Skip to content
US-NCFEDERAL profile2 enforcement actions

North Carolina — State AI Law (SL 2024-37 AI-CSAM/deepfake NCII; DOI Bulletin 24-B-19 insurer AI; SL 2025-84 Art. 51A) + Breach/UDTPA + Federal Profile: AI Compliance Requirements

North Carolina has no comprehensive/standalone private-sector AI statute as of June 2026, but it has enacted one AI-specific criminal law that binds private parties: Session Law 2024-37 (HB 591, "Modernize Sex Crimes"; signed by Gov. Roy Cooper July 8, 2024; effective Dec 1, 2024). It expands the definition of CSAM "material" (G.S. 14-190.13) to include "digital or computer-generated visual depictions" and creates a new offense (G.S. 14-190.17C) that reaches fully synthetic/AI-generated imagery even where the depicted minor does not exist, and it amends the disclosure-of-private-images statute (G.S. 14-190.5A) so that "image" includes a realistic depiction "created, adapted, or modified by technological means, including algorithms or artificial intelligence" (deepfake NCII of adults). Enforced by NC district attorneys (criminal). (Verify-the-negative: North Carolina has NO comprehensive/standalone AI Act enacted as of this cycle. CYCLE 20 PRECISION FIX (2026-08-22): the prior "the 2025 AI bills died" framing overstated finality — several AI bills remain formally pending on the General Assembly's own tracker deep into the 2025-2026 biennium rather than having failed outright: House Bill 934 ("AI Regulatory Reform Act") and House Bill 375 remained under committee consideration as of March 2026, and Senate Bill 963 ("AI Chatbots — Licensing, Safety, & Privacy") and Senate Bill 747 (Office of AI Policy) were newly introduced/active in spring 2026 — none had passed both chambers as of this cycle. Gov. Stein's Executive Order 24 of Sept 2, 2025 is government-internal AI governance, not a private-sector statute.) North Carolina has one of the most important AI compliance environments in the US: Bank of America, Truist, First Citizens Bank, and Wells Fargo operations are all headquartered or significantly based in Charlotte, and the Research Triangle (IBM, Lenovo, Cisco, SAS Institute) is a major AI technology center. Federal laws apply: FTC Act § 5, Title VII / ADA, FCRA, OCC AI risk guidance (banking), COPPA. NC AG has shown interest in AI consumer protection. Monitor ncleg.gov. R508 (2026-08-25) ADDS THREE PREVIOUSLY-MISSING NORTH CAROLINA TRACKS. (i) INSURANCE — North Carolina DID adopt the NAIC Model AI Bulletin: NC DOI Bulletin 24-B-19 (Commissioner Mike Causey, December 18, 2024) tells every insurer holding a certificate of authority in NC that consumer-impacting decisions made or supported by AI Systems must comply with all applicable insurance law, sets out expectations for a written "AIS Program" governing AI across the insurance life cycle, and lists the documentation the Department may demand in an AI-focused market conduct examination; confirmed against the NAIC implementation map dated August 6, 2026. (ii) DATA BREACH — the NC Identity Theft Protection Act (G.S. 75-61, 75-65) requires notice to affected residents and to the Consumer Protection Division of the Attorney General's Office "without unreasonable delay" (North Carolina sets NO numeric deadline), with nationwide consumer reporting agencies added once more than 1,000 persons are notified; the 75-61 definition of protected personal information expressly includes BIOMETRIC data, which is what pulls AI/ML identity and authentication systems inside it, and a violation is an unfair trade practice carrying mandatory treble damages. (iii) SL 2025-84 (HB 805, "Prevent Sexual Exploitation of Women and Minors Act"; veto overridden July 29, 2025; new Article 51A of Chapter 66, G.S. 66-505 to 66-510; effective December 1, 2025) imposes age-and-consent verification, a 72-hour removal duty, and a duty to block "any altered or edited version" of a removed image on operators of covered online entities — the altered-version duty is the AI/deepfake hook — backed by damages of the greater of $10,000 per day per image or actual damages. Verify-the-negative, all re-confirmed this cycle: North Carolina has NO BIPA-equivalent biometric statute and NO comprehensive consumer-privacy act (H462 and S514 both failed), and House Bill 301 ("Social Media & AI Safety") passed the House 106-6 but remained pending in the Senate and is NOT law.

Summary of publicly-available regulatory text as of 2026-08-25. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2024

Maximum Penalty

State AI penalties now exist across four tracks. CRIMINAL: SL 2024-37 (HB 591, eff. Dec 1, 2024) criminalizes AI-generated CSAM including fully synthetic imagery (G.S. 14-190.17C — Class E felony to produce, distribute, receive, or possess with intent to distribute; Class H felony for simple possession) and deepfake NCII of adults (G.S. 14-190.5A), enforced by NC district attorneys. CIVIL/PLATFORM: SL 2025-84 (Art. 51A of Ch. 66, eff. Dec 1, 2025) exposes an operator to the greater of $10,000 per day per image or actual damages, plus attorney fees. INSURANCE: conduct falling short of NC DOI Bulletin 24-B-19 is pursued as an unfair trade or unfair claim settlement practice under Chapter 58, Article 63 and G.S. 58-63-15, with civil penalties under G.S. 58-2-70 of $100 to $1,000 per violation (each day a separate violation) plus court-ordered restitution and license suspension or revocation. CONSUMER: NCUDTPA (G.S. 75-1.1) carries mandatory treble damages in private actions (G.S. 75-16) and AG-sought civil penalties of up to $5,000 per knowing violation (G.S. 75-15.2). Federal FTC civil penalties up to $53,088 per violation. OCC/FDIC banking penalties can reach $1,000,000 per day.

What Your Business Must Do

10 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

North Carolina SL 2024-37 (HB 591) — AI-Generated CSAM + Deepfake NCII (Criminal)

High Priority

North Carolina Session Law 2024-37 (HB 591, "Modernize Sex Crimes"; signed by Gov. Roy Cooper July 8, 2024; effective Dec 1, 2024) is a private-binding criminal statute with two AI hooks. (1) It expands the CSAM definition of "material" (G.S. 14-190.13) to include "digital or computer-generated visual depictions" and creates a new obscene-minor-depiction offense (G.S. 14-190.17C, a Class E felony) that applies even where the depicted minor does not actually exist — reaching fully AI-generated CSAM and AI "child sex dolls" of identifiable minors. (2) It amends the disclosure-of-private-images statute (G.S. 14-190.5A) so that "image" includes a realistic visual depiction "created, adapted, or modified by technological means, including algorithms or artificial intelligence, such that a reasonable person would believe the image depicts an identifiable individual" (deepfake NCII of adults). The bill also adds sextortion offenses (G.S. 14-202.7). Enforced by NC district attorneys (criminal prosecution). Counsel should confirm the felony classes across the amended subsections and the Dec 1, 2024 effective date against the enacted session law. legal_review_pending.

Deadline: December 1, 2024

G.S. 14-190.13(2) (CSAM "material" definition extended to digital/computer-generated depictions created by algorithms or artificial intelligence), 14-190.13(1e) ("identifiable minor"), 14-190.16(a)(5) (first-degree sexual exploitation), 14-190.17(a)(2) (second-degree), 14-190.17A(a) (third-degree), 14-190.17C (obscene visual representation of sexual exploitation of a minor — Class E / Class H), 14-190.5A (disclosure of private images / deepfake NCII), 14-202.7 (sextortion), as amended/enacted by SL 2024-37 (HB 591); sentencing grid at G.S. 15A-1340.17

NC DOI Bulletin 24-B-19 — AI Systems in Insurance (NAIC Model AI Bulletin, adopted Dec 18, 2024)

