Skip to content
これは参考訳です。英語版が正式かつ法的拘束力を持つ公式バージョンです。 英語版を表示
US-MNMEDIUM coverage

Minnesota — Consumer Data Privacy Act (§§ 325M.10-.21, profiling rights), Social Media Transparency (§§ 325M.33/.335), Nudification Ban (§ 325E.91), Deepfake Election Law (§ 609.771) + MHRA: AI Compliance Requirements

ROUND 517 (2026-08-25) rebuilt this entry around the obligation that actually binds most Minnesota businesses and that the entry previously omitted entirely: the Minnesota Consumer Data Privacy Act, Minn. Stat. §§ 325M.10 to 325M.21 (NOT "chapter 325O" — no such chapter exists), added by Laws 2024, ch. 121, art. 5 and in force since July 31, 2025. It applies to entities doing business in Minnesota or targeting Minnesota residents that either control/process the personal data of 100,000+ consumers (excluding data processed solely to complete a payment transaction) or derive over 25% of gross revenue from selling personal data while processing data of 25,000+ consumers. Its distinguishing feature — rarer than any other US state privacy law and the reason AI deployers should read it before the more famous statutes — is § 325M.14, subd. 1(g): where personal data is profiled in furtherance of decisions producing legal or similarly significant effects, the consumer has the right "to question the result of the profiling, to be informed of the reason that the profiling resulted in the decision," to be told what actions they might have taken and might take in future to secure a different decision, to review the personal data used in the profiling, and — if the decision was based on inaccurate personal data — to have the data corrected and "the profiling decision reevaluated based upon the corrected data." That is a substantive right to contest and force re-run of an automated decision, not merely an opt-out. Subd. 1(h) separately grants a right to a list of the SPECIFIC third parties to which the controller disclosed the consumer's data. Subd. 3 requires honoring universal opt-out preference signals; subd. 4 sets a 45-day response deadline (one 45-day extension). Section 325M.18 requires a documented privacy policy naming the controller's chief privacy officer, a maintained data inventory, and data privacy and protection assessments the Attorney General can demand by civil investigative demand. Section 325M.17 reaches even SBA-defined small businesses (otherwise excluded) with a flat ban on selling sensitive data without prior consent. Enforcement is AG-exclusive at up to $7,500 per violation with NO private right of action, and the 30-day warning-letter cure period EXPIRED January 31, 2026 — Minnesota is now a no-cure state. Postsecondary institutions regulated by the Office of Higher Education have until July 31, 2029. Minnesota also now bans AI "nudification technology" (Minn. Stat. § 325E.91, added by Laws 2026, ch. 72, § 1, signed May 7, 2026, effective August 1, 2026) with AG civil penalties up to $500,000 per violation and a private right of action; xAI sued to enjoin it on First Amendment grounds and LOST its TRO bid on July 31, 2026, so the ban took effect on schedule (see caseCitations). Chapter 325M also carries a Social Media Manipulation subchapter (§§ 325M.30-.34) requiring platforms to publicly disclose how their algorithmic ranking systems weight content-quality assessments (§ 325M.33), and — since July 1, 2026 — a mental health warning label on each access (§ 325M.335). Minnesota has NO BIPA-style biometric statute and, verified against the NAIC's own August 6, 2026 adoption map, has NOT adopted the NAIC AI model bulletin and issues no insurance-specific AI guidance. Minnesota Statute § 609.771 (enacted as HF 1370, Laws 2023 Chapter 58, effective August 1, 2023) makes it a CRIME — not a disclosure/labeling requirement — to disseminate a "deep fake" (realistic synthetic media) depicting a candidate's speech or conduct without that person's consent, with intent to injure the candidate or influence an election, during the window from 90 days before precinct caucuses/conventions through the election. There is no "unless labeled" safe harbor. Criminal penalties: up to 90 days/$1,000 fine (base offense), up to 364 days/$3,000 (intent to cause violence), up to 5 years/$10,000 (repeat within 5 years); convicted candidates face forfeiture of office and disqualification. Subdivision 4 also authorizes CIVIL injunctive/equitable relief sought by the Attorney General, county/city attorneys, the depicted individual, or an injured candidate — a limited private right of action for an injunction, not damages. Separately, Minnesota has no comprehensive AI employment law, but the Minnesota Human Rights Act (MHRA) applies to discriminatory AI use in hiring — employers using AI screening tools must be able to demonstrate the tools do not have disparate impact on protected classes. No comprehensive Minnesota AI law has passed as of July 2026 (web-verified 2026-07-01), but the Legislature has active proposals including the Minnesota Artificial Intelligence Transparency Act. Monitor revisor.mn.gov for updates.

