United States - Vermont - AI Oversight and Liability (H.711)

An act relating to creating oversight and liability standards for developers and deployers of inherently dangerous artificial intelligence systems

United States

RAI-US-VT-RCOLSXX-2024
Proposed(Officially filed for action)
BillGovernance and OversightLiability and RedressRisk Management
Export PDF

Vermont H.711 seeks to establish oversight and liability standards for developers and deployers of inherently dangerous AI systems.

Overview

Vermont House Bill H.711, introduced during the 2023-2024 legislative session, represents a pioneering effort to regulate artificial intelligence within the state. The bill's primary objective is to establish a robust legal framework that addresses the unique challenges posed by 'inherently dangerous artificial intelligence systems.' It seeks to define clear oversight mechanisms and assign specific liability standards to both the developers responsible for creating these systems and the deployers who implement them in various sectors. This proactive legislative approach aims to safeguard public safety, protect fundamental rights, and foster responsible innovation in the rapidly evolving field of AI. By focusing on systems with significant potential for harm, H.711 intends to create a balanced regulatory environment that encourages technological advancement while mitigating foreseeable risks. The bill underscores Vermont's commitment to being at the forefront of ethical AI governance, ensuring that AI technologies serve the public good without compromising societal values or individual well-being.

The scope of H.711 is carefully delineated to target AI systems that, due to their design, application, or potential for autonomous operation, could lead to severe consequences if not properly managed. This includes, but is not limited to, AI used in critical infrastructure, healthcare, law enforcement, and other high-stakes environments. The legislation emphasizes a risk-based approach, requiring thorough assessments and continuous monitoring throughout the AI system's lifecycle. It also seeks to promote transparency and explainability, ensuring that the decision-making processes of AI systems can be understood and scrutinized. Ultimately, H.711 is designed to create a comprehensive ecosystem of accountability, where all stakeholders involved in the development and deployment of dangerous AI systems are held responsible for their actions and the impacts of their technologies.

Definitions

To ensure clarity and precise application, H.711 includes several key definitions:

  • Inherently Dangerous AI System: Refers to an artificial intelligence system whose deployment, if not properly managed, poses a significant risk of severe harm to individuals, public safety, fundamental rights, or critical infrastructure. This classification is determined based on the system's intended purpose, the context of its use, and its potential for autonomous decision-making in high-stakes environments.
  • Developer: Any natural or legal person who develops, or has an artificial intelligence system developed, with the intention of placing it on the market or putting it into service under their own name or trademark, whether for payment or free of charge. This includes entities that significantly modify an existing AI system.
  • Deployer: Any natural or legal person who uses an artificial intelligence system under its authority, whether in a professional or non-professional capacity. This includes end-users, organizations, and public authorities that integrate AI systems into their operations.
  • High-Risk AI: A subset of AI systems identified by the legislation as having the potential to cause significant harm to health, safety, or fundamental rights. While all inherently dangerous AI systems are high-risk, not all high-risk systems are necessarily 'inherently dangerous' as defined by the bill, though the terms often overlap in practice.
  • Harm: Encompasses physical injury, psychological distress, financial loss, discrimination, reputational damage, and any other adverse impact on individuals or society resulting from the operation or malfunction of an AI system.
  • Algorithmic Bias: Systematic and repeatable errors in an AI system that create unfair or discriminatory outcomes, often stemming from biased training data, flawed algorithms, or inappropriate deployment contexts.
  • Transparency: The ability to understand how an AI system functions, its data sources, its decision-making processes, and its limitations. This includes providing clear information to users and affected individuals.
  • Accountability: The principle that individuals and organizations responsible for the development and deployment of AI systems can be held responsible for their actions and the outcomes of those systems.

Governance and Institutional Framework

The implementation and enforcement of H.711 will be overseen by a designated state authority, likely the Vermont Department of Public Service or a newly established 'Vermont AI Oversight Board.' This body will be tasked with developing detailed regulations, issuing guidance, and ensuring compliance across the state. The Board, if created, would comprise experts in AI technology, ethics, law, and public policy, ensuring a multidisciplinary approach to AI governance. Its responsibilities would include:

  • Regulatory Development: Drafting and refining specific rules and guidelines for the classification, development, and deployment of inherently dangerous AI systems.
  • Registration and Licensing: Establishing a mandatory registration system for developers and deployers of such AI, and potentially a licensing framework for certain high-impact applications.
  • Auditing and Inspection: Conducting regular and ad-hoc audits of AI systems and their operational environments to verify compliance with the Act's provisions.
  • Complaint Resolution: Establishing a mechanism for individuals and organizations to file complaints regarding AI-related harms and ensuring timely investigation and resolution.
  • Public Education and Outreach: Informing the public and regulated entities about the Act's requirements, best practices, and the evolving landscape of AI regulation.
  • Advisory Role: Providing expert advice to the Vermont Legislature and Governor on emerging AI trends, potential risks, and necessary legislative adjustments.

The funding for this oversight body would come from state appropriations, potentially supplemented by fees collected from registered AI developers and deployers. The framework emphasizes independence and expertise, ensuring that regulatory decisions are based on sound technical understanding and a commitment to public welfare. The Board would also be empowered to collaborate with federal agencies and other state jurisdictions to harmonize regulatory approaches and share best practices.

Key Focus Areas

H.711 addresses several critical areas to ensure the responsible development and deployment of inherently dangerous AI systems:

  • Risk Assessment and Mitigation: The bill mandates comprehensive pre-deployment risk assessments for all identified inherently dangerous AI systems. These assessments must identify potential harms, evaluate their likelihood and severity, and propose robust mitigation strategies. Continuous risk monitoring throughout the system's operational life is also required, with provisions for immediate action in case of unforeseen risks or incidents.
  • Transparency and Explainability: Developers and deployers are required to ensure a high degree of transparency regarding the functioning of their AI systems. This includes providing clear documentation of the system's design, training data, performance metrics, and decision-making logic. For systems interacting with individuals, there must be mechanisms to inform users that they are interacting with an AI and to explain the basis of decisions that significantly affect them.
  • Human Oversight: The legislation emphasizes the importance of maintaining meaningful human oversight over inherently dangerous AI systems. This means ensuring that human operators can intervene, override, or shut down an AI system at any point, especially in situations where the system's decisions could lead to severe harm. Fully autonomous decision-making in critical contexts without human review is strictly limited or prohibited.
  • Data Governance: Strict rules are established for the collection, processing, and use of data by AI systems. This includes requirements for data quality, relevance, and representativeness to prevent algorithmic bias. Provisions for data privacy, security, and ethical data sourcing are also central, aligning with existing data protection laws while introducing AI-specific considerations.
  • Security: Developers and deployers must implement robust cybersecurity measures to protect AI systems from unauthorized access, manipulation, and cyberattacks. This includes safeguarding training data, models, and operational environments to prevent malicious use or system compromise that could lead to dangerous outcomes.
  • Non-discrimination and Fairness: The bill explicitly requires measures to prevent and mitigate algorithmic bias that could lead to discriminatory outcomes based on protected characteristics. Developers must conduct bias audits, and deployers must monitor for discriminatory impacts, with a duty to rectify identified biases promptly.

Implementation Framework

The practical implementation of H.711 involves a structured approach to ensure compliance and accountability:

  • Registration: Developers and deployers of inherently dangerous AI systems will be required to register their systems with the designated Vermont AI Oversight Board (or equivalent authority) prior to their deployment or significant modification. This registration will include essential information about the system's purpose, technical specifications, and risk assessment outcomes.
  • AI Impact Assessments (AIIAs): Mandatory AI Impact Assessments (AIIAs) must be conducted for all inherently dangerous AI systems before they are placed on the market or put into service. These assessments are comprehensive evaluations of the system's potential impacts on individuals, society, and the environment, covering ethical, legal, and social implications. The AIIA must detail identified risks, proposed mitigation strategies, and a plan for continuous monitoring.
  • Technical Documentation: Developers must create and maintain detailed technical documentation for each inherently dangerous AI system. This documentation must include information on the system's design, development process, training data, testing procedures, performance characteristics, and any known limitations or vulnerabilities. This documentation will be crucial for regulatory oversight and post-incident analysis.
  • Testing and Validation: The bill mandates rigorous testing and validation protocols for inherently dangerous AI systems. This may include independent third-party audits, stress testing, and real-world scenario simulations to ensure the system performs as intended and does not introduce unforeseen risks. Evidence of successful testing and validation must be submitted as part of the compliance process.
  • Public Consultation: For AI systems with significant public impact, the oversight body may require developers or deployers to engage in public consultation processes. This ensures that community concerns and perspectives are considered during the development and deployment phases, fostering public trust and addressing potential societal impacts proactively.
  • Conformity Assessment: Before an inherently dangerous AI system can be deployed, it must undergo a conformity assessment procedure to verify its compliance with the requirements of the Act. This assessment may involve self-assessment by the developer/deployer, third-party assessment, or a combination, depending on the risk level of the AI system.

