Virginia High-Risk AI Bill Vetoed
High-Risk Artificial Intelligence Developer and Deployer Act
United States • Virginia
RAI-US-VA-HB20940-2025HB 2094
Virginia House Bill 2094, aimed at regulating high-risk AI systems and preventing algorithmic discrimination, was passed but vetoed by Governor Youngkin.
Overview
Virginia House Bill 2094, officially titled the High-Risk Artificial Intelligence Developer and Deployer Act, represented a significant legislative endeavor to establish a comprehensive regulatory framework for artificial intelligence within the Commonwealth. Introduced on January 10, 2025, during the 2025 Regular Session, the bill swiftly moved through the legislative process, ultimately passing the Virginia General Assembly on February 20, 2025. Its primary objective was to safeguard consumers from potential harms associated with high-risk AI systems, particularly concerning algorithmic discrimination and the lack of transparency in automated decision-making processes. The bill sought to impose a duty of care, risk assessment requirements, and specific disclosure obligations on entities involved in the development and deployment of such systems, aiming to foster responsible AI innovation while protecting individual rights.
Despite its passage by the legislature, HB 2094 faced a pivotal moment when it reached the desk of Governor Glenn Youngkin. On March 24, 2025, Governor Youngkin exercised his veto power, effectively preventing the bill from becoming law. His stated reasons for the veto centered on concerns that the bill's stringent requirements would impede innovation and economic growth within Virginia, particularly burdening startups and small businesses. The Governor emphasized that the rigid framework of HB 2094 failed to account for the rapidly evolving nature of the AI industry, suggesting that the compliance costs and regulatory hurdles could deter new businesses from investing or innovating in the Commonwealth. This decision marked a significant turning point for AI regulation in Virginia, distinguishing its approach from states like Colorado, which has enacted similar comprehensive AI legislation, and from the broader, more stringent regulatory model seen in the European Union's AI Act.
Definitions
Central to HB 2094 was its precise definition of a "high-risk artificial intelligence system," which determined the scope of its regulatory obligations. The bill defined such a system as any machine-learning-based system that, for any explicit or implicit objective, infers from inputs to generate outputs (including content, decisions, predictions, and recommendations) that can influence physical or virtual environments. Crucially, a system was deemed high-risk if it (i) operated without meaningful human oversight, (ii) served as the principal basis for consequential decisions, and (iii) was explicitly intended to autonomously make or substantially influence such decisions about Virginians in their individual or household capacities. This narrow focus aimed to target AI applications with the most significant potential impact on individuals.
The bill further elaborated on the concept of "consequential decisions," listing specific areas where AI-driven outcomes could have material legal or similarly significant effects on consumers. These included decisions related to parole, probation, pardon, or other forms of release from incarceration or court supervision; education enrollment or opportunities; access to employment; financial or lending services; healthcare services; housing; insurance; marital status; and legal services. HB 2094 also provided several exemptions for what would not be considered a high-risk AI system, such as those intended to perform narrow procedural tasks, improve previously completed human activity, detect decision-making patterns, or perform preparatory tasks. Additionally, a range of technologies were specifically excluded, including anti-fraud technology (without facial recognition), AI-enabled video games, autonomous vehicle technology, cybersecurity technology, databases, data storage, firewall technology, networking, spam and robocall filtering, and natural language communicators (provided they adhered to an acceptable use policy prohibiting discriminatory or unlawful content).
Governance and Institutional Framework
Had HB 2094 been signed into law, the enforcement authority for its provisions would have rested exclusively with the Virginia Office of the Attorney General. This centralized enforcement mechanism aimed to ensure consistent application of the new regulatory framework across the Commonwealth. The Attorney General would have been empowered to investigate potential violations, issuing civil investigative demands before initiating formal enforcement actions. This approach underscored a preference for governmental oversight rather than relying on individual legal actions, as the bill explicitly stated that there would be no private right of action for consumers to sue developers or deployers directly under its provisions.
While HB 2094 itself did not establish a new, dedicated state-level AI regulatory body, its intended framework would have complemented existing governance efforts in Virginia. Notably, Governor Youngkin had previously signed Executive Order No. 30 in 2024, which established baseline standards and guidelines for the use of AI within Virginia's state government agencies. This executive order also created an Artificial Intelligence Task Force, comprised of experts from business, technology, and academia, tasked with developing further "guardrails" for responsible AI use and providing ongoing recommendations. Although separate from HB 2094, these initiatives collectively reflect Virginia's broader engagement with AI governance, aiming to address its implications across both public and, had HB 2094 passed, private sectors. The Attorney General's role would have been critical in navigating the nuances of these interconnected, yet distinct, regulatory landscapes.
Key Focus Areas
The core of HB 2094's regulatory approach centered on establishing a "reasonable duty of care" for both developers and deployers of high-risk artificial intelligence systems, with a strong emphasis on consumer protection and the mitigation of algorithmic discrimination. Developers were mandated to document known or reasonably foreseeable limitations of their AI systems, ensuring transparency regarding performance, capabilities, and potential biases. This included providing deployers with detailed documentation explaining the evaluation methods used to test the system's performance and any steps taken to mitigate identified risks. Furthermore, the bill required that generated or substantially modified synthetic content from generative AI high-risk systems be made identifiable and detectable using industry-standard tools, comply with applicable accessibility requirements where feasible, and be identified at the time of generation, with limited exceptions for low-risk or creative applications.
For deployers of high-risk AI systems, the bill imposed obligations to disclose the use of AI to consumers and to conduct impact assessments. These assessments were intended to evaluate the potential risks of algorithmic discrimination and to ensure that the systems were used responsibly and ethically. The bill referenced established AI risk frameworks, such as the NIST AI Risk Management Framework (RMF) and ISO/IEC 42001, as benchmarks for developers and deployers to adhere to in their risk management and documentation practices. By focusing on these key areas—duty of care, transparency through documentation and disclosure, risk assessment, and the identifiability of synthetic content—HB 2094 aimed to create a robust framework that would compel businesses to proactively address the ethical and societal implications of their high-risk AI systems, thereby protecting Virginians from potential harms.
Implementation Framework
Had it been signed into law, HB 2094 was slated to take effect on July 1, 2026, providing businesses with a substantial lead time to prepare for compliance with its new regulatory requirements. The bill's implementation framework included a discretionary 45-day right to cure period, which the Attorney General could offer to entities found in violation of the Act. This provision aimed to provide businesses with an opportunity to rectify non-compliance before facing penalties, reflecting a regulatory approach that favored corrective action over immediate punitive measures, particularly for non-willful violations. This cure period was a notable difference compared to some other AI regulatory proposals, offering a degree of flexibility for businesses navigating the new framework.
The Act also outlined several exemptions and conditions under which obligations would be deemed satisfied. For instance, AI use in response to a consumer request or to provide a requested service or product under a contract was generally excluded from certain provisions. Furthermore, specific industries, including banks, credit unions, mortgage lenders, savings institutions, and their affiliates or service providers, would be deemed to have met the Act's requirements if they were already subject to state or federal regulations or published guidance concerning the use of high-risk AI systems. This acknowledged that highly regulated sectors often have existing frameworks addressing similar risks. However, unlike some other state AI bills, HB 2094 did not include direct incident reporting requirements, broad public disclosure requirements, or a specific small business exception, which were points of contention during its legislative journey and contributed to concerns about its potential impact on smaller firms.
Monitoring and Evaluation
The monitoring and evaluation of compliance under HB 2094, had it become law, would have primarily fallen under the purview of the Virginia Office of the Attorney General. As the exclusive enforcement authority, the Attorney General's office would have been responsible for investigating potential violations by developers and deployers of high-risk AI systems. This would involve responding to complaints, conducting civil investigative demands, and assessing whether entities were adhering to the prescribed duties of care, transparency obligations, and risk management requirements. While the bill did not explicitly establish a dedicated state-level AI regulatory agency or a formal, ongoing monitoring program for AI systems in the private sector, the Attorney General's enforcement actions would have served as the primary mechanism for overseeing the implementation and effectiveness of the Act's provisions.
The discretionary 45-day right to cure period, a key feature of the enforcement framework, also implicitly contributed to a form of ongoing evaluation. It would have allowed the Attorney General's office to engage with businesses to identify and address non-compliance, thereby prompting self-correction and potentially refining compliance practices over time. However, without specific requirements for public reporting of AI system deployments, algorithmic impact assessment summaries, or incident data, the broader societal impact and efficacy of the Act in mitigating algorithmic discrimination would have largely been assessed through the outcomes of enforcement cases rather than through a comprehensive, proactive monitoring and evaluation framework. This reliance on enforcement as the primary oversight mechanism meant that the monitoring aspect would have been reactive, triggered by potential violations rather than systematic, continuous assessment of AI systems across the state.
Penalties, Liability, and Appeals
HB 2094 prescribed a clear structure for penalties and liability for non-compliance, designed to deter violations and ensure adherence to the established duties of care and transparency. For general violations of the Act's provisions, businesses could face civil penalties of up to $1,000 per occurrence. In cases where violations were deemed willful, the penalties would significantly increase, with fines potentially reaching up to $10,000 per occurrence. Each instance of non-compliance would be considered separately for penalty assessment, allowing the Attorney General to impose cumulative fines for multiple or ongoing infractions. Additionally, the bill included provisions for attorney fee shifting, meaning that in enforcement actions, the costs of legal proceedings could be imposed on the non-compliant party.
A crucial aspect of the enforcement process was the discretionary 45-day right to cure period. Before initiating any formal enforcement action, the Attorney General was required to issue a civil investigative demand, and then had the discretion to provide the offending party with 45 days to address and rectify the violation. This cure period offered businesses an opportunity to come into compliance without immediately facing the full extent of the civil penalties, promoting a more collaborative approach to regulatory adherence. However, it is important to reiterate that HB 2094 explicitly precluded a private right of action, meaning that individual consumers harmed by a high-risk AI system could not directly sue developers or deployers under the provisions of this specific Act. Their avenues for redress would remain through existing consumer protection laws or other applicable legal frameworks, rather than through direct claims under HB 2094.
Relationship to Other Instruments
Virginia's HB 2094 was closely modeled on the Colorado AI Act (CAIA), which was signed into law in May 2024, making Colorado the first U.S. state with comprehensive AI regulations. Despite this foundational similarity in adopting a risk-based approach to AI governance, HB 2094 introduced several notable distinctions. Virginia's bill defined "consumers" more narrowly, limiting its scope to individuals and households and explicitly excluding commercial and employment contexts, which the CAIA includes. Furthermore, HB 2094's definition of "high-risk AI" was more constrained, focusing specifically on machine-learning-based systems that operate without meaningful human oversight and serve as the principal basis for consequential decisions, while also expanding the list of high-risk uses to include areas like parole, probation, and marital status decisions. The Virginia bill also provided clearer guidelines on when a developer transitions into a deployer role, imposed more specific documentation and transparency obligations, and enhanced trade secret protections.
Key differences from the CAIA included the absence of a requirement in HB 2094 for reporting algorithmic discrimination to the Attorney General and the provision of a discretionary 45-day right to cure violations, as opposed to the CAIA's more prescriptive approach. When compared to the European Union's AI Act, HB 2094 presented even more significant divergences. The EU AI Act is considerably broader and more stringent, employing a comprehensive risk-based classification system that includes prohibited AI practices and imposes stricter compliance obligations with substantial penalties. Virginia's bill, being significantly shorter and less prescriptive, did not contain direct incident reporting requirements, extensive public disclosure mandates, or a small business exception, all of which are features or considerations in the EU framework. Despite HB 2094's veto, businesses in Virginia remain subject to other existing state laws, such as the Virginia Consumer Data Protection Act (CDPA), which continues to govern the use of personal information and the outcomes of automated decisions, regardless of specific AI legislation.
National/Federal Alignment
Virginia's HB 2094 emerged within a burgeoning landscape of state-level AI regulation across the United States, positioning the Commonwealth as a potential early adopter of comprehensive AI legislation, following Colorado. This trend reflects a growing recognition among state legislatures of the need to address the societal implications of artificial intelligence in the absence of a unified federal framework. The bill's design, heavily influenced by the Colorado AI Act, underscored a common approach among states to focus on high-risk AI systems and consumer protection. However, Governor Youngkin's veto on March 24, 2025, represented a divergence from this trend, signaling a preference for an approach that prioritizes innovation and economic growth, echoing sentiments sometimes expressed at the federal level, such as the "Removing Barriers to American Leadership in Artificial Intelligence" executive order under a previous administration, which emphasized innovation over stringent regulation.
Even with the veto of HB 2094, Virginia is not without its own AI governance initiatives. Governor Youngkin's Executive Order No. 30, signed in 2024, established baseline standards and guidelines for the use of AI within Virginia's state government agencies. This executive order directed the Virginia Information Technologies Agency (VITA) to publish AI policy and IT standards for all executive branch agencies, requiring compliance from any AI technologies used by state agencies, including those provided by outside vendors. Executive Order No. 30 also created an Artificial Intelligence Task Force to develop further "guardrails" for responsible AI use and provide ongoing recommendations. Therefore, while HB 2094's veto halted private-sector-specific AI legislation, Virginia continues to engage in AI governance through its executive branch, indirectly influencing private businesses that contract with state agencies. This layered approach illustrates the complex and evolving nature of AI regulation, where state-level efforts, executive directives, and existing general laws collectively shape the regulatory environment.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Bill Introduced | 2025-01-10 | House Bill 2094 introduced in the Virginia House of Delegates. |
| Passed General Assembly | 2025-02-20 | Bill passed by the Virginia General Assembly (House and Senate). |
| Governor's Veto | 2025-03-24 | Governor Glenn Youngkin vetoed HB 2094. |
| Proposed Effective Date (if enacted) | 2026-07-01 | The date the Act would have become law, had it not been vetoed. |
Compliance Checklist
| Check | Required Action |
|---|---|
| For Developers of High-Risk AI Systems: | |
| Document Limitations | Document known or reasonably foreseeable limitations of the AI system, including its purpose, intended uses, and material risks of algorithmic discrimination. |
| Transparency & Documentation | Provide deployers with clear documentation explaining the AI system's performance, evaluation methods, and steps taken to mitigate known risks. |
| Risk Management | Implement a risk management program, potentially referencing frameworks like NIST AI RMF or ISO/IEC 42001. |
| Synthetic Content Identification | Ensure generated or substantially modified synthetic content is identifiable and detectable using industry-standard tools and complies with accessibility requirements. |
| For Deployers of High-Risk AI Systems: | |
| Disclose AI Usage | Clearly disclose to consumers when a high-risk AI system is being used to make consequential decisions affecting them. |
| Impact Assessments | Conduct regular impact assessments to evaluate and mitigate the risks of algorithmic discrimination associated with the AI system's use. |
| Duty of Care | Exercise a reasonable duty of care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. |
Sources and References
| Source | Type |
|---|---|
| HB2094 - 2025 Regular Session | official |
| HB2094 - 2025 Regular Session (Bill Text) | official |
| HB2094ER - 2025 Regular Session (Engrossed Bill Text) | official |
Related Regulations
Virginia Commission on Artificial Intelligence (established by SB 487, 2024 Session)
United States84% similar
Concerning Consumer Protections in Interactions with Artificial Intelligence Systems
Colorado, United States83% similar
Concerning Consumer Protections in Interactions with Artificial Intelligence Systems
Colorado, United States83% similar
An Act Concerning Artificial Intelligence (Connecticut SB 2)
United States83% similar
Georgia HB 887 - Insurance use of artificial intelligence in coverage decisions
United States82% similar
© Regulations.AI — created on 05-Aug-2026 using Gemini 2.5 Flash