United States - Ohio - AI Regulation (HB 392)
To enact section 9.89 of the Revised Code to limit further regulation of certain computational systems, require risk management policies for AI-controlled critical infrastructure, and to name this act the Ohio Right to Compute Act.
United States
RAI-US-OH-ES9RCXX-2025Ohio's HB 392, the Right to Compute Act, aims to limit regulation on computational systems and mandate AI risk management for critical infrastructure.
Summary
Read full text ↗Plain English
Overview
The Ohio Right to Compute Act, House Bill 392 (HB 392), introduced in the 136th General Assembly (2025-2026), seeks to enact section 9.89 of the Revised Code. The primary goals are to limit further regulation of certain computational systems and to require risk management policies for artificial intelligence (AI) systems controlling critical infrastructure. This legislation aims to establish guidelines for the use and regulation of computational resources, particularly AI systems, within Ohio.Definitions
The bill defines key terms pertinent to its scope. These include "computational resource" and "AI system," though specific detailed definitions are found within the bill text itself. It also defines "compelling governmental interest" as a basis for any restrictions on computational resources.Governance and Institutional Framework
HB 392 proposes that no political subdivision or state agency shall enact, adopt, enforce, or maintain any law, rule, regulation, permit requirement, or other administrative practice that restricts or prohibits any person's lawful use, development, deployment, or possession of a computational resource. Such restrictions are only permissible if they are narrowly tailored to achieve a compelling governmental interest.Key Focus Areas
- Regulation of Computational Systems: The act limits the ability of state agencies and local governments to restrict the use of computational resources. Any such restrictions must be narrowly tailored to address a compelling governmental interest.
- AI-Controlled Critical Infrastructure: Entities operating AI systems that control critical infrastructure are required to implement comprehensive risk management policies. These policies must align with established national and international standards, such as frameworks from the National Institute of Standards and Technology (NIST) and other international standardization organizations.
- Compelling Governmental Interests: The bill outlines specific compelling governmental interests that may justify restrictions. These include protecting critical infrastructure, preventing fraud, safeguarding minors from harmful AI-generated content (like deepfakes), and managing public nuisances related to data center infrastructure.
- Exemptions: The requirements for AI risk management do not apply to AI systems performing only nonexecutive tasks or those that serve as cybersecurity tools. Basic procedural tools are also exempted.
- Intellectual Property Rights: The legislation explicitly protects intellectual property rights, ensuring it does not interfere with existing patent, trademark, copyright, and trade secret protections.
Implementation Framework
As a proposed bill, the implementation framework is currently in the legislative process. Should it pass, it would enact section 9.89 of the Revised Code.Monitoring and Evaluation
Details regarding specific monitoring and evaluation mechanisms are not extensively detailed in the publicly available summaries of the introduced bill. Compliance with risk management policies for AI-controlled critical infrastructure would likely be subject to existing regulatory oversight bodies responsible for critical infrastructure.Penalties, Liability, and Appeals
The publicly available summaries of the introduced bill do not extensively detail specific penalties, liability provisions, or appeal processes. These aspects would typically be elaborated during the legislative drafting and amendment process.Relationship to Other Instruments
The bill requires AI risk management policies for critical infrastructure to align with national and international standards, including those from the National Institute of Standards and Technology (NIST) and other international standardization organizations.International Alignment
The legislation references alignment with national and international standards for AI risk management, particularly concerning AI systems in critical infrastructure.Implementation Timeline
| Date | Milestone | Status |
|---|---|---|
| 2025-07-07 | Introduced in the House | Proposed |
| 2025-09-15 | Referred to House Technology and Innovation Committee | Under Review |
| 2025-11-13 | House Technology and Innovation Committee, 3rd Hearing (Opp/IP Testimony) | Under Review |
Compliance Checklist
| Requirement | Description | Deadline |
|---|---|---|
| Limit on Governmental Restrictions | State agencies and political subdivisions must not restrict computational resources unless narrowly tailored to a compelling governmental interest. | Upon enactment |
| AI Risk Management Policy | Entities operating AI systems controlling critical infrastructure must implement comprehensive risk management policies aligned with national/international standards (e.g., NIST). | Upon enactment |
| Protection of Intellectual Property | Ensure actions do not interfere with existing patent, trademark, copyright, and trade secret protections. | Ongoing |
Sources and References
| Source | Type |
|---|---|
| House Bill 392 | 136th General Assembly - Ohio House of Representatives | Official Gazette |
| OH HB392 - BillTrack50 | Legal Database |
| HB392 | Ohio 2025-2026 | Enact the Ohio Right to Compute Act - PolicyEngage | Legal Database |
| Bill tracking in Ohio - HB 392 (136 legislative session) - FastDemocracy | Legal Database |
| Ohio Right to Compute: A Bold Vision for Technology Leadership in the Intelligence Era | Academic Paper |
Ohio's proposed Right to Compute Act aims to protect the use of computational systems across the state while also requiring specific safety measures for artificial intelligence (AI) controlling vital infrastructure. This bill broadly affects anyone in Ohio who develops, deploys, or uses computational resources, from individuals to businesses. More specifically, it places obligations on organizations that operate AI systems managing critical infrastructure, such as utilities or transportation networks.
The core of the act has two main thrusts. First, it largely prevents state agencies and local governments from creating new rules that restrict the lawful use of computational resources. They can only do so if a restriction is absolutely necessary to achieve a "compelling governmental interest" – for example, protecting critical infrastructure, preventing fraud, or safeguarding minors from harmful AI-generated content like deepfakes – and is very narrowly defined. Second, for companies using AI to control critical infrastructure, the bill mandates the creation of comprehensive risk management policies. These policies must follow established national and international standards, such as those from the National Institute of Standards and Technology (NIST).
It's important to note that AI systems performing only basic, non-executive tasks or those used for cybersecurity are exempt from these risk management requirements. The bill also explicitly states it won't interfere with existing intellectual property rights like patents, trademarks, and copyrights.
Currently, this is a proposed bill, introduced in the Ohio House of Representatives. If it passes and becomes law, these provisions would take effect upon its enactment. The publicly available summaries of the bill do not yet detail specific penalties, liability provisions, or appeal processes for non-compliance, which are typically refined as legislation moves through the drafting stages. A key practical takeaway is that while the bill champions a "right to compute," this right isn't absolute. The "compelling governmental interest" clause provides a significant carve-out, meaning future regulations could still emerge if deemed essential for public safety or other vital state interests. Businesses should monitor the bill's progress closely.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 4 marked completePlain-English obligations under United States - Ohio - AI Regulation (HB 392). Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Upon enactment
Applies to: Ohio political subdivisions and state agencies.
“no political subdivision or state agency shall enact, adopt, enforce, or maintain any law, rule, regulation, permit requirement, or other administrative practice that restricts or prohibits any person's lawful use, development, deployment, or possession of a computational resource.”
- #2Critical⏰ Upon enactment
Applies to: Entities operating AI systems that control critical infrastructure.
“Entities operating AI systems that control critical infrastructure are required to implement comprehensive risk management policies.”
- #3Critical⏰ Upon enactment
Applies to: Entities operating AI systems that control critical infrastructure.
“These policies must align with established national and international standards, such as frameworks from the National Institute of Standards and Technology (NIST) and other international standardization organizations.”
- #4Important⏰ Ongoing
Applies to: All entities and agencies subject to this act.
“The legislation explicitly protects intellectual property rights, ensuring it does not interfere with existing patent, trademark, copyright, and trade secret protections.”
Related Regulations
Ohio HB 469 - Declare artificial intelligence systems nonsentient and prohibit legal personhood
United States90% similar
Make state operating appropriations for FY 2026-27 (Ohio House Bill 96)
United States88% similar
Ohio SB 217 - AI-generated products watermark requirements and identity fraud
United States88% similar
Montana SB 212 - Right to Compute Act
United States88% similar
An act relating to creating oversight and liability standards for developers and deployers of inherently dangerous artificial intelligence systems
United States88% similar
© Regulations.AI — created on 06-Jan-2026 using Gemini 2.5 Flash