0

Risks of Shared AI Workspaces and Confidentiality, Security, and Privacy Concerns

Traditionally, the relationship between a company and its outside advisors, law firms, consultants, and financial advisors has been governed by confidentiality agreements, attorney-client privilege, and codes of professional ethics. These agreements assure that these outside advisors have access only to the information necessary for the scope of the project. However, artificial intelligence is becoming a mainstay in these working relationships, dismantling that clear separation.  AI-powered productivity tools are increasingly deployed not just within a single organization, but across shared digital workspaces, the collaborative platforms where companies and their external advisors jointly draft documents, manage new projects, exchange data, and make decisions. This shift represents a fundamentally new risk landscape, one that most organizations and their advisors have not yet adequately mapped.  This post identifies the three primary risk categories that arise when AI enters these shared spaces and the key considerations to mitigate them.  

Risk 1: Confidentiality

When AI tools operate within a shared workspace, there are two primary threats to client confidentiality:  1) Cross-client training and model contamination, and  2) over-input of information.  

Cross-Client Training Model Contamination

Many AI tools learn continuously from user interactions. For example, if a law firm’s AI assistant is trained, even implicitly, on documents, queries, and outputs across multiple client engagements sharing a platform environment. In this case, client information can become embedded in the model’s behavior. The AI may begin surfacing language, structures, or strategic approaches drawn from one client’s confidential materials when assisting another.  This is an example of cross-client training contamination. 

Over-Input of Information

When processing the information above, AI tools may ask follow-up questions, or the user may want to include additional context and guidance for the tool. These prompts and the need for greater contextual clarity may drive users to input additional information, information that may not normally be shared or be strictly necessary for the task at hand. This could lead to AI tools being trained on, and potentially re-sharing, information that is not strictly necessary. 

Risk 2: Overexposure

AI processes operating across shared workspaces introduce a new failure mode: overexposure through automated workflow. When an AI agent is tasked with summarizing documents, preparing briefings, or surfacing relevant materials, it may draw on content from across the workspace without respecting the role-based and project-based permissions designed to contain that information.

Misconfiguration and Permission Gaps

AI tools in shared workspaces are typically configured by IT or platform administrators, not by the lawyers or compliance officers who understand the sensitivity of the underlying information. Permissioning structures that may be technically correct for human access often fail to account for how AI agents traverse and aggregate information. A consultant with project-scoped access to a workspace may, through the AI layer, receive synthesized summaries that draw on materials outside their authorized scope.

Role and Project Segmentation Failures

Even well-intentioned configurations can break down when AI tools are updated. For example, this could occur when team membership changes or when workspace structures evolve mid-engagement. Unlike a human employee who is subject to ongoing supervision, an AI system with broad access will continue operating at that level until it is explicitly restricted. The moment of overexposure may be difficult to trace, making the discovery of these failures especially challenging. 

Risk 3: Accountability

Who is Responsible when AI makes the decision? Professional service relationships often assign responsibilities clearly; for example, the lawyer is responsible for legal advice, the auditor for the audit opinion, and the consultant for the recommendation. These lines of responsibility are the foundation of malpractice liability, professional licensing, and regulatory compliance. However, AI tools make this division more complicated. 

The Absence of Auditable Decision Trails

Many AI tools used in professional services do not generate decision logs or explainable outputs in a meaningful sense. When a deal recommendation, a compliance conclusion, or a litigation strategy is influenced by an AI-generated analysis, there may be no record of what data the AI considered, what it weighted, or what it excluded. If the decision is later challenged in litigation, a regulatory proceeding, or a malpractice claim, the AI’s contribution cannot be reconstructed or audited.

Diffused Liability Across a Shared Platform

In a shared workspace involving the company, its law firm, its auditors, and potentially a technology platform provider, an AI-assisted error may have no clear owner. Did the AI fail because of a platform defect? Because the law firm configured it incorrectly? Because the company provided bad inputs? Because no human professional adequately reviewed the output? Engagement letters, platform terms of service, and professional liability policies may not be drafted to answer these questions.

