0

California Invasion of Privacy Act (CIPA) – The Latest Privacy Litigation Trend

As more U.S. states enact comprehensive consumer privacy legislation, plaintiffs are turning to laws from the 1960s to pursue claims against companies that use website tracking technologies. Most notably, there has been a significant uptick in privacy litigation claiming that the use of website technology, such as session replay, chatbots, tracking pixels, and other analytics software, violates the California Invasion of Privacy Act (“CIPA”).

How We Got Here

Since 2022, a wave of class action lawsuits has been filed regarding Meta’s pixel, a tracking tool often used by companies for targeted advertising by tracking user activity. Many of these cases allege a violation of the Video Privacy Protection Act of 1988 (“VPPA”), a federal law prohibiting videotape service providers from knowingly disclosing personally identifiable information concerning their consumers. These lawsuits allege that companies which stream online video content on their websites while using the Meta pixel violated the VPPA by transmitting personally identifiable information about a website user to Meta. While many courts dismissed the VPPA Meta pixel cases, some of these cases (such as Ambrose v. Boston Globe Media Partners LLC[1]) have survived the motion to dismiss stage, leading the parties to settle instead.

Lawsuits involving the Meta pixel, along with similar technology, are also being filed under alleged violations of strong state wiretapping laws, such as the CIPA. The CIPA, which was enacted in 1961, intended to protect California residents from then-new technologies used for different kinds of wiretapping. In these modern-day cases, plaintiffs claim that the use of many web analytics tools amount to a violation of CIPA’s wiretapping and eavesdropping provisions.

Relying on a Ninth Circuit court decision which held that CIPA also applies to “internet communications”[2], plaintiffs’ firms circulated hundreds of demand letters threatening CIPA class action litigation under CIPA’s Section 631(a) – which prohibits third-party wiretapping – and Section 632.7 – which prohibits the interception or receipt and recording of certain wireless communications without consent. The statutory penalty is $5,000 per violation, making it an attractive avenue for plaintiffs’ firms.

Where We Are Now (Thanks to Greenley v. Kochava[3])

An even more recent decision from the United States District Court for the Southern District of California has prompted plaintiffs’ firms to turn to yet another theory and to file suits under alleged violations of CIPA Section 638.51. Section 638.51 prohibits the installation or use of a “pen register” or a “trap and trace device” without first obtaining a court order. A “pen register” is defined as a device or process that records or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted.

The plaintiff in Greenley v. Kochava claimed that the defendant’s software that was installed in third-party mobile applications constituted an illegally installed pen register by tracking a user’s “geolocation, search terms, click choices, purchase decisions, and/or payment methods,” collecting this tracked information, and then selling it to third-party advertisers. Deciding on a motion to dismiss, the Greenley court stated that while CIPA’s definition of a pen register was specific as to the type of data a pen register collects, it was “vague and inclusive as to the form of the collection tool – ‘a device or process.’” With this in mind, the Greenley court held that “software that identifies consumers, gathers data, and correlates that data through unique ‘fingerprinting’ is a process that falls within CIPA’s pen register definition.” Accordingly, the court denied the defendant’s motion to dismiss.

Following the Greenley court’s decision, over 50 new cases have already been filed in California state and federal courts under the CIPA pen register provision.

Where to Go from Here

Accordingly, businesses should evaluate their use of tracking software and technology, along with the disclosures in their privacy policy and potential consent mechanisms. The CIPA pen register provision allows a provider of electronic or wire communication services to use such a pen register if the consent of the user has been obtained. Although California courts have not yet interpreted consent in the context of the CIPA’s pen register provision, courts have found a user’s affirmative consent to be a successful defense in other CIPA claims.

 

[1] Ambrose v. Boston Globe Media Partners LLC, No. 1:22-cv-10195-RGS.

[2] Javier v. Assurance IQ LLC et al., 2022 WL 1744107, *1 (9th Cir. 2022).

[3] Greenley v. Kochava, Inc., No. 22-CV-01327-BAS-AHG, 2023 WL 4833466 (S.D. Cal. July 27, 2023).

