Chapter 276A — Information Technology
ORS 276A.346 Secretary of State prohibited from using covered products; risk mitigation; exceptions
As used in this section:
“Artificial intelligence” means a machine-based system that is capable, for a given set of human-defined objectives, of making predictions, recommendations or decisions influencing real or virtual environments and uses machine- or human-based inputs to:
Perceive real or virtual environments;
Abstract the perceptions into models through analysis in an automated manner; and
Use model inference to formulate options for information or action.
“Covered product” means:
Any form of hardware, software or service provided by a covered vendor.
Any hardware, software or service that uses artificial intelligence and the artificial intelligence is developed or owned by a covered vendor.
“Covered vendor” means any of the following corporate entities, or any parent, subsidiary, affiliate or successor entity of the following corporate entities:
Ant Group Co., Limited.
ByteDance Limited.
Huawei Technologies Company Limited.
Kaspersky Lab.
Tencent Holdings Limited.
ZTE Corporation.
“State information technology asset” means any form of hardware, software or service for data processing, office automation or telecommunications used directly by the office of the Secretary of State or used to a significant extent by a contractor in the performance of a contract with the office of the Secretary of State.
Except as provided in subsection (4) of this section, the Secretary of State shall:
Prohibit a covered product from being:
Installed or downloaded onto a state information technology asset; or
Used or accessed by a state information technology asset;
Remove any covered product that is installed or downloaded onto a state information technology asset; and
Implement all measures necessary to prevent the:
Installation or download of a covered product onto a state information technology asset; or
Use or access of a covered product by a state information technology asset.
For any corporate entity that the State Chief Information Officer designates as a covered vendor under ORS 276A.344, the secretary may:
Prohibit a covered product from being:
Installed or downloaded onto a state information technology asset; or
Used or accessed by a state information technology asset;
Remove any covered product that is installed or downloaded onto a state information technology asset; and
Implement all measures necessary to prevent the:
Installation or download of a covered product onto a state information technology asset; or
Use or access of a covered product by a state information technology asset.
If the secretary adopts risk mitigation standards and procedures related to the installation, download, use or access of a covered product, the secretary may, for investigatory, regulatory or law enforcement purposes, permit the:
Installation or download of the covered product onto a state information technology asset; or
Use or access of the covered product by a state information technology asset.
Official sources · 1Tap to view provenance details
Provenance
2025 Oregon Revised Statutes — official online source
Official online edition
- Source
- oregonlegislature.gov
- SHA-256
b4adecc9…5494b22f- Review
- auto verified
Version history
2025 Oregon Revised Statutes — official online source