Summary of publicly-available regulatory text as of 2026-08-25. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

August 1, 2023

Maximum Penalty

Nudification technology (Minn. Stat. § 325E.91): AG-enforced civil penalty up to $500,000 per violation — the largest per-violation exposure in this entry — plus a private right of action for the depicted individual. MCDPA (Minn. Stat. § 325M.20): AG-only civil penalty up to $7,500 per violation, no private right of action; the 30-day warning-letter cure period EXPIRED January 31, 2026. Election deepfake (Minn. Stat. § 609.771): criminal — up to $1,000/90 days (base), up to $3,000/364 days (intent to cause violence), up to $10,000/5 years (repeat offense); candidates convicted forfeit office. Civil injunctive relief (not damages) available to the AG, county/city attorneys, the depicted individual, or an injured candidate. Social media transparency (§§ 325M.33/.335): AG investigation and action under § 325M.34; the statute specifies no penalty figure and creates no private cause of action for § 325M.33 violations. Employment discrimination: MHRA remedies including back pay, damages, and injunctive relief.

What Your Business Must Do

11 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

MCDPA — Right to Question, Explain and Re-Run a Profiling Decision (§ 325M.14, subd. 1(g))

Critical

This is the single most demanding automated-decision provision in any US state consumer privacy law and it has no analogue in the Virginia/Colorado/Connecticut model. Where a consumer's personal data "is profiled in furtherance of decisions that produce legal effects concerning a consumer or similarly significant effects concerning a consumer," Minn. Stat. § 325M.14, subd. 1(g) gives that consumer the right (i) "to question the result of the profiling"; (ii) "to be informed of the reason that the profiling resulted in the decision"; (iii) where feasible, to be informed "of what actions the consumer might have taken to secure a different decision and the actions that the consumer might take to secure a different decision in the future"; (iv) "to review the consumer's personal data used in the profiling"; and (v) where the decision is determined to have been based on inaccurate personal data, "to have the data corrected and the profiling decision reevaluated based upon the corrected data." Opt-out alone does not discharge this — a Minnesota consumer can force a controller to explain a model output and re-run the decision on corrected inputs. Operationally this requires per-decision logging of the inputs and the reason factors, a human-reachable channel to receive challenges, and a re-adjudication path. Note the trigger is PROFILING in furtherance of a significant decision, not "solely automated" decision-making — a human in the loop does not by itself take a system outside subd. 1(g). Separately, subd. 1(h) grants a right to obtain a list of the specific third parties to which the controller disclosed the consumer's personal data (a generic list of third parties is permitted only where the controller does not maintain the information consumer-specifically).

Deadline: July 31, 2025

Minn. Stat. § 325M.14, subd. 1(g) and 1(h) (Laws 2024, ch. 121, art. 5)

MCDPA — Documented Privacy Policy, Named Chief Privacy Officer, Data Inventory and Assessments (§ 325M.18)

Critical

Section 325M.18(a) requires a controller to "document and maintain a description of the policies and procedures the controller has adopted to comply with sections 325M.10 to 325M.21," and that description must include, where applicable, "the name and contact information for the controller's chief privacy officer or other individual with primary responsibility for directing the policies and procedures" — a named-accountable-person requirement that most state privacy laws do not impose. It must also describe policies and procedures that reflect § 325M.16 and that are designed to build the Act's requirements into system design, provide personal data to consumers on request, maintain reasonable administrative, technical and physical security "including the maintenance of an inventory of the data that must be managed" (an express data-inventory mandate), limit collection to what is adequate, relevant and reasonably necessary, prevent retention of data no longer relevant and reasonably necessary, and identify and remediate violations. Section 325M.18(b) requires a documented data privacy and protection assessment for targeted advertising, sale of personal data, processing sensitive data, any processing presenting a heightened risk of harm, and profiling where it presents a reasonably foreseeable risk of unfair or deceptive treatment or disparate impact, financial/physical/reputational injury, offensive intrusion on solitude or private affairs, or other substantial injury. Paragraph (d) requires weighing the benefits of processing to controller, consumer, other stakeholders and the public against the risks to the consumer as mitigated by safeguards, factoring in use of deidentified data, reasonable consumer expectations, processing context and the controller-consumer relationship. Paragraph (e) requires the assessment to include the paragraph (a) policy description. Paragraph (f) lets the Attorney General demand any relevant assessment by civil investigative demand; assessments are nonpublic data under Minn. Stat. § 13.02, subd. 9, and disclosure does not waive attorney-client privilege or work product. Paragraphs (g)-(h) allow reuse of assessments done for other laws with similar scope and effect, and a single assessment covering multiple comparable processing operations.

Deadline: July 31, 2025

Minn. Stat. § 325M.18 (History: 2024 c 121 art 5 s 10); cross-refs Minn. Stat. §§ 325M.16, 325M.19, 13.02 subd. 9

MCDPA Enforcement — AG-Exclusive, $7,500 per Violation, Cure Period EXPIRED (§ 325M.20)

Critical

Section 325M.20 vests enforcement exclusively in the Attorney General and provides that a violator is "liable for a civil penalty of not more than $7,500 for each violation." The Act expressly provides that nothing in §§ 325M.10 to 325M.21 establishes a private right of action. The compliance-relevant point for 2026 planning is the cure structure: before bringing an action the Attorney General was required to issue a warning letter identifying the alleged violations and allow 30 days to remedy them — but that warning-letter requirement EXPIRED ON JANUARY 31, 2026. That date has now passed. Minnesota is therefore a no-cure jurisdiction as of this entry's verification date: an MCDPA violation is directly actionable with no statutory right to a pre-suit fix, which materially raises the cost of discovering a gap late. Entities that deferred MCDPA build-out on the assumption a warning letter would arrive first no longer have that cushion.

Deadline: January 31, 2026

Minn. Stat. § 325M.20 (attorney general enforcement); cure-period sunset January 31, 2026

AI Nudification Technology Ban — In Force Since August 1, 2026 (§ 325E.91)

Critical

Minn. Stat. § 325E.91, added by Laws 2026, ch. 72, § 1 (signed May 7, 2026; effective August 1, 2026), is the first state ban of its kind in the nation. It makes it unlawful for a person who owns or operates a website, application, software, program or other service to make available to users the ability to "nudify" an image or video of an identifiable individual, or to do so on a user's behalf, and it prohibits advertising such a service. Nudification is defined in terms of an image or video being altered or generated to depict an intimate part not depicted in the original unaltered image or video of an identifiable individual. An exception applies where the service requires the substantial application of technological or artistic skill by a human creator directing and controlling the output — a narrow carve-out for general-purpose creative tools, not a safe harbour for a filtered general model. The Attorney General may seek civil penalties up to $500,000 per violation, and the depicted individual has a private right of action for damages including mental anguish, punitive damages and attorney fees. LITIGATION POSTURE, stated honestly: xAI filed a First Amendment challenge in the US District Court for the District of Minnesota on July 28, 2026, arguing the statute is overbroad and imposes strict liability on platform operators regardless of terms-of-service prohibitions or technical controls. Judge Donovan W. Frank DENIED xAI's temporary restraining order on July 31, 2026, reasoning that xAI's delay in seeking emergency relief undermined the claim of urgency. The statute therefore took effect on schedule and is enforceable now; the merits of the constitutional challenge remain undecided and no injunction is in place.

Deadline: August 1, 2026

Minn. Stat. § 325E.91 (Laws 2026, ch. 72, s. 1); cf. 47 U.S.C. § 230 (expressly preserved by the act)

MCDPA — Applicability Thresholds and Exclusions (§ 325M.12)

High Priority

Determine MCDPA applicability before building any of the other controls. Section 325M.12 applies the Act to legal entities that conduct business in Minnesota or produce products or services targeted to Minnesota residents AND satisfy one or more thresholds: (1) during a calendar year, control or process personal data of 100,000 consumers or more, "excluding personal data controlled or processed solely for the purpose of completing a payment transaction"; or (2) derive over 25 percent of gross revenue from the sale of personal data and process or control personal data of 25,000 consumers or more. The payment-transaction carve-out in threshold (1) is a real narrowing that retailers frequently miscount. Entity-level exclusions include government entities and federally recognized Indian tribes, banks/credit unions and other financial institutions, insurance companies and producers, health care providers as to protected health information, consumer reporting agencies acting under the FCRA, and small businesses as defined by the US Small Business Administration under 13 CFR part 121. Data-level exclusions include HIPAA protected health information, Driver's Privacy Protection Act data, FERPA records, Gramm-Leach-Bliley data, and personal data of employees and job applicants processed solely within the employment context — the last of which is why the MHRA item in this entry, not the MCDPA, governs AI hiring tools in Minnesota. Small businesses are excluded from the Act generally but remain bound by § 325M.17 (see separate requirement).

Deadline: July 31, 2025

Minn. Stat. § 325M.12 (scope; exclusions); small-business definition at 13 C.F.R. pt. 121

MCDPA — Consumer Rights Intake, 45-Day Response, and Universal Opt-Out Signals (§ 325M.14, subds. 2-4)

High Priority

Beyond the profiling right, § 325M.14, subd. 1 provides the rights to confirm processing and access data, to correct inaccurate data, to delete, to obtain a portable copy where processing is automated, and to opt out of targeted advertising, sale of personal data, and "profiling in furtherance of automated decisions that produce legal effects concerning a consumer or similarly significant effects." Subd. 4(d) requires a controller to comply with an opt-out request "as soon as feasibly possible, but no later than 45 days of receipt of the request," and subd. 4(e) sets the same 45-day clock for requests generally with one additional 45-day extension where reasonably necessary given complexity or volume. Subd. 4(b) requires one or more secure and reliable request channels, and subd. 4(c) forbids requiring a consumer to create a NEW account to exercise a right (though an existing account may be required). Subd. 3 requires controllers to honor an opt-out preference signal sent by a platform, technology, or mechanism with the consumer's consent; the mechanism must not use a default setting but require an affirmative, freely given, unambiguous choice, and a controller that recognizes opt-out preference signals approved under other state laws is in compliance. Parents/guardians may exercise rights for a known child, and guardians/conservators for a consumer under guardianship (subd. 2(b)-(c)); authorized agents may be designated by browser setting or extension (subd. 2(d)).

Deadline: July 31, 2025

Minn. Stat. § 325M.14, subds. 1-4 (rights; exercising rights; universal opt-out mechanisms; controller response)

MCDPA — Small Businesses May Not Sell Sensitive Data Without Prior Consent (§ 325M.17)

High Priority

A trap for entities that correctly conclude they are outside the MCDPA. Small businesses as defined by the US Small Business Administration under 13 C.F.R. part 121 are excluded from the Act generally by § 325M.12, but § 325M.17(a) provides that a small business "that conducts business in Minnesota or produces products or services that are targeted to residents of Minnesota, must not sell a consumer's sensitive data without the consumer's prior consent." Paragraph (b) applies the § 325M.20 penalties and Attorney General enforcement procedures to a small business that violates the section. There is no consumer-count or revenue threshold on this duty — it reaches any SBA-small business touching Minnesota residents. Practical effect: a small AI or adtech vendor that monetizes precise geolocation, biometric or health-adjacent inference data must obtain prior consent even though none of the Act's other machinery applies to it.

Deadline: July 31, 2025

Minn. Stat. § 325M.17 (requirements for small businesses); 13 C.F.R. pt. 121

Social Media Algorithmic Ranking Disclosure and Mental Health Warning Label (§§ 325M.33, 325M.335)

High Priority

Chapter 325M carries a Social Media Manipulation subchapter (§§ 325M.30-.34) that is separate from the MCDPA and reaches recommender systems directly. Section 325M.33 (Laws 2024, ch. 114, art. 3, s. 66) requires a covered social media platform to publicly and conspicuously post on its website an explanation of how it limits excessive account interactions; an explanation of how it assesses the quality of content and of how those assessments are utilised "in each of the social media platform's algorithmic ranking system, including how the assessments are weighted in relation to other signals"; usage statistics across percentiles of users; an explanation of how it determines whether a notification is time sensitive; and a description of all product experiments conducted on 1,000 or more users. The algorithmic-weighting disclosure is the operative AI provision — it obliges a platform to describe the signal weighting inside its ranking model, not merely to state that a ranking model exists. Section 325M.335 (Laws 2025, 1st Spec. Sess., ch. 3, art. 19, s. 13), effective July 1, 2026 and therefore already live, requires a mental health warning label warning users of potential negative mental health impacts of accessing the platform and providing access to crisis resources including the website and telephone number of a national suicide prevention and mental health crisis hotline system, expressly including but not limited to the 988 Suicide and Crisis Lifeline; the label must appear each time a user accesses the platform and may only be dismissed when the user exits or acknowledges the risk and chooses to proceed. Enforcement for both sits in § 325M.34: the Attorney General may investigate and bring an action for an alleged violation of § 325M.33 or § 325M.335. The statute specifies no penalty figure, and it provides that nothing in §§ 325M.30 to 325M.34 creates a private cause of action for a person injured by a violation of § 325M.33 — note the drafting, which names only § 325M.33 in that bar.

Deadline: July 1, 2026

Minn. Stat. §§ 325M.33 (2024 c 114 art 3 s 66), 325M.335 (1Sp2025 c 3 art 19 s 13), 325M.34 (2024 c 114 art 3 s 67, amended 1Sp2025 c 3 art 19 s 14)

Data Breach Notification — 48-Hour Consumer Reporting Agency Clock (§ 325E.61)

High Priority

Minn. Stat. § 325E.61 (headed "DATA WAREHOUSES; NOTICE REQUIRED FOR CERTAIN DISCLOSURES" — the heading obscures that this is Minnesota's breach-notification statute) requires disclosure of any breach of the security of the system, following discovery or notification of the breach, to any Minnesota resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Two features matter for AI systems holding training or inference data. First, the individual-notice deadline is a standard-based one — "in the most expedient time possible and without unreasonable delay" — with no fixed day count, so a controller cannot point to a safe-harbour number of days. Second, subd. 2 imposes a hard 48-HOUR clock for notifying consumer reporting agencies where more than 500 persons are affected at one time; that is among the shortest such clocks in the country and is frequently missed because it runs independently of the individual-notice work. Honest absence recorded: subd. 1 contains no Attorney General notification requirement or deadline — Minnesota, unusually, does not require regulator notice of a private-sector breach, though subd. 6 gives the Attorney General enforcement authority. Related but distinct: § 325E.64 (Plastic Card Security Act, "ACCESS DEVICES; BREACH OF SECURITY") and § 325E.59 (use of Social Security numbers) impose separate duties not folded into this item.

Minn. Stat. § 325E.61, subds. 1, 2 and 6; related Minn. Stat. §§ 325E.59, 325E.64

Deepfake Election Content — Consent + Intent Prohibition (not a disclosure duty)

Medium Priority

Under Minn. Stat. § 609.771 (HF 1370, 2023), it is a crime to disseminate a realistic AI-generated/synthetic depiction of a candidate's speech or conduct WITHOUT that candidate's consent, with intent to injure the candidate or influence an election result, during the window from 90 days before precinct caucuses/conventions through the election. There is no disclosure-label safe harbor — labeling content "AI-generated" does not exempt it if consent and intent elements are met. Obtain the depicted candidate's consent, or ensure content is clearly satire/parody a reasonable person would not mistake for fact (courts have found content "clearly unbelievable" as such falls outside the statute's reach — Kohls v. Ellison, 2025).

Deadline: August 1, 2023

Minn. Stat. § 609.771

AI Hiring Tools — MHRA Disparate Impact

Medium Priority

Minnesota Human Rights Act (Minn. Stat. § 363A) prohibits employment discrimination. AI-powered resume screening, interview analysis, or selection tools that disproportionately screen out protected classes (race, sex, age, disability) violate the MHRA. Validate AI hiring tools for disparate impact before deployment and document validation methodology.

Minn. Stat. § 363A

Who Does This Apply To?

ROUND 517 (2026-08-25) — scope restated: this entry now covers FIVE lanes, not two. (A) CONSUMER PRIVACY / AUTOMATED DECISIONS: the Minnesota Consumer Data Privacy Act, Minn. Stat. §§ 325M.10-.21 (Laws 2024, ch. 121, art. 5), in force 2025-07-31, binding entities doing business in Minnesota or targeting Minnesota residents that meet a § 325M.12 threshold (100,000+ consumers excluding payment-transaction-only data, or 25,000+ consumers with over 25% of gross revenue from selling personal data); its § 325M.14, subd. 1(g) right to question, be given reasons for, and force reevaluation of a profiling decision is the strictest automated-decision provision in any US state privacy statute and is the reason Minnesota should not be treated as a low-salience privacy jurisdiction. Employee and job-applicant data processed solely in the employment context is excluded, so AI hiring tools fall to lane (D), not the MCDPA. SBA-defined small businesses are excluded from the Act but still bound by § 325M.17. (B) NUDIFICATION TECHNOLOGY: § 325E.91 (Laws 2026, ch. 72, § 1), in force 2026-08-01, binding any operator of a service that makes nudification capability available to Minnesota users or advertises one, with no size threshold — enforceable now, xAI's TRO having been denied 2026-07-31. (C) SOCIAL MEDIA / RECOMMENDER SYSTEMS: §§ 325M.30-.34, requiring algorithmic-ranking-weight disclosure (§ 325M.33) and, since 2026-07-01, a per-access mental health warning label (§ 325M.335), AG-enforced under § 325M.34. (D) EMPLOYMENT AI: the MHRA, as before. (E) ELECTION DEEPFAKES: § 609.771, as before. VERIFIED ABSENCES, recorded so they are not re-guessed each round: Minnesota has NO BIPA-style biometric privacy statute (§ 325E.63 is CREDIT ISSUED TO MINORS, not biometrics); Minnesota has NOT adopted the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers and is not among the four jurisdictions with insurance-specific AI regulation or guidance, per the NAIC's own adoption map dated "Status as of August 6, 2026" (25 adopting jurisdictions; Minnesota unshaded), and the Minnesota Department of Commerce bulletins page surfaced no AI or predictive-model bulletin this round; § 325E.61 imposes no Attorney General breach-notification duty. LEGACY LANES (unchanged text follows). Applies in two distinct lanes. (1) Election deepfakes: Minn. Stat. § 609.771 (HF 1370, 2023, effective August 1, 2023) criminalizes disseminating a realistic AI-generated depiction of a candidate's speech/conduct without consent, with intent to injure the candidate or influence an election, in the window from 90 days before precinct caucuses/conventions through the election — this is a PROHIBITION, not a disclosure/labeling regime (no bill called "HF 4352" is involved; that citation was a phantom — see requirement-level note). Applies to anyone disseminating such content targeting a Minnesota election. (2) Employment AI: Minnesota has no comprehensive AI-employment statute, but the Minnesota Human Rights Act reaches discriminatory AI use in hiring, so employers using AI screening tools must be able to show no disparate impact on protected classes. STATUS: no comprehensive Minnesota AI law has passed as of July 2026 (web-verified 2026-07-01; the proposed Minnesota Artificial Intelligence Transparency Act is pending — monitor revisor.mn.gov). Scope turns on the specific use, not company size.

Recent Regulatory Guidance

guidance2025-02

Minnesota Attorney General — Report on Emerging Technology and Its Effects on Youth Well-Being (2025 edition)

GUIDANCE / POLICY REPORT, NOT BINDING LAW. Attorney General Keith Ellison released a February 2025 report — a follow-up to a February 2024 report on the same subject — on the harms that AI and social media inflict on young Minnesotans. It examines the harms, analyses the specific design features causing them (infinite scroll, excessive notifications, AI-powered engagement-optimising recommendation algorithms, and optimising content for engagement above all else), evaluates prior legislative efforts, and makes policy recommendations to the Minnesota Legislature. Its practical significance is directional rather than legal: it maps the AG office's enforcement and legislative priorities, and the design features it names are the same ones later reached by Minn. Stat. §§ 325M.33 and 325M.335. Do not cite it as a source of obligation.

guidance2026-08-06

NAIC AI Model Bulletin — Minnesota is a NON-ADOPTER (verified against the map, not inferred)

RECORDED ABSENCE. The NAIC's "Implementation of NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers" adoption map, in the version headed "Status as of August 6, 2026," shows 25 adopting jurisdictions and 4 with insurance-specific regulation or guidance (California, Colorado, New York, Texas). Minnesota appears in NEITHER group — it is unshaded on the map and absent from the reference list of adopted states. The Minnesota Department of Commerce bulletins page likewise surfaced no bulletin, guidance, or administrative letter on insurers' use of AI or predictive models this round (its current Administrative Bulletin 2026-1 concerns rate-filing review). Minnesota insurers are therefore governed by the general obligations in this entry plus federal law, with no state insurance-AI instrument. Note for future rounds: an older "April 1, 2026" copy of this NAIC map also circulates; the August 6, 2026 version was the one read here.

guidance2024-08

Minnesota SOS — 2024 Election Cycle AI-Content Bulletin

Minnesota Secretary of State Steve Simon published an advisory clarifying that Minn. Stat. §609.771 makes it a crime to disseminate, within the 90-day pre-election window, deepfake content of a candidate without the candidate's consent and with intent to injure the candidate or influence the election — there is NO exemption for content that carries an AI-generated label (corrected this cycle; no such safe harbor exists in the statute). The bulletin laid out platform notification procedures and victim-candidate intake.

Key Case Law & Precedent

xAI Corp. v. Minnesota (D. Minn., filed 2026-07-28)

US District Court, District of Minnesota (Judge Donovan W. Frank) · 2026

First Amendment challenge to Minn. Stat. § 325E.91, Minnesota's AI "nudification technology" ban — the first state ban of its kind and the newest binding AI obligation in this entry. xAI, the AI company behind Grok, filed suit days before the statute's August 1, 2026 effective date, arguing the law is overbroad and imposes strict liability on AI platform operators regardless of whether they prohibit nudification in their terms of service or deploy technical controls to prevent it. This is the leading test of whether a state may regulate a generative-AI capability at the platform-operator level rather than at the level of the individual who misuses it.

Outcome: TRO DENIED 2026-07-31. Judge Donovan W. Frank declined to issue a temporary restraining order blocking the ban, reasoning that xAI's delay in seeking emergency relief undermined its claim that immediate court action was necessary. The statute accordingly took effect on schedule on August 1, 2026 and is enforceable now. POSTURE STATED HONESTLY: this is a denial of emergency relief on timing, not a merits ruling on the First Amendment question, and no preliminary-injunction or final-judgment outcome had issued as of this round. Deployers should treat § 325E.91 as in force while the challenge proceeds. Distinct from Kohls v. Ellison and X Corp. v. Ellison, both of which concern the election-deepfake statute § 609.771, not § 325E.91.

Case reference

Kohls v. Ellison, No. 24-cv-3754 (LMP/DLM) (D. Minn.)

US District Court, District of Minnesota; on appeal, US Court of Appeals for the Eighth Circuit · 2024

Federal court case challenging Minnesota's deepfake election law (Minn. Stat. § 609.771) on First Amendment grounds, brought by a content creator (Christopher Kohls) and state Rep. Mary Franson. The leading test of state deepfake-election laws against First Amendment scrutiny.

Outcome: CYCLE 5 (2026-08-22) date/substance correction: preliminary injunction DENIED on 2025-01-10 (not "mid-2024" as previously stated) — the court held Kohls had not shown the law would apply to his content at all (parody/satire that is "clearly unbelievable" falls outside the statute's reach) and Franson failed to show irreparable harm. CYCLE 20 UPDATE (2026-08-22, No. 25-1300): the Eighth Circuit panel (Chief Judge Colloton, Judges Loken and Benton) AFFIRMED the denial of a preliminary injunction on 2026-02-09 — verified via the court's own published opinion (law.justia.com) and Reason/Volokh Conspiracy's coverage. Precision correction: the panel ruled on the MERITS, not standing — Kohls's labeled-parody videos are not "deep fakes" under the statute's own definition, so he had not shown a likelihood of success; Franson's claim failed separately because she waited over a year after the law took effect before seeking emergency relief. Kohls and Franson sought en banc rehearing in March 2026; the full Eighth Circuit (11 active judges) DENIED rehearing in April 2026 without stating reasons (confirmed via MediaPost). The statute has now survived preliminary-injunction review at the district court and two appellate levels without being enjoined — not yet a final merits judgment, and no confirmed certiorari petition to the Supreme Court as of this cycle. A related case, X Corp. v. Ellison, is proceeding separately with its Section 230 claim allowed to move forward while constitutional claims are stayed pending this appeal.

Case reference

Frequently Asked Questions

Does Minnesota — Consumer Data Privacy Act (§§ 325M.10-.21, profiling rights), Social Media Transparency (§§ 325M.33/.335), Nudification Ban (§ 325E.91), Deepfake Election Law (§ 609.771) + MHRA apply to my business?

ROUND 517 (2026-08-25) rebuilt this entry around the obligation that actually binds most Minnesota businesses and that the entry previously omitted entirely: the Minnesota Consumer Data Privacy Act, Minn. Stat. §§ 325M.10 to 325M.21 (NOT "chapter… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Minnesota — Consumer Data Privacy Act (§§ 325M.10-.21, profiling rights), Social Media Transparency (§§ 325M.33/.335), Nudification Ban (§ 325E.91), Deepfake Election Law (§ 609.771) + MHRA is: Nudification technology (Minn. Stat. § 325E.91): AG-enforced civil penalty up to $500,000 per violation — the largest per-violation exposure in this entry — plus a private right of action for the depicted individual. MCDPA (Minn. Stat. § 325M.20): AG-only civil penalty up to $7,500 per violation, no private right of action; the 30-day warning-letter cure period EXPIRED January 31, 2026. Election deepfake (Minn. Stat. § 609.771): criminal — up to $1,000/90 days (base), up to $3,000/364 days (intent to cause violence), up to $10,000/5 years (repeat offense); candidates convicted forfeit office. Civil injunctive relief (not damages) available to the AG, county/city attorneys, the depicted individual, or an injured candidate. Social media transparency (§§ 325M.33/.335): AG investigation and action under § 325M.34; the statute specifies no penalty figure and creates no private cause of action for § 325M.33 violations. Employment discrimination: MHRA remedies including back pay, damages, and injunctive relief.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Minnesota — Consumer Data Privacy Act (§§ 325M.10-.21, profiling rights), Social Media Transparency (§§ 325M.33/.335), Nudification Ban (§ 325E.91), Deepfake Election Law (§ 609.771) + MHRA?

The 11 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.revisor.mn.gov/statutes/cite/609.771

Last updated: 2026-08-25 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan