To enact section 9.89 of the Revised Code to limit further regulation of certain computational systems, require risk management policies for AI-controlled critical infrastructure, and to name this act the Ohio Right to Compute Act.
HB392, titled the Ohio Right to Compute Act, would add a new section to the Revised Code limiting state and local regulation of “computational resources,” a term defined broadly to include hardware, software, algorithms, cryptography, artificial intelligence systems, machine learning systems, quantum computing tools, and related technologies. Under the bill, state agencies and political subdivisions could not restrict or prohibit a person’s lawful use, development, deployment, or possession of these resources unless the restriction is narrowly tailored to serve a compelling governmental interest.
The bill also creates a specific compliance requirement for any person or entity that operates an artificial intelligence system that in whole or part controls a critical infrastructure facility. Before or shortly after deployment, the operator would have to adopt a risk management policy aligned with the latest NIST AI Risk Management Framework, ISO/IEC 42001 or another recognized AI risk standard, and all applicable federal regulations. The requirement would not apply to systems limited to nonexecutive or preparatory tasks, systems that only implement prior human decisions, or AI used exclusively as antivirus, antimalware, or cybersecurity tools.
HB392 would preempt a broad range of state and local restrictions on computational technologies by setting a high legal standard—narrow tailoring to a compelling governmental interest—for any regulation affecting lawful use, development, deployment, or possession of computational resources. It would likely affect future Ohio rules involving AI, software, data centers, quantum computing, and other digital systems, while preserving certain government interests such as critical infrastructure reliability, fraud prevention, protection against harmful deepfakes, and nuisance abatement tied to data center facilities. The bill would also impose a new operational compliance obligation on operators of AI systems used in critical infrastructure, potentially affecting utilities, transportation, communications, and other infrastructure sectors.
The available context shows the bill was introduced and referred to the House Technology and Innovation Committee, with no recorded votes or committee testimony provided. Based on the text, the bill appears to reflect a pro-innovation, technology-friendly approach that seeks to limit regulatory barriers while still acknowledging targeted public-safety concerns. Because there is no transcript or vote history, there is no documented opposition or support to characterize beyond the bill’s stated policy balance.
The main point of contention is likely the bill’s broad restriction on state and local regulation of computational resources, which could be viewed by critics as limiting Ohio’s ability to respond to emerging harms from AI, software, and related technologies. Supporters would likely emphasize the need to protect innovation and prevent fragmented or overly burdensome regulation. Another likely area of debate is the scope of the critical infrastructure AI requirement, including whether the mandated risk-management standards are sufficiently flexible and whether the exemptions for nonexecutive or cybersecurity-only systems are appropriately drawn.