Skip to content
Esta es una traduccion de conveniencia. La version en ingles es la version oficial y legalmente vinculante. Ver version en ingles
US-MIFEDERAL profile2 enforcement actions

Michigan — State AI + Consumer/Data Regimes (PA 263–266 of 2023 election AI eff 2024; PA 11–12 of 2025 intimate deepfakes; DIFS AI bulletins 2024-20-INS & 2026-03-BT/CF/CU; MCL 445.72 breach; MCPA post-Eli Lilly) + Federal AI Profile: AI Compliance Requirements

Michigan has no comprehensive cross-sector private-sector AI statute as of June 2026, but it has enacted two in-force AI-specific clusters that bind private actors. (1) ELECTION AI — Public Acts 263–266 of 2023 (HB 5141/5143/5144/5145; signed Nov 30, 2023; effective Feb 13, 2024) amend the Campaign Finance Act and Election Law to require a clear-and-conspicuous AI disclaimer on political advertisements created substantially with AI, and to prohibit distributing "materially deceptive media" (deepfakes) intended to influence an election within 90 days unless disclaimed — penalties escalate to a Class G felony (disclosure) and a Class E felony / up to 5 years (deepfake distribution), enforced via the Attorney General and Secretary of State with candidate injunctive relief. (2) INTIMATE DEEPFAKES — Public Acts 11–12 of 2025 ("Protection from Intimate Deep Fakes Act," HB 4047/4048; signed and immediately effective Aug 26, 2025) create criminal offenses and a private civil cause of action for nonconsensual creation/dissemination of AI- or digitally-generated sexually explicit images of a real, identifiable person (first offense misdemeanor up to 1 year/$3,000; aggravated → Class F felony up to 3 years). (Verify-the-negative: Michigan has NO enacted comprehensive employment-AI or chatbot-disclosure statute — HB 4608/SB 502 died; SB 760 (companion-chatbot restriction for minors, "Kids Over Clicks" package, SB 757-760) passed the Senate 20-17 on 2026-04-29/30 and was sent to the House, where no confirmed further action was found this cycle — CYCLE 18 CORRECTION: a prior version of this entry wrongly claimed SB 760 "was VETOED by Gov. Whitmer 2026-07-21" — that veto is a real event but involves nine UNRELATED 2024-era House bills [HB 4177/4665/4666/4667/4900/4901/5817/5818/6058] tied to a completely separate interbranch-transmission dispute, not SB 760 or any AI legislation; HB 4668, HB 5579 remain pending.) (3) INSURANCE AI — DIFS Bulletin 2024-20-INS (issued Aug 7, 2024) adopts the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers; it applies to all Insurers, Nonprofit Health Services Plans, HMOs and Dental Plan Organizations holding a Michigan certificate of authority, and expects a written AI Systems (AIS) Program covering governance, risk management, third-party AI oversight and documentation producible on examination. (4) FINANCIAL-SERVICES AI — DIFS Bulletin 2026-03-BT/CF/CU (issued Jan 14, 2026) extends the same AIS-Program expectations to DIFS-regulated depository institutions, mortgage brokers/lenders/servicers, money transmitters, licensed lenders, installment sellers and sales finance companies, credit card companies, debt management entities, deferred presentment (payday) providers, and Class I/II licensees under the Consumer Financial Services Act. (5) BREACH NOTIFICATION — the Identity Theft Protection Act (2004 PA 452, MCL 445.63, 445.72) requires notice to affected Michigan residents without unreasonable delay unless the breach has not caused and is not likely to cause substantial loss or injury or result in identity theft; notice to nationwide consumer reporting agencies is required when more than 1,000 Michigan residents are notified; NO Attorney General notice is required; $250 civil fine per knowing failure to notify, capped at $750,000 per breach. (6) CONSUMER PROTECTION — the Michigan Consumer Protection Act (MCL 445.901 et seq.) was substantially RESTORED on 2026-07-31: in Attorney General v Eli Lilly & Co, Docket No. 165961, the Michigan Supreme Court (4-3) overruled Smith v Globe Life (1999) and Liss v Lewiston-Richards (2007), ending the categorical "regulated industry" exemption — the MCL 445.904(1)(a) exemption now turns on whether the specific transaction or conduct alleged to be unlawful was specifically authorized, so insurers, lenders, auto dealers/manufacturers, mortgage and real-estate firms now face real MCPA exposure for AI-driven pricing, marketing and consumer practices. (Verify-the-negative, second pass: Michigan has NO enacted biometric-privacy statute and NO enacted comprehensive consumer-privacy law — SB 359/SB 659 (Personal Data Privacy Act) and SB 360 (Identity Theft Act amendments adding a 45-day notice window and AG notice) are pending, not law; the "Kids Over Clicks" minors/chatbot package SB 757-760 is not law — SB 760, the LEAD for Kids Act, passed the Senate 2026-04-29 and sits in the House Communications and Technology Committee.) Michigan has the largest auto-manufacturing AI deployment in the US (Ford, GM, Stellantis, all headquartered in Metro Detroit). Federal laws apply: FTC Act § 5, Title VII / ADA (employment AI — critical for Michigan manufacturing), FCRA (credit AI), COPPA (children's data). State employment-discrimination law also reaches AI screening outcomes via the Elliott-Larsen Civil Rights Act (1976 PA 453, MCL 37.2101–37.2804), which the DIFS 2026 bulletin itself cites. NLRB algorithmic management guidance applies to Michigan's heavily unionized UAW plants. Monitor legislature.mi.gov — Michigan AI employment legislation is likely.

