Law / United States / Arizona

Arizona

United States law applies in Arizona Arizona is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Arizona, described on this page below, applies here too.

11 of 13 named instruments researched to a stage, across five of the six areas of law we track: 10 in force and 1 enacted but not yet in force. As of 16 September 2026.

  1. AI law 5
  2. Privacy law 1
  3. Scraping law 3
  4. Cybersecurity law 1
  5. Age gating law 1
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law5 instruments, 5 in force

Research summary (503 words)

Arizona has no general-purpose AI-transparency or algorithmic-accountability statute of broad application. Five narrower measures are in force.

A.R.S. § 16-1023 creates a private declaratory and injunctive cause of action for any Arizona resident depicted in a non-consensual, undisclosed digital impersonation (a deepfake using deep generative AI methods), with an expedited preliminary-relief track for election candidates and other specified categories; enacted as an emergency measure effective May 21, 2024, with the section applying fourteen days after that date.

A.R.S. § 16-1024, enacted eight days later in the same legislative session, separately requires a person distributing synthetic media depicting a candidate within ninety days of an election to disclose that the content was AI-generated, backed by a civil penalty under A.R.S. § 16-937(B), with exemptions for satire, parody, and interactive computer services.

A.R.S. § 20-3103, in force with the codified section's own effective date of July 1, 2026, bars a health care insurer from denying a claim on medical-necessity grounds without an individualized review by a medical director exercising independent judgment; the statute's own text and the Legislature's own fact sheet for the enacting bill describe this duty in technology-neutral terms and do not themselves use the term artificial intelligence, though contemporaneous news coverage of the bill's passage frames it as a response to insurers' use of AI and algorithmic tools in claims review.

Two 2025 amendments extend Title 13's sexual-offense definitions to reach AI-generated content: HB 2678 (2025 Ariz. Sess. Laws ch. 174) amends A.R.S. §§ 13-3551 and 13-705 so that a computer-generated or digitally altered image indistinguishable from an actual minor is treated the same as an image of a real child, exposing a person who produces, distributes, or possesses such a depiction to the class 2 felony liability Title 13, chapter 35.1 imposes for child exploitation, enhanced under § 13-705 where the depicted minor is under fifteen; and SB 1462 (2025 Ariz. Sess. Laws ch. 106) amends A.R.S. § 13-1425 to add a 'realistic pictorial representation' (an AI-generated or digitally altered image reasonably appearing to be an actual, non-consensual intimate depiction of a person) to the statute's unlawful-disclosure prohibition, though disclosing that kind of synthetic image is itself classified only as a class 1 misdemeanor, a lower tier than the class 5 or class 4 felony that applies to disclosure of a genuine image.

Outside these enacted measures, the Arizona Consumer Fraud Act, A.R.S. §§ 44-1521 to 44-1534, is a general deceptive-practices statute; it names no AI system and creates no AI-specific duty. The Arizona Department of Administration's Statewide Policy P2000 (rev. October 24, 2024) is an executive-branch policy, not a statute, governing state agencies' own use of generative AI tools; it binds no private person and creates no enforceable right.

A general-purpose conversational-AI chatbot disclosure and safety bill, HB 2311 (2026), passed both chambers but was vetoed by Governor Hobbs on June 19, 2026; a companion-privilege bill, HB 2410 (2026), died in Senate committee; and a content-provenance bill, SB 1786 (2026), did not pass. None of the three is in force.

AI prohibited practices

AI-generated and indistinguishable depictions included in child-exploitation definitions (HB 2678)

A.R.S. §§ 13-3551, 13-705; 2025 Ariz. Sess. Laws ch. 174 (HB 2678, 57th Leg., 1st Reg. Sess.)official Arizona Revised Statutes text, Arizona State Legislature website

In force. Binds public and private bodies.

What this law does

Arizona's chapter on sexual exploitation of children defines 'visual depiction' to include an image created or modified by computer software, artificial intelligence, or other digital editing tools. It defines 'minor' to include a visual depiction that is 'indistinguishable' from an actual minor. 'Indistinguishable' means a visual depiction such that a person viewing it would reasonably conclude it is of an actual minor.

Commercial sexual exploitation of a minor under A.R.S. § 13-3552 is a class 2 felony. Sexual exploitation of a minor under A.R.S. § 13-3553 is also a class 2 felony. Where the depicted minor, including an indistinguishable AI-generated depiction, is under fifteen years of age, A.R.S. § 13-705 reclassifies the offense as a dangerous crime against children in the first degree.

