AI Policy Wiki
Dashboard

Virginia HB 2094 (High-Risk AI Developer and Deployer Act, vetoed)

high confidence · updated 2026-06-06

Virginia's high-risk AI bill, modeled on the Colorado AI Act. Passed the General Assembly in Feb 2025 and vetoed by Gov. Youngkin on Mar 24, 2025 — the highest-profile red/purple-state rejection of the Colorado-style duty-of-care model.

The High-Risk Artificial Intelligence Developer and Deployer Act (Virginia House Bill 2094, 2025 Regular Session) was a Virginia bill that would have imposed duty-of-care obligations on developers and deployers of high-risk AI systems used in consequential decisions about Virginia consumers. Its structure closely tracked the Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment). The bill passed both chambers of the Virginia General Assembly in February 2025 and was vetoed by Governor Glenn Youngkin (R) on March 24, 2025. It did not become law.

Status and legislative history

HB 2094 was introduced in January 2025 by lead sponsor Del. Michelle Lopes Maldonado (D); a Senate version was carried by Sen. Saddam Azlan Salim (D). The House passed the bill on February 11, 2025, and the Senate on February 20, 2025, both by narrow margins. The bill was transmitted to the Governor on March 10, 2025.

Governor Youngkin vetoed the bill on March 24, 2025. A veto override attempt failed, with the two-thirds margin unreachable. The bill remains vetoed and is not law. Had it been signed, its provisions would have taken effect July 1, 2026.

Scope and definitions

The bill would have applied to two categories of actor:

  • Developers: persons who develop an AI system, or substantially modify an AI system, and offer it for commercial use.
  • Deployers: persons who use a high-risk AI system to make a "consequential decision" about a Virginia consumer.

A "consequential decision" covered decisions in employment, education, financial services, healthcare, housing, insurance, legal services, and parole, pretrial, and sentencing.

Key provisions

Developer obligations

Developers would have been required to provide deployers with documentation on intended uses, limitations, known risks, a training-data overview, and performance across demographic groups; to supply information sufficient for the deployer to complete an impact assessment; and to disclose algorithmic discrimination risks known or reasonably knowable.

Deployer obligations

Deployers would have been required to implement a risk-management program aligned to the NIST AI Risk Management Framework (AI RMF 1.0) or an equivalent; to complete impact assessments before deploying a high-risk AI system and annually thereafter; to notify consumers that a high-risk AI system was used in a consequential decision and of the consumer's right to correction and human review; and to provide opt-out and human-review rights for adverse decisions.

Duty to avoid algorithmic discrimination

Developers and deployers would have been required to exercise reasonable care to protect consumers from algorithmic discrimination.

Enforcement and penalties

Enforcement would have rested exclusively with the Virginia Attorney General, with no private right of action. The bill provided a 45-day cure period, shorter than Colorado's 60 days and TRAIGA's 60 days. Civil penalties were capped at $1,000 per violation, rising to $10,000 for willful violations — lower than the penalties under the Colorado and Texas laws.

Youngkin veto rationale

Governor Youngkin's official veto statement, dated March 24, 2025, stated that the bill would "harm the creation of new jobs, the attraction of new business investment, and the availability of innovative technology in the Commonwealth," and characterized the bill as imposing "burdensome regulations" inconsistent with Virginia's pro-innovation posture. The statement cited industry estimates of roughly $30M in annual compliance cost concentrated on startups and small businesses, and argued that existing Virginia law — particularly consumer-protection and civil-rights statutes — already addresses algorithmic harms. The position that existing consumer-protection and civil-rights laws already cover algorithmic discrimination is one that state attorneys general have adopted for enforcement purposes (see State AG AI Guidances (CA, NJ, MA, OR)).

The $30M compliance estimate came from industry-funded research (NetChoice and Chamber of Progress); consumer advocates produced competing estimates as low as $5M.

Comparison with other state AI legislation

HB 2094 was the closest legislative replica of the Colorado model among the state bills tracked here. Its veto has been read as a signal that the Colorado duty-of-care template did not transfer to Republican-governed jurisdictions even where the bill passed the legislature with bipartisan support.

LawCore logicDiscrimination standardStatus
VA HB 2094 (vetoed)Duty of care for high-risk AIReasonable care; impact-basedVetoed Mar 2025
Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment)Duty of care for high-risk AIReasonable care; impact-basedSigned 2024, effective 2026
Texas Responsible AI Governance Act (TRAIGA / HB 149) — Source SummaryIntent-based prohibitionsIntent required; disparate impact insufficientSigned Jun 2025
California SB 53 — Transparency in Frontier AI ActFrontier transparencyN/ASigned 2025
New York RAISE Act (S. 8828)Frontier transparency + safetyN/ASigned 2025
NYC Local Law 144 (Automated Employment Decision Tools)Bias auditImpact-ratio testingEffective 2023

HB 2094 and Texas TRAIGA

HB 2094 and the Texas Responsible AI Governance Act (TRAIGA / HB 149) — Source Summary (TX HB 149) addressed similar regulatory terrain in red and purple states within months of each other but diverged in design and outcome.

DimensionVA HB 2094 (vetoed)TX TRAIGA / HB 149 (signed)
LogicDuty of care (Colorado template)Intent-based prohibitions (scaled back from Colorado template)
Disparate impactActionableNot sufficient to prove violation
SandboxNone36-month regulatory sandbox
RulemakingAG rulemakingNon-binding council only
Small-business burden$30M estimated complianceIntent-gated; narrower surface area
Political frameAnti-discriminationInnovation-friendly guardrails

TRAIGA's redesign away from a duty-of-care model and toward intent-based prohibitions has been widely read as a response anticipating the kind of veto Youngkin issued: it retained prohibitions flavored after EU AI Act Article 5 (which carry bipartisan valence) while shedding the Colorado duty-of-care apparatus that Republicans characterize as regulatory overreach.

Reactions and reception

The bill passed both chambers narrowly with bipartisan votes, but the executive veto operated as an independent check; the divergence between bipartisan legislative passage and an executive veto illustrates the uneven, actor-by-actor character that Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race attributes to state AI regulation. Within US AI policy, the veto was the highest-profile state AI-regulatory veto since California SB 1047 — Safe and Secure Innovation for Frontier AI Models Act (enrolled + veto) (vetoed by Governor Newsom in 2024), and it reinforced the Texas TRAIGA approach as the Republican alternative to the Colorado template. The veto was followed by similar bills being pulled or slowed in at least three other states, with Washington, Connecticut, and New Jersey all pulling or slowing analogous bills in Q2 2025.

The veto aligns with the ceiling-preemption posture of Executive Order 14365 — Ensuring a National Policy Framework for AI, though Youngkin did not cite the executive order. The veto has been referenced in America's AI Action Plan and Executive Order 14365 — Ensuring a National Policy Framework for AI messaging supporting federal preemption.

Relationships

Sources

  • Virginia LIS bill page: https://lis.virginia.gov/bill-details/20251/HB2094
  • Youngkin veto statement, Mar 24, 2025
  • Secondary: Ogletree Deakins (Mar 2025); IAPP (Mar 2025); Davis Polk (Mar 2025); Skadden (Mar 2025); Saul Ewing; ABA Health Law Section; Data Innovation (opposition); Washington Examiner coverage