Skip to content
Esta e uma traducao de conveniencia. A versao em ingles e a versao oficial e legalmente vinculativa. Ver versao em ingles
US-HIFEDERAL profile1 enforcement action

Hawaii — State AI/Deepfake Laws + Insurance AI Governance (Commissioner Memorandum 2025-13A, NAIC AI bulletin adopted 2025-12-10) + Federal AI Profile (HRS §711-1110.9 sexual-deepfake NCII 2021; Act 247 general deepfakes + Act 248 AI chatbot safety, both signed July 2026; 2024 election-deepfake Act 191 enacted-then-enjoined): AI Compliance Requirements

Hawaii has NO comprehensive cross-sector AI statute, but it has THREE private-binding AI/deepfake laws now in force. (1) HRS § 711-1110.9 (Violation of privacy in the first degree), amended by SB 309 / Act 59, Session Laws Hawaii 2021 (signed Gov. Ige), criminalizes intentionally creating or disclosing — or threatening to disclose — a deepfake "composite fictitious person" image/video depicting a known, recognizable person nude or in sexual conduct without consent, with intent to harm or as revenge — a CLASS C FELONY (up to 5 years). (2) Act 247, SLH 2026 (HB 2137, signed by Gov. Green 2026-07-14) prohibits creating realistic digital imitations of real people that cause reputational or financial harm, or that are made with intent to defraud, harass, or commit a crime; subjects may sue for up to $25,000 per image, and non-consensual deepfakes are banned from advertisements. (3) Act 248, SLH 2026 (SB 3001, signed same date) regulates AI-chatbot safety: developers must include periodic reminders that a chatbot is non-sentient (persistent for minors); when a user expresses suicidal ideation or self-harm, the chatbot must refer to crisis services and clarify it is not professional mental-health care; services must not encourage self-harm or harm to others; for minors, engagement-incentivizing point systems and sexually explicit content are prohibited; beginning 2028, operators must file annual crisis-referral reports with the Department of Health. Separately, Hawaii's 2024 election-deepfake law (Act 191, SLH 2024 / SB 2687, signed Gov. Green Jul 3 2024), which criminalized recklessly distributing "materially deceptive media" of candidates during election season, was PERMANENTLY ENJOINED in January 2026 (Babylon Bee LLC v. ..., D. Haw., Judge Shanlyn Park) as an unconstitutional First Amendment restriction — it is enacted-but-not-enforceable and must not be relied on. (Verify-the-negative: HRS § 707-752's "computer-generated image" CSAM language is long-standing pre-2024 definitional text, NOT a new generative-AI enactment; HB 1607 (2024 generative-AI/employment) DIED in committee; SB 2572 / HB 2176 "Office of AI Safety" deferred; SB 1156 (2025→2026 sexual deepfake) DEAD; no comprehensive cross-sector AI statute enacted.) Hawaii's economy — dominated by tourism and healthcare (aging population, rural telehealth) — also exposes businesses to federal AI enforcement: FTC Act § 5, EEOC / Title VII / ADA (employment), FCRA (lending), COPPA (children's data). Hawaiian Native sovereignty creates additional sensitivity around AI processing indigenous cultural data. Hawaii Office of Consumer Protection is active in deceptive AI enforcement. Monitor capitol.hawaii.gov. Current Hawaii AG: Anne Lopez. INSURANCE (added R528): although Hawaii has no cross-sector AI statute, its INSURANCE regulator has issued binding-in-practice AI governance expectations. Insurance Commissioner Scott K. Saiki issued Memorandum 2025-13A, "The Use of Artificial Intelligence Systems in Insurance," on 2025-12-10, adopting the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers — the newest adoption recorded on the NAIC implementation map (status 2026-08-06). It directs all AUTHORIZED insurers to maintain a written AI Systems (AIS) Program covering governance, risk management and internal controls, testing and validation for errors and bias, third-party AI oversight, consumer notice that AI is in use, and documentation producible on examination, and it routes AI decisions into four existing bodies of Hawaii law: unfair methods of competition and unfair or deceptive acts and practices (HRS chapter 431, article 13, part I, including the unfair-claim-settlement standards of HRS § 431:13-103(a)(11)), Corporate Governance Annual Disclosure (HRS chapter 431, article 3G, filed by June 1 annually by DOMESTIC insurers, with HAR title 16 chapter 186), property and casualty rate regulation (HRS chapter 431, article 14), and market conduct (HRS chapter 431, article 2D). On utilization review, Hawaii has NO AI-specific statute — the 2026 vehicles SB 3027 and HB 2537, which would have regulated automated decision support tools in claims determinations and utilization review, both died in first-committee referral without a hearing — but AI-assisted UR sits inside HRS chapter 432E, where an "adverse determination" is technology-neutral, every adverse action is externally reviewable through the commissioner, the external review decision BINDS the carrier (HRS § 432E-37), and the reviewing clinician must be a licensed, board-certified, clinically active human expert (HRS § 432E-39(b)).

Summary of publicly-available regulatory text as of 2026-08-26. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2024

Maximum Penalty

State AI/deepfake penalties: HRS § 711-1110.9 (sexual-deepfake NCII, Act 59 SLH 2021) — CLASS C FELONY (up to 5 years); Act 247 SLH 2026 (general deepfakes) — private right of action up to $25,000 per image; Act 248 SLH 2026 (AI chatbot safety) — compliance duties effective 2026-07-14, annual DOH reporting from 2028 (statutory penalty for non-compliance not independently confirmed this cycle). (Hawaii's 2024 election-deepfake law, Act 191, was permanently enjoined Jan 2026 — not currently enforceable.) Federal: FTC civil penalties up to $51,744 per violation; EEOC Title VII damages up to $300K; FCRA statutory damages $100–$1,000/violation; COPPA up to $51,744/violation. Hawaii consumer protection (HRS § 480-3.1): up to $10,000 per violation. INSURANCE (added R528, all figures fetched from capitol.hawaii.gov this round): Memorandum 2025-13A carries no fine of its own and is enforced through the statutes it cites — HRS § 431:13-201(a) allows a fine of not more than $1,000 per act capped at $10,000, rising to not more than $5,000 per act capped at $50,000 in any six-month period where the insurer knew or reasonably should have known it was violating HRS § 431:13-103, plus discretionary licence suspension or revocation; HRS § 431:13-202 adds not more than $10,000 for each act violating a cease-and-desist order, and its subsection (b) preserves a first-party insured's bad-faith cause of action (82 H. 120, 920 P.2d 334 (1996)). Rate violations under HRS § 431:14-117: not more than $500 per violation, or not more than $5,000 per violation if wilful, with each day of a failure to file a rate or its supporting information counting as a separate violation. General insurance-code backstop, HRS § 431:2-203(b)(3): not less than $100 nor more than $10,000 per violation, or imprisonment up to one year, or both. Chapter 432E (managed care / utilization review) contains no monetary penalty in the sections read this round; its consequences are structural — external review decisions bind the carrier (HRS § 432E-37) and the carrier funds the review (HRS § 432E-42).

What Your Business Must Do

14 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Hawaii HRS § 711-1110.9 — Sexual Deepfake / Nonconsensual Intimate Image Felony (Act 59, SLH 2021)

High Priority

Hawaii Revised Statutes § 711-1110.9 (Violation of privacy in the first degree), as amended by SB 309 / Act 59, Session Laws Hawaii 2021 (signed Gov. Ige), makes it a CLASS C FELONY to intentionally create, disclose, or threaten to disclose an image or video of a "composite fictitious person" depicted nude or engaged in sexual conduct that includes the recognizable physical characteristics of a real, known person so that it appears to depict that person — i.e., an AI/digitally-generated sexual deepfake — done with intent to substantially harm the depicted person (health, safety, business, career, reputation, relationships) or as revenge/retribution. The court may also order destruction of the offending recording. This binds private individuals and businesses (e.g., any platform employee, marketer, or individual creating such synthetic media) and is currently in force. Counsel should confirm the exact current statutory text and felony class against the codified HRS and the Act 59 (2021) enrolled text. legal_review_pending.

HRS § 711-1110.9 (Violation of Privacy in the First Degree), as amended by Act 59, SLH 2021 (SB 309)

Hawaii Act 247 (General Deepfakes) + Act 248 (AI Chatbot Safety), signed July 2026

High Priority

Governor Green signed two new AI laws 2026-07-14. Act 247 (HB 2137) prohibits creating a realistic digital imitation of a real person causing reputational or financial harm, or made with intent to defraud, harass, or commit a crime; the depicted person may sue for up to $25,000 per image; non-consensual deepfakes are banned from advertisements. Act 248 (SB 3001) requires AI chatbot developers to: (1) include periodic non-sentience reminders (persistent display for minor users); (2) on any user expression of suicidal ideation or self-harm, refer to crisis services and clarify the chatbot is not professional mental-health care; (3) not encourage self-harm or harm to others; (4) for minor users, prohibit engagement-incentivizing point systems and sexually explicit content; (5) beginning 2028, file annual crisis-referral reports with the Department of Health. Counsel should confirm exact codified HRS sections and any statutory penalty for Act 248 non-compliance against the enrolled Act text — not independently re-derived this cycle. legal_review_pending.

Deadline: July 14, 2026

Act 247, SLH 2026 (HB 2137); Act 248, SLH 2026 (SB 3001)

FTC Act § 5 — Deceptive or Unfair AI Practices

High Priority

FTC Act § 5 prohibits deceptive and unfair AI practices. Tourism-sector AI (hotel pricing algorithms, dynamic tour booking, AI chatbots posing as humans) carries particular scrutiny in Hawaii. Ensure AI systems disclose their nature, avoid algorithmic pricing exploitation, and do not engage in deceptive personalization. Hawaii Office of Consumer Protection may pursue violations under HRS § 480 independently.

15 U.S.C. § 45(a) (unfair/deceptive practices); civil-penalty authority § 45(l), § 45(m)(1)(A); HRS § 480 (Hawaii consumer protection), penalty at HRS § 480-3.1

EEOC / Title VII / ADA — AI Employment Screening Compliance

High Priority

EEOC May 2023 guidance requires employers using AI hiring tools to test for disparate impact across race, sex, age, and disability. Hawaii's diverse workforce — majority Asian-American workforce, significant Native Hawaiian employees — makes adverse impact analysis essential. Run disparate impact analyses on any AI used for hiring, scheduling, or performance evaluation. Ensure AI vendors can demonstrate EEOC compliance (see Mobley v. Workday, Inc., N.D. Cal. Case No. 3:23-cv-00770-RFL — a private collective/class action, not an EEOC-filed suit; core claims allowed to proceed to trial per a 2026-06-22 ruling).

Title VII, 42 U.S.C. § 2000e-2; ADA, 42 U.S.C. § 12112; damages caps at 42 U.S.C. § 1981a(b)(3)

Hawaii Insurance Commissioner Memorandum 2025-13A — Written AI Systems (AIS) Program for Insurers

High Priority

Hawaii adopted the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers as Insurance Commissioner Memorandum 2025-13A, "The Use of Artificial Intelligence Systems in Insurance," issued December 10, 2025 by Commissioner Scott K. Saiki and addressed "To: All Authorized Insurers Offering Policies in the State of Hawaii." Core proposition: decisions or actions impacting consumers that are made or supported by advanced analytical and computational technologies, including AI Systems, must comply with all applicable insurance laws and regulations, including those addressing unfair trade practices and unfair discrimination. The Division expects every authorized insurer to develop, implement and maintain a WRITTEN program (an "AIS Program") for the responsible use of AI Systems that make or support decisions related to regulated insurance practices, designed to mitigate the risk of Adverse Consumer Outcomes. The AIS Program must address governance, risk management controls and internal audit functions, and must vest responsibility for its development, implementation, monitoring and oversight — and for setting the insurer's AI strategy — with senior management accountable to the board or an appropriate board committee. It must be tailored to and proportionate with the insurer's use of and reliance on AI, calibrated against five stated factors: (i) the nature of the decisions being made, informed or supported; (ii) the type and Degree of Potential Harm to Consumers; (iii) the extent of human involvement in final decision-making; (iv) the transparency and explainability of outcomes to the impacted consumer; and (v) the extent and scope of reliance on third-party data, Predictive Models and AI Systems. Scope obligations: the program must cover the whole insurance life cycle (product development and design, marketing, use, underwriting, rating and pricing, case management, claim administration and payment, fraud detection); all phases of an AI System life cycle (design, development, validation, implementation, use, ongoing monitoring, updating and retirement); AI Systems whether built in-house or supplied by a Third-Party; and it must include processes providing NOTICE TO IMPACTED CONSUMERS that AI Systems are in use, with access to appropriate levels of information based on the life-cycle phase. Governance must address policies and internal controls at each life-cycle stage, documentation requirements, and an accountability structure (cross-disciplinary committees drawn from business units, product, actuarial, data science and analytics, underwriting, claims, compliance and legal; scope of authority and decisional hierarchies; independence of decision-makers and lines of defence; monitoring, auditing, escalation and reporting protocols; ongoing personnel training and supervision). Risk management and internal controls must address the oversight and approval process for adopting or acquiring AI Systems; data practices covering currency, lineage, quality, integrity, bias analysis and minimisation, and suitability; management and oversight of Predictive Models including inventories, detailed development documentation, and assessments of interpretability, repeatability, robustness, regular tuning, reproducibility, traceability, Model Drift and auditability; validation, testing and retesting to assess generalisation of outputs upon implementation; protection of non-public consumer information including unauthorised access to the models themselves; and data and record retention. The AIS Program may sit inside or outside the insurer's existing Enterprise Risk Management programme and may adopt or rely on a third-party standard such as the NIST AI Risk Management Framework, Version 1.0, which the memorandum names expressly. The memorandum defines Adverse Consumer Outcome, Algorithm, Artificial Intelligence, AI System, Degree of Potential Harm to Consumers, Generative AI, Machine Learning, Model Drift, Predictive Model and Third-Party. It is principles-based: the Division states its goal "is not to prescribe specific practices or to prescribe specific documentation requirements," and insurers may demonstrate compliance through alternative means. The memorandum recognises the NAIC Principles of Artificial Intelligence adopted in 2020 as an appropriate source of guidance.

Deadline: December 10, 2025

Hawaii Insurance Commissioner Memorandum 2025-13A, "The Use of Artificial Intelligence Systems in Insurance" (issued 2025-12-10), adopting the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (NAIC-adopted 2023-12-04). Authority enumerated by the memorandum itself in Section 1 ("Legislative Authority"): HRS chapter 431, article 13, part I (Unfair Methods of Competition and Unfair and Deceptive Acts and Practices in the Business of Insurance), specifically HRS § 431:13-103 and § 431:13-103(a)(11) (unfair claim settlement practices); HRS chapter 431, article 3G (Corporate Governance Annual Disclosure) with HAR title 16, chapter 186; HRS chapter 431, article 14 (rate regulation); and HRS chapter 431, article 2D (Market Conduct). Penalty route: HRS § 431:13-201 and § 431:13-202.

Hawaii Memorandum 2025-13A — Third-Party AI Systems and Data: Diligence, Contract Terms and Audit Rights

High Priority

Section 3, item 4.0 of Memorandum 2025-13A requires each AIS Program to address the insurer's process for acquiring, using or relying on (i) Third-Party data used to develop AI Systems, and (ii) AI Systems developed by a Third-Party — "Third-Party" being defined by the memorandum as an organization other than the Insurer that provides services, data, or other resources related to AI. The insurer is expected to establish standards, policies, procedures and protocols covering: (a) due diligence and the methods used to assess the Third-Party and its data or AI Systems, so that decisions made or supported by those systems which could lead to Adverse Consumer Outcomes will meet the legal standards imposed on the INSURER ITSELF — the accountability does not transfer to the vendor; (b) where appropriate and available, contract terms that provide audit rights and/or entitle the insurer to receive audit reports by qualified auditing entities, and that require the Third-Party to cooperate with the insurer on regulatory inquiries and investigations relating to the insurer's use of the vendor's product or services; and (c) actual performance of those contractual audit rights and other activities to confirm the Third-Party's compliance with contractual and, where applicable, regulatory requirements. Section 4, item 2 sets out what the Division will request where an investigation or examination concerns data, Predictive Models or AI Systems collected or developed in whole or in part by third parties: the due diligence conducted on the third parties and their data, models or AI Systems; the contracts themselves, including terms relating to representations, warranties, data security and privacy, data sourcing, intellectual property rights, confidentiality and disclosures, and cooperation with regulators; audits and confirmation processes performed regarding Third-Party compliance; and documentation of validation, testing and auditing including evaluation of Model Drift. Practical consequence: a Hawaii-authorized insurer that buys a scoring, triage, pricing or fraud-detection model from a vendor must be able to produce vendor diligence records and contracts with audit and regulator-cooperation clauses, and cannot answer a Division inquiry by pointing at the vendor.

Deadline: December 10, 2025

Hawaii Insurance Commissioner Memorandum 2025-13A, Section 3 item 4.0 (Third-Party AI Systems and Data) and Section 4 item 2; definition of "Third-Party" at Section 2. Underlying authority as enumerated in Section 1: HRS chapter 431, article 13, part I; article 3G; article 14; article 2D.

Hawaii Memorandum 2025-13A — Regulatory Oversight: AI Documentation Producible on Examination or Market Conduct Action

High Priority

Section 4 of Memorandum 2025-13A advises insurers what the Division may request during an investigation or market conduct action. Critically, the memorandum states this applies "Regardless of the existence or scope of a written AIS Program" — an insurer that never wrote one is still expected to answer for its development, deployment and use of AI Systems, any specific Predictive Model or application, and the outcomes (including Adverse Consumer Outcomes) arising from them. The enumerated production list covers: the written AIS Program itself; documentation evidencing its ADOPTION; the Program's scope, including any AI Systems and technologies NOT covered by it; how the Program is tailored to and proportionate with the insurer's use of AI, the risk of Adverse Consumer Outcomes and the Degree of Potential Harm to Consumers; and the policies, procedures, guidance and TRAINING MATERIALS relating to adoption, implementation, maintenance, monitoring and oversight — expressly including processes for development, adoption or acquisition of AI Systems (identification of constraints and controls on automation and design; data governance and controls covering data lineage, quality, integrity, bias analysis and minimisation, suitability and Data Currency), processes for management and oversight of Predictive Models (including the measurements, standards or thresholds the insurer adopted or uses in development, validation and oversight), and protection of non-public information including unauthorised access to the Predictive Models themselves. The Division may also request evidence of the formation and ongoing operation of the insurer's AI coordinating bodies; documentation of data practices and accountability procedures; the insurer's INVENTORIES and descriptions of Predictive Models and AI Systems used to make or support decisions that can result in Adverse Consumer Outcomes; and, for any specific model under investigation, documentation of compliance with the insurer's own AI programme policies, information about the data used (source, provenance, lineage, quality, integrity, bias analysis and minimisation, suitability and Data Currency), and information on the techniques, measurements, thresholds and similar controls used. It may further request documentation of validation, testing and auditing including evaluation of Model Drift, noting that the nature of that work should reflect whether the AI System is based on Predictive Models or on Generative AI. The memorandum closes by preserving the Division's full authority: work performed may include inquiry, examination of company documentation, or any of the continuum of market actions described in the NAIC Market Regulation Handbook, may involve contracted specialists with relevant subject-matter expertise, and "Nothing in this memorandum limits the authority of the Division to conduct any regulatory investigation, examination, or enforcement action." Division contact for questions: insurance@dcca.hawaii.gov / (808) 586-2790.

Deadline: December 10, 2025

Hawaii Insurance Commissioner Memorandum 2025-13A, Section 4 (Regulatory Oversight and Examination Considerations), item 1.0; Section 1 (market conduct authority). HRS chapter 431, article 2D (Market Conduct), which establishes the framework for the Division's market analysis and targeted examinations; NAIC Market Regulation Handbook (referenced by the memorandum).

Hawaii HRS § 431:13-103 — AI-Driven Underwriting and Claims Must Not Be Unfair, Deceptive or Unfairly Discriminatory

High Priority

Memorandum 2025-13A states that actions taken by insurers in Hawaii must not violate HRS chapter 431, article 13, part I, "regardless of the methods the Insurer used to determine or support its actions," and that insurers are expected to adopt governance frameworks and risk management protocols designed to ensure their use of AI Systems does not result in (1) unfair methods of competition and unfair and deceptive acts and practices as defined in HRS § 431:13-103, or (2) unfair claim settlement practices as defined in HRS § 431:13-103(a)(11). The memorandum adds that the applicable standards require, at a minimum, that decisions made by insurers are not inaccurate, arbitrary, capricious, or unfairly discriminatory, and that compliance is required regardless of the tools and methods used. HRS § 431:13-103(a)(11) defines unfair claim settlement practices as committing or performing, with such frequency as to indicate a general business practice, any of a list of acts that includes: misrepresenting pertinent facts or policy provisions relating to coverages at issue; failing to respond with reasonable promptness — IN NO CASE MORE THAN FIFTEEN WORKING DAYS — to communications from the policyholder, from any other person including the commissioner, or from the insurer of a person involved in an incident in which the policyholder is also involved, the response being required to be more than an acknowledgment and to adequately address the concerns raised; failing to adopt and implement reasonable standards for the prompt investigation of claims; refusing to pay claims without conducting a reasonable investigation based upon all available information; failing to affirm or deny coverage within a reasonable time after proof-of-loss statements are completed; failing to offer payment WITHIN THIRTY CALENDAR DAYS of affirmation of liability where the amount is determined and not in dispute; failing to provide a reasonable written explanation for any delay on every claim remaining unresolved THIRTY CALENDAR DAYS from the date reported; not attempting in good faith to effectuate prompt, fair and equitable settlements where liability has become reasonably clear; compelling insureds to litigate by offering substantially less than amounts ultimately recovered; and making claims payments unaccompanied by a statement setting forth the coverage under which payment is made. Compliance consequence for AI: an automated claim-triage, denial-recommendation, document-review or settlement-valuation system that suppresses response times, produces boilerplate that does not adequately address the claimant's stated concerns, denies without a reasonable investigation of available information, or systematically undervalues settlements, exposes the insurer under (a)(11) on a general-business-practice theory — the frequency threshold is precisely the pattern an automated system produces at scale.

HRS § 431:13-103 (Unfair methods of competition and unfair or deceptive acts or practices defined), including § 431:13-103(a)(11) (unfair claim settlement practices, with the fifteen-working-day response and thirty-calendar-day payment and delay-explanation standards); HRS chapter 431, article 13, part I generally; applied to AI by Hawaii Insurance Commissioner Memorandum 2025-13A, Sections 1 and 3.

Hawaii HRS Chapter 431, Article 14 — AI- and Predictive-Model-Derived Rates Must Not Be Excessive, Inadequate or Unfairly Discriminatory

High Priority

Memorandum 2025-13A states that Hawaii's rate regulation laws in HRS chapter 431, article 14 require that property and casualty insurance rates not be excessive, inadequate, or unfairly discriminatory, and that those requirements apply "regardless of the methodology that the Insurer used to develop rates, rating rules, and rating plans." The insurer is therefore responsible for assuring that rates, rating rules and rating plans developed using AI techniques and Predictive Models that rely on data and Machine Learning do not produce excessive, inadequate or unfairly discriminatory rates — with respect to all forms of casualty insurance, including fidelity, surety and guaranty bond, and all forms of property insurance, including fire, marine and inland marine, and any combination of the foregoing. The governing rate-making standard is HRS § 431:14-103(a): rates shall not be excessive, inadequate, or unfairly discriminatory, and due consideration shall be given to past and prospective loss experience within and outside the State, conflagration and catastrophe hazards, a reasonable margin for underwriting profit and contingencies, dividends and returned premium, past and prospective expenses both countrywide and Hawaii-specific, investment income from unearned premium and loss reserve funds, and all other relevant factors within and outside the State. HRS § 431:14-104 requires every insurer to file with the commissioner every manual of classifications, rules and rates, every rating plan, every other rating rule and every modification proposed for use; each filing must state its proposed effective date, indicate the character and extent of coverage contemplated, include a report on investment income, and be accompanied by a $50 fee deposited in the commissioner's education and training fund, and must be submitted via the NAIC System for Electronic Rates and Forms Filing (SERFF) or an equivalent service approved by the commissioner. At the same time the insurer must file all supplementary rating and supporting information used in support of or in conjunction with a rate. Compliance consequence for AI: where a machine-learning model generates or informs a rating plan, the model and its supporting information fall inside the filing obligation, and the insurer — not the model vendor — carries the burden of demonstrating the resulting rates satisfy § 431:14-103(a).

HRS chapter 431, article 14 (rate regulation); HRS § 431:14-103 (Making of rates — not excessive, inadequate or unfairly discriminatory; due-consideration factors); HRS § 431:14-104 (Rate filings; SERFF submission; $50 filing fee; supplementary rating and supporting information); HRS § 431:14-117 (Penalties). Applied to AI-derived rates by Hawaii Insurance Commissioner Memorandum 2025-13A, Section 1.

Hawaii HRS Chapter 431, Article 3G — AI Governance Must Be Reported in the Corporate Governance Annual Disclosure

High Priority

Memorandum 2025-13A cites the Corporate Governance Annual Disclosure (CGAD) regime in HRS chapter 431, article 3G as one of the laws its Section 3 and Section 4 expectations rely on, and states expressly that "The requirements of Corporate Governance Annual Disclosure apply to elements of the Insurer's corporate governance framework that address the Insurer's use of AI Systems to support actions and decisions that impact consumers." In other words, an insurer's AI governance structure is not a free-standing disclosure — it is a reportable component of the corporate governance framework the insurer already files. Article 3G requires insurers to report on governance practices and to provide a summary of corporate governance structure, policies and practices; the content, form and filing requirements are set out in HAR title 16, chapter 186. Under HRS § 431:3G-103(a), an insurer or the insurance group of which it is a member must, NO LATER THAN JUNE 1 OF EACH CALENDAR YEAR, submit a corporate governance annual disclosure containing the information required by HRS § 431:3G-105; where the insurer is a member of an insurance group it files with the commissioner of the LEAD STATE for the group, in accordance with the lead state's laws, as determined by the procedures in the most recent NAIC Financial Analysis Handbook. Under § 431:3G-103(b) the disclosure must carry the signature of the insurer's or group's chief executive officer or corporate secretary attesting, to the best of that person's belief and knowledge, that the insurer has implemented the corporate governance practices described and that a copy has been provided to the board or the appropriate board committee — so an AI governance framework described in the CGAD is a CEO- or corporate-secretary-attested representation. Under § 431:3G-103(c) an insurer not otherwise required to file must do so upon the commissioner's request, and under § 431:3G-103(d) disclosure may be made at the ultimate controlling parent level, an intermediate holding company level, or the individual legal entity level depending on how the group has structured its governance. The article's stated purposes (§ 431:3G-101(a)) include providing the commissioner a summary sufficient to gain and maintain an understanding of the insurer's corporate governance framework and providing for CONFIDENTIAL treatment of the disclosure and related information, which will contain confidential and sensitive information about internal operations and proprietary and trade secret material that could cause competitive harm if made public — a point that dovetails with the memorandum's own instruction that AI governance must prioritise transparency, fairness and accountability "recognizing that proprietary and trade secret information must be protected." Article 3G does not prescribe corporate governance standards beyond those required under applicable state corporate law (§ 431:3G-101(b)).

Deadline: June 1, 2026

HRS chapter 431, article 3G (Corporate Governance Annual Disclosure), L 2019, c 71 — § 431:3G-101 (purpose and scope; domestic-insurer application), § 431:3G-102 (definitions), § 431:3G-103 (disclosure requirement; June 1 annual filing; CEO or corporate secretary attestation; lead-state filing for groups), § 431:3G-105 (required contents, cross-referenced by § 431:3G-103(a)); HAR title 16, chapter 186 (content, form and filing requirements). Applied to AI governance by Hawaii Insurance Commissioner Memorandum 2025-13A, Section 1.

Hawaii HRS Chapter 432E — AI-Assisted Utilization Review, Adverse Determinations and Binding External Review

High Priority

Hawaii has no AI-specific utilization-review statute, but AI-assisted UR is fully inside the managed-care regime in HRS chapter 432E. HRS § 432E-1 defines an "adverse determination" as a determination BY A HEALTH CARRIER OR ITS DESIGNATED UTILIZATION REVIEW ORGANIZATION that an admission, availability of care, continued stay, or other health care service that is a covered benefit has been reviewed and, based upon the information provided, does not meet the health carrier's requirements for medical necessity, appropriateness, health care setting, level of care, or effectiveness, with the service or payment therefore denied, reduced or terminated; "adverse action" means an adverse determination or a final adverse determination. That definition is technology-neutral — a denial produced or recommended by an algorithm is an adverse determination and carries the full external-review consequence. Part IV of the chapter (HRS §§ 432E-31 to 432E-44) governs external review of health insurance determinations and applies to ALL health carriers, excluding only policies providing coverage limited to a specified disease, specified accident or accident-only, credit, dental, disability income, hospital indemnity, long-term care, vision care or other limited supplemental benefit, and medicare supplemental coverage. Key mechanics: § 432E-32 requires notice of the right to external review setting out the enrollee's options, in a form and content the commissioner may specify. § 432E-33 requires requests to be made IN WRITING TO THE COMMISSIONER — Hawaii routes external review through the regulator, not the carrier — enclosing a copy of the final internal determination, a signed authorization for release of relevant medical records, a conflict-of-interest disclosure under § 432E-43, and a $15 filing fee deposited into the compliance resolution fund, the fee being REFUNDED if the adverse determination or final internal adverse determination is reversed on external review, and waivable by the commissioner. § 432E-34 sets standard external review: the enrollee or appointed representative files within ONE HUNDRED THIRTY DAYS of receipt of notice of an adverse action; the commissioner sends a copy to the health carrier within THREE BUSINESS DAYS; the carrier determines reviewability within FIVE BUSINESS DAYS of receiving it; and a carrier that reverses its adverse action must act within THREE BUSINESS DAYS of that decision. § 432E-35 provides expedited external review where the timeframe for a standard process would seriously jeopardize the enrollee's life, health or ability to gain maximum functioning, or subject the enrollee to severe pain that cannot be adequately managed, or where the determination concerns emergency services and the enrollee has not been discharged. § 432E-36 covers experimental or investigational treatment determinations. THE DECISIVE PROVISION FOR AUTOMATED DENIALS IS § 432E-37: an external review decision is BINDING on the health carrier. LICENSED-PROVIDER REQUIREMENT — § 432E-39(b) requires that each clinical reviewer assigned by an independent review organization be A PHYSICIAN OR OTHER APPROPRIATE HEALTH CARE PROVIDER who (1) is an expert in the treatment of the medical condition at issue; (2) is knowledgeable about the recommended health care service and treatment through recent or current actual clinical experience treating patients with the same or similar condition; (3) HOLDS A NON-RESTRICTED LICENSE IN A STATE OF THE UNITED STATES and, for physicians, a current certification by a recognized American Medical Specialty Board in the area appropriate to the subject of the review; and (4) has no history of disciplinary actions or sanctions, including loss of staff privileges or participation restrictions, raising a substantial question as to the reviewer's fitness. Section 432E-39(a) additionally requires the IRO to maintain a quality assurance mechanism ensuring reviews are conducted within the specified timeframes, ensuring selection of qualified and impartial clinical reviewers and suitable matching of reviewers to specific cases (employing or contracting an adequate number of them), ensuring confidentiality of medical and treatment records and clinical review criteria, and ensuring compliance by all its personnel. So while Hawaii does not forbid AI in the carrier's own utilization review, the appellate layer above it is statutorily reserved to a licensed, board-certified, clinically active human expert whose decision binds the carrier. Supporting duties: § 432E-40 immunises IROs and clinical reviewers from damages except for bad faith or gross negligence; § 432E-41 requires IROs and carriers to maintain aggregate written records by state and by carrier on all external review requests — total requests, numbers resolved upholding versus reversing the adverse action, average length of time for resolution, summary of coverage types, and the number terminated because the carrier reconsidered after receiving additional information — retained for at least three years and reported to the commissioner on request; § 432E-42 places the cost of the external review on the health carrier against which the request is filed; § 432E-43 requires each carrier to describe the external review procedures in or attached to the evidence of coverage, to inform enrollees of the right to file with the commissioner including the commissioner's telephone number and address, and to make request forms — including a HIPAA-compliant authorization release form and a conflict-of-interest disclosure form — available on its website and on request. Compliance consequence for AI: a carrier deploying automated medical-necessity screening should expect its reversal rate to be measurable through the § 432E-41 aggregate reporting, and every automated denial to be appealable to a human specialist whose contrary decision it must honour.

HRS chapter 432E (Patients' Bill of Rights and Responsibilities Act) — § 432E-1 (definitions of "adverse action", "adverse determination", utilization review), § 432E-12 (commissioner's rulemaking under HRS chapter 91), § 432E-13 (annual report to the legislature on external review cases); Part IV, External Review of Health Insurance Determinations — § 432E-31 (applicability and scope; excluded limited-benefit and medicare supplemental coverage), § 432E-32 (notice of right to external review), § 432E-33 (request requirements; $15 refundable filing fee), § 432E-34 (standard external review; 130-day filing window; three- and five-business-day clocks), § 432E-35 (expedited external review), § 432E-36 (experimental or investigational treatment), § 432E-37 (external review decision binding on the health carrier), § 432E-38 (approval of independent review organizations), § 432E-39 (minimum qualifications for IROs; § 432E-39(b) clinical reviewer non-restricted licence and specialty-board certification), § 432E-40 (hold harmless), § 432E-41 (external review reporting; three-year retention), § 432E-42 (funding of external review by the carrier), § 432E-43 (disclosure requirements). Verify-the-negative: SB 3027 and HB 2537 (2026), which would have added AI and automated-decision-support-tool requirements to chapter 432E, both died in first-committee referral without a hearing.

FCRA / CFPB — AI Credit Decision Adverse Action Notices

Medium Priority

AI-driven credit or loan decisions must comply with FCRA adverse action notice requirements. CFPB Circular 2022-03 confirms that citing "model output" is not a sufficient adverse action reason — lenders must state specific factors from the consumer's file. Hawaii financial institutions and fintech companies using AI must provide specific adverse action notices.

15 U.S.C. § 1681b(b)(3) (adverse action notice); §§ 1681n, 1681o (civil liability); CFPB Circular 2022-03

HIPAA — AI in Healthcare and Telehealth Applications

Medium Priority

Hawaii has a significant healthcare AI sector with rural telehealth services. AI systems processing Protected Health Information (PHI) must comply with HIPAA Security and Privacy Rules. AI diagnostic tools, triage chatbots, and clinical decision support systems used by covered entities require Business Associate Agreements with AI vendors and end-to-end HIPAA-compliant data handling.

45 CFR Parts 160, 164; civil penalty tiers at 45 CFR § 160.404 (amounts set by 45 CFR § 102.3)

Monitor Hawaii AI Legislation + Indigenous Data Sovereignty

Lower Priority

Hawaii has no comprehensive cross-sector AI statute and no enacted general chatbot-disclosure or employment-AI law. Status of recent vehicles (verify-the-negative, updated August 2026): the 2024 election-deepfake law (Act 191, SLH 2024 / SB 2687) was PERMANENTLY ENJOINED in Jan 2026 (Babylon Bee LLC v. ..., D. Haw.) and is not enforceable; HB 1607 (2024 generative-AI/employment) died in committee; SB 2572 / HB 2176 ("Office of AI Safety and Regulation") were deferred; SB 1156 (2025→2026 sexual-deepfake misdemeanor) died. HB 639/SB 640 (2026 general chatbot disclosure) remains NOT enacted, BUT SB 3001 (2026 AI-companion/chatbot-for-minors safety bill) WAS signed into law as Act 248 on 2026-07-14 — see the new hi_act247_248_2026 requirement above; a companion general-deepfake bill (HB 2137) was signed the same day as Act 247. Note also that HRS § 707-752's "computer-generated image" CSAM language is long-standing pre-2024 definitional text, not a new AI enactment. Monitor capitol.hawaii.gov — Hawaii may follow California's AI regulatory approach within 1-2 sessions, and an election-deepfake re-draft narrowed to survive First Amendment review is plausible. Additionally, consider Office of Hawaiian Affairs guidance on AI use of indigenous cultural data and Native Hawaiian genealogical information. AI trained on or deployed for Native Hawaiian communities carries unique data sovereignty implications beyond standard federal compliance.

Recent Enforcement Actions

2023-12-19Source verified· as of 2026-08-26

Against:

Recent Regulatory Guidance

guidance2022-05-12

EEOC: ADA and AI Employment Screening Technical Assistance (May 2022)

Explains how the ADA applies to AI tools used in hiring — including when employers may be liable for AI vendor tools that screen out disabled applicants. Covers pre-offer medical inquiry rules, reasonable accommodation in AI screening, and disparate impact obligations for Hawaii employers using automated hiring software.

Frequently Asked Questions

Does Hawaii — State AI/Deepfake Laws + Insurance AI Governance (Commissioner Memorandum 2025-13A, NAIC AI bulletin adopted 2025-12-10) + Federal AI Profile (HRS §711-1110.9 sexual-deepfake NCII 2021; Act 247 general deepfakes + Act 248 AI chatbot safety, both signed July 2026; 2024 election-deepfake Act 191 enacted-then-enjoined) apply to my business?

Hawaii has NO comprehensive cross-sector AI statute, but it has THREE private-binding AI/deepfake laws now in force. (1) HRS § 711-1110.9 (Violation of privacy in the first degree), amended by SB 309 / Act 59, Session Laws Hawaii 2021 (signed Gov.… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Hawaii — State AI/Deepfake Laws + Insurance AI Governance (Commissioner Memorandum 2025-13A, NAIC AI bulletin adopted 2025-12-10) + Federal AI Profile (HRS §711-1110.9 sexual-deepfake NCII 2021; Act 247 general deepfakes + Act 248 AI chatbot safety, both signed July 2026; 2024 election-deepfake Act 191 enacted-then-enjoined) is: State AI/deepfake penalties: HRS § 711-1110.9 (sexual-deepfake NCII, Act 59 SLH 2021) — CLASS C FELONY (up to 5 years); Act 247 SLH 2026 (general deepfakes) — private right of action up to $25,000 per image; Act 248 SLH 2026 (AI chatbot safety) — compliance duties effective 2026-07-14, annual DOH reporting from 2028 (statutory penalty for non-compliance not independently confirmed this cycle). (Hawaii's 2024 election-deepfake law, Act 191, was permanently enjoined Jan 2026 — not currently enforceable.) Federal: FTC civil penalties up to $51,744 per violation; EEOC Title VII damages up to $300K; FCRA statutory damages $100–$1,000/violation; COPPA up to $51,744/violation. Hawaii consumer protection (HRS § 480-3.1): up to $10,000 per violation. INSURANCE (added R528, all figures fetched from capitol.hawaii.gov this round): Memorandum 2025-13A carries no fine of its own and is enforced through the statutes it cites — HRS § 431:13-201(a) allows a fine of not more than $1,000 per act capped at $10,000, rising to not more than $5,000 per act capped at $50,000 in any six-month period where the insurer knew or reasonably should have known it was violating HRS § 431:13-103, plus discretionary licence suspension or revocation; HRS § 431:13-202 adds not more than $10,000 for each act violating a cease-and-desist order, and its subsection (b) preserves a first-party insured's bad-faith cause of action (82 H. 120, 920 P.2d 334 (1996)). Rate violations under HRS § 431:14-117: not more than $500 per violation, or not more than $5,000 per violation if wilful, with each day of a failure to file a rate or its supporting information counting as a separate violation. General insurance-code backstop, HRS § 431:2-203(b)(3): not less than $100 nor more than $10,000 per violation, or imprisonment up to one year, or both. Chapter 432E (managed care / utilization review) contains no monetary penalty in the sections read this round; its consequences are structural — external review decisions bind the carrier (HRS § 432E-37) and the carrier funds the review (HRS § 432E-42).. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Hawaii — State AI/Deepfake Laws + Insurance AI Governance (Commissioner Memorandum 2025-13A, NAIC AI bulletin adopted 2025-12-10) + Federal AI Profile (HRS §711-1110.9 sexual-deepfake NCII 2021; Act 247 general deepfakes + Act 248 AI chatbot safety, both signed July 2026; 2024 election-deepfake Act 191 enacted-then-enjoined)?

The 14 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://ag.hawaii.gov

Last updated: 2026-08-26 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan