Law / United States / Michigan

Michigan

United States law applies in Michigan Michigan is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Michigan, described on this page below, applies here too.

16 of 20 named instruments researched to a stage, across five of the six areas of law we track: 10 in force, 1 enacted but not yet in force and 5 proposed. As of 14 September 2026.

When they take effect10 of 16 carry a date, 6 do not. Earlier is before 2014.
Before 2014: 5 instruments (5 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 2 instruments (2 in force) 2022: 0 instruments 2023: 0 instruments 2024: 2 instruments (2 in force) 2025: 1 instrument (1 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 3
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law 2
  5. Age gating law 4
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law3 instruments, 3 in force

Research summary (219 words)

Michigan enacted two artificial-intelligence-specific election transparency statutes in 2023 and a criminal ban on nonconsensual intimate deepfakes in 2025. Public Act 263 of 2023 requires a disclosure when a qualified political advertisement, or a prerecorded campaign telephone message, is generated in whole or substantially by artificial intelligence (MCL 169.247, 169.259).

Public Act 265 of 2023 prohibits distributing media the Act itself defines as artificial-intelligence-produced and materially deceptive within 90 days of an election, unless the media carries a prescribed manipulation disclaimer (MCL 168.932f). The Protection from Intimate Deep Fakes Act (Public Act 11 of 2025) criminalizes the nonconsensual creation or dissemination of a sexually explicit deep fake of an identifiable person and creates a parallel civil cause of action (MCL 752.381 to 752.390).

Several further AI bills remain pending and are not yet law: HB 4668 (AI Safety and Security Transparency Act, foundation-model risk assessments), HB 5579 (employer AI and electronic-monitoring notice duties), HB 5899 (a state-agency AI governing board and pilot program, which would bind only government AI use even if enacted), and SB 760 (the LEAD for Kids Act, companion-chatbot safety duties), which passed the Senate April 29, 2026 and remains in a House committee.

Michigan's child sexually abusive material statute (MCL 750.145c) has not been checked for whether its definitions reach a computer- or AI-generated depiction.

AI prohibited practices

Protection from Intimate Deep Fakes Act (Public Act 11 of 2025)

MCL 752.388official Michigan Compiled Laws text, Protection from Intimate Deep Fakes Act, Michigan Legislature

In force since 26 August 2025. Binds public and private bodies.

What this law does

The Protection from Intimate Deep Fakes Act (Public Act 11 of 2025) makes it a crime for an individual to intentionally create or disseminate a deep fake that realistically depicts the intimate parts of, or a sexual act involving, an identifiable individual, where the individual knew or should have known the deep fake would cause the depicted individual physical, emotional, reputational, or economic harm.

A first violation is a misdemeanor punishable by up to one year's imprisonment or a $3,000 fine; the offense becomes a felony punishable by up to three years or a $5,000 fine where the depicted individual suffers financial loss, the creator intends to profit, the creator operates a website or app for the purpose, the creator posts the deep fake online, the creator intends to harass, extort, threaten, or harm, or the creator has a prior conviction under this section.

Consent to the deep fake's creation is not a defense unless given in a signed, plain-language agreement describing the depiction.

The Act also creates a civil cause of action for the depicted individual for economic and noneconomic damages, confidential filing, and injunctive relief to maintain that confidentiality, and exempts interactive computer services, telecommunications providers, and technology developers who prohibit the conduct in their terms of service and did not design or market the technology for it.

What it requires

AI transparency

AI-Generated Political Advertisement and Robocall Disclosure (Public Act 263 of 2023)

MCL 169.247, 169.259official Michigan Compiled Laws text, Michigan Campaign Finance Act, Michigan Legislature

In force since 13 February 2024. Binds public and private bodies.

What this law does

MCL 169.259, added to the Michigan Campaign Finance Act by Public Act 263 of 2023, requires a person, committee, or entity that creates, originally publishes, or originally distributes a qualified political advertisement generated in whole or substantially by artificial intelligence to include a clear and conspicuous disclosure, with format and duration requirements that vary by medium.

A companion amendment to MCL 169.247 requires the same disclosure on a prerecorded campaign telephone message generated in whole or substantially by artificial intelligence. The disclosure duty does not apply to a bona fide news broadcast that discloses the manipulation, a paid broadcaster, a distribution platform with a stated compliance policy, satire or parody, or a business regulated by the Michigan Public Service Commission or the Federal Communications Commission.

A first violation is a state civil infraction with a fine of up to $250; a second or subsequent violation carries a fine of up to $1,000 per violation, with each distributed or aired advertisement a separate violation.

What it requires

Distribution of Materially Deceptive Election Media (Public Act 265 of 2023)

MCL 168.932fofficial Michigan Compiled Laws text, Michigan Election Law, Michigan Legislature

In force since 13 February 2024. Binds public and private bodies.

What this law does

MCL 168.932f, added to the Michigan Election Law by Public Act 265 of 2023, prohibits a person from distributing, or agreeing to distribute, media the section defines as materially deceptive because it depicts speech or conduct that did not occur, would cause a reasonable viewer to believe it did, and was produced by artificial intelligence, where the person knows the media falsely represents a depicted individual, intends within 90 days of an election to harm a candidate's reputation or electoral prospects, and intends to deceive electors about the depicted individual's actual speech or conduct.

The prohibition does not apply where the media carries a disclaimer, in a form prescribed for video, audio, or image media, stating that it was manipulated and does not depict real speech or conduct, or where media made by editing an existing work cites its unedited source. A first violation is a misdemeanor punishable by up to 90 days' imprisonment or a $500 fine; a violation within five years of a prior conviction under this section is a felony punishable by up to five years or a $1,000 fine.

The Attorney General, the depicted individual, an injured candidate, or a voter-representing organization may also seek permanent injunctive relief.

What it requires

Privacy law6 instruments, 5 in force, 1 enacted but not yet in force

Research summary (204 words)

Michigan has no comprehensive consumer personal-data statute. The Michigan Personal Data Privacy Act, SB 359, was reported favorably from committee in June 2025 but has seen no floor vote in either chamber and does not clear the marquee bar for a proposed instrument.

Michigan's sectoral law covers breach notification under the Identity Theft Protection Act (MCL 445.61 to 445.79d), whose breach-notice trigger turns on the narrower personal information term (MCL 445.63(r)), which excludes biometrics, while a separate, broader personal identifying information term in the same section (MCL 445.63(q)), used elsewhere in the Act for identity-theft and criminal provisions, does include biometrics; the two must not be conflated.

The Insurance Data Security Act (MCL 500.550 to 500.565), adopting the NAIC model law effective January 20, 2021, names biometric records as a protected data element for insurance licensees but defines the term no further and expressly forecloses a private right of action, as does the Identity Theft Protection Act's own breach-notice enforcement provision.

A physician-ordered genetic test informed-consent requirement (MCL 333.17020) binds health care providers but is not a consumer-facing genetic-privacy or data-processing statute; no Michigan law regulates direct-to-consumer genetic-testing companies' privacy practices, and no biometric-privacy statute reaches a general private-sector actor outside the insurance sector.

Breach notification

Identity Theft Protection Act, breach of security notice duty

MCL 445.72official Michigan Compiled Laws text, Michigan Legislature

In force since 2 July 2006. Binds public and private bodies.

What this law does

The Identity Theft Protection Act (Act 452 of 2004) requires a person or agency to provide breach notice without unreasonable delay, unless the entity determines the breach has not caused and is not likely to cause substantial loss, injury, or identity theft.

The notice trigger turns on the narrower personal information term at MCL 445.63(r), which does not include biometric data; a breach exposing only biometric identifiers, with no accompanying Social Security number, driver's license, or financial account number, does not trigger this notice duty. The publicly-available carve-out for this notice duty is placed in MCL 445.72(17), not in the definitions section, MCL 445.63. This section applies to a breach discovered or noticed on or after July 2, 2006.

What it requires

Identity Theft Protection Act, personal information and personal identifying information defined

MCL 445.63(q), (r)official Michigan Compiled Laws text, Michigan Legislature

In force since 1 April 2011. Binds public and private bodies.

What this law does

MCL 445.63 defines two distinct terms that must not be conflated. "Personal information," MCL 445.63(r), is a name combined with a Social Security number, driver's license or state ID number, or financial account or card number with an access code; it does not include biometric data.

"Personal identifying information," MCL 445.63(q), is a broader term, used for the Act's identity-theft-prevention and criminal provisions elsewhere in the chapter, that does include biometrics among many other data elements such as address, employer, government passport number, and account passwords. Only the narrower "personal information" term is the breach-notice trigger at MCL 445.72.

What it requires

Enforcement supervision

Identity Theft Protection Act, enforcement

MCL 445.72(13)-(15)official Michigan Compiled Laws text, Michigan Legislature

In force since 2 July 2006. Binds private bodies.

What this law does

A person that knowingly fails to give required breach notice may be ordered to pay a civil fine of up to $250 per failure to notify, with aggregate liability for multiple violations arising from the same breach capped at $750,000; the Attorney General or a prosecuting attorney may bring the action.

The Act preserves, but does not itself create, any other civil remedy available under state or federal law; no provision ties a violation to the Michigan Consumer Protection Act or any other statute carrying a private right of action.

What it requires

Insurance Data Security Act, no private cause of action

MCL 500.550official Michigan Compiled Laws text, Michigan Legislature

In force since 20 January 2021. Binds private bodies.

What this law does

The Insurance Data Security Act expressly does not create or imply a private cause of action for its violation, and does not curtail a private cause of action that would otherwise exist independent of the chapter. The chapter establishes the exclusive Michigan standards for a licensee's data security, cybersecurity-event investigation, and notification to the Director of the Department of Insurance and Financial Services, who enforces it.

What it requires

Sensitive categories

Genetic test; informed consent

MCL 333.17020official Michigan Compiled Laws text, Public Health Code, Michigan Legislature

Commencement not set. Binds public and private bodies.

What this law does

A physician, or an individual to whom the physician has delegated authority to perform a selected act, task, or function, may not order a presymptomatic or predictive genetic test without first obtaining the test subject's written, informed consent.

This is a health-care informed-consent requirement binding a physician's ordering conduct, not a consumer-facing data-privacy or data-processing statute, and it does not reach a direct-to-consumer genetic-testing company; no Michigan statute regulates such a company's privacy practices. The precise commencement date, tied to the expiration of 6 months after the effective date of the amendatory act that added this section, was not independently established.

What it requires

Insurance Data Security Act, nonpublic information including biometric records

MCL 500.553official Michigan Compiled Laws text, Michigan Legislature

In force since 20 January 2021. Binds private bodies.

What this law does

Michigan adopted the NAIC Insurance Data Security Model Law as Chapter 5A of the Insurance Code (MCL 500.550 to 500.565), effective January 20, 2021. Nonpublic information (MCL 500.553(i)) includes electronic information that is not publicly available and that, combined with an identifying element such as a name or number, includes a Social Security number, driver's license or state ID number, financial account or card number, a financial-account access code, or biometric records.

Biometric records appears as a bare, undefined term with no elaboration anywhere in the chapter's definitions and no photograph, video, or audio-recording exclusion or clawback clause of any kind, so whether it excludes a recording-derived identifier cannot be tested against this text and is not recorded. This chapter binds insurance licensees only, not a general private-sector actor.

What it requires

Scraping law1 instrument, 1 in force

Research summary (102 words)

Michigan's principal scraping-adjacent statute is the Fraudulent Access to Computers, Computer Systems, and Computer Networks Act (Act 53 of 1979, MCL 752.791 to 752.797), a computer-misuse statute that criminalizes intentional access without authorization or by exceeding authorization, independent of any privacy, copyright, or terms-of-service theory.

Michigan has no separate terms-of-service enforceability statute, text-and-data-mining exception, sui generis database right, or robots.txt-specific rule; a service's copyright and terms-of-service exposure for scraping rests on federal law and general common-law doctrine that Michigan has not separately codified. The Michigan Consumer Protection Act (MCL 445.903) was checked and contains no subsection naming automated access or data collection.

Computer misuse

Fraudulent Access to Computers, Computer Systems, and Computer Networks Act

MCL 752.791 to 752.797official Michigan Compiled Laws text, Michigan Legislature

In force since 27 March 1980. Binds public and private bodies.

What this law does

Act 53 of 1979 prohibits intentionally accessing or causing access to a computer, computer system, or computer network to devise or execute a fraud scheme, or to obtain money, property, or a service by false pretense (MCL 752.794).

Separately, MCL 752.795 prohibits intentionally accessing, or causing access to, a computer, computer system, or computer network without authorization or by exceeding valid authorization, to acquire, alter, damage, delete, or destroy property or to use its services, and prohibits planting instructions or a program intended to do the same.

Michigan Act 53 also creates a rebuttable presumption that access was unauthorized, which is rebutted by showing written or oral permission was granted, that the accessed system displayed a pre-programmed message a reasonable person would believe identified it as within the public domain, or that access did not require bypassing an access-control procedure.

MCL 752.796 separately prohibits using a computer, computer system, or computer network to commit, attempt, conspire to commit, or solicit another to commit a crime.

Penalties escalate with the aggregate value involved or the severity of the underlying crime: a violation of the fraud-scheme prohibition ranges from a misdemeanor (93 days, $500, or 3 times the aggregate amount) to a felony (10 years, or 3 times the aggregate amount) as the aggregate loss or prior-conviction count rises; a violation of the unauthorized-access prohibition is a felony punishable by up to 5 years or a $10,000 fine, rising to 10 years or $50,000 with a prior conviction; and a violation of the commit-a-crime prohibition is tiered to the maximum term of the underlying offense, from a 1-year misdemeanor up to a 20-year felony.

What it requires

Cybersecurity law2 instruments, 1 in force, 1 proposed

Research summary (1,034 words)

Michigan has no single cross-sector product-security or cyber-resilience statute.

Its only enacted baseline-security duty is narrow: MCL 445.72a (Sec. 12a of the Identity Theft Protection Act, Act 452 of 2004, added by 2006 PA 566 and effective July 2, 2007) requires a person or agency that maintains a database including personal information about multiple Michigan residents to destroy, or arrange for the destruction of, any data containing an individual's personal information once it is removed from the database and not retained elsewhere for a purpose state or federal law does not prohibit, with retention for an investigation, audit, or internal review expressly permitted; a knowing violation is a misdemeanor punishable by a fine of up to $250 per violation, and the section neither creates a private right of action nor displaces whatever other civil remedy state or federal law might otherwise provide.

This is a disposal-only duty split out of the Act's breach-notification section, MCL 445.72, already this jurisdiction's privacy-topic row; it does not by its own text impose the broader administrative, technical, and physical safeguards program that New York's SHIELD Act (General Business Law 899-bb) or Utah's Protection of Personal Information Act (Utah Code 13-44-201) require, and no other enacted Michigan statute does either.

A broader, comprehensive reasonable-security-procedures duty is pending, not yet law.

Senate Bill 360 of the 2025-2026 Regular Session, as passed by the Senate on August 26, 2025 (Roll Call No. 212, 19-15) and referred to the House Committee on Government Operations the same day, would add a new Section 11a to the Identity Theft Protection Act requiring a person or agency that owns, possesses, collects, or accesses personal information to implement and maintain reasonable security procedures: designate a coordinator, identify internal and external risks, include safeguards addressing those risks, assess the safeguards' effectiveness, contractually require every service provider to maintain safeguards conforming to the NIST Cybersecurity Framework 2.0 or another industry-standard framework, and evaluate and adjust the procedures over time; reasonableness would turn on the entity's size, the amount and type of personal information involved, and the cost of the procedures relative to the entity's resources, and an entity that reasonably conforms to NIST CSF 2.0, or is already regulated under and conforms to Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Title V, the Federal Information Security Modernization Act of 2014, or HITECH, would be deemed compliant.

The bill would also add a duty to investigate a suspected breach (proposed Section 11b) and would arm only the Attorney General, through a new civil-investigative-demand and assurance-of-discontinuance framework, with a civil fine of up to $2,000 for a knowing failure to implement or maintain reasonable security procedures and a further $2,000 for a knowing failure to investigate a breach; no provision of the bill as passed by the Senate was located creating a private right of action.

This bill has not been enacted and binds nothing today. It is a reintroduction of Senate Bills 888 through 892 of the 2023-2024 Regular Session, which likewise passed the Senate on December 12, 2024 (Roll Call No. 540, 20-15) and were referred to the same House committee but received no further action before that session ended; as of September 14, 2026 the reintroduced bill remains in the House Committee on Government Operations, with no further recorded action since its Senate passage.

No enacted Michigan statute provides a Utah, Ohio, or Iowa-shaped cybersecurity affirmative-defense safe harbor conditioned on a framework-conforming program.

Senate Bill 672 of the 2021-2022 Regular Session would have added exactly that, an affirmative defense to a tort claim for a person that maintained a written cybersecurity program reasonably conforming to a named framework; it passed the Senate on March 9, 2022 (Roll Call No. 65, 20-17) and was referred to the House Committee on Financial Services the same day, but received no further action before the session ended, and no successor safe-harbor bill has been introduced since.

Senate Bill 360, the currently pending bill, does not include an affirmative-defense provision; it imposes a mandatory duty rather than offering a shield.

Michigan's one sector-specific cyber-resilience regime is the Insurance Data Security Act, MCL 500.550 to 500.565 (Chapter 5A of the Insurance Code of 1956, added by 2018 PA 690 and effective January 20, 2021), adopting the NAIC Insurance Data Security Model Law.

Its core duty, MCL 500.555, requires a licensee (a licensed insurer, producer, or other person licensed, authorized, or registered under the Insurance Code) to develop, implement, and maintain a comprehensive written information security program with administrative, technical, and physical safeguards, board-level oversight, a written incident-response plan, and an annual compliance certification to the Director of the Department of Insurance and Financial Services; MCL 500.559 separately requires a licensee to notify the Director within ten business days of determining that a qualifying cybersecurity event occurred.

Because a licensee is a financial-services-style regulated entity, a role the LexLint activity vocabulary cannot yet express, this regime is deferred rather than flagged on a guess (#6740): no instrument for it is filed here, exactly as New York's parallel regime, 23 NYCRR Part 500, is deferred on this jurisdiction's own row.

MCL 500.550 forecloses a private cause of action for the chapter's violation and states that the chapter sets the exclusive Michigan standards for a licensee's data security, and MCL 500.553's definition of nonpublic information, which names biometric records among other elements, is already this jurisdiction's privacy-topic row rather than repeated here.

No enacted Michigan statute sets security requirements a connected device or software product must meet to be placed on the market, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act, and no enacted Michigan statute imposes a general private-sector duty to report an exploited vulnerability or a security incident to a state authority; the federal Cyber Incident Reporting for Critical Infrastructure Act's reporting duty, not yet in effect pending a final rule, is this jurisdiction's national-layer row rather than a Michigan-specific one.

Michigan's computer-misuse statute, the Fraudulent Access to Computers, Computer Systems, and Computer Networks Act (1979 PA 53), binds a person who accesses a computer system without authorization; it belongs to this jurisdiction's scraping-topic computer_misuse family and is not recorded here, because it binds the intruder rather than the operator or manufacturer this profile researches.

Security baseline statutes

Identity Theft Protection Act, destruction of data no longer needed

MCL 445.72a (Sec. 12a of Act 452 of 2004, added by 2006 PA 566)official Michigan Compiled Laws text, Michigan Legislature

In force since 2 July 2007. Binds public and private bodies.

What this law does

MCL 445.72a requires a person (a private business or other legal entity) or agency (a Michigan state government department, board, commission, office, authority, or unit, including a public university, but not a court) that maintains a database including personal information about multiple Michigan residents to destroy, or arrange for the destruction of, any data containing an individual's personal information once that data is removed from the database and is not retained elsewhere for a purpose state or federal law does not prohibit.

Retaining data for an investigation, audit, or internal review is not itself a violation of this duty. "Destroy" means shredding, erasing, or otherwise modifying the data so it cannot be read, deciphered, or reconstructed through generally available means. An entity already subject to, and in compliance with, a federal law governing the disposal of records containing personal identifying information is considered compliant with this section too.

A knowing violation is a misdemeanor punishable by a fine of up to $250 for each violation, and the section neither creates a private right of action nor displaces whatever other civil remedy state or federal law might otherwise provide.

This is a narrower, disposal-only duty that does not, by its own text, impose the broader administrative, technical, and physical safeguards program that New York's SHIELD Act (General Business Law 899-bb) or Utah's Protection of Personal Information Act (Utah Code 13-44-201) require.

What it requires

Senate Bill 360 (2025-2026), Identity Theft Protection Act reasonable security procedures duty

2025 S.B. 360, proposed MCL 445.71a and 445.85c (secs. 11a and 20c), as passed by the Senateofficial Michigan Senate Bill 360 text as passed by the Senate, Michigan Legislature

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

This bill has not been enacted and binds nothing today. Senate Bill 360 of the 2025-2026 Regular Session, as passed by the Senate on August 26, 2025 and pending in the House Committee on Government Operations, would add a new Section 11a to the Identity Theft Protection Act requiring a person or agency that owns, possesses, collects, or accesses personal information to implement and maintain reasonable security procedures.

Those procedures would have to designate a coordinator, identify internal and external risks, include safeguards addressing those risks, assess the safeguards' effectiveness, contractually require every service provider to maintain safeguards conforming to the NIST Cybersecurity Framework 2.0 or another industry-standard framework, and evaluate and adjust the procedures over time.

Reasonableness would turn on the entity's size, the amount and type of personal information involved, and the cost of the procedures relative to the entity's resources. An entity that reasonably conforms to the current NIST Cybersecurity Framework 2.0, or that is regulated by Michigan or the federal government and reasonably conforms to Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Title V, the Federal Information Security Modernization Act of 2014, or HITECH, would be deemed compliant.

The bill would also add a duty to investigate a suspected breach under proposed Section 11b. Only the Attorney General could enforce this duty, by a civil action seeking injunctive relief and a fine of up to $2,000 for a knowing failure to implement or maintain reasonable security procedures under proposed section 11a. No provision of the bill as passed by the Senate was located creating a private right of action.

What it requires

Age gating law4 instruments, 4 proposed

Research summary (130 words)

Michigan has not enacted an age-gating statute in any of the four families.

Four related Senate bills passed the Senate 20 to 17 on April 29, 2026 and are pending in the House Committee on Communications and Technology: Senate Bill 757 would restrict addictive social media feeds for minors, Senate Bill 758 would create a Michigan Kids Code age-appropriate design code, Senate Bill 759 is tie-barred to Senate Bill 758 and would amend the Michigan Consumer Protection Act to make a Kids Code violation an unfair trade practice, and Senate Bill 760 would restrict AI companion chatbots available to minors.

Separate bills on social media age verification and parental consent (House Bill 4388) and adult content age verification (Senate Bill 191) remain in committee and have not passed either chamber.

Age-appropriate design code

SB 758 (2026), Michigan Kids Code Act

Senate Bill 758, 2025-2026 Regular Sessionofficial bill text and status, Michigan Legislature

Proposed: draft date not recorded. Before the second chamber, dated 29 April 2026, as of 13 September 2026. Binds private bodies.

What this law does

Would require a covered online service provider to give a parent tools to manage a covered minor's privacy and account settings, screen time, and purchases, to collect only the personal data a covered minor needs for the service, and to bar profiling, dark patterns, and personalized-feed recommendations directed at a covered minor absent the minor's own request.

Does not take effect unless Senate Bill 759 is also enacted; passed the Senate 20 to 17 on April 29, 2026 and is pending in the House Committee on Communications and Technology.

Note and primary source

SB 759 (2026), Michigan Consumer Protection Act amendment (Kids Code Act enforcement)

Senate Bill 759, 2025-2026 Regular Session (amending MCL 445.903)official bill text and status, Michigan Legislature

Proposed: draft date not recorded. Before the second chamber, dated 29 April 2026, as of 13 September 2026. Binds private bodies.

What this law does

Would amend the Michigan Consumer Protection Act to add violating the Michigan Kids Code Act (Senate Bill 758) to the Act's list of unfair, unconscionable, or deceptive trade practices, arming the Consumer Protection Act's existing private right of action and the Attorney General's enforcement powers for a Kids Code violation.

Tie-barred to Senate Bill 758, which does not take effect unless this bill is also enacted; passed the Senate 20 to 17 on April 29, 2026 and is pending in the House Committee on Communications and Technology.

Note and primary source

SB 760 (2026), Leading Ethical AI Development for Kids Act

Senate Bill 760, 2025-2026 Regular Sessionofficial bill text and status, Michigan Legislature

Proposed: draft date not recorded. Before the second chamber, dated 29 April 2026, as of 13 September 2026. Binds private bodies.

What this law does

Would bar a chatbot operator from making an advanced chatbot, a generative AI system with a natural language interface that provides ongoing, adaptive responses, available to a minor if it could foreseeably undermine the minor's safety, wellbeing, or development, and would restrict data collection, companionship-simulating design features, and training the chatbot on a minor's inputs absent the minor's parent or guardian's written consent. Passed the Senate 20 to 17 on April 29, 2026; pending in the House Committee on Communications and Technology.

Note and primary source

Social media and minors

SB 757 (2026), Stop Addictive Feeds Exploitation for Kids Act

Senate Bill 757, 2025-2026 Regular Sessionofficial bill text and status, Michigan Legislature

Proposed: draft date not recorded. Before the second chamber, dated 29 April 2026, as of 13 September 2026. Binds private bodies.

What this law does

Would bar a covered operator of an addictive internet-based service or application from providing an addictive feed, a feed that recommends or prioritizes user-generated media based on the user or the user's device, to a minor unless the operator has determined the user is not a minor or has obtained verifiable parental consent, and bars sending addictive feed notifications to a minor overnight or during school hours.

Passed the Senate 20 to 17 on April 29, 2026 in its second substitute; pending in the House Committee on Communications and Technology.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.