Skip to content
US-MAFEDERAL profile2 enforcement actions

Massachusetts — Ch. 93A + AG AI Advisory, 201 CMR 17.00 WISP, c. 93H Breach, c. 272 §99 Wiretap, Ch. 118/2024 Deepfake NCII, Insurance AI (DOI Bulletin 2024-10; utilization review, c. 176O §12) + Federal AI Profile: AI Compliance Requirements

Massachusetts has no comprehensive AI statute and no enacted election-deepfake, chatbot-disclosure, employment-AI, or healthcare-AI law as of June 2026, but it has enacted one AI-specific binding provision: Chapter 118 of the Acts of 2024 ("An Act to Prevent Abuse and Exploitation," H.4744; signed by Gov. Maura Healey June 20, 2024; effective Sept 18, 2024; CYCLE 4 2026-08-22 CORRECTION — previously mis-cited as "Chapter 178," a digit-transposition error). It criminalizes nonconsensual sharing of sexually explicit images and expressly extends to "digitization" — computer-generated/AI-altered images that falsely appear to depict a real person in a sexually explicit manner (deepfake nudes); enforced criminally by district attorneys / the AG, punishable by up to 2.5 years in a house of correction, a fine up to $10,000, or both. Separately, AG Andrea Campbell's April 16, 2024 AI Advisory is guidance (existing Chapter 93A consumer-protection, anti-discrimination, and Chapter 93H data-security law applies to AI), not a new statute. Massachusetts remains among the most active US states for AI and privacy legislation, but ROUND 507 (2026-08-25) re-verified every pending item and NONE is enacted: the comprehensive privacy bill exists in two unreconciled versions — S.2608/S.2619 (Massachusetts Data Privacy Act, passed the Senate 40-0 on Sept 25, 2025, proposed effective Jan 1, 2027) and H.5479 (Massachusetts Consumer Data Privacy Act, passed the House unanimously June 4, 2026, proposed effective July 1, 2027, with a private right of action limited to "large data holders") — with a House-Senate conference committee appointed in June 2026 and no compromise reported as of this round; neither chamber's text carries express automated-decision-making or profiling provisions (the prior claim that it does is REMOVED as unsupported). H.94 (HD396), "An Act to ensure accountability and transparency in artificial intelligence systems," would create a new Chapter 93M imposing developer/deployer duties to identify and mitigate algorithmic discrimination plus annual impact assessments for high-risk AI — still in committee. S.264 (AI chatbot consumer protections) and S.43 (a BIPA-style biometric act carrying a $5,000-per-violation private right of action) were reported favorably to Senate Ways and Means; H.81 (AI disclosure) was sent to a study order on Feb 12, 2026 and is effectively dead this session, as are the campaign-deepfake bills. Treat all of these as watch-list, not requirements. What IS binding: 201 CMR 17.00 (effective March 1, 2010), one of the strictest state data-security regimes in the US, requiring a written comprehensive information security program covering any AI system that touches Massachusetts residents' personal information; M.G.L. c. 93H breach notification, which since April 11, 2019 requires 18 months of free credit monitoring where Social Security numbers are exposed (42 months if the breached entity is a consumer reporting agency) and forces disclosure to the AG of whether a WISP is maintained; and M.G.L. c. 272 § 99, the wiretap act, which criminalizes SECRETLY recording a conversation and therefore governs AI call recorders, voice bots and meeting transcribers — though the SJC held in Vita v. New England Baptist Hospital (Oct 24, 2024) that § 99 does not reach website browsing or pixel tracking. The Massachusetts AG uses Chapter 93A as the general-purpose AI enforcement tool: the April 16, 2024 AG Advisory construes it to reach false AI quality claims, defective AI systems, unsubstantiated reliability/safety/bias claims, deepfakes and voice cloning, and discriminatory AI outputs, and the office has now brought both an algorithmic-pricing matter (RealPage/LivCor) and a squarely AI-model-bias matter (the $2.5M Earnest Operations settlement over AI lending underwriting, July 10, 2025) — see enforcementActions. ROUND 521 (2026-08-25) added the INSURANCE surface, which was entirely absent: the Division of Insurance adopted the NAIC model bulletin as Bulletin 2024-10, "The Use of Artificial Intelligence Systems in Insurance," issued December 9, 2024 by Commissioner Michael T. Caljouw and addressed to all Insurers licensed to do business in Massachusetts — a term the bulletin defines expressly as every entity authorized to engage in the business of insurance under M.G.L. c. 175, c. 152 §§ 25E-25U, c. 176, 176A, 176B, 176E, 176F, 176G, 176H and 176P. It expects a written AIS Program covering governance, risk management and internal audit with senior management accountable to the board, predictive-model validation and unfair-discrimination testing, third-party vendor diligence and audit rights, notice to impacted consumers, and production of the whole documentary record on examination regardless of whether a written program exists. It rests on M.G.L. c. 176D § 3(1-8) and § 3(9), M.G.L. c. 176W § 4 (Corporate Governance Annual Disclosure), the Rating Laws (c. 175 §§ 108, 120, 120F, 122, 193T; c. 174A; c. 175A; c. 175E § 7; c. 176G § 16; c. 176J § 6) and the examination framework at c. 175 § 4 and c. 176G § 10. Separately — and this is a STATUTORY duty, not guidance — M.G.L. c. 176O § 12(a) already requires that adverse determinations rendered by a program of utilization review, and other denials of requests for health services, be made by a person licensed in the appropriate specialty and, where applicable, by a provider in the same licensure category as the ordering provider. That sentence is technology-neutral and therefore bars an algorithmic or AI system from issuing the denial itself without any AI statute being needed. Massachusetts has NOT enacted one: S.2632, which would restrict AI in utilization review and in mental/behavioural health decisions, was recommended ought to pass on April 2, 2026 and referred to Senate Ways and Means, where it remains — it has passed neither chamber. Federal laws apply immediately: FTC Act § 5, Title VII / ADA (employment AI), FCRA (lending AI), COPPA (children's AI).

Summary of publicly-available regulatory text as of 2026-08-25. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2024

Maximum Penalty

State AI provision: Chapter 118 of the Acts of 2024 (eff Sept 18, 2024; CYCLE 4 2026-08-22: corrected from a mis-cited "Chapter 178") criminalizes nonconsensual sexually explicit images including AI-altered "digitization" — a first offense carries up to 2.5 years in a house of correction and a fine up to $10,000, DA/AG-prosecuted. Chapter 93A: M.G.L. c. 93A § 4 sets a civil penalty of not more than $5,000 for each violation in an AG action, plus restoration of losses (doubled to trebled where the conduct is willful) and attorney fees, and not more than $10,000 for each violation of an injunction or order issued under that section (ROUND 507 2026-08-25 addition — the order-violation figure was previously absent). Real-world Chapter 93A AI outcomes far exceed the per-violation cap because counts and restitution stack: the Earnest Operations AI-underwriting settlement was $2,500,000 and the RealPage/LivCor algorithmic-pricing settlement $7,000,000 across a 9-state coalition — see enforcementActions; neither is a statutory-cap figure. Breach notification (M.G.L. c. 93H): enforced by the AG through c. 93A § 4 (c. 93H § 6), same $5,000-per-violation ceiling, on top of the mandatory 18-month (42-month for consumer reporting agencies) credit-monitoring cost. Data security (201 CMR 17.00): no fine schedule of its own; AG enforcement through c. 93A. Wiretap act (M.G.L. c. 272 § 99): secretly recording a conversation is a felony punishable by up to 5 years in state prison or up to 2.5 years in a house of correction and a $10,000 fine, and § 99(Q) adds a civil action for the greater of $100 per day of violation or $1,000, plus punitive damages and attorney fees. INSURANCE (ROUND 521 addition, figures read from the statute this session, not recalled): conduct by a Massachusetts-licensed insurer that breaches M.G.L. c. 176D — including AI-driven unfair trade practices under § 3(1-8) or unfair claims settlement practices under § 3(9) — is addressed under M.G.L. c. 176D § 7, which after a hearing requires written findings and a cease and desist order, permits the commissioner to suspend or, for REPEATED violations of § 3 or § 4, to REVOKE the licence and impose conditions for reinstatement, and provides that whoever commits such an act or practice shall be punished by a fine of not more than $1,000 for each and every act or practice. The commissioner may additionally order restitution to any claimant who suffered actual economic damage from a violation of the chapter, and in an action to recover on an insurance policy a court may award punitive damages of up to 25% of the claim where the claimant was damaged by a § 3 or § 4 violation so determined by the commissioner. Massachusetts is therefore the low-fine, high-licence-risk shape among NAIC adopters — the $1,000 per-act figure is an order of magnitude below sibling states, and licence revocation plus restitution is where the exposure actually sits. Health-insurance utilization review (M.G.L. c. 176O): the chapter sets NO general civil penalty — its only monetary sections are § 5C (coding-standards penalty) and § 8 (failure to file an annual statement) — so enforcement of the § 12 licensed-determination duty runs through the commissioner under § 3 and § 17, through carrier and utilization-review-organization licensure and accreditation, and through the c. 176D § 3(9)/§ 7 route where a denial practice is an unfair claims settlement practice. Federal: FTC civil penalties up to $53,088 per violation.

What Your Business Must Do

14 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Maintain a Written AI Systems (AIS) Program — Massachusetts-Licensed Insurers

Critical

Massachusetts adopted the NAIC model bulletin as Division of Insurance Bulletin 2024-10, "The Use of Artificial Intelligence Systems in Insurance", issued December 9, 2024 by Commissioner of Insurance Michael T. Caljouw and addressed to "All Insurers Licensed to do Business in Massachusetts". All Insurers authorized to do business in Massachusetts are expected to develop, implement and maintain a written program (an "AIS Program") for the responsible use of AI Systems that make or support decisions related to regulated insurance practices, designed to mitigate the risk of Adverse Consumer Outcomes including, at a minimum, the statutory provisions set out in the bulletin's Section 1. The AIS Program should address governance, risk management controls and internal audit functions, and should vest responsibility for its development, implementation, monitoring and oversight — and for setting the Insurer's strategy for AI Systems — with senior management accountable to the board or an appropriate committee of the board. It should be tailored to and proportionate with the Insurer's use and reliance on AI and AI Systems, with controls and procedures focused on the mitigation of Adverse Consumer Outcomes and the scope of controls for a given use case aligned to the Degree of Potential Harm to Consumers for that use case. It should cover the whole insurance life cycle (product development and design, marketing, use, underwriting, rating and pricing, case management, claim administration and payment, and fraud detection) and every phase of an AI System's own life cycle (design, development, validation, implementation of both systems and business, use, on-going monitoring, updating and retirement), and it must address AI Systems used with respect to regulated insurance practices whether developed by the Insurer or by a Third Party vendor. It may be independent of or part of the Insurer's existing Enterprise Risk Management program and may adopt, incorporate or rely upon, in whole or in part, a framework or standards developed by an official third-party standard organization such as the NIST Artificial Intelligence Risk Management Framework, Version 1.0 — the bulletin names that framework and version expressly. The governance framework should prioritise transparency, fairness and accountability in the design and implementation of AI Systems while recognising that proprietary and trade secret information must be protected, and should address the policies, processes and procedures to be followed at each stage of the life cycle from proposed development to retirement; the documentation requirements adopted to evidence compliance (developed, the bulletin says, with Section 4 in mind); and the Insurer's internal AI System governance accountability structure — the formation of centralized, federated or otherwise constituted committees drawn from business units, product specialists, actuarial, data science and analytics, underwriting, claims, compliance and legal; scope of responsibility and authority, chains of command and decisional hierarchies; the independence of decision-makers and lines of defense at successive life-cycle stages; monitoring, auditing, escalation and reporting protocols; and the development and implementation of ongoing training and supervision of personnel. The Division also grounds the expectation in the NAIC Principles of Artificial Intelligence adopted in 2020, which it names as an appropriate source of guidance and which emphasise fair and ethical use, accountability, compliance, transparency, and a safe, secure, fair and robust system.

Deadline: December 9, 2024

Massachusetts Division of Insurance Bulletin 2024-10, "The Use of Artificial Intelligence Systems in Insurance" (December 9, 2024), Section 3 and AIS Program Guidelines 1.0-2.2. Legislative authority enumerated in the bulletin's own Section 1: M.G.L. c. 176D (Unfair Methods of Competition and Unfair and Deceptive Acts and Practices in the Business of Insurance), with the bulletin expressly directing that AI Systems must not result in unfair trade practices as defined in M.G.L. c. 176D, § 3(1-8) or unfair claims settlement practices as defined in M.G.L. c. 176D, § 3(9); and M.G.L. c. 176W (Corporate Governance Annual Disclosure), whose content, form and filing requirements are set at M.G.L. c. 176W, § 4 and whose requirements the bulletin states apply to the elements of the Insurer's corporate governance framework that address its use of AI Systems to support actions and decisions that impact consumers.

Risk Management, Internal Controls and Model Validation for Insurance Predictive Models

Critical

The AIS Program should document the Insurer's risk identification, mitigation and management framework and internal controls for AI Systems generally and at each stage of the AI System life cycle. Bulletin 2024-10 enumerates what those controls must address: the oversight and approval process for the development, adoption or acquisition of AI Systems, together with the identification of constraints and controls on automation and design to align and balance function with risk; data practices and accountability procedures including data currency, lineage, quality, integrity, bias analysis and minimization, and suitability; the management and oversight of Predictive Models (including the algorithms used within them), covering inventories and descriptions of the models, detailed documentation of their development and use, and assessments such as interpretability, repeatability, robustness, regular tuning, reproducibility, traceability, model drift and the auditability of those measurements where appropriate; validating, testing and retesting as necessary to assess the generalization of AI System outputs upon implementation, including the suitability of the data used to develop, train, validate and audit the model, where validation can take the form of comparing model performance on unseen data available at the time of model development to performance observed on data post-implementation, measuring performance against expert review, or other methods; the protection of non-public information, particularly consumer information, including unauthorized access to the Predictive Models themselves; and data and record retention. Separately, under the governance framework, and specifically with respect to Predictive Models, the Insurer must address its processes and procedures for designing, developing, verifying, deploying, using, updating and monitoring Predictive Models, including a description of the methods used to detect and address errors, performance issues, outliers, or unfair discrimination in the insurance practices resulting from the use of the Predictive Model, plus a narrative description of the model's intended goals and objectives and how the model is developed and validated to ensure the AI Systems that rely on it correctly and efficiently predict or implement those goals. The bulletin fixes the substantive standard the models must meet: decisions subject to regulatory oversight that are made by Insurers using AI Systems must comply with the legal and regulatory standards that apply to those decisions, which require at a minimum that decisions made by Insurers are NOT INACCURATE OR UNFAIRLY DISCRIMINATORY, and compliance with those standards is required regardless of the tools and methods the Insurer uses to make such decisions. The Division adds that it encourages the development and use of verification and testing methods to identify errors and bias in Predictive Models and AI Systems, as well as the potential for unfair discrimination in the decisions and outcomes resulting from their use. DISTINCT FROM ma_ai_underwriting_bias_testing IN THIS SAME ENTRY: that item is the Attorney General's Chapter 93A theory, drawn from the Earnest Operations settlement, and applies to any organization making credit, pricing or eligibility decisions about Massachusetts residents whether or not it is licensed. This item is the Division of Insurance's expectation under the insurance code, addressed only to licensed Insurers and enforced through licence action. A Massachusetts-licensed insurer running an AI underwriting or rating model is subject to both, and satisfying one does not discharge the other.

Deadline: December 9, 2024

Massachusetts Division of Insurance Bulletin 2024-10 (December 9, 2024), AIS Program Guidelines 2.3 and 3.0-3.7, with the Section 3 standard that decisions made by Insurers using AI Systems must not be inaccurate or unfairly discriminatory. Substantive rating standards enumerated in the bulletin's Section 1 as the "Rating Laws": M.G.L. c. 175, §§ 108, 120, 120F, 122 and 193T; M.G.L. c. 174A; M.G.L. c. 175A; M.G.L. c. 175E, § 7; M.G.L. c. 176G, § 16; and M.G.L. c. 176J, § 6 — the bulletin gives these as examples of Rating Laws that mandate that insurance rates not be excessive, inadequate, unfairly discriminatory, or discriminate based on protected classes. Non-discrimination and claims standards at M.G.L. c. 176D, § 3(1-8) and § 3(9).

Produce AI Governance and Model Documentation on Divisional Investigation or Market Conduct Examination

Critical

The Division's regulatory oversight of Insurers includes oversight of an Insurer's conduct in Massachusetts, including its use of AI Systems to make or support decisions that impact consumers. REGARDLESS OF THE EXISTENCE OR SCOPE OF A WRITTEN AIS PROGRAM, an Insurer can expect to be asked, in the context of an investigation or market conduct action, about its development, deployment and use of AI Systems, or any specific Predictive Model, AI System or application and its outcomes (including Adverse Consumer Outcomes), as well as any other information or documentation the Division deems relevant. Insurers should expect those inquiries to include the governance framework, risk management and internal controls, and requests for: the written AIS Program itself; information and documentation relating to or evidencing its adoption; the scope of the program, including any AI Systems and technologies NOT included in or addressed by it; how the program is tailored to and proportionate with the Insurer's use and reliance on AI Systems, the risk of Adverse Consumer Outcomes and the Degree of Potential Harm to Consumers; the policies, procedures, guidance, training materials and other information relating to its adoption, implementation, maintenance, monitoring and oversight — including processes for the development, adoption or acquisition of AI Systems (identification of constraints and controls on automation and design; data governance and controls covering data lineage, quality, integrity, bias analysis and minimization, suitability and data currency), processes related to the management and oversight of Predictive Models including the measurements, standards or thresholds adopted or used in the development, validation and oversight of models and AI Systems, and the protection of non-public information including unauthorized access to Predictive Models themselves; documentation of pre-acquisition/pre-use diligence, monitoring, oversight and auditing of data or AI Systems developed by a Third Party; and documentation evidencing implementation of and compliance with the AIS Program, including the formation and ongoing operation of the Insurer's coordinating bodies for AI System development, use and oversight, data-practice and accountability records, inventories and descriptions of Predictive Models and AI Systems used to make or support decisions that can result in Adverse Consumer Outcomes, and — for any specific Predictive Model or AI System that is the subject of investigation or examination — documentation of compliance with all applicable AI Program policies, protocols and procedures, information about the data used in its development and oversight (source, provenance, lineage, quality, integrity, bias analysis and minimization, suitability and data currency), and information on the techniques, measurements, thresholds and similar controls used. Documentation of validation, testing and auditing, including evaluation of Model Drift to assess the reliability of outputs, is expected as well, with the nature of that validation, testing and auditing reflective of whether the underlying components of the AI System are based on Predictive Models or on Generative AI. Where the investigation or examination concerns data, Predictive Models or AI Systems collected or developed in whole or in part by Third Parties, the Insurer should additionally expect requests for the due diligence conducted on those Third Parties and their data, models or AI Systems; the contracts with Third-Party AI System, model or data vendors, including terms relating to representations, warranties, data security and privacy, data sourcing, intellectual property rights, confidentiality and disclosures, and/or cooperation with regulators; audits and/or confirmation processes performed regarding Third-Party compliance with contractual and, where applicable, regulatory obligations; and documentation pertaining to validation, testing and auditing including evaluation of Model Drift.

