Law / United States / Ohio

Ohio

United States law applies in Ohio Ohio is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Ohio, described on this page below, applies here too.

7 of 10 named instruments researched to a stage, across five of the six areas of law we track: 4 in force, 2 proposed and 1 repealed, withdrawn or blocked. As of 17 September 2026.

When they take effect5 of 7 carry a date, 2 do not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 2 instruments (2 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 1 instrument (1 repealed, withdrawn or blocked) 2025: 1 instrument (1 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 1
  3. Scraping law 1
  4. Cybersecurity law 1
  5. Age gating law 2
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 proposed

Research summary (327 words)

Ohio has not enacted an AI-specific statute binding a private actor as of the date shown.

Its one enacted AI-specific provision, Ohio Rev. Code § 3301.24 (created by the FY2026-27 biennial budget act, House Bill 96, effective September 30, 2025), requires the Department of Education and Workforce to publish a model AI-use policy and requires public school districts, community schools, and STEM schools to adopt one; it binds only those government bodies and imposes no duty on a private developer or deployer, so it is not catalogued here.

The most advanced private-facing measure is Senate Bill 163 (136th General Assembly), which passed the Senate unanimously on May 20, 2026 and, as of the date shown, remains in the House Technology and Innovation Committee, not yet enacted.

As passed by the Senate, it would require a generative AI system publicly accessible to Ohio consumers to carry a visible watermark and embedded provenance data on generated images and video, ban knowingly removing that watermark or knowingly distributing fully AI-generated content with false authenticity claims, and separately expand Ohio's child-exploitation statutes (§§ 2907.321 to .323) to reach a computer-generated or artificially generated depiction of a minor, including a "depiction of a purported minor" that a reasonable person would believe shows an actual minor but that may or may not actually do so, while also creating a new prohibition, inside the existing identity-fraud statute (§ 2913.49), on creating, using, or disseminating a nonconsensual AI-generated "replica" of a real person's voice, image, or likeness to induce a financial decision, damage a reputation, or depict the person in nudity or sexual conduct.

Ohio has not enacted an election-deepfake disclosure statute: a tally published in January 2026 counted Ohio among a small number of states with no deepfake-specific election law of any kind, and Ohio's own pending bills on the subject, including House Bill 367 of the 135th General Assembly and House Bill 185 of the 136th General Assembly, have not passed either chamber.

AI prohibited practices

S.B. 163, AI-Generated Child Sexual Abuse Material and Nonconsensual Replica Prohibitions

Ohio Rev. Code §§ 2907.321 2907.322, 2907.323, and 2913.49, as proposed to be amended by S.B. 163, 136th General Assembly (2025-2026 Session)bill text as passed by the Ohio Senate, Ohio Legislature (not yet enacted)

Proposed: draft date not recorded. Before the second chamber, dated 27 May 2026, as of 12 September 2026. Binds public and private bodies.

What this law does

This measure has passed the Ohio Senate but not the House, and binds nobody yet; what follows is what it would prohibit if enacted in its Senate-passed form. Ohio's child-exploitation statutes currently reach only material showing an actual minor.

As passed by the Senate, §§ 2907.321 to .323 would be amended to add a computer-generated or artificially generated depiction of a minor, and to add a "depiction of a purported minor," defined as a visual representation that appears to depict an actual minor that a reasonable person would believe depicts or represents an actual minor, but that may or may not actually depict a real child; this would reach material generated entirely by artificial intelligence with no real child involved at all, without changing the existing felony-degree structure for these offenses.

Separately, § 2913.49 (Ohio's identity-fraud statute) would be amended to add a "replica of a person's persona," a modified or fabricated version of an individual's voice, photograph, image, likeness, or distinctive appearance created or presented so that it appears to be the individual's authentic persona, including one produced in whole or in part by a generative AI system; new prohibitions would bar creating or using such a replica, without the depicted person's consent, to induce a financial decision or extend credit, to damage a person's or entity's reputation, or, where the depicted person is not a minor or impaired person, to depict them in nudity, sexual activity, or other obscene material.

The bill does not extend a civil action of its own to the new financial-inducement or reputational-harm replica prohibitions: the existing civil action for persons injured by a criminal act (R.C. 2307.60) remains available only for a violation of the identity-theft provisions in divisions (B), (D), or (E) of the amended section, which already reach a replica used with intent to defraud, and the new civil action added by this measure (R.C. 2307.66) reaches only the nonconsensual sexual or nude replica prohibition. The provider or developer of the underlying AI technology is excluded unless it is itself the violator.

What it requires

AI transparency

S.B. 163, AI-Generated Content Watermark and Provenance Mandate

Ohio Rev. Code §§ 1349.13 and 1349.14, as proposed by S.B. 163, 136th General Assembly (2025-2026 Session)bill text as passed by the Ohio Senate, Ohio Legislature (not yet enacted)

Proposed: draft date not recorded. Before the second chamber, dated 27 May 2026, as of 12 September 2026. Binds private bodies.

