What Michigan's Proposed AI Workplace Law Would Require of Employers
Originally Published: Sept. 15, 2026
By Tracey Birkenhauer, journalist and Chief Impact Officer, STACK Cybersecurity
A production supervisor at a mid-sized Michigan manufacturer gets an automated alert flagging an employee for "low engagement." The score comes from software that tracks keystrokes, mouse movement and idle time on a shop-floor workstation. No one on the management team wrote the criteria. No one reviewed the specific flag before it landed in the employee's file. The vendor built the model; the company just turned it on.
That kind of arrangement is exactly what a pair of bills moving through the Michigan Legislature would restrict. House Bill 5579 and its Senate companion, Senate Bill 1077, would place some of the strictest limits in the country on how employers use artificial intelligence to monitor workers and make employment decisions. Neither bill has passed, but both are active, and Michigan employers, especially those with union workforces or high-volume hiring, should understand what they would require.
Executive Summary
House Bill 5579, introduced Feb. 24, 2026, by state Rep. Penelope Tsernoglou, D-East Lansing, and a Senate companion, Senate Bill 1077, introduced June 24, 2026, by state Sen. Darrin Camilleri, D-Detroit, would create Michigan's first law governing employer use of automated decision tools and electronic workplace monitoring. Both bills are known as the Responsible AI Security for Employees Act. They would bar employers from using automated tools to make employment decisions except for narrow purposes, such as screening large volumes of applicants, and would require notice, consent, impact assessments and union bargaining before deploying monitoring software. The consent requirement includes an opt-out right that, once exercised, bars an employer from using that person's monitoring data for any employment decision at all. Both bills remain in committee as of Sept. 14, 2026, and neither has received a floor vote.
A separate bill, House Bill 4668 from Republican Rep. Sarah Lightner, targets AI developers directly with audit and whistleblower requirements. Michigan employers do not need to comply with either bill today, but the compliance questions they raise are landing on top of the Earned Sick Time Act, which manufacturers have already told state lawmakers is straining attendance policy and shop floor staffing. The direction of the debate, and the coalition backing it, make this worth tracking now.
What House Bill 5579 Would Require
The full text of House Bill 5579 and its Senate companion, Senate Bill 1077, is available on the Michigan Legislature's website. Section 4 would bar an employer, or a third party or service provider acting on an employer's behalf, from using an automated decisions tool to make an employment-related decision, with an exception for screening large volumes of job applications. The bill defines an employment-related decision broadly enough to cover wages, benefits, hours, work schedule, performance evaluation, hiring, discipline, promotion, termination, job content, assignment of work and workplace health and safety.
Section 5 lists the only purposes for which an employer may use an electronic monitoring tool at all: to help an employee do an essential job function, to monitor production processes or quality, to periodically assess performance, to comply with labor law, to protect health and safety, to administer wages tied to cost of living, or another business purpose the state labor department approves. Even within those allowed purposes, an employer using either tool must do all of the following:
- Provide written notice and get written consent from every covered individual before monitoring begins.
- Use the tool in the least invasive way possible, on the smallest number of people, collecting the least amount of data necessary.
- Complete a written impact assessment, conducted by an independent third party with no financial ties to the tool, one full year before deployment.
- Retain data no more than three years and never sell or license it, even if deidentified.
The bill's data categories go beyond what most employers currently treat as sensitive: health and medical information, personnel files, productivity data, workplace communications including emails and internal messaging, device usage and geolocation, and any output an automated decisions tool generates about a specific person. Section 5(5) bans facial, gait, voice or emotion-recognition technology outright, with no consent exception at all.
AI Governance Starts With Knowing What's Running
Michigan employers don't need to comply with House Bill 5579 or Senate Bill 1077 today. The bills expose a problem that exists regardless of whether either proposal becomes law: many businesses can't produce a complete inventory of the AI tools being used by employees.
AI use is no longer limited to someone opening ChatGPT in a browser. Employees may use personal AI accounts, browser extensions, transcription tools, AI features embedded in software the company already licenses, automated workflows, scripts and connections to external models. Human Resources may also be using recruiting, screening, productivity, or monitoring products that contain automated decision features management doesn't think of as AI.
That creates a basic governance problem. Before a business can determine whether an AI system affects employees, processes sensitive information, or falls within a legal requirement, it must identify the system, understand what it does, and determine who approved it.
STACK Cyber's Managed AI addresses that first layer by discovering AI use across managed environments, establishing sanctioned AI workspaces, enforcing an AI Acceptable Use Policy, and reporting on shadow AI activity. Higher service levels add managed connections, blocked-site review, prompt-level oversight, private infrastructure options, and periodic maturity reviews. Those controls can support an AI governance program, but they don't replace legal review, employee notices, consent requirements, or an independent impact assessment when the law requires them.
The pending Michigan bills may change substantially or never become law. Businesses still benefit from identifying the AI they use, document who owns it, control where sensitive information goes, and show that written policies are being enforced.
The Opt-Out Provision Employers Should Read Twice
Section 13 requires 30 days' written notice before an employer implements any monitoring or automated decision tool, delivered in every job posting, on the employer's website and directly to every applicant. That notice must give each covered individual the ability to opt out. Section 13(3) then states that if a covered individual opts out, the employer cannot use that tool to make any employment-related decision about that person at all.
For an employer monitoring remote staff specifically because of a documented performance issue, that provision creates an obvious problem: the employee with the most reason to avoid scrutiny has a legal path to opt out of the exact tool meant to document the issue. The bill doesn't include an exception for monitoring based on reasonable suspicion of misconduct or an existing performance record. Once an employee opts out, the employer is left choosing between dropping the monitoring entirely for that person or building a case through other means, such as direct supervisor observation and documented conversations, which the bill does not restrict in the same way.
Where the Bill Came From
Tsernoglou introduced HB 5579 at a Feb. 23, 2026, news conference in Lansing alongside the Michigan AFL-CIO, the Professional Employees Council of Sparrow Hospital, and the Communications Workers of America. At that event, Tsernoglou described examples such as employee body cameras used to deter theft, pay docked when a computer mouse sits idle for more than two minutes, and tracking of employees' bathroom breaks as the kind of surveillance the bill is meant to stop.
Tsernoglou said dozens of Democratic colleagues signed on as cosponsors, but as of the bill's introduction, no Republican lawmaker had joined it, though she said she had shared the legislation with GOP colleagues. The Senate version, SB 1077, was introduced four months later by Camilleri along with 17 other Senate Democrats and referred to the Senate Labor Committee.
Business Concerns About the Bill
The Michigan Chamber of Commerce has raised concerns about HB 5579's scope. In a Feb. 25, 2026, analysis, the chamber said the bill could create significant administrative and legal obligations for employers even when AI tools are used responsibly, pointing to the new civil fines, damages and mandatory audits the bill would create. The chamber has said it wants any final legislation to rest on verified facts and clear, practical standards rather than isolated anecdotes. It has asked Michigan employers to weigh in as the bill moves through the process.
That tension, between employee privacy protections and employer flexibility to use AI tools for legitimate safety and productivity purposes, is likely to shape how far the bill moves and what amendments it picks up along the way.
What a Data Breach Would Cost Under This Bill
Section 11 sets requirements for a security breach involving data collected through a monitoring or automated decisions tool that go well beyond Michigan's general breach notification law. An employer would have 48 hours, not the standard 30 days, to notify every affected covered individual. The employer would also have to provide each of them 10 years of paid identity theft protection, including an insurance policy of at least $5 million covering financial loss and legal fees, along with credit monitoring, dark web monitoring, and a three-bureau credit freeze. Section 9 separately requires the underlying impact assessment to be redone every year the tool stays in use, not just once at rollout.
The bill sets the coverage floor but not a price, so it helps to compare it against what breach-response vendors already charge. Enterprise breach-response providers typically price a comprehensive post-breach package, one that includes credit monitoring, dark web monitoring and a $1 million to $2 million insurance rider, at $15 to $30 per affected person per year, according to pricing benchmarks compiled by DataBreachCost.com. Those packages usually run one to four years. Consumer identity theft insurance policies rarely exceed $3 million in coverage at all, according to a 2026 ConsumerAffairs pricing survey, which puts HB 5579's $5 million floor at the outer edge of what the market sells today.
Line up those figures against what enterprise breach-response vendors already sell, and the gap is stark on three separate dimensions at once: how fast an employer has to notify people, how much insurance coverage is required, and how long that coverage has to last.
- Notification window: standard breach-response practice allows up to 30 days. HB 5579 requires notice within 48 hours, roughly 15 times faster.
- Insurance coverage floor: enterprise breach-response packages typically carry $1 million to $2 million in coverage. HB 5579 sets a $5 million floor, up to five times higher.
- Protection duration: enterprise packages typically run one to four years. HB 5579 requires 10 years of coverage, up to 10 times longer.
None of those three requirements is extreme in isolation. Faster notification helps affected employees respond sooner. More coverage and a longer protection window help someone whose data was exposed. Stacked together, though, they add up to a compliance obligation well beyond what most employers, in any industry, currently build into their breach response plans.
That chart covers the identity protection mandate alone. Three other costs stack on top of it. Section 11(2) requires an employer to contract with a third party to audit the monitoring tool after any breach, which typically runs into the tens of thousands of dollars depending on scope. Section 15 creates a private right of action with no cap on damages or attorney fees, on top of the $500 civil fine the state can pursue separately. And standard breach response costs, forensic investigation, legal counsel and notification logistics, apply regardless of this bill. IBM's 2025 Cost of a Data Breach Report put the average total cost of a breach in the industrial sector at $5 million, and the U.S. average across all industries at a record $10.22 million, both well above the identity protection costs alone. For a 250-employee manufacturer, a breach involving a monitoring tool's data could reasonably run from the low hundreds of thousands into seven figures once every layer is added together.
A Companion Bill Targets AI Developers
HB 5579 and SB 1077 aren't the only Michigan AI bills touching the workplace. Republican Rep. Sarah Lightner has introduced House Bill 4668, which would take a different approach: rather than regulating how employers use AI, it would require large AI developers to conduct regular risk assessments, adopt safety protocols and undergo third-party audits, and it would extend whistleblower protections to employees of AI companies themselves. Both HB 5579 and HB 4668 remain in committee, and neither had received a floor vote as of Sept. 8, 2026, according to Michigan Public Radio affiliate WILX.
Ryan Sebolt, director of government affairs for the Michigan AFL-CIO, said labor advocates plan to keep pushing on both fronts as workforce AI use grows. The two bills, from lawmakers in opposite parties, show that AI's effect on Michigan workers is drawing attention across the aisle, even if the two bills approach the problem differently.
How This Fits Into Michigan's Broader AI Legislative Picture
Michigan's enacted AI laws so far have focused mostly on political deepfakes and nonconsensual intimate imagery, not workplace AI. Senate Bill 760, the state's pending chatbot safety bill, has passed the Senate but remains in a House committee. HB 5579 and SB 1077 would be the state's first attempt at regulating employer use of automated decision-making and monitoring tools specifically. For the full picture of what's enacted, pending and proposed across the country, see our state AI law tracker, and for a comparison to how other states are regulating AI in hiring and employment decisions, see our AI in employment and health care guide.
Artificial Intelligence Readiness Evaluation (AIRE)
STACK Cybersecurity developed a custom evaluation tool for businesses of all sizes to gauge their AI readiness. Our comprehensive assessment offers you a custom score. Select the button below to start your evaluation.
A Second Compliance Burden Already in Effect
HB 5579 and SB 1077 would not arrive in a vacuum. Michigan's Earned Sick Time Act, which took effect Feb. 21, 2025, already requires most employers to let staff accrue and use paid sick time with limited ability to question how it's used. In testimony submitted to the Michigan House, one manufacturer described rejecting a wave of paid-time-off requests around hunting season and said the law leaves employers unable to enforce a normal attendance policy once an employee cites earned sick time for a late arrival. Another described dozens of workers absent on the first day of hunting season alone.
That testimony speaks to shop floor attendance, not automated monitoring, but the two issues compound each other. An employer already managing higher absenteeism under ESTA and now facing new notice, consent and impact assessment requirements for any tool used to track attendance or performance is looking at two separate compliance regimes layered on top of each other, both enacted within roughly two years of each other.
What Michigan Employers Should Do Now
Neither bill is law, and neither is close to a floor vote. But the underlying practices these bills target, deploying AI monitoring or screening tools without a clear internal record of how they work, who reviews their output and what happens with the data, create risk on their own, regardless of what the Legislature eventually passes. A business that can already answer basic questions about its AI-driven HR tools, what they do, who approved them, how long data is kept, is in a stronger position whether this bill becomes law, stalls in committee or comes back next session in a different form.
Frequently Asked Questions
Is Michigan's AI workplace bill law yet?
No. House Bill 5579 and Senate Bill 1077 are both pending in committee as of Sept. 14, 2026. Neither has received a floor vote in either chamber.
What would House Bill 5579 prohibit?
It would bar employers from using automated decision tools to make employment-related decisions such as hiring, promotion, discipline or termination, except for narrow purposes like screening large volumes of job applicants.
Would the bill apply to employee monitoring software?
Yes. Beyond automated decision tools, the bill would require notice, consent and an opt-out option before an employer collects data through electronic monitoring tools, along with a written impact assessment before deployment.
Who supports and opposes the legislation?
The Michigan AFL-CIO, the Professional Employees Council of Sparrow Hospital and the Communications Workers of America back the bill. The Michigan Chamber of Commerce has raised concerns about the administrative and legal burden the bill could place on employers.
Is there a separate bill regulating AI developers in Michigan?
Yes. House Bill 4668, introduced by Rep. Sarah Lightner, would require large AI developers to conduct risk assessments, adopt safety protocols, undergo third-party audits and extend whistleblower protections to their employees. It is a separate bill from HB 5579 and targets AI companies rather than employers that use AI tools.
Could an employee opt out of monitoring tied to a performance issue?
Under the bill as introduced, yes. Section 13 gives every covered individual the right to opt out of an electronic monitoring tool or automated decisions tool, and once someone opts out, the employer cannot use that tool to make any employment-related decision about them. The bill does not carve out an exception for monitoring based on a documented performance issue or suspected misconduct.
How much could a data breach cost under House Bill 5579?
The identity protection mandate alone, 10 years of coverage at a $5 million floor per affected person, could reasonably run $750 to $2,000 per person based on current market pricing, according to STACK Cybersecurity's analysis of enterprise breach-response benchmarks. That is before the mandatory third-party audit, potential private right of action claims, and standard breach response costs, which IBM's 2025 Cost of a Data Breach Report puts at a $5 million average for the industrial sector nationally.
Primary sources: House Bill 5579, Senate Bill 1077, House Bill 4668, manufacturer testimony on the Earned Sick Time Act submitted to the Michigan House, and IBM's 2025 Cost of a Data Breach Report.
Need Help Governing AI in Your Workplace?
STACK Cybersecurity helps businesses inventory their AI tools, document governance policies and prepare for a shifting compliance landscape. Email info@stackcyber.com or call (734) 744-5300.