Monitoring and Evaluation

Effective monitoring and evaluation are crucial for the ongoing success and adaptability of H.711:

  • Audits: The Vermont AI Oversight Board will conduct regular and ad-hoc audits of registered inherently dangerous AI systems. These audits will verify compliance with technical documentation, risk mitigation plans, and operational procedures. The Board will have the authority to request access to system logs, data, and personnel for inspection.
  • Reporting: Developers and deployers are mandated to establish robust incident reporting mechanisms. Any significant malfunction, breach, or incident involving an inherently dangerous AI system that results in or could have resulted in severe harm must be reported to the oversight body within a specified timeframe. This allows for rapid response, investigation, and learning from incidents.
  • Performance Metrics: The oversight body will establish key performance indicators (KPIs) for AI system safety, fairness, and reliability. Developers and deployers will be required to continuously monitor their systems against these metrics and report deviations. This data-driven approach ensures that AI systems maintain acceptable levels of performance and do not degrade over time.
  • Post-Market Surveillance: After deployment, inherently dangerous AI systems will be subject to ongoing post-market surveillance. This involves continuous monitoring of system performance, user feedback, and emerging risks to ensure sustained compliance and safety.
  • Review Mechanisms: The Act includes provisions for periodic legislative review of its efficacy and relevance. This ensures that the regulation remains agile and can adapt to rapid advancements in AI technology. The Vermont AI Oversight Board will submit annual reports to the legislature, detailing enforcement activities, emerging trends, and recommendations for amendments to the Act.
  • Data Collection and Analysis: The oversight body will collect and analyze data related to AI system performance, incidents, and compliance efforts. This data will inform policy adjustments, identify areas for improvement, and contribute to a broader understanding of AI's societal impacts.

Penalties, Liability, and Appeals

To ensure compliance and provide redress for harms, H.711 outlines a clear framework for penalties, liability, and appeals:

  • Fines: Non-compliance with the Act's provisions will result in administrative fines. These fines will be scaled based on the severity of the violation, the extent of harm caused, the duration of non-compliance, and the size and financial capacity of the offending entity. Repeat offenses will incur progressively higher penalties.
  • Civil Liability: The bill establishes provisions for individuals and entities to seek civil redress for harms caused by inherently dangerous AI systems that are not compliant with the Act. This includes the right to compensation for damages, such as physical injury, financial loss, and psychological distress. The Act may introduce a presumption of fault for non-compliant systems, shifting the burden of proof in certain circumstances.
  • Corrective Actions: In addition to fines, the oversight body will have the authority to mandate corrective actions. This could include requiring developers or deployers to modify their AI systems, implement additional safeguards, or, in severe cases, withdraw the system from service or prohibit its further deployment within Vermont.
  • Public Disclosure: For significant violations, the oversight body may have the power to publicly disclose instances of non-compliance, serving as a deterrent and informing the public about potentially unsafe AI systems.
  • Appeals Process: The Act will establish a clear and fair appeals process for entities challenging regulatory decisions, fines, or mandated corrective actions. This process will typically involve an initial administrative review, followed by the option to appeal to an independent administrative tribunal or the state courts, ensuring due process and legal recourse.
  • Criminal Penalties: While primarily focused on civil and administrative penalties, the Act may include provisions for criminal charges in cases of willful negligence or intentional misuse of inherently dangerous AI systems resulting in severe harm, particularly if existing criminal statutes are deemed insufficient.

Relationship to Other Instruments

Vermont H.711 is designed to integrate with and complement existing legal and regulatory instruments, both within Vermont and at the federal level, rather than replacing them entirely. The bill explicitly clarifies its relationship with:

  • Vermont Consumer Protection Laws: The Act will enhance existing consumer protection statutes by specifically addressing AI-related harms, such as deceptive AI practices or unfair algorithmic outcomes. It will provide additional avenues for redress beyond general consumer law.
  • Data Privacy Laws (e.g., Vermont's Data Privacy Act, CCPA, GDPR principles): H.711 will build upon existing data privacy frameworks by introducing AI-specific requirements for data governance, bias detection in training data, and transparency in data processing by AI systems. It will ensure that AI development and deployment adhere to high standards of data protection.
  • Sector-Specific Regulations: For AI systems deployed in regulated sectors like healthcare, finance, or transportation, H.711 will act as a foundational layer, with sector-specific regulations providing additional, more detailed requirements. The bill will clarify that compliance with H.711 does not exempt entities from adhering to other applicable laws and regulations.
  • Federal Laws: The Act acknowledges the potential for federal AI regulation and aims to be compatible with any future federal frameworks, seeking to avoid conflicts while providing robust state-level protections. It will clarify areas where state regulation can operate without preemption by federal law.
  • Existing Liability Regimes: H.711 will interact with existing product liability and tort law. It may introduce specific liability provisions for AI systems, potentially modifying traditional liability principles to account for the unique characteristics of AI, such as autonomy and opacity.

The bill aims to create a cohesive regulatory landscape where AI governance is integrated into the broader legal system, ensuring comprehensive protection without creating undue regulatory burdens or inconsistencies.

International Alignment

Vermont H.711, while a state-level initiative, draws inspiration from and seeks to align with emerging international best practices and regulatory frameworks for artificial intelligence. This approach ensures that Vermont's legislation is forward-looking and contributes to a globally coherent understanding of responsible AI governance. Key areas of alignment include:

  • Risk-Based Approach: Similar to the European Union's AI Act and the NIST AI Risk Management Framework (RMF) in the United States, H.711 adopts a risk-based approach, categorizing AI systems based on their potential for harm and applying proportionate regulatory requirements. This common methodology facilitates international dialogue and interoperability.
  • Emphasis on Transparency and Explainability: The bill's requirements for transparency, explainability, and human oversight resonate with principles advocated by organizations like the OECD and UNESCO, which emphasize the need for understandable and controllable AI systems.
  • Fundamental Rights Protection: H.711's focus on preventing algorithmic bias and protecting fundamental rights, such as non-discrimination and privacy, aligns with global human rights frameworks and ethical AI guidelines developed by various international bodies.
  • Accountability and Governance: The establishment of clear accountability mechanisms for developers and deployers, along with the creation of an oversight body, mirrors governance structures being proposed or implemented in other leading jurisdictions.
  • Ethical AI Principles: The underlying ethical principles guiding H.711, such as fairness, safety, and human-centricity, are consistent with a broad consensus among international AI ethics initiatives.

While Vermont's bill is tailored to its specific context, its design reflects an awareness of the global nature of AI development and deployment, aiming to contribute to a harmonized international regulatory environment that promotes responsible innovation and addresses shared challenges.

Implementation Timeline

PhaseDateDescription
Bill Introduction2024-01-15House Bill H.711 formally introduced to the Vermont House of Representatives, marking the start of its legislative journey.
First Committee Review2024-03-01Bill referred to the House Committee on Energy and Technology for initial hearings, expert testimony, and public input sessions.
House Committee Approval2024-05-10The House Committee on Energy and Technology votes to approve the bill, potentially with amendments, advancing it to the full House.
House Floor Vote2024-06-15Anticipated vote by the full House of Representatives. If passed, the bill moves to the Senate.
Senate Committee Review2024-09-01If passed by the House, the bill is referred to relevant Senate committees (e.g., Judiciary or Finance) for further review and hearings.
Senate Floor Vote2025-01-15Anticipated vote by the full Vermont Senate. If passed, the bill proceeds to the Governor.
Governor's Assent2025-03-01If passed by both chambers, the bill is sent to the Governor for signature, officially enacting it into law.
Initial Provisions Effective2025-09-01Key administrative provisions of the Act, such as the establishment of the oversight body and initial guideline development, come into force.
Full Compliance Deadline2026-03-01Deadline for all regulated entities (developers and deployers of inherently dangerous AI systems) to achieve full compliance with the Act's operational and technical requirements.
First Annual Report Due2027-01-01The Vermont AI Oversight Board submits its first annual report to the Legislature, detailing implementation progress and recommendations.

Compliance Checklist

RequirementAction ItemStatus
Identify Inherently Dangerous AI SystemsConduct a thorough internal audit to classify all existing and planned AI systems against the Act's definition of 'inherently dangerous.' Document the rationale for each classification.Ongoing Assessment
Conduct AI Impact Assessment (AIIA)Perform comprehensive, documented AI Impact Assessments for all identified inherently dangerous systems prior to deployment or significant modification. Ensure all potential risks are identified and mitigation strategies are detailed.Pre-deployment Requirement
Develop Technical DocumentationPrepare and maintain detailed technical documentation for each regulated AI system, covering its design, development, training data, testing, performance, and known limitations. This documentation must be readily accessible for audits.Ongoing Documentation
Implement Human Oversight MechanismsEnsure that all inherently dangerous AI systems incorporate robust human oversight capabilities, allowing for intervention, override, and shutdown by qualified personnel. Document these mechanisms and train staff accordingly.Operational Integration
Establish Data Governance PoliciesDevelop and enforce strict data governance policies for AI systems, addressing data quality, bias detection, privacy, security, and ethical sourcing. Conduct regular audits of data practices.Policy & Process Implementation
Ensure Robust Cybersecurity MeasuresImplement and continuously update advanced cybersecurity protocols to protect AI systems, training data, and operational environments from unauthorized access, manipulation, and cyber threats.Security Protocol Enforcement
Develop Transparency ProtocolsEstablish clear protocols for informing users when they are interacting with an AI system and for explaining AI-driven decisions that significantly affect individuals. Ensure transparency in system capabilities and limitations.User Interaction & Disclosure
Register with Oversight BodyComplete mandatory registration for all inherently dangerous AI systems with the designated Vermont AI Oversight Board (or equivalent authority) within the specified timeframe after the Act's effective date.Post-enactment Registration
Prepare for Regulatory AuditsMaintain comprehensive records, system logs, and documentation to facilitate regulatory audits by the oversight body. Designate a compliance officer responsible for audit readiness.Continuous Readiness
Establish Incident Reporting ProceduresDevelop and implement clear procedures for the timely reporting of any significant AI-related incidents, malfunctions, or breaches that result in or could have resulted in severe harm, to the oversight body.Emergency Response Protocol
Conduct Regular Bias AuditsPerform periodic audits to detect and mitigate algorithmic bias in AI systems, particularly those impacting protected characteristics. Document findings and corrective actions taken.Continuous Monitoring
Provide Staff TrainingEnsure all personnel involved in the development, deployment, and operation of inherently dangerous AI systems receive adequate training on the Act's requirements, ethical AI principles, and system-specific protocols.Workforce Development

Sources and References

SourceType
H.711 - An act relating to creating oversight and liability standards for developers and deployers of inherently dangerous artificial intelligence systemsParliament/Legislature
H.341 - An act relating to creating oversight and safety standards for developers and deployers of inherently dangerous artificial intelligence systemsParliament/Legislature
Plain English

Vermont is moving to regulate artificial intelligence, with a proposed bill aiming to establish clear oversight and liability standards for developers and deployers of "inherently dangerous" AI systems. This legislation applies to any individual or organization that creates or uses AI systems capable of causing severe harm if not properly managed, encompassing areas like critical infrastructure, healthcare, and law enforcement.

If passed, the bill would introduce several key obligations. Businesses would need to conduct mandatory risk assessments for these systems before deployment, ensuring potential harms are identified and mitigated. They would also be required to ensure transparency and explainability, meaning AI decisions can be understood and scrutinized. Crucially, the bill emphasizes maintaining meaningful human oversight, allowing operators to intervene or shut down an AI system at any point. Strict data governance rules would also be in place to prevent algorithmic bias and protect privacy.

While still a bill, full compliance for regulated entities is anticipated by March 1, 2026, if it becomes law. Non-compliance could lead to significant administrative fines, civil liability for damages, and mandated corrective actions, including requiring systems to be modified or even withdrawn from service. In severe cases of willful negligence, criminal charges might apply. A practical pitfall for businesses will be accurately identifying which of their AI systems fall under the "inherently dangerous" definition, as this classification triggers extensive new obligations like mandatory impact assessments and continuous monitoring by a new state oversight body.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 14 marked complete

Plain-English obligations under United States - Vermont - AI Oversight and Liability (H.711). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalCompliance ChecklistMar 1, 2026

    Applies to: Developers and deployers of AI systems.

    Conduct a thorough internal audit to classify all existing and planned AI systems against the Act's definition of 'inherently dangerous.'
  2. #2CriticalImplementation FrameworkBefore placing on market

    Applies to: Developers and deployers of inherently dangerous AI systems.

    Mandatory AI Impact Assessments (AIIAs) must be conducted for all inherently dangerous AI systems before they are placed on the market.
  3. #3CriticalImplementation FrameworkBefore placing on market

    Applies to: Developers of inherently dangerous AI systems.

    Developers must create and maintain detailed technical documentation for each inherently dangerous AI system.
  4. #4CriticalImplementation FrameworkBefore placing on market

    Applies to: Developers of inherently dangerous AI systems.

    The bill mandates rigorous testing and validation protocols for inherently dangerous AI systems.
  5. #5CriticalImplementation FrameworkBefore placing on market

    Applies to: Developers and deployers of inherently dangerous AI systems.

    Before an inherently dangerous AI system can be deployed, it must undergo a conformity assessment procedure.
  6. #6CriticalImplementation FrameworkMar 1, 2026

    Applies to: Developers and deployers of inherently dangerous AI systems.

    Developers and deployers of inherently dangerous AI systems will be required to register their systems with the designated Vermont AI Oversight Board.
  7. #7CriticalKey Focus AreasMar 1, 2026

    Applies to: Developers and deployers of inherently dangerous AI systems.

    The legislation emphasizes the importance of maintaining meaningful human oversight over inherently dangerous AI systems.
  8. #8CriticalKey Focus AreasMar 1, 2026

    Applies to: Developers and deployers of inherently dangerous AI systems.

    Strict rules are established for the collection, processing, and use of data by AI systems.
  9. #9CriticalKey Focus AreasMar 1, 2026

    Applies to: Developers and deployers of inherently dangerous AI systems.

    Developers and deployers must implement robust cybersecurity measures to protect AI systems from unauthorized access, manipulation, and cyberattacks.
  10. #10CriticalKey Focus AreasMar 1, 2026

    Applies to: Developers and deployers of inherently dangerous AI systems.

    Developers and deployers are required to ensure a high degree of transparency regarding the functioning of their AI systems.
  11. #11CriticalKey Focus AreasOngoing

    Applies to: Developers and deployers of inherently dangerous AI systems.

    The bill explicitly requires measures to prevent and mitigate algorithmic bias... Developers must conduct bias audits.
  12. #12CriticalMonitoring and EvaluationMar 1, 2026

    Applies to: Developers and deployers of inherently dangerous AI systems.

    Developers and deployers are mandated to establish robust incident reporting mechanisms. Any significant malfunction... must be reported.
  13. #13CriticalMonitoring and EvaluationOngoing

    Applies to: Developers and deployers of inherently dangerous AI systems.

    The Vermont AI Oversight Board will conduct regular and ad-hoc audits of registered inherently dangerous AI systems.
  14. #14ImportantCompliance ChecklistMar 1, 2026

    Applies to: Developers and deployers of inherently dangerous AI systems.

    Ensure all personnel involved in the development, deployment, and operation of inherently dangerous AI systems receive adequate training.

© Regulations.AI — created on 09-Jan-2026 using Gemini 2.5 Flash