Deadline: December 9, 2024

Massachusetts Division of Insurance Bulletin 2024-10 (December 9, 2024), Section 4 "Regulatory Oversight and Examination Considerations", items 1.1-1.3 and 2.1-2.4. Examination and investigation authority enumerated in the bulletin's Section 1: M.G.L. c. 175, § 4 (Examination of Companies) and M.G.L. c. 176G, § 10 (Reports; audits, examinations or inspections; confidentiality and privilege) "and other similar statutes", which the bulletin states establish the framework pursuant to which the Division performs market conduct examinations and investigations — undertaken both as part of the Division's authority to periodically monitor Insurers' market practices and to address illegal practices brought to the Division's attention by individual consumer complaints.

Utilization Review — Only a Licensed Specialist May Render an Adverse Determination (Statutory, Technology-Neutral)

Critical

This is a STATUTORY duty rather than a bulletin expectation, and it is the sharpest constraint on AI in Massachusetts insurance law — reached not through an AI statute, which Massachusetts does not have, but through words already on the books that an algorithm cannot satisfy. Under M.G.L. c. 176O § 12(a), "Adverse determinations rendered by a program of utilization review or other denials of requests for health services, shall be made by a person licensed in the appropriate specialty related to such health service and, if applicable, by a provider in the same licensure category as the ordering provider." The provision is technology-neutral: it does not mention algorithms, so it does not need amending to bite. An automated or AI-assisted utilization-review pipeline may triage, flag, gather information, apply criteria or APPROVE, but the adverse determination itself — the denial — must be made by a licensed human in the appropriate specialty, and where applicable in the same licensure category as the ordering provider. The surrounding subsections tighten the same screw. Section 12(a) also requires that utilization review conducted by a carrier or utilization review organization be conducted under a written plan, UNDER THE SUPERVISION OF A PHYSICIAN and staffed by appropriately trained and qualified personnel, with a documented process to review and evaluate its effectiveness, ensure the consistent application of utilization review criteria, and ensure the timeliness of determinations; and it requires that the review criteria be, to the maximum extent feasible, scientifically derived and evidence-based and developed with the input of participating physicians, applied consistently, and made easily accessible and up to date on the carrier's or utilization review organization's website — with a new or amended preauthorization requirement or restriction barred from implementation until the website has been updated to reflect it. Section 12(d) then constrains what a denial notice may say: the written notification of an adverse determination shall include a substantive clinical justification consistent with generally accepted principles of professional medical practice and shall at a minimum identify the specific information on which the determination was based, discuss the insured's presenting symptoms or condition, diagnosis and treatment interventions and the specific reasons the medical evidence fails to meet the relevant medical review criteria, specify any alternative treatment option offered by the carrier, and reference and include the applicable clinical practice guidelines and review criteria. A model-generated denial reason that cannot be traced to those elements does not satisfy the section. Section 12(e) gives the treating provider a right to seek reconsideration from a CLINICAL PEER REVIEWER within one working day on an initial or concurrent determination. And M.G.L. c. 176O § 16(a) sets the background rule that the treating physician, consistent with generally accepted principles of professional medical practice and in consultation with the insured, makes all clinical decisions regarding medical treatment, while § 16(b) requires that any medical-necessity guidelines a carrier uses in making coverage determinations be developed with input from practising physicians and participating providers in the service area, developed under the standards adopted by national accreditation organizations, updated at least biennially or more often as new treatments, applications and technologies are adopted as generally accepted professional medical practice, and evidence-based if practicable — which is the provision an AI-derived or vendor-supplied medical-necessity criteria set must be measured against. Section 9 separately requires a carrier to provide the commissioner an annual written attestation that its utilization review program, or its designee's, complies with all applicable state and federal laws concerning confidentiality and reporting requirements. VERIFIED NEGATIVE, recorded so that no one re-derives it: Massachusetts has NOT enacted an AI-specific utilization-review statute. S.2632, "An Act relative to the use of artificial intelligence and other software tools in healthcare decision-making", which would bar AI from making independent therapeutic decisions in mental and behavioural health settings and restrict carriers' use of AI in utilization review, was reported out of committee as a new draft of S.46 on October 16, 2025 and, on April 2, 2026, was recommended ought to pass and referred to Senate Ways and Means, where it still sat as of the most recent verifiable snapshot of its history page. It has passed neither chamber and is not law. The duty stated here rests entirely on the existing text of c. 176O.

M.G.L. c. 176O § 12(a) (utilization review; written plan under the supervision of a physician; review criteria; the requirement that adverse determinations and other denials of requests for health services be made by a person licensed in the appropriate specialty and, if applicable, by a provider in the same licensure category as the ordering provider); § 12(d) (required content of a written adverse-determination notice); § 12(e) (reconsideration by a clinical peer reviewer within one working day); § 16(a)-(b) (treating physician makes all clinical decisions; standards for medical-necessity guidelines); § 9 (annual written attestation to the commissioner). Statutory text read this session from Internet Archive raw-bytes snapshots of malegislature.gov — § 12 from 2026-02-07, § 16 from 2025-12-08, § 9 from 2025-09-06, chapter contents from 2026-04-21 — malegislature.gov itself being unreachable from this toolchain at the network level.

Massachusetts Chapter 118 of the Acts of 2024 — Deepfake "Digitization" NCII (Criminal)

High Priority

Massachusetts Chapter 118 of the Acts of 2024 ("An Act to Prevent Abuse and Exploitation," H.4744; signed by Gov. Maura Healey June 20, 2024; effective Sept 18, 2024; CYCLE 4 2026-08-22: corrected from a mis-cited "Chapter 178" — a digit-transposition error confirmed via WebSearch this cycle, malegislature.gov itself unreachable) criminalizes the nonconsensual sharing of sexually explicit images ("revenge porn") and expressly extends to "digitization" — computer-generated or AI-altered images that falsely appear to depict a real, identifiable person in a sexually explicit manner (deepfake nudes). It also adds "coercive control" to the ch. 209A abuse definitions and a teen-sexting diversion program (non-AI parts). Enforced criminally by district attorneys / the Massachusetts AG: up to 2.5 years in a house of correction, a fine up to $10,000, or both. Note: AG Andrea Campbell's April 16, 2024 AI Advisory — that Chapter 93A, anti-discrimination, and Chapter 93H data-security law already apply to AI — is guidance, not a statute. Requirement id retains the old "ch178" string for id-stability (not referenced elsewhere in src/, but renaming is a code change out of this cycle's data-only scope) — the id is an internal identifier, not a customer-facing citation. ROUND 507 (2026-08-25): the "digitization" definition and the penalty were re-verified against three mutually independent current mirrors (Serpa Law's Chapter 118 explainer, Boston Lawyer Blog 2024-07-15, and Sen. Mike Moore's own newsroom release 2024-06-14), which converge on a definition covering computer-generated images that would falsely appear to a reasonable person to be an authentic depiction of the person shown, and on a first offense of up to 2.5 years in a house of correction and a fine of up to $10,000. legal_review_pending REMAINS OPEN on one narrow point only: malegislature.gov returned ECONNREFUSED when fetched directly this round, so the primary session-law text is still unread and the codified General Laws section number is deliberately NOT asserted here.

Deadline: September 18, 2024

Massachusetts Acts of 2024, Chapter 118 (H.4744), "digitization" clause

Massachusetts Data Security Law (201 CMR 17.00) — AI Systems

High Priority

Massachusetts 201 CMR 17.00 (effective March 1, 2010) requires a written comprehensive information security program — universally called a WISP — for any person or business that owns or licenses personal information about a Massachusetts resident. There is no revenue or headcount floor: holding the data is the trigger, and a single Massachusetts resident's record is enough. ROUND 507 (2026-08-25) verified the specific control set rather than describing it generically. Under 201 CMR 17.03 the program must: designate one or more employees to maintain it; identify and assess reasonably foreseeable internal and external risks to paper, electronic and other records containing personal information; impose disciplinary measures for violations; restrict terminated employees' access; take reasonable steps to SELECT AND RETAIN third-party service providers capable of maintaining appropriate safeguards AND require those safeguards BY CONTRACT (the provision that governs every AI SaaS vendor, model API and annotation contractor in your stack); limit collection and retention of personal information to what is reasonably necessary; provide ongoing employee training; and review the program at least annually and whenever business practices change materially. Under 201 CMR 17.04, to the extent technically feasible: encrypt personal information transmitted across public networks or wirelessly and all personal information stored on laptops and other portable devices; use secure authentication with unique identifiers and control of passwords; maintain access control so each user reaches only what their duties require; run reasonably up-to-date firewall protection and security patches on any internet-connected system holding personal information; and run reasonably up-to-date malware protection with current definitions. Mapped onto AI: training corpora and embedding stores holding MA-resident personal information fall inside the encryption-at-rest duty when carried on portable devices, model API traffic falls inside the transmission-encryption duty, and every AI vendor falls inside the 17.03 contractual-safeguards duty. Failure to have a WISP is separately damaging because M.G.L. c. 93H forces you to disclose its absence to the Attorney General when you report a breach.

Deadline: March 1, 2010

201 CMR 17.03 (Duty to Protect; WISP contents); 201 CMR 17.04 (Computer System Security Requirements); issued under M.G.L. c. 93H § 2; enforced via M.G.L. c. 93A § 4 (M.G.L. c. 93H § 6)

Massachusetts Breach Notification (M.G.L. c. 93H) — AI and Vendor Incidents

High Priority

If personal information about a Massachusetts resident is breached — including through an AI vendor, a model API, a training-data store, or an inference log — M.G.L. c. 93H requires notice to the Attorney General, the Office of Consumer Affairs and Business Regulation (OCABR), and each affected resident as soon as practicable and without unreasonable delay. Massachusetts imposes obligations no other state stacks the same way, all verified this round. (1) The regulator notice must state whether you maintain a written information security program and whether the breach caused you to update it or plan to — so the 201 CMR 17.00 WISP duty above is audited at exactly the moment you are least able to fix it retroactively. (2) If the breached entity is a subsidiary, the notice must name the parent or affiliated corporation. (3) The notice must identify the person who caused the breach, if known. (4) Notice may NOT be delayed on the ground that the total number of affected residents is not yet ascertained — you notify on what you know and supplement later, which is the opposite of the "wait until the forensic report is final" instinct. (5) Where Social Security numbers were disclosed you must offer credit monitoring free of charge for at least 18 months, or at least 42 months if the breached entity is itself a consumer reporting agency. (6) You may not require an affected resident to waive their private right of action as a condition of receiving that credit monitoring. The consumer-facing notice is also constrained in what it may say: Massachusetts deliberately keeps the nature of the breach and the number of residents affected out of the resident notice. Practical AI consequence: your AI vendor contracts need incident-reporting clocks fast enough for you to meet a "without unreasonable delay" standard you cannot restart, and your WISP needs to exist before an incident, not after.

Deadline: April 11, 2019

M.G.L. c. 93H §§ 3, 3A (as amended by St. 2018, c. 444, eff. April 11, 2019); enforced via M.G.L. c. 93H § 6 and M.G.L. c. 93A § 4

Massachusetts Wiretap Act (M.G.L. c. 272 § 99) — AI Call Recording, Voice Bots and Meeting Transcription

High Priority

Massachusetts is commonly described as a two-party consent state, but the statute's actual operative word is SECRETLY: M.G.L. c. 272 § 99 makes it a crime to secretly hear or secretly record the contents of any wire or oral communication through an intercepting device without prior authority from ALL parties. Commonwealth v. Hyde, 434 Mass. 594 (2001), makes the practical test concrete — the recording there would not have been "secret" had the recorder simply announced it or been held in plain sight. That is the standard any AI feature that captures speech must meet: an AI notetaker joining a call, a voice agent that records for quality or model training, an automated transcription service, or a support bot that retains audio must make its recording actually known to every participant before capture begins, and a buried clause in a terms-of-service page is a weak substitute for an audible or on-screen announcement. Massachusetts also does not carve out the participant: unlike federal law and most states, a party to the conversation gains no safe harbour from being a party. ROUND 507 verified how courts ACTUALLY apply this, and the answer materially narrows the exposure: in Vita v. New England Baptist Hospital, SJC-13542 (Oct. 24, 2024), the Supreme Judicial Court rejected wiretap claims built on website pixel and third-party tracking technology, holding that entering a URL, loading a page, clicking links and scrolling are "clearly not the type of person-to-person conversation or messaging unambiguously protected by the act." So § 99 should NOT be modeled as a website-analytics or session-replay risk in Massachusetts, and the wave of pixel class actions premised on it fails. It remains fully live for anything that captures an actual conversation — which is precisely where conversational AI operates.

