Law / United States / Montana

Right to Compute Act (SB 212, 2025), critical AI infrastructure risk management duty

Mont. Code Ann. 2-10-205

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force.

An AI risk obligations rule binding private bodies.

As of 6 September 2026.

What it requires

  • If a deployer of a critical artificial intelligence system controls, in whole or in part, a critical infrastructure facility, develop a risk management policy after deploying the system
  • The policy must be reasonable and consider a nationally or internationally recognized AI risk management framework, such as the NIST AI risk management framework
  • A risk management plan already prepared to satisfy a federal requirement counts as compliance

If you get it wrong

Criminal exposureNo

Private right of actionNo

What it reaches

Obligation class

Governance

What it makes you log

Logging duty

Section 2-10-205 requires a deployer whose critical artificial intelligence system controls a critical infrastructure facility to develop, after deploying the system, a risk management policy that considers a recognized artificial intelligence risk management framework. The section never uses the words logs, records, or audit trail, but a policy that must be developed and shown to consider a named framework cannot be demonstrated without documenting it. The section states no period the policy must be kept for and names nobody who may demand to see it; a plan already prepared to meet a federal requirement satisfies the duty on the same terms.

Kind
Implicit
As of
21 September 2026
Provision
Mont. Code Ann. 2-10-205
Trigger
high_risk_systems

Who checks it

Audit expectation

none

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Right to Compute Act declares that the rights to acquire, possess, and protect property and the freedom of expression under the Montana Constitution embody a fundamental right to own and make use of computational resources, including artificial intelligence systems, and that a government action restricting that use must be limited to what is demonstrably necessary and narrowly tailored to a compelling government interest.

The Act's one affirmative duty on a private actor falls on a deployer, an individual, company, or other organization that utilizes an artificial intelligence system. That duty applies when the deployer's system is a critical artificial intelligence system, one designed and deployed to make or be a substantial factor in making a consequential decision, and that system controls a critical infrastructure facility in whole or in part.

That deployer must develop, after deploying the system, a risk management policy that considers the National Institute of Standards and Technology's AI risk management framework, the ISO/IEC 4200 artificial intelligence standard, or another nationally or internationally recognized framework, and a plan already prepared to meet a federal requirement satisfies this duty. The Act preserves existing intellectual property remedies. It states that nothing in it preempts federal law.

It took effect on passage and approval under its own effective-date clause, though the enrolled act text does not print the specific day of approval.

When LexLint raises it

  • high_risk_decisions
  • operates_essential_service

Read the law

official enrolled act text, Montana Legislature

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app