AI Governance and Compliance: A Comprehensive Guide
48 questions
48 questions on AI governance and compliance, answered and cited by the UpLaw editorial team.
- Can a company that only uses AI, rather than building it, still be regulated as a "provider" under the EU AI Act?
- Can an AI system be named as an inventor on a patent?
- Can an employer be liable for discrimination caused by a third-party AI hiring vendor's tool?
- Can an employer simply adjust AI scores by race to eliminate a disparate impact?
- Can employees paste confidential company information into a public AI chatbot?
- Does an indemnity from an AI vendor protect a company from its own customers' claims?
- Does the EU AI Act apply to US companies with no European offices?
- Does using AI create a new body of "AI law," or does existing law already apply?
- Does withdrawing federal AI guidance or revoking an executive order reduce a company's AI legal exposure?
- Do the various state AI hiring laws require companies to build different compliance programs for each state?
- How does the ADA's "screen-out" provision apply to AI hiring tools?
- How does the EU AI Act regulate general-purpose AI (foundation) models?
- How does the EU's approach to regulating AI differ from the United States' approach?
- How does the FTC regulate deceptive AI claims, or "AI washing"?
- How do you build an AI governance program?
- If an employer's AI screening tool shows a disparate impact, how can it defend the tool?
- Is it fair use to train an AI model on copyrighted works?
- Is it legal to use emotion-recognition or "sentiment" AI to score job candidates?
- What are Illinois's laws on the use of AI in hiring?
- What are the four risk tiers under the EU AI Act?
- What are the main sources of law that regulate AI systems?
- What contract terms matter most when procuring an AI system from a vendor?
- What did Griggs v. Duke Power establish, and why does it matter for AI hiring tools?
- What does New York City's Local Law 144 require for automated hiring tools?
- What does the Colorado AI Act require of developers and deployers of high-risk AI systems?
- What ethical duties do lawyers have when using generative AI?
- What is AI governance, and why is it a legal problem rather than just an engineering one?
- What is BIPA, and why is it the most significant privacy statute for AI?
- What is red-teaming, and why does it matter for AI compliance?
- What is the difference between disparate treatment and disparate impact under Title VII?
- What is the EU AI Act, when do its obligations take effect, and what are the penalties?
- What is the four-fifths rule, and does it apply to AI hiring tools?
- What is the NIST AI Risk Management Framework?
- What laws require disclosing that content is AI-generated or that a user is talking to a bot?
- What legal regimes apply to AI used in healthcare?
- What legal regimes govern the use of AI in lending and credit decisions?
- What makes an AI evaluation legally adequate, and how should fairness metrics be chosen?
- What makes an AI system "high-risk" under the EU AI Act?
- What must a deployer of a high-risk AI system do under the EU AI Act?
- What obligations does the EU AI Act impose on providers of high-risk AI systems?
- What rights does GDPR Article 22 give against automated decisions, and when does a human reviewer defeat it?
- What transparency obligations does Article 50 of the EU AI Act impose?
- When does "human oversight" of an AI decision count as meaningful rather than a rubber stamp?
- When is an AI deployment "unfair" under Section 5 of the FTC Act, even if nobody lied?
- Which AI practices are prohibited outright under the EU AI Act?
- Who owns the copyright in AI-generated output?
- Why are AI hiring tools especially prone to disparate-impact liability?
- Why does a voluntary framework like the NIST AI RMF matter legally if it is not binding?