consent for under-16 accounts)

Critical

Ohio's Parental Notification by Social Media Operators Act (H.B. 33, 135th Gen. Assemb. (2023), codified at ORC § 1349.09) obliges an "operator" — any business running an online platform reaching Ohio users that permits social interaction, profile creation, connection lists and user-generated content — to do five things before a child under 16 may create an account: (1) obtain VERIFIABLE parental consent by one of the enumerated methods (signed form returned by mail, fax or scanned e-mail; a payment-card transaction; a toll-free verification call; videoconference identity verification; or a government-ID database check); (2) disclose the content-moderation features the platform offers; (3) provide a durable, accessible link at which a parent can review those moderation features later; (4) send the parent written confirmation of consent by e-mail, mail or fax, or by telephone where no such contact detail is available; and (5) DENY access where the parent refuses. THE LITIGATION POSTURE IS THE WHOLE ANSWER AND IS STATED PRECISELY: the Southern District of Ohio entered final judgment for NetChoice and permanently enjoined the Act on 2025-04-16 (No. 2:24-cv-00047, Marbley, J.); on 2026-06-18 the Sixth Circuit, in NetChoice, LLC v. Yost, No. 25-3371, held that "NetChoice has failed to establish that the Act is facially unconstitutional", REVERSED the district court's judgment and REMANDED "with instructions to enter judgment in favor of Yost" (Clay, J., lead opinion; Batchelder, J., concurring in the judgment; Ritz, J., dissenting; argued 2026-02-04); NetChoice petitioned for rehearing en banc on 2026-07-16 and the petition was declined; and on 2026-08-17 the Sixth Circuit STAYED ITS MANDATE, which leaves the district court's permanent injunction operative while NetChoice seeks Supreme Court review. NET EFFECT FOR A Ohio-facing operator as of 2026-08-25: the Act is NOT currently enforceable, but the controlling appellate holding is now AGAINST the platforms, so the consent, disclosure and confirmation workflow should be built and held ready rather than deferred — if certiorari is denied the mandate issues and the escalating per-day penalties begin running with no grace period written into the statute.

ORC § 1349.09 (H.B. 33, 135th Gen. Assemb. (2023)); operator definition at § 1349.09(A); consent, disclosure and confirmation duties at § 1349.09(B); AG enforcement and civil penalties at § 1349.09(I). Litigation: NetChoice, LLC v. Yost, No. 25-3371 (6th Cir. June 18, 2026), rev'g and remanding No. 2:24-cv-00047 (S.D. Ohio Apr. 16, 2025); mandate stayed Aug. 17, 2026.

FTC Act § 5 + OCSPA — Deceptive or Unfair AI Practices

High Priority

FTC Act § 5 applies to all Ohio businesses using AI. Ohio Consumer Sales Practices Act (OCSPA, ORC § 1345.02) independently prohibits unfair or deceptive acts in consumer transactions — Ohio courts have applied OCSPA to algorithmic deception. The Ohio AG (Andy Wilson since June 7, 2026; Dave Yost previously) has been active in AI consumer protection enforcement. Ensure AI chatbots disclose their nature, AI claims are truthful, and AI pricing does not exploit consumers.

15 U.S.C. § 45(a) (unfair/deceptive practices); civil-penalty authority § 45(l), § 45(m)(1)(A); ORC § 1345.02 (OCSPA); AG remedies and penalties at ORC § 1345.07(A)(2)(b)(i)-(ii), § 1345.07(D), limitations at § 1345.07(E)

EEOC / Title VII / ADA — AI Employment Screening in Manufacturing

High Priority

Ohio's large manufacturing sector (Honda, GM, Ford, P&G) and logistics companies use AI for hiring, scheduling, and worker monitoring. EEOC May 2023 guidance requires employers to test AI employment tools for disparate impact. The Ohio Civil Rights Act independently prohibits AI that discriminates in employment, and — unlike Illinois, Maryland, New York City or Colorado — Ohio has enacted NO AI-specific hiring statute, NO automated-employment-decision audit duty, and NO biometric-privacy statute, so the ONLY Ohio-law route to an AI hiring claim is ordinary ORC Chapter 4112 discrimination doctrine. Since H.B. 352 of the 133rd GA (eff. 2021-04-15) an aggrieved employee must first file a charge with the Ohio Civil Rights Commission and has TWO YEARS from the alleged unlawful discriminatory practice to do so (ORC §§ 4112.051, 4112.052) — the practical retention horizon for AI screening logs, model versions, scoring outputs and disparate-impact test results.

Title VII, 42 U.S.C. § 2000e-2; ADA, 42 U.S.C. § 12112; damages caps at 42 U.S.C. § 1981a(b)(3); Ohio Civil Rights Act, ORC Chapter 4112; charge-filing and civil-action deadlines at ORC §§ 4112.051, 4112.052 (H.B. 352, 133rd GA, eff. 2021-04-15)

FCRA / CFPB + Ohio DOI — AI in Financial Services and Insurance

High Priority

Ohio's large financial services sector (Nationwide, Progressive, Huntington, KeyBank) uses extensive AI. AI credit decisions must comply with FCRA adverse action notice requirements. IMPORTANT NEGATIVE for insurers: Ohio is one of the states that has NOT adopted the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers and has issued no equivalent AI-specific insurance guidance — so an Ohio-domiciled insurer has NO state AI-governance-programme filing or documentation mandate, and the applicable duties are the generic ones (unfair trade practices, rate filing, market-conduct examination) plus federal law. Insurers operating in Ohio AND in adopting states (Pennsylvania, Illinois, Kentucky, Michigan, West Virginia and 20 other jurisdictions) will still be held to the NAIC bulletin by those regulators, so the practical answer is to run one AI governance programme to the NAIC standard rather than an Ohio-specific carve-out.

15 U.S.C. § 1681b(b)(3) (adverse action notice); §§ 1681n, 1681o (civil liability); CFPB Circular 2022-03. NOTE: no Ohio Revised Code or Ohio Administrative Code AI-in-insurance provision is cited because none was found to exist.

ORC §§ 1354.01-1354.05 — Ohio Data Protection Act cybersecurity safe harbour (affirmative defence for AI data pipelines)

High Priority

The Ohio Data Protection Act (eff. 2018-11-02) is voluntary but is the single most valuable Ohio-law instrument available to a business deploying AI over personal data, because it converts a written security programme into a pleadable defence. Under ORC § 1354.02(A) a covered entity — defined at § 1354.01(B) as "a business that accesses, maintains, communicates, or processes personal information or restricted information" — must create, maintain and comply with a WRITTEN cybersecurity programme containing administrative, technical and physical safeguards that reasonably conforms to a framework named in § 1354.03, covering either personal information alone (§ 1354.02(A)(1)) or personal information AND restricted information (§ 1354.02(A)(2)). Section 1354.02(B) requires the programme to be designed to (1) protect the security and confidentiality of the information, (2) protect against anticipated threats or hazards to its security or integrity, and (3) protect against unauthorised access and acquisition likely to result in a material risk of identity theft or other fraud. Section 1354.02(C) makes scale and scope adequate if calibrated to five factors: the entity's size and complexity, the nature and scope of its activities, the sensitivity of the information, the cost and availability of security tools, and the resources available to it. Section 1354.02(D) then grants the payoff — an affirmative defence to any tort cause of action brought under Ohio law or in Ohio courts alleging that a failure to implement reasonable information security controls resulted in a data breach; the § 1354.02(A)(2) route extends that defence to breaches of restricted information (defined at § 1354.01(E) as unencrypted, unredacted information other than personal information that alone or in combination can distinguish or trace an individual's identity). Qualifying frameworks under § 1354.03(A)(1) are the NIST "Framework for improving critical infrastructure cybersecurity", NIST SP 800-171, NIST SP 800-53 and 800-53a, the FedRAMP security assessment framework, the CIS Critical Security Controls, and the ISO/IEC 27000 family; § 1354.03(B)(1) lets a regulated entity instead conform to the HIPAA Security Rule (45 CFR Part 164 Subpart C), GLBA Title V, FISMA 2014, or HITECH (45 CFR Part 162); and § 1354.03(C) requires an entity subject to PCI DSS to comply with the current PCI DSS PLUS one framework from division (A). TWO TRAPS FOR AI DEPLOYERS. First, the § 1354.03 list is CLOSED and does NOT include the NIST AI Risk Management Framework, ISO/IEC 42001, or any AI-specific standard — running an AI governance programme, however good, earns no Ohio safe harbour on its own; the AI data pipeline must sit inside a conforming SECURITY programme. Second, the defence is an affirmative one, so it must be pleaded and proved, which means the written programme, its framework mapping, and evidence of actual compliance must exist BEFORE the breach and be producible afterwards.

