Law / United States / Georgia

Georgia

United States law applies in Georgia Georgia is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Georgia, described on this page below, applies here too.

8 of 9 named instruments researched to a stage, across five of the six areas of law we track: 2 in force, 5 enacted but not yet in force and 1 repealed, withdrawn or blocked. As of 16 September 2026.

  1. AI law 2
  2. Privacy law 2
  3. Scraping law 1
  4. Cybersecurity law 1
  5. Age gating law 2
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 enacted but not yet in force

Research summary (331 words)

Georgia has no comprehensive AI risk-management statute; its AI-specific enactments are narrow and sector-specific.

Senate Bill 9 (2025-2026 session), the “Ensuring Accountability for Illegal AI Activities Act,” which would have criminalized AI-generated child sexual abuse material and provided enhanced sentencing for AI-assisted crimes, died when the Senate disagreed to the House's committee substitute on January 28, 2026 and the 2025-2026 biennium ended at Sine Die on April 2, 2026 with no further recorded action.

Several trackers and AI-generated legal summaries describe a Georgia ‘SB 9’ as an election deepfake disclosure and criminalization measure amending Title 21 (Elections); no such measure exists under that bill number for the 2025-2026 session, and the SB 9 on file at the General Assembly is the AI-generated child sexual abuse material bill described above.

Senate Bill 540 was enacted as 2026 Ga. Laws Act 518, signed May 11, 2026 and effective July 1, 2027, adding O.C.G.A. § 39-5-6 to Title 39, Chapter 5 to regulate 'AI companion chatbots' with disclosure, minor-protection, crisis-response, and age-assurance duties enforced by the Attorney General; the enacted text is narrower than an earlier committee substitute that would have reached 'conversational AI services' generally.

Senate Bill 444 (2025-2026 session), published by the Governor's office among Georgia's 2026 signed legislation, adds O.C.G.A. § 33-46-7.1 to the private review agent certification chapter: a private review agent or utilization review entity may use artificial intelligence in a utilization review, but the system may not issue an adverse coverage determination until a natural person qualifying as a private review agent, with a clinical peer participating, has reviewed it; the Act's own text sets its effective date as January 1, 2027.

A broader AI Accountability Act, Senate Bill 37, which would have required state agencies and municipalities to publish AI usage plans and created a Georgia Board for Artificial Intelligence, died in committee without a floor vote when the 2026 session ended and binds nobody. Georgia has not enacted a general AI risk-obligations, training-data-transparency, or algorithmic-discrimination statute.

AI sector rules

Private Review Agent Artificial Intelligence Coverage Determinations Act (SB 444)

O.C.G.A. § 33-46-7.1, enacted by Ga. SB 444 (2025-2026 session)text as passed by the General Assembly, published by the Governor's Office among Georgia's 2026 signed legislation (gov.georgia.gov)

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

SB 444, as passed by the General Assembly, adds O.C.G.A. § 33-46-7.1 to the private-review-agent certification chapter of the insurance code.

A private review agent or utilization review entity may use an artificial intelligence system or other software tool as part of a utilization review plan meeting the Insurance Commissioner's standards, but such a system may not issue an adverse coverage determination for healthcare services until a natural person qualifying as a private review agent or utilization review entity conducts the review with a clinical peer participating, and the system may never supersede that clinical peer's judgment. The Act sets its own effective date of January 1, 2027.

What it requires

AI transparency

AI Companion Chatbot Safety Act (SB 540)

2026 Ga. Laws Act 518 (SB 540), adding O.C.G.A. § 39-5-6 to Title 39, Ch. 5text as passed by the General Assembly, published by the Governor's Office among Georgia's 2026 signed legislation (gov.georgia.gov)

In force in 281 days, effective 1 July 2027. Binds public and private bodies.

What this law does

SB 540, enacted as 2026 Ga. Laws Act 518, adds Code Section 39-5-6 to Title 39, Chapter 5 to govern 'AI companion chatbots,' systems using artificial intelligence or emotional-recognition algorithms designed to simulate a sustained human-like relationship by retaining information across sessions, asking unprompted emotion-based questions, and sustaining an ongoing personal dialogue; the definition excludes an internal-use or productivity-focused generative AI system, an ordinary customer-service chatbot, a voice-activated device assistant, a narrow educational tool, and a video-game or entertainment character restricted to its own subject matter.

An operator must disclose that a user is interacting with an AI companion chatbot at the start of each session and at least every three hours, or every hour where the operator knows or should know the user is a minor, and for a known minor must take reasonable measures against the chatbot claiming sentience, producing sexually explicit content, simulating a romantic relationship, encouraging secrecy or isolation from a trusted adult, or using engagement techniques designed to prolong attachment.

An operator must adopt and publicly disclose a protocol for detecting and responding to expressions of severe harm, including self-harm and suicidal ideation, with referral to crisis resources and an annual public count of referrals, and for accounts known to belong to minors must offer tools to manage privacy, notifications, and safety settings and use a commercially reasonable, privacy-protective age-assurance method before granting access to any feature that could generate sexually explicit synthetic content.

The Attorney General enforces the section, with a civil penalty of up to $10,000 per knowing violation (each day counted separately for each affected user), plus damages, fees, and injunctive relief, and discretion to allow a 30-day cure period for a first-time non-knowing violation; a hosting provider, app store, or search engine is not liable solely for providing access absent direct operation or control of the chatbot.

The Act was signed May 11, 2026 and takes effect July 1, 2027; an earlier committee substitute would instead have reached 'conversational AI services' generally, a broader and differently defined category than the AI companion chatbot the enacted text regulates.

What it requires

Privacy law2 instruments, 2 enacted but not yet in force

Research summary (208 words)

Georgia has no comprehensive consumer-privacy statute. A genuine comprehensive bill, SB 111 (2026), titled the Georgia Consumer Privacy Protection Act, passed the Senate, but the House replaced its entire text with unrelated rural-hospital tax-credit provisions before Governor Kemp signed the substituted bill on May 11, 2026, so no privacy law was actually enacted under that number.

Georgia's operative privacy statute is the narrow Georgia Personal Identity Protection Act, O.C.G.A. Secs. 10-1-910 to 10-1-915, a breach notification and identity-theft statute whose personal information definition covers only a name combined with a Social Security number, driver's license or state ID number, or an account, credit card, or debit card number, with no biometric, genetic, or health category and no general data-subject rights; Georgia courts have held the Act creates no freestanding data-security duty.

The identity-theft statute itself creates no private right of action, but Georgia's general Fair Business Practices Act separately arms a person injured by a deceptive trade practice with an individual civil action for injunctive relief and damages.

O.C.G.A. Sec. 10-1-911's definition of personal information names no biometric, genetic, or health category, and the Attorney General's Consumer Ed guidance describes the covered data in the same terms (a name combined with a driver's license or credit card number).

Breach notification

Georgia Personal Identity Protection Act, notification of security breach

O.C.G.A. Sec. 10-1-912official guidance quoting O.C.G.A. Sec. 10-1-912, Georgia Attorney General's Consumer Protection Division (Consumer Ed)

Commencement not set. Binds public and private bodies.

What this law does

An information broker or data collector, including a government agency, that maintains computerized personal information on a Georgia resident must give notice of a breach of the security of the system in the most expedient time possible and without unreasonable delay, unless a law enforcement agency determines notification would compromise a criminal investigation.

A person or business maintaining data on behalf of an information broker or data collector must notify that broker or collector of a breach it discovers, and above a 10,000-resident notification threshold the notifying party must also notify nationwide consumer reporting agencies.

Georgia's operative personal information definition (O.C.G.A. Sec. 10-1-911, a companion definitions section not itself quoted on the page cited below) covers only a name combined with a Social Security number, driver's license or state ID number, or an account, credit card, or debit card number where it could be misused without more; biometric, genetic, and health data are absent from the definition entirely, so a breach of biometric data alone triggers no notice duty.

The Act has no direct notice duty running to a state regulator or the Attorney General, and Georgia courts have held the Act imposes no freestanding data-security standard of conduct in its own right.

What it requires

Enforcement supervision

Georgia Fair Business Practices Act, civil action by individuals

O.C.G.A. Sec. 10-1-399official Code of Georgia Annotated text, hosted by the Georgia Attorney General's Consumer Protection Division

Commencement not set. Binds private bodies.

What this law does

Any person who suffers injury or damage from a consumer act or practice that violates the Georgia Fair Business Practices Act may bring an individual civil action, though not a class action, to obtain equitable injunctive relief and to recover general and exemplary damages, with exemplary damages available only for an intentional violation and the court awarding three times actual damages for an intentional violation.

A prevailing injured party is also entitled to reasonable attorneys' fees and expenses of litigation, though fees incurred after rejecting a reasonable written settlement offer within 30 days of the required pre-suit demand are excluded, and fees shift against a plaintiff who continues an action after such a rejection in bad faith or to harass.

This private right of action is separate from, and broader in subject matter than, the Personal Identity Protection Act's breach-notification duty, which itself creates no private right of action.

What it requires

Scraping law1 instrument, 1 enacted but not yet in force

Research summary (244 words)

Georgia diverges from the federal baseline through its own Computer Systems Protection Act, O.C.G.A. § 16-9-93, which criminalizes computer theft, computer trespass, computer invasion of privacy, computer forgery, and computer password disclosure whenever committed 'without authority,' a term the Act defines to include use that 'exceeds any right or permission granted by the owner of the computer or computer network.'

Unlike Virginia's narrower malicious-intent standard, Georgia's authorization test tracks the federal Computer Fraud and Abuse Act's own exceeds-authorized-access language, so ordinary unauthenticated access to a public page that grants and denies no permission at all does not, on its own text, satisfy the statute's authorization element, though no Georgia court decision applying the Act to a scraping or automated-collection fact pattern specifically was located.

The Act arms a private civil action for damages alongside its felony-level criminal penalties. A companion provision in the same article, O.C.G.A. § 16-9-93.1, separately criminalizes using a computer network to falsely identify oneself as another person, organization, or trademark holder (misappropriation of computer identity), a spoofing offense rather than one reaching automated collection of public data.

Copyright, text-and-data-mining, and database rights are federal only; Georgia adds nothing there. Terms-of-service enforceability rests on ordinary Georgia contract law, and no Georgia-specific browsewrap or clickwrap precedent was located. robots.txt carries no independent legal weight under Georgia law. Georgia has no comprehensive privacy statute reaching scraped public personal data; see this jurisdiction's privacy topic document for the narrow breach-notification statute that does exist.

Computer misuse

Georgia Computer Systems Protection Act, computer theft, trespass, invasion of privacy, forgery, password disclosure

O.C.G.A. § 16-9-93Georgia Code Title 16, Crimes and Offenses, FindLaw's copy of the official text (codes.findlaw.com), current as of March 28, 2024

Commencement not set. Binds public and private bodies.

What this law does

Section 16-9-93 makes it a crime, whenever committed without authority, to take or appropriate another's property using a computer (computer theft), to delete, obstruct, or damage computer data, programs, or operation (computer trespass), to examine another person's employment, medical, salary, credit, or other financial or personal data (computer invasion of privacy), to create, alter, or delete data in a way that would be forgery if done on paper (computer forgery), or to disclose a password or access code resulting in damages over $500 (computer password disclosure).

'Without authority' is defined at Section 16-9-92(18) to include use that exceeds any right or permission the computer's owner granted, a test closer to the federal Computer Fraud and Abuse Act's exceeds-authorized-access standard than to Virginia's added malicious-intent or deceptive-means requirement. Subsection (g) grants any person injured by a violation a civil action for damages and costs, not limited to the criminal remedy, with a four-year discovery-based limitations period.

Subsection (f) is a general savings clause preserving the applicability of any other law that presently applies or may apply to the same conduct; it does not name contract law specifically.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (929 words)

Georgia's private-sector security-topic footprint is narrow: one enacted state statute imposes a genuine record-disposal duty distinct from breach notification, no enacted state law sets market-entry security requirements for a connected device or software product, no state law creates a general private-sector duty to report a vulnerability or a security incident to an authority, and no state regime was located adopting the newer NAIC Insurance Data Security Model Law.

O.C.G.A. Sec. 10-15-2 (Title 10, Commerce and Trade), part of a chapter (O.C.G.A. Secs. 10-15-1 to 10-15-7) that already had at least one provision in force by July 1, 2004 (the same chapter's receipt-truncation section, O.C.G.A. Sec. 10-15-3(b)(1), states that date for its own first phase-in; the disposal duty's own commencement date is not stated in the unannotated code text consulted here), requires a 'business,' defined broadly to include a sole proprietorship, partnership, corporation, association, or other group organized for profit or not, and expressly including a financial institution and an entity that destroys records, to shred, erase, modify to make unreadable, or otherwise take reasonable action to prevent unauthorized access to a customer's record before discarding it, where that record combines personally identifiable data with a customer's medical condition, an account or credit balance, information supplied when opening an account or applying for a loan or credit, or a federal, state, or local income tax return.

The duty carves out a bank or financial institution subject to the Gramm-Leach-Bliley Act's privacy and security provisions, a hospital or health care institution subject to Health Insurance Portability and Accountability Act (HIPAA)'s privacy and security provisions, and any other entity governed by a federal law that itself requires disposal of such records in the same manner.

The same chapter's O.C.G.A. Sec. 10-15-3 requires a merchant accepting a payment card to truncate the account number and omit the expiration date on a printed receipt, phased in from July 1, 2004 for machines first used on or after that date to July 1, 2006 for all machines; because that duty binds a merchant printing a payment receipt rather than a duty over a software product's security posture or a business's general handling of covered information, and because it substantially overlaps the federal Fair and Accurate Credit Transactions Act's own truncation requirement, it is named here rather than filed as its own instrument.

The same chapter's O.C.G.A. Sec. 10-15-4, which makes it a crime for a person to use a scanning device or reencoder to capture or transfer payment-card magnetic-strip data with intent to defraud, and O.C.G.A. Sec. 10-15-7's felony penalties for that offense (one to three years' imprisonment or a fine of up to $10,000.00 for a first offense, three to ten years or up to $50,000.00 for a second or subsequent offense), bind the intruder who captures the data rather than the system's operator or manufacturer, so both sit with the scraping topic's computer-misuse family rather than here.

O.C.G.A. Sec. 10-15-5 authorizes the Attorney General to enforce the chapter using the Fair Business Practices Act's investigative powers, and O.C.G.A. Sec. 10-15-6 caps an administrative penalty for a violation of the disposal duty at $500.00 per wrongfully discarded customer record with a $10,000.00 total ceiling per order, subject to an affirmative due-diligence defense, with hearings and judicial review under the Georgia Administrative Procedure Act; the chapter states no private right of action of its own.

No enacted Georgia statute was located that sets security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act, and no enacted Georgia statute creates a general private-sector duty to report an exploited vulnerability or a security incident to a state authority; both are researched absences rather than gaps in coverage.

Georgia's Insurance Code, Title 33, carries a chapter on insurers' collection, use, and disclosure of information (O.C.G.A. Secs. 33-39-1 et seq., the older NAIC Insurance Information and Privacy Protection Act model, itself a privacy-topic matter), but the full Title 33 chapter listing read here, dated by its publisher to March 28, 2024 and running from Chapter 1 through Chapter 65, carries no chapter addressing an insurer's or insurance licensee's information-security program, a cybersecurity event, or a data-security duty comparable to the newer NAIC Insurance Data Security Model Law already adopted in South Carolina, Hawaii, Alaska, Arizona, and Wisconsin, and the Georgia Department of Insurance and Safety Fire Commissioner's own website carries no reference to a data-security or cybersecurity regulatory program either.

A 2025 or 2026 session enactment of the newer model law is not confirmed in the primary text consulted here: the Georgia General Assembly's own legislation-search site, www.legis.ga.gov, serves only a JavaScript application that returned no readable statute text, so a very recent adoption cannot be fully ruled out from the sources read here.

The Georgia Technology Authority (O.C.G.A. Title 50, Chapter 25) has the statutory power 'to establish technology security policies, standards, and services to be used by all agencies' (O.C.G.A. Sec. 50-25-4(a)(20)); nothing in the section read here extends that duty to a vendor or contractor doing business with the state, so it is a government's own information-security programme rather than a duty this topic tracks, and it is not filed as an instrument here.

Georgia's breach-notification statute, the Georgia Personal Identity Protection Act (O.C.G.A. Secs. 10-1-910 to 10-1-915), is already this jurisdiction's privacy-topic row rather than repeated here, and the Georgia Computer Systems Protection Act's hacking, computer theft, trespass, invasion-of-privacy, forgery, and password-disclosure offenses (O.C.G.A. Sec. 16-9-90 et seq.) bind an intruder rather than a system's operator and belong to the scraping topic.

Security baseline statutes

Disposal of records containing personal information

O.C.G.A. Sec. 10-15-2official statute text, Code of Georgia Annotated (unannotated), hosted by FindLaw

In force. Binds private bodies.

What this law does

A 'business' may not discard or dispose of a customer's record containing personal information unless it shreds the record, erases the personal information, modifies the record to make the personal information unreadable, or takes other action it reasonably believes will ensure that no unauthorized person will have access to the personal information for the period between disposal and destruction.

'Business' is defined broadly (sole proprietorship, partnership, corporation, association, or other group, organized for profit or not), expressly includes a financial institution and an entity that destroys records, and excludes a bank or financial institution subject to the Gramm-Leach-Bliley Act's privacy and security provisions, a hospital or health care institution subject to Health Insurance Portability and Accountability Act (HIPAA)'s privacy and security provisions, and any other entity governed by a federal law that itself requires disposal of such records in the same manner.

'Personal information' is personally identifiable data about a customer's medical condition, account or credit balance or limit, data supplied when opening an account or applying for a loan or credit, or a federal, state, or local income tax return, where 'personally identifiable' requires the data to be combined with an identifier such as a Social Security number, driver license number, passport number, or date of birth; a name, address, or phone number alone is not personally identifiable data under this chapter.

The Attorney General enforces the duty using the Fair Business Practices Act's investigative powers, and may impose an administrative penalty of not more than $500.00 for each wrongfully discarded customer record, capped at $10,000.00 total per order, after notice and a hearing conducted under the Georgia Administrative Procedure Act; a business that shows it used due diligence in its attempt to properly dispose of the record has an affirmative defense.

The chapter states no private right of action for a violation of this duty. The commencement date of this specific Code section is not stated in the unannotated code text consulted here, though the same chapter's receipt-truncation section (O.C.G.A. Sec. 10-15-3(b)(1)) states that its own first phase-in was already in force by July 1, 2004, which places the whole chapter's enactment at or before that date.

What it requires

Age gating law2 instruments, 1 in force, 1 repealed, withdrawn or blocked

Research summary (127 words)

Georgia's SB 351 (2024) was enacted as a single act that both restricts minors' social media accounts, requiring parental consent under age 16, and requires age verification on websites publishing material harmful to minors, with both provisions effective July 1, 2025. The social media provisions were preliminarily enjoined in NetChoice v. Carr in June 2025 and remain unenforceable pending Georgia's appeal, argued at the Eleventh Circuit in March 2026.

The separate harmful to minors age verification provision is not part of that suit (the district court's opinion states the case challenges only Section 3-1 of the act, O.C.G.A. Secs. 39-6-1 to 39-6-5) and is currently in effect. Georgia has not enacted an app store age verification or design code law, though state senators have called for one.

Adult content age verification (AV)

SB 351 (2024), commercial entity age verification for material harmful to minors

O.C.G.A. Sec. 39-5-5official Act text, Office of the Governor of Georgia

In force since 1 July 2025. Binds private bodies.

What this law does

Requires a commercial entity that knowingly publishes a substantial portion (more than 33.33 percent) of material harmful to minors on a public website to perform reasonable age verification before granting access, using a digitized identification card, government issued identification, or a method meeting the NIST Identity Assurance Level 2 standard, with a bar on retaining identifying information after access is granted. Not challenged in NetChoice v. Carr, which covers only the act's social media provisions.

Note and primary source

Social media and minors

SB 351 (2024), Protecting Georgia's Children on Social Media Act

O.C.G.A. Secs. 39-6-1 to 39-6-5official Act text, Office of the Governor of Georgia

Enjoined: enforcement paused by a court, effective 1 July 2025. Binds private bodies.

What this law does

Requires social media platforms to use commercially reasonable age verification and to obtain parental consent before a minor under 16 may hold an account, and limits data collection and advertising directed at minors. A federal court preliminarily enjoined these provisions on June 26, 2025.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.