United States - Arkansas - AI Policy Requirements (Act 848)

Arkansas HB 1958 — Public Entity AI Policy Requirements (Act 848)

United States

RAI-US-AR-AH1PEXX-2025
Effective: August 3, 2025
In Force(In Force)
ActGovernance and OversightAccountability and Documentation
Export PDF

Arkansas HB 1958 (Act 848), signed April 17, 2025, requires all Arkansas public entities to create policies governing AI and automated decision tool usage. The law mandates human final decision-making authority, employee training programs, and public availability of AI policies. It passed unanimously (House 93-0, Senate 35-0, final concurrence 99-0).

Overview

Arkansas HB 1958, enacted as Act 848 on April 17, 2025, establishes the first comprehensive framework for AI governance across Arkansas public entities. Sponsored by Representative S. Meeks and Senator J. English, the legislation responds to the rapid adoption of AI tools in government operations by ensuring responsible and transparent implementation. Unlike private sector AI regulations that focus on consumer protection or anti-discrimination, Arkansas's approach emphasizes public sector accountability, requiring government agencies to maintain human decision-making authority over AI recommendations. The law reflects growing recognition that AI systems increasingly influence government decisions affecting citizens' rights, benefits, and services, necessitating clear governance frameworks. The legislation's unanimous passage—93-0 in the House, 35-0 in the Senate, and 99-0 on final concurrence—demonstrates bipartisan consensus on the importance of AI oversight in government. Governor Sarah Huckabee Sanders signed the bill as part of a broader technology governance package that included HB 1876 on generative AI ownership rights.

Definitions

HB 1958 establishes foundational definitions for Arkansas public sector AI governance. Artificial intelligence means a machine-based system that can make predictions, recommendations, or decisions based on human-defined objectives. This broad definition encompasses traditional rule-based systems, machine learning applications, and generative AI tools used in government operations. Automated decision tool is defined more specifically as a system designed to make or significantly influence consequential decisions—those materially affecting individuals' rights, opportunities, or access to services. This distinction allows agencies to apply heightened scrutiny to AI systems with direct citizen impact while maintaining flexibility for administrative AI applications. Public entity encompasses the full range of Arkansas government: state departments, agencies, boards, commissions, educational institutions (including higher education), and political subdivisions such as counties, cities, and special districts. This comprehensive scope ensures consistent AI governance across all levels of Arkansas government. Technology resources includes hardware, software, data, and network infrastructure, establishing the scope of resources subject to the law's use restrictions.

Governance and Institutional Framework

HB 1958 establishes a decentralized governance model where each public entity bears responsibility for developing and implementing its own AI policy. Rather than creating a central AI oversight agency, the law empowers individual entities to craft policies appropriate to their specific operations while mandating common elements. This approach accommodates the diverse AI applications across state government—from predictive analytics in law enforcement to chatbots in citizen services to automated benefit processing in social services. The law does not establish new enforcement agencies or positions but integrates AI governance into existing management and oversight structures. Agency heads and governing boards bear responsibility for policy development, approval, and enforcement. The Arkansas legislature retains oversight through standard mechanisms including appropriations, audits, and legislative hearings. Public transparency requirements—making policies available upon request—enable citizen oversight and accountability. The law does not prescribe specific approval processes for new AI deployments, leaving procedural details to individual agency policies. This flexibility acknowledges varying agency capacities while ensuring minimum governance standards.

Key Focus Areas

  • Mandatory AI Policy Development: Every public entity must create a comprehensive policy governing AI and automated decision tool usage.
  • Human Final Decision Authority: Policies must mandate that human employees or designees always make final decisions, regardless of AI recommendations—the law's central safeguard.
  • Authorized Use Definitions: Policies must clearly define which AI applications are authorized within each entity.
  • Employee Training Programs: Public entities must develop training programs on appropriate AI and automated decision tool use.
  • Public Availability: AI policies must be made available to the public upon request, ensuring transparency.
  • Prohibited Uses: Technology resources cannot be used for personal political opinions, illegal activities, or circumventing security procedures.
  • Consequential Decision Scrutiny: Automated decision tools making or influencing consequential decisions receive heightened policy attention.
  • Data Security Integration: AI policies must align with existing data security and privacy requirements.

Implementation Framework

HB 1958 takes effect August 3, 2025, providing approximately three and a half months from enactment for public entities to develop compliant AI policies. Implementation requires each covered entity to inventory existing AI and automated decision tool applications, develop policy frameworks addressing authorized uses, establish human oversight mechanisms, create employee training programs, and prepare for public disclosure requests. Larger agencies with sophisticated AI deployments may require more extensive policy development, while smaller entities with limited AI use can implement proportionate policies. The law does not specify review or approval of policies by any central authority, leaving implementation to agency discretion within statutory requirements. Entities should coordinate with their legal counsel, IT departments, and program managers to ensure policies address all AI applications. Training programs must be developed and rolled out to relevant employees before the effective date. Public entities should establish processes for responding to policy disclosure requests. The law's prohibition on using technology for personal political opinions or security circumvention should be integrated into broader acceptable use policies.

Monitoring and Evaluation

HB 1958 does not establish formal monitoring or evaluation mechanisms at the state level. Compliance assessment occurs through decentralized mechanisms: internal agency oversight, public records requests, legislative audits, and constituent complaints. The public availability requirement creates accountability through transparency—citizens, journalists, and advocacy organizations can review AI policies and identify gaps or concerns. The Arkansas legislature may conduct oversight hearings or request compliance reports through existing authorities. Individual agencies bear responsibility for monitoring their own compliance and updating policies as AI applications evolve. The training requirement creates ongoing monitoring opportunity as agencies assess employee understanding and policy adherence. The law's broad applicability to all public entities means monitoring capacity varies significantly—state agencies may have dedicated compliance resources while smaller political subdivisions may rely on existing staff. No specific reporting deadlines or evaluation metrics are prescribed, suggesting a compliance-focused rather than continuous improvement approach. Future legislative amendments may add monitoring requirements based on initial implementation experience.

Penalties, Liability, and Appeals

HB 1958 does not establish specific penalties for non-compliance, distinguishing it from private sector AI regulations with enforcement mechanisms and civil penalties. Compliance is expected through standard government accountability structures: personnel actions for employees violating policies, political accountability for agency leadership, legislative oversight, and potential litigation. The prohibition on using technology resources for illegal activities reinforces existing criminal law rather than creating new penalties. Citizens harmed by AI-influenced government decisions may have recourse through existing administrative appeal processes, constitutional due process claims, or civil rights litigation depending on the specific harm. The human final decision requirement may affect liability analysis—if agencies can demonstrate human review of AI recommendations, they may have stronger defenses against claims of arbitrary or automated decision-making. The law does not create a private right of action specifically for AI policy violations. State employees who violate AI policies may face disciplinary actions under existing personnel rules. Agency heads may face political consequences for significant compliance failures.

Relationship to Other Instruments

HB 1958 operates alongside Arkansas HB 1876 (Act 927), which addresses ownership of generative AI-created content. Together, these laws represent Arkansas's 2025 AI legislative package. HB 1958's focus on public sector governance complements HB 1876's private sector intellectual property framework. The law interacts with existing Arkansas data privacy and security requirements, requiring AI policies to align with established information governance frameworks. At the federal level, the legislation aligns with Executive Order 14110's direction for federal agencies to implement AI governance, potentially facilitating federal-state coordination on AI initiatives. Arkansas's approach differs from more prescriptive state laws like Colorado SB24-205, which regulates private sector high-risk AI systems with detailed compliance requirements. The human oversight requirement reflects principles in the EU AI Act requiring human review of high-risk AI applications, though Arkansas applies this broadly to all public entity AI rather than specific risk categories. The training requirement aligns with federal guidance on AI literacy for government workers.

International Alignment

Arkansas HB 1958 addresses a domain—public sector AI governance—receiving increasing international attention. The EU AI Act includes specific requirements for AI systems used by public authorities, including transparency obligations and fundamental rights impact assessments. Arkansas's human final decision requirement aligns with the EU's principle of human oversight for high-risk AI applications, though implemented through policy mandates rather than technical requirements. The OECD AI Principles emphasize accountability and transparency in AI governance, which Arkansas addresses through its policy development and public availability requirements. UNESCO's Recommendation on the Ethics of AI calls for human oversight of AI systems affecting individuals' rights, consistent with Arkansas's human decision-making mandate. The Council of Europe's emerging AI Convention addresses governmental AI use, making Arkansas's early state-level framework relevant to transatlantic governance discussions. Canada's federal AI governance framework, including the Directive on Automated Decision-Making, similarly requires human oversight and transparency for government AI systems. Arkansas's approach—setting minimum standards while allowing agency flexibility—resembles regulatory patterns in other federalist systems balancing central guidance with local implementation.

Implementation Timeline

DateMilestone
February 2025HB 1958 introduced by Rep. S. Meeks and Sen. J. English
March 2025House passage (93-0) and Senate passage (35-0)
April 9, 2025Final House concurrence (99-0)
April 17, 2025Governor Sarah Huckabee Sanders signs HB 1958 as Act 848
August 3, 2025Law takes effect; public entities must have compliant AI policies
OngoingPolicies must be updated as AI applications evolve

Compliance Checklist

RequirementDetails
Inventory AI ApplicationsIdentify all AI and automated decision tools currently in use or planned within the public entity
Develop Comprehensive PolicyCreate written policy defining authorized AI uses and governance requirements
Mandate Human Decision AuthorityEnsure policy requires human employees to make all final decisions regardless of AI recommendations
Identify Consequential DecisionsDetermine which AI applications influence consequential decisions requiring heightened oversight
Establish Training ProgramDevelop and implement employee training on appropriate AI and automated decision tool use
Prepare for Public DisclosureEstablish process for making AI policy available upon public request
Address Prohibited UsesInclude prohibitions on personal political use, illegal activities, and security circumvention
Integrate with Existing PoliciesAlign AI policy with data security, privacy, and acceptable use frameworks
Assign Oversight ResponsibilityDesignate personnel responsible for policy compliance and updates
Plan for Policy UpdatesEstablish process for reviewing and updating policy as AI applications evolve

Sources and References

SourceType
HB 1958 Bill Page - Arkansas LegislaturePrimary Source
HB 1958 Bill TextPrimary Source
Act 848 Enrolled TextPrimary Source
Plain English

Arkansas's new Act 848, effective August 3, 2025, requires all public entities in the state to develop and implement policies for their use of artificial intelligence (AI) and automated decision tools. This includes state departments, agencies, boards, commissions, educational institutions, counties, cities, and special districts.

The law mandates that each public entity create a comprehensive policy outlining how it will use AI. Key requirements for these policies include: - Ensuring human employees always retain final decision-making authority, even when AI provides recommendations. - Defining authorized AI applications within the entity. - Establishing training programs for employees on the appropriate use of AI and automated decision tools. - Making these AI policies publicly available upon request, promoting transparency. The law also explicitly prohibits using technology resources for personal political opinions, illegal activities, or to bypass security procedures.

Unlike some other AI regulations, Act 848 does not create a new state agency to oversee compliance or impose specific financial penalties for violations. Instead, enforcement relies on existing government accountability structures, such as internal personnel actions for employees, political accountability for agency leadership, and legislative oversight. There is no new private right of action for citizens under this law.

A practical surprise for many entities might be the decentralized approach: each public entity is solely responsible for developing, implementing, and enforcing its own AI policy without central review or approval. This means entities must proactively inventory their AI use, craft detailed policies, and ensure staff training well before the August 3, 2025 effective date, without a central playbook or enforcement body to guide them.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 11 marked complete

Plain-English obligations under United States - Arkansas - AI Policy Requirements (Act 848). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalAug 3, 2025

    Applies to: All Arkansas public entities.

    Policies must mandate that human employees or designees always make final decisions, regardless of AI recommendations.
  2. #2CriticalAug 3, 2025

    Applies to: All Arkansas public entities.

    Technology resources cannot be used for personal political opinions, illegal activities, or circumventing security procedures.
  3. #3ImportantAug 3, 2025

    Applies to: All Arkansas public entities.

    Every public entity must create a comprehensive policy governing AI and automated decision tool usage.
  4. #4ImportantAug 3, 2025

    Applies to: All Arkansas public entities.

    Policies must clearly define which AI applications are authorized within each entity.
  5. #5ImportantAug 3, 2025

    Applies to: All Arkansas public entities.

    Public entities must develop training programs on appropriate AI and automated decision tool use.
  6. #6ImportantAug 3, 2025

    Applies to: All Arkansas public entities.

    AI policies must be made available to the public upon request, ensuring transparency.
  7. #7ImportantAug 3, 2025

    Applies to: All Arkansas public entities.

    Automated decision tools making or influencing consequential decisions receive heightened policy attention.
  8. #8ImportantAug 3, 2025

    Applies to: All Arkansas public entities.

    AI policies must align with existing data security and privacy requirements.
  9. #9ImportantAug 3, 2025

    Applies to: All Arkansas public entities.

    Implementation requires each covered entity to inventory existing AI and automated decision tool applications.
  10. #10ImportantAug 3, 2025

    Applies to: All Arkansas public entities.

    Agency heads and governing boards bear responsibility for policy development, approval, and enforcement.
  11. #11ImportantOngoing

    Applies to: All Arkansas public entities.

    Individual agencies bear responsibility for monitoring their own compliance and updating policies as AI applications evolve.

© Regulations.AI — created on 12-Jun-2026