Virginia's New AI Regulations and What You Need to Know and How to Comply
On February 20, 2025, Virginia passed the High-Risk Artificial Intelligence Developer and Deployer Act (HB 2094). If signed into law by Governor Glenn Youngkin, Virginia will become the second state, after Colorado, to enact comprehensive regulations aimed at governing the use of AI, particularly in high-risk applications. These new rules will have significant implications for businesses that develop or deploy AI systems that impact Virginia residents. Here’s what you need to know about this legislation and how your business can stay ahead of the curve.
The Virginia AI Act focuses on AI systems that are deemed "high-risk," those that have the potential to autonomously make or heavily influence important decisions affecting individuals. These decisions include areas like parole, probation, education, housing, employment, healthcare, and even marital status. The law specifically targets AI systems that are the primary basis for making such consequential decisions without meaningful human oversight.
Importantly, the law does not apply to AI systems used for narrow procedural tasks, like fraud detection, or systems that merely assist in decision-making but don't directly drive significant outcomes. It also excludes certain technologies, such as AI in cybersecurity or video games.
The Virginia AI Act will apply to both developers and deployers of high-risk AI systems. A “developer” is anyone who creates or substantially modifies an AI system that is used in Virginia, while a “deployer” refers to businesses that actually use or deploy these systems. The law is designed to protect Virginia residents in their personal or household contexts, rather than in commercial or employment-related scenarios.
This means that companies developing or deploying AI systems for decisions like loan approvals, medical treatment, or education opportunities may need to pay attention. If your business falls into this category, it’s important to understand how these regulations could impact your operations.
Both developers and deployers of high-risk AI systems face specific responsibilities under the Virginia AI Act. Developers must take proactive steps to manage the risks of algorithmic discrimination. This includes documenting the limitations of the AI system, being transparent about its performance, and ensuring that it complies with industry standards for transparency, especially when generating synthetic content (like AI-created text, images, or videos).
Deployers, on the other hand, must establish a risk management policy, conduct impact assessments before deploying any high-risk AI systems (and after significant updates), and provide clear disclosures to consumers about the use of AI. Additionally, they must offer mechanisms for consumers to appeal or correct decisions made by AI systems, ensuring that individuals have avenues for redress if they are adversely impacted by an AI-driven decision.
While the Virginia AI Act covers a broad swath of AI applications, there are some important exemptions. For example, the law does not apply to federal agencies, certain financial institutions, healthcare entities, or insurers. Businesses in these sectors should carefully review the criteria to determine whether they are exempt.
Enforcement of the law will be handled by the Virginia Attorney General, with penalties for non-compliance ranging from $1,000 per violation to up to $10,000 for willful violations. Businesses will have a 45-day window to cure violations once notified, offering some flexibility in how quickly they must act to address compliance issues.
How to Prepare for the Virginia AI Act.
If your business develops or deploys high-risk AI systems in Virginia, now is the time to take action. Here are a few key steps you can take to ensure compliance if the Governor signs and for when the law goes into effect in 2026:
-
Assess Your AI Systems. Review all AI systems your business uses to determine if they fall within the scope of the Virginia AI Act. Pay special attention to applications that make decisions related to housing, employment, healthcare, and other high-risk areas.
-
Update Your Governance Frameworks. If your AI systems are deemed high-risk, ensure that your internal governance structures and risk management processes are in line with the new regulations. This might involve creating or updating documentation regarding the limitations, risks, and uses of your AI systems.
-
Develop Impact Assessment Procedures. Before deploying high-risk AI, you’ll need to conduct an impact assessment. Work with your legal and compliance teams to develop procedures for this assessment and to ensure transparency with consumers.
-
Implement Consumer Protections. The law requires you to offer consumers the ability to appeal decisions made by AI systems. Be sure that these mechanisms are in place, and that clear disclosures are provided about when AI is used in decision-making.
-
Monitor Exemptions. If your business operates in an exempt sector, be sure to document your eligibility for these exemptions. Regularly review your AI systems to ensure they continue to meet the exemption criteria.
Looking Ahead
The passage of the Virginia AI Act signals the growing of AI regulation at the state level. As businesses across the country begin to grapple with these new laws, it’s essential to stay informed about developments both in Virginia and other states that may introduce similar regulations. Preparing for the Virginia AI Act now will not only ensure compliance but also set your business up for success in an evolving regulatory landscape.
© 2025 Cliclaw.com
(Image Credit: iStock Photo)
This article is for information purposes only. It is not intended to be and should not be relied on as legal advice for any particular matter.