Law / United States / Kentucky

Kentucky

United States law applies in Kentucky Kentucky is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Kentucky, described on this page below, applies here too.

10 of 11 named instruments researched to a stage, across four of the six areas of law we track: 9 in force and 1 proposed. As of 15 September 2026.

When they take effect9 of 10 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 1 instrument (1 in force) 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 1 instrument (1 in force) 2025: 1 instrument (1 in force) 2026: 5 instruments (5 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law 2
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (275 words)

Kentucky's most substantial artificial-intelligence enactment, 2025 Ky. Acts ch. 66 (Senate Bill 4, an emergency-clause act signed March 24, 2025, not the 2024 session as some trackers state), directs the Commonwealth Office of Technology and a new Artificial Intelligence Governance Committee to set AI-use policy for state agencies. That duty binds government bodies rather than private actors, so it is not recorded as an instrument here.

The same Act separately created KRS 117.322, a private cause of action against undisclosed synthetic media in a candidate's electioneering communications, which is Kentucky's one AI-transparency duty reaching a private actor and is the instrument below. House Bill 227 (2026), which as introduced would have addressed AI companion-platform and chatbot safety, had that language stripped by a floor amendment before the House passed it 96-0.

The version that reached the Senate, and that later died with the session, regulates addictive social-media design and minor-account verification generally rather than artificial intelligence specifically, so it is recorded only as this jurisdiction's separate finding on protections for minors online and is not repeated here.

House Bill 455 (2026), which would have restricted licensed mental-health professionals' use of artificial intelligence in therapy, passed the House 88-7 but died in Senate committee without a floor vote, and is recorded below as dead.

Kentucky's general Consumer Protection Act and its Consumer Data Protection Act, neither an AI-specific statute, are the stated basis for a pending Attorney General lawsuit against Character Technologies (Character.AI) filed in Franklin Circuit Court and announced January 8, 2026, alleging deceptive and privacy-violating chatbot conduct toward minors; that action is background to Kentucky's AI regulatory posture rather than an AI-transparency instrument itself.

AI transparency

Synthetic Media Disclosure in Electioneering Communications

KRS 117.322official text, Kentucky Revised Statutes (KRS 117.322)

In force since 24 March 2025. Binds public and private bodies.

What this law does

Created by 2025 Ky. Acts ch. 66 (Senate Bill 4) and effective March 24, 2025, the same emergency-clause Act that also directs Commonwealth-agency AI governance, KRS 117.322 lets a candidate for elected office whose appearance, action, or speech is altered through synthetic media in an electioneering communication seek an injunction or other equitable relief against the communication's sponsor requiring a disclosure that is clear and conspicuous and placed in or alongside the content so a user is likely to notice it, and lets a prevailing plaintiff recover attorney's fees and costs.

The medium disseminating the communication and its advertising sales representative are not liable except where they intentionally remove a required disclosure or, intending to deceive, alter content so that it becomes synthetic media, and an interactive computer service keeps its federal Communications Decency Act section 230 exemption. It is an affirmative defense that the communication already carries the required disclosure.

Failing to comply with a court's order to include the disclosure is punishable as a Class D felony under KRS 121.990(3). The section was amended again by 2026 Ky. Acts ch. 161, effective July 15, 2026.

What it requires

Privacy law5 instruments, 5 in force

Research summary (139 words)

Kentucky's comprehensive privacy law, the Kentucky Consumer Data Protection Act (KCDPA, KRS 367.3611 to 367.3629), took effect January 1, 2026. The statute's own codification note reads "Created 2024 Ky. Acts ch. 72, sec. 1"; a session-law citation to ch. 89 is wrong.

KCDPA requires opt-in consent for sensitive data, including genetic or biometric data processed to uniquely identify a person, and gives consumers access, correction, deletion, portability, and opt-out rights, enforced exclusively by the Attorney General with a permanent 30-day cure period and no private right of action.

A separate breach-notification statute, KRS 365.732, covers only name plus a Social Security, driver's license, or financial account number, and does not reach biometric identifiers or establish a private right of action in the text read. A 2026 amendment to KRS 367.3611, effective July 1, 2027, leaves the biometric-data definition unchanged.

