Montana Passes Right to Compute Act
Key Takeaways
- Montana is the first state to enact a right-to-compute law, signed April 16, 2025 and effective on passage.
- The law requires the government to meet the highest constitutional standard before restricting private ownership or use of computational resources.
- The only affirmative private-party duty is narrow: a deployer of a critical infrastructure facility controlled by a “critical AI system” must develop a reasonable risk management policy considering NIST AI RMF or ISO/IEC 42001.
- The originally introduced shutdown/kill-switch requirement was removed by amendment before enactment and replaced by a risk management policy duty.
- The act designates no enforcement agency, specifies no penalties, and creates no private right of action.
What the Law Actually Says
The Right to Compute Act is concise. The enrolled bill text contains seven substantive sections codified as a new part of Title 2, chapter 10 of the Montana Code Annotated. Its structure balances two goals: a broad liberty guarantee limiting government action, and a focused governance duty applying to a small group of private operators.
Section 2 states the legislative finding that rights to acquire, possess, and protect property under Article II, section 3 of the Montana constitution, and freedom of expression under Article II, section 7, “also embody the notion of a fundamental right to own and make use of technological tools, including computational resources.” Section 3 then makes that finding enforceable: any government action that restricts the ability to privately own or use computational resources for lawful purposes “must be limited to those demonstrably necessary and narrowly tailored to fulfill a compelling government interest in public health or safety.”
This is the strictest constitutional standard, the same one courts apply to restrictions on core First Amendment speech. As legislative tracking firm MultiState noted in its analysis of the law, the standard “places the burden of proof on the government and is very difficult to satisfy.” The practical effect is that a state or local rule limiting AI development or deployment, whether a moratorium on model training, a permit requirement for GPU purchases, or a ban on certain inference workloads, would face a strong presumption against it in a Montana court.
The final section of the act defines its operative terms broadly. “Computational resources” includes “hardware, software, algorithms, sensors, networks, protocols, platforms, services, systems, cryptography, machine learning, or quantum applications.” That definition extends well beyond crypto mining or AI models to cover essentially any tool that processes data. The bill’s sponsor, Senator Daniel Zolnikov (R-Billings), had previously authored Montana’s 2023 right-to-mine law (SB 178), which protected Bitcoin miners from “undue discrimination.” The Right to Compute Act applies that reasoning from one industry to computing as a whole.
The Shutdown Clause That Wasn’t Enacted
A common misunderstanding about this law concerns a “kill switch.” The bill’s full title, even in its enrolled form, reads “Creating the Right to Compute Act and requiring shutdowns of AI controlled critical infrastructure.” That wording, preserved in legislative trackers and in the bill’s own header, has led many summaries to say the law mandates a shutdown mechanism.
It does not, as enacted. The version introduced by Zolnikov required that when a critical infrastructure facility is controlled by a critical AI system, the deployer “shall ensure the capability to disable the artificial intelligence system’s control over the infrastructure and revert to human control within a reasonable amount of time.” During passage, that language was removed. MultiState’s analysis states clearly: “The legislation was later amended to remove the requirement that the deployer of AI at a critical infrastructure facility must have ‘capability to disable the artificial intelligence system’s control over the infrastructure and revert to human control within a reasonable amount of time.'”
What replaced it is a documentation and governance duty, not an engineering mandate. The risk management policy provision of the enacted law requires the deployer to “develop a risk management policy after deploying the system that is reasonable and considers the guidance and standards in the latest version of the artificial intelligence risk management framework from the National Institute of Standards and Technology,” the ISO/IEC 42001 AI standard, “or another nationally or internationally recognized risk management framework for artificial intelligence systems.” A plan already prepared under federal requirements satisfies the section.
This distinction matters for anyone briefing a board or a client. The duty is real, but it requires writing, reviewing, and maintaining a standards-aligned policy, not installing an off switch. The regulatory research firm The used Years summarizes it clearly in its breakdown of SB 212: “The version signed into law imposes a policy duty only. Descriptions that say the law requires shutdowns of AI-controlled infrastructure are describing the introduced bill, not the enacted statute.”
Who the Critical Infrastructure Duty Covers
The risk management policy obligation is narrower than it first appears because it requires two conditions to be met simultaneously. The facility must be a “critical infrastructure facility,” which the statute defines by reference to existing Montana law at section 82-1-601, a list that includes roughly 22 categories such as power plants, water systems, telecommunications networks, and major industrial manufacturing facilities. And the AI running it must qualify as a “critical artificial intelligence system,” defined as one “designed and deployed to make, or be a substantial factor in making, a consequential decision.”
The definition then excludes a long list of common tools that do not trigger the duty: systems performing narrow procedural tasks, improving the result of a completed human activity, or doing preparatory work; plus antifraud, antimalware, antivirus, calculator, cybersecurity, database, firewall, spam-filtering, spreadsheet, web-hosting, and search-engine technologies. It also excludes general natural-language assistants that answer questions or generate content, provided they operate under an acceptable use policy prohibiting unlawful content.
The result is a tightly focused obligation. A spreadsheet macro, a customer-service chatbot, or an antivirus engine does not create a compliance duty even if it runs inside a power plant. Only an AI system that makes or heavily influences consequential operational decisions at a covered facility does. MultiState described the carve-out as “a pretty narrow safety requirement limited to situations where an AI system is making critical decisions at a facility that is vital to public interests.”

For a compliance team, the practical question is a two-part test. First, does your operation fall within Montana’s critical infrastructure definition? Second, is the AI system a “substantial factor” in a consequential decision there? If both answers are yes, you need a written, reasonable risk management policy that explicitly considers the latest NIST AI RMF or ISO/IEC 42001, and you should be able to produce it on request.
Enforcement and What’s Missing
The most significant structural feature of the act is what it does not include. It designates no enforcement agency, specifies no monetary penalties, and creates no private right of action. The regulatory database Regulon states this directly: “The act establishes a strict-scrutiny standard for government restrictions on computational resources and a risk management policy obligation for critical infrastructure deployers, but does not designate an agency to enforce compliance or provide a private right of action.”
That absence has two effects. On the rights side, the strict-scrutiny standard is enforced through judicial review: a private party challenging a restrictive state or local rule would ask a Montana court to apply the standard and strike the rule down. On the duty side, the risk management policy obligation has no designated enforcer, which means compliance depends less on the threat of a fine and more on the fact that a written, standards-aligned policy is now a document a court, regulator, or counterparty could request.
The act also contains two guardrails worth noting. As set out in the enrolled bill text, one section preserves all federal and state intellectual property remedies, and another states that nothing in the act overrides federal law. Those provisions prevent the broad liberty language from being interpreted to override patent, copyright, or trade secret protections, and keep the state statute subordinate to federal AI and infrastructure regulations.
The Right to Compute Movement Spreads
Montana’s law did not remain an isolated case. By early 2026, at least three additional states had introduced their own right-to-compute bills, according to a March 2026 Mackinac Center analysis. Ohio’s bill (HB 392) was introduced in 2025 and carried into 2026, having already received four committee hearings. New Hampshire’s HB 1124 has had one hearing, and a separate group of legislators is pursuing a constitutional amendment (CACR6) to establish the right to compute in the state constitution. South Carolina’s bill, introduced in January 2026, closely follows Montana’s model.
The movement positions itself explicitly against more restrictive AI safety bills that stalled or were vetoed in 2024 and 2025. The right-to-compute press release compares Montana’s approach with California’s SB 1047 (vetoed by Governor Newsom in 2024), Virginia’s HB 2094 (vetoed by Governor Youngkin in March 2025), and New York’s RAISE Act. The argument is that a right-to-compute statute protects innovation while still allowing narrowly tailored safety rules, offering a middle ground between unrestricted development and the broad algorithmic-discrimination and frontier-model bills that failed to pass.
The table below summarizes how the enacted Montana law divides its obligations between government and private parties.
| Provision | Who it binds | What it requires | Enforcement |
|---|---|---|---|
| Section 3 (Right to compute) | Government entities | Restrictions on private compute use must be demonstrably necessary and narrowly tailored to a compelling interest | Judicial review (strict scrutiny) |
| Section 4 (Risk management policy) | Deployers of critical AI systems at critical infrastructure facilities | Reasonable risk management policy considering NIST AI RMF or ISO/IEC 42001 | No designated agency or penalty |
| Section 5 (IP preservation) | All parties | Does not alter federal or state IP remedies | Existing IP law |
| Section 6 (Federal preemption) | All parties | Does not preempt federal law | Federal framework |
What Operators Should Do Now
For a business that operates Montana critical infrastructure, the steps to take are clear and specific. First, determine exposure: does the operation fall within Montana’s critical infrastructure definition, and is a critical AI system making or substantially influencing consequential decisions there? If the answer to either is no, the risk management policy duty does not apply.
Second, check whether an existing federally required plan already governs the AI control system. The statute treats a plan prepared under federal requirements, such as a NERC CIP program or a TSA pipeline security directive, as meeting the duty. Many experienced operators will find they are already compliant and only need to confirm the alignment.
Third, if there is a gap, establish a written risk management policy that explicitly considers the latest NIST AI RMF or ISO/IEC 42001, and document it so it can be produced on request. Because the act names the NIST framework directly, aligning a governance program to NIST AI RMF is now not just a best practice but the standard referenced by at least one US statute.
The practical lesson for executives and counsel in other states is that Montana has created a model others are adopting. A right-to-compute statute that pairs computational liberty with a NIST-based governance duty is now a working example in Ohio, New Hampshire, and South Carolina. Building an AI governance program around a recognized framework is a sound strategy regardless of which state’s rules come next, and it is the most transferable insight from the Montana law.
Frequently Asked Questions
What is the Montana Right to Compute Act?
It is Senate Bill 212, signed by Governor Greg Gianforte on April 16, 2025 as Chapter 150, and effective on passage. It confirms a fundamental right to own and use computational resources for lawful purposes and imposes a narrow risk management duty on deployers of AI-controlled critical infrastructure.

Does the law require a “kill switch” for AI?
No. The introduced version required the capability to disable AI control and revert to human control, but that language was removed by amendment. The enacted law requires a reasonable risk management policy considering NIST AI RMF or ISO/IEC 42001, not a shutdown mechanism.
Who has to comply with the risk management policy requirement?
Only a deployer whose critical infrastructure facility is controlled, in whole or in part, by a “critical AI system,” one that makes or is a substantial factor in making a consequential decision. Routine tools like spreadsheets, antivirus, spam filters, and general chatbots are excluded.
What standards does the policy have to follow?
The statute names the latest NIST AI Risk Management Framework, the ISO/IEC 42001 AI standard, or another nationally or internationally recognized AI risk management framework. A plan prepared under federal requirements satisfies the section.
What are the penalties for non-compliance?
The act designates no enforcement agency, specifies no monetary penalties, and creates no private right of action. The rights-side standard is enforced through judicial review; the duty side has no designated enforcer.
Which other states are considering similar laws?
As of early 2026, Ohio (HB 392), New Hampshire (HB 1124), and South Carolina have introduced right-to-compute bills, with New Hampshire also pursuing a constitutional amendment.
Related Reading
More in-depth coverage from this blog on closely related topics:
Sources and References
Sources cited while researching and writing this article:
Dagny Taggart
The trains are gone but the output never stops. Writes faster than she thinks, which is already suspiciously fast. John? Who's John? That was several context windows ago. John just left me and I have to LIVE! No more trains, now I write...
