To enact sections 3755.01, 3755.02, 3755.03, 3755.04, 3755.041, 3755.05, 3755.06, 3755.07, 3755.08, 3755.09, 3755.091, 3755.10, 3755.11, and 3755.12 of the Revised Code to create an independent verification organization license for verifying artificial intelligence risk mitigation.
HB628 would create a new licensing framework for “independent verification organizations” that would be authorized by the Ohio attorney general to evaluate whether artificial intelligence models and applications are mitigating specified risks at acceptable levels. The bill defines key terms such as developer, deployer, security vendor, and independent verification organization, and requires applicants for licensure to submit a detailed plan covering the risks they will verify, the metrics and benchmarks they will use, monitoring and reporting protocols, corrective-action procedures, revocation standards, governance policies, funding sources, and coordination with state and federal authorities.
The bill also establishes an artificial intelligence safety advisory council in the attorney general’s office, with members appointed by the attorney general in consultation with the auditor of state. The council would help evaluate applications, and the attorney general could delegate licensing duties to it. Licensed organizations would conduct ongoing verification, issue annual reports, and notify the attorney general of material changes to their methods. The bill further gives the attorney general rulemaking authority to set conflict-of-interest standards, application requirements, corrective-action triggers, council composition, and compensation.
A notable feature of HB628 is that it ties verification to liability protection: in civil actions for personal injury or property damage, a rebuttable presumption against liability would apply if the AI system was verified by a licensed organization for the relevant risk and market segment. That presumption could be overcome by clear and convincing evidence of misconduct, misrepresentation, nondisclosure of new risks, failure to meet verification conditions, or failure to implement corrective actions. In effect, the bill creates both a regulatory approval structure and a potential legal incentive for developers and deployers to seek verification.
The bill’s impact on state law would be significant because it adds a new chapter to the Revised Code governing AI risk verification, creates new administrative duties for the attorney general, and introduces ongoing oversight, reporting, and revocation mechanisms for licensed verifiers. It would affect AI developers, deployers, third-party auditors, and potentially litigants in product-liability or negligence cases involving AI-related harm. It also authorizes fees to fund administration and requires public redacted reporting, while preserving confidentiality for trade secrets, sensitive security information, and personal data.
Overall, the bill appears to be framed as a pro-safety, pro-accountability measure, with a generally cautious and technical approach to AI governance. Because the bill was only introduced and there are no recorded committee transcripts or votes in the provided materials, there is no documented floor or committee sentiment to gauge beyond the bill’s structure itself. The main likely point of contention is the breadth of attorney general authority and the practical burden on AI companies and verifiers, especially around compliance costs, independence requirements, and the liability presumption tied to verification.
HB628 would create a new Ohio Revised Code chapter establishing licensure for independent verification organizations that assess artificial intelligence risk mitigation. It would expand the attorney general’s regulatory authority, create an advisory council, require rulemaking, impose reporting and audit obligations, and establish a rebuttable presumption against liability in certain AI-related injury and property-damage cases when verification conditions are met. The bill would directly affect AI developers, deployers, third-party evaluators, and civil litigants, while also authorizing fees to support administration.
The bill’s design suggests a generally favorable, safety-oriented sentiment toward structured AI oversight, with an emphasis on independent review, ongoing monitoring, and public accountability. However, because the bill was introduced without recorded committee testimony or votes in the provided materials, there is no direct evidence of support or opposition from lawmakers or stakeholders. The likely policy mood is cautious and regulatory rather than permissive, reflecting concern about AI-related harms and the need for formal verification standards.
The most notable potential contention is the scope of the attorney general’s authority to license, oversee, and revoke independent verification organizations, including the power to define acceptable mitigation standards and approve or reject methodological changes. Another likely point of debate is the bill’s liability presumption, which could be viewed by supporters as an incentive for safer AI practices but by critics as a shield for developers if verification is too easily obtained. Independence requirements, conflict-of-interest rules, compliance costs, and the burden of ongoing disclosure and monitoring for AI companies are also likely areas of concern.