Law / United States / Nevada

Nevada

United States law applies in Nevada Nevada is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Nevada, described on this page below, applies here too.

All 12 named instruments researched to a stage, across four of the six areas of law we track: 6 in force and 6 enacted but not yet in force. As of 14 September 2026.

When they take effect6 of 12 carry a date, 6 do not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 4 instruments (4 in force) 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 5
  2. Privacy law 4
  3. Scraping law 1
  4. Cybersecurity law 2
  5. Age gating law none researched
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law5 instruments, 5 in force

Research summary (348 words)

Nevada's 2025 legislative session enacted a cluster of AI-transparency and AI-prohibited-practices provisions layered onto existing NRS chapters, while two further 2025 bills touching AI in health-insurance claims handling and a broad AI-company registration framework did not become law.

NRS 433.567 bars an artificial intelligence provider, or an uncredentialed natural person, from representing that an AI system can provide, or from offering an AI system that provides, professional mental or behavioral health care, backed by a civil penalty of up to $15,000 per violation; NRS 629.610, in the same act, separately restricts a licensed mental or behavioral health provider's own direct clinical use of AI with a patient, enforced through professional discipline rather than a civil fine.

NRS 294A.3493 requires a clear and conspicuous disclosure on a paid political communication that includes AI-generated or manipulated synthetic media, enforceable by the depicted candidate through an injunction action in district court.

NRS 200.770 and 200.780 extend Nevada's existing unlawful-dissemination-of-intimate-image statute to a photorealistic, digital or computer-generated depiction of an identifiable person, and NRS 200.700 and 200.725 extend the state's child sexual abuse material statutes to a visual depiction created by artificial intelligence that is indistinguishable from an actual minor, both as felony crimes binding any person.

Separately, the same 2025 act that created NRS 433.567 and 629.610 also directs the Department of Education, at NRS 391.297, to adopt a policy governing school counselors', psychologists' and social workers' own use of artificial intelligence with pupils; because that duty binds only a government body's own use of AI, it is not catalogued here as an instrument.

Two other 2025 bills did not become law: SB 128, which would have barred a health or dental insurer, or a self-insured local government plan, from relying solely on AI to deny or modify a prior-authorization request, passed both chambers but was vetoed by the Governor and is not reflected in the currently codified prior-authorization statute; SB 199, a broad bill that would have required registration of AI-as-a-service companies with the Bureau of Consumer Protection, among other AI-related duties, was referred to committee and did not pass.

AI prohibited practices

AB 406 (2025), AI mental and behavioral health care provider and marketing prohibitions

Nev. Rev. Stat. 433.567official text, Nevada Revised Statutes (leg.state.nv.us)

In force since 1 July 2025. Binds public and private bodies.

What this law does

An artificial intelligence provider may not represent, or program an AI system to represent, that the system is capable of providing professional mental or behavioral health care, that a user may interact with the system to obtain such care, or that the system or any component of it is a therapist, counselor, psychiatrist or similar provider; nor may a provider make available an AI system specifically programmed to provide a service that would constitute the practice of professional mental or behavioral health care if provided by a natural person.

A natural person who lacks a valid credential to practice professional mental or behavioral health care in Nevada may not represent himself or herself as qualified to do so, including by using titles such as therapist, psychotherapist or counselor.

The Nevada Division of Public and Behavioral Health, Department of Health and Human Services, may investigate potential violations and bring a civil action to recover a civil penalty of up to $15,000 per violation; the section does not prohibit self-help materials that do not purport to offer professional care, or an AI system a licensed provider uses for administrative support consistent with NRS 629.610.

What it requires

SB 213 (2025), AI-generated and digitally altered intimate images

Nev. Rev. Stat. 200.770, 200.780official text, Nevada Revised Statutes (leg.state.nv.us)

In force 12 months, effective 1 October 2025. Binds public and private bodies.

What this law does

Nevada's existing unlawful-dissemination-of-intimate-image crime, NRS 200.780, already reached a photograph, film, videotape or other recorded image; a 2025 amendment to the definition of "intimate image" at NRS 200.770 added a photorealistic, digital, computer, or computer-generated image that a reasonable person would believe depicts an identifiable person's genitals, anus, or fully exposed female nipple, or an identifiable person engaged in sexual conduct.

A person who knowingly distributes such an AI-generated or digitally altered image of an identifiable person, created in a way that would lead a reasonable person to believe it is an actual depiction of that person, without the person's prior consent, is guilty of a category D felony; a person convicted is not required to register as a sex offender.

The enrolled act contains no specifically prescribed effective date, so Nevada's default rule (effective the October 1 following passage where none is prescribed) fixes the commencement at October 1, 2025, correcting an earlier tracker's claim of January 1, 2026.

What it requires

SB 263 (2025), AI-generated and computer-generated child sexual abuse material

Nev. Rev. Stat. 200.700, 200.725official text, Nevada Revised Statutes (leg.state.nv.us)

In force 12 months, effective 1 October 2025. Binds public and private bodies.

What this law does

A 2025 amendment to NRS 200.700 expanded the definition of "computer-generated child sexual abuse material" to include a visual representation appearing to depict a child as the subject of a sexual portrayal or engaging in sexual conduct where the representation is created by the use of artificial intelligence or other computer technology capable of processing and interpreting specific data inputs, and is indistinguishable from an actual minor to an ordinary viewer.

NRS 200.725 makes it unlawful to knowingly prepare, advertise or distribute computer-generated child sexual abuse material; a first offense is a category B felony (one to fifteen years' imprisonment, a fine of up to $15,000, or both), and a subsequent offense is a category A felony (ten years to life with the possibility of parole, and a fine of up to $15,000).

The enrolled act contains no specifically prescribed effective date for these provisions, so Nevada's default rule (effective the October 1 following passage where none is prescribed) fixes the commencement at October 1, 2025.

What it requires

AI sector rules

AB 406 (2025), licensed provider restriction on direct clinical use of AI

Nev. Rev. Stat. 629.610official text, Nevada Revised Statutes (leg.state.nv.us)

In force since 1 July 2025. Binds public and private bodies.

What this law does

A Nevada-licensed provider of mental and behavioral health care (psychiatrists, psychologists, licensed social workers, psychiatric nurses, marriage and family therapists, and certain counselors) may not use an artificial intelligence system in connection with providing professional mental and behavioral health care directly to a patient, except that the provider may use AI for administrative support such as scheduling, records management, billing, operational data analysis, and organizing session notes, subject to compliance with federal and Nevada health-privacy law and to the provider's own independent review of any AI-generated report or data.

A provider who violates this section is guilty of unprofessional conduct and subject to disciplinary action by the licensing board, agency or other entity that licenses or certifies the provider.

What it requires

AI transparency

AB 73 (2025), AI-manipulated media disclosure in paid political communications

Nev. Rev. Stat. 294A.3493official text, Nevada Revised Statutes (leg.state.nv.us)

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

A paid communication made in support of or opposition to a candidate, group of candidates or political party, or that solicits campaign contributions, must carry a clear and conspicuous disclosure reading "This (image/video/audio) has been manipulated" whenever it includes synthetic media, meaning an image, audio or video recording intentionally manipulated using generative adversarial network techniques, artificial intelligence or generative AI to realistically but falsely depict a person's appearance, speech or conduct.

A video disclosure must run for the entire video; an audio disclosure must be read clearly at the start, at the end, and, for audio longer than two minutes, at intervals of no more than two minutes.

A depicted candidate whose likeness appears in a non-disclosing communication may seek an injunction or other equitable relief in district court against whoever made or paid for it; the section does not impose liability on a streaming, interactive computer, cloud or internet service provider, a broadcaster or cable or satellite operator, a programmer or producer of broadcast content, or a publisher of synthetic media as satire or parody.

What it requires

Privacy law4 instruments, 4 enacted but not yet in force

Research summary (221 words)

Nevada has no comprehensive personal-data-privacy statute. NRS chapter 603A instead layers three sectoral regimes: a general breach-notification duty (NRS 603A.220), an Online Privacy Notice regime that lets a consumer opt out of the sale of narrowly defined covered information to data brokers and website operators (NRS 603A.300-360), and a Consumer Health Data chapter granting access, disclosure-list, cessation, and deletion rights over health-related data (NRS 603A.400-550).

Nevada's only enacted biometric-data definition sits inside the health-data chapter and reaches a voiceprint, faceprint, or other biometric identifier only when it is related to a health condition, diagnosis, or treatment; a general-purpose biometric identifier collected for identification, authentication, or marketing has no Nevada statutory home at all, and the definition carries no exclusion at all for data derived from a photograph, video, or audio recording.

The opt-out chapter expressly denies a private right of action with no deeming route around it; the health-data chapter both deems a violation a deceptive trade practice and expressly denies a private right of action in the same section; the breach chapter grants a data collector its own civil action against whoever caused the breach and is deemed a deceptive trade practice without an express denial, which combines with a narrow elderly-or-disabled civil action statute to give that class, but not the general public, an indirect private right of action.

Breach notification

Security breach of personal information, notification

NRS 603A.220official Nevada statute text, NRS chapter 603A, Nevada Legislature website

Commencement not set. Binds public and private bodies.

What this law does

A data collector that owns or licenses computerized data including personal information must disclose a breach of security to an affected Nevada resident in the most expedient time possible and without unreasonable delay, with no fixed numeric deadline, unlike every other statute in this batch. Consumer-reporting-agency notice is required once more than 1,000 persons are notified at one time; no requirement to notify the Nevada Attorney General appears in the text read.

"Personal information" for breach purposes never includes biometric data, so a biometric-only breach does not trigger this duty. A separate section grants a data collector its own civil action against whoever caused the breach, which is not a consumer's private right of action.

But NRS 603A.260 deems any violation of NRS 603A.010 to 603A.290, which includes this breach duty, a deceptive trade practice under NRS 598.0903 to 598.0999, and NRS 598.0977 gives an elderly or disabled Nevada resident harmed by a deceptive trade practice a standalone civil action for actual and punitive damages and attorney's fees; that route is not excepted for this chapter the way it is for NRS 603A.550's consumer health data chapter.

So a general Nevada resident still has no private right of action for a breach-notification violation, but an elderly or disabled resident does, indirectly, through this deeming-plus-UDAP chain. The section's own history note ("Added to NRS by 2005, 2504; A 2023, 3481") gives no printed effective date, so none is recorded here.

What it requires

Data subject rights

Consumer Health Data, access, disclosure, and deletion rights

NRS 603A.500-515official Nevada statute text, NRS chapter 603A, Nevada Legislature website

Commencement not set. Binds private bodies.

What this law does

A regulated entity processing consumer health data must give a Nevada consumer the right to access it, obtain a list of third parties it was disclosed to, stop its collection, sharing, or sale, and delete it, sector-scoped to health data rather than a general personal-data right. A controller must respond within 45 days, with one 45-day extension available, and must provide two free responses per consumer per year.

This provision is in force under the current codified text; no dated original commencement is established, so no effective date is recorded here.

What it requires

Online Privacy Notice, opt-out of sale

NRS 603A.300-360official Nevada statute text, NRS chapter 603A, Nevada Legislature website

Commencement not set. Binds private bodies.

What this law does

An operator of a commercial internet website or online service directed at Nevada residents, or a data broker, must post a privacy notice and, on request, may not sell a Nevada consumer's covered information after the consumer directs it not to.

"Covered information" is limited to name, address, email, phone, Social Security number, and similar contact identifiers plus a catch-all for information maintained with an identifier in personally identifiable form; it never reaches biometric or sensitive-category data as a class. A first-time failure to comply may be cured within 30 days without violating the statute.

This provision is in force under the current codified text; no dated original commencement is established, so no effective date is recorded here.

What it requires

Sensitive categories

Consumer Health Data, biometric data definition

NRS 603A.415, 603A.430official Nevada statute text, NRS chapter 603A, Nevada Legislature website

Commencement not set. Binds private bodies.

What this law does

Nevada's only enacted biometric-data definition binds a controller only when the biometric data is related to a health condition, diagnosis, treatment, or similar information, making it "consumer health data" under this chapter; it does not operate as a general biometric-privacy statute.

"Biometric data" is defined broadly, including imagery of a fingerprint, palm print, hand print, scar, bodily mark, tattoo, voiceprint, face, retina, iris, or vein pattern, and keystroke or gait patterns or rhythms that contain identifying information, and unlike New Hampshire's, Kentucky's, Rhode Island's, and Vermont's definitions, it carries no exclusion for a photograph or recording at all, in either direction: imagery of a person's face is itself named as a form of biometric data.

A general-purpose voiceprint or faceprint collected for identification, authentication, or marketing, with no connection to health status, has no Nevada statutory home at all.

What it requires

Scraping law1 instrument, 1 in force

Research summary (210 words)

Nevada's computer-crimes statute departs from federal law mainly in its remedy structure rather than its authorization test: NRS 205.4765 bars a person from knowingly, willfully and without authorization modifying, damaging, disclosing, using, transferring, concealing, taking, retaining, copying or accessing computer data, a program or a network, a bare authorization test close to the Computer Fraud and Abuse Act (CFAA)'s own, but Nevada layers on both a private civil action for the victim (damages, punitive damages, and attorney's fees, regardless of any parallel criminal charge) and Attorney General or district attorney injunctive enforcement.

The statute defines "access" broadly and presumes an employee authorized to use an employer's own systems, but neither the statute nor any located Nevada case addresses how "authorization" applies to a member of the public collecting data from an unauthenticated public web page; no Nevada court decision addressing automated collection or scraping specifically has been located.

Nevada has no computer-crimes carve-out or statement preserving a contract's or license's terms comparable to Virginia's; ordinary Nevada contract law governs terms-of-service enforceability, and no Nevada case on browsewrap versus clickwrap enforceability for a scraping dispute was located.

Nevada has no state-specific copyright, text-and-data-mining, or database-right statute, and robots.txt carries no independent legal weight under Nevada law; those questions are federal only and are not restated here.

Computer misuse

Unlawful acts regarding computers, private action and enforcement

Nev. Rev. Stat. Ann. 205.4765 to 205.513official text, Nevada Revised Statutes (leg.state.nv.us)

In force since 1 October 1983. Binds public and private bodies.

What this law does

Section 205.4765 makes it unlawful for a person, knowingly, willfully and without authorization, to modify, damage, destroy, disclose, use, transfer, conceal, take, retain, copy, or obtain or attempt to obtain access to data, a program, equipment, or a computer, system or network; a bare violation is a misdemeanor, escalating to a category C felony carrying a fine of up to $100,000 where the act was committed to defraud, caused response costs or damage over $500, or interrupted a public service.

Section 205.477 separately punishes knowing, willful, malicious and unauthorized interference with or denial of access to a computer, system or network as a gross misdemeanor. Section 205.509 presumes an employee authorized to access his or her employer's own systems, and the chapter does not otherwise define how authorization is read for a member of the public accessing an unauthenticated public page.

Section 205.511 gives any victim of a crime described in this range a private civil action for response costs, loss or injury, punitive damages, and attorney's fees, independent of any criminal charge or conviction, and section 205.513 lets the Attorney General or the appropriate district attorney seek an injunction.

What it requires

Cybersecurity law2 instruments, 2 enacted but not yet in force

Research summary (413 words)

Nevada's private-sector security-of-personal-information law rests on two enacted provisions inside NRS Chapter 603A, Security and Privacy of Personal Information: NRS 603A.210, which requires any data collector, a term defined to include a governmental agency, institution of higher education, corporation, financial institution, retail operator, or other business entity or association, that maintains records containing a Nevada resident's personal information to implement and maintain reasonable security measures against unauthorized access, acquisition, destruction, use, modification, or disclosure, with an added CIS Controls or NIST-standards duty on a data collector that is itself a governmental agency; and NRS 603A.215, which requires a data collector that accepts a payment card to comply with the current PCI Data Security Standard and, for any other data collector, to encrypt personal information transferred electronically or moved on a data storage device beyond its controls, while conditioning a liability shield against breach damages on compliance with the section and the absence of the data collector's own gross negligence or intentional misconduct.

Nevada has no enacted statute setting security requirements a software product or connected device must meet before or after it reaches the market, and no general private-sector duty to report an exploited vulnerability or a security incident to an authority or to users; the state's own incident-reporting and cybersecurity-services framework, administered by the Office of Information Security and Cyber Defense within the Governor's Technology Office, binds only state agencies and elected state officers and belongs with this jurisdiction's government-accountability material rather than as a row in this profile's private-sector scope.

No sector-specific cyber-resilience regime reaching a digital service the LexLint activity vocabulary can express was located for Nevada.

Both baseline-security instruments are enforced the same way: NRS 603A.260 deems a violation of NRS 603A.010 to 603A.290, inclusive, a deceptive trade practice under NRS 598.0903 to 598.0999, which the Commissioner of the Consumer Affairs Unit, the Director of the Department of Business and Industry, a county district attorney, or the Attorney General may pursue for a civil penalty of up to $15,000 per willful violation and, on the same deeming chain, criminal exposure ranging from a misdemeanor up to a category B felony depending on the dollar loss involved; the general public has no private right of action, but NRS 598.0977 gives an elderly or disabled Nevada resident harmed by the deemed deceptive trade practice a standalone civil action for actual and punitive damages and attorney's fees.

Nevada's breach-notification duty, NRS 603A.220, is already this jurisdiction's privacy row rather than repeated here.

Security baseline statutes

Security measures for a data collector accepting payment cards, encryption duty, and conditioned liability shield

NRS 603A.215Official statute text, Nevada Revised Statutes chapter 603A, Nevada Legislature website

Commencement not set. Binds private bodies.

What this law does

A data collector that accepts a payment card in connection with a sale of goods or services must comply with the current Payment Card Industry (PCI) Data Security Standard adopted by the PCI Security Standards Council, with respect to those transactions, not later than the compliance date the standard itself sets.

A data collector to which that duty does not apply must not transfer a Nevada resident's personal information through an electronic, nonvoice transmission other than a facsimile outside its secure system, and must not move a data storage device containing that personal information beyond its logical or physical controls, unless the data collector encrypts the information using a standards-body-adopted encryption technology with appropriate cryptographic key management.

A data collector that complies with this section, and whose breach was not caused by its own gross negligence or intentional misconduct, is not liable for damages for a breach of the security of the system data. The section does not reach a telecommunication provider acting solely to convey the communications of other persons.

What it requires

Security measures for data collectors maintaining personal information

NRS 603A.210Official statute text, Nevada Revised Statutes chapter 603A, Nevada Legislature website

Commencement not set. Binds public and private bodies.

What this law does

A data collector that maintains records containing the personal information of a Nevada resident must implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure.

A data collector that is a governmental agency must, to the extent practicable, additionally comply with the current CIS Controls published by the Center for Internet Security or corresponding National Institute of Standards and Technology standards for the collection, dissemination, and maintenance of those records. A contract disclosing a Nevada resident's personal information must require the recipient to implement and maintain the same reasonable-security duty.

Compliance with a state or federal law requiring greater protection for the same records is deemed compliance with this section.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.