H.341 would create a new chapter in Vermont law establishing oversight, safety, and liability standards for certain artificial intelligence systems that the bill labels “inherently dangerous.” The bill defines that category to include high-risk AI systems, dual-use foundational models, and generative AI systems, and it applies only to non-small businesses that develop, distribute, or deploy covered systems in Vermont or produce products or services consumed by Vermont residents. It also defines key terms such as deployer, developer, consequential decision, biometric data, and substantial modification.
The bill requires deployers of covered systems to submit periodic Artificial Intelligence System Safety and Impact Assessments to a new Division of Artificial Intelligence within the Agency of Digital Services, with additional testing reports for high-risk systems during the first year of deployment. Those assessments must describe the system’s purpose, use cases, training data, transparency measures, monitoring, third-party dependencies, and impacts on consequential decisions or biometric data collection. Developers must document foreseeable risks and mitigation measures, and both developers and deployers must follow a standard of reasonable care to avoid foreseeable harms such as unlawful conduct, discrimination, privacy intrusions, intellectual property violations, and exploitation of vulnerable groups.
The bill also prohibits developers from placing an inherently dangerous AI system into commerce unless it has been tested and validated at least as stringently as the latest NIST AI Risk Management Framework, and it prohibits deployers from using such systems without a risk management policy and program meeting similar standards. Enforcement would be handled by the Attorney General, who could seek injunctions and use civil investigative demands, while consumers harmed by violations would have a private right of action for damages, injunctive relief, punitive damages in intentional cases, and attorney’s fees. The bill further states that compliance does not eliminate existing common-law or statutory causes of action.
The overall sentiment reflected by the bill text is strongly precautionary and consumer-protective. Its findings emphasize that AI can shift decision-making away from humans and can create serious risks if not carefully controlled, and the structure of the bill shows a preference for disclosure, monitoring, and accountability over voluntary compliance. Because there are no committee transcripts or recorded votes provided, there is no direct evidence of legislative debate or formal support/opposition in the available context.
The main points of contention likely center on the breadth of the bill’s definitions and compliance obligations. The inclusion of generative AI and dual-use foundational models, along with broad duties for developers and deployers, could raise concerns about regulatory burden, especially for companies that are not small businesses but still operate at scale. Potential friction points also include the private right of action, the Attorney General’s enforcement powers, the requirement to disclose sensitive information while protecting trade secrets, and whether the NIST-based standard is sufficiently clear or flexible for rapidly changing AI technologies.
H.341 would add a new AI-specific consumer protection and safety regime to Title 9 of Vermont law, creating duties for developers and deployers of covered artificial intelligence systems, establishing state oversight through a new Division of Artificial Intelligence, and authorizing Attorney General enforcement and consumer lawsuits. It would not preempt existing common-law or statutory claims, and it would apply prospectively beginning July 1, 2025.
The bill’s tone and structure indicate a generally cautious, pro-regulation approach aimed at preventing harms from advanced AI systems. Because no committee testimony or vote history is provided, there is no recorded legislative sentiment to summarize beyond the bill’s own strong emphasis on safety, transparency, and accountability.
Likely areas of contention include how broadly the bill defines “inherently dangerous” AI, whether generative AI and dual-use foundational models should be regulated the same as high-risk systems, and whether the reporting, testing, and risk-management requirements are too burdensome for industry. Other likely disputes involve the private right of action, the Attorney General’s enforcement authority, the treatment of trade secrets, and whether the bill could chill innovation or impose compliance costs that are difficult to meet in a fast-moving technology sector.