United States - Ohio - AI Regulation (HB 392)

To enact section 9.89 of the Revised Code to limit further regulation of certain computational systems, require risk management policies for AI-controlled critical infrastructure, and to name this act the Ohio Right to Compute Act.

United States

RAI-US-OH-ES9RCXX-2025
Proposed(Officially filed for action)
BillGovernance and OversightRisk ManagementFundamental Rights
Export PDF

Ohio's HB 392, the Right to Compute Act, aims to limit regulation on computational systems and mandate AI risk management for critical infrastructure.

Overview

The Ohio Right to Compute Act, House Bill 392 (HB 392), introduced in the 136th General Assembly (2025-2026), seeks to enact section 9.89 of the Revised Code. The primary goals are to limit further regulation of certain computational systems and to require risk management policies for artificial intelligence (AI) systems controlling critical infrastructure. This legislation aims to establish guidelines for the use and regulation of computational resources, particularly AI systems, within Ohio.

Definitions

The bill defines key terms pertinent to its scope. These include "computational resource" and "AI system," though specific detailed definitions are found within the bill text itself. It also defines "compelling governmental interest" as a basis for any restrictions on computational resources.

Governance and Institutional Framework

HB 392 proposes that no political subdivision or state agency shall enact, adopt, enforce, or maintain any law, rule, regulation, permit requirement, or other administrative practice that restricts or prohibits any person's lawful use, development, deployment, or possession of a computational resource. Such restrictions are only permissible if they are narrowly tailored to achieve a compelling governmental interest.

Key Focus Areas

  • Regulation of Computational Systems: The act limits the ability of state agencies and local governments to restrict the use of computational resources. Any such restrictions must be narrowly tailored to address a compelling governmental interest.
  • AI-Controlled Critical Infrastructure: Entities operating AI systems that control critical infrastructure are required to implement comprehensive risk management policies. These policies must align with established national and international standards, such as frameworks from the National Institute of Standards and Technology (NIST) and other international standardization organizations.
  • Compelling Governmental Interests: The bill outlines specific compelling governmental interests that may justify restrictions. These include protecting critical infrastructure, preventing fraud, safeguarding minors from harmful AI-generated content (like deepfakes), and managing public nuisances related to data center infrastructure.
  • Exemptions: The requirements for AI risk management do not apply to AI systems performing only nonexecutive tasks or those that serve as cybersecurity tools. Basic procedural tools are also exempted.
  • Intellectual Property Rights: The legislation explicitly protects intellectual property rights, ensuring it does not interfere with existing patent, trademark, copyright, and trade secret protections.

Implementation Framework

As a proposed bill, the implementation framework is currently in the legislative process. Should it pass, it would enact section 9.89 of the Revised Code.

Monitoring and Evaluation

Details regarding specific monitoring and evaluation mechanisms are not extensively detailed in the publicly available summaries of the introduced bill. Compliance with risk management policies for AI-controlled critical infrastructure would likely be subject to existing regulatory oversight bodies responsible for critical infrastructure.

Penalties, Liability, and Appeals

The publicly available summaries of the introduced bill do not extensively detail specific penalties, liability provisions, or appeal processes. These aspects would typically be elaborated during the legislative drafting and amendment process.

Relationship to Other Instruments

The bill requires AI risk management policies for critical infrastructure to align with national and international standards, including those from the National Institute of Standards and Technology (NIST) and other international standardization organizations.

International Alignment

The legislation references alignment with national and international standards for AI risk management, particularly concerning AI systems in critical infrastructure.

Implementation Timeline

DateMilestoneStatus
2025-07-07Introduced in the HouseProposed
2025-09-15Referred to House Technology and Innovation CommitteeUnder Review
2025-11-13House Technology and Innovation Committee, 3rd Hearing (Opp/IP Testimony)Under Review

Compliance Checklist

RequirementDescriptionDeadline
Limit on Governmental RestrictionsState agencies and political subdivisions must not restrict computational resources unless narrowly tailored to a compelling governmental interest.Upon enactment
AI Risk Management PolicyEntities operating AI systems controlling critical infrastructure must implement comprehensive risk management policies aligned with national/international standards (e.g., NIST).Upon enactment
Protection of Intellectual PropertyEnsure actions do not interfere with existing patent, trademark, copyright, and trade secret protections.Ongoing

Sources and References

SourceType
House Bill 392 | 136th General Assembly - Ohio House of RepresentativesOfficial Gazette
OH HB392 - BillTrack50Legal Database
HB392 | Ohio 2025-2026 | Enact the Ohio Right to Compute Act - PolicyEngageLegal Database
Bill tracking in Ohio - HB 392 (136 legislative session) - FastDemocracyLegal Database
Ohio Right to Compute: A Bold Vision for Technology Leadership in the Intelligence EraAcademic Paper
Plain English

Ohio's proposed Right to Compute Act aims to protect the use of computational systems across the state while also requiring specific safety measures for artificial intelligence (AI) controlling vital infrastructure. This bill broadly affects anyone in Ohio who develops, deploys, or uses computational resources, from individuals to businesses. More specifically, it places obligations on organizations that operate AI systems managing critical infrastructure, such as utilities or transportation networks.

The core of the act has two main thrusts. First, it largely prevents state agencies and local governments from creating new rules that restrict the lawful use of computational resources. They can only do so if a restriction is absolutely necessary to achieve a "compelling governmental interest" – for example, protecting critical infrastructure, preventing fraud, or safeguarding minors from harmful AI-generated content like deepfakes – and is very narrowly defined. Second, for companies using AI to control critical infrastructure, the bill mandates the creation of comprehensive risk management policies. These policies must follow established national and international standards, such as those from the National Institute of Standards and Technology (NIST).

It's important to note that AI systems performing only basic, non-executive tasks or those used for cybersecurity are exempt from these risk management requirements. The bill also explicitly states it won't interfere with existing intellectual property rights like patents, trademarks, and copyrights.

Currently, this is a proposed bill, introduced in the Ohio House of Representatives. If it passes and becomes law, these provisions would take effect upon its enactment. The publicly available summaries of the bill do not yet detail specific penalties, liability provisions, or appeal processes for non-compliance, which are typically refined as legislation moves through the drafting stages. A key practical takeaway is that while the bill champions a "right to compute," this right isn't absolute. The "compelling governmental interest" clause provides a significant carve-out, meaning future regulations could still emerge if deemed essential for public safety or other vital state interests. Businesses should monitor the bill's progress closely.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 4 marked complete

Plain-English obligations under United States - Ohio - AI Regulation (HB 392). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalUpon enactment

    Applies to: Ohio political subdivisions and state agencies.

    no political subdivision or state agency shall enact, adopt, enforce, or maintain any law, rule, regulation, permit requirement, or other administrative practice that restricts or prohibits any person's lawful use, development, deployment, or possession of a computational resource.
  2. #2CriticalUpon enactment

    Applies to: Entities operating AI systems that control critical infrastructure.

    Entities operating AI systems that control critical infrastructure are required to implement comprehensive risk management policies.
  3. #3CriticalUpon enactment

    Applies to: Entities operating AI systems that control critical infrastructure.

    These policies must align with established national and international standards, such as frameworks from the National Institute of Standards and Technology (NIST) and other international standardization organizations.
  4. #4ImportantOngoing

    Applies to: All entities and agencies subject to this act.

    The legislation explicitly protects intellectual property rights, ensuring it does not interfere with existing patent, trademark, copyright, and trade secret protections.

© Regulations.AI — created on 06-Jan-2026 using Gemini 2.5 Flash