High Priority

North Carolina adopted the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers as Department of Insurance Bulletin 24-B-19, issued by Commissioner of Insurance Mike Causey on December 18, 2024 and addressed to all insurers licensed to do business in North Carolina. The bulletin reminds every insurer holding a certificate of authority that decisions or actions impacting consumers that are made or supported by advanced analytical and computational technologies, including AI Systems, must comply with all applicable insurance laws and regulations — in particular those addressing unfair trade practices and unfair discrimination. It states the Department's expectation that insurers develop, implement, and maintain a written program (an "AIS Program") for the responsible use of AI Systems that make or support decisions related to regulated insurance practices, designed to mitigate the risk of "Adverse Consumer Outcomes". The AIS Program must address governance, risk management controls, and internal audit functions; vest responsibility for it with senior management accountable to the board or a board committee; be proportionate to the insurer's actual use of and reliance on AI; span the whole insurance life cycle (product development and design, marketing, use, underwriting, rating and pricing, case management, claim administration and payment, and fraud detection) and the whole AI System life cycle (design, development, validation, implementation, use, ongoing monitoring, updating, and retirement); cover AI Systems whether built in-house or supplied by a third-party vendor; and include processes for notifying impacted consumers that AI Systems are in use. The bulletin expressly permits an insurer to build its AIS Program on the NIST AI Risk Management Framework 1.0, and it defines the governance items an insurer should address, including committee structure across business, actuarial, data science, underwriting, claims, compliance, and legal disciplines, independence of decision-makers across life-cycle stages, monitoring and escalation protocols, personnel training, and — specifically for Predictive Models — documented methods for detecting and addressing errors, performance issues, outliers, and unfair discrimination. Section 4 of the bulletin sets out the information and documentation the Department may request in an AI-focused investigation or market conduct examination. Governance sensitivity: the bulletin phrases the AIS Program itself as an expectation ("strongly encouraged"), but the underlying obligation to avoid unfair trade practices and unfair claim settlement practices is statutory and mandatory, and the Department examines AI-driven decisions against it.

Deadline: December 18, 2024

NC DOI Bulletin 24-B-19 (Dec 18, 2024); N.C. Gen. Stat. Ch. 58, Art. 63 (unfair trade practices in the business of insurance); N.C. Gen. Stat. § 58-63-15 (unfair methods of competition and unfair or deceptive acts, incl. unfair claim settlement practices); Ch. 58, Art. 10, Part 11 (Corporate Governance Annual Disclosure); rating laws N.C.G.S. §§ 58-40-20, 58-51-95, 58-51-131, 58-65-40, 58-47-110; penalties at § 58-2-70

NC Identity Theft Protection Act (G.S. 75-61, 75-65) — Breach Notification for AI/ML Systems Holding Personal Information

High Priority

North Carolina's Identity Theft Protection Act governs any business that owns or licenses personal information of North Carolina residents — which includes the training corpora, feature stores, vector databases, model logs, and inference caches of AI/ML systems. The G.S. 75-61 definition of protected personal information couples a resident's first name or first initial and last name with identifiers including Social Security number, driver's license number, financial account or card number, PIN, password, and BIOMETRIC data; the express inclusion of biometric data is what pulls AI-based face, voice, and behavioural identification and authentication systems inside the statute. On a security breach, the business must notify affected residents without unreasonable delay — North Carolina sets no numeric deadline, allowing only the time reasonably needed to determine the scope of the breach, identify affected individuals, and restore the integrity of the system. Whenever residents are notified, the business must also notify the Consumer Protection Division of the Attorney General's Office, without unreasonable delay, and that notice must describe the nature of the breach, the number of consumers affected, the steps taken to investigate it, the steps taken to prevent a similar breach in future, and the timing, distribution, and content of the consumer notice. If more than 1,000 persons are notified at one time, the business must additionally notify all nationwide consumer reporting agencies. A violation is a violation of G.S. 75-1.1, so it carries the NCUDTPA remedy stack; a private action requires that the individual actually be injured by the violation, so a breach that causes no harm does not by itself support a suit.

N.C. Gen. Stat. § 75-61 (definitions, incl. biometric data as personal information), § 75-65 (protection from security breaches; consumer notice, AG Consumer Protection Division notice, 1,000-person consumer reporting agency threshold); remedies via § 75-1.1 and § 75-16

SL 2025-84 (HB 805) — Art. 51A of Ch. 66: Consent Verification, 72-Hour Removal, and Blocking of Altered/Edited Images (eff. Dec 1, 2025)

High Priority

North Carolina Session Law 2025-84 (House Bill 805, "Prevent Sexual Exploitation of Women and Minors Act"; enacted July 29, 2025 when the General Assembly overrode Governor Josh Stein's veto) created a new Article 51A of Chapter 66 of the General Statutes, G.S. 66-505 through 66-510, effective December 1, 2025. It binds operators of covered online entities that publish or distribute pornographic images — defined as a visual depiction of actual or feigned sexual activity or an intimate visual depiction. Before publishing such an image the operator must verify that each person appearing in it was not less than 18 years of age when the image was created, obtain explicit written evidence of consent for each act of sexual activity depicted, and obtain explicit written consent for the distribution of that specific image, using consent forms prepared by the Attorney General. The operator must review its records of previously published images against those requirements and remove images that do not conform. It must establish a removal-request process, designate employees to handle requests, and prominently display on the website how to request removal; on request by an eligible person the image must be removed not later than 72 hours, and where consent is questioned by a person who is not an eligible person the image is removed temporarily pending the operator's review procedure. THE AI HOOK: once an image is removed the operator must block from future distribution both that image and any altered or edited version of it — an obligation that reaches AI-generated, AI-altered, and deepfaked derivatives of the removed image, and that therefore requires operators to run derivative-detection rather than exact-hash matching. Counsel should confirm the covered-entity definitions and the scope of the blocking duty against the enacted session law before relying on this operationally.

Deadline: December 1, 2025

SL 2025-84 (HB 805); N.C. Gen. Stat. Ch. 66, Art. 51A, §§ 66-505 to 66-510 ("Prevent Sexual Exploitation of Women and Minors Act")

NCUDTPA (G.S. 75-1.1) — Unfair or Deceptive AI Practices, Mandatory Treble Damages

High Priority

North Carolina's Unfair and Deceptive Trade Practices Act, G.S. 75-1.1, is the state-law analogue to FTC Act § 5 and is the primary vehicle by which AI conduct is challenged in North Carolina in the absence of a comprehensive state AI statute. It reaches AI marketing claims that overstate capability or accuracy, undisclosed AI involvement in a consumer interaction, AI-driven pricing or steering that harms consumers, and — by the express bridge in the Identity Theft Protection Act — failures of breach notification. Two features make North Carolina exposure materially worse than a generic UDAP state and should drive AI risk assessment here. First, trebling is MANDATORY: G.S. 75-16 gives an injured person a right of action and requires the court to treble whatever actual damages are assessed, with no judicial discretion to decline. Second, a plaintiff who proves a violation of another Chapter 75 provision that is bridged into 75-1.1 does not have to separately establish that the conduct was unfair or deceptive — the statutory violation carries that element. The Attorney General enforces independently: G.S. 75-14 lets the AG sue to enjoin a practice alleged to violate 75-1.1 and lets the court order restoration of money or property and cancellation of contracts obtained through the violation, and G.S. 75-15.2 permits a discretionary civil penalty of up to $5,000 for each violation where the conduct was knowingly violative of a statute, or where it was specifically prohibited by a prior court order.

N.C. Gen. Stat. § 75-1.1 (unfair methods of competition and unfair or deceptive acts or practices in or affecting commerce); § 75-16 (private right of action; mandatory treble damages); § 75-14 (AG injunctive action; restoration of money or property, cancellation of contracts); § 75-15.2 (civil penalty up to $5,000 per knowing violation)

FTC Act § 5 — Deceptive or Unfair AI Practices

High Priority

FTC Act § 5 applies to all North Carolina businesses using AI. NC AG has expressed interest in AI deceptive practices enforcement and has broad powers under North Carolina Unfair and Deceptive Trade Practices Act (NCUDTPA, § 75-1.1). Ensure AI systems disclose their nature, AI marketing claims are truthful, and AI-driven pricing does not harm consumers.

15 U.S.C. § 45(a) (unfair/deceptive practices); civil-penalty authority § 45(l), § 45(m)(1)(A); N.C. Gen. Stat. § 75-1.1 (NCUDTPA)

OCC / FDIC — AI Risk Management in Banking (Charlotte Banking Sector)

High Priority

North Carolina's Charlotte banking sector — Bank of America, Truist, First Citizens Bank — is subject to OCC and FDIC AI guidance. OCC Bulletin 2021-12 (Third-Party Risk Management for AI) and FDIC guidance on AI in bank risk management require North Carolina banks to maintain AI model governance programs, conduct model validation, and manage third-party AI vendor risk. Bank AI systems affecting consumers trigger additional CFPB oversight.

12 U.S.C. § 1818(i) (OCC/FDIC civil money penalty authority); OCC Bulletin 2021-12; FDIC FIL-19-2023

EEOC / Title VII / ADA — AI Employment Screening Compliance

High Priority

EEOC May 2023 guidance applies to North Carolina employers using AI hiring, scheduling, or performance evaluation tools. North Carolina's Research Triangle tech sector (IBM, Lenovo, Cisco, SAS) and financial services companies using AI hiring must test for disparate impact. NC Equal Employment Practices Act (EEPA) provides independent state enforcement.

Title VII, 42 U.S.C. § 2000e-2; ADA, 42 U.S.C. § 12112; damages caps at 42 U.S.C. § 1981a(b)(3); NC Equal Employment Practices Act, N.C. Gen. Stat. § 143-422.2

FCRA / CFPB — AI Credit Decision Compliance

High Priority

North Carolina's banking sector — Bank of America (largest US bank by assets), Truist, First Citizens — is one of the most significant AI credit decision environments in the country. CFPB Circular 2022-03 requires specific adverse action reasons from the consumer's file. AI-driven mortgage, auto, and personal loan decisions must provide FCRA-compliant adverse action notices.

15 U.S.C. § 1681b(b)(3) (adverse action notice); §§ 1681n, 1681o (civil liability); CFPB Circular 2022-03

Monitor North Carolina AI Legislation and State-Agency AI Governance (Watch-List — Not Law)

Lower Priority

Monitor ncleg.gov. North Carolina has a large tech and banking presence and an unusually crowded AI bill docket, but as of this cycle NONE of the following is law, and none of it should be treated as a compliance obligation. HIGHEST-PROBABILITY WATCH ITEM: House Bill 301, retitled "Social Media & AI Safety", which would bar under-14s from creating social media accounts and require parental consent for 14- and 15-year-olds; it passed the House 106-6 but was still awaiting Senate action through 2026 and has continued to be revised — closest to enactment of any NC AI-adjacent bill, and worth pre-planning for. OTHER BILLS INTRODUCED IN THE 2025-2026 BIENNIUM AND NOT ENACTED, by theme: deepfakes (H375); comprehensive consumer data privacy (H462, S514) — which would have brought consent requirements for genetic and biometric data processing but did not pass; algorithmic rent-setting/price-fixing (H970); AI in health insurance and utilization review (S287, S315, S316); data-center electricity load (H638, H1002); AI curriculum in schools (S640); digital content authentication and provenance (S738); AI-generated robocalls (H936); AI workforce study (S746); AI developer safety duties (S735); AI research hubs (H1003); online child safety (S722); plus the AI Regulatory Reform Act (H934). SEPARATELY — GOVERNMENT-INTERNAL ONLY, DOES NOT BIND PRIVATE PARTIES: Governor Josh Stein's Executive Order No. 24 (September 2, 2025) created the North Carolina AI Leadership Council, established an AI Accelerator inside the Department of Information Technology, and required Cabinet agencies to stand up Agency AI Oversight Teams; NC DIT separately publishes the "North Carolina State Government Responsible Use of Artificial Intelligence Framework", which by its own terms covers state systems and excludes the legislative and judicial branches and the UNC system. Vendors selling AI into North Carolina state agencies should read both as procurement-adjacent expectations, not as regulation of their private-sector business.

Recent Enforcement Actions

2026-01-23Source verified· as of 2026-08-25

Against:

2025-08-25Source verified· as of 2026-08-25

Against:

Recent Regulatory Guidance

guidance2024-12-18

NC DOI Bulletin 24-B-19 — The Use of Artificial Intelligence Systems in Insurance (Commissioner Mike Causey, Dec 18, 2024)

North Carolina's adoption of the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers. Addressed to all insurers licensed to do business in North Carolina; sets out the Department's expectations for a written AIS Program covering governance, risk management controls and internal audit across the whole insurance and AI-system life cycle, permits reliance on the NIST AI Risk Management Framework 1.0, and describes in Section 4 the documentation the Department may request in an AI-focused investigation or market conduct examination. Confirmed as adopted on the NAIC implementation map dated August 6, 2026, which lists 25 adopting jurisdictions.

guidance2025-09-02

NC DIT — North Carolina State Government Responsible Use of Artificial Intelligence Framework (state agencies only)

Published by the North Carolina Department of Information Technology alongside Governor Stein's Executive Order No. 24 (September 2, 2025). Applies to state systems that use AI with the potential to impact North Carolinians' exercise of rights, and expressly excludes the legislative and judicial branches and the UNC system. It does NOT regulate private-sector AI use — it is relevant to vendors only as a procurement expectation when selling AI into North Carolina state agencies.

guidance2023-01-01

OCC: Model Risk Management Guidance — AI and Machine Learning (2021, updated 2023)

OCC guidance on model risk management specifically addresses AI and machine learning models used in banking — covering model development, validation, governance, and ongoing monitoring. Bank of America, Truist, and First Citizens Bank must apply these standards to all AI credit, risk, and compliance models used in North Carolina operations.

Frequently Asked Questions

Does North Carolina — State AI Law (SL 2024-37 AI-CSAM/deepfake NCII; DOI Bulletin 24-B-19 insurer AI; SL 2025-84 Art. 51A) + Breach/UDTPA + Federal Profile apply to my business?

North Carolina has no comprehensive/standalone private-sector AI statute as of June 2026, but it has enacted one AI-specific criminal law that binds private parties: Session Law 2024-37 (HB 591, "Modernize Sex Crimes"; signed by Gov. Roy Cooper July… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under North Carolina — State AI Law (SL 2024-37 AI-CSAM/deepfake NCII; DOI Bulletin 24-B-19 insurer AI; SL 2025-84 Art. 51A) + Breach/UDTPA + Federal Profile is: State AI penalties now exist across four tracks. CRIMINAL: SL 2024-37 (HB 591, eff. Dec 1, 2024) criminalizes AI-generated CSAM including fully synthetic imagery (G.S. 14-190.17C — Class E felony to produce, distribute, receive, or possess with intent to distribute; Class H felony for simple possession) and deepfake NCII of adults (G.S. 14-190.5A), enforced by NC district attorneys. CIVIL/PLATFORM: SL 2025-84 (Art. 51A of Ch. 66, eff. Dec 1, 2025) exposes an operator to the greater of $10,000 per day per image or actual damages, plus attorney fees. INSURANCE: conduct falling short of NC DOI Bulletin 24-B-19 is pursued as an unfair trade or unfair claim settlement practice under Chapter 58, Article 63 and G.S. 58-63-15, with civil penalties under G.S. 58-2-70 of $100 to $1,000 per violation (each day a separate violation) plus court-ordered restitution and license suspension or revocation. CONSUMER: NCUDTPA (G.S. 75-1.1) carries mandatory treble damages in private actions (G.S. 75-16) and AG-sought civil penalties of up to $5,000 per knowing violation (G.S. 75-15.2). Federal FTC civil penalties up to $53,088 per violation. OCC/FDIC banking penalties can reach $1,000,000 per day.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with North Carolina — State AI Law (SL 2024-37 AI-CSAM/deepfake NCII; DOI Bulletin 24-B-19 insurer AI; SL 2025-84 Art. 51A) + Breach/UDTPA + Federal Profile?

The 10 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://ncdoj.gov

Last updated: 2026-08-25 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan