Georgia enacted two AI laws in 2026: SB 540 (Chatbot Safety / Online Internet Safety) and SB 444 (Healthcare AI Insurance). This crosswalk maps both laws to SWT3 witness procedures for cryptographic compliance evidence.
Audience: Compliance officers, legal teams, AI product managers, and assessors responsible for Georgia AI law compliance. Applicable to operators of conversational AI services and insurers using AI for coverage decisions.
Side-by-side comparison of Georgia's two 2026 AI laws.
| Attribute | SB 540 (Chatbot Safety) | SB 444 (Healthcare AI Insurance) |
|---|---|---|
| Full Title | Online Internet Safety Act | Healthcare AI Insurance Regulation |
| Signed | May 11, 2026 | May 5, 2026 |
| Effective | July 1, 2027 | January 1, 2027 |
| Scope | Operators of conversational AI services | Private review agents; insurance coverage decisions |
| Core Obligation | AI disclosure, minor protections, safety protocols | Human oversight of AI-driven coverage decisions |
| Enforcement | Attorney General | Commissioner of Insurance |
| SWT3 Procedures | AI-TRANS.1, AI-SAFE.1, AI-GRD.1, AI-GRD.2, AI-CONSENT.1 | AI-HITL.1, AI-HITL.2, AI-FAIR.1, AI-EXPL.1 |
Note: SB 444 becomes enforceable on January 1, 2027, giving insurers approximately five months from publication of this guide. SB 540 follows on July 1, 2027. Organizations should prioritize SB 444 compliance first.
SB 540, the Online Internet Safety Act, targets operators of conversational AI services. It establishes disclosure requirements, safety protocols for vulnerable users, and privacy controls.
Operators must disclose that the user is interacting with an AI system. The disclosure must be repeated at defined intervals:
The SWT3 procedure AI-TRANS.1 witnesses each transparency disclosure event, capturing the interval timing and user category. This creates a tamper-evident record that disclosures were presented at the cadence required by statute.
When a conversational AI service detects indicators of suicidal ideation or self-harm, the operator must trigger a defined response protocol. This includes surfacing crisis resources, restricting harmful content generation, and logging the safety event.
AI-SAFE.1 witnesses the safe state transition, recording that the system detected a risk signal and executed the configured response. The witness anchor captures the transition type, timestamp, and whether crisis resources were surfaced.
Operators must apply age-appropriate content restrictions for users identified as minors. This includes content filtering, topic restrictions, and guardrail enforcement.
AI-GRD.1 and AI-GRD.2 witness that guardrails are active and content filters are applied during minor interactions. The witness record includes the guardrail configuration version and filter categories enforced.
Users must be provided with tools to manage their privacy preferences within the conversational AI service. This includes the ability to request data deletion, opt out of data retention, and manage consent.
AI-CONSENT.1 witnesses that consent and privacy preference collection mechanisms are available and functioning. Each consent event is anchored with the preference type and user action.
SB 444 addresses the use of AI systems in healthcare insurance coverage decisions. The law establishes that decisions regarding insurance coverage for healthcare services shall not be based solely on AI systems.
Private review agents must ensure that a qualified human reviewer evaluates AI-generated coverage recommendations before any final determination is issued. The AI system may assist, inform, or recommend, but must not be the sole decision-maker.
AI-HITL.1 witnesses that a human review was completed before the coverage decision was finalized. The anchor records the reviewer identifier, the AI recommendation, and the final human determination.
When a human reviewer disagrees with the AI recommendation and overrides the system output, the override event must be documented. This ensures accountability and traceability in the decision chain.
AI-HITL.2 witnesses the override event, capturing the original AI recommendation, the human decision, and the rationale for the override.
AI systems used for coverage determinations must not produce discriminatory outcomes based on protected characteristics. Insurers must monitor for disparate impact and bias in AI-driven decisions.
AI-FAIR.1 witnesses bias disparity measurements, recording that monitored metrics remain within acceptable thresholds. If a threshold is exceeded, the witness anchor captures the disparity value and the affected demographic category.
When an AI system contributes to a coverage determination, the insurer must be able to explain the basis of the decision to the policyholder. This requires the AI system to produce interpretable outputs.
AI-EXPL.1 witnesses that an explanation was generated for the coverage determination, capturing the explanation method, the key factors cited, and the confidence level of the AI recommendation.
The following table maps each statutory obligation from both Georgia AI laws to the corresponding SWT3 witness procedure.
| Obligation | Law | SWT3 Procedure | What It Witnesses |
|---|---|---|---|
| AI disclosure (3h/1h intervals) | SB 540 | AI-TRANS.1 |
Transparency disclosure presented at required intervals |
| Suicidal ideation response protocol | SB 540 | AI-SAFE.1 |
Safe state transition triggered by risk detection |
| Content safety for minors | SB 540 | AI-GRD.1, AI-GRD.2 |
Guardrails active, content filters applied |
| Privacy tools provided | SB 540 | AI-CONSENT.1 |
Consent/privacy preference collection witnessed |
| Human oversight of AI insurance decisions | SB 444 | AI-HITL.1 |
Human review completed before coverage decision |
| Override of AI recommendation | SB 444 | AI-HITL.2 |
Human override event recorded |
| Non-discrimination in AI decisions | SB 444 | AI-FAIR.1 |
Bias disparity measurement within threshold |
| Explainability of AI decision | SB 444 | AI-EXPL.1 |
Explanation generated for coverage determination |
Witnesses that a transparency disclosure was presented to the user, confirming that the system identified itself as AI. For SB 540 compliance, the witness anchor must include the disclosure interval (3 hours for general users, 1 hour for minors) and the timestamp of each presentation.
Factor A: Disclosure method (e.g., inline banner, modal dialog, system message)
Factor B: Interval configuration (3600s for minors, 10800s for general users)
Factor C: User category (general or minor)
Verify that the interval recorded in Factor B matches the statutory requirement for the user category in Factor C. A general user anchor with an interval shorter than 10800s is compliant (exceeds the requirement). A minor user anchor with an interval longer than 3600s is non-compliant.
Witnesses that the AI system detected a risk signal (suicidal ideation, self-harm indicators) and executed a safe state transition. The anchor records the detection mechanism, the response actions taken (crisis resource display, content restriction, session handoff), and the transition timestamp.
Factor A: Detection trigger type (keyword match, classifier score, pattern recognition)
Factor B: Response actions executed (e.g., crisis_hotline_displayed, content_blocked, session_escalated)
Factor C: Response latency in milliseconds
Confirm that Factor B includes at least one crisis resource action. SB 540 requires a defined response protocol, so a detection event without a corresponding response action is a compliance gap. Check that response latency (Factor C) is within the operator's documented SLA.
Witnesses that a human reviewer completed an evaluation of the AI-generated insurance coverage recommendation before the final determination was issued. SB 444 requires that coverage decisions shall not be based solely on AI, making this procedure the primary compliance anchor for healthcare insurers.
Factor A: Reviewer role or identifier (anonymized)
Factor B: AI recommendation outcome (approve, deny, partial)
Factor C: Human determination outcome (approve, deny, partial, override)
The critical check is that an AI-HITL.1 anchor exists for every coverage decision that involved AI assistance. If the insurer's system issues decisions without a corresponding HITL anchor, this indicates sole AI decision-making, which violates SB 444. Cross-reference with claim processing logs to verify completeness.
Witnesses that the operator measured bias disparity across protected demographic categories and that the results were within the configured threshold. For SB 444, this applies to AI-driven coverage determinations where disparate impact could result in discriminatory denial of healthcare services.
Factor A: Demographic categories evaluated (e.g., age, race, gender, disability status)
Factor B: Disparity metric and measured value (e.g., demographic_parity: 0.03)
Factor C: Configured threshold and pass/fail result
Review the threshold in Factor C against the insurer's documented fairness policy. A PASS verdict with a threshold of 1.0 (effectively no constraint) would satisfy the protocol but not the spirit of SB 444. The Commissioner of Insurance may establish specific thresholds through rulemaking. Monitor for regulatory guidance updates.
SB 444 is one of several state laws addressing AI in healthcare insurance decisions. Organizations subject to SB 444 may also face overlapping obligations under federal regulations and other state laws governing AI in insurance and healthcare.
For a broader analysis of AI in health insurance contexts, including prior authorization AI, utilization review, and claims processing, see the dedicated crosswalk:
The health insurance crosswalk covers additional SWT3 procedures beyond those mapped here, including AI-DATA.1 (data provenance for training data used in coverage models), AI-AUDIT.1 (audit trail for AI-assisted determinations), and AI-CHAIN.1 (decision chain linking for multi-step coverage workflows).
The following Python example demonstrates witnessing a human-in-the-loop review for an AI-assisted insurance coverage decision under SB 444.
from swt3_ai import Witness
witness = Witness(
tenant="acme-insurance",
signing_key="your-hmac-key"
)
# AI recommends approval; human reviewer confirms
result = witness.witness(
procedure="AI-HITL.1",
factor_a="claims_reviewer_7291",
factor_b="ai_recommendation:approve",
factor_c="human_determination:approve",
clearing_level=2,
jurisdiction="US-GA",
legal_basis="GA-SB-444",
purpose_class="insurance_coverage_decision"
)
print(result["fingerprint"])
# e.g., 96b7d56c0245
# Witness AI disclosure for chatbot (SB 540)
disclosure = witness.witness(
procedure="AI-TRANS.1",
factor_a="inline_banner",
factor_b="interval:10800",
factor_c="user_category:general",
clearing_level=1,
jurisdiction="US-GA",
legal_basis="GA-SB-540",
purpose_class="chatbot_disclosure"
)
print(disclosure["fingerprint"])
The jurisdiction field is set to US-GA (ISO 3166-2) and the legal_basis identifies the specific Georgia statute. These fields are preserved across all clearing levels, ensuring that the jurisdictional context is always available for regulatory inquiry.