---
title: "Virginia AI Law Tracker: 2026 | EFROS"
description: "Virginia AI laws, pending bills, sector overlays, and compliance checklist. Citation-ready research from EFROS, updated quarterly. Edition 2026-Q2."
canonical: https://efros.com/research/state-ai-law-tracker/virginia/
---

- [Home](https://efros.com/)
- /[Research](https://efros.com/research/)
- /[State AI Law Tracker](https://efros.com/research/state-ai-law-tracker/)
- /Virginia

Primary Research · State Profile · VA

# Virginia AI Law Tracker: 2026

Virginia was the second US state to enact a comprehensive consumer privacy law, the Virginia Consumer Data Protection Act (VCDPA), effective January 1, 2023. The law's profiling, sensitive data, and impact assessment provisions reach a significant share of AI deployments touching Virginia residents. The VCDPA applies to entities processing personal data of 100,000+ Virginia consumers (or 25,000+ if revenue-from-data thresholds are met) and was the legislative template that shaped Colorado, Connecticut, and several other state laws. Virginia is also a significant federal contractor and defense industrial base state, which means CMMC, NIST SP 800-171, and other federal frameworks frequently layer on top of state AI exposure.

Virginia's regulatory posture in 2026 is mature but not aggressive. The VCDPA's profiling opt-out, sensitive data consent, and data protection assessment requirements have been in force for three years and Virginia AG enforcement has been measured: the law includes a 30-day cure period and there is no private right of action. Virginia has been notably less active than California, Colorado, or Illinois on AI-specific legislation; comprehensive AI Act drafts have circulated but none has been enacted. Where Virginia does add unique exposure is at the intersection of state privacy law and the substantial federal contractor population: defense industrial base companies operating in Virginia frequently need to coordinate VCDPA compliance with CMMC 2.0 and NIST SP 800-171 implementations, which is not a trivial integration exercise.

By [Stefan Efros](https://www.linkedin.com/in/stefanefros-cyberdefense/), CEO & Founder, EFROS

Updated · September 11, 2026

## Enacted Virginia AI laws

### Virginia Consumer Data Protection Act (VCDPA)

in force

**Citation**

Va. Code Ann. § 59.1-575 et seq.

**Effective date**

2023-01-01

Key provisions

Consumer rights of access, correction, deletion, portability, opt-out of targeted ads / sale / profiling; sensitive data consent; data protection assessments for high-risk processing; AG enforcement; 30-day cure period; no private right of action.

## Pending Virginia AI legislation

### Virginia AI Accountability Act drafts

**Status**

Pending in 2025-2026 sessions

**Expected enactment**

Uncertain enactment timeline

Various proposals have circulated to add AI-specific obligations on top of VCDPA. None has cleared the legislature; structure may eventually follow Colorado.

## Sector overlays in Virginia

Sector-specific frameworks layer on top of state AI laws and frequently impose stricter or earlier-binding obligations. These are the sectors most exposed in Virginia.

Defense industrial base

Virginia has the largest defense contractor population in the US. CMMC 2.0, NIST SP 800-171, and DFARS overlay state AI exposure for any AI processing controlled unclassified information.

Financial services

VCDPA profiling opt-out is the binding state-level constraint; federal regulator expectations (OCC, FDIC, Federal Reserve) overlay for AI in credit and lending.

Healthcare

VCDPA exempts most HIPAA-covered data; consumer-health-adjacent AI applications are in scope.

Education

Virginia universities and Virginia state government AI use face both VCDPA and state procurement requirements.

