The regulation of artificial intelligence (AI) has drawn significant interest from policymakers in the US, particularly at the state level. There has been a recent slew of legislative activity with respect to comprehensive AI bills across various states. We expect to see this new wave of comprehensive AI regulation at the state level continue to increase over the coming months. Early state AI laws have the potential to exert an outsized influence on the trajectory of AI regulation in the US.
The need to develop comprehensive AI laws inherently stems from a need to ensure consumer protection in the use of AI – including ensuring transparent and nondiscriminatory use of AI and appropriate protections regarding the collection and processing of personal data in connection with AI. To this point, regulators appear to be focused on how companies are using consumer personal data to train and develop their AI and machine-learning models and algorithms. As we discussed in this January 2024 cyber/data/privacy insights blog post regarding the Federal Trade Commission’s Rite Aid enforcement action, the use of personal data to train AI and machine-learning algorithms has the potential to significantly impact consumers, including by resulting in algorithmic discrimination.
The latest regulations recently passed in Utah and Colorado have focused on broader consumer protection objectives in the use of AI. This blog post summarizes those AI laws, covers AI bills that have gained significant traction in Connecticut and California, and suggests what companies should be doing now to prepare.
Utah’s Artificial Intelligence Policy Act and Colorado’s SB 205
On March 13, 2024, Utah became the first US state to enact a broad consumer protection statute specifically governing AI with passage of the Utah Artificial Intelligence Policy Act (AIPA), which has a particular focus on ensuring transparent use of AI. Effective as of May 1, 2024, the AIPA imposes disclosure obligations on covered entities related to their use of generative AI (gen AI) technologies and provides for liability for violations, including civil penalties, calculated on a per-violation basis.
To encourage innovation, the AIPA also creates a new AI regulatory body, the Office of Artificial Intelligence Policy, tasked with establishing an AI “Learning Laboratory Program” aimed at, among other things, analyzing risks and benefits related to the development and use of AI technologies (and their related policy implications) to inform the state’s broader approach to regulating AI. The AIPA will establish procedures for inviting entities to participate in – and receiving requests to participate in – the learning laboratory. In line with this industry engagement, the AIPA also introduces the opportunity for participants to enter into regulatory mitigation agreements, which provide participants with the option to mitigate certain regulatory consequences in exchange for the participant agreeing to implement certain safeguards and limit the scope of use of their technology.
Following on Utah’s heels, Colorado has enacted its own comprehensive AI regulation with SB 205, known as the Colorado AI Act, which was signed into law by Gov. Jared Polis on May 17, 2024. The law will go into effect on February 1, 2026. Compared to Utah’s AIPA, which focuses primarily on transparency through disclosure requirements for the deployment of AI in consumer interactions, Colorado’s SB 205 imposes a wider range of obligations on developers and deployers of certain AI systems, focused primarily on algorithmic discrimination. It also adopts a risk-based approach to AI regulation, similar to the European Union AI Act – the world’s first major law to regulate AI, passed by the European Parliament in March 2024.
The following chart compares some of the core aspects of the two acts:
Other states race to enact robust AI regulation
AI-specific legislation has been proposed in a number of other states, and we expect that more states will soon follow. For example, AI-specific proposals are currently gaining significant traction in the following states:
Connecticut
Similar to Colorado’s SB 205, Connecticut’s SB 2 would regulate developers and deployers of high-risk AI systems and establish requirements related to risk management, impact assessments and consumer rights. The Connecticut bill also defines and lays out requirements for what it calls “general-purpose AI models,” defined as models that display significant generality, are capable of competently performing a wide range of distinct tasks, and can be integrated into a variety of downstream applications or systems. Under SB 2, developers of general-purpose AI models that generate or manipulate synthetic digital content also would be required, among other things, to mark their outputs as synthetic in a way that is detectable by consumers. If enacted, SB 2’s regulations would take effect in a phased approach, with some provisions taking effect as early as July 1, 2025.
California
California’s AB 2930 has many similarities to Colorado’s SB 205 (and Connecticut’s SB 2). AB 2930 would, among other things, require developers and deployers of an “automated decision tool” – defined as a system/service that uses AI and has been specifically developed or modified to make (or to be a substantial factor in making) consequential decisions – to perform impact assessments prior to using such a tool and annually thereafter. Like Colorado’s SB 205 and Connecticut’s SB 2, AB 2930 would provide certain rights to consumers, including a qualified right not to be subject to such an automated decision tool, if technically feasible. AB 2930 also would prohibit use of an automated decision tool that results in algorithmic discrimination. If enacted, AB 2930 would take effect on January 1, 2026.
While the proposals in Connecticut and California appear more closely aligned with Colorado’s SB 205 than Utah’s AIPA, time will tell which approach other states adopt, as well as whether any other trends emerge among states proposing new laws to regulate AI.
What should companies be doing now?
1. Inventory existing AI tools.
Review and inventory your company’s AI tools. This includes AI tools you have developed, along with those from vendors, and both stand-alone AI tools and AI features within larger products. For each AI tool, consider how the tool is used – with a particular focus on whether consumers can interact with the tool and whether the tool is used to make decisions about consumers.
Ensure that your company assesses whether existing AI tools, or those in development, will use any personal data to train the AI and machine-learning algorithms.
2. Determine applicability of state laws.
In the short term, consider whether you are a “developer” or “deployer” of a high-risk AI system in Colorado, or a regulated or nonregulated entity that deploys gen AI in Utah, in order to determine your level of compliance obligations under the latest regulations.
Unfortunately, the rapidly evolving and patchwork state-level regulatory framework means this kind of assessment must be done on an ongoing basis. Even in states like Colorado that have newly passed laws, implementing regulations are likely to be forthcoming. Consider scheduling periodic reviews to monitor future developments and ensure compliance in the states where your company conducts business.
3. Monitor regulator engagement and enforcement activities.
Clearly, with the establishment of bodies like the Office of Artificial Intelligence Policy in Utah, regulators are analyzing risks and benefits related to development and use of AI technologies and their related policy implications. Accordingly, regulatory and enforcement strategy is likely to evolve over time based on regulators’ learning activities and engagement with industry. Being close to these developments will assist in understanding the potential areas of regulatory enforcement.
4. Provide clear and conspicuous notice.
Utah’s AIPA and Colorado’s SB 205 both include requirements around transparency in connection with the use of AI systems. Companies should consider when and how they will provide required notices to consumers. Note that in many cases, providing required consumer disclosures in a website terms of use or privacy policy may not be sufficient.
5. Regularly monitor AI outputs.
Companies may be considered responsible for AI outputs. For example, the AIPA specifies that companies cannot skirt liability by disclaiming responsibility for the content that their gen AI tools produce. Therefore, it is essential to evaluate AI tools – during procurement, development and on an ongoing basis after deployment – including for outputs that are false, misleading, discriminatory, or otherwise violative of applicable laws. Under laws like the AIPA, it will not be sufficient that you have a broad disclaimer regarding the accuracy and quality of any AI outputs.
6. Conduct employee training on proper use of AI.
Employee training can raise awareness about the legal requirements around the use of AI. Internal acceptable AI usage policies can provide a clear compliance roadmap of what are acceptable and unacceptable uses of AI. Additionally, having appropriate internal escalation processes could help mitigate the risk of liability when, for example, a consumer complains about or challenges an AI output.
7. Establish robust policies, procedures and testing for AI.
Prepare internal policies (such as data retention policies) and guardrails for the use of AI tools (such as how to prevent algorithmic discrimination or bias), or consider implementing a third-party framework, such as the National Institute of Standards and Technology (NIST) AI Risk Management Framework. However, companies should not assume that even comprehensive policies and procedures will be wholly effective at meeting legal requirements. Regular testing and auditing for bias, discrimination and other problematic outputs/outcomes is essential.
8. Conduct independent third-party assessments.
Consider engaging a third-party independent expert to review and assess current AI tools and systems. To the extent feasible, ensure that your company implements recommendations from such auditors.
9. Monitor your vendors’ AI tools and policies.
Ensure that your company conducts diligence when onboarding and using vendors that provide AI tools, including with respect to vendors’ training data, cybersecurity and measures taken to prevent biased and discriminatory outputs. Companies may be held liable for AI outputs resulting from a vendor’s tool, so it is crucial to periodically assess your vendors’ tools and practices.
[View source.]