Governor Green signed both on the same day, and the coverage treated them as one story. They are not. Act 248 binds a narrow class of companies that build AI companions. Act 247 binds any person who publishes a realistic AI likeness of a real human being — which includes your marketing team, your agency, and the volunteer who made the fundraising video.
Plain-language summary, not legal advice. Sources: HB 2137 CD1, enacted as Act 247; SB 3001 CD1, enacted as Act 248. Both approved July 14, 2026 and effective on approval.
Almost every summary you will read merges these. Getting the split right is the difference between a real compliance program and a stack of policies for a law that does not reach you.
Makes it unlawful for any person to knowingly publish a realistic AI-generated imitation of an identifiable individual without that individual’s consent, where the imitation is used in an advertisement, causes harm, or is used to commit fraud, defamation or harassment. This is the one that reaches ordinary employers, nonprofits, agencies and creators.
Imposes disclosure, crisis-response and minor-protection duties on an operator — a person who develops and makes available an AI companion to the public. Added to the unfair practices chapter. If you buy or deploy someone else’s chatbot, you are very likely not an operator.
The prohibition is a single sentence with three disjunctive triggers. Knowing publication of a realistic digital imitation of an identifiable individual, without that individual’s consent, is unlawful if any one of these is true.
“Advertisement” is defined broadly: a message published in any medium with the primary purpose of promoting, directly or indirectly, a product, service or commercial transaction. Recruitment media, donor appeals and product demos are not obviously outside that.
“Harm” is defined to include reputational injury, financial loss, emotional distress, or misappropriation of identity for commercial gain. No advertisement is required for this trigger — an internal video that leaks can qualify.
Fraud, defamation, harassment or other criminal acts. This is the trigger most organizations assume is the whole statute. It is one third of it.
Not verbal. Not implied by an employment relationship. Not a model release signed in 2019 that says nothing about synthesis. The definition is in the statute, and it is the single most operationally consequential line in either Act: it converts an editorial judgement into a records question. Either you can produce the writing, or you cannot.
“AI companion” is a functional definition, not a product category. A system qualifies only if it is designed to simulate a sustained human or human-like relationship by doing all three of the following. A customer-service bot that answers a question and forgets you is not an AI companion.
Retains information on prior interactions, sessions and user preferences to personalise the interaction and facilitate ongoing engagement.
Asks unprompted or unsolicited emotion-based questions that go beyond a direct response to a user prompt.
Sustains an ongoing dialogue concerning matters personal to the user.
“Operator” means a person who develops and makes available an AI companion to the public. An app store or search engine that merely provides access is not, by itself, an operator. Act 248 also expressly does not create liability for the developer of an underlying AI model when a third party builds the companion on top of it.
If you are one, six duties attach immediately: identity disclosure where a reasonable person would think the system is human; a persistent or hourly disclaimer for known minors; a crisis-response protocol using evidence-based measurement of suicidal ideation; no claim to provide professional mental or behavioral health care; no unpredictable engagement rewards or sexualised output for minors; and parental screen-time and account controls. Annual reporting to the Behavioral Health Administration begins January 1, 2028.
This is where most vendor pages overreach. Hawaiʻi did not enact a general AI act, and saying otherwise is the fastest way to lose a general counsel’s attention.
Hawaii has nothing resembling Colorado's ADMT regime or Connecticut's automated employment-decision framework. No duty of reasonable care, no impact assessment mandate, no hiring-tool disclosure duty.
Neither Act requires you to catalog your AI systems or file anything with the State — except the 2028 companion report.
The legislature said expressly that it wanted to avoid mandatory collection of identity documentation. Act 248's minor duties are triggered by actual knowledge or reasonable certainty, not by an ID check.
Nothing in it creates a private right of action, or supports one under any other law. Enforcement runs through the Attorney General and the Office of Consumer Protection.
The medium used to disseminate third-party content — newspapers, broadcasters, streaming services, transit advertising — is exempt in that role. The underlying conduct is not.
Parody, satire, commentary, criticism, scholarship, political and educational expression, news reporting used to illustrate a story, and documentary or biographical portrayal are all exempt.
One genuine ambiguity worth naming: Act 247 defines “digital imitation” as a depiction, audio or video portraying an individual’s voice, face or likeness in a sound recording or audiovisual work in which the individual did not actually perform or appear. Whether a single synthesized still image, standing alone, falls inside that phrasing has not been tested. We treat still images as in scope for control purposes and say so, rather than asserting a conclusion the text does not clearly supply.
A statute that turns on express written consent and enumerated exemptions is a statute you can be demonstrably compliant with — if the evidence exists before the complaint does, not after.
Every synthesized likeness gets a record: who is depicted, what was generated, the express written permission on file, its scope, and its expiry. Attached to the asset, not to somebody's inbox.
Triggers two and three do not need an advertisement. A review step that asks whether the output could cause reputational injury, financial loss or emotional distress — and records the answer — is the whole control.
Parody, commentary, news illustration and biographical portrayal are real defenses. They are much harder to run two years later if nobody recorded which one applied and why. This is the control that turns an argument into a document.
Disclosure cadence, crisis protocol, minor safeguards, parental controls, and the annual filing to the Behavioral Health Administration.
Not generated at request time. Authored against the chaptered text, versioned, and retrieved with a citation. The system retrieves controls; it does not invent them. HI-DPF-001 is highlighted because it maps to the operative word in Act 247 — if you build only one thing this quarter, build that one.
The consent register you build for Act 247 is most of the evidence a Colorado deployer duty wants, and a good deal of what ISO/IEC 42001 asks for under records of AI system use. Crosswalks show that overlap instead of making you rediscover it.
Take the free scorecard →Illustrative figures for layout only. Your actual overlap is computed from the controls your approved documents cite and the systems in your inventory.
Fifteen questions, about ten minutes, a banded score and a named gap list. No account, no payment method, no sales call.
This page is a plain-language summary of Hawaiʻi Act 247 (HB 2137 CD1) and Act 248 (SB 3001 CD1), both approved July 14, 2026, and is provided for general information. It is not legal advice and does not create an attorney-client relationship. GOVERNBOX.ai is a product of Gradient Descent LLC and is not affiliated with, endorsed by, or sponsored by the State of Hawaiʻi, the Hawaiʻi Department of the Attorney General, the Office of Consumer Protection, or the Department of Health. Read the chaptered text and take advice on your own facts.