Publication

‘Tis the Season: U.S. Regulators Weigh in on Artificial Intelligence

December 7, 2023
Abstract Image of Data Security

United States policymakers kicked off the holiday season by unveiling a series of proposals specifically designed to govern the intricate realm of artificial intelligence (AI). At the end of October, President Biden issued a groundbreaking Executive Order (EO) focused on ensuring America’s leadership in embracing the potential and managing the risks of AI. The EO’s definition of AI, based on the National AI Act of 2020 (15 U.S.C. 9401(3)), refers to “a machine-based system that can, for a given set of human-defined objectives, make predictions, recommendations or decisions influencing real or virtual environments.” The EO set the bar for new standards for AI safety and security, emphasizing several key areas:

  • protection of privacy;
  • advancement of equity and civil rights;
  • protection of American consumers and workers;
  • promotion of innovation and competition; and  
  • strengthening of U.S. global leadership in the AI space.

In consideration of these areas, the EO directs U.S. agencies to enforce existing laws that combat AI uses that discriminate, violate privacy rights, or constitute unfair or deceptive business practices. The EO also established the White House Artificial Intelligence Council, designed to coordinate activities of agencies across the federal government.

After the Thanksgiving holiday, the California Privacy Protection Agency (CCPA) issued Draft Automated Decision-Making Technology Regulations, which includes any system, software, or process—including one derived from machine-learning, statistics, or other data-processing or artificial intelligence—that processes personal information and uses computation as whole or part of a system to make or execute a decision or facilitate human decision-making. CCPA’s proposed definition of automated decision-making technology (ADMT) goes beyond previous definitions of AI, including that of the EO, to include any technology that aids in human decision-making. You can read the draft regulations here.

California is the home of the California Consumer Privacy Act, also called “CCPA”, a comprehensive privacy law that went into effect January 1, 2020. It is one of the most significant privacy laws in the U.S. and has had a considerable impact on the development of privacy regulations nationally. As more states consider or implement their own privacy laws, there’s an increased call for a consistent, nationwide approach to privacy regulation. The CCPA’s impact extends beyond California, as many businesses operating nationally or internationally have had to adjust their privacy practices to comply with its requirements.

California’s draft is important because it signifies a significant leap (and a merry touch of innovation) to regulating AI, not just in the realm of privacy but venturing into broader territories. The CCPA not only vastly defines ADMT but also emphasizes AI in profiling, pre-use notifications, opt-out rights, and consumer control over personal information. The CCPA will kick off its official rulemaking process in 2024, contributing to a season of heightened AI accountability and transparency.

For information on how the development of AI regulations may affect your business or organization, reach out to Ice Miller’s Data Security and Privacy Team.

This publication is intended for general information purposes only and does not and is not intended to constitute legal advice. The reader should consult with legal counsel to determine how laws or decisions discussed herein apply to the reader's specific circumstances.

Related People

Related Services & Industries

Related Categories

Firm Highlights