In mid-August, Taft published the latest edition of The Big Long List of U.S. AI Laws. The list now includes over 60 entries focused on the commercial regulation of AI by the states.
Despite persistent rumors to the contrary, AI law compliance is anything but a detail or triviality.
There is nothing particularly glamorous about notifying your job applicants of your AI, putting disclaimers on your chatbot, conducting risk assessments, disclosing data sources, developing policies, or ensuring contracting standards. But, increasingly, requirements such as these are required or advisable under law for a growing number of particular AI applications. Businesses that develop and deploy AI without carefully considering the growing list of compliance issues do so at their own risk.
New entries on the latest list include:
- Illinois Artificial Intelligence Safety Act. From the bulletin: “Requires certain AI model developers to develop, implement, publish, and annually update a frontier AI framework addressing potential catastrophic risk and to obtain independent third-party audits of covered frontier models, report safety incidents within strict timeframes, and prohibit retaliation against employees who report such risks. Requires frontier developers to publish a transparency report before deploying or substantially modifying a covered model, disclosing its release date, intended uses, and restrictions.”
- Three Separate Rhode Island Laws. HB 7538 requires health care providers and facilities to notify patients of the use of AI, and to engage in quality control review of AI documentation after the visit. HB 7350 requires disclosures to consumers around the use of “AI Companion” applications. Such applications must also detect expressions of self-harm and respond appropriately. And SB 2197 restricts the use and advertising of AI for therapeutic purposes.
- South Carolina. HB 4591 reflects unique regulation on social media. If a platform uses AI to estimate user ages (noting that such estimation is required), it must refresh or update that estimate when using AI to update certain other information.
- NAIC / Insurance Regulation. Our list now notes the wide adoption, across states, of a model bulletin governing the use of AI by insurance providers. I previously wrote about AI in the insurance industry context here.
- Connecticut’s Online Safety Act, signed in May with provisions effective this October, probably deserves an honorable mention. Though it escaped the notice of many businesses at the time, this statute reflects a broad AI regulation with special focus on subscription services (SaaS providers beware!), frontier developers, HR applications, companion bots, and restrictions on the provision of algorithmic feeds to minors in the social media context.
To keep up with the latest for the latest in privacy, security, and artificial intelligence legal news, you can follow us here at Privacy and Data Security Insights and on LinkedIn. Should you need counsel in any of these areas, Taft’s Privacy, Security & AI attorneys are ready to assist.
Recent Comments