Market
AI law in Arizona
7 binding provisions TwinEthos encodes that reach Arizona (US-AZ): 7 in force, 0 enacted but not yet applying. Start from the guards to add.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Includes US federal law, which applies in every state. See also United States (federal).
Get the build plan for Arizona
The guards that cover the most here
58 guards address 99 items across 2 jurisdictions with binding law: 7 binding law in force, 0 enacted but not yet applying, 59 standards and frameworks, 33 TwinEthos recommended guardrails.
AI agent configured to pose as, or claim affiliation with, a government body or a business it does not represent
Make the agent's persona, greeting, and scripts name only the operating organization, and never instruct it to claim a government or third-party business identity or endorsement.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
AI or algorithm denies, delays or downgrades care in utilization review without a licensed clinical reviewer deciding
Route every adverse outcome an AI or algorithm proposes in utilization review to a qualified clinical reviewer, and issue a denial only from that reviewer's recorded decision.
Addresses 1 item: 1 binding law in force
Law in force in Arizona (US-AZ).
Children's personal information copied into AI stores is kept without a retention limit or deletion
Give every store of children's data in an AI feature (transcripts, audio, embeddings, training sets) a retention period from a written policy and delete on schedule.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
Health information sent to an external AI vendor without the contractual or legal basis the law requires
Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
More health information than the task needs is sent to an AI model
Build AI prompts, context and fine-tuning rows from a per-task allowlist of health-record fields, never by serializing a whole patient record or FHIR bundle.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
A child below the national age threshold uses an AI feature without the consent of a parent or guardian
Gate every AI feature on an age check and, for a user below the legal threshold, on a verified parental or guardian consent record.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
User content used for model training without purpose-limited consent
Prefer checking a training-specific, unwithdrawn consent record before user content enters any training, fine-tuning, or evaluation dataset, and record lineage per model.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
GenAI with untracked third-party components (value chain)
Keep an inventory of every third-party model, dataset, package, plugin, and MCP server with pinned versions, its reviewed model card or vendor due-diligence record, and an owner.
Addresses 5 items: 4 standards · 1 recommended guardrail
Agent high-impact action without human approval
Classify agent tools by impact and route every high-impact or irreversible call through an enforced human-approval step in the executor, with the decision logged.
Addresses 4 items: 3 standards · 1 recommended guardrail
AI inputs, outputs and tool calls not recorded as redacted, retained security telemetry
Trace every model and tool call as a security event, and keep raw prompt and output text out of general logs.
Addresses 4 items: 3 standards · 1 recommended guardrail
The top 10 of 58; the build plan ranks all of them and lets you narrow by AI feature.
By AI feature
Plans for one feature in Arizona:
- Chat or assistant
- Answers from your documents (RAG)
- Agents that use tools or take actions
- Decisions about people (hiring, credit, insurance, health)
- Generated text, images, audio or video
- Classification, scoring or biometrics
- Embeddings and vector search
Laws
- Arizona HB 2175 (Laws 2025, ch. 165; A.R.S. 20-3103, 20-3407) Arizona (US-AZ)
- COPPA Rule (16 CFR Part 312), as amended 2025 United States (federal) (US)
- FTC Impersonation Rule (16 CFR Part 461) United States (federal) (US)
- HIPAA Privacy Rule (45 CFR 160, 164 Subpart E) United States (federal) (US)
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.