M.G.L. c. 272 § 99(C)(1) (secret interception offence); M.G.L. c. 272 § 99(Q) (civil remedy); Commonwealth v. Hyde, 434 Mass. 594 (2001); Vita v. New England Baptist Hospital, SJC-13542 (Mass. Oct. 24, 2024)

AG AI Advisory (April 16, 2024) — Chapter 93A Applied to AI (Enforcement Posture, Not a New Statute)

High Priority

On April 16, 2024 Attorney General Andrea Joy Campbell issued the Attorney General Advisory on the Application of the Commonwealth's Consumer Protection, Anti-Discrimination, and Data Security Laws to Artificial Intelligence. It is GUIDANCE: it enacts nothing and creates no new obligation. What it does is tell you, in the regulator's own words, how M.G.L. c. 93A § 2 will be applied to AI, which in a state with no comprehensive AI act is the operative rulebook. The Advisory identifies these as potentially unfair or deceptive acts: falsely advertising the quality, value or usability of an AI system; supplying an AI system that is defective, unusable or impractical for its advertised purpose; misrepresenting an AI system's reliability, performance, safety or freedom from bias, including making such claims without substantiation; offering an AI system for sale in breach of warranty; misrepresenting audio or video content to deceive another, expressly including deepfakes, voice cloning, and chatbots used in fraud; and failing to comply with other Massachusetts statutes protecting public health, safety or welfare. On anti-discrimination, the AG states it is unlawful for AI systems to rely on discriminatory inputs or to produce discriminatory results, including disparate outcomes on protected characteristics REGARDLESS OF INTENT, and that creditors must give accurate, specific reasons when an AI-assisted decision denies credit. On data security, the Advisory ties AI back to the Commonwealth's existing safeguarding and breach-notification duties. Concretely, then: substantiate every performance and bias claim in your AI marketing before you publish it, disclose synthetic media and chatbots, test AI outputs for disparate impact, and keep adverse-action reasons specific and true to the model that produced them. The Advisory is not theoretical — the AG has since settled an AI-model-bias matter for $2.5M on exactly these theories (see enforcementActions).

Deadline: April 16, 2024

M.G.L. c. 93A § 2 (unfair or deceptive acts), as construed by the Massachusetts Attorney General Advisory on the Application of the Commonwealth's Consumer Protection, Anti-Discrimination, and Data Security Laws to Artificial Intelligence (April 16, 2024); enforced under M.G.L. c. 93A § 4

AI Underwriting and Eligibility Models — Disparate-Impact Testing and Accurate Adverse-Action Reasons

High Priority

If you use AI or algorithmic models to decide eligibility, terms or pricing for Massachusetts consumers — lending, credit, insurance-adjacent pricing, tenancy screening, or any similar gate — the Massachusetts AG has now demonstrated exactly which practices it will treat as unfair or deceptive under M.G.L. c. 93A, and it did so through imposed settlement terms rather than commentary. The conduct the AG challenged in the Earnest Operations matter: deploying AI underwriting models without testing them for disparate impact on protected groups; applying a categorical "knockout rule" that automatically denied applicants who lacked at least a green card, creating disparate-impact exposure on national origin and immigration status; feeding in proxy variables such as the cohort default rate of the applicant's college, which imports the demographics of an institution into an individual decision; failing to assess individual model variables for bias; and issuing adverse-action notices that did not give the specific, accurate reasons the model actually relied on. The corrective terms are the compliance bar to build to: a written corporate governance framework for AI model use, documented fair-lending testing on the models themselves, internal controls and periodic risk assessments, and adverse-action notices that reflect the real determinative factors. Note that the AG framed model bias as an unfair practice WITHOUT needing to prove discriminatory intent, so "we did not mean to and we did not know" is not a defense in this jurisdiction — the absence of testing is itself the failure. Federal ECOA and Regulation B run in parallel: an adverse action based on a model still requires a statement of specific principal reasons.

M.G.L. c. 93A § 2, enforced under § 4 (see the Massachusetts AG's Earnest Operations LLC settlement, July 10, 2025, in enforcementActions); ECOA adverse-action notice duty, 15 U.S.C. § 1691(d); Regulation B, 12 C.F.R. § 1002.9

Third-Party AI System and Data Diligence, Contractual Audit Rights and Regulator Cooperation

High Priority

Each AIS Program should address the Insurer's process for acquiring, using, or relying on (i) third-party data to develop AI Systems and (ii) AI Systems developed by a Third Party, which may include, as appropriate, the establishment of standards, policies, procedures and protocols relating to: due diligence and the methods employed by the Insurer to assess the Third Party and its data or AI Systems acquired from the Third Party, to ensure that decisions made or supported from such AI Systems that could lead to Adverse Consumer Outcomes will meet the legal standards imposed on the Insurer ITSELF; where appropriate and available, the inclusion of terms in contracts with Third Parties that provide audit rights and/or entitle the Insurer to receive audit reports by qualified auditing entities, and that require the Third Party to cooperate with the Insurer with regard to regulatory inquiries and investigations related to the Insurer's use of the Third Party's product or services; and the performance of contractual rights regarding audits and/or other activities to confirm the Third Party's compliance with contractual and, where applicable, regulatory requirements. Independently of those qualified items, the AIS Program must in any event address the AI Systems used with respect to regulated insurance practices whether developed by the Insurer or by a Third Party vendor — buying the model does not move it outside the program. "Third Party" is defined in the bulletin as an organization other than the Insurer that provides services, data, or other resources related to AI.

Deadline: December 9, 2024

Massachusetts Division of Insurance Bulletin 2024-10 (December 9, 2024), AIS Program Guidelines 1.8 and 4.0-4.3, with the "Third Party" definition at Section 2 and the corresponding examination expectations at Section 4, items 1.2 and 2.1-2.4.

Notice to Impacted Consumers That AI Systems Are in Use

High Priority

The AIS Program should include processes and procedures providing notice to impacted consumers that AI Systems are in use, and provide access to appropriate levels of information based on the phase of the insurance life cycle in which the AI Systems are being used. This sits alongside the bulletin's treatment of the transparency and explainability of outcomes to the impacted consumer as one of the five factors that determine how extensive an Insurer's AI controls must be, and alongside the governance requirement that the framework prioritise transparency, fairness and accountability in the design and implementation of AI Systems while recognising that proprietary and trade secret information must be protected.

Deadline: December 9, 2024

Massachusetts Division of Insurance Bulletin 2024-10 (December 9, 2024), AIS Program Guideline 1.9; transparency and explainability factor at Section 3, factor (iv); governance transparency principle at Guideline 2.0.

Federal AI Compliance (Massachusetts)

Medium Priority

Federal laws apply: FTC Act § 5 (deceptive/unfair AI practices), Title VII / ADA (AI must not discriminate in employment), FCRA (AI credit decisions require adverse action notices), COPPA (AI systems processing children under 13 require parental consent). Massachusetts AG has used Chapter 93A (Consumer Protection Act) to pursue algorithmic discrimination and deceptive AI claims — ensure your AI disclosures are honest and your AI outputs do not discriminate on protected characteristics.

FTC Act §5 (15 U.S.C. §45(a)); Title VII (42 U.S.C. §2000e-2); ADA (42 U.S.C. §12112); FCRA (15 U.S.C. §1681 et seq.); COPPA (15 U.S.C. §§6501-6506); Mass. Gen. Laws ch. 93A (Consumer Protection Act)

Monitor Massachusetts AI Legislation — High Activity in 2026

Medium Priority

Massachusetts is among the most active states for AI and privacy legislation, and ROUND 507 (2026-08-25) replaced this item's previously generic bill descriptions with the real bill numbers and their real status. NOTHING below is enacted; treat every item as a watch-list entry, not a requirement. (1) Comprehensive privacy — two unreconciled versions: S.2608/S.2619, the Massachusetts Data Privacy Act, passed the Senate 40-0 on Sept 25, 2025 with exclusive AG enforcement, a proposed Jan 1, 2027 effective date and a 60,000-consumer applicability threshold; and H.5479, the Massachusetts Consumer Data Privacy Act, passed the House unanimously June 4, 2026 with a proposed July 1, 2027 effective date, a 100,000-consumer threshold, a ban on selling precise geolocation data, protections for under-18s, and a private right of action confined to "large data holders." A House-Senate conference committee was appointed in June 2026; no compromise had been reported as of this round, and neither text carries express automated-decision-making or profiling provisions. Both cap penalties at $5,000 per violation. (2) AI accountability — H.94 (HD396), "An Act to ensure accountability and transparency in artificial intelligence systems," would create a new Chapter 93M requiring developers to use reasonable care to identify, mitigate and disclose algorithmic-discrimination risk and to hand deployers documentation of intended uses, known limitations and training-data provenance, with annual impact assessments for high-risk systems; still in committee. This is the bill previously referred to here as the "AI Accountability Act," which is not its name. (3) S.264 — AI chatbot consumer protections; reported favorably Dec 18, 2025 and referred to Senate Ways and Means. (4) S.43 — a BIPA-style Biometric Information Privacy Act requiring written consent before collecting biometric identifiers, a published retention/destruction policy capped at one year, and a private right of action of at least $5,000 per violation; reported favorably to Senate Ways and Means. If S.43 ever passes it would be the single largest new exposure for face, voice and fingerprint AI in the Commonwealth — watch it closely. (5) S.35 — limits on employee electronic monitoring tools; reported favorably Oct 16, 2025 to Senate Ways and Means. (6) DEAD, do not track as live: H.81 (AI disclosure) was sent to a study order on Feb 12, 2026, and the campaign-deepfake bills (S.2631 and House companions) did not advance. Meanwhile the operative rulebook remains Chapter 93A as construed by the AG's April 16, 2024 AI Advisory. Check malegislature.gov and mass.gov/ago for updates — note both domains blocked automated fetches during this round.

Recent Enforcement Actions

2024-08Source verified· as of 2026-08-25

Against:

2025-07Source verified· as of 2026-08-25

Against:

Recent Regulatory Guidance

guidance2024-04-16

Attorney General Advisory on the Application of the Commonwealth's Consumer Protection, Anti-Discrimination, and Data Security Laws to Artificial Intelligence

Issued April 16, 2024 by AG Andrea Joy Campbell. The Advisory creates no new obligation; it states how existing Massachusetts law applies to AI. Under M.G.L. c. 93A it identifies six categories of potentially unfair or deceptive AI conduct: falsely advertising the quality, value or usability of an AI system; supplying a defective, unusable or impractical AI system; misrepresenting an AI system's reliability, performance, safety or freedom from bias, including unsubstantiated claims; offering an AI system for sale in breach of warranty; misrepresenting audio or video content to deceive, expressly including deepfakes, voice cloning and chatbots used in fraud; and failing to comply with other statutes protecting public health, safety or welfare. On anti-discrimination it states that AI relying on discriminatory inputs or producing discriminatory results is unlawful regardless of intent, and that creditors must give accurate specific reasons for AI-assisted credit denials. On data security it ties AI back to the Commonwealth's existing safeguarding and breach-notification duties. The AG has since acted on these theories in the $2.5M Earnest Operations AI-underwriting settlement (July 2025).

ruling2024-10-24

Vita v. New England Baptist Hospital, SJC-13542 — Wiretap Act Does Not Reach Website Tracking

Decided October 24, 2024. The Massachusetts Supreme Judicial Court rejected an attempt to apply the wiretap act, M.G.L. c. 272 § 99, to hospitals' use of third-party web-tracking pixels, holding that "activities such as entering a URL, accessing a specific webpage, clicking on links, and scrolling through a webpage are clearly not the type of person-to-person conversation or messaging unambiguously protected by the act." The plaintiff had not alleged interception of patient records or messages to providers. Practical effect: the wave of § 99 class actions premised on web analytics and session replay fails in Massachusetts, and § 99 should not be modeled as a website-tracking risk. It remains fully applicable to secret recording of actual conversations — the AI call-recording, voice-agent and meeting-transcription scenario.

guidance2024-12-09

Division of Insurance Bulletin 2024-10 — The Use of Artificial Intelligence Systems in Insurance

Issued December 9, 2024 by Commissioner of Insurance Michael T. Caljouw to all Insurers licensed to do business in Massachusetts. Massachusetts' adoption of the NAIC model bulletin. It reminds Insurers that decisions or actions impacting consumers made or supported by advanced analytical and computational technologies, including AI Systems, must comply with all applicable insurance laws and regulations, including those addressing unfair trade practices and unfair discrimination; sets the Division's expectations for how Insurers will govern the development, acquisition and use of those technologies; and advises Insurers of the information and documentation the Division may request during an investigation or examination. Substantively it expects a written AIS Program (governance, risk management controls, internal audit, senior management accountable to the board, NIST AI RMF v1.0 named as an acceptable framework, whole-insurance-life-cycle and whole-model-life-cycle scope, vendor-built systems included), predictive-model management and validation with detection of errors, performance issues, outliers and unfair discrimination, third-party diligence with audit and regulator-cooperation contract terms where appropriate and available, notice to impacted consumers that AI Systems are in use, and full documentary production on examination regardless of whether a written AIS Program exists. Legal authority as enumerated in the bulletin itself: M.G.L. c. 176D (§ 3(1-8) unfair trade practices, § 3(9) unfair claims settlement practices), M.G.L. c. 176W § 4 (Corporate Governance Annual Disclosure), the Rating Laws (M.G.L. c. 175 §§ 108, 120, 120F, 122, 193T; c. 174A; c. 175A; c. 175E § 7; c. 176G § 16; c. 176J § 6) and the examination framework (M.G.L. c. 175 § 4; M.G.L. c. 176G § 10). The bulletin sets no compliance date, prescribes no specific practices or documentation, and expressly permits Insurers to demonstrate compliance through alternative means. It closes by stating that the Division intends to revisit the guidance periodically and will consider any relevant recommendations made by the Artificial Intelligence Task Force created pursuant to Executive Order Number 629.

Frequently Asked Questions

Does Massachusetts — Ch. 93A + AG AI Advisory, 201 CMR 17.00 WISP, c. 93H Breach, c. 272 §99 Wiretap, Ch. 118/2024 Deepfake NCII, Insurance AI (DOI Bulletin 2024-10; utilization review, c. 176O §12) + Federal AI Profile apply to my business?

Massachusetts has no comprehensive AI statute and no enacted election-deepfake, chatbot-disclosure, employment-AI, or healthcare-AI law as of June 2026, but it has enacted one AI-specific binding provision: Chapter 118 of the Acts of 2024 ("An Act… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Massachusetts — Ch. 93A + AG AI Advisory, 201 CMR 17.00 WISP, c. 93H Breach, c. 272 §99 Wiretap, Ch. 118/2024 Deepfake NCII, Insurance AI (DOI Bulletin 2024-10; utilization review, c. 176O §12) + Federal AI Profile is: State AI provision: Chapter 118 of the Acts of 2024 (eff Sept 18, 2024; CYCLE 4 2026-08-22: corrected from a mis-cited "Chapter 178") criminalizes nonconsensual sexually explicit images including AI-altered "digitization" — a first offense carries up to 2.5 years in a house of correction and a fine up to $10,000, DA/AG-prosecuted. Chapter 93A: M.G.L. c. 93A § 4 sets a civil penalty of not more than $5,000 for each violation in an AG action, plus restoration of losses (doubled to trebled where the conduct is willful) and attorney fees, and not more than $10,000 for each violation of an injunction or order issued under that section (ROUND 507 2026-08-25 addition — the order-violation figure was previously absent). Real-world Chapter 93A AI outcomes far exceed the per-violation cap because counts and restitution stack: the Earnest Operations AI-underwriting settlement was $2,500,000 and the RealPage/LivCor algorithmic-pricing settlement $7,000,000 across a 9-state coalition — see enforcementActions; neither is a statutory-cap figure. Breach notification (M.G.L. c. 93H): enforced by the AG through c. 93A § 4 (c. 93H § 6), same $5,000-per-violation ceiling, on top of the mandatory 18-month (42-month for consumer reporting agencies) credit-monitoring cost. Data security (201 CMR 17.00): no fine schedule of its own; AG enforcement through c. 93A. Wiretap act (M.G.L. c. 272 § 99): secretly recording a conversation is a felony punishable by up to 5 years in state prison or up to 2.5 years in a house of correction and a $10,000 fine, and § 99(Q) adds a civil action for the greater of $100 per day of violation or $1,000, plus punitive damages and attorney fees. INSURANCE (ROUND 521 addition, figures read from the statute this session, not recalled): conduct by a Massachusetts-licensed insurer that breaches M.G.L. c. 176D — including AI-driven unfair trade practices under § 3(1-8) or unfair claims settlement practices under § 3(9) — is addressed under M.G.L. c. 176D § 7, which after a hearing requires written findings and a cease and desist order, permits the commissioner to suspend or, for REPEATED violations of § 3 or § 4, to REVOKE the licence and impose conditions for reinstatement, and provides that whoever commits such an act or practice shall be punished by a fine of not more than $1,000 for each and every act or practice. The commissioner may additionally order restitution to any claimant who suffered actual economic damage from a violation of the chapter, and in an action to recover on an insurance policy a court may award punitive damages of up to 25% of the claim where the claimant was damaged by a § 3 or § 4 violation so determined by the commissioner. Massachusetts is therefore the low-fine, high-licence-risk shape among NAIC adopters — the $1,000 per-act figure is an order of magnitude below sibling states, and licence revocation plus restitution is where the exposure actually sits. Health-insurance utilization review (M.G.L. c. 176O): the chapter sets NO general civil penalty — its only monetary sections are § 5C (coding-standards penalty) and § 8 (failure to file an annual statement) — so enforcement of the § 12 licensed-determination duty runs through the commissioner under § 3 and § 17, through carrier and utilization-review-organization licensure and accreditation, and through the c. 176D § 3(9)/§ 7 route where a denial practice is an unfair claims settlement practice. Federal: FTC civil penalties up to $53,088 per violation.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Massachusetts — Ch. 93A + AG AI Advisory, 201 CMR 17.00 WISP, c. 93H Breach, c. 272 §99 Wiretap, Ch. 118/2024 Deepfake NCII, Insurance AI (DOI Bulletin 2024-10; utilization review, c. 176O §12) + Federal AI Profile?

The 14 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://malegislature.gov

Last updated: 2026-08-25 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan