0
Robotic hand and human hand pointing toward each other with the letters "AI" in between them.

Comparing EU and US AI legislation: déjà vu to 2020

This article was initially published in Reuters and Thomson Reuters Westlaw Today.   Lily Li of Metaverse Law discusses the landscape for AI legislation, with the passage of the European Union’s AI Act while states pass AI bills with differing thresholds, coverage and subject matter.   The landscape for EU and US AI legislation feels like a rinse and repeat of data privacy legislation in 2020. Back then, the General Data Protection Regulation (GDPR) was in full force and effect, while California and other states were developing privacy laws at breakneck speed. Many companies were caught unaware by GDPR, only to face a new onslaught of US state-by-state privacy laws.   Now, companies face the same problem. The EU has just passed a comprehensive AI law, the EU AI Act, which imposes significant compliance obligations and antitrust-style mega fines.   In the United States, state legislatures are passing AI bills at a breakneck speed, with differing thresholds, coverage and subject matter. Do global companies bite the bullet and comply with the EU AI Act globally, or should there be a more nuanced jurisdiction-by-jurisdiction approach?   Comprehensive and imposing   The EU AI act is a comprehensive law that has been in development for years by EU regulators. One of its unique features, not seen in US legislation, is a complete ban on certain “prohibited AI practices” (Article 5, https://bit.ly/4gQHfe8). Some of these prohibited practices include assessing whether an individual is likely to commit a crime and real-time biometric identification by law enforcement (think Minority Report), as well as social scoring of individuals.   In addition to setting forth prohibited practices, the EU AI Act designates a list of high-risk AI practices. This includes, but is not limited to, use of AI in employment decisions, credit scores, insurance and access to services. For these high-risk AI practices, AI providers need to implement a full risk management program that considers the following factors:  
  • Data governance
  • Technical documentation
  • Recordkeeping
  • Human oversight
  • Accuracy, robustness, and cybersecurity management
  • Quality management
  Like the GDPR, the EU AI Act imposes significant fines. This can be up to $35,000,000 or 7% of total worldwide revenue, whichever is higher, for engaging in prohibited AI practices (Article 99, https://bit.ly/3XRewgl), and up to $15,000,000 Euros or 3% of the total worldwide annual turnover, whichever is higher for other violations (Article 99, https://bit.ly/3XRewgl). The law requires each EU country to designate at least one independent and impartial body to monitor and enforce the EU AI Act’s requirements.   In contrast, the US is following a patchwork approach. Instead of comprehensive federal legislation, we are seeing a state by state and agency approach. To date, these laws generally fall into four main categories: (i) consumer protection; (ii) employment rights; (iii) image and likeness rights; and (iv) transparency/ risk assessment requirements for high-risk AI processing.   Consumer protection   For state consumer protection laws governing AI, Utah is one of the first movers. In May of 2024, it added requirements governing AI to its consumer protection statutes. Utah’s AI Policy Act requires businesses in Utah to disclose the use of generative AI tools, and also makes businesses liable for any consumer protection violations by these generative AI tools.   At the federal level, the FTC has used its consumer protection authority under Section 5 of the FTC Act, in order to regulate against unfair and deceptive practices in commerce concerning AI. In 2022, Weight Watchers agreed to pay a $1.5 million civil penalty in a settlement with the FTC, in part over allegations that the company improperly collected children’s data to train its models and algorithms. This settlement included “algorithmic disgorgement” — i.e., Weight Watchers was required to delete any models trained on such data.   More recently, on Sept. 25, 2024, the Federal Trade Commission (FTC) has cracked down on companies that make misleading or fraudulent claims about their use of AI tools. This included taking action against DoNotPay (https://bit.ly/3BtSWXW), a company that claimed to offer an AI service that was “the world’s first robot lawyer.”   DoNotPay agreed to a $193,000 settlement with the FTC, pursuant to a consent order. The consent order (https://bit.ly/4dNyjmN) also requires DoNotPay to refrain from “representing that its Service or any other internet-enabled product or service that it offers operates like a human lawyer or any other type of professional, unless that representation is not misleading and DoNotPay possesses competent and reliable evidence to substantiate the representation.” In addition, DoNotPay is required to notify consumers of the order and to submit compliance reports to the FTC.   AI in employment decisionmaking   At the employment level, Illinois recently enacted a law that prohibits the use of AI systems from discriminating against employees or job applicants based on any protected classes.   In addition, this amendment explicitly bans the use of race or zip code when used as a proxy for race in AI systems making employment decisions. Illinois’ requirements join New York City Local Law 144 (https://on.nyc.gov/3zHlSva) in regulating automated employment decision-making tools. While Local Law 144 does not include an explicit ban on the use of race or zip code in AI systems, it has very stringent notice and audit rights.   Where employers use AI systems “to substantially assist or replace discretionary decision making,” Local Law 144 requires publicly available third-party bias audits of automated employment decision-making tools.   Image and likeness rights   Generative AI is also regulated by state laws and cases governing image and likeness rights. Following the actors and writers strike in Hollywood, and high-profile litigation by Sarah Silverman and others, California has acted. In the last week, Governor Gavin Newsom signed two AI bills designed to protect entertainers.   AB 2602 requires contracts with actors and other performers to specify whether generative AI will be used to create a replica of the performer’s voice or likeness. AB 2836 bans the use of digital replicas for deceased performers, without the consent of the performer’s estate.   Transparency and risk assessment   The majority of US state comprehensive data privacy laws require transparency concerning the use of AI to process personal data and make decisions that impact important rights, such as employment, housing, and access to services. In addition, these laws generally give consumers the right to opt out of such processing.   Colorado’s AI Act, slated to go in effect in 2026, goes even further. It imposes risk assessment and bias assessment requirements for any “high-risk artificial intelligence system” that makes or is a substantial factor in making a consequential decision.   For purposes of the law, “consequential decision” means a decision that has a material or similarly significant effect on the provision or denial to any consumer of, or the cost or terms of:  
  • Education
  • Employment
  • Financial or lending services
  • Essential government services
  • Health-care services
  • Housing
  • Insurance
  • Legal service
  The Colorado AI Act has even more substantial transparency and notification obligations. As just one example, developers and deployers of “high-risk” AI systems are required to publicly post on their websites a description of the high-risk systems, as well as describe how the AI system manages the risks of bias. This includes further reporting to the Attorney General of “any known or reasonably foreseeable risks of AI discrimination arising from the intended use of the system.” Section §6-1-1702(5).   Where to go from here?   The trend lines are clear, and AI legislation is here to stay. While the US has not enacted federal AI legislation of the same scope as the EU AI Act, we already see significant risk assessment and transparency requirements. As a result, AI companies need to go global with their AI risk management strategies and not get left behind.   Lily Li is the founder and president of Metaverse Law. She advises global clients on their AI risk assessments and data protection impacts assessments, and supports her clients’ overall governance, risk, and compliance (GRC) programs. In addition, she holds the GIAC Certified Forensic Analyst (GCFA) certification for advanced incident response and digital forensics and certifications in information privacy such as the FIP, CIPP/US/E/M. She is based in Newport Beach, California, and can be reached at info@metaverselaw.com.
0
Flyer for the Risk Digital UK/EU global livestream featuring an image of Lily Li, Founder/President of Metaverse Law Corporation.

Metaverse Law Presents at #RISK DIGITAL UK/EU

Metaverse Law’s Lily Li recently spoke at the #Risk Digital UK/EU global livestream last week
for two sessions: “A New Era of AI Governance” and “The Role of
Technology in Modern Governance, Risk and Compliance.”

Lily’s presentations included an overview about artificial
intelligence risks and discussed the latest developments in European
Union and United States AI legislation and regulations. Major
developments in the US include:
— NY and Illinois AI bias legislation in employment
— Colorado comprehensive AI legislation
— California AI bills that have recently passed the legislature.

Lily also touched on how the results of the U.S. presidential election
could impact the AI landscape, either through changes in FTC priority
and state legislation, and the need for AI risk management and
governance programs.

The law in this area is developing very quickly and will affect
businesses in almost every industry. Keeping up with these changes is
critical as businesses deploy and integrate AI into everyday operations.

You can learn more about #Risk Digital and watch on-demand content by clicking on the link: https://www.grcworldforums.com/risk/risk-digital

#Risk Digital is one of a number of conferences organized by GRC World
Forums, a producer of in-person and livestream educational events for
governance, risk and compliance professionals.

0
Photo of Uber sign on the windshield of a car.

Uber Fined $324 Million for Data Transfer Violations

What Happened?

On Monday, the Dutch Data Protection Authority (DPA) found that Uber will be fined over $324 million for violating a European Union data privacy law.[1] The Dutch DPA stated that Uber transferred personal data about its drivers to the United States without appropriate safeguards, violating the GDPR.[2] According to the decision, transfer tools to protect this data were not used during the two years that Uber sent personal data from the EU to its US headquarters.[3]

 

Uber is expected to appeal the ruling, and Michael Valvo, an Uber spokesperson, stated that the “flawed decision and extraordinary fine are completely unjustified.”[4] In 2018, the Dutch DPA fined Uber $1.2 million for failing to report a data breach in a timely manner.[5] Earlier this year, the Dutch DPA fined Uber $11 million for infringement of privacy regulations, also concerning the personal data of drivers working for Uber.[6]

 

What Can We Learn?

Uber’s fine is among one of the largest penalties issued under the GDPR, highlighting the strict enforcement and requirements of data protection law within the EU.[7] The chairman of the Dutch DPA, Aleid Wolfsen, stated that, “the GDPR protects people’s fundamental rights by requiring companies and governments to handle personal data with care” and that Uber’s violations were “very serious.”[8]

 

Enacted in 2016, the GDPR sets forth rigorous standards for transferring and managing personal data. Significant financial penalties have been issued to multiple technology companies, including Meta’s $1.3 billion fine in 2023 for similar violations.[9]

 

The Dutch DPA alleges that Uber failed to implement adequate protections as they were not part of the Data Privacy Framework.[10] Additionally, the Dutch DPA alleged that in August of 2021, the company stopped their use of Standard Contractual Clauses (SCCs).[11] Either of these methods may have resulted in Uber avoiding regulatory scrutiny.

 

Understanding the Data Privacy Framework

There are specific rules that apply to data transfers from the EU to the US.[12] Some businesses in the US are members of the Data Privacy Framework, a set of agreements about safe personal data transfers to the US.[13] If the organization belongs to the Data Privacy Framework, they are treated as having an equivalent level of data protection to the EU.[14] This means that those businesses can transfer EU personal data to businesses consistent with EU law and without additional transfer tools.[15] However, if the business is not part of the Data Privacy Framework, the company will have to take additional protective steps when transferring data.[16]

 

Understanding Standard Contractual Clauses

If the US-based business or entity does not participate in the Data Privacy Framework and does not fall within Article 49 derogations or another exception to data transfer requirements, then two additional requirements should be met to transfer personal data outside of the EU: 1) a transfer tool, and 2) additional measures to protect data must be taken as needed. Article 46 of the GDPR provides a list of transferring tools which provide “appropriate safeguards,” including Standard Contractual Clauses (SCCs).[17]

 

SCCs are model contracts approved by the European Commission which allow controllers and processors to comply with requirements of EU data protection law.[18] SCCs have highly specific data protection safeguards, so when they are used between companies, there is a contractual obligation that personal data will be treated with a high level of protection when transferred outside the EU.[19] Because these contracts are standardized, SCC’s are a “ready-made” tool, which are relatively easy to implement.[20]

 

The investigation into Uber arose after the Schrems II ruling, which invalidated the EU-US Privacy Shield due to insufficient data protection standards in the US.[21]  Despite this ruling, Uber continued transferring personal data of their drivers from the EU to the US without implementing SCCs or other safeguards, based on the argument that Chapter V of the GDPR, which covers transfers of personal data to other countries, did not apply.[22] Uber stated that their actions were exempted under Article 3(2), which defines the territorial scope of processing activities.[23] While Uber maintains that its data protecting policies and processes, found in its privacy notice, are sufficient, this investigation and initial ruling demonstrate the heightened scrutiny that US companies face when operating in the EU.

 

Update from 9/13/2024

The European Commission has launched public consultation on the new EU SCCs. This consultation is for clauses in specific cases where a data importer is located in a third country but is directly subject to the GDPR. Adoption of these guidelines is expected in Q2 of 2025.

 

[1] https://www.reuters.com/technology/cybersecurity/dutch-privacy-watchdog-fines-uber-sending-drivers-data-us-2024-08-26/

[2] https://www.reuters.com/technology/cybersecurity/dutch-privacy-watchdog-fines-uber-sending-drivers-data-us-2024-08-26/

[3] https://www.jurist.org/news/2024/08/netherlands-data-protection-authority-fines-uber-e290m-for-violating-eu-data-regulation/

[4] https://www.nytimes.com/2024/08/26/business/uber-netherlands-fine-driver-data.html

[5] https://www.ciodive.com/news/uber-hit-with-12m-in-fines-for-2016-data-breach/543017/

[6] https://www.reuters.com/technology/cybersecurity/dutch-privacy-watchdog-fines-uber-sending-drivers-data-us-2024-08-26/

[7] https://complexdiscovery.com/uber-faces-e290-million-fine-for-gdpr-violation-in-data-transfer-to-us/

[8] https://complexdiscovery.com/uber-faces-e290-million-fine-for-gdpr-violation-in-data-transfer-to-us/

[9] https://www.metaverse.law/2023/05/22/meta-fined-for-data-transfer-violations/

[10] https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-dpa-imposes-a-fine-of-290-million-euro-on-uber-because-of-transfers-of-drivers-data-to-the-us

[11] https://www.autoriteitpersoonsgegevens.nl/en/current/dutch-dpa-imposes-a-fine-of-290-million-euro-on-uber-because-of-transfers-of-drivers-data-to-the-us

[12] https://www.autoriteitpersoonsgegevens.nl/en/themes/international/transfer-within-and-outside-the-eea/personal-data-transfers-to-the-us

[13] https://www.autoriteitpersoonsgegevens.nl/en/themes/international/transfer-within-and-outside-the-eea/personal-data-transfers-to-the-us

[14] https://ec.europa.eu/commission/presscorner/detail/en/ip_23_3721

[15] https://www.dataprivacyframework.gov/Program-Overview

[16] https://www.autoriteitpersoonsgegevens.nl/en/themes/international/transfer-within-and-outside-the-eea/personal-data-transfers-to-the-us

[17] https://www.edpb.europa.eu/system/files/2021-06/edpb_recommendations_202001vo.2.0_supplementarymeasurestransferstools_en.pdf

[18] https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/new-standard-contractual-clauses-questions-and-answers-overview_en

[19] https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/new-standard-contractual-clauses-questions-and-answers-overview_en

[20] https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/new-standard-contractual-clauses-questions-and-answers-overview_en

[21] https://www.metaverse.law/2020/11/30/eu-us-data-transfers-after-schrems-ii-european-commission-publishes-new-draft-standard-contractual-clauses/

[22] https://www.linkedin.com/posts/protectionofdata_uber-decision-dutch-dpa-activity-7234087611676463106-PWNz?utm_source=share&utm_medium=member_desktop

[23] https://www.linkedin.com/posts/protectionofdata_uber-decision-dutch-dpa-activity-7234087611676463106-PWNz?utm_source=share&utm_medium=member_desktop

1 2