Law / United States / Rhode Island

Rhode Island

United States law applies in Rhode Island Rhode Island is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Rhode Island, described on this page below, applies here too.
Rhode Island has 1 local jurisdiction That local jurisdiction has law of its own, on a page of its own, listed below.

14 of 16 named instruments researched to a stage, across four of the six areas of law we track: 9 in force and 5 enacted but not yet in force. As of 14 September 2026.

When they take effect8 of 14 carry a date, 6 do not.
2025: 2 instruments (2 in force) ’25 2026: 5 instruments (5 in force) 2027: 1 instrument (1 enacted but not yet in force) ’27 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 6
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law6 instruments, 3 in force, 3 enacted but not yet in force

Research summary (296 words)

Rhode Island has no general statute imposing AI-content disclosure or watermarking duties across the board, but it has enacted several sector-specific and prohibition-style AI instruments since 2025. Its child-pornography statute, in force since 2001 with 2004 amendments, already reaches a computer-generated or digitally altered depiction of a minor without a separate 2024 or 2025 AI-specific amendment, because its definition of a covered image was written in technology-neutral terms.

A 2025 amendment to the unauthorized-dissemination-of-indecent-material chapter and a new election chapter, both effective July 2, 2025, reach non-consensual synthetic intimate imagery of an identifiable adult and deceptive election synthetic media respectively, each with a private civil right of action.

Three further AI-specific chapters, an oversight-of-AI-in-mental-health-care act, a healthcare-AI-use notification act, and an AI-companion-model safety act, were reported by contemporaneous Rhode Island state-policy journalism (Rhode Island Current, Route Fifty, Providence Business News) as signed into law by Governor Dan McKee in June 2026.

Their substantive terms are confirmed directly against the enacted bill text on the Rhode Island General Assembly's own website, but the exact signing date and enrolled chapter numbers are not confirmed in a primary session-law or bill-status record, so no effective date is stated for the two acts whose own text says only that they take effect upon passage.

A broader High-Risk Artificial Intelligence Accountability Act (S 0627, 2025) did not advance past committee and was reported to have died; a Health Insurer AI Transparency Bill (S 2010, 2026) had cleared only a Senate committee vote and had not passed a chamber; neither is catalogued as an instrument here.

An Attorney General advance notice of proposed rulemaking on AI-driven automated decision-making, reported under docket 110-40-00-5, was not found at that docket on the Rhode Island Department of State's regulations site and is not described further.

AI prohibited practices

Artificial Intelligence Companion Models Act

R.I. Gen. Laws §§ 6-63-1 to 6-63-6 (S 2195, 2026 Regular Session)official bill text, Rhode Island General Assembly (webserver.rilegislature.gov)

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

Effective January 1, 2027 by the act's own terms, it is unlawful to operate or provide an "AI companion" (a system using AI, generative AI, or emotional-recognition algorithms to simulate social human interaction) unless it contains a protocol addressing possible suicidal ideation or self-harm, physical harm to others, and financial harm to others expressed by a user, including referral to crisis services.

An operator must also notify users at the start of an interaction and at least every three hours thereafter, in specified bold text or spoken form, that the AI companion is a computer program that cannot feel human emotion. A person physically or financially harmed as a result of a violation may sue in superior court for damages and equitable relief, and the Attorney General may investigate and sue under the state's deceptive trade practices chapter.

What it requires

Child pornography prohibited, computer-generated and digitally altered depictions

R.I. Gen. Laws § 11-9-1.3official text, Rhode Island General Laws (webserver.rilegislature.gov)

In force. Binds public and private bodies.

What this law does

Section 11-9-1.3 defines "child pornography" to include a visual depiction that is a digital image, computer image, or computer-generated image of a minor engaging in sexually explicit conduct, or one that has been created, adapted, or modified to display an identifiable minor engaging in such conduct, alongside the ordinary case of an actual minor's image.

This technology-neutral language, in force since 2001 and last amended in 2004, already reaches an AI-generated or AI-altered depiction without needing a dedicated 2024 or 2025 amendment; no such amendment was located. Production, transport, or reproduction of covered material is punishable by a fine of not more than $5,000 and imprisonment of not more than fifteen years, or both; mere possession is punishable by not more than $5,000 and five years, or both.

What it requires

Unauthorized dissemination of indecent material, digitally created or altered images

R.I. Gen. Laws §§ 11-64-1, 11-64-3official text, Rhode Island General Laws (webserver.rilegislature.gov)

In force since 2 July 2025. Binds public and private bodies.

What this law does

Section 11-64-3(a)(1), as amended by two 2025 public laws effective July 2, 2025, reaches a sexually explicit visual image of an identifiable adult "including any image created by a digital device or altered by digitization," language that covers a synthetic or AI-altered intimate image of a real, identifiable person alongside an unaltered photograph or recording.

Liability requires that the image was made or obtained under circumstances a reasonable person would know were meant to stay private (or was made without consent), was disseminated without the depicted person's consent, and was disseminated with knowledge or reckless disregard of likely harm, or with intent to harass, intimidate, threaten, or coerce.

A first violation is a misdemeanor (up to one year and $1,000); a second or subsequent violation is a felony (up to three years and $3,000); threatening to disclose such an image for a benefit, or demanding payment to remove one from public view, is a separate felony (up to five years and $5,000). Newsworthy, law-enforcement, legal-proceeding, and interactive-computer-service exemptions apply.

What it requires

AI sector rules

Oversight of Artificial Intelligence Technology in Mental Health Care Act

R.I. Gen. Laws §§ 40.1-5.5-1 to 40.1-5.5-6 (H 7349, Substitute A, 2026 Regular Session)House Substitute A bill text, Rhode Island General Assembly (webserver.rilegislature.gov)

Commencement not set. Binds public and private bodies.

What this law does

This act bars any individual, corporation, or entity from offering therapy or psychotherapy services in Rhode Island, including through internet-based AI, unless the services are conducted by a state-licensed professional or provider.

A licensed provider may use AI only for administrative or supplementary support (scheduling, billing, records, drafting logistics communications, tracking client progress subject to professional review), and never to make independent therapeutic decisions, conduct therapeutic communication directly with a client without an established provider relationship, or determine treatment plans.

Where a client's session is recorded or transcribed and an AI system simulating emotional attachment or bonding assists with supplementary support or therapeutic communication, the patient or their representative must be informed in writing and consent. The act's own text states it takes effect upon passage.

Contemporaneous Rhode Island state-policy reporting (Rhode Island Current, Route Fifty) describes the act as signed by Governor Dan McKee in June 2026, but the exact signing date and session-law chapter number are not confirmed in a primary session-law record.

What it requires

AI transparency

Deceptive and Fraudulent Synthetic Media in Election Communications

R.I. Gen. Laws §§ 17-30-1 to 17-30-4official text, Rhode Island General Laws (webserver.rilegislature.gov)

In force since 2 July 2025. Binds private bodies.

What this law does

Effective July 2, 2025, section 17-30-1 bars a candidate, campaign committee, party committee, or independent-expenditure person or entity from distributing, within ninety days of an election, "synthetic media" that realistically but falsely depicts a candidate's appearance, action, or speech in a way that creates a fundamentally different impression than the real, unaltered version, where the distributor knows or should know it is deceptive.

The prohibition does not apply if the media carries a disclosure that it was manipulated or generated by artificial intelligence, sized and timed as the statute specifies for visual and audio media. A depicted candidate may seek injunctive relief and sue for general or special damages plus attorney's fees, proven by clear and convincing evidence. Broadcasters, news publications that label the media as inaccurate, satire and parody, and interactive computer services are exempted.

What it requires

Use of Artificial Intelligence by Healthcare Providers Notification Act

R.I. Gen. Laws §§ 23-106-1 to 23-106-3 (H 7538, Substitute A, 2026 Regular Session)House Substitute A bill text, Rhode Island General Assembly (webserver.rilegislature.gov)

Commencement not set. Binds public and private bodies.

What this law does

This act requires any healthcare provider or healthcare facility that employs AI to document an in-person or telehealth visit to notify patients that AI was used for that purpose, and to review the AI-generated documentation for accuracy after the visit. "Healthcare facility" carries the meaning given at section 23-17-2, which reaches a facility whether public or private, so the duty binds a government-run facility as well as a private one. The act's own text states it takes effect upon passage.

Contemporaneous Rhode Island state-policy reporting describes it as signed into law alongside two related AI bills in June 2026, but the exact signing date and session-law chapter number are not confirmed in a primary session-law record.

What it requires

Privacy law5 instruments, 4 in force, 1 enacted but not yet in force

Research summary (160 words)

Rhode Island's comprehensive privacy law, the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA, R.I. Gen. Laws ch. 6-48.1), took effect January 1, 2026 from two companion 2024 bills, H 7787 and S 2500.

