SB 936 creates a new subtitle in Maryland’s Commercial Law Article regulating “high-risk artificial intelligence systems” used to make or substantially influence consequential decisions about consumers. The bill defines covered systems and key terms, excludes certain technologies and uses, and sets out a framework focused on preventing algorithmic discrimination. It applies to developers and deployers doing business in the state and is generally aimed at consumer-facing AI used in areas such as employment, housing, lending, insurance, health care, education, legal services, and other significant decisions.
Beginning February 1, 2026, developers of high-risk AI systems would have to use reasonable care to protect consumers from known and reasonably foreseeable risks of algorithmic discrimination, provide detailed disclosures and documentation to deployers, and update those disclosures after substantial modifications. Deployers would have to implement a risk management policy, complete impact assessments before deployment and after significant updates, notify consumers when such systems are used, explain the system and its logic in plain language, and provide reasons, correction rights, and appeal opportunities when an adverse consequential decision is made. The bill also includes transparency requirements for certain generative AI outputs, including marking synthetic content in detectable ways, subject to exceptions.
The bill would also create enforcement mechanisms. The Attorney General could investigate, require disclosures, issue notices of violation, allow a 45-day cure period in some cases, adopt regulations, and bring civil actions. Civil penalties would range from up to $1,000 per violation to $10,000 for willful violations, plus attorney’s fees and costs. In addition, a consumer could bring a civil action against a deployer after first filing an administrative complaint and waiting 180 days, subject to a two-year limitations period.
The bill’s impact on state law would be to add a comprehensive consumer-protection regime for AI systems under Maryland commercial law, with compliance obligations for AI developers and deployers and new remedies for regulators and consumers. It would also create statutory definitions and carve-outs for federal systems, insurers regulated under Maryland insurance law, and certain HIPAA-covered health care uses, while preserving trade secret and security protections. The law would take effect October 1, 2025, with most operational requirements beginning February 1, 2026.
Because no committee transcripts or votes are provided, there is no recorded discussion or voting history to gauge legislative sentiment. Based on the bill text alone, the measure appears strongly consumer-protective and focused on transparency, accountability, and anti-discrimination safeguards in AI deployment. The main likely points of contention are the breadth of compliance obligations, the cost and feasibility of impact assessments and documentation, the scope of consumer notice and appeal rights, and whether the bill’s definitions of high-risk AI and consequential decisions are too broad or too narrow for industry and civil rights stakeholders.
SB 936 would amend Maryland’s Commercial Law Article by adding Subtitle 47A governing high-risk artificial intelligence developer and deployer conduct. It would impose affirmative duties on AI developers and deployers to mitigate algorithmic discrimination, conduct and retain impact assessments, provide consumer disclosures, and maintain risk management programs, while also authorizing Attorney General enforcement and limited private civil actions. The bill would affect businesses that develop or use AI systems in consumer-facing consequential decision contexts, with specific exclusions for certain federal, insurance, and HIPAA-related uses and for various low-risk or non-covered technologies.
No committee transcripts or vote records were provided, so there is no direct evidence of legislative debate or roll-call sentiment. From the bill’s structure and findings, the measure is clearly intended as a consumer-protection and civil-rights safeguard for AI use, emphasizing transparency, accountability, and discrimination prevention. The overall policy direction suggests support from lawmakers concerned about AI bias and consumer harms, while likely drawing scrutiny from technology and business stakeholders over compliance burdens and operational complexity.
The most likely points of contention are the bill’s broad regulatory scope and the practical burden it places on AI developers and deployers. Industry stakeholders may object to required disclosures, documentation, impact assessments, consumer notices, and appeal/correction procedures, especially for systems that are updated frequently or rely on proprietary models. Civil rights and consumer advocates are likely to support these requirements but may debate whether the bill’s exclusions, cure provisions, and limits on disclosure of trade secrets and confidential information weaken enforcement. Another likely issue is the definition of “high-risk” AI and whether it captures too many or too few systems, particularly in health care, employment, housing, lending, and insurance.