A first offense of commercial sexual exploitation of a minor under that reclassification carries a sentencing range of thirteen to twenty-seven years. A first offense of sexual exploitation of a minor under that reclassification carries a sentencing range of ten to twenty-four years. This measure was enacted as House Bill 2678 and approved by the Governor on May 12, 2025, as 2025 Arizona Session Laws chapter 174.

What it requires

Unlawful disclosure extended to AI-generated 'realistic pictorial representation' intimate images (SB 1462)

A.R.S. § 13-1425; 2025 Ariz. Sess. Laws ch. 106 (SB 1462, 57th Leg., 1st Reg. Sess.)official Arizona Revised Statutes text, Arizona State Legislature website

In force. Binds public and private bodies.

What this law does

Arizona's unlawful-disclosure-of-intimate-images statute defines a 'realistic pictorial representation' as an image created or modified to reasonably appear to be an actual image of an identifiable person depicted in a state of nudity or engaged in specific sexual activities that did not actually occur.

Intentionally disclosing an identifiable person's realistic pictorial representation, where the person has a reasonable expectation of privacy and the disclosure is made with intent to harm, harass, intimidate, threaten, or coerce them, is a class 1 misdemeanor. That is a lower tier than the class 5 felony, or class 4 felony if disclosed by electronic means, that applies to disclosure of a genuine, non-synthetic image.

This measure was enacted as Senate Bill 1462 and approved by the Governor on May 2, 2025, as 2025 Arizona Session Laws chapter 106.

What it requires

AI sector rules

Denial of claims; individualized review requirement

A.R.S. § 20-3103official Arizona Revised Statutes text, Arizona State Legislature website

In force 84 days, effective 1 July 2026. Binds private bodies.

What this law does

Before a health care insurer may deny a claim submitted by a provider on the basis of medical necessity, a medical director must individually review the denial, exercise independent medical judgment, and may not rely solely on recommendations from any other source.

The section's own text and the Arizona Senate's fact sheet for the enacting bill, HB 2175 (2025), state this duty in technology-neutral terms; neither document uses the term artificial intelligence, though contemporaneous news coverage of the bill's passage describes it as a response to insurers' use of AI and algorithm-based tools to automate medical-necessity and prior-authorization denials. Enacted in 2025 as HB 2175, with the codified section itself noting an effective date of July 1, 2026.

What it requires

AI transparency

Deepfakes; candidate disclosure requirement and civil penalty

A.R.S. § 16-1024official Arizona Revised Statutes text, Arizona State Legislature website

In force. Binds public and private bodies.

What this law does

Within ninety days before an election at which a candidate appears on the ballot, a creator, meaning any person who uses artificial intelligence or other digital technology to generate synthetic media, other than a provider of the underlying technology, may not create and distribute a deceptive and fraudulent deepfake of that candidate, meaning synthetic media the creator knows is false and intends to injure the candidate's reputation and that is intentionally calculated to mislead a reasonable person, unless the media carries a clear and conspicuous disclosure that it includes content generated by artificial intelligence.

Satire, parody, and an interactive computer service as defined in 47 U.S.C. § 230 are exempt. A creator who fails to make the required disclosure is liable for the civil penalty prescribed by A.R.S. § 16-937(B) for each day the undisclosed deepfake is distributed. Enacted as chapter 199 of the 2024 session laws, this section was approved by the Governor on May 29, 2024.

Unlike its companion section 16-1023, it carries a severability clause rather than an emergency clause, so it took effect on the legislative session's general effective date under the Arizona Constitution rather than immediately on signature; that specific day is not confirmed against a primary source here, though the section has been in force well before the date shown regardless of which 2024 general effective date applies.

What it requires

Digital impersonation of a candidate or other person (civil action)

A.R.S. § 16-1023official Arizona Revised Statutes text, Arizona State Legislature website

In force since 21 May 2024. Binds public and private bodies.

What this law does

A candidate for public office or political party office, or any citizen of Arizona, may bring an action for digital impersonation, defined as synthetic media digitally manipulated or generated using deep generative methods and artificial intelligence techniques to convincingly replace or simulate a person's likeness or voice, created with intent to deceive, that a reasonable viewer or listener would believe is an authentic depiction, and that is not commentary, parody, satire, criticism, or artistic expression.

Liability turns on non-disclosure: a plaintiff must show the digital impersonation was published without the publisher reasonably conveying that it was a digital impersonation or that its authenticity was disputed, or that this would not be obvious to a reasonable person.

The sole remedy is preliminary and permanent declaratory relief unless the plaintiff also proves an additional element, such as a pending election within one hundred eighty days for a candidate-plaintiff, a sexual or criminal-act depiction, or reasonably expected personal, financial, or reputational harm, in which case injunctive relief and damages are also available.

An interactive computer service is not liable under this section merely for publishing content supplied by another information content provider. Enacted as chapter 193 of the 2024 session laws and approved by the Governor as an emergency measure on May 21, 2024, operative immediately, the section states that it applies fourteen days after its effective date.

What it requires

Privacy law1 instrument, 1 enacted but not yet in force

Research summary (162 words)

Arizona has no comprehensive personal-data privacy law. The one 2026 attempt at an omnibus consumer privacy act, SB 1815, died in the Senate Rules Committee without a floor vote in either chamber and does not qualify as a marquee proposal under this topic's source-quality rules.

Arizona's operative privacy statute is a security-breach notification law, A.R.S. sections 18-551 to 18-552, which requires notice to affected residents within 45 days of a breach determination and, above a 1,000-resident threshold, notice to the Attorney General, the state Department of Homeland Security, and the largest nationwide consumer reporting agencies.

Biometric data generated to authenticate access to an online account is one of eleven data elements the statute treats as personal information for breach purposes, but the Act creates no capture-consent, retention, or destruction duty for biometric data, no data-subject rights of any kind, and no private right of action; enforcement runs exclusively through the Attorney General as an unlawful practice under the Arizona Consumer Fraud Act.

Breach notification

Arizona data breach notification law

A.R.S. secs. 18-551 to 18-552official Arizona Revised Statutes text, Arizona State Legislature website

Commencement not set. Binds public and private bodies.

What this law does

Arizona's breach-notification statute requires a person or entity that owns, maintains, or licenses unencrypted computerized personal information of an Arizona resident to notify the affected individual without unreasonable delay and no later than 45 days after determining a breach of system security occurred.

The duty runs to any 'person' that conducts business in the state, a term A.R.S. sec. 18-551(6) defines to include a government or governmental subdivision or agency alongside a natural person or business entity, with no exclusion for public bodies anywhere in sec. 18-552, so the duty is not private-sector-only.

If the breach affects more than 1,000 individuals, the person must also notify the three largest nationwide consumer reporting agencies, the Arizona Attorney General, and the director of the Arizona Department of Homeland Security. Notice may be delayed for an active law enforcement investigation, and no notice is required at all if a reasonable investigation determines there is no substantial risk of economic loss. Gramm-Leach-Bliley Act (GLBA)- and Health Insurance Portability and Accountability Act (HIPAA)-regulated entities are exempt.

The statute creates no lawful-basis, purpose-limitation, or data-subject-rights framework for ordinary processing; it governs breach response only.

What it requires

Scraping law3 instruments, 3 in force

Research summary (206 words)

Arizona's computer-crime scheme, A.R.S. §§ 13-2316 to 13-2316.02, departs from a narrow malicious-intent-only test in the opposite direction from a peer state such as Virginia: alongside intent-based paragraphs for fraud, damage, or disruption, section 13-2316(A)(8) separately criminalizes knowingly accessing a computer, computer system, network, software, program, or data without authority or in excess of authorization, with no further intent element required, making bare unauthorized access a class 6 felony standing on its own.

Nothing in the statute's text carves out ordinary, non-disruptive automated access to a publicly available page. Two companion sections reach trafficking in access devices (credentials) and disclosing a specific system's own confidential security information. Arizona has no comprehensive consumer privacy statute reaching scraped public personal data at the state level; its only enacted privacy measure is a security-breach notification law, covered under the privacy topic, not restated here.

Terms-of-service enforceability rests on ordinary Arizona contract law, with no statutory modification located. Copyright, text-and-data-mining, database rights, unfair competition, and robots.txt's legal weight raise only the federal and common-law questions the national document already covers; Arizona adds no state-specific statute on any of them.

No reported Arizona case applying section 13-2316 or its companion sections to an automated web-scraping or bulk-data-collection fact pattern was located.

Computer misuse

Computer tampering (Arizona's computer-misuse statute)

A.R.S. § 13-2316official Arizona Revised Statutes text, Arizona State Legislature website

In force. Binds public and private bodies.

What this law does

Subsection A makes it computer tampering for a person, acting without authority or in excess of authorization of use, to do any of eight listed things: paragraphs 1 through 5 require an added mental state such as intent to defraud, knowing alteration or destruction of data, or reckless disruption, but paragraph 8 separately criminalizes knowingly accessing any computer, computer system, network, software, program, or data at all, with no further intent element beyond knowledge and lack of authority, a bare unauthorized-access offense that is a class 6 felony on its own.

Paragraph 6 criminalizes preventing a user from exiting a site or connected location in order to compel the user's device to keep communicating with or displaying the service, and a violation of that paragraph is also an unlawful practice under the Arizona Consumer Fraud Act, enforceable by the Attorney General in addition to any criminal prosecution.

Paragraph 7 reaches knowingly obtaining confidential or non-public information by accessing a computer operated by the state, a political subdivision, a health care provider, or a clinical laboratory.

What it requires

Unauthorized release of proprietary or confidential computer security information

A.R.S. § 13-2316.02official Arizona Revised Statutes text, Arizona State Legislature website

In force. Binds public and private bodies.

What this law does

Makes it unlawful to communicate, release, or publish proprietary or confidential computer security information, security-related measures, algorithms, or encryption devices relating to a particular computer, system, or network, without the authorization of that system's owner or operator.

Exemptions cover releasing a security warning or defect information that is not specific to a particular owner's or operator's system, sharing security information among a system's own authorized users, notifying an owner or operator of a perceived threat, and research, development, or testing of security measures that is likewise not specific to a particular owner's or operator's system.

A scraper or security researcher who discovers and publishes a vulnerability specific to one operator's own system, rather than a generic product defect, is not exempted merely because the underlying access was otherwise lawful.

What it requires

Unlawful possession of an access device

A.R.S. § 13-2316.01official Arizona Revised Statutes text, Arizona State Legislature website

In force. Binds public and private bodies.

What this law does

Makes it unlawful to knowingly possess, traffic in, publish, or control an access device, a credential or similar means of reaching an account or system, without the consent of its issuer, owner, or authorized user and with intent to use or distribute it; possessing five or more such devices without consent may itself support an inference of that intent.

This reaches obtaining or trading in login credentials or similar access devices used to reach data behind a login wall, rather than the act of automated collection itself.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (725 words)

Arizona's private-sector security-topic footprint is narrow: one enacted state statute imposes a genuine disposal duty on paper records, no enacted state law sets market-entry security requirements for a connected device or software product, no state law creates a general private-sector duty to report a vulnerability or a security incident to an authority, and the one sector regime located binds a role this profile's activity vocabulary cannot express.

A.R.S. section 44-7601 (Title 44, Trade and Commerce, Chapter 33), in effect by at least 2005 (the earliest year for which a copy of this section could be located; the current statute text carries no enactment-date annotation of its own), requires an 'entity,' defined broadly to include a corporation, unincorporated association, sole proprietorship, partnership, trust, and a government, governmental subdivision or agency, to redact or destroy a paper record or document before discarding or disposing of it if the record or document combines an individual's first and last name, or first initial and last name, with a Social Security number, a credit, charge or debit card number, a retirement account number, a savings, checking or securities entitlement account number, or a driver license or nonoperating identification license number; the duty reaches paper records and documents only, states no parallel duty over electronic data, and exempts an entity already regulated under the Gramm-Leach-Bliley Act, Health Insurance Portability and Accountability Act (HIPAA), or the federal Fair Credit Reporting Act.

Arizona's Administrative Code, Title 20, Chapter 6, Article 21 (R20-6-2101 through R20-6-2104, adopted in 2004 under the older NAIC Standards for Safeguarding Customer Information model, distinct from and narrower than the newer NAIC Insurance Data Security Model Law), requires a 'licensee,' an insurance institution, insurance producer, or insurance support organization, to implement a comprehensive written customer information security program with administrative, technical and physical safeguards appropriate to the licensee's size and complexity; because it binds only an insurance licensee, a bound-party class no activity in the LexLint vocabulary expresses, and because it carries no duty to report a cybersecurity event to the Insurance Commissioner or to affected consumers, unlike a jurisdiction that has adopted the newer NAIC model law, it is recorded here rather than flagged on a guess or filed as an instrument.

A.R.S. section 15-1046(C)(1) requires an 'operator' of an internet website, online service, online application or mobile application used primarily for school purposes and marketed for school purposes to implement and maintain reasonable security procedures and practices appropriate to the nature of covered student information; that duty is one subsection of Arizona's comprehensive student-data-privacy statute, whose other subsections restrict targeted advertising, profiling and the sale of student data and impose deletion and privacy-policy-notice duties, so the security clause belongs to the privacy topic in the same way the General Data Protection Regulation's Article 32 and the Texas Data Privacy and Security Act's section 541.101(a)(2) do, and it is not yet researched under either topic as of this visit; it is named here rather than duplicated as a security-topic row.

A.R.S. section 13-2316.02, which makes it a felony to communicate, release or publish proprietary or confidential computer security information about a particular computer, computer system or network without its owner's or operator's authorization, binds any person who releases such information about another's system rather than the system's own operator or manufacturer, so it sits with the state's computer-tampering chapter (A.R.S. section 13-2316 and its offense-by-an-intruder siblings) in the scraping topic's computer_misuse family rather than here.

No enacted Arizona statute was located that sets security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act, or that creates a general private-sector duty to report an exploited vulnerability or a security incident to a state authority; both are researched absences rather than gaps in coverage.

A.R.S. section 44-7601 is enforced by a county attorney in the county where records were wrongfully discarded or disposed, or by the Attorney General, with a civil penalty per violation arising from one incident that rises with each violation (up to $500 for a first violation, $1,000 for a second, and $5,000 for a third or subsequent violation) and no private right of action; no published enforcement record for it is confirmed in the primary text consulted here.

Arizona's breach-notification duty, A.R.S. section 18-552, is already this jurisdiction's privacy row rather than repeated here.

Security baseline statutes

Discarding and disposing of records containing personal identifying information

A.R.S. sec. 44-7601Official statute text, Arizona Revised Statutes, Arizona State Legislature

In force since 1 January 2005. Binds public and private bodies.

What this law does

An 'entity' may not knowingly discard or dispose of a paper record or document that combines an individual's first and last name, or first initial and last name, with a Social Security number, a credit, charge or debit card number, a retirement account number, a savings, checking or securities entitlement account number, or a driver license or nonoperating identification license number, without first redacting that information or destroying the record or document.

'Entity' is defined broadly to include a corporation, unincorporated association, sole proprietorship, partnership, trust, or a government, governmental subdivision or agency. The duty applies to paper records and documents only. It does not reach an entity already regulated under the Gramm-Leach-Bliley Act, Health Insurance Portability and Accountability Act (HIPAA), or the federal Fair Credit Reporting Act. An entity that maintains and follows its own consistent disposal procedures is deemed compliant.

A county attorney or the Attorney General may enforce the section, and a civil penalty applies per violation arising out of one incident, rising from up to $500 for a first violation to up to $5,000 for a third or subsequent violation.

What it requires

Age gating law1 instrument, 1 in force

Research summary (117 words)

Arizona requires commercial websites and apps where more than one third of content is sexual material harmful to minors to verify that users are 18 or older, effective September 2025, after Governor Hobbs vetoed a similar bill in 2024.

A 2026 bill that would have barred social media accounts for children under 14 without parental consent, required parental approval for 14 and 15 year olds, and added an anonymous verification option to the adult content law passed the House in March 2026 and cleared two Senate committees, but never received a Senate third reading, and it died when the 57th Legislature's second regular session adjourned Sine Die on June 13, 2026 without the bill ever being chaptered.

Adult content age verification (AV)

HB2112, internet pornography, minors, age verification

Ariz. Rev. Stat. Title 18, Chapter 7 (§ 18-701 et seq.)official Arizona Revised Statutes text (A.R.S. § 18-701), Arizona Legislature

In force 12 months, effective 26 September 2025. Binds private bodies.

What this law does

Requires a commercial entity that knowingly publishes material of which more than one third is sexual material harmful to minors to use a reasonable age verification method, such as government issued identification or transactional data, to confirm a visitor is 18 or older, without retaining identifying information.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.