AI Regulation in Flux: What businesses should do

This is Part Two of a two-part series. Part One is available here.

U.S. law in the area of artificial intelligence is fragmented, consisting of state laws, local regulations, and existing laws regarding privacy and discrimination. Even as the regulatory environment is becoming more hospitable for businesses, the legal risk remains significant, particularly in high-impact and rights use cases.

Transparency is a common denominator. Across jurisdictions, AI regulation appears to be focusing on (1) disclosure of AI use, (2) the ability to explain consequential decisions, and (3) consumer notice and appeal rights.

This trend is evident in both Colorado’s revised law (discussed in Part One), as well as regulation in the European Union.

Even as comprehensive AI regulations retreat from stringent prohibitions on discrimination, U.S. states are enacting highly-focused AI laws, especially in areas that affect individual rights, including hiring, lending, and health care. Although there is no omnibus federal legislation, federal agencies -- including the Equal Employment Opportunity Commission, the Federal Trade Commission, and the Department of Health and Human Services -- have released AI guidance.

In the employment context, we expect regulators and agencies to continue to focus on algorithmic discrimination, bias auditing and testing, and fairness with or without prescriptive governance requirements.

Recommended steps for businesses

Organizations using AI should adopt compliance strategies that include the following:

No. 1: Inventory AI systems. Companies should begin by conducting a comprehensive inventory of all AI and automated decision-making systems used across the organization. This includes not only internally developed tools, but also third-party systems embedded in Human Resources, customer service, marketing, fraud detection, and analytics platforms. Particular attention should be paid to systems used in making “consequential decisions” (for example, hiring, lending, pricing, or access to services), because these uses are most likely to trigger regulatory obligations. The inventory should identify the purpose, inputs and outputs, and data sources of the system, and whether human oversight is involved.

No. 2: Adopt internal governance programs. Organizations should establish internal AI governance programs that define roles, responsibilities, and escalation procedures for AI-related risks. Many companies are aligning with recognized programs such as the AI Risk Management Framework of the National Institute of Standards and Technology, which provides guidance on risk identification, measurement, and mitigation. At a minimum, governance programs should include policies for acceptable AI use, procedures for approving new AI deployments, and documentation standards to demonstrate accountability.

No. 3: Conduct risk and bias assessments. Even if not required by an AI law to do so, companies should evaluate their AI systems for risks related to bias, discrimination, accuracy, and unintended outcomes. For example, employers using AI in hiring should assess whether the system has a disparate impact on protected classes. These assessments may include statistical testing, validation studies, and periodic re-evaluation as systems evolve. Documenting these efforts can be critical in defending against regulatory inquiries or litigation.

No. 4: Ensure transparency. Businesses should put into place clear and consistent disclosure practices regarding their use of AI, particularly where systems influence decisions affecting individuals. This may include providing advance notice that AI is being used, explaining in general terms how the system operates, and offering explanations for adverse decisions where feasible. Internally, companies should also maintain documentation that explains how key decisions are made and what role AI plays in those processes.

No. 5: Monitor regulatory developments. Given the rate of change, companies should establish a process for ongoing monitoring of legal developments at the state, federal, and international levels. This includes keeping up with developments in jurisdictions such as Colorado, California, and New York, as well as in the European Union. Assigning responsibility to legal or compliance personnel -- or engaging outside counsel -- can help to ensure that the organization remains current and avoids being caught off guard by new obligations.

No. 6: Review vendor contracts. Because many AI systems are provided by third-party vendors, companies should carefully review and, where necessary, renegotiate contracts to address compliance responsibilities. Agreements should clearly allocate responsibility for issues such as bias audits, data protection, and regulatory compliance. They should also contain clear provisions addressing indemnification.

The Constangy Cyber Team assists businesses of all sizes and industries with compliance needs. If you would like additional information about state or federal data privacy laws, please contact us at cyber@constangy.com.

The Constangy Cyber Advisor posts regular updates on legislative developments, data privacy, and information security trends. Our blog posts are informed through the Constangy Cyber Team's experience managing thousands of data breaches, providing robust compliance advisory services, and consultation on complex data privacy and security litigation. 

Search

Get Updates By Email

Subscribe

Archives

Jump to Page

Constangy, Brooks, Smith & Prophete, LLP Cookie Preference Center

Your Privacy

When using this website, Constangy and certain third parties may collect and use cookies or similar technologies to enhance your experience. These technologies may collect information about your device, activity on our website, and preferences. Some cookies are essential to site functionality, while others help us analyze performance and usage trends to improve our content and features.

Please note that if you return to this website from a different browser or device, you may need to reselect your cookie preferences.

For more information about our privacy practices, including your rights and choices, please see our Privacy Policy. 

Strictly Necessary Cookies

Always Active

Strictly Necessary Cookies are essential for the website to function, and cannot be turned off. We use this type of cookie for purposes such as security, network management, and accessibility. You can set your browser to block or alert you about these cookies, but if you do so, some parts of the site will not work. 

Functionality Cookies

Always Active

Functionality Cookies are used to enhance the functionality and personalization of this website. These cookies support features like embedded content (such as video or audio), keyword search highlighting, and remembering your preferences across pages—for example, your cookie choices or form inputs during submission.

Some of these cookies are managed by third-party service providers whose features are embedded on our site. These cookies do not store personal information and are necessary for certain site features to work properly.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek