Enacted Law Verified June 17, 2026

North Carolina AI Legislation in 2026

North Carolina has enacted deepfake criminal penalties and has synthetic media and healthcare AI bills in committee.

3 Tracked bills
3 Enacted

The North Carolina Picture

North Carolina has chosen governance over regulation. Rather than enact a sweeping AI statute on the model of Colorado or the EU, the state has built its AI posture through executive action and agency guidance that bind state government itself, not private builders. Executive Order No. 24, signed by Governor Stein in September 2025, is the centerpiece. It stands up an AI Leadership Council, an AI Accelerator inside the Department of Information Technology, and agency oversight teams that must route every proposed AI use case through a central risk review. Paired with the 2024 Responsible Use framework, this creates a real compliance regime, but one aimed squarely inward at how the state procures and deploys AI. If you sell AI to North Carolina agencies, this is the gate you pass through. If you sell to private parties, the order does not reach you.

Where North Carolina has actually legislated, it has done so through the criminal code, not a technology statute. Session Law 2024-37, effective December 1, 2024, is the law that matters for builders touching image and likeness generation. It folded AI-generated and AI-modified content into the state's definition of exploitative material, created a new offense for obscene visual representations of minors that applies even when no real child exists, and expanded the nonconsensual private images statute to cover realistic deepfakes of identifiable adults. This is a deliberate, surgical approach. North Carolina chose to criminalize the most acute harms, synthetic CSAM and deepfake intimate imagery, while leaving bias, transparency, and high-risk automated decisions to future sessions.

I want to be precise about what is and is not law, because the gap is wide. Across the 2025-2026 session the General Assembly introduced bills on deepfakes, data privacy, algorithmic rent fixing, AI in healthcare insurance decisions, AI in schools, content authentication, robocalls, and developer safety requirements. None of them passed. There is no enacted election-deepfake statute, no enacted political-ad AI disclosure mandate, and no enacted general AI consumer-protection law in North Carolina as of June 2026. Anyone who tells you otherwise is conflating introduced bills with enacted law.

For builders, the practical guidance is straightforward. First, if you generate synthetic imagery of people, treat Session Law 2024-37 as a hard line: AI-generated CSAM and nonconsensual intimate deepfakes are criminal regardless of whether a real person was depicted. Build detection, provenance, and abuse-reporting accordingly. Second, if you contract with North Carolina state agencies, expect to be assessed against the framework's seven principles and reviewed by an agency oversight team and the AI Accelerator. Third, watch the General Assembly closely, because the volume of failed 2025 bills signals that broader private-sector AI rules are a question of when, not whether.

Tracked North Carolina AI Bills

Trustworthy AI in State Government

Governance

Signed by Governor Stein on September 2, 2025. Creates the AI Leadership Council, an AI Accelerator within the Department of Information Technology, and agency oversight teams that route AI use cases through central risk review. Applies to state government.

Effective: September 2, 2025

Key Provisions

  • AI Leadership Council and AI Accelerator
  • Agency AI oversight teams and use-case review
  • Public AI literacy and fraud-prevention training

AI-Generated CSAM and Deepfakes

CSAMDeepfakesCrime

Enacted 2024, effective December 1, 2024. Folds AI-generated content into exploitative-material law, creates an offense for obscene depictions of minors even where no real child exists, and extends the private-images statute to realistic deepfakes of adults.

Effective: December 1, 2024

Key Provisions

  • AI-generated content within exploitative-material definition
  • Offense reaches entirely AI-generated CSAM
  • Covers nonconsensual deepfakes of identifiable adults

Responsible Use of AI Framework

Governance

Published August 2024. Seven principles and practices for responsible state AI use in development, procurement, and deployment. Binds executive-branch agencies; guidance, not statute.

Effective: August 2024

Key Provisions

  • Seven responsible-AI principles for state agencies
  • Guidance on development, procurement, deployment
  • Restriction on confidential data in public AI tools

Download The AI Law Brief of All 50 States

A formatted PDF covering every tracked AI bill across all 50 states, with status, effective dates, and key provisions. Useful for compliance teams and board packs.

* You will also be subscribed to my newsletter.

Other states

← All 50 states and the full report