United States - Kentucky - AI Governance Act (SB 4)

Kentucky SB 4 — AI Governance Framework and Election Integrity Act

United States

RAI-US-KY-KS4AGXX-2025
Effective: March 24, 2025
In Force(In Force)
ActGovernance and OversightConformity Assessment and Registration
Export PDF

Kentucky SB 4, signed March 24, 2025, establishes comprehensive AI governance for Kentucky state government with risk-based oversight. The law creates an AI Governance Committee within the Commonwealth Office of Technology, requires disclosure of AI use in decision-making, mandates human oversight for consequential decisions, and includes election integrity provisions prohibiting unreported AI-generated content in political messaging.

Overview

Kentucky Senate Bill 4 establishes one of the most comprehensive state-level AI governance frameworks in the United States, creating structured oversight for AI use across Kentucky state government while addressing emerging concerns about AI-generated content in elections. Signed by Governor Andy Beshear on March 24, 2025, the law reflects Kentucky's position in the growing movement of states developing AI governance absent federal legislation. Championed by Senate Republicans Amanda Mays Bledsoe and Brandon Storm, the legislation achieved remarkable bipartisan support with 30-3 passage in the Senate and 86-10 in the House. Unlike private sector-focused AI laws in states like Colorado, Kentucky's approach concentrates on government AI use, establishing approval processes, disclosure requirements, and human oversight mandates. The law also uniquely addresses election integrity concerns, prohibiting deceptive AI-generated political content—a provision reflecting growing awareness of AI's potential to disrupt democratic processes. The framework takes effect immediately upon signing, requiring prompt compliance by state agencies.

Definitions

SB 4 establishes definitions aligned with emerging national standards. Artificial intelligence system encompasses machine-based systems that infer from inputs how to generate outputs including content, decisions, predictions, or recommendations. Generative AI specifically refers to AI systems capable of producing new content such as text, images, or code. High-risk AI systems are those substantially affecting consequential decisions. Consequential decisions are those affecting legal rights, access to government services, or costs to citizens and businesses—the threshold triggering heightened oversight requirements. Substantial factor means the AI system materially influences decision outcomes rather than merely providing background information. Synthetic media refers to AI-generated or manipulated audio, video, or images that falsely depict individuals, addressed specifically in election integrity provisions. The law distinguishes between different risk levels, applying graduated requirements based on potential impact. Deployer refers to state agencies that implement AI systems, while developer encompasses those creating AI tools.

Governance and Institutional Framework

SB 4 creates a multi-layered governance structure centered on the Commonwealth Office of Technology (COT). An AI Governance Committee within COT develops policy standards and guiding principles for AI systems, with particular attention to generative and high-risk applications. COT establishes standards aligned with national benchmarks including NIST and ISO frameworks, ensuring Kentucky's approach reflects best practices. State agencies must obtain COT approval before implementing AI systems, creating centralized oversight and technical review. A centralized registry of AI systems maintains transparency and enables monitoring. Each state cabinet must submit annual reports to COT by December 1 identifying potential beneficial AI uses, creating a forward-looking planning process. The Governor's office retains ultimate authority over state AI policy. Individual agencies bear responsibility for implementation within COT guidelines, including conducting risk assessments, ensuring human oversight, and maintaining documentation. The framework creates accountability at multiple levels while preserving agency flexibility within established parameters.

Key Focus Areas

  • Risk-Based Oversight: Structured approach targeting AI systems substantially affecting consequential decisions on legal rights, services, or costs.
  • COT Approval Requirement: State agencies must obtain Commonwealth Office of Technology approval before implementing AI systems.
  • Public Disclosure: Mandatory disclosure when AI is used in decision-making processes affecting citizens.
  • Centralized Registry: Maintenance of comprehensive registry of AI systems deployed across state government.
  • Human Oversight Mandate: Human review required for all consequential AI-driven decisions.
  • Anti-Discrimination Requirements: Agencies must document how AI systems will not discriminate.
  • Data Security: AI systems must maintain data privacy and protection standards.
  • Election Integrity: Disclosure requirements and prohibitions on deceptive AI-generated political content.
  • Synthetic Media Restrictions: Ban on unreported AI-generated content fraudulently depicting individuals in political contexts.
  • Legal Remedies: Available for individuals targeted by deceptive AI-generated media in elections.
  • Agency Reporting: Annual cabinet reports on potential beneficial AI uses due December 1.
  • National Standard Alignment: Oversight aligned with NIST and ISO benchmarks.

Implementation Framework

SB 4 took effect immediately upon Governor Beshear's signature on March 24, 2025, requiring prompt compliance. State agencies must inventory existing AI systems and assess which require COT approval based on consequential decision involvement. New AI deployments require pre-implementation approval, creating a gating process for AI adoption. COT must develop approval criteria, risk assessment templates, and registry infrastructure. Agencies must establish human oversight procedures for consequential decisions and create documentation demonstrating non-discrimination, citizen benefit, and data security compliance. The election integrity provisions apply immediately to upcoming elections, requiring political actors to disclose AI-generated content. The December 1 annual reporting deadline creates ongoing planning cycles. Agencies should establish designated personnel responsible for AI governance compliance and liaison with COT. Training programs should be developed to ensure staff understanding of requirements, particularly regarding disclosure obligations and human oversight procedures.

Monitoring and Evaluation

SB 4 establishes ongoing monitoring through multiple mechanisms. The centralized AI registry provides visibility into deployed systems across state government. Regular agency reporting to COT creates accountability and enables identification of compliance gaps. Annual cabinet reports on beneficial AI uses create forward-looking assessment of AI opportunities. COT's oversight role enables ongoing evaluation of agency compliance with approval requirements, disclosure obligations, and human oversight mandates. The AI Governance Committee can update standards based on implementation experience and evolving best practices. Risk assessments conducted by agencies create documentation for compliance verification. The election integrity provisions will be monitored through standard election oversight mechanisms, with legal remedies creating private enforcement incentives. The legislature may conduct oversight hearings and consider amendments based on implementation experience. Comparison with other state approaches—particularly Colorado, Texas, and Utah—will inform evaluation of Kentucky's framework effectiveness.

Penalties, Liability, and Appeals

SB 4 establishes differentiated consequences for violations. State agencies deploying AI without required COT approval may face administrative consequences through standard government accountability mechanisms. Individual employees violating AI policies may face personnel actions. The election integrity provisions create specific legal remedies for individuals depicted in deceptive AI-generated political content, enabling civil litigation against those releasing synthetic media without disclosure. Criminal penalties may apply for election-related AI fraud under existing election law frameworks. The anti-discrimination documentation requirement creates potential liability exposure if AI systems are later shown to discriminate despite agency assurances. No private right of action exists for general AI governance violations—enforcement occurs through government oversight and accountability structures. Appeals from agency AI decisions follow standard administrative procedure, with judicial review available. COT denial of AI system approval may be appealed through administrative processes.

Relationship to Other Instruments

SB 4 joins the growing patchwork of US state AI legislation while taking a distinctive government-focused approach. Colorado SB24-205 regulates private sector high-risk AI with consumer protection focus, while Kentucky concentrates on state government operations. Arkansas HB 1958 similarly addresses public sector AI but with less detailed governance infrastructure. The law's alignment with NIST and ISO standards creates federal compatibility and international alignment. Executive Order 14110 directs similar federal agency AI governance, and Kentucky's framework could facilitate state-federal coordination. The election integrity provisions address concerns highlighted in multiple state deepfake laws. The risk-based approach reflects principles from the EU AI Act applied to government context. Kentucky's centralized approval process differs from states allowing agency-level AI governance discretion. The immediate effective date contrasts with extended implementation periods in other state laws.

International Alignment

Kentucky's SB 4 reflects international trends in AI governance while adapting approaches to US state government context. The EU AI Act's risk-based categorization influences Kentucky's focus on consequential decisions and high-risk AI systems, though Kentucky applies these concepts specifically to government operations rather than economy-wide. The disclosure requirements align with international transparency principles articulated in OECD AI Principles and UNESCO's Recommendation on the Ethics of AI. The human oversight mandate reflects global consensus on maintaining human agency over AI decision-making in sensitive contexts. NIST and ISO alignment creates indirect international standard compatibility. The election integrity provisions address concerns highlighted internationally regarding AI manipulation of democratic processes—the Council of Europe has emphasized similar protections. Canada's federal AI governance framework includes comparable government AI oversight mechanisms. The centralized registry approach follows patterns used in EU member states tracking public sector AI deployment. Kentucky's immediate effectiveness differs from extended implementation timelines common internationally.

Implementation Timeline

DateMilestone
January 2025SB 4 introduced by Sens. Bledsoe and Storm
March 2025Senate passage (30-3) and House passage (86-10)
March 24, 2025Governor Beshear signs SB 4; law takes immediate effect
OngoingState agencies conduct AI system inventories and seek COT approval
December 1, 2025First annual cabinet reports on beneficial AI uses due to COT
OngoingElection integrity provisions apply to all elections

Compliance Checklist

RequirementDetails
Inventory AI SystemsIdentify all AI systems deployed or planned within agency operations
Assess Consequential DecisionsDetermine which AI systems substantially affect decisions on rights, services, or costs
Obtain COT ApprovalSubmit required AI systems for Commonwealth Office of Technology approval before deployment
Implement DisclosureEstablish public disclosure when AI influences decision-making
Ensure Human OversightCreate procedures for human review of all consequential AI-driven decisions
Document Non-DiscriminationPrepare documentation demonstrating AI systems will not discriminate
Maintain Data SecurityEnsure AI systems comply with data privacy and protection requirements
Register AI SystemsSubmit AI systems for inclusion in centralized registry
Prepare Annual ReportDevelop cabinet report on beneficial AI uses for December 1 submission
Election ComplianceEnsure any AI-generated political content includes required disclosures

Sources and References

SourceType
SB 4 Bill Page - Kentucky LegislaturePrimary Source
SB 4 on LegiScanPrimary Source
Commonwealth Office of TechnologyEnforcement Authority
NIST AI Risk Management FrameworkReference Standard
Plain English

Kentucky's new AI law establishes a comprehensive framework for how the state government uses artificial intelligence and also addresses the use of AI in political messaging during elections. Primarily, this law applies to Kentucky state government agencies, requiring them to follow strict guidelines when developing or deploying AI systems. It also impacts political campaigns and individuals involved in election communications, setting rules for AI-generated content.

State agencies must obtain approval from the Commonwealth Office of Technology (COT) before implementing any AI system. They are also required to publicly disclose when AI is used in decision-making that affects citizens, and crucially, ensure human oversight for all "consequential decisions"—those impacting legal rights, access to government services, or costs to individuals and businesses. Agencies must also document how their AI systems avoid discrimination and maintain robust data security.

The law took effect immediately upon signing on March 24, 2025, meaning state agencies needed to begin inventorying existing AI systems and seeking COT approval right away. The first annual reports from state cabinets on beneficial AI uses are due by December 1, 2025.

For political actors, the law prohibits the use of AI-generated or manipulated audio, video, or images (synthetic media) that falsely depict individuals in political messaging, unless properly disclosed. Individuals targeted by such deceptive content have specific legal remedies, allowing them to pursue civil litigation. While there's no general private right of action for citizens to sue the state over AI governance violations, administrative consequences and personnel actions can be taken against non-compliant agencies or employees. A key pitfall for state agencies is the immediate effective date, demanding rapid compliance and potentially requiring a quick overhaul of existing AI practices without a lengthy grace period.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 11 marked complete

Plain-English obligations under United States - Kentucky - AI Governance Act (SB 4). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore releasing political content

    Applies to: Political actors.

    Ban on unreported AI-generated content fraudulently depicting individuals in political contexts.
  2. #2CriticalBefore releasing political content

    Applies to: Political actors.

    Disclosure requirements and prohibitions on deceptive AI-generated political content.
  3. #3CriticalBefore implementation

    Applies to: State agencies.

    State agencies must obtain COT approval before implementing AI systems.
  4. #4CriticalBefore implementation

    Applies to: State agencies deploying AI systems affecting consequential decisions.

    Human review required for all consequential AI-driven decisions.
  5. #5CriticalBefore implementation

    Applies to: State agencies.

    Agencies must document how AI systems will not discriminate.
  6. #6CriticalBefore implementation

    Applies to: State agencies.

    AI systems must maintain data privacy and protection standards.
  7. #7Important

    Applies to: State agencies.

    State agencies must inventory existing AI systems and assess which require COT approval based on consequential decision involvement.
  8. #8ImportantUpon use of AI in decision-making

    Applies to: State agencies.

    Mandatory disclosure when AI is used in decision-making processes affecting citizens.
  9. #9ImportantUpon deployment

    Applies to: State agencies.

    A centralized registry of AI systems maintains transparency and enables monitoring.
  10. #10ImportantBefore implementation

    Applies to: State agencies.

    Individual agencies bear responsibility for implementation within COT guidelines, including conducting risk assessments.
  11. #11ImportantDec 1, 2025

    Applies to: State cabinets.

    Each state cabinet must submit annual reports to COT by December 1 identifying potential beneficial AI uses.

© Regulations.AI — created on 13-Jun-2026