Summary of publicly-available regulatory text as of 2026-08-25. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2024

Maximum Penalty

State AI penalties now exist: PA 263–266 of 2023 (eff Feb 13, 2024) — a political-ad AI-disclaimer violation is a first-offense misdemeanor of up to 90 days and a fine of up to $500, rising to a felony of up to 5 years and a fine of up to $1,000 for a further violation within 5 years; distributing materially deceptive media within 90 days of an election carries up to 5 years and a fine of up to $1,000 (MCL 168.932f), AG/SoS-enforced with candidate injunctive relief. PA 11–12 of 2025 (eff Aug 26, 2025) — nonconsensual intimate deepfakes: misdemeanor up to 1 year/$3,000, aggravated felony up to 3 years/$5,000 (a Class F felony on the sentencing guidelines), plus a private civil action with civil fines up to $1,000 per day for violating a TRO or permanent injunction. Data-breach notification (MCL 445.72): $250 civil fine for each knowing failure to give notice, aggregate liability capped at $750,000 for violations arising from the same breach, recoverable by the Attorney General or a prosecuting attorney. Michigan Consumer Protection Act (MCL 445.905): AG civil fine up to $25,000 for a persistent and knowing violation of MCL 445.903, and up to $5,000 for each knowing violation of an injunction, order, decree or judgment; private plaintiffs recover actual damages or $250, whichever is greater, plus reasonable attorney fees (MCL 445.911) — the $250 is a recovery FLOOR, not a penalty cap. Federal FTC civil penalties up to $53,088 per violation for violating a final order or rule.

What Your Business Must Do

11 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Michigan State AI Laws — Election AI (PA 263–266 of 2023), Intimate Deepfakes (PA 11–12 of 2025)

High Priority

Michigan has two in-force AI-specific statutory clusters binding private actors. (1) Public Acts 263–266 of 2023 (HB 5141/5143/5144/5145; signed Nov 30, 2023; effective Feb 13, 2024) amend the Michigan Campaign Finance Act and Election Law: any "qualified political advertisement" created substantially with AI must carry a clear-and-conspicuous AI disclaimer, and distributing "materially deceptive media" (deepfakes) intended to influence an election within 90 days is prohibited unless disclaimed (PA 265 adds MCL 168.932f to the Michigan Election Law, 1954 PA 116). A disclaimer violation is a first-offense misdemeanor of up to 90 days and a fine of up to $500, and a further violation within 5 years is a felony of up to 5 years and a fine of up to $1,000; distributing materially deceptive media carries up to 5 years and a fine of up to $1,000. Satire and parody are exempt, and a disclaimed distribution is permitted. Enforced via the Attorney General and Secretary of State with candidate injunctive relief. (2) Public Acts 11–12 of 2025 ("Protection from Intimate Deep Fakes Act," HB 4047/4048; signed and immediately effective Aug 26, 2025; codified MCL 752.383) create criminal offenses plus a private civil cause of action for nonconsensual creation/dissemination of AI- or digitally-generated sexually explicit images of a real, identifiable person (first offense misdemeanor up to 1 year/$3,000; aggravated factors → felony up to 3 years/$5,000, added to the sentencing guidelines as a Class F felony by PA 12). The civil cause of action accrues when the depicted individual DISCOVERS that the deep fake was created or disseminated, and supports economic and non-economic damages plus civil fines of up to $1,000 per day for violating a temporary restraining order or permanent injunction; the Act exempts uses such as legal proceedings and medical treatment, and certain internet-infrastructure providers, from its criminal and civil liability. R509 note: the earlier "Class G felony"/"Class E felony" labels for the election cluster were removed — no source reachable this session corroborated them, while three independent sources gave the statutory terms and fines now stated. legal_review_pending.

Deadline: February 13, 2024

Public Acts 263-266 of 2023 (HB 5141/5143/5144/5145), amending the Michigan Campaign Finance Act (1976 PA 388) and adding MCL 168.932f to the Michigan Election Law (1954 PA 116); Public Acts 11-12 of 2025 (HB 4047/4048), MCL 752.383

FTC Act § 5 — Deceptive or Unfair AI Practices

High Priority

FTC Act § 5 applies to all Michigan businesses using AI. Ensure AI systems disclose their nature, AI claims are truthful, and AI pricing does not engage in unfair practices. The parallel state track is the Michigan Consumer Protection Act (MCL 445.903) — modelled separately as mi_mcpa_deceptive_practices. R509 HONEST CORRECTION: a prior version of this description asserted that the Michigan AG "has pursued AI dark patterns and deceptive subscription cases" under the MCPA. No such case could be corroborated from any source reachable this round; the AG's verifiable AI activity is consumer-alert publication (see recentGuidance), and the AG's live MCPA litigation of record is the insulin-pricing investigation of Eli Lilly that produced the 2026-07-31 Supreme Court ruling. The unsupported claim is removed rather than restated.

15 U.S.C. § 45(a) (unfair/deceptive practices); civil-penalty authority § 45(l), § 45(m)(1)(A); MCL 445.903 (Michigan Consumer Protection Act)

EEOC / Title VII / ADA — AI Employment Screening in Auto Manufacturing

High Priority

Michigan's auto manufacturing sector (Ford, GM, Stellantis, Toyota) — the largest in the US — is deploying AI for hiring, production monitoring, and performance evaluation. EEOC May 2023 guidance requires employers to test AI employment tools for disparate impact on race, sex, age, and disability. Michigan HB 4608 (pending re-introduction) would require AI hiring transparency — implement proactively. Document vendor disparate impact test results.

Title VII, 42 U.S.C. § 2000e-2; ADA, 42 U.S.C. § 12112; damages caps at 42 U.S.C. § 1981a(b)(3)

NLRB / UAW — AI Algorithmic Management Bargaining Obligation

High Priority

NLRB GC Memo 23-02 (Oct. 2022) requires employers to bargain with unions before implementing AI algorithmic management, electronic surveillance, or AI-driven work measurement systems for unionized workers. Michigan's UAW-represented plants (Ford, GM, Stellantis) must negotiate before deploying AI production monitoring, AI-driven line speed management, or AI safety surveillance. Failure to bargain is an unfair labor practice.

NLRA § 8(a)(5), 29 U.S.C. § 158(a)(5) (duty to bargain); NLRB General Counsel Memo GC 23-02 (Oct. 2022)

Michigan DIFS Bulletin 2024-20-INS — NAIC Model AI Bulletin: Written AIS Program for Insurers

High Priority

Michigan adopted the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers as DIFS Bulletin 2024-20-INS, issued August 7, 2024. It applies to all Insurers, Nonprofit Health Services Plans, HMOs and Dental Plan Organizations holding a certificate of authority to do business in Michigan. Core proposition: where advanced analytical and computational technologies, including AI systems, are used to make or support decisions or actions that impact consumers, those decisions must comply with all applicable Michigan insurance laws and regulations — including those addressing unfair trade practices and unfair discrimination. DIFS expects each insurer to develop, implement and maintain a written Artificial Intelligence Systems Program (AIS Program) designed to mitigate the risk of adverse consumer outcomes, proportionate to the insurer's use of and reliance on AI, and covering governance and accountability across the AI lifecycle, risk management and internal controls, testing and validation for errors and bias, oversight of third-party AI systems and data, and documentation. The bulletin is principles-based: it does not prescribe specific practices or specific documentation formats, and insurers may demonstrate compliance by means other than those described. DIFS may request AIS Program documentation during market conduct examinations and investigations.

Deadline: August 7, 2024

Michigan DIFS Bulletin 2024-20-INS (issued 2024-08-07), adopting the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (NAIC-adopted 2023-12-04); Michigan Insurance Code, Unfair and Prohibited Trade Practices and Frauds, MCL 500.2001 et seq.

Michigan DIFS Bulletin 2026-03-BT/CF/CU — Written AIS Program for Financial Service Providers

High Priority

DIFS Bulletin 2026-03-BT/CF/CU, "Use of Artificial Intelligence Systems by Financial Service Providers," issued January 14, 2026, extends the AIS-Program architecture of the insurance bulletin to DIFS-regulated financial institutions. Covered entities are depository institutions; mortgage brokers, lenders and servicers; money transmission service providers; licensed lenders; installment sellers and sales finance companies; credit card companies; debt management entities; deferred presentment service providers (payday lenders); and Class I or II licensees under the Consumer Financial Services Act. The bulletin reaches AI use across the business cycle — product development, marketing, sales and distribution, deposits, lending, account servicing, management and fraud detection — and reminds providers that where AI systems make decisions or take actions affecting consumers, those decisions must comply with existing law, expressly including the Elliott-Larsen Civil Rights Act's prohibitions on discrimination. Providers are expected to maintain a written AIS Program tailored to their use of and reliance on AI, with senior management accountable to the board or an appropriate board committee, covering: governance (transparent policies and accountability structures across design, development, use and retirement); risk management and internal controls (oversight of AI adoption and development, data practices, security, validation and data retention, plus internal audit); testing and validation to identify errors, hallucinations and bias; and third-party AI oversight (due diligence before acquisition, contractual safeguards including audit rights and notification obligations, with the provider remaining ultimately accountable). The program may be embedded in enterprise risk management or aligned to a framework such as the NIST AI Risk Management Framework. On examination or investigation DIFS may request the written AIS Program, pre-acquisition due-diligence records, AI inventories and approvals, testing and validation results, monitoring and audit evidence, training records, governance materials and third-party contractual safeguards. Compliance expectations are immediate — the bulletin states no grace period.

Deadline: January 14, 2026

Michigan DIFS Bulletin 2026-03-BT/CF/CU (issued 2026-01-14); Elliott-Larsen Civil Rights Act, 1976 PA 453, MCL 37.2101 to 37.2804 (cited in the bulletin); Michigan Consumer Financial Services Act (Class I/II licensees)

Michigan Identity Theft Protection Act — Data Breach Notification (MCL 445.63, 445.72)

High Priority

Any person or agency that owns or licenses data including personal information about a Michigan resident must, following the discovery of a security breach, notify each affected Michigan resident. "Personal information" is a first name or first initial and last name combined with a Social Security number, a driver license or state personal identification card number, or a financial account, credit card or debit card number together with any required security code, access code or password. Notice is NOT required if the person or agency determines the breach has not caused, and is not likely to cause, substantial loss or injury to, or result in identity theft with respect to, Michigan residents. Notice must be given without unreasonable delay, consistent with the measures necessary to determine the scope of the breach and restore reasonable integrity to the data system, and may be delayed at the request of law enforcement. The notice must describe the security breach in general terms, describe the type of personal information subject to unauthorized access or use, generally describe what the notifying entity has done to protect data from further breaches (if applicable), include a telephone number where a recipient may obtain assistance or additional information, and remind recipients to remain vigilant for incidents of fraud and identity theft. Written notice to the recipient's most recent known address, or electronic notice where email is the primary means of communication or where the notice complies with federal e-signature requirements, are the ordinary methods; substitute notice (email, conspicuous website posting and notice to major statewide media) is available where the cost of notice would exceed $250,000 or more than 500,000 Michigan residents would have to be notified. If more than 1,000 Michigan residents are notified of a single breach, the entity must also notify each nationwide consumer reporting agency. HONEST NEGATIVE (R509): Michigan does NOT require notice to the Attorney General — this was checked directly because AG notice was hypothesised at the start of the round, and two independent state-law digests confirm no regulator notice is required under the Act as it currently stands. Pending SB 360 would change this by imposing a uniform 45-day window for both residents and the AG, but it is not law.

