Any laws should be legislating the downstream effects of AI, not the models themselves. Otherwise we will quickly get to a place where we have a handful of government-sanctioned and white-washed “safe” models responsible for deleterious effects on society, with plausible deniability for the companies abusing them. Legislating around the model is missing the point. There is no evidence that a runaway artificial intell…
That would require stronger consumer protections. So that's politically unacceptable in the US at the moment. We may well see it in the EU.
The EU already regulates "automated decision making" as it affects EU citizens. This is part of the General Protection on Data Regulation. This paper discusses the application of those rules to AI systems.[1]
Key points summary:
- AI isn't special for regulation purposes. "First, the concept of Automated Decision Making includes algorithmic decision-making as well as AI-driven decision-making."
- Guiding Principle 1: Law-compliant ADM. An operator that decides to use ADM for a particular purpose shall ensure that the design and the operation of the ADM are compliant with the laws applicable to an equivalent non- automated decision-making system.
- Guiding Principle 2: ADM shall not be denied legal effect, validity or enforceability solely on the grounds that it is automated.
- Guiding Principle 3: The operator has to assume the legal effects and bear the consequences of the ADM’s decision. ("Operator" here means the seller or offerer of the system, not the end user.)
- Guiding Principle 4: It shall be disclosed that the decision is being made by automated means
- Guiding Principle 5: Traceable decisions
- Guiding Principle 6: The complexity, the opacity or the unpredictability of ADM is not a valid ground for rendering an unreasoned, unfounded or arbitrary decision.
- Guiding Principle 7: The risks that the ADM may cause any harm or damage shall be allocated to the operator.
- Guiding Principle 8: Automation shall not prevent, limit, or render unfeasible the exercise of rights and access to justice by affected persons. An alternative human-based route to exercise rights should be available.
- Guiding Principle 9: The operator shall ensure reasonable and proportionate human oversight over the operation of ADM taking into consideration the risks involved and the rights and legitimate interests potentially affected by the decision.
- Guiding Principle 10: Human review of significant decisions Human review of selected significant decisions on the grounds of the relevance of the legal effects, the irreversibility of their consequences, or the seriousness of the impact on rights and legitimate interests shall be made available by the operator.
This is just a summary. The full text has examples, which include, without naming names, Google closing accounts and Uber firing drivers automatically.
[1] https://europeanlawinstitute.eu/fileadmin/user_upload/p_eli/...