🔴Illinois HB 3773IN EFFECT$10M fine|🔴Texas TRAIGAIN EFFECTActive enforcement|⚠️Colorado SB 205Jun 30, 2026Per-violation fines|⚠️California SB 942Aug 2, 2026$5K/day|⚠️EU AI Act Art. 50Aug 2, 2026€35M or 7% revenue|⚠️Virginia HB 2154Jul 1, 2026$10K/violation|⚠️Connecticut SB 2Oct 1, 2026$25K/violation|🔴Illinois HB 3773IN EFFECT$10M fine|🔴Texas TRAIGAIN EFFECTActive enforcement|⚠️Colorado SB 205Jun 30, 2026Per-violation fines|⚠️California SB 942Aug 2, 2026$5K/day|⚠️EU AI Act Art. 50Aug 2, 2026€35M or 7% revenue|⚠️Virginia HB 2154Jul 1, 2026$10K/violation|⚠️Connecticut SB 2Oct 1, 2026$25K/violation|
📢
Latest UpdateAI regulations in Missouri are evolving. Last checked: April 2026.
Check your status →
HomeStatesMissouri
No LawDeadline: N/A

AI Laws in Missouri (MO)

By the AI Law Tracker Editorial Team · Last verified

No state-specific AI law. Federal laws apply. Missouri AG monitors AI-driven consumer protection violations under the Merchandising Practices Act.

What companies in Missouri need to know about AI compliance

As of 2026-04-29, Missouri has not enacted an AI-specific statute; the Missouri Attorney General office defers to no comprehensive state privacy statute; UDAP coverage via Missouri Merchandising Practices Act (Mo. Rev. Stat. sec. 407.020). Operators across sectors in Missouri watch federal signals first.

Three neighboring regimes create compounding exposure: Iowa (AI in Government Act, penalty Administrative), Illinois (HB 3773 — AI in Employment, penalty Up to $5,000 per violation (willful/repeated)), and Kentucky (AI Study Resolution, penalty TBD). Multi-state Cross-Sector operators headquartered in Missouri default to the strictest stack.

Federal law still governs Cross-Sector AI in Missouri primarily through FTC Section 5 (15 USC 45) and NIST AI RMF 1.0. Adjacent federal authorities include Gramm-Leach-Bliley Act (GLBA) / NIST Cybersecurity Framework (15 U.S.C. § 6801-6809; NIST CSF 2.0); California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) (CA Civil Code §§ 1798.100-1798.199); General Data Protection Regulation (GDPR) (for EU users) (EU Regulation 2016/679). Gramm-Leach-Bliley Act (GLBA) / NIST Cybersecurity Framework (enforced by Federal Trade Commission; NIST) applies to saas platforms handling personal/financial data via ai must implement nist csf security standards: identify, protect, detect, respond, recover. Penalty exposure: ftc civil penalties up to $100,000/violation; private litigation for data breaches. FTC Operation AI Comply (Sep 2024) targeted five companies across sectors.

The practical effect for Missouri operators: AI compliance risk is driven by federal agencies first, with Missouri Attorney General acting on UDAP residual authority only when consumer harm surfaces.

The federal and neighboring-state framework that governs your AI operations. Cross-Sector operators in Missouri operate under a federal-dominant framework anchored by FTC Section 5 (15 USC 45) and NIST AI RMF 1.0, with adjacent authorities Gramm-Leach-Bliley Act (GLBA) / NIST Cybersecurity Framework (15 U.S.C. § 6801-6809; NIST CSF 2.0); California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) (CA Civil Code §§ 1798.100-1798.199); General Data Protection Regulation (GDPR) (for EU users) (EU Regulation 2016/679). FTC Operation AI Comply (Sep 2024) targeted five companies across sectors. The practical risk they have to price in is cross-sector FTC Section 5 exposure and state UDAP liability, and the bellwether signal to monitor is NIST AI RMF 1.0 (Jan 2023) is cited as the federal baseline across 30+ agency guidance documents. Iowa -- AI in Government Act sets the de-facto regional floor. Missouri considered HB 1687 (AI liability) in 2024 but did not advance; no AI-specific statute; monitoring neighboring Illinois HB 3773 and Kansas AI Working Group. Use this as a starting point; sector pages on this site go deeper into industry-specific obligations.

With 11-50 employees you can justify a half-time compliance lead and part-time external counsel on retainer. Small-stage Cross-Sector operators should deploy a named compliance lead, formal AI inventory, quarterly bias spot-checks, and a documented escalation path, with semi-annual internal audit with annual external review and ownership resting with a designated AI compliance lead reporting to the CEO. small-business budgets ($50K-$250K) justify a compliance lead plus a GRC tool such as Credo AI, Fairly, or Holistic AI. For Cross-Sector specifically, the sharpest exposure to manage is cross-sector FTC Section 5 exposure and state UDAP liability. Given Missouri's concentration in transportation logistics, financial services, and healthcare, freight-routing algorithms, consumer-lending models, and rural telehealth AI deserve priority in your AI inventory.

The enforcement surface for Cross-Sector centres on FTC, CFPB, State Attorneys General, and the statute operators most often under-document is California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) (CA Civil Code §§ 1798.100-1798.199) — a gap that surfaces in cross-sector FTC Section 5 exposure disputes. Build an evidence binder covering AI inventory, risk-tier register, incident-response runbook, and board-level AI risk report. Treat NIST AI RMF 1.0 (Jan 2023) is cited as the federal baseline across 30+ agency guidance documents as your leading indicator and escalate when the signal shifts.

Verified 2026-04-29. See https://ago.mo.gov/ for the Missouri Attorney General public record on Missouri AI policy.

Even without a Missouri-specific AI law, federal enforcement from the FTC, EEOC, CFPB, and HHS applies to AI-driven decisions in your state. See the industry pages below for sector-specific obligations.
✓ Free · No email · 2 minutes
Does your Missouri business comply with AI laws?
Answer 4 quick questions → get your personalized risk score + action list.
Check My Risk — Free →

Applicable laws

No AI-specific lawN/A

Missouri AI compliance by industry

Healthcare
Finance & Banking
HR & Recruiting
Tech & SaaS
Marketing & Advertising
Insurance
Education
Legal Services
Real Estate
Retail & E-Commerce
Manufacturing
Transportation
Media & Entertainment
Nonprofit
Government Contractor

AI compliance by company size

Jump to top-risk sectors for your company size

Startups (1-10)
🏥 Healthcare
Small (11-50)
🏦 Finance
Mid-Market (51-500)
👥 HR & Recruiting
Enterprise (500+)
💻 Tech & SaaS

Quick resources for Missouri

✅ Compliance checklist
💰 Fines & penalties
📋 Requirements
📖 Compliance guide
⏰ Deadlines

Industry risk levels in Missouri

Risk by sector
🏥 HealthcareVery High
🏦 Finance & BankingVery High
💻 Tech & SaaSHigh
🛒 Retail & E-CommerceMedium-High
👔 HR & RecruitingVery High
⚖️ Legal ServicesHigh
📢 Marketing & AdvertisingMedium
🎓 EducationMedium-High
Risk levels based on Missouri AI law requirements and industry-specific regulations

Do you also serve EU customers?

The EU AI Act applies to any company serving EU customers, even if you're based in Missouri. Penalties reach €35M or 7% of global revenue. Deadline: August 2, 2026.

Check EU compliance →·GermanyFranceIreland

Other states with active AI laws

California
$5,000/day per violation
Illinois
Up to $5,000 per violation (willful/repeated)
Colorado
Per-violation fines under CCPA framework
Texas
Varies by violation type
Washington
Civil penalties up to $7,500/violation
Massachusetts
Civil penalties
Check your state's risk →

Related resources

Free AssessmentHealthcare AI LawsHR & Hiring AI LawsEU AI Act
Editorial standards

Sources verified against official .gov filings · Last verified Apr 29, 2026.

Official sources · Missouri