Hawaiʻi · Act 247 · Act 248

Hawaiʻi passed two AI laws. Only one of them is probably about you.

Governor Green signed both on the same day, and the coverage treated them as one story. They are not. Act 248 binds a narrow class of companies that build AI companions. Act 247 binds any person who publishes a realistic AI likeness of a real human being — which includes your marketing team, your agency, and the volunteer who made the fundraising video.

Plain-language summary, not legal advice. Sources: HB 2137 CD1, enacted as Act 247; SB 3001 CD1, enacted as Act 248. Both approved July 14, 2026 and effective on approval.

Days in force
There is no runway here.Neither Act has a phase-in. Both took effect on approval, July 14, 2026. The only future date in either statute is January 1, 2028, when AI companion operators file their first annual safety report.
Start here

Two statutes, two completely different audiences

Almost every summary you will read merges these. Getting the split right is the difference between a real compliance program and a stack of policies for a law that does not reach you.

Act 247 · HB 2137
Any person

Realistic digital imitations

Makes it unlawful for any person to knowingly publish a realistic AI-generated imitation of an identifiable individual without that individual’s consent, where the imitation is used in an advertisement, causes harm, or is used to commit fraud, defamation or harassment. This is the one that reaches ordinary employers, nonprofits, agencies and creators.

Act 248 · SB 3001
Operators only

AI companions

Imposes disclosure, crisis-response and minor-protection duties on an operator — a person who develops and makes available an AI companion to the public. Added to the unfair practices chapter. If you buy or deploy someone else’s chatbot, you are very likely not an operator.

Act 247 · the one that reaches everyone

Three ways to break it. You only need one.

The prohibition is a single sentence with three disjunctive triggers. Knowing publication of a realistic digital imitation of an identifiable individual, without that individual’s consent, is unlawful if any one of these is true.

Trigger one

It is used in connection with an advertisement

“Advertisement” is defined broadly: a message published in any medium with the primary purpose of promoting, directly or indirectly, a product, service or commercial transaction. Recruitment media, donor appeals and product demos are not obviously outside that.

Trigger two

It causes harm

“Harm” is defined to include reputational injury, financial loss, emotional distress, or misappropriation of identity for commercial gain. No advertisement is required for this trigger — an internal video that leaks can qualify.

Trigger three

It is used to commit a wrong

Fraud, defamation, harassment or other criminal acts. This is the trigger most organizations assume is the whole statute. It is one third of it.

The word that does the work

“Consent” means express, written permission.

Not verbal. Not implied by an employment relationship. Not a model release signed in 2019 that says nothing about synthesis. The definition is in the statute, and it is the single most operationally consequential line in either Act: it converts an editorial judgement into a records question. Either you can produce the writing, or you cannot.

  • A staff member's voice cloned for a training moduleneeds a writing.
  • An executive's face in a synthesized promo cutneeds a writing.
  • A deceased founder in an anniversary campaignthe estate may sue for ten years.
  • A licensed stock likeness synthesized into something newcheck what the license actually grants.
Act 248 · the narrow one

Are you an operator? Three prongs, all required.

“AI companion” is a functional definition, not a product category. A system qualifies only if it is designed to simulate a sustained human or human-like relationship by doing all three of the following. A customer-service bot that answers a question and forgets you is not an AI companion.

Prong one

It remembers you

Retains information on prior interactions, sessions and user preferences to personalise the interaction and facilitate ongoing engagement.

Prong two

It asks unprompted emotional questions

Asks unprompted or unsolicited emotion-based questions that go beyond a direct response to a user prompt.

Prong three

It sustains a personal dialogue

Sustains an ongoing dialogue concerning matters personal to the user.

And you must be the one who built it

“Operator” means a person who develops and makes available an AI companion to the public. An app store or search engine that merely provides access is not, by itself, an operator. Act 248 also expressly does not create liability for the developer of an underlying AI model when a third party builds the companion on top of it.

If you are one, six duties attach immediately: identity disclosure where a reasonable person would think the system is human; a persistent or hourly disclaimer for known minors; a crisis-response protocol using evidence-based measurement of suicidal ideation; no claim to provide professional mental or behavioral health care; no unpredictable engagement rewards or sexualised output for minors; and parental screen-time and account controls. Annual reporting to the Behavioral Health Administration begins January 1, 2028.

The credibility section

What Hawaiʻi did not do

This is where most vendor pages overreach. Hawaiʻi did not enact a general AI act, and saying otherwise is the fastest way to lose a general counsel’s attention.

No algorithmic discrimination regime.

Hawaii has nothing resembling Colorado's ADMT regime or Connecticut's automated employment-decision framework. No duty of reasonable care, no impact assessment mandate, no hiring-tool disclosure duty.

No risk assessments, no registration, no inventory duty.

Neither Act requires you to catalog your AI systems or file anything with the State — except the 2028 companion report.

No age verification.

The legislature said expressly that it wanted to avoid mandatory collection of identity documentation. Act 248's minor duties are triggered by actual knowledge or reasonable certainty, not by an ID check.

No private suits under Act 248.

Nothing in it creates a private right of action, or supports one under any other law. Enforcement runs through the Attorney General and the Office of Consumer Protection.

Publishers and platforms are largely carved out of Act 247.

The medium used to disseminate third-party content — newspapers, broadcasters, streaming services, transit advertising — is exempt in that role. The underlying conduct is not.

Expression is protected on the face of the statute.

Parody, satire, commentary, criticism, scholarship, political and educational expression, news reporting used to illustrate a story, and documentary or biographical portrayal are all exempt.

One genuine ambiguity worth naming: Act 247 defines “digital imitation” as a depiction, audio or video portraying an individual’s voice, face or likeness in a sound recording or audiovisual work in which the individual did not actually perform or appear. Whether a single synthesized still image, standing alone, falls inside that phrasing has not been tested. We treat still images as in scope for control purposes and say so, rather than asserting a conclusion the text does not clearly supply.

What GOVERNBOX actually does about it

Act 247 is a records problem. That is good news.

A statute that turns on express written consent and enumerated exemptions is a statute you can be demonstrably compliant with — if the evidence exists before the complaint does, not after.

A consent register that predates publication

Every synthesized likeness gets a record: who is depicted, what was generated, the express written permission on file, its scope, and its expiry. Attached to the asset, not to somebody's inbox.

In GOVERNBOX: HI-DPF-001 — Express Consent for Digital Imitation and Likeness Deployment, with the consent artefact stored against the AI system record in your inventory.

A pre-publication screen for the harm and fraud triggers

Triggers two and three do not need an advertisement. A review step that asks whether the output could cause reputational injury, financial loss or emotional distress — and records the answer — is the whole control.

In GOVERNBOX: HI-DPF-002 — Malicious Imitation, Fraud, and Defamation Interception, run as a recurring task with an owner and a due date.

The exemption you relied on, written down at the time

Parody, commentary, news illustration and biographical portrayal are real defenses. They are much harder to run two years later if nobody recorded which one applied and why. This is the control that turns an argument into a document.

In GOVERNBOX: HI-DPF-003 — Protected Expression and Statutory Exemption Validation, generated with a citation to the exemption paragraph it rests on.

If you are an operator, the Act 248 stack — and the 2028 report

Disclosure cadence, crisis protocol, minor safeguards, parental controls, and the annual filing to the Behavioral Health Administration.

In GOVERNBOX: HI-CMP-001/002/003, HI-MIN-001/002/003, HI-REP-001 and HI-ENF-001 — the reporting control carries a January 1, 2028 first-due date.
The control library

eleven authored Hawaiʻi controls across four domains

Not generated at request time. Authored against the chaptered text, versioned, and retrieved with a citation. The system retrieves controls; it does not invent them. HI-DPF-001 is highlighted because it maps to the operative word in Act 247 — if you build only one thing this quarter, build that one.

HI-DPF-001Express Consent for Digital Imitation and Likeness Deployment
HI-DPF-002Malicious Imitation, Fraud, and Defamation Interception
HI-DPF-003Protected Expression and Statutory Exemption Validation
HI-CMP-001Session Identity Disclosure and Recurring Interval Notice
HI-CMP-002Prohibition of Deceptive Humanization and Unlicensed Medical Claims
HI-CMP-003Suicidal Ideation Interception and Crisis Intervention Protocols
HI-MIN-001Minor Protection Plan and Risk Assessment Filing
HI-MIN-002Addictive Design Elimination and Minor Content Filtering
HI-MIN-003Parental Governance Controls and Age Assurance
HI-REP-001Annual Behavioral Health Administration Safety Reporting
HI-ENF-001Statutory Penalty Defense and Enforcement Audit Logging
Why a library instead of a policy generator

Hawaiʻi is one jurisdiction. You are probably in several.

The consent register you build for Act 247 is most of the evidence a Colorado deployer duty wants, and a good deal of what ISO/IEC 42001 asks for under records of AI system use. Crosswalks show that overlap instead of making you rediscover it.

Take the free scorecard →
Hawaiʻi controls · overlap
NIST AI RMF 1.064%
ISO/IEC 4200155%
Colorado SB 26-189 (ADMT)45%
Connecticut PA 26-1536%
EU AI Act27%

Illustrative figures for layout only. Your actual overlap is computed from the controls your approved documents cite and the systems in your inventory.

Questions we actually get

Hawaiʻi, answered honestly

The chapter says it applies to the fullest extent permitted by federal law, which is a deliberate reach-as-far-as-we-can clause rather than a bright line. It does not contain an in-state-conduct test you can point at. If you publish advertising that Hawaii residents see and it contains a synthesized likeness, assume the question is live and take advice, rather than assuming geography protects you.

Find out where you stand before somebody else does.

Fifteen questions, about ten minutes, a banded score and a named gap list. No account, no payment method, no sales call.

This page is a plain-language summary of Hawaiʻi Act 247 (HB 2137 CD1) and Act 248 (SB 3001 CD1), both approved July 14, 2026, and is provided for general information. It is not legal advice and does not create an attorney-client relationship. GOVERNBOX.ai is a product of Gradient Descent LLC and is not affiliated with, endorsed by, or sponsored by the State of Hawaiʻi, the Hawaiʻi Department of the Attorney General, the Office of Consumer Protection, or the Department of Health. Read the chaptered text and take advice on your own facts.