Law / United States / Arkansas

Arkansas

United States law applies in Arkansas Arkansas is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Arkansas, described on this page below, applies here too.

13 of 15 named instruments researched to a stage, across five of the six areas of law we track: 9 in force, 1 enacted but not yet in force and 3 repealed, withdrawn or blocked. As of 15 September 2026.

  1. AI law 4
  2. Privacy law 1
  3. Scraping law 3
  4. Cybersecurity law 1
  5. Age gating law 4
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law4 instruments, 4 in force

Research summary (411 words)

Arkansas has no general AI-transparency or chatbot-disclosure statute and no comprehensive AI-risk-management framework. Four narrower Acts from the 2025 Regular Session add activity-specific duties or a default ownership rule on private actors; a fifth, Act 848 (HB 1958), the Arkansas Public Entity AI Policy Act, binds only public entities' own use of AI and is not catalogued as an instrument here.

Act 159 (HB 1071) amends the Frank Broyles Publicity Rights Protection Act of 2016 to bring an AI-generated reproduction of a person's photograph, voice, or likeness within the Act's existing right of publicity. Act 827 (HB 1529) creates both a criminal offense and a civil cause of action for a nonconsensual sexual deepfake, and reaches the developer of the image-generation technology used to create it where the developer lacked reasonable safeguards against that misuse.

Act 927 (HB 1876) assigns default ownership of a generative AI tool's output: the person who supplies the input or directive owns the generated content, the person who supplies the training data owns the resulting trained model, and where an employee does either within the scope of employment at the employer's direction, the employer owns the result instead.

Act 977 (HB 1877) extends the state's child-exploitation statutes to a computer-generated image indistinguishable from a real child, with a safe harbor for good-faith AI-safety adversarial testing.

None of these four Acts states an explicit commencement date beyond the governor's signature date, so each is recorded here as in force with the commencement date confirmed absent rather than invented; other 2025 Regular Session Acts carrying no emergency clause, including Act 900 and Act 901, are recorded elsewhere as commencing August 5, 2025.

Commentary describes an Arkansas requirement to disclose an AI-generated deepfake of a candidate in election communications, reportedly enacted in 2024 with a satire and parody exemption, but its Arkansas Code citation is not confirmed in any primary text located and it is not catalogued for that reason.

In the absence of an AI-specific bot-disclosure or transparency statute, Arkansas's general Deceptive Trade Practices Act, Ark. Code Ann. § 4-88-107, prohibits deceptive and unconscionable trade practices generally and could reach an undisclosed AI-generated misrepresentation to a consumer, but as a general consumer-protection statute rather than an AI-specific measure it is not catalogued as an instrument here.

A comprehensive accountability bill, SB 258 (2025), died at sine die adjournment; its text is a general consumer-data-privacy bill with a single passing reference to AI-driven decision-making rather than an AI-specific measure.

AI prohibited practices

Act 159 of 2025 (HB 1071), AI-Generated Replicas Amendment to Publicity Rights Act

Ark. Code Ann. §§ 4-75-1103, 4-75-1110, 4-75-1112session law text, Arkansas General Assembly

In force. Binds public and private bodies.

What this law does

Act 159 amends the Frank Broyles Publicity Rights Protection Act of 2016 so that the Act's existing definitions of "likeness" and "photograph" expressly include a reproduction generated through artificial intelligence, and adds a new definition of "voice" that reaches a simulation of an individual's voice, including an AI-generated simulation, whether or not it contains the person's actual voice.

It also narrows a safe harbor for a system or network provider, so that a provider loses that protection once it has actual knowledge that a photograph, voice, or likeness on its system violates the Act. Approved February 25, 2025.

What it requires

Act 827 of 2025 (HB 1529), Unlawful Creation or Distribution of Deepfake Visual Material

Ark. Code Ann. §§ 5-14-139, 16-118-119session law text, Arkansas General Assembly

In force. Binds public and private bodies.

What this law does

Act 827 creates the offense of unlawful creation or distribution of deepfake visual material: without the depicted person's consent, knowingly creating or distributing an AI-generated or AI-modified visual depiction that an ordinary person would conclude shows an identifiable person nude or engaged in sexual conduct. A first offense is a Class A misdemeanor and a second or subsequent offense is a Class D felony.

The Act separately creates a civil cause of action: a person injured by a violation may sue whoever created the deepfake or the provider or developer of the image-generation technology used to create it, and the Attorney General may separately sue a provider or developer of prompt-based image-generation technology used to create the material if that provider or developer lacked reasonable safeguards against generating it.

Ark. Code Ann. § 5-14-139(d) exempts a provider of, or an affiliate of a provider of, a telecommunication service, information service, or cable service as defined in 47 U.S.C. § 153, for content provided by another person. Approved April 17, 2025.

What it requires

Act 977 of 2025 (HB 1877), AI-Generated Child Sexual Abuse Material Amendments

Ark. Code Ann. §§ 5-27-302, 5-27-304, 5-27-601 to 5-27-603, 5-27-609session law text, Arkansas General Assembly

In force. Binds public and private bodies.

What this law does

Act 977 amends the Arkansas Protection of Children Against Exploitation Act of 1979 and the state's computer-crimes-against-minors chapter to add "computer generated" (produced, adapted, or modified, in whole or in part, through artificial intelligence) alongside the existing categories of prohibited child sexual abuse material, and adds "indistinguishable," a visual or print medium that an ordinary person viewing it would conclude depicts an actual child, excluding a drawing, cartoon, sculpture, or painting.

Electronic facilitation of child sexual abuse, which now reaches this computer-generated material, is a Class B felony under section 5-27-603; the felony class for the amended distributing, possessing, or viewing offense at section 5-27-602 is not stated in the text of this Act.

The Act carves out an interactive computer service for content supplied by another party, a law-enforcement investigation exemption, and a safe harbor for a provider or developer whose computer-generated material was produced through adversarial testing conducted in good faith to prevent, detect, or mitigate the risk of an AI system generating this material, so long as the testing was not for personal, exploitative, or unrelated purposes. Approved April 22, 2025.

What it requires

AI training data

Act 927 of 2025 (HB 1876), Generative AI Ownership of Model Training and Content

Ark. Code Ann. § 18-4-101session law text, Arkansas General Assembly

In force. Binds public and private bodies.

What this law does

Act 927 adds Ark. Code Ann. § 18-4-101, assigning default ownership of a generative artificial intelligence tool's output.

Absent a contrary agreement, the person who provides the input or directive to the tool owns the content it generates, and the person who provides the data or input used to train the tool owns the resulting trained model, provided the content or training data does not infringe an existing copyright or other intellectual property right and, for a trained model, that the training data was lawfully acquired and ownership was not otherwise transferred by contract.

Where an employee uses the tool to generate content or train a model within the scope of employment and under the employer's direction and control, the employer owns the result instead. The section grants no ownership over infringing content regardless of AI use. Approved April 21, 2025.

What it requires

Privacy law1 instrument, 1 enacted but not yet in force

Research summary (165 words)

Arkansas has no comprehensive personal-data privacy law. A signed, dated comprehensive Arkansas act is sometimes attributed to this state in error; those dates belong to Tennessee's Information Protection Act and are not repeated here. The one 2025 Arkansas bill that would have created an AI and data-privacy accountability framework, SB 258, died on the Senate calendar at sine die adjournment and Arkansas held no 2026 regular session, so no successor bill exists to catalogue.

Arkansas's operative privacy statute is the Personal Information Protection Act (PIPA), Ark. Code Ann. section 4-110-101 et seq., a security-practices and breach-notification law that names faceprint and voiceprint as biometric data elements with no photograph- or recording-derived exclusion, but creates no capture-consent, retention, or destruction duty, and no data-subject rights.

PIPA borrows the Arkansas Deceptive Trade Practices Act's enforcement mechanism for Attorney General action; whether that Act's own private-suit provision also reaches a PIPA violation is not established and is recorded here as an open question rather than a decided finding.

Breach notification

Arkansas Personal Information Protection Act, breach notification and security

Ark. Code Ann. secs. 4-110-101 to 4-110-108official Arkansas General Assembly session-law text

Commencement not set. Binds public and private bodies.

What this law does

PIPA requires an individual, business, or state agency that acquires, owns, or licenses personal information of an Arkansas resident to implement and maintain reasonable security procedures, dispose of records properly, and notify affected Arkansas residents of a breach of security without unreasonable delay.

If a breach affects more than 1,000 individuals, the person or business must also notify the Attorney General, at the same time as consumer notice or within 45 days of determining a reasonable likelihood of harm, whichever is first.

Biometric data, including faceprint and voiceprint, is one of the data elements that makes information personal information for these purposes, named with no exclusion for data derived from a photograph or recording, but PIPA imposes no separate capture-consent, retention, or destruction duty on biometric data as such.

PIPA violations are enforced by the Attorney General under the Arkansas Deceptive Trade Practices Act; whether that Act's own private-suit provision, section 4-88-113, also arms a private plaintiff for a PIPA violation specifically was not confirmed from primary text and is left as an open question rather than a decided finding.

What it requires

Scraping law3 instruments, 3 in force

Research summary (256 words)

Arkansas adds its own computer-crime chapter on top of the federal Computer Fraud and Abuse Act.

Ark. Code Ann. section 5-41-103 makes it a Class D felony to intentionally access a computer to defraud, extort, or obtain money, property, or a service by false pretense; section 5-41-104 makes intentional, unauthorized access, alteration, or disruption a misdemeanor that escalates to a Class D felony once the resulting loss or damage reaches two thousand five hundred dollars; and section 5-41-203 separately criminalizes knowingly and without authorization interfering with another person's access to a computer, or using or accessing one, with an affirmative defense for a reasonable, good-faith belief of authorization.

None of the three sections defines "without authorization" beyond ordinary usage, and no Arkansas case applying any of them to a scraping or automated-collection fact pattern was located.

A section sometimes confused with this group, section 5-41-108, is captioned "Unlawful computerized communications" but in fact criminalizes threatening or obscene electronic messages sent to harass a specific person; it has no bearing on unauthorized computer access or automated collection and is not catalogued here.

Arkansas has published no free official full-text edition of its own consolidated Code, so these sections are cited to a commercial legal-reference site's copy, current as of March 28, 2024, which states no original enactment or amendment date; each is recorded as in force with the commencement date confirmed absent rather than invented.

No Arkansas statute assigns robots.txt any independent legal weight, and terms-of-service enforceability rests on ordinary Arkansas contract law, untested against scraping specifically.

Computer misuse

Computer fraud

Ark. Code Ann. § 5-41-103Arkansas Code, as published by FindLaw

In force. Binds public and private bodies.

What this law does

A person commits computer fraud by intentionally accessing, or causing to be accessed, any computer, computer system, or computer network for the purpose of devising or executing a scheme to defraud or extort, or of obtaining money, property, or a service through a false or fraudulent intent, representation, or promise.

The offense does not turn on whether the access itself was authorized, only on the fraudulent or extortionate purpose behind it, so ordinary automated access to a public page for a non-fraudulent purpose falls outside this section. Computer fraud is a Class D felony.

What it requires

Computer trespass

Ark. Code Ann. § 5-41-104Arkansas Code, as published by FindLaw

In force. Binds public and private bodies.

What this law does

A person commits computer trespass by intentionally and without authorization accessing, altering, deleting, damaging, destroying, or disrupting any computer, computer system, computer network, computer program, or data.

The offense is graded by loss or damage caused: a Class C misdemeanor for a first violation causing none, rising to a Class B misdemeanor for a repeat violation causing none or a violation causing less than five hundred dollars, a Class A misdemeanor between five hundred and two thousand five hundred dollars, and a Class D felony at two thousand five hundred dollars or more. The statute requires both intent and a lack of authorization.

What it requires

Unlawful interference with access to computers; unlawful use or access of computers

Ark. Code Ann. § 5-41-203Arkansas Code, as published by FindLaw

In force. Binds public and private bodies.

What this law does

A person commits unlawful interference with access to computers by knowingly and without authorization interfering with, denying, or causing the denial of access to or use of a computer, system, or network to a person who has the duty and right to use it, a Class A misdemeanor.

Separately, a person commits unlawful use or access to computers by knowingly and without authorization using, accessing, attempting to access, or causing access to be gained to a computer, system, network, telecommunications device, telecommunications service, or information service, also a Class A misdemeanor, rising to a Class C felony where either violation is committed to devise or execute a scheme to defraud or illegally obtain property.

It is an affirmative defense that the person reasonably believed they were authorized and acting within the scope of that authorization, or that the person able to consent would have authorized the access; a defendant who intends to raise this defense must give the prosecuting attorney written notice at least fourteen calendar days before trial or hearing.

This section is sometimes cited under the caption "unlawful computerized communications," which is instead the name of a different, unrelated section, Ark. Code Ann. § 5-41-108, a harassment statute covering threatening or obscene electronic messages and having no bearing on unauthorized computer access.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (294 words)

Arkansas's product-security and cyber-resilience posture rests on one enacted state statute reaching software or systems generally: the Personal Information Protection Act's reasonable-security duty, Ark. Code Ann. section 4-110-104(b), which requires a person or business, a term defined to include a state agency, that acquires, owns, or licenses personal information about an Arkansas resident to implement and maintain reasonable security procedures and practices appropriate to the nature of the information.

This duty is legally distinct from, though enacted in the same 2005 Act as, the Personal Information Protection Act's breach-notification duty at section 4-110-105, which is Arkansas's privacy row and is not repeated here.

No Arkansas statute was located setting security requirements a software product or connected device must meet before or after being placed on the market, a duty to report a vulnerability or a security incident to an authority, or a sector-specific cyber-resilience regime reaching a digital service this corpus can currently flag against.

Arkansas has not enacted the NAIC Insurance Data Security Model Act as its own insurance-licensee-scoped statute; the NAIC's own 2026 state-adoption tracker records Arkansas's citation as the general Personal Information Protection Act together with Ark. Code Ann. section 25-1-128, rather than a dedicated insurer security-program law, so no insurance-sector absence document is filed for this jurisdiction.

Ark. Code Ann. sections 25-26-301 to 25-26-306, the Arkansas Cyber Initiative Act, and section 25-1-128 bind only the state's own technology-resource policy and a voluntary economic-development cybersecurity alliance; neither imposes a checkable duty on a private software vendor, so both stay with the Government Accountability wing rather than this topic.

The reasonable-security duty is enforced only by the Attorney General under the Arkansas Deceptive Trade Practices Act, and no published enforcement record specific to a Personal Information Protection Act reasonable-security action was located.

Security baseline statutes

Arkansas Personal Information Protection Act, reasonable security procedures

Ark. Code Ann. section 4-110-104(b)Official Arkansas General Assembly session-law text, Act 1526 of 2005 (SB1167), sec. 4 (original enactment of Ark. Code Ann. sec. 4-110-104)

In force. Binds public and private bodies.

What this law does

A person or business that acquires, owns, or licenses personal information about an Arkansas resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect the personal information from unauthorized access, destruction, use, modification, or disclosure.

This reasonable-security duty sits in the same Act, and the same code section, as the Act's separate duty to take all reasonable steps to destroy or arrange for the destruction of a customer's records containing personal information that is no longer to be retained, and it is legally distinct from the Act's breach-notification duty at section 4-110-105, already researched as this jurisdiction's privacy row.

"Business" is defined to include a state agency, so the duty reaches Arkansas's own state agencies as well as private persons and businesses. The reasonable-security duty has not been amended since the Act's original 2005 enactment: the only later amendment to this subchapter located, Act 1030 of 2019, added biometric data elements to the definition of personal information and separately amended the breach-notification section, and left this duty's own text untouched.

Act 1526 of 2005 itself states no day-precise commencement date and carries no emergency clause, so its default constitutional commencement, ninety days after the 2005 Regular Session's sine die adjournment, is not pinned to a calendar day from primary text here.

The Act names no dedicated regulator and no penalty amount of its own for a violation of this duty; any violation of the subchapter is punishable only by action of the Attorney General under the Arkansas Deceptive Trade Practices Act, and whether that Act's own private-suit provision also arms a private plaintiff for a violation of the reasonable-security duty specifically was not confirmed from primary text.

What it requires

Age gating law4 instruments, 1 in force, 3 repealed, withdrawn or blocked

Research summary (101 words)

Arkansas requires commercial websites where more than one third of content is harmful to minors to verify users are 18 or older under a 2023 law that remains in effect. Arkansas has enacted three social media minor access laws since 2023, the original Social Media Safety Act and two 2025 acts strengthening its addictive design rules and adding civil liability for platforms.

Federal courts have blocked all three on First Amendment grounds: the 2023 Act was permanently enjoined and is on appeal to the Eighth Circuit, and the two 2025 Acts took effect in August 2025 but are now preliminarily enjoined.

Adult content age verification (AV)

Act 612 of 2023 (SB66), Protection of Minors from Distribution of Harmful Material Act

Act 612 of 2023 (SB66), codified at Ark. Code Ann. § 4-88-1101 et seq.official act text, Arkansas State Legislature

In force since 1 August 2023. Binds private bodies.

What this law does

Makes a commercial entity liable if more than one third of its website content is material harmful to minors and it fails to perform reasonable age verification using a government issued ID, digital identification, or a commercially reasonable method meeting identity assurance level 2.

Note and primary source

Social media and minors

Act 689 of 2023 (SB396), Social Media Safety Act

Act 689 of 2023 (SB396), codified at Ark. Code Ann. § 4-88-1401 et seq.official act text, Arkansas State Legislature

Struck down: invalidated by a court, effective 1 September 2023. Binds private bodies.

What this law does

Would have required social media companies to use a third party vendor to perform reasonable age verification, such as a digitized ID or government issued ID, before allowing account access, and to obtain parental consent for minor accounts.

Note and primary source

Act 900 of 2025 (SB611), Social Media Safety Act amendments (addictive design)

Act 900 of 2025 (SB611), amending Ark. Code Ann. § 4-88-1401 et seq.official act text, Arkansas State Legislature

Enjoined: enforcement paused by a court, effective 5 August 2025. Binds private bodies.

What this law does

Amends the Social Media Safety Act to lower the covered minor age from 18 to 16, prohibit addictive design features, require default privacy settings, and disable non-essential notifications between 10 PM and 6 AM. Signed April 21, 2025; most provisions took effect August 5, 2025, while the addictive design and notification duties in Section 2 carried a delayed effective date of April 21, 2026, one year after enactment.

Note and primary source

Act 901 of 2025 (SB612), social media platform civil liability

Act 901 of 2025 (SB612), codified at Ark. Code Ann. §§ 4-88-1501 to 4-88-1503official act text, Arkansas State Legislature

Enjoined: enforcement paused by a court, effective 5 August 2025. Binds private bodies.

What this law does

Creates a private right of action against a social media platform whose design, algorithm, or feature causes a minor to suffer harm such as an eating disorder, suicide or attempted suicide, or platform addiction. Signed April 21, 2025 and effective August 5, 2025 with no separate effective date clause.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.