Key Considerations in Light of these Risks

The risks described may be present in any organization that has extended its advisory relationships (law firms, consultants, and financial advisors, to name a few) into AI-enabled collaborative platforms. To minimize these risks, organizations may want to consider the following tips:  Consider…
  • Auditing shared platforms and tools currently used with outside advisors to identify any AI features, and map what data those features can access. 
  • Reviewing engagement agreements, NDAs, and platform terms of service for AI-specific confidentiality provisions. 
  • Assessing whether AI access controls in shared workspaces respect role-based and project-based information silos and construct limitations where they do not. 
  • Establishing AI decision-logging protocols with outside advisors, including requirements for human review and sign-off before AI-influenced advice is acted upon. 
  • Negotiating clear contractual allocation of liability for AI-related errors across the full advisory chain, company, advisors, and platform providers. 
  • Briefing executive leadership and the board on AI-specific risks in advisory relationships, particularly in regulated industries where privilege and data protection obligations are most acute. 
Establishing governance frameworks for AI early in advisory relationships may enable companies to reduce their own exposure and hold advisors accountable if one of the risks of use materializes. 
0
AI and Legal Privilege

AI and Legal Privilege: Updates from Federal District Courts

AI and Legal Privilege: Updates from Federal District Courts 

US v. Heppner and Warner v. Gilbarco

“Chat, is our conversation protected?”  As usual, the answer may be “it depends.”

Highlights from two recent federal district court cases, US v. Heppner and Warner v. Gilbarco, provide different answers to this question. The learning? If you are using AI tools for legal-related matters, you should think twice before entering personal information or other case-related information.

United States v. Heppner

On February 17, 2026, the federal district court for the Southern District of New York found that neither attorney-client privilege nor the work product doctrine applied in protecting legal strategy materials that were generated using a public version of Claude. In its memorandum of reasoning, the court states its ruling “appears to answer a question of first impression nationwide: whether, when a user communicated with a publicly available AI platform in connection with a pending criminal investigation, are the AI user’s communication protected by attorney-client privilege or the work product doctrine?” The court answers with a resounding “no,” given the circumstances of the case. In Heppner, the court first ruled that the defendant’s conversations with AI were not covered by attorney-client privilege. This is because attorney-client privilege attaches with:
  1. Communications between a client and their attorney,
  2. which are intended to be, and were, kept confidential,
  3. for the purposes of obtaining or providing legal advice.
The court held that the AI-generated communications failed at least two, if not all three of these elements. Not only were the conversations not with counsel, but Heppner’s communications were not confidential because he used a public or consumer version of the Claude platform. The court notes that the platform’s privacy policy specifies that user inputs and outputs are used for training purposes, and that the platform reserves the right to disclose this information to third parties, including governmental regulatory authorities. In Heppner, the court also held that the work product doctrine also did not apply to the materials generated from the public or consumer version of Claude. This is because the work product doctrine requires that materials are prepared by or at the direction of counsel. Because these documents were not prepared by or on behalf of counsel, and did not reflect the defense counsel’s strategy, the court held the work product doctrine did not apply.

Warner v. Gilbarco

On February 10, 2026, the Eastern District of Michigan heard a similar – but not identical case – and found that the work generated by AI was attorney-client work product. In this case, the AI tools were used to prepare legal materials. However, in contrast to Heppner, the court reasoned that “ChatGPT (and other generative AI programs) are tools, not persons” and found that both the attorney-client privilege and work product doctrine apply. Although the court determined that sensitive information pertaining to the case was provided to ChatGPT, they found that this was not equivalent to a “voluntary disclosure to a third person,” which would ordinarily waive attorney-client privilege, did not apply. This is because the AI was not considered a third person. Additionally, the court found that work product waiver requires disclosure to an adversary or in a manner likely to reach an adversary. Because this was not found to be the case with the disclosure to ChatGPT, this doctrine was not waived.

Key Takeaways

Although these two similar cases come to different conclusions, it is important to note that they are not factually identical. It is also important to emphasize that these are early federal district court cases, and these matters of first impression are likely to evolve in the coming year. In the meantime, individuals (and other entities) using generative AI for legal advice should consider these cases and their outcomes. If you are planning on using generative AI for legal advice, you should consider the AI tools you’re using, the configurations of those tools, and the purposes for which you are using the tools. Credit: Emma Wallace
0
Automated decision-making technologies (ADMT) in employment decisions

Using AI’s Tools in Hiring, Firing, and Compensation Decisions

What Employers Need to Know About Using ADMT in Employment Decisions

Decisions about hiring, termination, and compensation represent substantial administrative costs for employers. Automated decision-making technologies (“ADMT”) can significantly streamline the process. However, employers using ADMT should be aware of recent and existing regulations governing the use of AI tools in evaluating prospective and current employees.

In addition to recent AI-specific regulation, use of AI tools in making employment decisions may be regulated by existing anti-discrimination statutes. Use of an algorithm that discriminates against a protected class identified in federal statutes – most notably Title VII of the Civil Rights Act and the Americans with Disabilities Act (ADA) – may expose employers to liability. What is ADMT? ADMT, or automated decision-making technology, is any technology that processes personal information and uses computation to replace or substantially replace human decision-making. AI tools used in employment may be one type of ADMT available to employers. In the context of ADMT, significant employment decisions may include:
  • Hiring
  • Allocating work or compensation
  • Promotion and demotion
  • Suspension and termination
State and local compliance requirements may create exceptions for businesses that do not use the AI tool’s recommendations as a substitute for human discretion. However, this may be a high bar to overcome, and not all types of human involvement qualify for an exception. For further explanation, please refer to the “Best Practices for Employers” section below. What are the risks of employment discrimination? AI and other ADMT tools involved in significant employment decisions may pose two key risks regarding employment discrimination. There is a risk they may: 1) Exclude or disadvantage applicants from a protected group identified in Title VII or applicants with disabilities. Groups are protected by the statute on the basis of race, color, sex, religion, or national origin. This may apply even if there is no intent to discriminate: If the technology is shown to have a disproportionate effect on a protected group, the employer may be vulnerable to a lawsuit. For example, if ADMT tends to exclude candidates with names that suggest a particular racial or national identity, this could pose risk to the employer using this ADMT. 2) Screen out candidates based on aspects of their application that characterize a disability recognized by the ADA. This screening process may apply to a seemingly neutral selection criterion. For example, an AI tool that screens employees out for a resume gap lasting longer than four months could raise a risk of liability if the individual has a disability requiring substantial recovery periods after medical intervention. What types of ADMT pose particular risks of discrimination? Certain types of ADMT may pose particular risks of violating state and federal regulations. This may include AI-hiring tools with algorithms that:
  • Fail to take into account reasonable accommodations or available workplace alternatives in their assessment of a candidate’s ability to uphold the employer’s performance standards
  • Fail to include measures to mitigate against sensitivity to names of candidates – which contain information as to the gender and/or ethnic or racial origins of the applicant
  • Are overly reliant on inferences between the applicant and existing successful employees, which may reinforce existing hiring biases
  • Fail to account for possible reasonable accommodations related to their disability that are available to the applicant
  • Rely on an empirical evaluation of an individual’s conformity with a subjective standard such as “culture fit”.Additionally, video-interviewing software that includes emotion-recognition technology without human involvement in their hiring decision, and hiring tools that require the applicant to provide medical information prior to employment may also create additional risk.
Best Practices for Employers When selecting an AI tool for use in your employment decisions, there are measures employers can take to potentially reduce the risk of discrimination. 1. Transparency. Measures may include requesting transparency from the developer about mitigating measures to insulate decisions against particular risk factors.For example, seek tools that do not weigh factors posing particular risks of discrimination in the scoring process so heavily that they disqualify candidates. Transparency is also useful in preparing risk assessments which may be required by state and local regulations when using AMDT. 2. Human Involvement. Employers may also consider assessing the degree of human involvement in the decision-making process to see if the applied use qualifies for an exception from the regulation. If seeking an exception, a certain degree of human involvement may be required. Examples of insufficient degrees of human involvement may include situations where the decision-maker:
  • Is tasked with merely reviewing AI output
  • Lacks authority to change the decision
  • Lacks access necessary to make an independent decision
  • Operates under time constraints insufficient for substantive review
  • Only intervenes for obvious mistakes
In general, businesses should not recommend that the human decision-maker follow the AI’s decision by default in policy or in practice and should encourage independent human review. 3. Preparation. When using AI to assist in employment decisions, businesses may want to consider:
  • Conducting and submitting a risk assessment evaluating the risks of potential discrimination or data privacy balanced against the benefit to the business
  • Disclosing use of an AI tool in the applicant selection process before an applicant submits their application
  • Consulting state and local regulations to confirm compliance with required procedures and components. For example, CA, NY, IL, and CO are among the states that mandate some type of pre-disclosure when using ADMT or similar tools. Depending on the jurisdiction, it may be helpful for employers to consult relevant statutes to determine specific compliance requirements and timelines for disclosure.
  • Maintaining alternative processes to ADMT for selecting qualified candidates and allow potential applicants to opt-out of its use in evaluating their application. For candidates with disabilities, this may also include providing candidates with reasonable accommodations, including specialized equipment or extended timing or other modifications for timed skill assessments.
  • Establishing an appeal process for employment decisions made using AI tools.
  • Anticipating possible requests for deletion of personal data in response to evolving privacy rights across various jurisdictions. For example, in California, applicants may have existing privacy protections that include the rights to:
    • Be notified regarding a business’s use of AI in making employment decisions
    • Know what data is being collected, its purpose, and with whom it will be shared
    • Request deletion of personal information
    • Correct inaccurate personal information
    • Stop or limit the sale of sensitive personal information
    • And non-discrimination for exercising the rights provided.
What’s Next? The recent Executive Order suggests that national policy may soon tend away from allowing applicants and/or employees to bring claims based on an AI tool’s disproportionate effect on a protected group. (Executive Order, Ensuring a National Policy Framework for Artificial Intelligence, Sections 6 & 9, issued December 11, 2025). However, as state and local-level protections take effect and as federal minimum standards continue to be fleshed out, some caution is required as these standards are interpreted by relevant state and federal agencies.
0
Flag of California, depicting a large brown bear beside a red star, above the words "California Republic."

California: New AI laws in California – roundup of the 2025 legislative session

This article was originally published by OneTrust DataGuidance on November 24, 2025 and can be found on the DataGuidance website here.

California introduces comprehensive AI laws focusing on transparency, children’s safety, healthcare, antitrust, and law enforcement.

California has taken an aggressive stance towards artificial intelligence (AI) legislation and will likely set the standard for other US states. Back in 2024, Governor Newsom vetoed comprehensive AI safety legislation under bill SB 1047 and advised caution on regulations for this nascent and important technology. This year, Governor Newsom pressed ahead with a full slate of new AI laws. The reasons for this change in approach are many, including but not limited to the lack of federal AI legislation, the growing concern over children’s interactions with AI, especially sexualized content, and harmonization with more stringent requirements in the EU and elsewhere.

This year’s legislative session set records for the number and scope of new AI laws. For the roundup this year, Lily Li, of Metaverse Law Corporation, breaks down the new AI laws by scope and sector, noting where this may add on to existing California legislation and rulemaking from 2024-2025.

General AI safety, transparency, and risk assessments

  • SB 53: Transparency in Frontier Artificial Intelligence Act (Wiener) – Starting in January 2026, California will require large frontier AI developers to publish a framework detailing how they incorporate safety, security, and testing standards into their AI models. SB 53 also creates a mechanism for AI developers and the public to report critical safety incidents, and protects internal whistleblowers who report risks posed by frontier AI models. The law establishes significant penalties for companies that fail to comply, with fines of up to $1 million per violation.
  • AB 316: Artificial Intelligence defenses (Krell) – This amends California’s Civil Code. If a party to a lawsuit develops, modifies, or uses AI, this law prohibits them from asserting as a defense that the AI autonomously caused the harm.
  • AB 853: California AI Transparency Act (Wicks) – This bill expands the existing AI Transparency Act and modifies the effective date from January 1, 2026, to August 2, 2026. The California AI Transparency Act requires covered generative AI developers to provide an AI-detection tool to assess whether image, video, or audio content is created or altered by generative AI. This bill adds to the existing law by requiring large online platforms to embed provenance data into generated content. Starting January 1, 2028, users will also have the option to include latent disclosures on ‘capture devices’ such as cameras, video recorders, and other recorders.

This new California approach to AI transparency and safety legislation needs to be read in conjunction with the following existing laws.

  • California Privacy Protection Agency’s (CPPA’s) recently approved Cyber, Risk, ADMT, and Insurance Regulations – The CPPA’s most recently updated 127-page regulation package contains requirements governing cybersecurity audits, risk assessments, and automated decision-making technology. AI developers and systems that process personal information and meet certain California privacy thresholds will now face new cybersecurity audit and risk assessment requirements. In addition, automated and significant decisions concerning the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services will trigger significant notice, opt-out, and risk assessment requirements.
  • AB 2013: AI Training Data Transparency Act (Irwin-2024) – Passed last year, this law will require covered generative AI developers to publish online a high-level summary of the datasets used in the development of the generative AI system or service, including but not limited to whether personal information or copyrighted information is included in the training data. The law is scheduled to go into effect on January 1, 2026.

Children’s safety, age verifications, and companion chatbots

  • SB243: Companion Chatbots (Padilla) – This law applies to chatbots that provide human-like interactions and are capable of sustaining relationships across multiple interactions. Beginning July 1, 2027, developers of these ‘companion chatbots’ will need to develop and report protocols addressing suicidal ideation and self-harm to regulators and the public. The law requires AI disclosures, referrals to suicide hotlines or crisis text lines, and break reminders. SB 243 further requires developers to institute reasonable measures to prevent the chatbot from producing visual material of sexually explicit conduct or directly stating that the minor should engage in sexually explicit conduct. The legislation includes a private right of action to individuals who suffer ‘an injury in fact’ with statutory damages of $1,000 per violation, or actual damages if greater.
  • AB 1043 – Digital Age Assurance Act (Wicks) – Starting January 1, 2027, operating systems and covered application stores will be required to obtain age data from users and pass on age bracket data to developers when users download and launch an application.
  • AB 56: Social Media Warning Law (Bauer-Kahan) – Starting January 1, 2027, covered social media platforms will need to display a warning label to minors the first time a user accesses the platform each day, after three hours of active use, as well as once per hour of cumulative active use after that. The warning label must say ‘The Surgeon General has warned that while social media may have benefits for some young users, social media is associated with significant mental health harms and has not been proven safe for young users.’
  • AB 621: Deepfake pornography (Bauer-Kahan) – This amends California’s Civil Code and expands protections against deepfake pornography. The law explicitly provides a cause of action against individuals who create or disclose deepfake pornography if they know, or reasonably should know, that the depicted individual was a minor and also provides a cause of action against individuals who knowingly facilitate or recklessly aid or abet the creation or disclosure of such nonconsensual deepfake pornography. The bill confirms that a minor cannot consent to the creation or distribution of deepfake pornography.

California’s approach to AI and children has a long and complicated history, and these new laws should be read in conjunction with the following laws on the books.

  • California Age Appropriate Design Code (Wicks) – This law was signed on September 15, 2022, and was scheduled to go into effect on July 1, 2024. Modeled after the UK Age Appropriate Design Code, this law requires businesses to conduct impact assessments, provide Privacy by Default, estimate the age of all users, and restrict dark patterns. The law was enjoined in March 2025, but is being appealed by the California Attorney General.
  • Protecting Our Kids from Social Media Addiction Act (Skinner-2024) – This law is scheduled to go into effect on January 1, 2027, and prohibits covered social media platforms from providing addictive feeds to minors without verifiable parental consent. The law has so far escaped a constitutional challenge, but may face other court challenges prior to the effective date.

Healthcare AI and chatbots

  • AB 489: Health care professions: deceptive terms or letters: artificial intelligence (Bonta) – This law prohibits AI systems from falsely indicating or implying possession of a medical license or certificate through advertising, marketing, or other functionality. AB 489 also makes AI developers directly subject to the healthcare professional licensing board or enforcement agency if they develop such a system. Each use of a prohibited term, letter, or phrase shall constitute a separate violation.

California’s approach to AI in healthcare also needs to be read in conjunction with the following laws and guidance.

  • Legal Advisory on the Application of Existing California Law to Artificial Intelligence in Healthcare – In January 2025, California Attorney General Rob Bonta issued this advisory, setting forth California’s existing consumer protection, civil rights, competition, and data privacy laws governing healthcare AI.
  • SB 1120: Physicians Make Decisions Act (Becker-2024) – This law prohibits covered healthcare service plans from denying, delaying, or changing healthcare services based, in whole or in part, on medical necessity using AI, algorithms, or other software tools. Such determinations shall require a physician or licensed healthcare professional and review of individual circumstances. This law also requires written policies and procedures governing such determinations.
  • AB 3030: Artificial Intelligence in Health Care Services (Calderon – 2024) – This law applies to health facilities, clinics, physicians’ offices, or other health group practices that use generative AI for communications about patient clinical information. Under this bill, generative AI, which pertains to clinical information, must include:
    • a disclaimer that indicates the communication was generated by AI at the beginning of the interaction; and
    • clear instructions on how the patient can contact the appropriate person.

Antitrust and pricing discrimination

  • AB 325: Cartwright Act violations (Aguiar-Curry) – This amends California’s existing antitrust law, the Cartwright Act, to explicitly cover ‘common pricing algorithms.’ The law prohibits:
    • the use or distribution of a ‘common pricing algorithm’ as part of a contract, combination in the form of a trust, or conspiracy to restrain trade or commerce; or
    • coercion to set or adopt a recommended price or term, recommended by the common pricing algorithm for the same or similar products or services.

Complaints shall not be required to allege facts tending to exclude the possibility of independent action.

Law enforcement use of AI

  • SB 524 Law Enforcement Agencies (Arreguín) – SB 524 requires law enforcement to disclose if an official report was written either fully or in part using AI, as well as retain the first draft created by AI and an associated audit trail that, at minimum, identifies both the officer who used AI to create a report and the video and audio footage used to create a report, if any. SB 524 also prohibits AI vendors from sharing, selling, or otherwise using information, except as provided in the bill (e.g., troubleshooting, bias mitigation, quality control, legal purposes, etc.).

Employment and bias

While Governor Newsom vetoed SB 7, the No Robo Bosses Act, the Governor’s veto letter pointed to the CPPA’s ADMT regulations as addressing some of the bill’s requirements. Per Governor Newsom, SB 7 is ‘partially covered’ by these regulations, as they ‘allow employees and independent contractors to better understand how their personal data is used by automated decision technology.’ In addition, the California Civil Rights Council’s recently promulgated regulations state that California’s antidiscrimination laws apply to AI workplace tools. These regulations address another concern raised in SB 7, which sought to prohibit ADS systems from inferring a worker’s protected status.

0
Image of a cellular phone with the ChatGPT app open.

Overview: The EU General-Purpose AI Code of Practice

Why Do We Need a Code of Practice?

On August 2, 2025, the general-purpose AI (GPAI) provisions of the EU AI Act went into effect. GPAI models (including models that support most generative AI, like ChatGPT), now face certain obligations in the EU, including requirements around transparency, copyright and systemic risk. However, the EU AI Act is a framework: it defines obligations but leaves technical details to harmonized standards and codes of practice. While this approach sets certain expectations and allows the EU AI Act to remain technology-neutral, it also leaves questions about how businesses substantially comply with the EU AI Act. To bridge this gap, a multi-stakeholder group drafted the General-Purpose AI Code of Practice (GPAI Code). On August 1, 2025, the European Commission issued a formal opinion confirming the GPAI Code is an “adequate tool” to help demonstrate compliance with the EU AI Act. Why is the Code significant? This opinion signals that organizations who adopt the GPAI Code may be able to demonstrate good-faith efforts to comply with the relevant provisions of the EU AI Act –  according to the Commission’s website: “The Code of Practice helps industry comply with the AI Act legal obligations…of general-purpose AI models.” In its opinion, the Commission notes that the Code provides actionable commitments and reporting mechanisms, especially for high-risk models. Additionally, the Commission emphasized that the Code provides a practical framework to demonstrate regulatory compliance. Following this endorsement, providers of GPAI models can voluntarily sign the Code, which “will reduce their administrative burden and give them more legal certainty than if they proved compliance through other methods.” Still, signatories should be aware that the Code explicitly states that adherence to the Code does not necessarily constitute evidence of compliance with the EU AI Act.

What is a General-Purpose AI Model?

A GPAI model is a component of an AI system with a wide range of possible uses, whether intentional or unintentional. It is important to note that these models are not systems in themselves but are part of AI systems. Additional elements, like user interfaces, are necessary to make these models fully operational systems. Under Article 3(63) of the EU AI Act, a GPAI model includes those trained on a “large amount of data using self-supervision at scale.”  They can be applied across sectors or tasks, usually without substantial modification, meaning GPAI models “can be integrated into a variety of downstream systems or applications.” Recital 98 of the EU AI Act states that the generality of the model can also be determined by the number of parameters, and “models with at least a billion parameters…should be considered to display significant generality and to competently perform a wide range of distinctive tasks.” GPAI models are sometimes called “foundation” or “frontier” models, and while they may include large language models (LLMs), they can also process audio, physical, textual or visual data, powering systems like DALL-E, GPT-4, Gemini, LaMDA, SEER, ALIGN, and more.

How are general-purpose AI models regulated?

Under the EU AI Act, the chapter on GPAI both addresses generative AI and outlines some of the most stringent requirements under the Act. However, all requirements for GPAI under the EU AI Act are directed to providers as opposed to deployers. Providers of GPAI models have a range of obligations under the EU AI act, both directly to supervising authorities and onward to AI providers who integrate the GPAI models into their systems. Obligations of Providers of GPAI Models If a provider places a GPAI model on the EU market, or integrates such a model into its own AI system on the EU market, it must:
  • Prepare and maintain technical documentation for regulators. This should include at least a general description of the GPAI model, including the tasks it’s designed to perform and the types of systems in which it can be integrated; acceptable use policies; and information on training process.
  • Prepare and maintain documentation for downstream providers. This should include information that allows the downstream AI system providers to comply with their own obligations under Article 53(1)(b). Similar to the technical documentation, this includes but is not limited to a general description of the model, and a description of its elements and development process.
  • Prepare an EU copyright policy. This policy should establish a means to comply with EU regulations on copyright and related rights.
  • Prepare and publish a summary of training content. Using the template provided by the AI Office, providers of GPAI must share a comprehensive summary of AI training information. This should allow stakeholders to exercise their rights by informing them of the information used to train the GPAI model.
  • Cooperate with relevant authorities and appoint an authorized representative. Providers must also cooperate with relevant authorities, and if they are established outside the EU, appoint an authorized representative located in the EU.
It is notable that under Recital 85, the EU AI Act states that GPAI systems “may be used as high-risk systems by themselves or be components of other high-risk systems.” Therefore, the providers of GPAI systems must work closely with providers of high-risk AI systems to ensure compliance with any requirements of high-risk systems under the Act. Obligations of Providers of GPAI Models with Systemic Risk What does “systemic risk” mean? GPAI models with systemic risk include models that reasonably pose foreseeable negative effects relating to major accidents, disruption of critical sectors, serious consequences to public health and safety, public and economic security, democratic processes, and the dissemination of false or discriminatory content, or other similar effect. Under Article 51(1) of the EU AI Act, a GPAI model will be classified as having systemic risk if:
  • It has high impact capabilities, or
  • It is designated by the Commission to have high impact capabilities based on the criteria in Annex XIII (i.e., the number of parameters in the model, the size of the data set, the amount of computation used to train the model, etc.).
What are the additional obligations for these models? In addition to the requirements for all GPAI models, those with systemic risk have additional obligations related to:
  • Model evaluation, assessment, and mitigation of systemic risks;
  • Incident management and reporting; and
  • Cybersecurity protections and technical documentation.
Because there are differences in the obligations between GPAI systems generally and GPAI systems with systemic risk, this classification procedure should be noted by providers of GPAI systems; it is essential to understand where each GPAI model falls, and what requirements the model has under the EU AI Act. According to Article 52(6), a list of GPAI models with systemic risk will be published and updated by the European Commission, but it has not been published at the time of writing.

What is the General-Purpose AI Code of Practice?

While not legally binding, providers of GPAI models can use the Code of Practice to demonstrate compliance with their obligations under the EU AI Act. The Code consists of three chapters on 1) transparency, 2) copyright, and 3) safety and security. The first two chapters apply to all providers of general-purpose AI models, providing a way to demonstrate compliance with obligations under Article 53 of the AI Act. The final chapter applies only to general-purpose AI models with systemic risk under Article 55 of the AI Act. Chapter 1: Transparency Among other things, this chapter requires signatories to create and maintain documentation for all GPAI models distributed within the EU for up to ten years. There are exceptions for models that are free, open-source, and do not pose systemic risk. When completing this documentation, signatories must use a standard Model Documentation Form, which includes information on licensing, technical specifications, training data, and other parameters of the GPAI model. The Code encourages publication of this information to promote transparency. Chapter 2: Copyright This chapter requires signatories to create and maintain a copyright policy that complies with the EU’s legal standards. This includes, but is not limited to, ensuring that data collected by web crawling is lawfully accessible, and certain websites flagged for copyright infringement are avoided. Importantly, signatories must designate a contact for copyright holders to submit complaints, along with a process for handling those complaints. Chapter 3: Safety & Security (GPAI with systemic risk only) One of the main elements of this chapter is the requirement for signatories to develop a state-of-the-art Safety and Security Framework before releasing any GPAI model categorized as posing a systemic risk. Additionally, systemic risks should be identified and inventoried, and before progressing with development or deployment, the signatories should weigh the relative risks and determine if they are acceptable, among other requirements.

What’s next?

The Code will be monitored and reviewed at regular intervals by the AI Office, and may be updated in response to emerging risks, technological developments, or incidents involving general-purpose AI models.
1 2 3 4 5 … 9