Market
AI law in Washington
8 binding provisions TwinEthos encodes that reach Washington (US-WA): 6 in force, 2 enacted but not yet applying. Start from the guards to add.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Includes US federal law, which applies in every state. See also United States (federal).
Get the build plan for Washington
The guards that cover the most here
48 guards address 66 items across 2 jurisdictions with binding law: 6 binding law in force, 2 enacted but not yet applying, 34 standards and frameworks, 24 TwinEthos recommended guardrails.
AI agent configured to pose as, or claim affiliation with, a government body or a business it does not represent
Make the agent's persona, greeting, and scripts name only the operating organization, and never instruct it to claim a government or third-party business identity or endorsement.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
Face or voice biometric template computed without prior notice and consent
Check a recorded, purpose-specific biometric notice and consent before any code computes, enrolls, or matches a face or voice template.
Addresses 1 item: 1 binding law in force
Law in force in Washington (US-WA).
Data erasure does not reach embeddings, vector stores or AI chat history
Make the account-deletion handler also delete the person's vector entries, embeddings, chat history, agent memory and provider-stored files or conversations.
Addresses 1 item: 1 binding law in force
Law in force in Washington (US-WA).
Health information sent to an external AI vendor without the contractual or legal basis the law requires
Send identifiable health data only to AI endpoints registered with a signed BAA or processing agreement and retention and training off; otherwise de-identify first.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
More health information than the task needs is sent to an AI model
Build AI prompts, context and fine-tuning rows from a per-task allowlist of health-record fields, never by serializing a whole patient record or FHIR bundle.
Addresses 1 item: 1 binding law in force
Law in force in United States (federal) (US).
User content used for model training without purpose-limited consent
Prefer checking a training-specific, unwithdrawn consent record before user content enters any training, fine-tuning, or evaluation dataset, and record lineage per model.
Addresses 1 item: 1 binding law in force
Law in force in Washington (US-WA).
AI chat interaction without disclosure
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
Addresses 4 items: 1 enacted, not yet applying · 2 standards · 1 recommended guardrail
enacted, not yet applying in Washington (US-WA); next date 2027-01-01.
Companion or conversational AI without a self-harm crisis protocol
Screen every user message for suicidal ideation and self-harm, return a crisis referral instead of the normal reply on detection, and block encouragement or method content.
Addresses 2 items: 1 enacted, not yet applying · 1 recommended guardrail
enacted, not yet applying in Washington (US-WA); next date 2027-01-01.
Adverse AI decision without explanation/appeal
Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome.
Addresses 3 items: 2 standards · 1 recommended guardrail
GenAI in consequential decisions without confabulation/output-validation controls
Validate GenAI output against a schema and its cited sources, and send unverifiable claims to review, before it drives a consequential decision or record.
Addresses 3 items: 2 standards · 1 recommended guardrail
The top 10 of 48; the build plan ranks all of them and lets you narrow by AI feature.
By AI feature
Plans for one feature in Washington:
- Chat or assistant
- Answers from your documents (RAG)
- Agents that use tools or take actions
- Generated text, images, audio or video
- Classification, scoring or biometrics
- Embeddings and vector search
Laws
- FTC Impersonation Rule (16 CFR Part 461) United States (federal) (US)
- HIPAA Privacy Rule (45 CFR 160, 164 Subpart E) United States (federal) (US)
- Washington HB 2225 (AI companion chatbots) Washington (US-WA)
- Washington My Health My Data Act (RCW 19.373) Washington (US-WA)
Coming into force
- : AI companion chatbots must maintain a self-harm crisis protocol (Washington) (Washington (US-WA))
- : AI companion chatbots must disclose they are not human (Washington) (Washington (US-WA))
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.