Michigan Identity Theft Protection Act, 2004 PA 452 — MCL 445.63 (definitions of "personal information" and "security breach"), MCL 445.72 (notice of security breach; content; substitute notice; consumer reporting agency notice; civil fine)

Michigan Consumer Protection Act — AI Deception and the Post-Eli Lilly Collapse of the Regulated-Industry Exemption

High Priority

The Michigan Consumer Protection Act prohibits unfair, unconscionable or deceptive methods, acts and practices in the conduct of trade or commerce (MCL 445.903), which reaches AI-driven pricing, marketing claims, undisclosed AI interaction, synthetic endorsements and dark patterns aimed at Michigan consumers. For twenty-seven years the Act was largely inert against regulated businesses: Smith v Globe Life Ins Co, 460 Mich 446 (1999) and Liss v Lewiston-Richards, Inc, 478 Mich 203 (2007) read the MCL 445.904(1)(a) exemption for conduct "specifically authorized under laws administered by a regulatory board or officer acting under statutory authority of this state or the United States" to exempt entire regulated INDUSTRIES — insurance, residential building, car sales and manufacturing, mortgage lending, real estate, medicine, plumbing, grocery, casinos and pesticide application among them — leaving Michigan consumer law rated among the weakest in the country. On July 31, 2026, in Attorney General v Eli Lilly & Co, Docket No. 165961, the Michigan Supreme Court overruled both decisions 4-3. The test is now whether the SPECIFIC transaction or conduct alleged to be unlawful was specifically authorized, not whether the defendant operates in a generally regulated field. Practical consequence for AI compliance: a Michigan insurer, lender, auto dealer or manufacturer, mortgage or real-estate firm, health provider or retailer can no longer treat its licence as a categorical MCPA defence to a claim that its AI-driven pricing, targeting, marketing or servicing practice was unfair or deceptive. Expect increased Attorney General enforcement and private consumer class actions. The underlying dispute — the AG's investigation into whether Eli Lilly artificially inflated insulin list prices — is itself a pricing-conduct case, the same shape as an algorithmic-pricing claim.

Deadline: July 31, 2026

Michigan Consumer Protection Act, 1976 PA 331 — MCL 445.901 et seq.; MCL 445.903 (unfair, unconscionable or deceptive methods, acts and practices); MCL 445.904(1)(a) (specifically-authorized-conduct exemption); MCL 445.905 (AG injunctions and civil fines); MCL 445.911 (private and class actions); Attorney General v Eli Lilly & Co, Docket No. 165961 (Mich. Sup. Ct., July 31, 2026), overruling Smith v Globe Life Ins Co, 460 Mich 446 (1999) and Liss v Lewiston-Richards, Inc, 478 Mich 203 (2007)

FCRA / CFPB — AI Auto Lending and Credit Compliance

Medium Priority

Michigan's large auto finance sector (Ford Motor Credit, GM Financial, Ally Financial) using AI for credit decisions must comply with FCRA adverse action notice requirements. CFPB Circular 2022-03 requires specific adverse action reasons — not generic model outputs. Michigan's financial institutions and fintech companies must provide consumer-file-specific reasons when AI denies or limits credit.

15 U.S.C. § 1681b(b)(3) (adverse action notice); §§ 1681n, 1681o (civil liability); CFPB Circular 2022-03

Elliott-Larsen Civil Rights Act — State Discrimination Exposure for AI Screening and Scoring

Medium Priority

The Elliott-Larsen Civil Rights Act is Michigan's own anti-discrimination statute and applies to AI-produced outcomes independently of federal law. It prohibits discrimination on the basis of religion, race, colour, national origin, age, sex, sexual orientation, gender identity or expression, and marital status, in employment and in other covered areas. Michigan DIFS expressly cites it in Bulletin 2026-03-BT/CF/CU as law that AI systems used in consumer-affecting decisions must satisfy, and the Michigan Civil Rights Commission adopted Guiding Principles on AI bias on October 21, 2024 warning that AI systems tend to incorporate biased data and perpetuate discriminatory outcomes in areas including hiring, housing and insurance. Practical compliance posture: an employer or provider deploying AI screening, ranking, scoring or monitoring in Michigan should assume state-law exposure for discriminatory outcomes even where the federal threshold questions (e.g. Title VII / ADA employer size) are not met, and should preserve disparate-impact testing evidence for the Michigan protected classes, which include categories federal law does not cover.

Elliott-Larsen Civil Rights Act, 1976 PA 453, MCL 37.2101 to 37.2804 — MCL 37.2202 (employer prohibited practices); MCL 37.2801 (civil action for injunctive relief or damages, damages defined to include reasonable attorney fees); MCL 37.2802 (costs of litigation, attorney and witness fees); Michigan Civil Rights Commission Resolution Adopting MDCR Guiding Principles on AI (2024-10-21)

Monitor Michigan AI Legislation

Lower Priority

Michigan watch-list, re-verified R509 (2026-08-25) — every item below is PENDING, none is law: (a) SB 757-760, the "Kids Over Clicks" package unveiled late January 2026 — SB 758-759 are the Kids Code Act (minors' data/safety defaults, parental controls) and SB 760 is the Leading Ethical AI Development (LEAD) for Kids Act (age verification before minors access AI chatbots, bar on companion chatbots capable of encouraging self-harm, illegal activity or sexually explicit interaction, direct parental right of action); SB 760 cleared Senate committee in March 2026, PASSED THE SENATE 2026-04-29, and now sits in the House Communications and Technology Committee. (b) HB 4668, the Artificial Intelligence Safety and Security Transparency Act (introduced 2025-06-24), targeting developers spending $100M+ annually on foundation models, with safety protocols, transparency reports and whistleblower protection. (c) HB 5579 (introduced February 2026), restricting AI employee monitoring and automated employment decisions with consent requirements, data-collection limits and a retention cap. (d) SB 359 / SB 659, the Personal Data Privacy Act — Michigan's first comprehensive consumer-privacy framework, covering biometric and genetic data; Michigan has NO enacted biometric-privacy statute and this is the vehicle to watch. (e) SB 360, amending the Identity Theft Protection Act to impose a uniform 45-day breach-notice window for residents AND the Attorney General, expand "personal information" to passport numbers, health records, insurance identifiers, online-account credentials and authentication biometrics, mandate reasonable security procedures with a designated coordinator, and add $2,000 fines for failure to maintain security procedures or to investigate a breach. (f) Earlier employment-AI bills HB 4608 and SB 502 died and have not been re-enacted. Monitor legislature.mi.gov.

Recent Enforcement Actions

2026-07-31Source verified· as of 2026-08-25

Against:

Source
2023-02-21Source verified· as of 2026-08-25

Against:

Source

Recent Regulatory Guidance

guidance2024-08-07

Michigan DIFS Bulletin 2024-20-INS — Use of Artificial Intelligence Systems by Insurers (NAIC Model AI Bulletin adoption)

Michigan adopted the NAIC Model AI Bulletin on 2024-08-07. Confirmed against the primary NAIC implementation map ("Implementation of NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers," status as of April 1, 2026), where Michigan appears in the 25-jurisdiction "Adopted" set and the reference list reads "Michigan: Bulletin 2024-20-INS — Adopted August 7, 2024." Applies to all Insurers, Nonprofit Health Services Plans, HMOs and Dental Plan Organizations holding a Michigan certificate of authority; expects a written AIS Program covering governance, risk management and internal controls, testing for error and bias, third-party AI oversight and documentation producible on market conduct examination. Principles-based: it does not prescribe specific practices or documentation formats.

Source
guidance2026-01-14

Michigan DIFS Bulletin 2026-03-BT/CF/CU — Use of Artificial Intelligence Systems by Financial Service Providers

Issued 2026-01-14, extending NAIC-style AI governance expectations beyond insurance to DIFS-regulated banks and credit unions, mortgage brokers/lenders/servicers, money transmitters, licensed lenders, installment sellers and sales finance companies, credit card companies, debt management entities, payday lenders and Consumer Financial Services Act Class I/II licensees. Requires a written AIS Program with senior management accountable to the board, covering governance across the AI lifecycle, risk management and internal audit, testing for errors, hallucinations and bias, and third-party due diligence with contractual audit and notification rights. Examiners may request the program, due-diligence records, AI inventories and approvals, testing results, monitoring evidence, training records and vendor safeguards. Cites the Elliott-Larsen Civil Rights Act as governing anti-discrimination law. Compliance expectations are immediate; no grace period.

guidance2024-10-21

Michigan Civil Rights Commission — Resolution Adopting MDCR Guiding Principles for the Elimination and Prevention of AI Bias and Discrimination

Adopted 2024-10-21. NON-BINDING: it carries no force of law and is recorded here as the state civil-rights regulator's stated framework, not as a requirement. The resolution warns that unless purposefully addressed, "the tendency of Artificial Intelligence systems to incorporate biased and discriminatory data will result in the perpetuation of discriminatory outcomes with serious implications for the civil rights of Michigan citizens." Its principles include that AI should not be the sole tool used to evaluate people for housing, hiring or insurance; that data collection should be limited to what is strictly necessary for the specific context and monitored by a designated task force; that people should be able to opt out of AI-driven automated systems in favour of a human alternative with accommodations for persons with disabilities; and that legislation should prevent algorithmic discrimination. MDCR ran a follow-on AI summit on 2026-06-18.

guidance2026-04-20

Michigan Attorney General — Artificial Intelligence and Scams Consumer Alert (reissued 2026-03-04 and 2026-04-20)

AG Dana Nessel first issued this alert in December 2023 and has reissued it repeatedly, most recently on 2026-03-04 and again on 2026-04-20 during Money Smart Week. SCOPE NOTE (R509): this is a CONSUMER-facing alert about AI-enabled fraud — deepfake audio and video, voice cloning from public social-media audio, caller-ID spoofing to impersonate a relative in distress, and demands for payment in cryptocurrency, gift cards or wire transfer. It is not business-facing regulatory guidance and imposes no compliance obligation. It is recorded because it is the AG's only verifiable, recurring AI output and it signals where Michigan AG consumer-protection attention sits.

guidance2022-10-31

NLRB GC Memo 23-02: Electronic Monitoring and Algorithmic Management (Oct. 2022)

NLRB General Counsel established that employers must bargain with unions before implementing AI algorithmic management or electronic surveillance for unionized workers. Critical guidance for Michigan's UAW-represented Ford, GM, and Stellantis plants deploying AI production monitoring, AI-driven performance management, and AI safety systems.

Frequently Asked Questions

Does Michigan — State AI + Consumer/Data Regimes (PA 263–266 of 2023 election AI eff 2024; PA 11–12 of 2025 intimate deepfakes; DIFS AI bulletins 2024-20-INS & 2026-03-BT/CF/CU; MCL 445.72 breach; MCPA post-Eli Lilly) + Federal AI Profile apply to my business?

Michigan has no comprehensive cross-sector private-sector AI statute as of June 2026, but it has enacted two in-force AI-specific clusters that bind private actors. (1) ELECTION AI — Public Acts 263–266 of 2023 (HB 5141/5143/5144/5145; signed Nov… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Michigan — State AI + Consumer/Data Regimes (PA 263–266 of 2023 election AI eff 2024; PA 11–12 of 2025 intimate deepfakes; DIFS AI bulletins 2024-20-INS & 2026-03-BT/CF/CU; MCL 445.72 breach; MCPA post-Eli Lilly) + Federal AI Profile is: State AI penalties now exist: PA 263–266 of 2023 (eff Feb 13, 2024) — a political-ad AI-disclaimer violation is a first-offense misdemeanor of up to 90 days and a fine of up to $500, rising to a felony of up to 5 years and a fine of up to $1,000 for a further violation within 5 years; distributing materially deceptive media within 90 days of an election carries up to 5 years and a fine of up to $1,000 (MCL 168.932f), AG/SoS-enforced with candidate injunctive relief. PA 11–12 of 2025 (eff Aug 26, 2025) — nonconsensual intimate deepfakes: misdemeanor up to 1 year/$3,000, aggravated felony up to 3 years/$5,000 (a Class F felony on the sentencing guidelines), plus a private civil action with civil fines up to $1,000 per day for violating a TRO or permanent injunction. Data-breach notification (MCL 445.72): $250 civil fine for each knowing failure to give notice, aggregate liability capped at $750,000 for violations arising from the same breach, recoverable by the Attorney General or a prosecuting attorney. Michigan Consumer Protection Act (MCL 445.905): AG civil fine up to $25,000 for a persistent and knowing violation of MCL 445.903, and up to $5,000 for each knowing violation of an injunction, order, decree or judgment; private plaintiffs recover actual damages or $250, whichever is greater, plus reasonable attorney fees (MCL 445.911) — the $250 is a recovery FLOOR, not a penalty cap. Federal FTC civil penalties up to $53,088 per violation for violating a final order or rule.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Michigan — State AI + Consumer/Data Regimes (PA 263–266 of 2023 election AI eff 2024; PA 11–12 of 2025 intimate deepfakes; DIFS AI bulletins 2024-20-INS & 2026-03-BT/CF/CU; MCL 445.72 breach; MCPA post-Eli Lilly) + Federal AI Profile?

The 11 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://michigan.gov/ag

Last updated: 2026-08-25 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan