Enacted Law Verified June 17, 2026

Maryland AI Legislation in 2026

Maryland passed four AI-related bills in 2026 covering surveillance pricing, deepfake protection, AI in schools, and deepfakes in political campaigns. All four are awaiting governor signature.

6 Tracked bills
3 Enacted

The Maryland Picture

Maryland has not enacted a comprehensive, cross-sector private-sector AI law of the kind seen in Colorado. What Maryland has built instead is a two-track model that is distinctive and, for executives, consequential. The first track is government-facing AI governance. Through Executive Order 01.01.2024.02 and the Artificial Intelligence Governance Act of 2024 (SB 818), Maryland requires its own agencies to inventory high-risk AI, run impact assessments, and operate under policies overseen by a Governor's AI Subcabinet. This binds state procurement and deployment directly. Any vendor selling AI systems to Maryland agencies should expect inventory disclosure, impact-assessment cooperation, and the possibility that a deployment is barred under the Act's prohibitions.

The second and more commercially significant track runs through privacy law rather than a standalone AI statute. The Maryland Online Data Privacy Act, effective October 1, 2025 with penalty enforcement phasing in from April 1, 2026, is where most businesses will feel AI regulation in practice. MODPA gives consumers the right to opt out of profiling that drives legally or similarly significant decisions, requires documented data protection assessments for profiling and sensitive-data processing, and conditions automated decision-making on transparency, necessity, and the ability of affected consumers to contest outcomes or obtain human review. Maryland also pairs unusually strict data-minimization and sensitive-data rules with these provisions, which is why it is frequently described as one of the strongest state privacy laws in the country. For builders, MODPA is effectively Maryland's de facto AI accountability regime for consumer-facing systems.

Beyond these enacted laws, Maryland is in a study-and-iterate posture. The 2025 session produced HB 956, which stood up a Workgroup on AI Implementation with a deliberately broad civil-society and labor membership and a report due July 1, 2026. I read that report deadline as the most important near-term signal for what comprehensive Maryland AI legislation may look like in the 2027 session. The 2025 session also moved sector-specific measures, notably HB 820 on AI in health-insurance utilization review, while broader developer-duty proposals such as HB 823 on generative AI training-data transparency failed to advance. The pattern is clear. Maryland is regulating AI narrowly by sector and through privacy, not through a single omnibus AI act.

For builders and businesses, my guidance is concrete. If you process Maryland residents' personal data, treat MODPA as your binding AI obligation now: map profiling and automated decisions, build opt-out and human-review mechanisms, and complete and retain data protection assessments, because penalty enforcement is live as of April 2026. If you sell to Maryland government, prepare for inventory and impact-assessment scrutiny under the Governance Act. If you operate chatbots, companion or behavioral-health AI, or use AI in elections, watch the 2026 session bills, including the HB 952 chatbot disclosure measure, and the HB 956 workgroup output, treating disclosure and human-oversight features as the likely direction of travel even before any of these mandates are final.

Tracked Maryland AI Bills

Artificial Intelligence Governance Act of 2024

Governance

Signed May 9, 2024. Requires state agencies to inventory high-risk AI, run impact assessments, and follow Department of Information Technology policies overseen by the Governor's AI Subcabinet. First inventory obligations began December 1, 2024.

Effective: December 1, 2024

Key Provisions

  • Inventory of high-risk state-agency AI systems
  • Regular impact assessments for high-risk AI
  • Department of Information Technology AI policies
  • Limits on certain state AI deployments

Maryland Online Data Privacy Act

PrivacyConsumer Protection

Signed May 9, 2024, effective October 1, 2025 with penalty enforcement from April 1, 2026. Grants profiling opt-out and human-review rights, requires data protection assessments, and is among the strictest US state privacy laws on data minimization.

Effective: October 1, 2025

Key Provisions

  • Opt-out of profiling in significant decisions
  • Data protection assessments for profiling and sensitive data
  • Right to contest automated decisions or seek human review
  • Strict data-minimization and sensitive-data limits

Workgroup on Artificial Intelligence Implementation

Governance

Signed April 22, 2025, effective July 1, 2025, sunsets June 30, 2029. Establishes a workgroup to study AI regulation focused on decisions affecting livelihoods, with a report due July 1, 2026.

Effective: July 1, 2025

Key Provisions

  • Studies developer and deployer obligations
  • Broad civil-society and labor membership
  • Report to legislative committees due July 1, 2026
HB 820 Passed Both Chambers

Health Insurance Utilization Review and AI

Healthcare

2025 session measure regulating carrier, PBM, and private review agent use of AI in utilization review, requiring AI tools used for coverage decisions to meet specified standards.

Key Provisions

  • Standards for AI used in utilization review
  • Targets AI-driven coverage and prior-authorization decisions
SB 361 Passed Both Chambers

Election Synthetic Media Prohibition

DeepfakesElections

Passed both chambers in 2025. Defines election fraud to include AI-generated synthetic media mimicking a candidate and prohibits its use to influence a voter, with carveouts for news, satire, and parody.

Key Provisions

  • Synthetic media added to election fraud definition
  • Prohibits deceptive synthetic media influencing voters
  • Exemptions for news, satire, and parody
HB 952 In Committee

AI Companion Chatbot Disclosures

ChatbotsConsumer Protection

Passed the House 123-4 in the 2026 session and advanced to the Senate; final passage not confirmed as of June 2026. Would require persistent and dynamic chatbot warnings and a complaint review process.

Key Provisions

  • Persistent on-screen and pop-up AI warnings
  • Disclosures at start, hourly, and on request
  • Complaint review-and-response requirement

Download The AI Law Brief of All 50 States

A formatted PDF covering every tracked AI bill across all 50 states, with status, effective dates, and key provisions. Useful for compliance teams and board packs.

* You will also be subscribed to my newsletter.

Other states

← All 50 states and the full report