It applies only to for-profit entities that controlled or processed personal data of at least 35,000 customers, or 10,000 customers while deriving more than 20 percent of gross revenue from personal-data sales, a lower sale-revenue threshold than New Hampshire's or Kentucky's near-identical statutes.

RIDTPPA requires opt-in consent for sensitive data, including biometric data processed to uniquely identify a person, and gives customers access, correction, deletion, portability, and opt-out rights, enforced solely by the Attorney General with no mandatory cure period and no private right of action.

A separate breach-notification statute, the Identity Theft Protection Act of 2015 (R.I. Gen. Laws sec. 11-49.3-4), covers municipal and state agencies as well as private persons, and no private right of action was found in either statute's enforcement text.

Breach notification

Identity Theft Protection Act of 2015, notification of breach

R.I. Gen. Laws secs. 11-49.3-4, 11-49.3-5official Rhode Island statute text, R.I. General Laws chapter 11-49.3, Rhode Island General Assembly website

Commencement not set. Binds public and private bodies.

What this law does

Any municipal agency, state agency, or person that stores, owns, collects, processes, maintains, acquires, uses, or licenses data including personal information must notify affected Rhode Island residents of a breach that poses a significant risk of identity theft, within 30 days of confirmation for a state or municipal agency and within 45 days for any other person, with Attorney General and consumer-reporting-agency notice required once more than 500 residents are affected.

Reckless violations carry a penalty of up to $100 per record and knowing and willful violations up to $200 per record, brought by the Attorney General; no private right of action was found in the text read. Sections 11-49.3-4 and 11-49.3-5 both originate in P.L. 2015, ch. 138 and ch. 148; sec. 11-49.3-4's notice duty was last amended by P.L. 2023, ch. 375, sec. 1, effective June 27, 2023, while sec. 11-49.3-5's penalty provisions carry no amendment since 2015.

Neither section's own history note prints a same-page effective date for the original 2015 enactment, so no single effective date is recorded for this citation's combined range.

What it requires

Comprehensive regime

Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), general applicability

R.I. Gen. Laws ch. 6-48.1, secs. 6-48.1-2, 6-48.1-5, 6-48.1-6official Rhode Island statute text, R.I. General Laws chapter 6-48.1, Rhode Island General Assembly website

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

RIDTPPA applies only to for-profit entities conducting business in Rhode Island, or targeting products or services to Rhode Island residents, that in the preceding calendar year controlled or processed personal data of at least 35,000 customers (excluding payment-only data), or 10,000 customers while deriving more than 20 percent of gross revenue from personal-data sales.

Two companion 2024 bills, H 7787 and S 2500, produced two public laws for the same chapter (P.L. 2024, ch. 430 and ch. 453), both effective January 1, 2026.

What it requires

Data subject rights

Rhode Island Data Transparency and Privacy Protection Act, customer rights

R.I. Gen. Laws secs. 6-48.1-5, 6-48.1-6official Rhode Island statute text, R.I. General Laws chapter 6-48.1, Rhode Island General Assembly website

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

RIDTPPA gives a Rhode Island customer the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and significant-effect profiling. A controller must respond without undue delay and not later than 45 days after receipt, with one 45-day extension available, and must decide an appeal within 60 days, after which the customer may complain to the Attorney General.

What it requires

Enforcement supervision

Rhode Island Data Transparency and Privacy Protection Act, enforcement

R.I. Gen. Laws sec. 6-48.1-8official Rhode Island statute text, R.I. General Laws chapter 6-48.1, Rhode Island General Assembly website

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

A violation of RIDTPPA is a deceptive trade practice, and intentional disclosure of personal data to a shell company or otherwise in violation of the chapter carries a fine of $100 to $500 per disclosure. The Attorney General has sole enforcement authority, and unlike New Hampshire's and Kentucky's near-identical statutes, no mandatory or discretionary cure period appears in the enforcement section as read. The chapter creates no private right of action.

What it requires

Sensitive categories

Rhode Island Data Transparency and Privacy Protection Act, sensitive data and biometric data definitions

R.I. Gen. Laws sec. 6-48.1-2(26), (3)official Rhode Island statute text, R.I. General Laws chapter 6-48.1, Rhode Island General Assembly website

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

RIDTPPA classifies genetic or biometric data processed to uniquely identify a person, along with racial or ethnic origin, religious belief, health condition, sex life, sexual orientation, citizenship or immigration status, a known child's data, and precise geolocation, as sensitive data.

"Biometric data" is textually identical to New Hampshire's and Kentucky's definitions: it means data from automatic measurement of a biological characteristic, such as a fingerprint, voiceprint, or eye retina or iris, used to identify a specific individual, and excludes a photograph or recording, or data generated from one, only until that data is generated to identify a specific individual.

What it requires

Scraping law2 instruments, 2 in force

Research summary (221 words)

Rhode Island diverges from the federal baseline in the computer_misuse and personal_data families.

Its Computer Crime chapter defines "without authority" as lacking the owner's permission or exceeding the scope of granted permission, a broad without-permission standard closer to California's pre-hiQ approach than to the Computer Fraud and Abuse Act's narrower gates-based reading confirmed in Van Buren v. United States; it also gives any person injured by a chapter violation a private civil right of action for compensatory and punitive damages plus attorney's fees, which the federal Computer Fraud and Abuse Act (CFAA) does not extend as broadly.

The Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), effective January 1, 2026, excludes "publicly available information" from its definition of personal data, but with only two prongs (a government record, or information the controller reasonably believes the customer lawfully made available to the general public through widely distributed media), narrower than California's four-prong test and lacking a prong for a third party's unrestricted disclosure of someone else's data; RIDTPPA's applicability thresholds and enforcement are researched in this jurisdiction's privacy topic document and are not restated here.

No Rhode Island court decision addressing computer-misuse liability, terms-of-service enforceability, or robots.txt in a scraping context was located. Copyright, text-and-data-mining, database rights, terms-of-service enforceability, and unfair competition are federal or general-contract-law questions only; Rhode Island adds nothing state-specific in those families.

Computer misuse

Rhode Island Computer Crime chapter, unauthorized access and computer trespass

R.I. Gen. Laws §§ 11-52-1, 11-52-2, 11-52-3, 11-52-4.1, 11-52-5, 11-52-6official text, Rhode Island General Laws (webserver.rilegislature.gov)

In force. Binds public and private bodies.

What this law does

Section 11-52-1(15)(v) defines a person as "without authority" when he or she has no right or permission of the owner to use a computer, or uses a computer in a manner exceeding his or her right or permission, a broad without-permission-or-exceeding-permission standard rather than the Computer Fraud and Abuse Act (CFAA)'s narrower gates-based test.

Section 11-52-3 makes it a felony to intentionally and without authorization access, alter, damage, or destroy a computer, system, network, program, or data for a fraudulent or other illegal purpose. Section 11-52-4.1 separately criminalizes using a computer or network without authority and with intent to disable data or programs, cause a malfunction, alter or erase data, forge bulk-email headers, or similar disruptive acts, regardless of a fraudulent purpose.

Felony violations of the chapter carry a fine of not more than five thousand dollars and imprisonment of not more than five years, or both. The lesser tier under section 11-52-4.1 (property value of five hundred dollars or less) is a misdemeanor punishable by not more than one year and a one-thousand-dollar fine, a different fine amount from the chapter's general misdemeanor tier of five hundred dollars.

Section 11-52-6 gives any person injured by a violation of the chapter a private civil right of action for compensatory damages, punitive damages, court costs, and reasonable attorney's fees, broader than the federal CFAA's civil-suit route, which is conditioned on specific categories of loss.

What it requires

Personal data

Rhode Island Data Transparency and Privacy Protection Act, publicly available information exemption

R.I. Gen. Laws § 6-48.1-2(24)official text, Rhode Island General Laws (webserver.rilegislature.gov)

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

RIDTPPA's definition of "personal data" at section 6-48.1-2(18) excludes "publicly available information," defined at (24) as information that is lawfully made available through federal, state, or municipal government records or widely distributed media, or that a controller has a reasonable basis to believe a customer has lawfully made available to the general public.

Unlike California's four-prong CCPA exemption, Rhode Island's exemption has no separate prong reaching information a third party (rather than the data subject) disclosed without restricting the audience, so personal data a scraper pulls from a re-hosted directory or an aggregator that is neither a government record nor the data subject's own act falls outside the exemption and inside RIDTPPA's reach for a controller the Act otherwise covers.

RIDTPPA applies only to for-profit entities that conduct business in, or target products or services to, Rhode Island residents and meet its 35,000-customer or 10,000-customer-plus-20-percent-revenue thresholds; its enforcement and further customer-rights detail are researched in this jurisdiction's privacy topic document.

What it requires

Cybersecurity law1 instrument, 1 enacted but not yet in force

Research summary (529 words)

Rhode Island's private-sector security-topic law rests on one enacted safeguards duty, R.I. Gen. Laws sec. 11-49.3-2, a standalone risk-based information security program requirement inside the state's Identity Theft Protection Act of 2015, a chapter separate from and companion to the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA).

A municipal agency, a state agency, or a person, defined broadly to include an individual, sole proprietorship, partnership, association, corporation, joint venture, business, legal entity, trust, estate, cooperative, or other commercial entity, that stores, collects, processes, maintains, acquires, uses, owns, or licenses personal information about a Rhode Island resident must implement and maintain a risk-based information security program with reasonable security procedures and practices appropriate to the organization's size and scope, the nature of the information, and the purpose for which it was collected; must not retain the information longer than reasonably necessary; must destroy it securely; and must require the same safeguards by written contract of any nonaffiliated third party to whom it discloses the information.

Sec. 11-49.3-5 makes each reckless violation of the chapter, a class that reaches this duty as well as the chapter's own breach-notification duty, a civil violation of up to $100 per record, and each knowing and willful violation up to $200 per record, enforced solely by the Attorney General; no private right of action was found in the text read.

No Rhode Island statute or bill is confirmed to set security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's or Oregon's connected-device statutes or the Cyber Resilience Act; a dedicated search for one located none. Rhode Island has no general private-sector duty to report an exploited vulnerability or a security incident, as distinct from a personal-data breach, to an authority.

One incident-notification duty exists, R.I. Gen. Laws sec. 11-49.3-7, requiring a municipal or state agency that detects a cybersecurity incident to notify the Rhode Island State Police within twenty-four hours, binds only the agency's own systems, the same government information-security-programme shape as FISMA, and is recorded here rather than filed as an instrument.

Two sector regimes reach a class of private licensee no activity in the LexLint vocabulary currently expresses, so both are recorded rather than flagged on a guess: R.I. Gen. Laws sec. 27-1-46 et seq.

(enacted by 2024 H 7281, effective January 1, 2025), modeled on the NAIC Insurance Data Security Model Law, requires a domestic or foreign insurer licensed in Rhode Island to develop a written information security program with named technical and governance controls and to notify the insurance commissioner of a cybersecurity event; and 2025 S.B. 603, effective July 2, 2025 and modeled on the New York Department of Financial Services' 23 NYCRR Part 500, requires a nonbank financial institution licensed by the Department of Business Regulation to maintain a written information security program with named technical controls and to report a security event to the department.

Rhode Island's breach-notification duty, R.I. Gen. Laws secs. 11-49.3-4 and 11-49.3-5, and RIDTPPA's own security-of-processing clause for data a controller processes under this chapter's exemptions, R.I. Gen. Laws sec. 6-48.1-7(s), are already this jurisdiction's privacy-topic rows rather than repeated here.

Security baseline statutes

Identity Theft Protection Act of 2015, risk-based information security program

R.I. Gen. Laws secs. 11-49.3-2, 11-49.3-5official Rhode Island statute text, R.I. General Laws chapter 11-49.3, Rhode Island General Assembly website

Commencement not set. Binds public and private bodies.

What this law does

A municipal agency, a state agency, or a person who or that stores, collects, processes, maintains, acquires, uses, owns, or licenses personal information about a Rhode Island resident must implement and maintain a risk-based information security program with reasonable security procedures and practices appropriate to the size and scope of the organization, the nature of the information, and the purpose for which it was collected, to protect the personal information from unauthorized access, use, modification, destruction, or disclosure and to preserve its confidentiality, integrity, and availability.

Personal information may not be retained longer than reasonably required to provide the requested services, meet the purpose for which it was collected, or comply with a written retention policy or legal requirement. It must be destroyed securely, including by shredding, pulverization, incineration, or erasure, regardless of the medium.

A municipal agency, state agency, or person that discloses personal information about a Rhode Island resident to a nonaffiliated third party must require by written contract that the third party implement and maintain the same kind of reasonable security procedures and practices. Sec. 11-49.3-5 makes each reckless violation of the chapter a civil violation of up to $100 per record.

Each knowing and willful violation is a civil violation of up to $200 per record, brought solely by the Attorney General; no private right of action was found in the text read. Both sections originate in P.L. 2015, ch. 138 and P.L. 2015, ch. 148, and neither section's own history note prints a same-page effective date for the 2015 enactment.

What it requires

Law in local jurisdictions1 with a page

Each has a page of its own; the number is how many of its instruments are researched to a stage.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.