Law / United States / Alabama

Alabama

United States law applies in Alabama Alabama is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Alabama, described on this page below, applies here too.

All 12 named instruments researched to a stage, across five of the six areas of law we track: 5 in force and 7 enacted but not yet in force. As of 15 September 2026.

When they take effect11 of 12 carry a date, 1 does not. Earlier is before 2015.
Before 2015: 1 instrument (1 in force) earlier 2015: 0 instruments 2016: 0 instruments 2017: 0 instruments 2018: 1 instrument (1 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 3 instruments (3 in force) 2025: 0 instruments ’25 2026: 1 instrument (1 enacted but not yet in force) 2027: 5 instruments (5 enacted but not yet in force) ’27 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 3
  2. Privacy law 5
  3. Scraping law 1
  4. Cybersecurity law 1
  5. Age gating law 2
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law3 instruments, 2 in force, 1 enacted but not yet in force

Research summary (498 words)

Alabama's AI-content transparency duty remains its election deepfake law, Ala. Code section 17-5-16.1, in force since October 1, 2024: distributing AI-produced materially deceptive media of a candidate within 90 days of an election is unlawful unless the distributor carries a clear and conspicuous disclaimer, so the operative duty is a labeling and disclosure one rather than an outright ban.

The Alabama Child Protection Act of 2024 (Act 2024-98, HB 168) amended Ala. Code sections 13A-12-190, 13A-12-191, 13A-12-192, 13A-12-193, 13A-12-194, 13A-12-196, 13A-12-197, and 13A-12-198, and repealed section 13A-12-195, so that the definition of child sexual abuse material expressly reaches a virtually indistinguishable depiction created, altered, or produced by digital, computer-generated, or other means: dissemination, public display, advertising, and soliciting such material are each a Class B felony; possession with intent to disseminate is a Class B felony and simple possession a Class C felony; and production, or a parent's or guardian's knowing permission of a minor's use in production, are each a Class A felony, all effective October 1, 2024.

That statute is a content prohibition rather than a transparency or labeling duty, but because it binds any person's production, dissemination, or possession of an AI-generated or AI-indistinguishable depiction, it is catalogued here as an AI prohibited-practices instrument.

Senate Bill 63 (2026), effective October 1, 2026, bars a health benefit plan provider from letting artificial intelligence alone decide a prior-authorization request: an AI-assisted determination must rest on the enrollee's own medical history and clinical circumstances rather than a group dataset, a licensed physician or other qualified clinician must make the final call on any adverse determination, and the provider must certify annually to the Department of Insurance that its artificial intelligence does not discriminate against any subscriber group; enforcement is administrative, by the Department of Insurance, with a fine of up to $5,000 for a violation occurring with the frequency of a general business pattern or practice; at its effective date the act had not yet been assigned a Code of Alabama section, so this instrument cites the enacted act directly.

Alabama's comprehensive privacy statute, the Alabama Personal Data Protection Act (HB 351, 2026), separately includes a right to opt out of profiling used for solely automated significant decisions; because that duty attaches to personal data rather than to an AI system as such, it remains a privacy-topic instrument, recorded there and not here.

Three AI-related bills died at sine die on April 9, 2026, without floor votes and are not catalogued as instruments: House Bill 324 would have required AI chatbot operators to verify users' ages, adopt harmful-output safeguards, and meet heightened rules for a chatbot acting as a therapy or mental-health companion; House Bill 325 would have made an AI chatbot operator's failure to disclose that a user is talking to a bot an unfair or deceptive trade practice; and Senate Bill 129 would have required disclosure of AI-generated content.

No other 2025 or 2026 Alabama enactment imposing an AI-transparency, output-labeling, prohibited-practice, or AI-system-governance duty was located.

AI prohibited practices

Alabama Child Protection Act of 2024, AI-Generated Child Sexual Abuse Material

Ala. Code §§ 13A-12-190 to 13A-12-197 (as amended by Act 2024-98, HB 168, 2024 Regular Session)official text, enrolled Act 2024-98 (HB 168, 2024 Regular Session), Alabama Legislature

In force since 1 October 2024. Binds public and private bodies.

What this law does

The Alabama Child Protection Act of 2024 amended Alabama Code sections 13A-12-190, 13A-12-191, 13A-12-192, 13A-12-193, 13A-12-194, 13A-12-196, 13A-12-197, and 13A-12-198, and repealed section 13A-12-195, so that the definition of child sexual abuse material expressly includes a virtually indistinguishable depiction created, altered, or produced by digital, computer generated, or other means.