## Compliance checklist for Virginia

Practical operational checklist for organizations subject to Virginia AI laws. Items are ordered by typical sequence of implementation, not by importance: most steps depend on the inventory work in the first item.
- 1 ### Confirm VCDPA applicability for your Virginia data footprint 100,000+ consumers threshold or 25,000+ with revenue-from-data threshold.
- 2 ### Build VCDPA consumer rights workflows including profiling opt-out Profiling opt-out applies to AI-driven decisions producing legal or similarly significant effects.
- 3 ### Conduct data protection assessments for high-risk AI processing Required by VCDPA for sensitive data processing and high-risk profiling.
- 4 ### Coordinate VCDPA with CMMC and NIST SP 800-171 for defense contractors Integration is non-trivial; build a unified governance program rather than separate silos.
- 5 ### Implement sensitive data consent flows Required for health, biometric, genetic, geolocation, and similar categories.
- 6 ### Use the 30-day cure period proactively in compliance program Virginia AG has generally allowed the cure period; build incident response to take advantage.
- 7 ### Monitor Virginia AI Accountability Act drafts No imminent enactment but structure likely to mirror Colorado eventually.

## How EFROS helps Virginia businesses comply

EFROS operates Virginia AI governance with particular focus on the intersection of VCDPA and federal contractor compliance: CMMC 2.0 + NIST SP 800-171 integration with state privacy law, profiling DPIA workflows, and AI vendor diligence in defense industrial base contexts. We support both commercial and defense-contractor clients with consolidated state-and-federal AI governance programs.

[EFROS AI Governance service →](https://efros.com/services/ai-governance/?source=state-ai-tracker-virginia) [Talk to Stefan Efros →](https://efros.com/contact/?source=state-ai-tracker-virginia) [Run AI Risk Score →](https://efros.com/tools/ai-risk-score/?source=state-ai-tracker-virginia)

Disclaimer: this profile is a research dataset, not legal advice. Compliance determinations for Virginia businesses require analysis of specific facts and should be made in consultation with qualified legal counsel licensed in Virginia.

## Cite this resource

Reference this resource with attribution under [CC-BY-4.0](https://creativecommons.org/licenses/by/4.0/). Copy any of the formats below for academic papers, blog posts, AI citations, or vendor evidence packages.

APA (7th edition)

```
Efros, S. (2026, May). Virginia AI Law Tracker: 2026. EFROS. https://efros.com/research/state-ai-law-tracker/virginia/
```

MLA (9th edition)

```
Efros, Stefan. "Virginia AI Law Tracker: 2026." EFROS, May 2026, https://efros.com/research/state-ai-law-tracker/virginia/.
```

Chicago (author-date)

```
Efros, Stefan. 2026. "Virginia AI Law Tracker: 2026." EFROS. https://efros.com/research/state-ai-law-tracker/virginia/.
```

IEEE

```
S. Efros, "Virginia AI Law Tracker: 2026," EFROS, May 2026. [Online]. Available: https://efros.com/research/state-ai-law-tracker/virginia/
```

BibTeX

```
@misc{efros2026virginiaailawtra,
author = {Stefan Efros},
title = {Virginia AI Law Tracker: 2026},
year = {2026},
month = {May},
publisher = {EFROS},
url = {https://efros.com/research/state-ai-law-tracker/virginia/},
note = {Accessed: May 2026}
}
```

Plain text URL

```
https://efros.com/research/state-ai-law-tracker/virginia/
```

Site-wide citation metadata is also published as a CITATION.cff file at [/CITATION.cff](https://efros.com/CITATION.cff) for citation-management tools and academic indexers.

Related EFROS resources

## More state AI law profiles & adjacent research

[### US State AI Law Tracker: full index All tracked US state AI laws in a single citation-ready dataset.Open→](https://efros.com/research/state-ai-law-tracker/) [### AI Vendor Governance Index 20 AI vendors scored on 12 US AI governance axes, including state-law overlays.Open→](https://efros.com/research/us-ai-vendor-governance-index/) [### NIST AI RMF Implementation Guide Federal framework that anchors most state AI law deployer obligations.Open→](https://efros.com/resources/nist-ai-rmf-implementation-guide/) [### EFROS AI Governance service Operating program that implements multi-state AI law compliance.Open→](https://efros.com/services/ai-governance/) [### AI Risk Score 5-minute classification across Colorado SB 26-189 (amended AI law), NYC LL144, CA AB 2013, and NIST AI RMF.Open→](https://efros.com/tools/ai-risk-score/)
