Maryland
Maryland AI Laws and Regulation (2026)
Independently fact-checked against primary sources (last audited August 20, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 20, 2026. · 12 primary sources cited on this page. How we verify our legal content

Maryland regulates AI through multiple enacted statutes, including the AI Governance Act of 2024 (SB 818), which requires state agencies to inventory high-risk AI systems, and HB 1202, which bars employers from using a facial recognition service to create a facial template during a job interview without the applicant's signed consent. A pending bill would extend those protections to the private sector.
Maryland has emerged as one of the most active states in the country on artificial intelligence regulation. The state has enacted legislation addressing AI governance in state government, facial recognition in hiring, deepfake intimate images, and healthcare AI decision-making. Governor Wes Moore's executive order and AI Subcabinet have positioned Maryland as a leader in government AI oversight, while the legislature continues pushing ambitious consumer protection bills.
This guide covers Maryland's enacted AI laws, executive branch policies, pending legislation, and how federal developments affect the state's regulatory framework.
This article is for informational purposes only and does not constitute legal advice. AI regulation is evolving rapidly. Consult a licensed Maryland attorney for advice about your specific situation.
Enacted AI Laws in Maryland
Maryland has enacted more AI-related legislation than most states, with laws spanning government operations, employment, criminal law, and healthcare.
AI Governance Act of 2024 (SB 818)
The Artificial Intelligence Governance Act of 2024 (SB 818, Chapter 496) is Maryland's cornerstone AI governance law. Signed by Governor Moore on May 9, 2024, this law establishes a comprehensive framework for how state government agencies develop, procure, deploy, and assess AI systems.
Key Requirements:
Each unit of Maryland state government must conduct inventories of all systems that employ high-risk artificial intelligence. Agencies using high-risk AI must perform regular impact assessments as determined by the AI Subcabinet. The requirements are codified at State Finance and Procurement Article 3.5-804.
The law directs the Department of Information Technology (DoIT) to develop policies and procedures governing AI use across state government. These policies must be made publicly available on DoIT's website within 45 days of adoption. The department has since published Responsible AI Policy Implementation Guidance.
AI Subcabinet:
The law codifies the Governor's AI Subcabinet into statute, tasking it with facilitating cooperation among state agencies, overseeing policy implementation, and developing a roadmap to review the risks and opportunities of AI in state services.

Facial Recognition in Hiring (HB 1202)
Maryland was one of the earliest states to regulate AI in employment. HB 1202, enacted as Chapter 446 in 2020 and codified at Labor and Employment Article 3-717, prohibits an employer from using a facial recognition service to create a facial template of an applicant during a job interview without the applicant's signed consent.
Consent Requirements:
Before using a facial recognition service to create a facial template during an interview, an employer must obtain a signed waiver from the applicant that includes:
- The applicant's name
- The date of the interview
- A statement that the applicant consents to the use of facial recognition during the interview
- Confirmation that the applicant has read the waiver
Scope:
The statute is narrower than the phrase "AI hiring law" suggests, and the difference matters in both directions. Section 3-717 defines a "facial recognition service" as technology that analyzes facial features and is used for recognition or persistent tracking of individuals in still or video images. The prohibition is triggered only when an employer uses such a service to create a facial template during the interview.
Word choice, speaking voice, and the generation of assessment scores appear nowhere in the section. An AI interview tool that scores an applicant's vocal tone, word choice, or answer content without creating a facial template falls outside HB 1202, and no waiver is required for it under this statute. Conversely, an employer that does create a facial template needs the signed waiver even if it never scores or ranks the applicant on that basis.
Maryland, along with Illinois and New York City, is one of only three jurisdictions in the United States with laws specifically regulating AI in the hiring process.

Deepfake Intimate Images (SB 360)
Maryland Senate Bill 360 expanded the state's revenge pornography statute to cover AI-generated deepfakes, effective July 1, 2025. The bill passed unanimously in both chambers: 47-0 in the Senate on March 12, 2025, and 140-0 in the House on April 7, 2025.
Definition of Visual Representation:
The law defines "visual representation" as an unaltered image of a person or a computer-generated image, created with or without existing depictions, that is indistinguishable from the person to an ordinary observer. This encompasses both authentic imagery and AI-generated deepfake content of a sexual or intimate nature.
Criminal Penalties:
| Offense | Maximum Imprisonment | Maximum Fine |
|---|---|---|
| Distribution of nonconsensual intimate images (including deepfakes) | 2 years | $5,000 |
Civil Remedies:
SB 360 also created a civil cause of action, allowing victims to file lawsuits against individuals who distribute nonconsensual intimate imagery. This provides victims a legal avenue to seek compensation and accountability, which is particularly valuable when identifying anonymous distributors is difficult.

Healthcare AI Utilization Management
Maryland enacted legislation regulating AI in healthcare utilization management decisions, effective October 1, 2025 and codified at Insurance Article 15-10B-05.1. The section is built around keeping AI in a supporting role rather than letting it make the coverage call.
The Core Prohibition:
Subsection (d) states the rule flatly: an artificial intelligence, algorithm, or other software tool "may not deny, delay, or modify health care services." An AI tool can inform a utilization review, but the adverse decision itself has to come from a human reviewer.
Who Is Covered:
The section reaches carriers, meaning insurers, nonprofit health service plans, HMOs, and dental plan organizations, and it also reaches the pharmacy benefits managers and private review agents that conduct utilization review under contract for a carrier.
Requirements for the Tool:
When a covered entity uses AI or an algorithm in utilization review, the tool must:
- Base each determination on the enrollee's own medical history and individual clinical circumstances, not on a group dataset alone
- Not replace the health care provider's role in making the determination
- Not discriminate unfairly, and be applied fairly and equitably
- Not cause harm to the enrollee
- Be open to inspection for audit or compliance review by the Insurance Commissioner
- Have its performance, use, and outcomes reviewed and revised, if necessary, at least on a quarterly basis
- Be governed by written policies included in the entity's utilization review plan
- Not use enrollee data beyond the tool's stated purpose
Disclosure Runs to the Regulator, Not to the Public:
Maryland's AI transparency duty is a filing obligation, and readers looking for a carrier's published AI statistics on its own website will not find them. Under Insurance Article 15-10A-06, each carrier reports quarterly to the Insurance Commissioner on its adverse decisions, including whether an artificial intelligence, algorithm, or other software tool was used in making the adverse decision and the number of adverse decisions overturned after a reconsideration request. The Commissioner then compiles an annual summary report based on those filings for the Governor and the General Assembly.
Section 15-10B-05.1 itself carries no website-posting duty, no mandated third-party audit, and no penalty schedule of its own. Oversight runs through the Commissioner's audit and compliance-review authority and the Insurance Article's general enforcement provisions.
Deepfake Laws and Elections
SB 361: Election Deepfake Prohibition
Maryland introduced Senate Bill 361 in January 2025, titled "Election Law: Influence on a Voter's Voting Decision By Use of Fraud: Prohibition." The bill strengthens Maryland's election laws by prohibiting the use of deepfakes and synthetic media to fraudulently influence voters.
Key Provisions:
The bill defines fraud to include the use of "synthetic media," meaning a false image, audio recording, or video recording that has been purposely created using artificial intelligence and digital technology to mimic a real candidate's appearance, speech, or conduct.
Under SB 361, a person is prohibited from using synthetic media to influence or attempt to influence a voter's voting decision. Violations are treated as election fraud under Maryland election law.
The bill passed the Maryland Senate 42-5 on March 12, 2025, and then passed the House 129-10 on April 7, 2025, with amendments. After a conference committee resolved the differences, the Senate gave final passage 39-8 on April 7, 2025. However, Maryland's legislative tracker shows no record of the bill being presented to or signed by the Governor, and it did not become law. The R Street Institute submitted testimony opposing the bill on First Amendment grounds.
Executive Branch AI Policy
Governor Moore's Executive Order (January 2024)
On January 8, 2024, Governor Wes Moore signed Executive Order 01.01.2024.02, "Catalyzing the Responsible and Productive Use of Artificial Intelligence in Maryland State Government" (the order is no longer posted at its original URL on the redesigned governor.maryland.gov site).
Core Principles:
The executive order establishes seven guiding principles for state government AI use: fairness, equity, innovation, privacy, safety, transparency, and accountability. All state agencies must follow these principles when deploying AI technologies.
AI Subcabinet:
The order created the AI Subcabinet to develop and implement a comprehensive AI action plan, create appropriate guardrails for agencies' AI use, and promote AI knowledge and talent in state government. The subcabinet is also tasked with identifying opportunities to use AI for economic development and business recruitment.
Cybersecurity Integration:
The executive order was part of a broader technology modernization effort that also established the Maryland Cybersecurity Task Force, bringing together experts from the state's IT department, Military Department, and Department of Emergency Management.
AI Advisory and Oversight Commission (SB 1087)
The Maryland AI Advisory and Oversight Commission was established through SB 1087 in 2024. The commission includes members from the state legislature, private AI sector, and State Board of Education.
The commission is required to report findings and recommendations to the Governor and General Assembly annually, beginning December 1, 2024. Its mandate includes guiding the state in growing and diversifying AI, ensuring diversity in AI-related contract awards and training programs, and assisting diverse groups in AI adoption.
Maryland Public Schools AI Policy
The Maryland State Department of Education issued a Responsible Use of Artificial Intelligence Tools policy governing AI use in K-12 education across the state.
Pending AI Legislation

Preventing Algorithmic Discrimination Act (HB 1331 / SB 936, Died in Committee)
The most closely watched AI bill in Maryland's 2025 session was the Preventing Algorithmic Discrimination Act, introduced as both HB 1331 and its Senate companion SB 936. Both bills received only an initial committee hearing (HB 1331 on March 4, 2025; SB 936 on February 27, 2025) and died in committee without a floor vote when the 2025 session ended.
Developer Obligations:
Developers of high-risk AI systems must use reasonable care to protect consumers from known and reasonably foreseeable risks of algorithmic discrimination.
Deployer Requirements (as proposed):
As introduced, the bill would have required that by January 1, 2027, deployers must:
- Create risk management policies for AI systems
- Conduct annual impact assessments for automated decision tools
- Notify consumers when a high-risk AI system is used to make consequential decisions about them
- Provide robust disclosure about how and why the AI system is used
Consumer Rights:
The bill gives consumers the right to correct incorrect personal data used in AI decisions and the right to appeal adverse AI-driven decisions.
Definition of Algorithmic Discrimination:
The bill defines algorithmic discrimination as differential treatment based on protected characteristics. Privacy advocates have noted that the original definition was missing sexual orientation and gender identity, which are covered by the Maryland Online Data Privacy Act.
Industry Opposition:
Business groups have opposed the bill, arguing that mandatory assessments are time-consuming and expensive for the software development industry.
AI Working Group
The Maryland Legislature passed an AI working group bill after incorporating civil society feedback. This workgroup is tasked with drafting recommendations to protect consumers from AI-related harms in areas such as employment, housing, and insurance.
Federal AI Policy Impact on Maryland
TAKE IT DOWN Act
The federal TAKE IT DOWN Act (P.L. 119-12) complements Maryland's SB 360 by providing federal criminal penalties for nonconsensual intimate deepfakes. While Maryland's law provides both criminal penalties and civil remedies at the state level, the federal law creates an additional layer of enforcement and requires platforms to remove reported content within 48 hours.
Federal Preemption Risks
President Trump's Executive Order 14365 (December 2025) poses potential challenges to Maryland's ambitious AI regulatory agenda. The order directs the DOJ to identify state AI laws that could be challenged on preemption grounds. Maryland's Preventing Algorithmic Discrimination Act, if enacted, could face federal scrutiny as a state-level regulation of AI development and deployment.
However, Maryland's existing laws, particularly those governing state government operations (SB 818) and criminal conduct (SB 360), operate in areas traditionally reserved to state authority and are less vulnerable to preemption challenges.
NIST Alignment
Maryland's AI Governance Act explicitly references federal AI standards. The Department of Information Technology's Responsible AI Policy Implementation Guidance aligns with the NIST AI Risk Management Framework, positioning Maryland's approach as complementary to, rather than conflicting with, federal standards.
Looking Ahead
Maryland is positioned to become one of the leading states in AI regulation. The Preventing Algorithmic Discrimination Act died in committee in the 2025 session without a vote; if a similar bill is reintroduced and enacted, it would place Maryland alongside Colorado and Illinois in requiring comprehensive risk assessments and anti-discrimination protections for AI systems.
The state's AI Advisory Commission continues to develop recommendations, and the legislative working group on AI consumer protection is expected to inform 2026 session bills. With strong executive branch support through Governor Moore's executive order and AI Subcabinet, Maryland's regulatory infrastructure is more developed than most states.
This article is for informational purposes only and does not constitute legal advice. AI regulation is evolving rapidly, and new legislation may be enacted after this article was last reviewed. Consult a licensed Maryland attorney for advice about your specific situation. Last reviewed: March 2026.
More Maryland Laws
Frequently Asked Questions
Does Maryland have a comprehensive AI law?
Maryland has one of the most extensive AI regulatory frameworks in the country, though it is spread across multiple statutes rather than a single comprehensive law. The AI Governance Act of 2024 (SB 818) governs state government AI use, HB 1202 regulates facial recognition in hiring, SB 360 criminalizes deepfake intimate images, and healthcare AI utilization management is regulated effective October 2025. The Preventing Algorithmic Discrimination Act (HB 1331 / SB 936) died in committee without a vote in the 2025 session; if a similar bill is reintroduced and enacted, it would add comprehensive private-sector AI regulation.
Can Maryland employers use AI and facial recognition in job interviews?
Yes, but a facial recognition service that creates a facial template requires the applicant's signed consent. Under HB 1202, codified at Labor and Employment Article 3-717 and effective October 1, 2020, an employer may not use a facial recognition service to create a facial template of an applicant during an interview unless the applicant signs a waiver stating the applicant's name, the date of the interview, that the applicant consents to the use of facial recognition during the interview, and that the applicant has read the waiver. The statute defines a facial recognition service as technology that analyzes facial features for recognition or persistent tracking, so an AI interview tool that scores word choice or speaking voice without creating a facial template is not covered by this section.
What are the penalties for distributing AI-generated intimate images in Maryland?
Under SB 360 (effective July 1, 2025), distributing nonconsensual AI-generated intimate images is punishable by up to 2 years imprisonment and a $5,000 fine. The law also allows victims to file civil lawsuits to seek compensation. The statute covers any computer-generated image that is indistinguishable from the real person to an ordinary observer.
How does Maryland regulate AI in healthcare decisions?
Effective October 1, 2025, Insurance Article 15-10B-05.1 requires carriers and the pharmacy benefits managers and private review agents that conduct utilization review for them to base AI-assisted determinations on the enrollee's own medical history and clinical circumstances rather than a group dataset alone. Subsection (d) goes further: an artificial intelligence, algorithm, or other software tool may not deny, delay, or modify health care services, so the adverse decision itself must come from a human. The tool must also be open to audit by the Insurance Commissioner and reviewed at least quarterly. Separately, Insurance Article 15-10A-06 requires each carrier to report quarterly to the Commissioner on adverse decisions, whether AI was used in making them, and how many were overturned on reconsideration, and the Commissioner compiles an annual summary for the Governor and General Assembly. Carriers are not required to post that data on their own websites.
What is Maryland's Preventing Algorithmic Discrimination Act?
The Preventing Algorithmic Discrimination Act (HB 1331 / SB 936) died in committee without a floor vote in the 2025 session. As introduced, it would have required developers and deployers of high-risk AI systems to use reasonable care to prevent algorithmic discrimination, with deployers needing to conduct annual impact assessments, notify consumers when AI makes consequential decisions about them, and allow consumers to correct personal data and appeal adverse decisions by January 1, 2027.
Updates
Corrected the healthcare AI section against the codified statute: Maryland law flatly bars an AI tool from denying, delaying, or modifying health care services, and carriers report AI use in adverse decisions quarterly to the Insurance Commissioner rather than posting audits, overturn rates, or misdiagnosis rates on their websites; also narrowed the HB 1202 description to its actual trigger, creating a facial template during an interview.
Corrected the page to reflect that Maryland's Preventing Algorithmic Discrimination Act (HB 1331/SB 936) died in committee in 2025 rather than being pending, clarified that the election-deepfake bill SB 361 passed both chambers but was never signed into law, and removed a dead executive-order citation link.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Maryland Code, State Finance and Procurement Article
§ 3.5-804In force
§3.5–804. (a) On or before December 1, 2024, the Department, in consultation with the Governor’s Artificial Intelligence Subcabinet, shall adopt policies and procedures concerning the development, procurement, deployment, use, and ongoing assessment of systems that employ high–risk artificial intelligence by a unit of State government. (b) The policies and procedures required by subsection (a) of this section shall: (1) subject to any other applicable law, govern the procurement, deployment, and ongoing assessment of systems that employ high–risk artificial intelligence by a unit of State government; (2) define the criteria for an inventory of systems that employ high–risk artificial intelligence; (3) be sufficient to ensure that the use of any system that employs artificial intelligence by a unit of State government is governed by adequate guardrails to protect individuals and communities; (4) if the Department is notified that an individual or group of individuals may have been negatively impacted by a system that employs high–risk artificial intelligence, require the Department to: (i) notify an individual or a group of individuals determined to have been negatively…
Official text (excerpt) · last checked 2026-09-03 · Read the full text in our law library · Verify at mgaleg.maryland.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Maryland AI Governance Act (SB 818)(mgaleg.maryland.gov).gov
- SB 818 Fiscal Note(mgaleg.maryland.gov).gov
- Maryland DoIT AI Policy Guidance(doit.maryland.gov).gov
- HB 1202 - Facial Recognition in Hiring(mgaleg.maryland.gov).gov
- HB 1202 Chapter 446 Enrolled(mgaleg.maryland.gov).gov
- SB 1087 - AI Advisory Commission(mgaleg.maryland.gov).gov
- HB 1331 - Algorithmic Discrimination Act(mgaleg.maryland.gov).gov
- Healthcare AI Utilization Law Analysis(alston.com)
- Maryland Public Schools AI Policy(marylandpublicschools.org).gov
- TAKE IT DOWN Act(congress.gov).gov
- SB 360 Deepfake Law(mgaleg.maryland.gov).gov
- SB 360 - Deepfake Intimate Images (2025)(southernmarylandchronicle.com)
- SB 936 (2025) - Official Bill Status (Died in Committee)(mgaleg.maryland.gov).gov
- SB 361 (2025) - Official Bill Status (Passed Legislature, No Governor Action)(mgaleg.maryland.gov).gov
- Md. Insurance Article 15-10B-05.1 - Artificial Intelligence in Utilization Review(mgaleg.maryland.gov)
- Md. Insurance Article 15-10A-06 - Carrier Quarterly Reports to the Commissioner(mgaleg.maryland.gov)
- Md. Labor and Employment Article 3-717 - Facial Recognition Services in Interviews(mgaleg.maryland.gov)
- Md. State Finance and Procurement Article 3.5-804 - High-Risk AI Inventory and Assessment(mgaleg.maryland.gov)