Deadline: February 26, 2025

ORC § 1354.01(B) (covered entity), (C) (data breach), (E) (restricted information); § 1354.02(A)(1)-(2), (B)(1)-(3), (C)(1)-(5), (D)(1)-(2); § 1354.03(A)(1)(a)-(f), (B)(1)(a)-(d), (C), (D)

ORC §§ 1349.19, 1349.192 — 45-day breach notification and escalating AG civil penalties

High Priority

Any person that owns or licenses computerised data including personal information about an Ohio resident must disclose a breach of the security of the system "in the most expedient time possible but not later than forty-five days following its discovery or notification of the breach" (ORC § 1349.19). A processor or custodian that merely stores data on another entity's behalf must instead notify that entity. "Personal information" is an individual's name in combination with a Social Security number, a driver's licence or state ID number, or an account/credit-card number together with the security code — and only where the data is unencrypted, unredacted and otherwise readable. Substitute notice is available where notification cost exceeds $250,000 or more than 500,000 residents are affected (e-mail plus website posting plus major statewide media reaching 75% of the population); an entity with TEN OR FEWER employees may use substitute notice at a $10,000 cost threshold, via a quarter-page-minimum newspaper advertisement run three consecutive weeks, website posting and local media. WHY THIS IS AN AI REQUIREMENT AND NOT MERELY A SECURITY ONE: an AI deployment materially widens the breach surface — training corpora and embedding stores that replicate identifiers outside the system of record, prompt and completion logs that capture identifiers pasted by staff, vector databases that are rarely inside the encryption perimeter, and third-party model APIs that create a custodian relationship triggering the notify-the-controller duty. The 45-day clock runs from DISCOVERY, so an AI data map that cannot answer "which stores hold identifiers" within days effectively consumes the notification window.

ORC § 1349.19 (definitions, 45-day notification duty, substitute-notice thresholds); ORC § 1349.192 (Attorney General exclusive civil action and penalty tiers, covering violations of § 1347.12 or § 1349.19)

HIPAA — AI in Ohio Healthcare Systems

Medium Priority

Ohio has world-class healthcare AI deployers (Cleveland Clinic, OhioHealth, University Hospitals). AI systems processing Protected Health Information must comply with HIPAA Security and Privacy Rules. Cleveland Clinic's AI diagnostic programs are under FDA scrutiny — Ohio healthcare AI companies should implement equivalent governance standards including BAAs with AI vendors.

45 CFR Parts 160, 164 (HIPAA); civil penalty tiers at 45 CFR § 160.404

ORC § 3301.24 — mandatory AI-use policy for Ohio districts, community (charter) schools and STEM schools

Medium Priority

Enacted by Am. Sub. H.B. 96 of the 136th General Assembly (the FY2026-27 operating budget, effective 2025-09-30), ORC § 3301.24 makes Ohio the first state to convert AI guidance for schools from a recommendation into a STATUTORY DUTY. Every Ohio school district, community (charter) school and STEM school board had to ADOPT a policy governing the use of artificial intelligence by students and staff for educational purposes by 2026-07-01 — a date now past. The Ohio Department of Education and Workforce was separately required to publish a model AI policy by 2025-12-31 and released it in early January 2026. The statute mandates that a policy EXIST; it does not prescribe the policy's contents, does not require AI to be taught, and does not require AI tools to be used in classrooms, so a board may adopt the ODEW model verbatim and be compliant. COMMERCIAL RELEVANCE, which is why this sits in a business-compliance registry rather than only an education one: community schools and STEM schools are governed by independent, frequently privately-managed boards and operators, so this is a duty falling on non-governmental entities; and any vendor selling AI tutoring, proctoring, grading, attendance-analytics or chat products into Ohio K-12 will now be asked to map its product against an adopted local policy as a condition of procurement. A vendor with no answer to "how does your product fit our § 3301.24 policy" is at a live disadvantage in every Ohio K-12 deal.

Deadline: July 1, 2026

ORC § 3301.24, enacted by Am. Sub. H.B. 96, 136th Gen. Assemb. (eff. 2025-09-30); ODEW model AI policy published pursuant to the same section

Ohio Rules of Professional Conduct — AI competence, confidentiality and candour for Ohio law firms

Medium Priority

Ohio has produced binding-adjacent AI expectations for one regulated profession ahead of any general AI statute. The Ohio Board of Professional Conduct issued Informal Advisory Opinion 2024-01 in June 2024, reading generative AI through the existing Ohio Rules of Professional Conduct and confirming that a lawyer using AI must maintain competence under Rule 1.1, which includes understanding the capabilities AND the limitations of the tools used. On 2026-06-02 the Supreme Court of Ohio, through the Board, issued the "Ohio Ethics Guide on Artificial Intelligence for Lawyers and Judicial Officers" — non-binding guidance grounded in the Ohio Rules of Professional Conduct and the Ohio Code of Judicial Conduct. It addresses generative-AI hallucinations (noting lawyers in other jurisdictions have been sanctioned or disciplined for fictitious citations in filings), the risk that disclosing client material to unsecured or public AI platforms breaches confidentiality or waives privilege, and the duty of candour where Ohio courts require disclosure of AI use in filings. This is not theoretical in Ohio: the Office of Disciplinary Counsel has filed a complaint with the Board against a Cleveland-area attorney over AI tools that generated false statements. Practical controls for an Ohio firm: an enterprise AI tool with contractual no-training and confidentiality terms, a mandatory citation-verification step before any filing, per-matter client disclosure where required, and a record of which tool touched which matter.

Ohio Rules of Professional Conduct 1.1 (competence), 1.6 (confidentiality), 3.3 (candour toward the tribunal), 5.1/5.3 (supervision); Ohio Board of Professional Conduct Informal Advisory Opinion 2024-01 (June 2024); Ohio Ethics Guide on Artificial Intelligence for Lawyers and Judicial Officers (2026-06-02); Ohio Code of Judicial Conduct for judicial officers

Ohio AI legislative watch list — SB 163 and HB 469 (both PENDING, neither enacted)

Lower Priority

Two Ohio AI bills are live and BOTH sit in the House Technology and Innovation Committee; neither is law, and nothing in this entry treats either as law. (1) SB 163 (136th GA) — a three-part bill criminalising AI-generated child sexual abuse material, requiring AI systems to embed a distinctive watermark in AI-generated content, and extending identity-fraud law to the unauthorised use of a "replica of a person" (AI voice or likeness) with civil remedies; reporting indicates the Attorney General could seek a civil penalty of up to $10,000 where a violator removes an AI watermark. It passed the Senate unanimously on 2026-05-20 and was referred to House Technology and Innovation on 2026-05-27; no House committee hearing, House floor vote or gubernatorial signature has been reported in the three months since, and the absence of any hearing is itself the signal to watch. NOTE ON AN UNRESOLVED CONFLICT, carried forward deliberately: secondary sources disagree on the felony grading of the CSAM provision (second degree versus third degree). The Legislative Service Commission's as-passed-by-the-Senate text was not retrievable this session, so the grading is left UNSTATED rather than resolved by picking the more common secondary account — the bill is not law either way. (2) HB 469 (136th GA, Rep. Thaddeus Claggett) — would declare AI systems nonsentient, bar them from obtaining legal personhood, marrying, owning property or serving as an officer, director or manager of a legal entity, and would assign liability for AI-caused harm to the human owner, user, developer or manufacturer. Introduced 2025-09-23, referred to House Technology and Innovation 2025-10-01, still in committee. The prior versions of this requirement asserted that "Ohio is one of the most likely states to enact comprehensive AI regulation" and that the "Ohio AG has expressed clear intent to pursue AI enforcement actions" — both were unsourced forecasts and are removed; the contemporaneous reporting actually available points the other way, with the Ohio Capital Journal running the headline "Why Ohio doesn't have any artificial intelligence regulations" on 2026-05-18 and Ohio legislators quoted saying they are unsure what they would be able to enforce. Monitor legislature.ohio.gov and ohiohouse.gov; both refused TCP connections during parts of this session, so allow for fallback to Legislative Service Commission daily reports and LegiScan.

Recent Enforcement Actions

2025-09-25Source verified· as of 2026-08-25

Against:

Recent Regulatory Guidance

guidance2026-06-02

Supreme Court of Ohio / Board of Professional Conduct — Ohio Ethics Guide on Artificial Intelligence for Lawyers and Judicial Officers

Non-binding ethics guidance issued through the Ohio Board of Professional Conduct, grounded in the Ohio Rules of Professional Conduct and the Ohio Code of Judicial Conduct. Covers generative-AI hallucinations (noting lawyers elsewhere have been court-sanctioned or disciplined for fictitious citations in filings), the confidentiality and privilege-waiver risk of putting client material into unsecured or public AI platforms, and the duty of candour where Ohio courts require disclosure of AI use in filings. It supersedes nothing but builds on the Board's Informal Advisory Opinion 2024-01. Ohio's Office of Disciplinary Counsel has separately filed a Board complaint against a Cleveland-area attorney over AI-generated false statements, so this is an enforced area, not a theoretical one.

Source
opinion2024-06

Ohio Board of Professional Conduct — Informal Advisory Opinion 2024-01 (generative AI and the Rules of Professional Conduct)

Reads generative AI through the existing Ohio Rules of Professional Conduct and confirms that an attorney using AI must maintain competence under Rule 1.1, which includes understanding both the capabilities and the limitations of the AI tools employed. Day-level date not asserted: sources place it in June 2024 without a specific day, and inventing one would be fabrication.

Source
guidance2026-01-05

Ohio Department of Administrative Services — Administrative Policy IT-17, "Use of Artificial Intelligence in State of Ohio Solutions"

Effective 2026-01-05, issued by DAS Director Kathleen C. Madden. Sets statewide planning, implementation, procurement, security, privacy and governance requirements for AI, built on five principles — Fair, Accountable, Secure and Safe, Explainable and Transparent, Human-Centric and Socially Beneficial — and stands up a multi-agency AI Council that runs an AI sandbox, audits AI solutions and sets legal requirements for THIRD-PARTY AI SERVICES. SCOPE, stated precisely: it binds state agencies, boards and commissions under the authority of the Governor, NOT private business generally. Its commercial significance is procurement — a vendor selling AI into Ohio state government inherits IT-17 terms through contract. ACCESS NOTE: das.ohio.gov/technology-and-strategy/policies/it-17 returned HTTP 404 on direct fetch this session, so the policy text itself was not read; the effective date, issuer, scope and principle set come from the Center for Community Solutions summary and search-result metadata, and no clause-level requirement is quoted or paraphrased as if verified.

Source

Key Case Law & Precedent

NetChoice, LLC v. Yost, No. 25-3371

United States Court of Appeals for the Sixth Circuit · 2026

The controlling authority on whether Ohio's Parental Notification by Social Media Operators Act (ORC § 1349.09) may be enforced against online platforms — the single largest Ohio-law exposure for any consumer-facing product, AI or otherwise, with users under 16.

Outcome: Argued 2026-02-04, decided and filed 2026-06-18. Reviewing the Southern District of Ohio's final order and judgment in No. 2:24-cv-00047 (Marbley, J.), which had declared the Act unconstitutional and permanently enjoined it on 2025-04-16, the panel held that "NetChoice has failed to establish that the Act is facially unconstitutional", REVERSED the district court's judgment and REMANDED "with instructions to enter judgment in favor of Yost". Clay, J. announced the judgment and delivered the lead opinion; Batchelder, J. concurred in the judgment in a separate opinion; Ritz, J. dissented. NetChoice petitioned for rehearing en banc on 2026-07-16 and the petition was declined; on 2026-08-17 the court granted NetChoice's motion to STAY THE MANDATE pending a petition for certiorari, which leaves the district court's permanent injunction in effect and the Act unenforceable for now. TWO SOURCING NOTES, recorded rather than smoothed over: (a) the disposition language above is quoted from the slip opinion itself (File Name 26a0177p.06), read this session; (b) NetChoice's own case page describes the ruling as "vacating the preliminary injunction", which is inaccurate — the opinion reverses a FINAL judgment and permanent injunction — and the 2026-07-16 en banc filing, its denial, and the 2026-08-17 stay of the mandate rest on that same NetChoice page, a party-published source, because the Sixth Circuit docket was not independently reachable this session.

Case reference

Frequently Asked Questions

Does Ohio — State Law (Social Media Parental Notification Act, Data Protection Act safe harbour, School AI Policy Mandate, OCSPA) + Federal AI Compliance Profile apply to my business?

Ohio has NO comprehensive AI statute and NO comprehensive consumer-privacy statute as of 2026-08-25 — both negatives re-verified this round (the Ohio Personal Privacy Act, HB 345 of the 135th GA, was referred to Government Oversight 2023-12-06 and… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Ohio — State Law (Social Media Parental Notification Act, Data Protection Act safe harbour, School AI Policy Mandate, OCSPA) + Federal AI Compliance Profile is: Ohio state exposure (not zero — the prior "No state AI penalty" framing understated it): ORC § 1349.09(I) social-media operator penalties escalate up to $1,000/day (days 1-60), up to $5,000/day (days 61-90), up to $10,000/day (day 91+), AG-exclusive — currently unenforceable only because the Sixth Circuit stayed its mandate 2026-08-17. ORC § 1349.192 breach-notification penalties run on the identical $1,000/$5,000/$10,000-per-day escalator for intentional or reckless non-compliance. OCSPA: up to $5,000 per day of violation under ORC § 1345.07(A)(2)(b)(i), $5,000-$15,000 per day where the violation is of § 1345.02 or § 1349.81, and up to $25,000 under § 1345.07(D) where a prior court determination or a pre-existing AG rule made the conduct deceptive. Federal: FTC up to $53,088 per violation of a final order or rule (16 CFR Part 1, 2025 figure); HIPAA up to $2,190,294 per violation category per calendar year.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Ohio — State Law (Social Media Parental Notification Act, Data Protection Act safe harbour, School AI Policy Mandate, OCSPA) + Federal AI Compliance Profile?

The 10 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://ohioattorneygeneral.gov

Last updated: 2026-08-25 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan