A bill for an act relating to restrictions on the use of artificial intelligence, and creating a civil cause of action.
HF 406 would create a new Iowa Code chapter regulating artificial intelligence used in smart devices and AI-enabled applications, with a focus on notice, user consent, and data-use limits. For smart devices sold in Iowa on or after July 1, 2025, device companies would have to present a separate agreement at device initialization disclosing that AI is installed, explaining any access to private data, offering an option to uninstall the AI, and, if AI remains installed, allowing the user to refuse access to each category of private data before access occurs. Similar requirements would apply to developers of AI-enabled applications that are designed to access private data, including a separate startup agreement, a statement of purpose, and an interactive consent form.
The bill also restricts how device companies and app developers may use private data once access is authorized. They could not access categories of private data not authorized by the user, use the data in ways not disclosed in the statement of purpose, or transfer, maintain, disseminate, or delete transferred data inconsistently with that statement. Device companies would also be prohibited from requiring AI installation as a condition of using a smart device and would have to provide a clear way to uninstall AI installed by the company.
In addition, HF 406 creates a right of action against anyone who intentionally uses AI to recreate a person’s audio or visual likeness without consent when the likeness is substantially indistinguishable from the individual and is used for commercial activity, an unsupported political campaign, offensive false impressions, reputational harm, or to induce someone to act or disclose information. The bill authorizes actual and punitive damages, attorney fees, costs, and class actions, with punitive damages capped at $250,000 per violation. It also treats each affected device or day of violation as a separate violation for damages purposes.
The bill’s overall sentiment appears cautious and consumer-protective rather than anti-technology. The only recorded action provided is that a subcommittee recommended passage, suggesting at least some legislative support at the committee level. The bill is framed around transparency, user control, and protection against deceptive or harmful AI uses, especially involving personal data and likeness rights.
The main points of contention are likely to involve the breadth of the definitions and compliance burdens on device manufacturers and app developers, especially the requirement for separate consent flows and ongoing updates when statements of purpose change. Another likely issue is the scope of the likeness restriction, which reaches commercial, political, and reputational uses of AI-generated replicas, and the bill’s private right of action with punitive damages and class-action exposure, which could raise concerns from technology companies and other potential defendants.
HF 406 would add a new chapter to Iowa law governing AI use in smart devices and AI-enabled applications, imposing disclosure, consent, uninstall, and data-handling requirements on device companies and developers. It would also create a new civil cause of action for violations, including actual and punitive damages, attorney fees, costs, and class actions, while establishing a separate consent-based right of publicity-style protection against unauthorized AI-generated audio or visual likenesses. The bill would directly affect manufacturers of smart devices, software/app developers, and anyone using AI to create realistic digital replicas of individuals.
The available record suggests generally favorable or at least forward-moving sentiment, with a subcommittee recommending passage and no recorded votes or transcript opposition provided. The bill’s structure indicates a consumer-privacy and anti-deepfake policy approach, emphasizing informed consent and control over personal data. Because no committee transcript is included, there is no direct evidence of debate, but the bill’s advancement implies some support for regulating AI rather than leaving it entirely unregulated.
Likely areas of contention include whether the bill’s consent and disclosure requirements are too burdensome for device companies and app developers, especially given the need for separate startup agreements, ongoing updates, and granular refusal options for each type of private data. The private cause of action, class-action authorization, and punitive damages cap of $250,000 per violation may also draw concern from industry groups due to litigation risk. The likeness provisions could be debated by free-speech advocates, media interests, political actors, and AI developers because they regulate AI-generated depictions in commercial and political contexts and could implicate expressive uses of synthetic media.