Breach notification

Notification to affected persons of computer security breach

KRS 365.732official Kentucky statute text, KRS section 365.732, Kentucky Legislature website

In force since 15 July 2014. Binds private bodies.

What this law does

An information holder must disclose a breach of the security of the system involving unencrypted personal information to any affected Kentucky resident in the most expedient time possible and without unreasonable delay, with consumer-reporting-agency notice required once more than 1,000 persons are affected at one time.

"Personally identifiable information" is limited to a name plus a Social Security, driver's license, or financial account number with access credentials, and does not reach biometric identifiers. No provision in the eight subsections read requires notice to the Kentucky Attorney General, and none establishes a private right of action; the codified text's own history note dates it to 2014 Ky. Acts ch. 84, sec. 1, effective July 15, 2014.

What it requires

Comprehensive regime

Kentucky Consumer Data Protection Act (KCDPA), general applicability and controller and processor duties

KRS 367.3611, 367.3613, 367.3617, 367.3619official Kentucky statute text, KRS chapter 367, Kentucky Legislature website

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

KCDPA applies to a person that conducts business in Kentucky, or produces a product or service targeted to Kentucky residents, and that during a calendar year controls or processes personal data of at least 100,000 consumers, or 25,000 consumers while deriving over 50 percent of gross revenue from the sale of personal data.

It exempts city and state government, Gramm-Leach-Bliley Act (GLBA)-covered financial institutions, Health Insurance Portability and Accountability Act (HIPAA) covered entities and business associates, nonprofits, higher-education institutions, certain insurance-fraud investigative organizations, and small telephone, CMRS, or municipal utilities that do not sell personal data. Controllers must limit collection to disclosed purposes and processors act on the controller's instructions under a written contract. The enacting session law is 2024 Ky. Acts ch. 72, sec. 1, not ch. 89.

What it requires

Data subject rights

Kentucky Consumer Data Protection Act, consumer rights

KRS 367.3615official Kentucky statute text, KRS chapter 367, Kentucky Legislature website

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

KCDPA gives a Kentucky consumer the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and significant-effect profiling.

A controller must respond without undue delay and in all cases within 45 days of receipt, with one 45-day extension available when reasonably necessary, and must decide an appeal of a denial within 60 days, after which the consumer may complain to the Attorney General.

What it requires

Enforcement supervision

Kentucky Consumer Data Protection Act, Attorney General enforcement

KRS 367.3627official Kentucky statute text, KRS chapter 367, Kentucky Legislature website

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

The Kentucky Attorney General has exclusive authority to enforce KCDPA. Before suing, the Attorney General must give a controller or processor 30 days' written notice; curing the violation and confirming the cure in writing bars an action, and this 30-day cure period is permanent, unlike New Hampshire's and Rhode Island's time-limited or absent versions. An uncured, continuing violation is subject to damages of up to $7,500 per violation, and the statute creates no private right of action.

What it requires

Sensitive categories

Kentucky Consumer Data Protection Act, sensitive data and biometric data definitions

KRS 367.3611(28), 367.3611(3), 367.3617official Kentucky statute text, KRS chapter 367, Kentucky Legislature website

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

KCDPA classifies genetic or biometric data processed to uniquely identify a person as sensitive data, requiring opt-in consent under KRS 367.3617.

"Biometric data" means data from automatic measurement of a biological characteristic, such as a fingerprint, voiceprint, or eye retina or iris, used to identify a specific individual; a photograph, video, or audio recording, or data generated from one, is excluded only until that data is generated to identify a specific individual or is health care information governed by Health Insurance Portability and Accountability Act (HIPAA), at which point the general exclusion lifts. A 2026 amendment effective July 1, 2027 leaves this definition's operative text unchanged.

What it requires

Scraping law2 instruments, 2 in force

Research summary (149 words)

Kentucky's computer-access statute is broader than the federal baseline and broader than several peer states: it criminalizes accessing a computer, system, or network without the effective consent of the owner even where the access causes no loss or damage at all, with no requirement of malicious intent or deceptive means outside the fraud-purpose tier.

The Kentucky Consumer Data Protection Act (KCDPA), now in force, excludes publicly available information from its definition of personal data on the same terms as Virginia's parallel statute, placing most scraped public personal data outside its coverage at the threshold.

Terms-of-service enforceability rests on ordinary Kentucky contract law rather than a dedicated statute, Kentucky has adopted no state database right or text-and-data-mining exception (copyright and any federal text and data mining (TDM) exception are covered in the national document), and no Kentucky statute or reported decision assigns robots.txt independent legal weight or singles out AI-training collection for separate treatment.

Computer misuse

Kentucky Unlawful Access to a Computer

KRS 434.845 to 434.855official text, Kentucky Revised Statutes (KRS 434.840 to 434.860)

In force since 15 July 2002. Binds public and private bodies.

What this law does

Kentucky makes it unlawful to access, cause to be accessed, or attempt to access a computer, computer system, computer network, or any data or software on one, without the effective consent of the owner, and grades the offense in four degrees. Access made to defraud or to obtain money, property, or services is a Class C felony (first degree). Access without that purpose that causes loss or damage of $300 or more is a Class D felony (second degree).

Access causing loss or damage of less than $300 is a Class A misdemeanor (third degree). Access causing no loss or damage at all is still a Class B misdemeanor (fourth degree), so the statute does not require any resulting harm to establish criminal liability, only the absence of effective consent. Separately, knowingly receiving, concealing, or using data or property obtained through a first-degree violation is its own Class C felony (misuse of computer information).

Effective consent is defined at KRS 434.840 and is not effective when induced by deception or coercion or given by a person not authorized to act for the owner, so deceptively circumventing a login, paywall, or other access control falls within the statute regardless of which degree applies.

The statute's text does not expressly except ordinary, unauthenticated access to a publicly available page, and no Kentucky court decision construing the without-effective-consent standard as applied to automated collection of public web content has been located.

What it requires

Personal data

Kentucky Consumer Data Protection Act, publicly available information exclusion

KRS 367.3611official text, Kentucky Revised Statutes (KRS 367.3611)

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

The Kentucky Consumer Data Protection Act (KCDPA), in force since January 1, 2026, defines personal data as information linked or reasonably linkable to an identified or identifiable natural person, and expressly excludes de-identified data and publicly available information from that definition.

Publicly available information means information lawfully made available through federal, state, or local government records, or that a business has a reasonable basis to believe is lawfully made available to the general public through widely distributed media, by the consumer, or by a person to whom the consumer disclosed it, unless the consumer has restricted it to a specific audience.

This places most scraped public personal data outside the KCDPA's coverage at the definitional level, the same approach Virginia's parallel statute takes.

The Act applies only to a person conducting business in Kentucky, or producing products or services targeted to Kentucky residents, that controls or processes the personal data of 100,000 or more consumers a year, or of 25,000 or more while deriving over half of gross revenue from selling personal data, and it expressly excludes a city, state agency, or other political subdivision.

The Act's consumer rights, controller and processor duties, and Attorney General enforcement are personal-data duties rather than scraping law.

What it requires

Age gating law2 instruments, 1 in force, 1 proposed

Research summary (74 words)

Kentucky has required age verification for adult websites since 2024, enforceable only through private civil action since the statute bars government enforcement. A bill requiring age verification, parental consent, and default restrictions on addictive features for minors on social media and AI companion platforms passed the House unanimously in March 2026 but died in the Senate Judiciary Committee when the session ended. No app store accountability or design code bill has advanced past committee.

Social media and minors

HB 227, addictive online platforms and minor protections

House Bill No. 227 (2026 Regular Session), died in Senate committeeofficial Kentucky Legislature bill text and vote history

Proposed: draft date not recorded. Binds private bodies.

What this law does

Would require social media and AI companion platforms to estimate user age, place users under 15 into default child safety settings and disable addictive features such as autoplay absent parental consent, and give parents account monitoring tools. Passed the House 96 to 0 on March 9, 2026, received two readings in the Senate, but died in the Senate Judiciary Committee when the 2026 session ended in April.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.