What this law does

This measure has passed the Ohio Senate but not the House, and binds nobody yet; what follows is what it would require if enacted in its Senate-passed form.

A "covered provider," a person or entity that creates, codes, or otherwise produces a generative AI system publicly accessible to Ohio consumers for personal use, would have to program the system to place a distinctive watermark on any image or video it generates that informs the user the content was AI-generated, and to embed provenance data in content the system creates; business-to-business use of a generative AI system for an otherwise lawful purpose is excluded.

It would be a violation, done knowingly and with intent to deceive a third party, to remove a required watermark or to distribute content fully generated by a generative AI system with false information about its authenticity. A person aggrieved by such a violation could bring a civil action for damages, but only after first filing a complaint with the Attorney General and the Attorney General not filing its own action within six months.

The Attorney General could separately seek injunctive relief for a violation of the watermark or false-authenticity bans, and a civil penalty of up to $10,000 specifically for a violation of the watermark-removal ban.

What it requires

Privacy law1 instrument, 1 in force

Research summary (227 words)

Ohio has no comprehensive consumer personal-data-protection statute; two 2026-session bills, House Bill 801 (the Ohio Privacy Act) and House Bill 807, remain in committee. Ohio's breach notification statute is Ohio Rev. Code Sec. 1349.19.

A person that owns or licenses computerized data including personal information must disclose a breach to an affected Ohio resident in the most expedient time possible and no later than 45 days following discovery, and, once a single breach affects more than 1,000 residents, to every nationwide consumer reporting agency.

Personal information is limited to a name combined with a Social Security number, a driver's license or state identification card number, or a financial account, credit, or debit card number with an access code, and it excludes information lawfully available to the general public from government records or widely distributed media; it carries no biometric, genetic, or student-data element.

Ohio's general definition of person, incorporated by cross-reference and narrowed to a business entity that conducts business in Ohio, does not include a state agency or other governmental body, so the notification duty binds only private actors. The Attorney General has exclusive authority to investigate and bring a civil action for a violation, with escalating per-day civil penalties, and the statute creates no private right of action.

Separately, Ohio Rev. Code ch. 1354 provides a voluntary cybersecurity-framework safe harbor rather than an independent duty.

Breach notification

Security Breach Notification Act

Ohio Rev. Code Sec. 1349.19official Ohio statute text, Ohio Revised Code section 1349.19, codes.ohio.gov

In force since 30 March 2007. Binds private bodies.

What this law does

Any person that owns or licenses computerized data including personal information must disclose a breach of the security of the system to an affected Ohio resident, in the most expedient time possible and no later than 45 days following discovery, subject to a law-enforcement delay.

Personal information is a name combined with a Social Security number, a driver's license or state identification card number, or a financial account, credit, or debit card number with an access code, and excludes information lawfully available to the general public from government records or widely distributed media; it carries no biometric, genetic, or student-data element.

Person has the meaning given in Ohio Rev. Code Sec. 1.59, an individual, corporation, business trust, estate, trust, partnership, or association with no government or governmental subdivision named, except that a business entity counts as a person only if it conducts business in Ohio, so this duty binds private actors, not the state or its political subdivisions.

A financial institution already subject to federal breach-notice requirements and a Health Insurance Portability and Accountability Act (HIPAA) covered entity are each exempt from this section. Once a single breach affects more than 1,000 Ohio residents, the person must also notify every nationwide consumer reporting agency without unreasonable delay.

The Attorney General has exclusive authority under Ohio Rev. Code Sec. 1349.192 to investigate and bring a civil action for a violation, with a civil penalty of up to $1,000 per day rising to $5,000 per day after 60 days and $10,000 per day after 90 days of an intentional or reckless violation, and the statute creates no private right of action.

Most recently amended by Senate Bill 126 (126th General Assembly), effective March 30, 2007; secondary reporting describes the original enactment as House Bill 104 (126th General Assembly), signed 2005, not independently confirmed against primary text.

What it requires

Scraping law1 instrument, 1 in force

Research summary (186 words)

Ohio diverges from the federal baseline through Ohio Rev. Code § 2913.04(B), a computer-misuse statute that reaches any access to a computer, computer network, cable service, or telecommunications service without the owner's consent or beyond the scope of that consent, with no requirement of fraudulent intent, malicious intent, or deceptive means; the base offense is a felony of the fifth degree regardless of the value involved, which is stricter on its face than a peer statute like Virginia's malicious-intent-or-deceptive-means standard.

No Ohio case addressing this statute's application to automated collection of a public web page has been located. Ohio has not enacted a comprehensive consumer data-privacy statute carrying a publicly-available-information exemption comparable to Virginia's VCDPA; the only Ohio data-privacy statute researched for this jurisdiction is the Security Breach Notification Act, filed under the privacy topic.

Copyright, text-and-data-mining, and database rights over scraped Ohio content are federal only. Terms-of-service enforceability rests on ordinary Ohio contract law, with no statutory provision either preserving or displacing it and no Ohio case addressing browsewrap versus clickwrap for a scraping dispute specifically. robots.txt carries no independent legal weight under Ohio law.

Computer misuse

Unauthorized use of computer, cable, or telecommunication property

Ohio Rev. Code § 2913.04official statute text, Ohio Revised Code (codes.ohio.gov)

In force since 23 March 2018. Binds public and private bodies.

What this law does

Division (B) makes it unlawful for any person, in any manner and by any means, including but not limited to computer hacking, to knowingly gain access to, attempt to gain access to, or cause access to be gained to a computer, computer system, computer network, cable service, cable system, telecommunications device, telecommunications service, or information service without the consent of, or beyond the scope of the express or implied consent of, the owner or another person authorized to give consent.

"Gain access" is defined elsewhere in the chapter to include approaching, instructing, communicating with, storing data in, retrieving data from, or otherwise making use of any resources of a computer, computer system, or computer network, which reaches ordinary automated retrieval of a public page; no malicious intent, deceptive means, or fraudulent purpose is required for the base offense. The base violation of division (B) is a felony of the fifth degree regardless of value.

Two independent factors escalate the degree, and the higher of the two applicable results controls: committing the violation for the purpose of devising or executing a scheme to defraud, obtaining property or services by false pretenses, or committing another criminal offense raises it to a felony of the fourth degree where the value of the property or services or the loss is at least $7,500 and less than $150,000, and to a felony of the third degree at $150,000 or more; and the victim being an elderly person or a disabled adult raises it, independent of any fraud purpose, to a felony of the fourth degree at $1,000 to $7,500 in value or loss, a felony of the third degree at $7,500 to $37,500, and a felony of the second degree at $37,500 or more.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (517 words)

Ohio's product-security and cyber-resilience posture rests on one enacted state statute, the Ohio Data Protection Act, Ohio Revised Code sections 1354.01 to 1354.05 (enacted by Senate Bill 220, 132nd General Assembly, effective November 2, 2018, with its definitions section 1354.01 last amended by House Bill 66, 132nd General Assembly, effective April 5, 2019), which gives a covered entity, any business that accesses, maintains, communicates, or processes personal information or restricted information in or through a system located in or outside Ohio, an affirmative defense to a tort claim alleging that a failure to implement reasonable information security controls caused a data breach, if the covered entity voluntarily creates, maintains, and complies with a written cybersecurity program that reasonably conforms to a named industry framework (the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53 and 800-53A, FedRAMP, the CIS Critical Security Controls, or the ISO/IEC 27000 family, or, for an already-regulated entity, the entirety of Health Insurance Portability and Accountability Act (HIPAA)'s security rule, Gramm-Leach-Bliley Act Title V, FISMA, or HITECH, or the PCI Data Security Standard paired with one of the first group).

This is a safe harbor rather than a duty: no Ohio statute requires any business to build a cybersecurity program, and section 1354.04 bars any private right of action, including a class action, with respect to any act or practice the chapter regulates, so no regulator administers it and nobody can sue to compel one; a covered entity's only exposure is a tort claim brought under other law, against which the chapter's affirmative defense is a shield it may or may not have earned in advance.

No enacted Ohio statute sets security requirements a connected device or software product must otherwise meet to be placed on the market, and none was located imposing a general, sector-neutral duty on a private business to report an exploited vulnerability or a security incident to a state authority.

Ohio does bind one sector directly: Ohio Revised Code Chapter 3965, Cybersecurity Requirements for Insurance Companies (enacted by Senate Bill 273, 132nd General Assembly, effective March 20, 2019, adopting the NAIC Insurance Data Security Model Law), requires a licensee, any person licensed, authorized, or registered under Ohio's insurance laws including an insurer, to maintain a comprehensive written information security program, investigate a cybersecurity event, and notify the superintendent of insurance within three business days of certain cybersecurity events, enforced through the superintendent's examination and investigation power under section 3965.05; compliance with Chapter 3965 is itself deemed, by that chapter's own section 3965.02(J), to satisfy the Data Protection Act's reasonable-conformance test.

Because Chapter 3965's bound party, an insurance licensee, is a role the LexLint activity vocabulary cannot yet express, it is deferred rather than flagged on a guess (#6740): no instrument for it is filed here, and it is recorded in this summary so a reader knows it exists.

Ohio's breach-notification duty, Revised Code section 1349.19, the Security Breach Notification Act, is already this jurisdiction's privacy row rather than repeated here: the Data Protection Act's own definition of personal information incorporates that section's definition by reference, and Chapter 3965's insurer-specific consumer notification likewise routes through it.

Security baseline statutes

Ohio Data Protection Act, cybersecurity program safe harbor

Ohio Rev. Code sections 1354.01 to 1354.05 (enacted by Senate Bill 220, 132nd General Assembly, effective November 2, 2018; section 1354.01 last amended by House Bill 66, 132nd General Assembly, effective April 5, 2019)Official statute text, Ohio Revised Code Chapter 1354, Ohio Laws (Legislative Service Commission)

In force since 2 November 2018. Binds private bodies.

What this law does

The Ohio Data Protection Act, sections 1354.01 to 1354.05 of the Ohio Revised Code, extends an affirmative defense to any cause of action sounding in tort that is brought under the laws of this state or in the courts of this state and that alleges that the failure to implement reasonable information security controls resulted in a data breach concerning personal information, to a covered entity that creates, maintains, and complies with a written cybersecurity program that reasonably conforms to an industry recognized cybersecurity framework.

A covered entity is a business that accesses, maintains, communicates, or processes personal information or restricted information in or through one or more systems, networks, or services located in or outside this state, and the defense reaches personal information and restricted information together where the covered entity's program covers both.

The scale and scope of that program is appropriate if it is based on the size and complexity of the covered entity, the nature and scope of its activities, the sensitivity of the information to be protected, the cost and availability of tools to improve information security and reduce vulnerabilities, and the resources available to the covered entity.

Reasonable conformance is satisfied by the current version of the framework for improving critical infrastructure cybersecurity developed by NIST, NIST special publication 800-171, NIST special publications 800-53 and 800-53a, the FedRAMP security assessment framework, the CIS critical security controls, or the ISO/IEC 27000 family, alone or in combination.

Alternatively, reasonable conformance is satisfied by reasonably conforming to the entirety of the current version of the Health Insurance Portability and Accountability Act (HIPAA) security rule, Gramm-Leach-Bliley Act Title V, the Federal Information Security Modernization Act of 2014, or the Health Information Technology for Economic and Clinical Health Act for a covered entity already regulated under one of them, or by complying with the PCI data security standard together with one of the first group's frameworks.

A covered entity must reasonably conform to a revised or amended framework not later than one year after its publication. This is an optional safe harbor and not a duty: sections 1354.01 to 1354.05 shall not be construed to provide a private right of action, including a class action, with respect to any act or practice regulated under those sections, so no covered entity can be sued for lacking a program and no state regulator administers this chapter.

An insurer or other licensee that meets Ohio's separate insurance-sector cybersecurity law, Ohio Revised Code Chapter 3965, is deemed by that chapter's own section 3965.02(J) to have a program that reasonably conforms to an industry recognized cybersecurity framework for purposes of this safe harbor.

What it requires

Age gating law2 instruments, 1 in force, 1 repealed, withdrawn or blocked

Research summary (120 words)

Ohio has enacted laws in two families.

The Parental Notification by Social Media Operators Act (2023) requires parental consent for minors under 16 to hold social media accounts; it was permanently enjoined by a federal district court in April 2025, but the Sixth Circuit reversed that ruling on June 18, 2026 and instructed the lower court to enter judgment for the state, so the law is poised to become enforceable once the appellate mandate issues (NetChoice had until July 16, 2026 to seek rehearing).

A separate adult content age verification law took effect September 30, 2025, though the Attorney General's office has found most major pornography sites are not complying, citing an interactive-computer-service exemption lawmakers are now working to close.

Adult content age verification (AV)

HB 96, Internet Age Verification for Obscenity or Material Harmful to Juveniles

Ohio Rev. Code sections 1349.10 and 1349.101official statute text

In force 12 months, effective 30 September 2025. Binds private bodies.

What this law does

Any entity that sells, disseminates, or presents material or a performance that is obscene or harmful to juveniles on the internet must verify that a user, and any person creating an account or subscription, is 18 or older using reasonable methods such as government-issued identification, a commercial age verification system, or transactional data, and must reverify age every two years.

The law exempts entities that qualify as interactive computer services under federal law, an exemption the Attorney General says most major pornography sites are relying on to avoid compliance, and which lawmakers were considering narrowing as of early 2026.

Note and primary source

Social media and minors

HB 33, Parental Notification by Social Media Operators Act

Ohio Rev. Code section 1349.09official statute text and appellate opinion

Enjoined: enforcement paused by a court, effective 15 January 2024. Binds private bodies.

What this law does

Operators of social media platforms directed to or reasonably expected to be accessed by children must obtain verifiable parental consent, through methods such as a signed form, credit card verification, phone or video call, or government ID, before allowing a child under 16 to create an account. Operators must also disclose available content moderation and parental control features.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.