0
Chicago Grand Central Looking Up

2024 U.S. regulatory enforcement priorities for data & AI

In late 2023 and early 2024, federal and state regulators signaled their enforcement priorities regarding the use of data and AI. These enforcement priorities range from sweeping investigations into entire labor sectors to targeting specific uses of technology.
FEDERAL

FTC. The FTC continues bringing actions against companies over their improper use of AI, increasing the risks of LLMs and generative AI. On March 8, 2024, the Federal Trade Commission (FTC) entered a stipulated order with Rite Aid prohibiting the pharmacy chain from using any machine-based systems to analyze biometric information. A month before, the FTC announced proposed rules combating the use of AI to impersonate individuals, which includes potentially imposing a rule that would declare it unlawful for an AI platform to provide goods or services that the platform knows or has reason to know is being used to harm consumers through impersonation.

SEC. In a surprising regulatory move, the Securities and Exchange Commission (SEC) took action against two entities that made misleading disclosures regarding their use of AI. On March 18, 2024, the SEC announced a $400,000 settlement against two investment advisers for making false and misleading statements about their purported use of AI. The investors allegedly stated in its SEC filings, in press releases, and on their websites that they were harnessing AI tools in certain ways, when in fact they were not. The SEC published an AI and investment fraud alert, signaling that they will likely continue monitoring AI-related disclosures.


CALIFORNIA

Data Minimization. On April 2, 2024, the California Privacy Protection Agency (the Agency) released its first Enforcement Advisory notice, emphasizing that covered businesses must apply the principle of data minimization to every purpose for which they collect, use, retain, and share personal information. Specifically, the Agency focused on the principle of data minimization during two scenarios: (1) responding to a consumer’s request to opt-out of sale/sharing and (2) verifying a consumer’s identity. Failure to adhere to the principle of data minimization may constitute a violation of the California Consumer Privacy Act (CCPA) and its regulations.

Amended CCPA Regulations. On March 29, 2024, the amended CCPA regulations will take effect and be enforceable. These regulations were originally supposed to take effect on March 29, 2023, but the California Chamber of Commerce filed suit on March 30, 2023, arguing that the amended regulations could not enter into force until one year after finalization. The court agreed, thereby effectively pushing the enforcement date back to March 29, 2024. However, a California appellate court subsequently reversed that decision, thereby making the regulations effective immediately.

The Agency and the California Attorney General have indicated that they anticipate aggressively enforcing the new regulations, and since covered entities had nearly an extra year to comply with the new regulations, California regulators may not be lenient in providing cure periods for noncompliance with the new regulations.

Streaming Services. On January 26, 2024, the California Attorney General announced investigative sweeps into “popular streaming apps and devices,” and sending letters to businesses that fail to comply with the CCPA. Specifically, the AG’s sweep focuses on whether streaming services are complying with the CCPA’s opt-out requirements for selling or sharing consumer personal information. The sweep includes analyzing whether the streaming services “do not offer an easy mechanism for consumers who want to stop the sale of their data.” For example, consumers using a SmartTV should be able to easily enable a “Do Not Sell My Personal Information” setting in the streaming service and have that choice honored across different devices.

Connected Vehicles and Related Technologies. On July 31, 2023, the Agency announced investigative sweeps into the data privacy practices of connected vehicle manufacturers and related technologies. The Agency conducted the review under the CCPA and its regulations enforceable at the time, with a focus on whether connected vehicle manufacturers and the like provided consumers with rights under the law (e.g., right to know, right to delete, and right to opt out of sale/share). However, the Agency has not indicated whether the sweep will continue into 2024 as the new regulations take effect, so connected vehicle manufacturers and producers of related technologies should remain vigilant.


COLORADO

Global Privacy Control. In the fall of 2023, the Colorado Department of Law accepted applications for universal opt-out mechanisms (UOOMs) that, under the Colorado Privacy Act (CPA), covered businesses would need to respect as a means for consumers to opt out of the sale of personal data or the sharing of personal data for targeted advertising. In December of 2023, the Colorado Attorney General announced that it selected the Global Privacy Control (GPC) as the UOOM the AG considers valid under the CPA.

Beginning on July 1, 2024, organizations subject to the CPA must ensure they are able to accept consumer opt-out requests made using the GPC, and the AG has announced that it “will prioritize for enforcement” compliance with the Department’s list of acceptable UOOMs.


CONNECTICUT

General Enforcement. On February 2, 2024, the Connecticut Attorney General released a report on the Connecticut Data Privacy Act (CTDPA), which detailed the AG’s enforcement efforts and priorities. Since the CTDPA took effect, the AG has issued cure notices to covered entities in a wide range of industries, including retail, fitness, event services, career services, parenting technologies, and home improvement.

The cure notices identified the following deficiencies:

    • Lacking or inadequate disclosures (e.g., failure to inform consumers completely or sufficiently about their rights under the law);
    • Lacking rights mechanisms (e.g., failure to provide a webpage that enables consumers to opt out of targeted advertising or sale of data);
    • Burdensome rights mechanisms (e.g., rights mechanisms that did not take into account the ways consumers normally interact with the company); and,
    • Broken / inactive rights mechanisms (e.g., non-working links or dead-end mechanisms).

Taken together, the report indicates an interest in the AG to ensure covered entities (in a wide range of industries) provide sufficient privacy disclosures and compliant rights mechanisms.


BEST PRACTICES CHECKLIST As we move through 2024, businesses should consider the following to lower their risk of enforcement actions:
  • Analyze State Privacy Thresholds. Each of the US state privacy laws feature their own thresholds of applicability that must be met before a business must comply with the law, so businesses must continually monitor whether they have satisfied any of these numerous thresholds. To help, we have compiled all of the state privacy law thresholds.
  • Create Data Maps. Because state and international privacy laws impose certain obligations on specific types of data (e.g., personal v. sensitive) and processing activities (e.g., using AI for significant decisions), businesses should create data maps to monitor and document their information practices.
  • Respect Opt-Out Signals. Where a state privacy law requires respecting opt-out preference signals, ensure that you have implemented a means for websites to recognize and respect such signals, and disclose to consumers that they have the right to use such opt-out mechanisms (e.g., Global Privacy Control).
  • Review Policies. While many of the disclosure requirements of US privacy laws and regulations overlap, there are intricate differences between them, so businesses should review external-facing policies to ensure the disclosures remain accurate and compliant.
  • Conduct DPIAs. Conduct a data protection impact assessment (DPIA) to the extent required by applicable state privacy laws or review existing DPIAs to ensure they remain compliant with applicable laws.
  • Analyze AI Tools. Understand and document how the business uses AI tools, which includes understanding the AI’s inputs and outputs, ensuring appropriate data minimization and IP safeguards are implemented, and analyzing disclosures regarding the use of the AI tools. This includes implementing an internal AI policy that covers whether and to what extent employees can use AI tools.
0

Metaverse Law to speak at OCBA Health Care Law Section Meeting

Healthcare Data, Trackers, & Artificial Intelligence: Are You Giving Away Sensitive Healthcare Information?

  Metaverse Law’s Lily Li will be speaking on this topic at this month’s OCBA Health Care Law Section Meeting. When? Thursday, March 14, 2024 12:30 PM – 1:30 PM Where? OCBA Offices 4101 Westerly Place Newport Beach, CA 92660 Click here for more information and to register for the event. *Advance registration required. No Walk-Ins.*
0
Orange County Lawyer Magazine Logo

Metaverse Law featured in OC Lawyer Magazine

The Orange County Bar Association recently released the January 2024 issue of Orange County Lawyer magazine. This month, Orange County Lawyer includes an article written by Metaverse Law’s Lily Li.

Read “AI Generated Deepfakes: Potential Liability and Remedies” below or in Orange County Lawyer magazine.

 

[Originally published as a Feature Article: AI-Generated Deepfakes: Potential Liability and Remedies, by Lily Li, in Orange County Lawyer Magazine, January 2024, Vol. 66 No.1, page 26.]

AI-Generated Deepfakes: Potential Liability and Remedies

 

by Lily Li

 

Almost ten years ago, in Netflix’s hit series House of Cards, the Underwoods’ presidential bid is almost derailed by a leaked picture of an affair, nude shower scene and all. While the picture was real, the Underwoods were able to undermine the credibility of the leaked image by claiming it was fake—going so far as to recreate the image using a hired model, to show how “easy” it was to fabricate photos.

This episode, aptly named “The Road to Power,” highlights one of the greatest risks of disinformation and fake or synthetic media. It is not through the public’s gullibility to doctored images; it is the watering down of trust in online media, leading individuals to rely solely on friends, family, and other sources of information that echo their own beliefs and values.

Fast forward a decade, and synthetic media—also known as “deepfakes” –-are now pervasive. In early 2022, for example, a fake video of Ukrainian President Volodymyr Zelensky circulated on social media, calling for his soldiers to lay down their arms and surrender to Russia.[1] At the corporate level, deepfakes have been used to mimic a CEO’s voice to fraudulently transfer $243,000.[2] Just as troubling, and even more creepy, a “sophisticated hacking team” impersonated the CEO of cryptocurrency company Binance by using “video footage of his past TV appearances and digitally alter[ing] it to make an ‘AI hologram’ of him and trick people into meetings.”[3] At home, scammers can use deepfaked voices to mimic loved ones, or AI-powered chatbots to engage in romance scams via text messages and phone calls. This is just a front to ask the victim to wire money, send gift cards, or reveal personal information to engage in identity theft. The problem has become so severe that both the FTC and the FCC have released consumer alerts in early 2023 regarding these AI-generated scams.[4]

The ease in which generative AI can create realistic videos, voice, and text will only aggravate these concerns. Deepfakes have long relied on machine learning to iterate and become more realistic with training, but in the past, this type of technology required significant computing resources and time. Now, almost every tech product is incorporating generative AI or machine learning in some form, making this accessible to every novice programmer or script kiddie.

Given these growing risks, this article will focus on the potential liability that creators, platforms, and publishers face in creating and spreading deepfakes, as well as the challenges of pursuing remedies under existing laws. In addition, this article will discuss pending rulemaking governing deepfakes and potential steps forward.

 

Privacy Liability for Deepfakes

Biometrics: If deepfakes rely on scans of faceprints, facial geometry, or voiceprints to make the false video or audio, or even to train their algorithms, then biometric privacy laws may apply. The Illinois Biometric Information Privacy Act (BIPA) is one of the strictest data privacy laws in the country. It requires express written consent and meaningful disclosures prior to any use and disclosure of Illinois resident biometric data. The collection of biometric data is interpreted broadly to include faceprints and voiceprints. It provides a private right of action, up to $5,000 in statutory damages per violation, and does not require a showing of harm.[5] Earlier this year, in Cothron v. White Castle Systems, Inc.,[6] the Illinois Supreme Court went even further, confirming that each scan in violation of BIPA counts as an ongoing violation—adding further teeth to this law.

Revenge Porn Laws: To the extent the deepfakes include pornographic images, several states, like Virginia,[7] have explicitly included deepfakes within “revenge porn” laws, while other victims have pursued claims under existing revenge porn laws by claiming that the deepfakes amount to non-consensual pornography. The legal consequences vary by jurisdiction, ranging from misdemeanors to felonies with fines and jail time. New York and California also provide a private right of action for deepfake pornography.

General Data Protection Regulation (GDPR): The EU has a broad privacy law that governs use of personal data. Unlike U.S. state privacy laws, which generally allow free use of publicly available data (except for biometric processing), the EU requires all individuals, companies, and non-profits to have a lawful basis for processing any personal data—with limited exclusions for personal data “manifestly made public by the data subject.” Thus, indiscriminate scraping of social media data for deepfakes, especially where the users have limited the audience for their data, would likely violate the GDPR and be subject to fines and regulatory scrutiny.

 

IP, Torts, and other Remedies

Defamation: Traditional defamation claims are also applicable to deepfakes, if the plaintiff can show that the deepfake is communicated to third parties and makes false assertions that harms the plaintiff’s reputation. For public figures, plaintiffs must also show malice.

Rights of Publicity: Many states recognize a “right of publicity” to an individual’s voice or image. The damages or royalties from a right to publicity claim are proportionate to the value associated with licensing one’s image, so these types of claims are more appropriate for celebrities that ordinarily profit from licensing their image.

Copyright and Trademark: To the extent deepfakes use existing logos, photos, music, or even unique website designs to make them seem official or legitimate, this may support multiple claims of copyright and trademark infringement. Copyright holders may also send copyright takedown notices under the DMCA for infringing conduct.

Breach of Contract: If deepfakes rely on scraped content from existing sites or platforms, this may also support a breach of contract claim against the offending party (to the extent they’ve signed up and agreed to the platform’s rules). For example, in the widely publicized case, hiQ Labs, Inc. v. LinkedIn Corp., the Ninth Circuit found that hiQ breached LinkedIn’s User Agreement both through its own scraping of LinkedIn’s site and through its use of independent contractors to log into LinkedIn and do quality control of the data.[8] The Ninth Circuit noted, however, that LinkedIn was estopped from pursuing certain claims due to how much time had elapsed since its initial awareness of data scraping. Consequently, platforms that wish to rely on breach of contract claims to combat data scrapers, and potential misuse of their platforms for generative AI and deepfakes, must act swiftly and definitively. This is likely the impetus for X Corp’s (formerly Twitter) recent slew of crackdown on data scrapers, through a series of lawsuits filed in August.[9]

State Deepfake Laws: California, Texas, and Virginia have also enacted deepfake laws specific to political deepfakes, but these laws are limited in application and remedy. Texas SB 751, for instance, prohibits deepfake videos created “with intent to injure a candidate or influence the result of an election” and which are “published and distributed within thirty days of an election.” This law makes violations a Class A misdemeanor punishable by up to a year in jail and fines up to $4,000. More recently, Washington State passed a law requiring clear and transparent notices on any synthetic video or audio concerning candidates if it is related to an election. Senate Bill 5152 gives candidates a private right of action, including attorney’s fees for the prevailing party.

 

Limitations of Existing Remedies; Section 230 of the Communication Decency Act

There are several hurdles that would-be plaintiffs face in pursuing deepfake claims. For many torts like defamation and right of publicity, the amount of damages may be limited compared to the cost of litigation, and important First Amendment rights protect non-commercial speech that is satirical or political commentary. In addition, deepfake content can easily cross borders, so it may be difficult to find a defendant to penalize or enjoin. Consequently, instead of pursuing traditional claims, many victims rely solely on IP takedown notices, or a social media platform’s own processes to flag and remove deepfake content.

At present, Section 230 of the Communications Decency Act also shields platforms from liability for the content users upload and distribute on their platforms, as platforms generally do not constitute the “speaker” or “publisher” of such content. The line between acting as a pure platform, and contributing or generating harmful content, is increasingly blurred, however. In the recent Supreme Court case, Twitter, Inc. v. Taamneh et al,[10] plaintiffs alleged that social media platforms profited from ISIS recruitment videos and allowed ISIS to take advantage of the social media platforms’ “recommendation” algorithms that match content. While the Supreme Court declined to address the scope of 230 protections for these types of “recommendation” algorithms—the Supreme court noted that Section 230 may not protect platforms that create text, audio, or video through generative AI. In oral arguments to Google v. Gonzales, a companion case to Taamneh, Justice Gorsuch strongly implied that generative AI would fall outside of Section 230’s protections, stating: “I mean, artificial intelligence generates poetry, it generates polemics today. That—that would be content that goes beyond picking, choosing, analyzing, or digesting content. And that is not protected. Let’s—let’s assume that’s right, okay?”[11]

Going forward, we anticipate that the Illinois Biometric Information Privacy Act, and pending bills on biometric data, will likely be a more promising and lucrative way to attack platforms that explicitly use biometric data to generate or share deepfakes. In addition, as noted above, plaintiffs may have more luck pursuing claims against platforms that help create deepfake content or media using generative AI rather than solely relying on user content.

 

Do We Need Additional Laws?

As we can see from the patchwork of common law and statutory rights, the potential risks for creating and publishing deepfakes is many, but the best avenue for plaintiffs to pursue a remedy is unclear. Even some regulators are scratching their heads as to whether existing rules apply to deepfakes. For example, in July 2023, Public Citizen filed a petition with the Federal Election Commission (FEC), asking the FEC to amend its regulation on “fraudulent misrepresentation” at 11 C.F.R. § 110.16[12] to clarify that “the restrictions and penalties of the law and the Code of Regulations are applicable” should “candidates or their agents fraudulently misrepresent other candidates or political parties through deliberately false [AI]-generated content in campaign ads or other communications.”[13] In response, the FEC submitted a notice, soliciting public comment on this issue before making a decision on the merits of the petition.

The FTC has taken a firmer stance, stating that it does have authority to regulate AI generally, and deepfakes more specifically. In a March 2023 blog post titled “Chatbots, deepfakes, and voice clones: AI deception for sale,” the FTC noted that the “FTC Act’s prohibition on deceptive or unfair conduct can apply if you make, sell, or use a tool that is effectively designed to deceive—even if that’s not its intended or sole purpose.”[14]

Abroad, the European Union is taking an entirely different approach, developing a comprehensive law (the EU “AI Act”) that would govern artificial intelligence as a whole. The law, as drafted, requires all high-risk AI processing to undergo risk assessments for bias, safety, accuracy, and other risks. In addition, the AI Act would require transparency obligations for deepfakes, defined as “AI systems that generate or manipulate image, audio or video content.”[15] While the AI Act is still in draft form, it is likely to have as large and wide sweeping of an impact as the General Data Privacy Regulation, once it goes into effect.

Given the existing plethora of rights and remedies under the law, and the potential impact of the EU AI Act, this author does not believe that this is the right time to pursue a federal law specific to deepfakes—even though they present serious threats. In the current divisive political climate, it is likely that any proposed law will either get blocked, watered down, or if passed—fail to strike the right balance between free speech and misleading content. Instead, courts and regulators should strictly enforce existing laws that protect individual privacy and image rights, and the right to be free from false and deceptive practices. Attorneys should advise their tech clients on the risks of generative AI technologies and the potential gaps in Section 230 coverage. Finally, as private citizens, let’s remain diligent in what we read and share—and not be afraid to call out anyone who seeks to deceive.

 

ENDNOTES

(1) Bobby Allyn, Deepfake video of Zelenskyy could be ’tip of the iceberg’ in info war, experts warn, NPR (Mar. 16, 2022, 8:26 PM), https://www.npr.org/2022/03/16/1087062648/deepfake-video-zelenskyy-experts-war-manipulation-ukraine-russia.

(2) Catherine Stupp, Fraudsters Used AI to Mimic CEO’s Voice in Unusual Cybercrime Case, Wallstreet Journal (Aug. 30, 2019, 12:52 PM),  https://www.wsj.com/articles/fraudsters-use-ai-to-mimic-ceos-voice-in-unusual-cybercrime-case-11567157402.

(3) Luke Hurst, Binance executive says scammers created deepfake ’hologram’ of him to trick crypto developers, Euronews (Aug. 24, 2022, 2:47 PM), https://www.euronews.com/next/2022/08/24/binance-executive-says-scammers-created-deepfake-hologram-of-him-to-trick-crypto-developer.

(4) Alvaro Puig, Scammers use AI to enhance their family emergency schemes, Federal Trade Commission (Mar. 20, 2023), https://consumer.ftc.gov/consumer-alerts/2023/03/scammers-use-ai-enhance-their-family-emergency-schemes; ’Grandparent’ Scams Get More Sophisticated, Federal Communications Commission, https://www.fcc.gov/grandparent-scams-get-more-sophisticated (last visited Nov. 29, 2023).

(5) See Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186 (Jan. 25, 2019).

(6) 2023 IL 128004 (Feb. 17, 2023).

(7) Va. Code Ann. § 18.2-386.2.

(8) No. 17-3301 (N.D. Cal. Nov. 4, 2022).

(9) Blair Robinson, X Corp Lawsuits Target Data Scraping, National Law Review (Aug. 17, 2023), https://www.natlawreview.com/article/x-corp-lawsuits-target-data-scraping.

(10) 598 U.S. 471 (May 18, 2023).

(11) Transcript of Oral Argument at 49, Google v. Gonzales, 598 U.S. 617 (2023) (No. 21-1333).

(12) Available at https://www.ecfr.gov/current/title-11/section-110.16.

(13) Artificial Intelligence in Campaign Ads, 88 Fed. Reg. 55606 (proposed Aug. 16, 2023), https://www.federalregister.gov/documents/2023/08/16/2023-17547/artificial-intelligence-in-campaign-ads.

(14) Michael Atleson, Chatbots, deepfakes, and voice clones: AI deception for sale, Federal Trade Commission (Mar. 20, 2023), https://www.ftc.gov/business-guidance/blog/2023/03/chatbots-deepfakes-voice-clones-ai-deception-sale.

(15) Tambiama Madiega, Artificial intelligence act, EU Legislation in Progress, European Parliament (June 2023), https://www.europarl.europa.eu/RegData/etudes/BRIE/2021/698792/EPRS_BRI(2021)698792_EN.pdf.

 

Lily Li is a data privacy, AI, and cybersecurity lawyer and founder of Metaverse Law. She is a certified information privacy professional for the United States and Europe and is a GIAC Certified Forensic Analyst for advanced incident response and computer forensics.

0

AI vendor management – human programming for machine learning

Machine learning and artificial intelligence (AI) have permeated the supply chain. The reasons are apparent. Low cost and efficiency are an easy sell in today’s economy, with rampant inflation in the supply chain and tight labor markets. Yet, the economic motivation for AI must be tempered by human (or human-programmed) review of AI systems. Rules are necessary to ensure that the fundamental privacy and moral rights of individuals are protected. From data input to disaster recovery, AI vendor management ensures both the protection of businesses and the broader society. In an Insight article written by Lily Li, Founder of Metaverse Law for Data Guidance, Lily discusses data minimization for AI vendors, algorithmic bias and disgorgement, considerations for AI terms and conditions, and business continuity and disaster recovery considerations for AI. Click here to continue reading.
1 8 9 10 11 12 29