A person who knowingly disseminates or publicly displays child sexual abuse material is guilty of a Class B felony, as is a person who knowingly advertises, promotes, presents, distributes, or solicits by any means material that reflects, or is intended to cause another to believe, depicts an actual individual under 18 engaged in sexually explicit conduct.

A person who knowingly possesses child sexual abuse material with intent to disseminate it is guilty of a Class B felony, and simple possession is a Class C felony. A parent or guardian who knowingly permits or allows a child, ward, or dependent under 18 to be used in producing child sexual abuse material is guilty of a Class A felony, as is a person who knowingly produces the material.

An individual who commits any of these offenses, or the related private-image offense at section 13A-6-240, is civilly liable to the individual depicted, with actual damages, costs and attorney fees, and punitive damages available on clear and convincing evidence of wantonness or malice.

No civil action may be brought for actions taken to prevent, detect, protect against, report, or respond to the production, generation, incorporation, or synthesization of child sexual abuse material through artificial intelligence. The amendments took effect October 1, 2024.

What it requires

AI sector rules

SB 63 (2026), Artificial Intelligence in Health Insurance Prior Authorization

Ala. SB 63, 2026 Regular Sessionofficial text, enrolled SB 63 (2026 Regular Session), Alabama Legislature

In force in 8 days, effective 1 October 2026. Binds private bodies.

What this law does

A health benefit plan provider that uses artificial intelligence to determine medical necessity for a request for prior authorization must base the determination on the enrollee's own medical history, the clinical circumstances the treating health care provider presents, and other clinical information in the enrollee's medical record.

The provider must certify annually to the Alabama Department of Insurance that the artificial intelligence does not rely on a group dataset, is applied fairly and equitably consistent with applicable federal guidance, and does not discriminate against any subscriber group or enrollee.

A determination to deny, delay, or modify a prior-authorization request based on medical necessity must always be made by a licensed physician or other health care professional competent to evaluate the artificial intelligence's recommendation in light of the enrollee's own clinical circumstances.

The provider must make prominent written disclosure of its use of artificial intelligence in utilization review in its policies and procedures, periodically review the outcomes for accuracy, and keep patient data used in that review within its intended purpose under Health Insurance Portability and Accountability Act (HIPAA).

The Department of Insurance may investigate an alleged violation and order corrective changes to the provider's procedures, and for a violation occurring with the frequency of a general business pattern or practice, may impose an administrative fine of up to $5,000 or suspend or revoke the provider's certificate of authority. This act becomes effective October 1, 2026.

What it requires

AI transparency

Distribution of Materially Deceptive Media to Influence an Upcoming Election

Ala. Code § 17-5-16.1official text, Code of Alabama (alison.legislature.state.al.us)

In force since 1 October 2024. Binds public and private bodies.

What this law does

A person may not knowingly distribute, or agree with another to distribute, materially deceptive media, defined as an image, audio, or video produced by artificial intelligence that falsely depicts a candidate engaging in speech or conduct that did not occur, within 90 days of an election, where the distribution intends to harm the candidate's reputation or electoral prospects or to change how electors vote.

The duty is a disclosure one: a distributor avoids the prohibition entirely by including a specified clear and conspicuous disclaimer that the media has been manipulated by technical means, with format-specific rules for video, audio, and still images. A violation is a Class A misdemeanor, rising to a Class D felony on a second or subsequent conviction within five years.

The Attorney General, the depicted individual, an injured or threatened candidate, or an entity representing voters may also seek permanent injunctive relief, with fee-shifting against a frivolous complaint. The codified section attributes the enactment to Act 2024-349, sections 1 to 3, which is the citation used here.

What it requires

Privacy law5 instruments, 5 enacted but not yet in force

Research summary (192 words)

Alabama enacted a comprehensive consumer privacy statute in 2026, the Alabama Personal Data Protection Act (APDPA, HB 351), but it is not yet in force: its effective date is May 1, 2027, so every APDPA duty below is recorded as enacted rather than in force, as of the date shown.

Once effective, the Act will require a controller's consent before processing sensitive data, including genetic or biometric data processed to uniquely identify a person, will give Alabama consumers rights to access, correct, delete, and port their data and opt out of targeted advertising, sale, and certain automated profiling, and will vest exclusive enforcement in the Attorney General with a mandatory 45-day cure period and no private right of action.

Separately, and already in force, the Alabama Data Breach Notification Act of 2018 requires notice to the Attorney General of a breach of sensitive personally identifying information likely to cause substantial harm; that Act's codified text is not verified directly, because Justia serves a CAPTCHA challenge and FindLaw does not carry this chapter of the Alabama Code, so its penalty amount and private-right-of-action posture are left unstated rather than repeated from commentary alone.

Breach notification

Alabama Data Breach Notification Act of 2018

Ala. Code sec. 8-38-1 et seq. (Act 2018-396)official Alabama Attorney General's Office summary page

Commencement not set. Binds private bodies.

What this law does

The Alabama Data Breach Notification Act of 2018 requires certain entities that experience a data breach to notify the Alabama Attorney General when the breach results in unauthorized acquisition of sensitive personally identifying information and is reasonably likely to cause substantial harm to the affected individuals.

The codified text of Ala. Code section 8-38-1 et seq. is not verified directly: Justia serves a Cloudflare CAPTCHA challenge on every attempt, and FindLaw's Alabama coverage does not carry Title 8, Chapter 38.

The Act's specific notification deadline, civil penalty amount, and private-right-of-action posture are therefore not stated here as verified findings; secondary commentary describes a civil penalty of up to $5,000 per day capped at $500,000 per breach and no private right of action, but that has not been confirmed against the codified text.

What it requires

Comprehensive regime

Alabama Personal Data Protection Act (HB 351), general applicability and scope

Ala. HB 351, 2026 Regular Session, Secs. 1-4enrolled bill text, Alabama Legislative Information System (ALISON)

In force in 220 days, effective 1 May 2027. Binds private bodies.

What this law does

APDPA will govern private-sector processing of Alabama consumers' personal data once it takes effect on May 1, 2027. It applies to a person conducting business in Alabama, or targeting products or services to Alabama residents, who controls or processes personal data of 25,000 or more Alabama consumers, excluding payment-transaction-only data, or derives more than 25% of gross revenue from selling personal data.

Broad entity- and data-level exemptions apply, including government bodies, higher-education institutions, Gramm-Leach-Bliley Act (GLBA)- and Health Insurance Portability and Accountability Act (HIPAA)-regulated entities, small nonprofits and businesses under the applicability threshold, political committees, and employment or business-to-business data. 'Personal data' excludes deidentified data and publicly available information.

What it requires

Data subject rights

Alabama Personal Data Protection Act (HB 351), consumer rights

Ala. HB 351, 2026 Regular Session, Secs. 5-6enrolled bill text, Alabama Legislative Information System (ALISON)

In force in 220 days, effective 1 May 2027. Binds private bodies.

What this law does

Once in force, APDPA will give an Alabama consumer the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling in furtherance of a solely automated decision with a legal or similarly significant effect.

A controller must respond within 45 days of receipt, with one 45-day extension available when reasonably necessary, free of charge once per 12-month period; a controller may charge a reasonable fee or decline a manifestly unfounded, excessive, technically infeasible, or repetitive request, with the burden on the controller to show that. The Act provides no separate appeal-of-refusal mechanism.

A parent or guardian may exercise a known child's rights, and a guardian or conservator may exercise an incapacitated consumer's rights.

What it requires

Enforcement supervision

Alabama Personal Data Protection Act (HB 351), Attorney General enforcement

Ala. HB 351, 2026 Regular Session, Sec. 11enrolled bill text, Alabama Legislative Information System (ALISON)

In force in 220 days, effective 1 May 2027. Binds private bodies.

What this law does

Once in force, the Alabama Attorney General will have exclusive authority to enforce APDPA. Before any enforcement action, the Attorney General must issue a written notice of violation to the controller; if the controller corrects the violation within 45 days and provides a written statement confirming the cure and that no further violations will occur, no action may be initiated. An uncured violation is subject to a court-assessed civil penalty of not more than $15,000 per violation. The Act creates no private right of action.

What it requires

Sensitive categories

Alabama Personal Data Protection Act (HB 351), sensitive data and biometric consent

Ala. HB 351, 2026 Regular Session, Sec. 7(b)(2), Sec. 2(3), Sec. 2(21)enrolled bill text, Alabama Legislative Information System (ALISON)

In force in 220 days, effective 1 May 2027. Binds private bodies.

What this law does

Once in force, APDPA will require a controller to obtain an Alabama consumer's consent before processing sensitive data, defined to include racial or ethnic origin, religious belief, a mental or physical health diagnosis, sex life or sexual orientation, citizenship or immigration status, precise geolocation, a known child's personal data, and the processing of genetic or biometric data for the purpose of uniquely identifying an individual.

'Biometric data' means data generated by automatic measurements of biological characteristics, such as a fingerprint, voiceprint, retina, or iris, used to identify a specific individual, and the definition expressly excludes a digital or physical photograph and an audio or video recording, but claws that exclusion back for any data generated from a photograph or recording once that data is used to identify a specific individual.

What it requires

Scraping law1 instrument, 1 in force

Research summary (192 words)

Alabama diverges from the federal baseline with its own computer-misuse statute: the Alabama Digital Crime Act (2012), which replaced the older 1985 Alabama Computer Crime Act, makes it a crime to act without authority or to exceed authorization of use and, in doing so, knowingly commit one of eight listed acts such as altering or destroying data, taking or disclosing data, introducing a virus, disrupting service, or obtaining confidential government records.

The Act separately defines exceeding authorization of use as accessing a computer with actual or perceived authorization and then using that access to obtain or alter information the accessor is not entitled to obtain or alter, a definition close to the federal gates-based test. No Alabama court decision applying this statute to open-web scraping specifically was located, so whether ordinary, non-disruptive automated collection of a public page fits the statute's elements is untested.

Copyright, text-and-data-mining, and database rights remain federal only; Alabama adds nothing there. robots.txt carries no independent legal weight under Alabama law that was located. A separate provision of the same 2012 Act, encoded data fraud (card-skimming devices), was checked and does not reach web scraping or data collection.

Computer misuse

Alabama Digital Crime Act, Computer Tampering

Ala. Code § 13A-8-112official text, Code of Alabama (alison.legislature.state.al.us)

In force since 1 August 2012. Binds public and private bodies.

What this law does

A person who acts without authority or who exceeds authorization of use commits computer tampering by knowingly doing one of eight things: accessing and altering, damaging, or destroying a computer, program, or network; altering, damaging, deleting, or destroying data; disclosing, using, controlling, or taking programs, data, or documentation; introducing a virus; disrupting or denying computer or network services; preventing a user from exiting a site or connection; obtaining confidential information or non-public records from a government or medical computer system; or giving out a password or other security credential without consent.

Exceeds authorization of use is separately defined as accessing a computer with actual or perceived authorization and then using that access to obtain or alter information the accessor is not entitled to obtain or alter.

The base offense is a Class A misdemeanor; it rises to a Class C felony where the actor intends an unlawful act, benefit, defraud, or harm; to a Class B felony where a victim's expenditure exceeds $2,500 or the intended interruption reaches a government or utility service, and separately where the violation touches Alabama Criminal Justice Information Center or Alabama Justice Information Commission data; and to a Class A felony where a victim's expenditure exceeds $100,000 or the violation causes physical injury to an uninvolved person.

This statute replaced the prior Alabama Computer Crime Act (1985), whose intellectual-property offense provision was repealed by the same 2012 Act.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (633 words)

Alabama's product-security and cyber-resilience posture, for a private-sector operator, rests on one enacted state statute reaching a covered entity's general security posture: the Alabama Data Breach Notification Act of 2018 (Act 2018-396, effective June 1, 2018), whose Section 8-38-3 requires each covered entity and third-party agent to implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security, and whose Section 8-38-10 separately requires a covered entity or third-party agent to take reasonable measures to dispose of records containing that information, by shredding, erasing, or otherwise rendering it unreadable, once the records are no longer to be retained.

"Covered entity" is defined broadly to include a government entity as well as a private business, so both duties bind the state and its political subdivisions alongside private operators.

Enforcement of these two duties is narrower than the chapter's heading suggests: Section 8-38-9, titled "Violations of Notification Requirements," gives the Attorney General exclusive authority to bring a civil action under the chapter, but the only civil-penalty amounts the section actually states, up to $500,000 per breach under Section 8-19-11, or $5,000 per day under subsection (b)(1), are tied expressly to a violation of "the notification provisions of this chapter" and "the notice provisions of this chapter," the separate duties at Sections 8-38-4 through 8-38-8, not to the reasonable-security or disposal duties recorded here; no other enforcement mechanism or penalty figure is stated in the chapter for a violation of Section 8-38-3 or Section 8-38-10 specifically.

The chapter forecloses a private cause of action for a violation of any of its provisions, while preserving whatever right a person may separately have at common law, by statute, or otherwise. No enacted Alabama statute was located that sets security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act; this is a researched absence.

Alabama has adopted the NAIC Insurance Data Security Model Law as its own Insurance Data Security Law, Ala. Code sections 27-62-1 to 27-62-11 (Act 2019-98), which requires each "licensee," defined at Section 27-62-3 as a person licensed, authorized to operate, or registered pursuant to the insurance laws of the state, to develop, implement, and maintain a written information security program and to investigate and notify the Commissioner of a cybersecurity event.

Because "licensee" is a role the LexLint activity vocabulary cannot yet express, the same gap already recorded for South Carolina's, North Carolina's, Kentucky's, New Hampshire's, and Pennsylvania's insurance data security statutes, no instrument is filed for it here, and it is recorded in this summary so a reader knows it exists.

Alabama has no general private-sector duty to report an exploited vulnerability or a security incident to an authority: the Insurance Data Security Law's own incident-notification duty, Section 27-62-6, reaches only that same licensee population, and the state's Office of Information Technology operates a cyber-incident-reporting channel that is a state-agency program rather than a status-based duty on a private operator.

Alabama's breach-notification duty, the Data Breach Notification Act's Sections 8-38-4 through 8-38-8, is already this jurisdiction's privacy row rather than repeated here.

The Alabama Personal Data Protection Act (HB 351, 2026), Ala. Code Title 8, Chapter 44, effective May 1, 2027, layers a comprehensive privacy regime's own security-of-processing clause onto any controller it reaches, Section 7(a)(2), requiring a controller to establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data at issue; this belongs to the privacy topic rather than here, on the same reasoning Texas's Data Privacy and Security Act's Section 541.101(a)(2) does, because it is one subsection of a comprehensive regime addressed to a controller and the chapter's other controller duties are already researched there.

Security baseline statutes

Data Breach Notification Act, reasonable security measures and disposal of records

Ala. Code secs. 8-38-3, 8-38-10Official statute text, Code of Alabama, Title 8, Chapter 38 (Data Breach Notification Act of 2018)

In force since 1 June 2018. Binds public and private bodies.

What this law does

Each covered entity and third-party agent must implement and maintain reasonable security measures to protect sensitive personally identifying information against a breach of security, including designating an employee to coordinate the measures, identifying internal and external risks, adopting and assessing safeguards, requiring service providers to maintain appropriate safeguards by contract, adjusting the measures for changed circumstances, and keeping management informed of their overall status.

A covered entity or third-party agent must separately take reasonable measures to dispose, or arrange for the disposal, of records containing sensitive personally identifying information within its custody or control once the records are no longer to be retained, by shredding, erasing, or otherwise modifying the information to make it unreadable or undecipherable through any reasonable means consistent with industry standards.

"Covered entity" is defined to include a government entity as well as a private business. There is no private right of action for a violation of either duty, and the chapter's stated civil-penalty amounts apply only to a violation of the chapter's separate notification provisions, not to these two duties.

What it requires

Age gating law2 instruments, 1 in force, 1 enacted but not yet in force

Research summary (89 words)

Alabama requires commercial adult websites to verify that visitors are 18 or older under a 2024 law that remains in effect. In 2026 Alabama enacted an App Store Accountability Act requiring app store providers to verify user age and obtain parental consent before minors can download apps or make purchases, effective January 1, 2027.

Alabama has not enacted a general social media minor access law or a children's data protection design code; a 2025 bill to require social media age verification for minors did not advance out of committee.

Adult content age verification (AV)

HB164, age verification for material harmful to minors

Ala. Code § 8-19G-1 et seq.official enrolled bill text, Alabama Legislature

In force since 1 October 2024. Binds private bodies.

What this law does

Requires commercial entities whose websites are more than one-third sexual material harmful to minors to use a reasonable age verification method to ensure visitors are 18 or older, without retaining identifying information after access is granted.

Note and primary source

App store age verification (AV)

HB161, App Store Accountability Act

Act 2026-59 (HB161); Code of Alabama, Title 8official enrolled act text, Alabama Legislature

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

Requires app store providers to request and verify a user's age category (under 13, 13-15, 16-17, or 18 and older) at account creation, and to obtain verifiable parental consent before a minor may download an app or make purchases. Accounts existing before October 2, 2026 must be categorized and verified by October 1, 2027. Signed by Governor Kay Ivey on February 18, 2026 after passing both chambers unanimously.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.