Skip to content
Esta e uma traducao de conveniencia. A versao em ingles e a versao oficial e legalmente vinculativa. Ver versao em ingles
US-NJMEDIUM coverage

New Jersey — AI, Data Privacy, Insurance AI & Algorithmic Discrimination: AI Compliance Requirements

New Jersey regulates AI across four distinct, independently enforceable surfaces. (1) DEEPFAKES: A3540/S2544, signed 2025-04-02 (P.L.2025, c.40), makes producing or distributing deceptive AI-generated audio/visual media for an unlawful purpose a third-degree crime (up to 5 years imprisonment and/or a fine up to $30,000) and creates a private civil right of action; it exempts satire, parody, news reporting, teaching and research, and does not reach service providers or broadcasters that inadvertently carry such content. (2) INSURANCE: DOBI Bulletin No. 25-03 (issued 2025-02-11 by Commissioner Justin Zimmerman) applies to ALL insurers authorized or admitted in New Jersey and expects every one of them to develop, implement and maintain a written AI Systems ("AIS") Program governing AI across the insurance life cycle, including third-party models and data, with the Department entitled to demand that documentation in any investigation or market conduct action. (3) DATA PRIVACY: the New Jersey Data Privacy Act (P.L.2023, c.266, N.J.S.A. 56:8-166.4 et seq.), in force since 2025-01-15, grants a right to opt out of profiling in furtherance of decisions producing legal or similarly significant effects, requires recognition of a universal opt-out mechanism, requires data protection assessments for higher-risk processing, and requires consent for sensitive data; violations are unlawful practices under the Consumer Fraud Act. (4) CIVIL RIGHTS: the Attorney General / Division on Civil Rights "Guidance on Algorithmic Discrimination and the New Jersey Law Against Discrimination" (January 2025) applies the existing LAD to automated decision-making tools in employment, housing, places of public accommodation, credit and contracting — with liability attaching even where the covered entity did not build the tool and did not intend to discriminate. New Jersey has NOT enacted a standalone automated-employment-decision-tool statute (A3854 and A3911 remain unenacted bills) and has no biometric-privacy act.

Summary of publicly-available regulatory text as of 2026-08-25. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 15, 2025

Maximum Penalty

Deepfakes (A3540 / P.L.2025, c.40): third-degree crime — up to 5 years imprisonment and/or a fine up to $30,000 — plus a private civil right of action. Data Privacy Act and breach-notification violations: unlawful practices under the Consumer Fraud Act, carrying civil penalties of not more than $10,000 for a first offense and not more than $20,000 for each subsequent offense (N.J.S.A. 56:8-13). Insurance Bulletin 25-03 and the NJLAD algorithmic-discrimination guidance impose no bulletin- or guidance-specific penalty of their own; exposure runs through the underlying statutes each instrument interprets.

What Your Business Must Do

14 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Prohibit Deceptive AI-Generated Media

Critical

Do not produce or distribute AI-generated audio or visual media ("deepfakes") that: (1) Depicts a real person without their consent. (2) Is used to further any criminal activity (fraud, threats, child exploitation, harassment, hazing, etc.). Review all AI content generation workflows to ensure no unauthorized deepfakes are created.

Deadline: April 2, 2025

New Jersey A3540/S2544, signed 2025-04-02, enacted as P.L.2025, c.40

Maintain a Written AI Systems (AIS) Program — Insurers

Critical

Every insurer authorized to do business in New Jersey is expected to develop, implement and maintain a written program (an "AIS Program") for the responsible use of AI Systems that make or support decisions related to regulated insurance practices, designed to mitigate the risk of Adverse Consumer Outcomes. The AIS Program must address governance, risk management controls and internal audit functions, and must vest responsibility for its development, implementation, monitoring and oversight — and for setting the insurer's AI strategy — in senior management accountable to the board or an appropriate board committee. It must be tailored and proportionate to the insurer's actual use of and reliance on AI, and it must cover the whole insurance life cycle (product development and design, marketing, use, underwriting, rating and pricing, case management, claim administration and payment, and fraud detection) and every phase of an AI System's own life cycle (design, development, validation, implementation, use, ongoing monitoring, updating and retirement). It must cover AI Systems used for regulated insurance practices whether the insurer built them or bought them from a third-party vendor. The Program may sit inside or alongside the insurer's existing Enterprise Risk Management program and may adopt or rely on a third-party standard such as the NIST AI Risk Management Framework, Version 1.0.

Deadline: February 11, 2025

NJ DOBI Bulletin No. 25-03, "The Use of Artificial Intelligence Systems in Insurance" (Feb. 11, 2025), Section 3 and AIS Program Guidelines 1.0-2.0. Legislative authority enumerated in Section 1: Unfair Trade Practices Act, N.J.S.A. 17:29B-1 et seq. (unfair practices defined at N.J.S.A. 17:29B-4); Unfair Claims Settlement Practices Act, N.J.S.A. 17B:30-13.1 et seq. (standards at N.J.S.A. 17B:30-3 et seq.); Corporate Governance Annual Disclosure Act, N.J.S.A. 17:23-38 et seq. and N.J.A.C. 11:1-48 et seq.; Market Conduct Surveillance, N.J.S.A. 17:23-20 et seq.

Risk Controls, Validation and Bias Testing for Insurance Predictive Models

Critical

Document the insurer's risk identification, mitigation and management framework and internal controls for AI Systems, generally and at each stage of the AI System life cycle. This must address: the oversight and approval process for developing, adopting or acquiring AI Systems; data practices and accountability procedures covering data currency, lineage, quality, integrity, bias analysis and minimisation, and suitability; management and oversight of Predictive Models including inventories and descriptions, detailed development and use documentation, and assessments of interpretability, repeatability, robustness, regular tuning, reproducibility, traceability, Model Drift and the auditability of those measurements; validating, testing and retesting as necessary to assess the generalisation of AI System outputs upon implementation, including whether the training data was suitable and comparing model performance on unseen data against post-implementation performance; protection of non-public consumer information including unauthorised access to the Predictive Models themselves; and data and record retention. Governance must also cover the insurer's processes for detecting and addressing errors, performance issues, outliers or unfair discrimination in insurance practices resulting from a Predictive Model.

Deadline: February 11, 2025

NJ DOBI Bulletin No. 25-03 (Feb. 11, 2025), AIS Program Guidelines 2.4 and 3.0-3.7. Substantive standard supplied by the Property and Casualty Rating Laws enumerated in Section 1 — N.J.S.A. 17:29A-1 et seq. (motor vehicle), N.J.S.A. 17:29AA-1 et seq. (commercial lines), N.J.A.C. 11:1-2.1 et seq., N.J.A.C. 11:3-16.1 et seq., N.J.A.C. 11:4-9.1 et seq. and N.J.A.C. 11:13-8.1 et seq. — which require that rates not be excessive, inadequate or unfairly discriminatory regardless of the methodology used to develop them.

Prevent Algorithmic Discrimination Under the NJ Law Against Discrimination

Critical

The LAD applies to discrimination arising from automated decision-making tools exactly as it applies to any other discriminatory conduct — it "draws no distinctions based on the mechanism of discrimination". A covered entity (employer, housing provider, place of public accommodation, credit provider, contractor, or any other party subject to the LAD) can violate the LAD through an automated decision-making tool in two ways. DISPARATE TREATMENT: designing or using a tool to treat members of a protected class differently, selectively applying a tool only to members of a protected class, or using a tool that makes recommendations on a close proxy for a protected characteristic. DISPARATE IMPACT: using a tool whose recommendations or decisions disproportionately harm members of a protected class — prohibited unless the use is necessary to achieve a substantial, legitimate, nondiscriminatory interest AND there is no less discriminatory alternative that would achieve the same interest. Two facts drive the compliance posture: liability does NOT require intent to discriminate, and liability is NOT avoided because a third party built the tool or because the entity does not understand the tool's inner workings. Protected characteristics include actual or perceived race, religion, colour, national origin, sexual orientation, pregnancy, breastfeeding, sex, gender identity, gender expression and disability, among others.

Deadline: January 31, 2025

NJ Law Against Discrimination, N.J.S.A. § 10:5-1 et seq.; protected characteristics at N.J.S.A. § 10:5-12; disparate treatment provisions at N.J.S.A. § 10:5-12(a), (f), (g); disparate impact standard at 56 N.J.R. 969(a). Interpreted by NJ OAG / Division on Civil Rights, "Guidance on Algorithmic Discrimination and the New Jersey Law Against Discrimination" (January 2025), Section II. Supporting authority cited in the guidance: Lehman v. Toys 'R' Us, Inc., 132 N.J. 587, 604-05 (N.J. 1993) ("The LAD is not a fault- or intent-based statute"); Gerety v. Atl. City Hilton Casino Resort, 184 N.J. 391, 398-99 (2005); Nini v. Mercer Cty. Cmty. Coll., 202 N.J. 98, 115 (2010).

Honour Opt-Outs From Profiling With Legal or Similarly Significant Effects

Critical

Provide New Jersey consumers with the right to opt out of the processing of their personal data for purposes of profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer — alongside the parallel rights to opt out of targeted advertising and of the sale of personal data. Do not discriminate against a consumer for exercising any of these opt-outs. A consumer may exercise the right personally or through a designated authorized agent, and a controller must comply with an opt-out received from an authorized agent where it can verify, with commercially reasonable effort, both the consumer's identity and the agent's authority to act. This right is the operative AI hook in the NJDPA: an automated decision that materially affects a consumer is reachable through the profiling opt-out even though New Jersey has no standalone automated-decision statute.

Deadline: January 15, 2025

New Jersey Data Privacy Act, P.L.2023, c.266; consumer rights at N.J.S.A. 56:8-166.10; authorized-agent and opt-out mechanics at N.J.S.A. 56:8-166.11(a); anti-retaliation for opting out at N.J.S.A. 56:8-166.8.

Recognise a Universal Opt-Out Mechanism

Critical

A controller that processes personal data for purposes of targeted advertising or the sale of personal data must allow consumers to exercise the opt-out right through a user-selected universal opt-out mechanism — in practice, an opt-out preference signal such as Global Privacy Control. The statute frames this as an additional channel, not a substitute: the controller must still offer its own opt-out route. SCOPE PRECISION: as enacted, the universal-opt-out duty is written to cover targeted advertising and the sale of personal data. It is NOT written to extend to profiling; the separate authorized-agent provision reaches profiling only "when such technology exists". Secondary summaries frequently blur this and describe a universal opt-out covering profiling — do not repeat that framing to customers.

Deadline: July 15, 2025

N.J.S.A. 56:8-166.11(b)(1): "Beginning not later than six months following the effective date of P.L.2023, c. 266, a controller that processes personal data for purposes of targeted advertising, or the sale of personal data shall allow consumers to exercise the right to opt out of such processing through a user-selected universal opt-out mechanism." The Act took effect 2025-01-15, placing the compliance date at 2025-07-15.

Report Breaches to the NJ State Police BEFORE Notifying Customers

Critical

New Jersey inverts the sequencing most incident-response templates assume. Any business or public entity required to disclose a breach of security of a customer's personal information must, IN ADVANCE of the disclosure to the customer, report the breach and any information pertaining to it to the Division of State Police in the Department of Law and Public Safety, for investigation or handling — which may include dissemination or referral to other appropriate law enforcement entities. Only then may customer notification proceed, which must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement. Build the State Police report into the incident-response runbook as a blocking step ahead of customer notice; notifying customers first is itself the violation, independent of whether the customer notice was timely. This matters directly for AI deployments: models, training corpora and vector stores holding New Jersey customers' personal information are in scope like any other system.

Deadline: January 1, 2006

N.J.S.A. 56:8-163(c)(1) (verbatim: any business or public entity required to disclose a breach "shall, in advance of the disclosure to the customer, report the breach of security and any information pertaining to the breach to the Division of State Police in the Department of Law and Public Safety for investigation or handling"); customer-notice timing standard at N.J.S.A. 56:8-163(a); law-enforcement delay at N.J.S.A. 56:8-163(c)(2). Source: codes.findlaw.com, stamped "Current as of January 01, 2024".

Consent Policy for AI-Generated Likenesses

High Priority

Implement a written policy for any AI-generated content involving real individuals' likenesses, voices, or images. Obtain and document explicit consent before generating or distributing AI content depicting identifiable people. Maintain records of all authorizations.

Deadline: April 2, 2025

New Jersey A3540/S2544, signed 2025-04-02, enacted as P.L.2025, c.40

Third-Party AI Vendor Diligence and Contractual Audit Rights — Insurers

High Priority

The AIS Program must address the insurer's process for acquiring, using or relying on (i) third-party data used to develop AI Systems and (ii) AI Systems developed by a third party. This includes due diligence and the methods used to assess the third party and its data or AI Systems, so as to ensure that decisions made or supported by those systems which could lead to Adverse Consumer Outcomes will meet the legal standards imposed on the insurer itself. Where appropriate and available, contracts with third parties should include terms that provide audit rights and/or entitle the insurer to receive audit reports from qualified auditing entities, and that require the third party to cooperate with the insurer on regulatory inquiries and investigations relating to the insurer's use of the third party's product or services. The insurer should also exercise those contractual audit rights to confirm the third party's compliance with contractual and, where applicable, regulatory requirements.

Deadline: February 11, 2025

NJ DOBI Bulletin No. 25-03 (Feb. 11, 2025), AIS Program Guidelines 1.8 and 4.0-4.3; examination expectations at Section 4, items 1.2 and 2.0-2.4. "Third Party" is defined in Section 2 as an organization other than the insurer that provides services, data, or other resources related to AI.

Notify Insurance Consumers That AI Systems Are In Use

High Priority

The AIS Program must include processes and procedures providing notice to impacted consumers that AI Systems are in use, and providing access to appropriate levels of information based on the phase of the insurance life cycle in which the AI Systems are being used. This is a distinct, affirmative consumer-facing duty in the bulletin — it is not satisfied by internal governance documentation alone. It pairs with the bulletin's expectation that the transparency and explainability of outcomes to the impacted consumer is one of the factors determining how extensive the insurer's controls must be.

Deadline: February 11, 2025

NJ DOBI Bulletin No. 25-03 (Feb. 11, 2025), AIS Program Guideline 1.9; transparency factor at Section 3 (factor (iv), transparency and explainability of outcomes to the impacted consumer).

Be Able to Produce AI Documentation on Departmental Demand

High Priority

Regardless of whether the insurer has a written AIS Program at all, in an investigation or market conduct action the insurer can expect to be asked about the development, deployment and use of its AI Systems, about any specific Predictive Model or AI System and its outcomes (including Adverse Consumer Outcomes), and for any other information the Department deems relevant. Maintain retrievable evidence covering: the written AIS Program and documentation evidencing its adoption; the Program's scope, including which AI Systems and technologies are NOT covered by it; how the Program is proportionate to the insurer's AI use and the Degree of Potential Harm to Consumers; policies, procedures, guidance and training materials; documentation of the formation and ongoing operation of the insurer's AI coordinating bodies; data practices and accountability procedures; inventories and descriptions of Predictive Models and AI Systems used to make or support decisions that can result in Adverse Consumer Outcomes; for any model under examination, documentation of compliance with the insurer's own AI policies plus information on data source, provenance, lineage, quality, integrity, bias analysis and minimisation, suitability and currency, and the techniques, measurements and thresholds used; and documentation of validation, testing and auditing including evaluation of Model Drift.

Deadline: February 11, 2025

NJ DOBI Bulletin No. 25-03 (Feb. 11, 2025), Section 4 ("Regulatory Oversight and Examination Considerations"), items 1.1-1.3 and 2.0-2.4; investigation authority under Market Conduct Surveillance, N.J.S.A. 17:23-20 et seq.

Ensure Automated Tools Do Not Defeat Reasonable Accommodations

High Priority

Algorithmic discrimination can violate the LAD where an automated decision-making tool precludes or impedes the provision of reasonable accommodations, or of modifications to policies, procedures or physical structures needed for accessibility, on the basis of disability, religion, pregnancy or breastfeeding status. Three failure modes are identified in the guidance. (1) The tool itself is inaccessible to individuals with disabilities or others with a protected characteristic — for example a typing-speed assessment that cannot measure typing from a non-traditional keyboard. (2) The tool was not trained on data including individuals who use an accommodation, so it fails to recognise that an accommodation is possible or penalises candidates who need one — a covered entity that acts on such a recommendation may engage in disparate impact discrimination. (3) The tool fails to account for an accommodation the entity has already granted — for example productivity-monitoring software that flags atypical or unsanctioned breaks without being programmed to allow for breaks granted to accommodate a disability or milk expression; an employer that accepts the tool's recommendation to discipline those employees may violate the LAD. The LAD requires a covered entity to make reasonable accommodations based on protected-class membership where the entity knew or should have known of the need and the accommodation would not cause undue hardship.

Deadline: January 31, 2025

NJ OAG / DCR "Guidance on Algorithmic Discrimination and the New Jersey Law Against Discrimination" (January 2025), Section II, "Reasonable Accommodations". Underlying authority: N.J.A.C. § 13:13-2.5 (employment); N.J.A.C. § 13:13-3.4(f)(2) (housing); N.J.A.C. § 13:13-4.11 (public accommodations); N.J.S.A. § 10:5-12(q) (religion); N.J.S.A. § 10:5-12(s) (pregnancy and breastfeeding).

Conduct Data Protection Assessments for Higher-Risk Processing

High Priority

Conduct and document a data protection assessment for each processing activity that presents a heightened risk of harm to a consumer. The Act reaches, at minimum: processing personal data for purposes of targeted advertising; the sale of personal data; the processing of sensitive data; and profiling where the profiling presents a reasonably foreseeable risk of (i) unfair or deceptive treatment of, or unlawful disparate impact on, consumers, (ii) financial or physical injury to consumers, or (iii) a physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers where that intrusion would be offensive to a reasonable person. For AI deployments the profiling limb is the operative trigger — the disparate-impact language means an automated tool that materially affects New Jersey consumers is assessable under the NJDPA and, separately, under the NJLAD (see nj_lad_algorithmic_discrimination). Retain the assessment: it is the artefact the Attorney General will ask for.

Deadline: January 15, 2025

New Jersey Data Privacy Act, P.L.2023, c.266, data protection assessment provision at N.J.S.A. 56:8-166.13. HONEST SOURCING NOTE: the enrolled text of this section could not be fetched directly this session (njleg hosts refused connection; the FindLaw mirror is stamped "Current as of January 01, 2024" and did not serve this section), so the trigger list above is stated at the level the enrolled act's own language supports and the citation is not narrowed to a subsection that was not read.

Obtain Consent Before Processing Sensitive Data

High Priority

Do not process a consumer's sensitive data without first obtaining the consumer's consent. Consent under the Act must be an affirmative, freely given, specific, informed and unambiguous choice — it cannot be inferred from silence, pre-ticked boxes, or continued use of a service. For AI systems this bites at the training and feature-engineering stage as much as at inference: ingesting sensitive attributes into a model without consent is processing. Note that New Jersey's definition of sensitive data is broader than several peer states — it expressly reaches financial information alongside the more common categories, and the Act separately restricts processing the personal data of consumers the controller knows or wilfully disregards to be children aged 13 through 16 for targeted advertising, sale, or profiling without consent.

Deadline: January 15, 2025

New Jersey Data Privacy Act, P.L.2023, c.266 (N.J.S.A. 56:8-166.4 et seq.). HONEST SOURCING NOTE: the precise subsection carrying the sensitive-data consent duty could not be pinned against enrolled text this session (see the entry-level source log — njleg unreachable, Justia 403, FindLaw mirror predates the Act), so the citation is deliberately left at act level rather than guessed at a subsection number. The substance is stated only to the extent the enrolled act's own language supports it.

Who Does This Apply To?

Four independent scopes, which must be assessed separately because an organisation can fall inside one and outside the others. (1) DEEPFAKES (A3540/S2544, P.L.2025, c.40): any person who knowingly creates, or knowingly and recklessly distributes, deceptive AI-generated audio or visual media depicting a real person, where the conduct occurs in or affects New Jersey or its residents. No business-size threshold — individuals and organisations are equally within scope. The operative trigger is producing such media for an unlawful purpose, or distributing media known to have been created for one. Remedies are criminal (third-degree: up to 5 years imprisonment and/or a fine up to $30,000) and a private civil right of action for the depicted victim. The Act expressly exempts satire, parody, news reporting, teaching and research, and does not reach internet service providers, broadcasters or media platforms that inadvertently distribute such content; constitutionally protected expression and consented-to uses fall outside the core prohibition. (2) INSURANCE (DOBI Bulletin 25-03): ALL insurers authorized or admitted in New Jersey, with no premium-volume or size threshold — expressly including insurers that have chosen not to adopt a written AIS Program, who remain subject to the examination expectations regardless. Depth of the expected program scales with the insurer's use of and reliance on AI and the Degree of Potential Harm to Consumers, not with company size. (3) DATA PRIVACY (NJDPA): controllers that conduct business in New Jersey or produce products or services targeted to New Jersey residents AND, during a calendar year, either control or process the personal data of at least 100,000 consumers (excluding data processed solely to complete a payment transaction), or control or process the personal data of at least 25,000 consumers while deriving revenue or a discount from the sale of personal data (N.J.S.A. 56:8-166.5) — note the second limb has no percentage-of-revenue floor. (4) CIVIL RIGHTS (NJLAD): any LAD-covered entity — employer, housing provider, place of public accommodation, credit provider or contractor — using any automated decision-making tool affecting New Jersey residents, including tools it did not develop and does not understand, and including ordinary statistical tools and decision trees rather than only advanced AI. Breach notification (N.J.S.A. 56:8-163) is broader still and binds any business or public entity holding computerised personal information of New Jersey customers, independent of all four scopes above. NOT IN SCOPE, verified this session: New Jersey has no enacted automated-employment-decision-tool statute (A3854 and A3911 remain unenacted bills) and no biometric-privacy act.

Recent Regulatory Guidance

guidance2025-02-11

NJ DOBI Bulletin No. 25-03 — The Use of Artificial Intelligence Systems in Insurance

Commissioner Justin Zimmerman issued Bulletin 25-03 on 2025-02-11 to ALL insurers authorized or admitted in New Jersey, adopting the NAIC model AI bulletin framework. It expects every such insurer to develop, implement and maintain a written AI Systems ("AIS") Program addressing governance, risk management controls and internal audit, with senior management accountable to the board; covering the full insurance life cycle and the full AI System life cycle; covering vendor-built as well as in-house systems; providing notice to impacted consumers that AI Systems are in use; and documenting predictive-model validation, testing, bias analysis and Model Drift. Section 4 sets out, at length, the documentation the Department may demand in an investigation or market conduct action — expressly including from insurers that have no written AIS Program. Issued as guidance under existing law (UTPA, UCSPA, CGAD, the P&C rating laws and market conduct surveillance); effective on issuance, with no separate compliance date and no bulletin-specific penalty.

guidance2025-01

NJ AG / Division on Civil Rights — Guidance on Algorithmic Discrimination and the NJLAD

Issued January 2025 by Attorney General Platkin and DCR Director Sundeep Iyer alongside the launch of a Civil Rights and Technology Initiative. The guidance explains that the LAD applies to algorithmic discrimination exactly as to any other discriminatory conduct, because it "draws no distinctions based on the mechanism of discrimination", and covers employment, housing, places of public accommodation, credit and contracting. Two findings drive compliance: a covered entity can violate the LAD with no intent to discriminate, and is not immunised because a third party built the tool or because it does not understand the tool's inner workings. It analyses disparate treatment (including proxy discrimination), disparate impact (prohibited unless necessary to a substantial, legitimate, nondiscriminatory interest with no less discriminatory alternative), and reasonable accommodations. CRITICAL LIMIT, from the guidance's own footnote 1: it imposes no new or additional requirements beyond the LAD and establishes no rights or obligations — it is interpretive, not a rule, and bias testing is described as relevant evidence rather than a mandate.

guidance2026-06-02

NJDPA implementing rules proposed 2025-06-02 EXPIRED unadopted 2026-06-02

The Division of Consumer Affairs proposed comprehensive NJ Data Privacy Act rules (N.J.A.C. 13:45L) on 2025-06-02 at 57 N.J.R. 1101(a), with comments closing 2025-08-01; the proposal covered universal opt-out mechanism specifications (13:45L-5.1, 5.2), data minimisation documentation (13:45L-6.3) and consent for sensitive data and for the data of children aged 13-17. The proposal was never adopted and lapsed on 2026-06-02 under the one-year APA proposal window, and no replacement rulemaking has been proposed. PRACTICAL EFFECT: there are NO New Jersey data privacy regulations in force — the statute alone governs, and there is no state technical specification for universal opt-out mechanisms. Do not advise customers that N.J.A.C. 13:45L binds them.

guidance2025-04-02

Governor Murphy signs A3540 into law (April 2, 2025)

Governor Murphy signed A3540/S2544 on 2025-04-02, establishing third-degree criminal penalties (3-5 years imprisonment, up to $30,000 fine, or both) for producing deepfake audio/visual media for an unlawful purpose or distributing deepfakes known to have been created for one — covering advertising commercial sexual abuse of a minor, endangering child welfare, threats/improper influence in official/political matters, false public alarms, harassment, cyber-harassment, and hazing. Also creates victim civil liability (private right of action).

Key Case Law & Precedent

FCC AI-Robocall Declaratory Ruling (February 2024) + In re Steve Kramer Forfeiture Order (September 2024)

US Federal Communications Commission · 2024

The FCC's 2024-02-02 declaratory ruling confirmed the TCPA's "artificial or prerecorded voice" prohibition covers AI-generated/cloned voices, effective immediately, requiring prior express consent for AI voice robocalls. The companion enforcement action — the AI-voice-cloned Biden robocall targeting New Hampshire primary voters — resulted in a $6,000,000 FCC forfeiture order against Steve Kramer (confirmed/adopted 2024-09-26) and a separate $1,000,000 FCC settlement with carrier Lingo Telecom. Illustrative of the federal AI-voice-fraud enforcement backdrop against which NJ A3540's state criminal/civil layer operates — not confirmed as a case the NJ AG has itself cited.

Outcome: Declaratory ruling: AI-generated voice classified as "artificial" under TCPA, effective immediately. Companion enforcement: $6,000,000 FCC forfeiture order (Kramer, adopted 2024-09-26) + $1,000,000 FCC settlement (Lingo Telecom) — two separate amounts, not additive into a single ">$6M" figure.

Case reference

Industry Playbooks covering New Jersey — AI, Data Privacy, Insurance AI & Algorithmic Discrimination

These industry playbooks include jurisdiction-specific checklist items and guidance for New Jersey — AI, Data Privacy, Insurance AI & Algorithmic Discrimination.

Frequently Asked Questions

Does New Jersey — AI, Data Privacy, Insurance AI & Algorithmic Discrimination apply to my business?

New Jersey regulates AI across four distinct, independently enforceable surfaces. (1) DEEPFAKES: A3540/S2544, signed 2025-04-02 (P.L.2025, c.40), makes producing or distributing deceptive AI-generated audio/visual media for an unlawful purpose a… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under New Jersey — AI, Data Privacy, Insurance AI & Algorithmic Discrimination is: Deepfakes (A3540 / P.L.2025, c.40): third-degree crime — up to 5 years imprisonment and/or a fine up to $30,000 — plus a private civil right of action. Data Privacy Act and breach-notification violations: unlawful practices under the Consumer Fraud Act, carrying civil penalties of not more than $10,000 for a first offense and not more than $20,000 for each subsequent offense (N.J.S.A. 56:8-13). Insurance Bulletin 25-03 and the NJLAD algorithmic-discrimination guidance impose no bulletin- or guidance-specific penalty of their own; exposure runs through the underlying statutes each instrument interprets.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with New Jersey — AI, Data Privacy, Insurance AI & Algorithmic Discrimination?

The 14 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.nj.gov/governor/news/news/562025/20250402a.shtml

Last updated: 2026-08-25 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan