United States - Montana - Right to Compute Act (SB 212)
Montana SB 212 - Right to Compute Act
United States
RAI-US-MT-MS2RCXX-2025United States - Montana - Right to Compute Act (SB 212) is In Force in United States as of 8 Sep 2026, according to legis.mt.gov.
ActFundamental RightsRisk ManagementMontana SB 212 (Right to Compute Act), enacted by the Montana Legislature in 2025, establishes a right to use computational resources and mandates risk management policies for critical infrastructure AI deployers. The law is in force as of April 16, 2025, and is enforced through judicial oversight in state courts.
Summary
As of September 8, 2026, the Montana Senate Bill 212, officially enacted as the Right to Compute Act, is In Force. The bill passed both chambers of the 69th Montana Legislature and was signed into law by Governor Greg Gianforte on April 16, 2025, taking immediate effect on that same date.
The Act establishes a fundamental right for individuals and businesses to privately own, access, and utilize computational resources for lawful purposes throughout Montana. It defines computational resources broadly to include hardware, software, algorithms, data processing systems, and cloud infrastructure. Under the Act, any government action or regulation that restricts the ownership or use of computational resources is subject to strict scrutiny, requiring the government to prove that such restrictions are demonstrably necessary and narrowly tailored to fulfill a compelling government interest such as public health or safety.
In addition to protecting computing rights, the statute establishes specific obligations for deployers of artificial intelligence systems that control critical infrastructure facilities, such as energy grids, water systems, and communication networks. Deployers of critical AI systems must develop and maintain reasonable risk management policies aligned with recognized national and international standards.
The Right to Compute Act does not create a dedicated administrative regulatory agency or supervisory board to monitor compliance or issue administrative fines. Instead, enforcement of the Act primarily operates through judicial oversight in state courts, enabling private parties and organizations to legally challenge state or local governmental overreach that infringes upon computational rights.
Full article
Read full text ↗Overview
The Montana SB 212, officially known as the “Right to Compute Act,” represents a landmark legislative effort to establish and protect individual and business rights concerning computational resources within the state of Montana. Enacted in 2025, this Act is designed to address the rapidly evolving landscape of technology, particularly artificial intelligence (AI), by setting clear boundaries for government intervention in the private ownership and utilization of computing power. The core premise of the Act is to extend fundamental constitutional rights, such as property rights and freedom of expression, to the digital realm, ensuring that citizens retain significant autonomy over their technological tools. It recognizes the crucial role of computational technology, including machine learning and AI, in fostering economic growth, safeguarding national security, and maintaining a competitive edge in a globalized world. The legislation underscores the Montana Legislature's intent to be the primary authority in establishing policies and principles related to computational resources, aligning these with existing state constitutional provisions.
Beyond establishing a fundamental “right to compute,” the Act also introduces specific regulatory requirements for critical infrastructure facilities that are controlled by artificial intelligence systems. This dual approach acknowledges both the innovative potential of advanced technologies and the inherent risks they might pose to public health and safety. The Act mandates the development of robust risk management policies for such AI-controlled critical infrastructure, ensuring that these systems adhere to recognized national and international standards. Furthermore, it explicitly requires the implementation of mechanisms that allow for human control and intervention in emergency situations, thereby prioritizing safety and human oversight. The legislation also contains provisions that affirm and protect existing intellectual property rights, clarifying that the Act does not diminish or alter these protections. It also specifies that the Act does not preempt federal laws, maintaining a clear delineation of jurisdictional authority.
Definitions
The “Right to Compute Act” establishes several key definitions essential for its interpretation and application, ensuring clarity in the scope of its provisions. While the full text provides comprehensive definitions, central terms include “artificial intelligence system,” “critical infrastructure facility,” and “deployer.” An “artificial intelligence system” generally refers to any machine-based system that can, for a given set of human-defined objectives, make predictions, recommendations, or decisions influencing real or virtual environments. This broad definition aims to encompass a wide array of AI technologies, from sophisticated machine learning models to more basic automated decision-making systems, ensuring the Act remains relevant as technology advances. This comprehensive scope is critical for applying the Act's risk management and oversight provisions to the diverse forms of AI currently in use and those yet to emerge.
A “critical infrastructure facility” is defined to include assets, systems, and networks, whether physical or virtual, so vital to the United States that their incapacitation or destruction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof. This definition is crucial for identifying which AI systems fall under the Act's heightened risk management requirements, specifically those that, if compromised, could lead to significant societal disruption. Examples typically include facilities in sectors such as energy, water, telecommunications, and transportation. The term “deployer” refers to any entity or individual responsible for putting an artificial intelligence system into operation, particularly within a critical infrastructure facility. This definition assigns clear responsibility for compliance with the Act's safety and risk management mandates, ensuring accountability for the safe and secure deployment of AI systems in sensitive environments. The Act's precise definitions are fundamental to its enforceability and its objective of balancing technological innovation with public safety and individual rights.
Governance and Institutional Framework
The governance framework established by the Montana “Right to Compute Act” is primarily centered on defining the limits of government authority regarding computational resources, rather than creating new regulatory bodies. The Act asserts that the Montana Legislature is the appropriate governmental branch for establishing policies and principles related to the ownership and use of computational resources, thereby reinforcing state sovereignty in this technological domain. This legislative intent is rooted in the recognition that fundamental rights, such as the right to acquire, possess, and protect property and the freedom of expression, as enshrined in the Montana Constitution, extend to the ownership and utilization of technological tools, including computational resources. Consequently, any government action that seeks to restrict these rights must meet a stringent legal standard: it must be demonstrably necessary and narrowly tailored to fulfill a compelling government interest, such as public health or safety. This framework places a high bar for state or local government intervention, aiming to foster an environment conducive to technological innovation and digital liberty.
While the Act does not establish new oversight agencies, it implicitly tasks existing state governmental bodies with the responsibility of adhering to its principles when considering any regulations or actions that might impact computational resources. For critical infrastructure facilities controlled by artificial intelligence systems, the Act mandates the development and implementation of a risk management policy. This policy must adhere to recognized national and international standards, implying that relevant sector-specific regulatory bodies (e.g., those overseeing energy, water, or transportation) would be responsible for ensuring compliance within their respective domains. These existing agencies would need to integrate the Act's requirements into their oversight functions, particularly concerning the annual review and testing of risk management policies and the maintenance of human override mechanisms. The Act’s framework, therefore, leverages existing institutional structures while imposing new legislative directives to protect digital rights and manage AI-related risks in critical sectors.
Key Focus Areas
The Montana “Right to Compute Act” focuses on several interconnected areas to achieve its objectives of protecting digital liberties and managing AI risks. A primary focus is the establishment of a fundamental right to compute, which encompasses the rights of individuals and businesses to own, access, and utilize computational resources for lawful purposes. This includes hardware, software, algorithms, and data centers. The Act explicitly states that government restrictions on these rights must be limited to those demonstrably necessary and narrowly tailored to serve a compelling government interest, such as public health or safety. This provision is designed to prevent arbitrary or overly broad governmental interference in technological innovation and personal digital autonomy, effectively extending traditional property rights and freedom of expression into the digital age. It represents a proactive stance against potential overregulation of technology at the state and local levels.
Another critical focus area is risk management for artificial intelligence systems deployed in critical infrastructure facilities. Recognizing the potential for significant societal disruption, the Act mandates that these facilities develop and implement comprehensive risk management policies. These policies must align with recognized national and international standards, indicating a commitment to best practices in AI safety and security. A crucial component of this focus is the requirement for mechanisms that allow human operators to take control of AI-controlled critical infrastructure in emergency situations. This ensures that human judgment and intervention remain paramount when AI systems manage essential services. Furthermore, the Act emphasizes the protection of intellectual property rights, clarifying that its provisions do not alter or diminish existing protections under patent, copyright, trademark, and trade secret laws. This ensures that innovators retain legal safeguards for their creations while operating within the framework of the “Right to Compute Act.” The Act also explicitly states its non-preemptive nature regarding federal laws, ensuring that it complements rather than conflicts with broader national regulations.
Implementation Framework
The implementation framework for the Montana “Right to Compute Act” is designed for immediate effect and relies on a combination of legislative clarity and the integration of new requirements into existing operational and oversight practices. Given that the Act became effective immediately upon its passage and approval, there is no phased rollout period; its provisions are directly applicable. For the core “right to compute,” implementation primarily involves a shift in the legal standard for governmental actions. State and local government entities are now legally bound to ensure that any regulations or restrictions on computational resources are demonstrably necessary, narrowly tailored, and serve a compelling government interest. This requires a re-evaluation of existing or proposed policies to ensure they align with the Act's protective measures for digital liberties. The onus is on governmental bodies to justify any limitations on the right to compute, rather than on individuals or entities to prove their right to use computational resources.
For critical infrastructure facilities utilizing AI systems, the implementation framework mandates the proactive development and ongoing adherence to specific risk management policies. Deployers of AI in these critical sectors are immediately responsible for establishing policies that conform to recognized national and international standards. This involves conducting thorough risk assessments, developing mitigation strategies, and implementing fallback procedures. A key practical aspect of implementation is the requirement for human override mechanisms, ensuring that human operators can assume control from AI systems during emergencies. Furthermore, the Act stipulates annual review and testing of these risk management policies. This continuous evaluation ensures that safeguards remain effective and adapt to evolving technological risks. Compliance will likely be monitored through existing regulatory channels relevant to each critical infrastructure sector, with agencies integrating these new AI-specific requirements into their standard oversight and auditing processes. The Act's immediate effective date underscores the urgency placed on establishing these foundational rights and safety protocols in response to rapid technological advancements.
Monitoring and Evaluation
The monitoring and evaluation mechanisms for the Montana “Right to Compute Act” are primarily embedded within the ongoing responsibilities of both governmental entities and the deployers of artificial intelligence in critical infrastructure. While the Act does not establish a new dedicated monitoring agency, its provisions necessitate continuous vigilance and adherence to its core principles. For the fundamental right to compute, monitoring will largely occur through legal challenges and judicial review. If governmental actions are perceived to infringe upon the established right to own and utilize computational resources without meeting the strict criteria of being “demonstrably necessary and narrowly tailored to fulfill a compelling government interest,” affected individuals or entities may seek legal recourse. This judicial oversight serves as a crucial check on potential governmental overreach, ensuring that the legislative intent to protect digital liberties is upheld. The legal system, therefore, becomes a key mechanism for evaluating the practical application and effectiveness of this foundational right.
For the specific requirements concerning AI-controlled critical infrastructure, monitoring and evaluation are more prescriptive. The Act explicitly mandates that deployers of AI systems in these facilities conduct annual reviews and tests of their risk management policies. This self-assessment and internal auditing process is a primary form of monitoring, ensuring that the policies remain current, effective, and compliant with recognized standards. These annual evaluations must cover aspects such as risk identification, mitigation strategies, and the functionality of human override mechanisms. While the Act does not detail specific state agency roles for external auditing of these annual reviews, it is implied that existing regulatory bodies responsible for critical infrastructure sectors (e.g., energy, water, telecommunications) would incorporate these AI risk management requirements into their broader compliance and inspection regimes. This integration ensures that the safety and oversight provisions for AI in critical infrastructure are continuously assessed and improved, adapting to new threats and technological advancements.
Penalties, Liability, and Appeals
The Montana “Right to Compute Act” primarily focuses on establishing a framework of rights and responsibilities, particularly concerning government limitations on computational resources and risk management for AI in critical infrastructure. The Act itself does not explicitly detail a separate schedule of penalties or specific liability provisions for non-compliance within its text. Instead, potential penalties and liability would likely fall under existing legal frameworks within Montana law. For instance, if a government entity were found to violate the “right to compute” by imposing restrictions that do not meet the Act’s stringent criteria of being “demonstrably necessary and narrowly tailored to fulfill a compelling government interest,” affected parties could pursue legal action. This could involve seeking injunctive relief to halt the unlawful government action or potentially pursuing damages under existing state tort or constitutional law provisions, depending on the nature and impact of the infringement. The Act strengthens the legal standing of individuals and businesses to challenge such governmental overreach.
Regarding critical infrastructure facilities controlled by artificial intelligence systems, the Act mandates the development and annual review of risk management policies, including the requirement for human override mechanisms. While the Act does not specify direct penalties for failing to establish or adhere to these policies, non-compliance would likely trigger penalties under existing sector-specific regulations governing critical infrastructure. For example, if a failure to implement proper AI risk management leads to a system malfunction in an energy grid, the responsible entity could face fines, operational restrictions, or other sanctions imposed by the relevant energy regulatory authority, in addition to potential civil liability for any resulting damages. Appeals processes would similarly follow established administrative and judicial review procedures pertinent to the specific governmental action or regulatory violation in question. The Act’s intent is to integrate these new AI-specific requirements into the broader legal and regulatory landscape, leveraging existing mechanisms for enforcement, liability, and appeals.
Relationship to Other Instruments
The Montana “Right to Compute Act” is designed to integrate with and build upon existing legal instruments, particularly the Montana Constitution and federal laws, rather than supersede them. A foundational aspect of the Act is its explicit connection to the Montana Constitution, specifically Article II, Section 3 (the right to acquire, possess, and protect property) and Article II, Section 7 (freedom of expression). The Act interprets these constitutional provisions as embodying a fundamental right to own and utilize technological tools, including computational resources. This integration means that the “Right to Compute Act” serves to clarify and reinforce existing constitutional protections in the context of modern technology, providing a stronger legal basis for challenging governmental restrictions on digital activities. It essentially modernizes the application of long-standing constitutional principles to the digital age, ensuring that digital liberties are afforded the same level of protection as traditional rights.
Furthermore, the Act explicitly states that it does not preempt federal laws. This provision is crucial for maintaining a coherent legal framework across different levels of government. It ensures that any federal regulations or statutes pertaining to AI, technology, or critical infrastructure will continue to apply within Montana, and the “Right to Compute Act” will operate in conjunction with them. This non-preemption clause is particularly important in areas such as cybersecurity, national security, and interstate commerce, where federal oversight is often paramount. Additionally, the Act clarifies that it does not alter existing intellectual property laws, including those related to patents, copyrights, trademarks, and trade secrets. This ensures that the protections afforded to creators and innovators under intellectual property regimes remain intact and are not undermined by the establishment of the right to compute. By carefully delineating its relationship with constitutional, federal, and intellectual property laws, the Act aims to create a robust yet harmonious legal environment for technological development and use.
International Alignment
The Montana “Right to Compute Act,” while a state-level initiative within the United States, exhibits conceptual alignment with broader international discussions and emerging frameworks concerning digital rights and AI governance. The Act’s emphasis on a fundamental “right to compute,” rooted in constitutional principles of property and free expression, resonates with global dialogues on digital human rights and the need to protect individual autonomy in the digital sphere. Many international bodies and national governments are increasingly exploring how traditional rights apply to digital assets, data, and computational power. While not directly referencing international treaties or declarations, the Act's underlying philosophy of limiting governmental interference in digital activities, unless strictly justified, mirrors principles of proportionality and necessity often found in international human rights law and digital rights advocacy. This approach contrasts with more prescriptive regulatory models seen in some other jurisdictions, but shares the common goal of defining the boundaries of state power in the digital age.
Moreover, the Act's requirement for AI-controlled critical infrastructure facilities to develop risk management policies that adhere to “recognized national and international standards” demonstrates an indirect but significant alignment with global best practices in AI safety and governance. International organizations, such as the OECD, ISO, and NIST, have been instrumental in developing frameworks and standards for trustworthy AI, including principles for risk assessment, safety, transparency, and accountability. By mandating adherence to such standards, the Montana Act implicitly encourages the adoption of globally recognized methodologies for managing AI-related risks in sensitive sectors. This ensures that even at a sub-national level, the state is contributing to a harmonized approach to AI safety, rather than developing isolated or conflicting standards. This focus on established standards helps to bridge potential gaps between state-level legislation and the broader international efforts to responsibly govern artificial intelligence, promoting a level of interoperability and shared understanding in AI risk mitigation.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Bill Introduced to Senate | 2025-01-24 | First formal presentation of the bill in the Montana Senate. |
| Passed Senate | 2025-03-01 | Approved by the Montana Senate. |
| Passed House | 2025-03-28 | Approved by the Montana House of Representatives. |
| Signed by Governor | 2025-04-16 | Governor Greg Gianforte signed the bill into law. |
| Effective Date | 2025-04-16 | The Act became effective immediately upon passage and approval. |
| Chapter Number Assigned | 2025-04-17 | Official chapter number assigned to the enacted law. |
Sources and References
| Source | Type |
|---|---|
| Montana SB 212 Enrolled Bill Text | official |
| LegiScan: MT SB212 | 2025 | Regular Session | legal |
Requirements for a company
What an organisation has to do under United States - Montana - Right to Compute Act (SB 212), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
4- Develop and implement a comprehensive risk management policy for AI systems deployed in critical infrastructure facilities.Deployers of AI systems in critical infrastructure facilities
- Implement mechanisms allowing human operators to take control of AI-controlled critical infrastructure during emergency situations.Deployers of AI systems in critical infrastructure facilities
- Conduct annual reviews and testing of AI risk management policies, mitigation strategies, and human override functionality.Deployers of AI systems in critical infrastructure facilities
- Align AI risk management policies for critical infrastructure with recognized national and international standards.Deployers of AI systems in critical infrastructure facilities
Must not do
2- Do not impose restrictions on computational resource use unless demonstrably necessary and narrowly tailored for a compelling government interest.Montana state and local government entities
- Do not alter or diminish existing intellectual property protections when operating under the Right to Compute framework.Entities deploying or using computational resources in Montana
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under United States - Montana - Right to Compute Act (SB 212), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Deployers of AI systems in critical infrastructure facilities | Develop and implement a comprehensive risk management policy for AI systems deployed in critical infrastructure facilities. “mandates that these facilities develop and implement comprehensive risk management policies.” | Apr 16, 2025 | — | Critical |
| 2 | Deployers of AI systems in critical infrastructure facilities | Implement mechanisms allowing human operators to take control of AI-controlled critical infrastructure during emergency situations. “explicitly requires the implementation of mechanisms that allow for human control and intervention in emergency situations” | Apr 16, 2025 | — | Critical |
| 3 | Deployers of AI systems in critical infrastructure facilities | Conduct annual reviews and testing of AI risk management policies, mitigation strategies, and human override functionality. “Act explicitly mandates that deployers of AI systems in these facilities conduct annual reviews and tests of their risk management policies.” | Annually | — | Critical |
| 4 | Montana state and local government entities | Do not impose restrictions on computational resource use unless demonstrably necessary and narrowly tailored for a compelling government interest. “government restrictions on these rights must be limited to those demonstrably necessary and narrowly tailored to serve a compelling government interest” | Apr 16, 2025 | — | Critical |
| 5 | Deployers of AI systems in critical infrastructure facilities | Align AI risk management policies for critical infrastructure with recognized national and international standards. “These policies must align with recognized national and international standards” | Apr 16, 2025 | — | Important |
| 6 | Entities deploying or using computational resources in Montana | Do not alter or diminish existing intellectual property protections when operating under the Right to Compute framework. “clarifying that its provisions do not alter or diminish existing protections under patent, copyright, trademark, and trade secret laws.” | Apr 16, 2025 | — | Important |
Related Regulations
United States - Montana - Deepfakes Regulation (SB 25)
United States90% similar
New York RAISE Act for AI Safety
United States89% similar
United States - Colorado - AI Consumer Protections (SB24-205)
United States88% similar
TRUMP AMERICA AI Act
United States88% similar
Connecticut AI Responsibility and Transparency Act
United States88% similar
More AI regulation in United States
AI regulation in United States: full overview
- Montana AI Regulation Summary
- United States - Algorithmic Accountability Act (H.R. 5628)
- United States - AI Accountability Act (S. 2892)
- ABA Guidance on Lawyers' Ethical AI Use
- FTC AI Accuracy Policy Statement
- United States - AI Adoption in Government (S.1363/H.R.2575)
- United States - AI Risk Management Framework
- America's AI Action Plan
© Regulations.AI using Gemini 2.5 Flash · reviewed against official sources on 8 Sep 2026 using Gemini 3.6 Flash