AI Regulation Tracker / Statutes and critical infrastructure
Montana Passed the First US Right to Compute Law, and It Puts a Real AI Duty on Critical Infrastructure Operators
Montana Senate Bill 212, the Right to Compute Act, was signed by Governor Greg Gianforte on April 16, 2025 as Chapter 150, and it took effect immediately on passage and approval. Most coverage focuses on the constitutional right to own and use computational resources. The provision that actually creates work is Section 4: when a critical infrastructure facility is controlled by a critical artificial intelligence system, the deployer must develop a risk management policy that considers the NIST AI Risk Management Framework or a comparable recognized standard. Note a common misreading up front. The bill was introduced with a shutdown-capability requirement, but that language was removed. The enacted law requires the risk management policy, not a kill switch.
Right to Compute has been getting attention mostly for its libertarian headline, the idea that a state constitution protects your ability to own and run computers and code. That part is real and it is worth reading. But if you advise or run a business that touches Montana critical infrastructure, the headline is not the part that changes your Monday. The part that changes your Monday is a single operative section that quietly imposes an AI governance duty and ties it to a named federal framework.
What Section 4 actually requires
The enacted text is short and specific. In the words of the statute, "When critical infrastructure facilities are controlled in whole or in part by a critical artificial intelligence system, the deployer shall develop a risk management policy after deploying the system that is reasonable and considers guidance and standards in the latest version of the artificial intelligence risk management framework from the national institute of standards and technology." The law then gives alternatives to NIST, naming the ISO/IEC 42001 AI standard or another nationally or internationally recognized risk management framework for AI systems. It also builds in a shortcut: "A plan prepared under federal requirements constitutes compliance with this section." If a covered operator already maintains a federally required plan that governs the same AI control system, that plan can satisfy the state duty.
Read the trigger carefully, because it is narrower than it looks. The duty attaches only when two conditions meet. The facility is a critical infrastructure facility, which the statute defines by reference to existing Montana law at section 82-1-601. And the AI running it qualifies as a critical artificial intelligence system, which the statute defines as an AI system designed and deployed to make, or to be a substantial factor in making, a consequential decision. The definition then carves out a long list of ordinary tools: systems doing narrow procedural tasks, antifraud, antivirus, cybersecurity, spam filtering, spreadsheets, search, and general natural-language assistants that operate under an acceptable use policy against unlawful content. So a spreadsheet macro or a chatbot on the corporate website does not trip the duty. An AI system that makes or heavily drives consequential operational decisions at a covered facility does.
The right-to-compute half, and why the framing matters
The other half of the law is a rights statement grounded in the Montana constitution. The legislature found that the rights to acquire, possess, and protect property, and the freedom of expression, "also embody the notion of a fundamental right to own and make use of technological tools, including computational resources." Government actions that restrict private ownership or use of computational resources for lawful purposes must be, in the statute's words, "limited to those demonstrably necessary and narrowly tailored to fulfill a compelling government interest." The law then defines a compelling interest to include ensuring that a critical infrastructure facility controlled by AI develops a risk management policy, addressing fraud and deception, protecting people from harmful deepfakes distributed with actual knowledge, and abating nuisances from physical datacenter infrastructure.
That structure is the interesting design choice. The state grants a broad liberty to compute, then names the AI risk management policy for critical infrastructure as one of the narrow, compelling interests that justifies a rule. In other words, Montana positioned the governance duty not as heavy-handed AI regulation but as the kind of narrowly tailored public-safety measure its own right-to-compute framework permits.
Correcting the record on the shutdown requirement
You will see SB 212 described, including in some legislative tracking summaries, as a law that requires shutdowns of AI-controlled critical infrastructure. That description tracks the bill as introduced, not the law as enacted. The introduced title called for shutdown capabilities. During passage, that language was struck and replaced with the risk management policy requirement, which is why the enrolled bill title reads as a revision from shutdown capabilities to a risk management policy. The version the governor signed does not command a human shutdown, a kill switch, or a manual override. It commands a documented, standards-based risk management policy. If you are briefing a client or a board, do not overstate this. The duty is real, but it is a governance and documentation duty, not an engineering mandate to install an off switch.
Why a US professional should care
Two reasons, one direct and one strategic.
The direct reason is compliance for anyone touching Montana critical infrastructure. If your company, or a client, operates a facility that falls within Montana's critical infrastructure definition and runs it on an AI system that makes or substantially drives consequential decisions, there is now a statutory duty to have a written, reasonable risk management policy that considers NIST AI RMF or an equivalent standard. That is a concrete deliverable an executive or general counsel can be asked to produce. The good news is that the framework it points to, the NIST AI Risk Management Framework, is voluntary federal guidance that many mature operators already use, so compliance often means formalizing and documenting what a well-run program already does, and confirming whether an existing federally required plan already covers it.
The strategic reason is that Montana went first. A right-to-compute statute that pairs computational liberty with a NIST-anchored governance duty for critical infrastructure is a template other states can copy or react against. For executives and advisers building AI governance programs, anchoring on NIST AI RMF is now not just best practice, it is the standard a US statute has chosen to name. Building your program around a recognized framework is the move that travels across whichever state rules land next.
What to do now
Keep it practical. First, determine exposure: does the business operate anything that meets Montana's critical infrastructure definition, and is a critical AI system making or substantially driving consequential decisions there. If both are true, the Section 4 duty applies. Second, check whether an existing federally required plan already governs that AI control system, because the statute treats a federal-requirement plan as compliance. Third, if there is a gap, stand up a reasonable risk management policy that expressly considers the latest NIST AI RMF or ISO/IEC 42001, and document it so you can show the work. Fourth, separate the messaging in any board briefing: the enacted law is a documentation duty, not a shutdown mandate, and saying otherwise invites a credibility problem. And keep NIST AI RMF at the center of your governance stack regardless of Montana, because it is the framework US law is increasingly pointing to.
Questions professionals are asking
What does Montana SB 212 actually require of AI operators?
When a critical infrastructure facility is controlled in whole or in part by a critical AI system, the deployer must develop a reasonable risk management policy that considers the latest NIST AI Risk Management Framework, the ISO/IEC 42001 AI standard, or another recognized framework. A plan prepared under federal requirements satisfies the duty. It is a documentation and governance requirement, not an engineering mandate.
Does the law require a human shutdown or kill switch?
No, not in the enacted version. The bill was introduced with a shutdown-capability requirement, but that language was struck during passage and replaced with the risk management policy requirement. The version signed into law imposes the policy duty only. Descriptions that say the law requires shutdowns of AI-controlled infrastructure are describing the introduced bill, not the enacted statute.
When did it take effect?
It is already in force. Governor Gianforte signed SB 212 on April 16, 2025 as Chapter 150, and Section 10 makes the act effective on passage and approval, so it took effect that day. This is a 2025 statute, presented here as evergreen background, not breaking news.
Who is covered, and who is not?
The duty applies only when both a critical infrastructure facility, defined by reference to Montana law at section 82-1-601, and a critical AI system, one that makes or is a substantial factor in making a consequential decision, are involved. The statute carves out narrow procedural tools, antifraud, antivirus, cybersecurity, spam filtering, spreadsheets, search, and general natural-language assistants under an acceptable use policy. Ordinary office AI does not trigger it.
Why should a US professional outside Montana care?
Because it is the first US right-to-compute law and it anchors its one operational AI duty to the NIST AI Risk Management Framework. That makes it a template other states may copy, and it reinforces NIST AI RMF as the standard US law is choosing to name. For executives and counsel building AI governance programs, aligning to a recognized framework is the durable move.
RELATED BRIEFINGS
- Browse the full AI Regulation Tracker
- Enrolled text of Montana SB 212, the Right to Compute Act (Chapter 150)
- MultiState: Montana Right to Compute Act, what it does (legal analysis)
- NIST AI RMF critical infrastructure profile
- NIST and ISO 42001 crosswalk for your AI governance stack
- Illinois SB 315, the AI Safety Measures Act
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. This briefing summarizes an enacted 2025 Montana statute, presented as evergreen background. Confirm how the law applies to your specific facilities and operations with qualified counsel licensed in Montana.