The march to regulatory change for artificial intelligence: the commonalities between the EU and US
07. März 2023
The march to regulatory change for artificial intelligence: the commonalities between the EU and US07. März 2023 This briefing links up some commonalities between the EU and US in terms of the AI march to regulatory change. Our global regulatory specialists have put their heads together for this update on EU, New York City (NYC) and Colorado. AI, of course, can be about algorithms learning from data relating to people - whether that is in the context of employment applications, insurance claims, or otherwise. All are mentioned below. Reminder: What is happening in the EU? As a quick reminder:
Does the EU AI Act have wider impact than EU? Yes. Even if an organisation is not caught by extra territorial reach of the EU’s AI Act because it’s not using the output from it in the EU, AI themes/opportunities/concerns are going to be the same no matter which country/region. Data privacy regulators and other regulators, particularly in the financial services sector, have already produced detailed guidance about AI technology following the ‘OECD’s Principles for Trustworthy AI’. That is built around five values based core principles that are reflected, in whole or in part, in many other publications on trustworthy AI and corporate codes of ethics. There should be responsible stewardship of trustworthy AI. The principles mean that AI should ensure: (1) promotion of inclusive growth, sustainable development and wellbeing; (2) human centered values and fairness; (3) transparency and explainability; (4) robustness, security and safety; and (5) accountability. Indeed, the EU AI Act has these principles at its heart. What is happening in the US? NYC and Colorado are at the forefront NYCOf significant interest to a great many global businesses who have a presence in NYC is a NYC AI employment law. It’s important to keep bias out of the way in which AI is used to screen out candidates applying for jobs and promotions. AI technology can learn unhelpful things from data sets that are not in tune with an organization’s desire to recruit the best candidates in a way that is diverse and inclusive. AI can lead things the wrong way and draw conclusions without a firm basis in fact. This law means the any AI decision tool used to hire or promote NYC residents must be audited by an independent auditor before the tool is used, and annually thereafter, to prove there isn’t bias and that audit must be published on the company’s website. Employers must notify candidates that they are using the AI tool and provide candidates with an opportunity to request an alternative selection process. Quality input data helps with quality output. For instance, the training data input into the AI system may be based on a larger proportion of one type of person (whether based on their age, race, sex, gender or otherwise). Alternatively, that training data may reflect past discrimination. It may be possible to balance it out by adding or removing data about under or over-represented subsets of the population. The law was originally intended to go into effect on January 1, 2023, but enforcement has been delayed until April 15, 2023, as rule-making around the law continues. NYC can enforce the law and issue fines between $500 and $1,500 per violation, per day. The law also provides for a private right of action by employees and candidates. As NYC employers prepare for the day enforcement goes live, they should carefully assess whether they use AI decision tools in employment that could meet the NYC law’s definition, as its scope may be broader than one would expect. Employers must stay attuned to developments in this area and work with their trusted advisors to inventory and audit their AI tools, and incorporate counsel in the bias audit to ensure attorney-client privilege protection, where possible. ColoradoIn the insurance industry, around the world, decisions have traditionally been taken about whether to sell insurance to a customer and how much to charge the customer for that coverage based on insurance underwriting algorithms (a set of rules from a human or a computer) which draw on data sets of past modelling. AI technology is now being used for this and for other insurance practices, such as marketing, fraud protection and claims handling. In Colorado, a new law, Senate Bill 21-169, is leading the way. Insurers have increasingly used “external consumer data” - data from social media, credit scores and risk scores – to supplement or supplant traditional underwriting factors. The new law prohibits use of such data, and algorithms or models that use such external data, if their use results in unfair discrimination against protected classes of people (race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression.) Put simply: S.B. 21-169 prohibits the Colorado insurance industry (which consists of most large national insurers) from using AI technology and big data to determine insurance coverage and price, marketing targets, and claims settlements if the machine learning results in unfair discrimination against protected classes. On February 1, 2023, the Colorado Division of Insurance released a draft of the first of several regulations that will implement S.B. 21-169. This proposal covers detailed governance and risk management requirements, as well as documentation standards, regarding the use of external consumer data, algorithms and models by life insurers and will be followed soon by a separate rule proposal covering how to test for bias. Another set of regulations will be released for property and casualty insurers. The February 1 proposal makes clear that insurers will be held accountable at the board level for all aspects of their use of external consumer data, algorithms and models. While the regulation is still in the proposal phase, it is critical for insurers to begin fully inventorying their external consumer data, algorithms and models to understand why they are using such tools and how those tools operate. What does this all mean?It means that lawmakers around the globe are starting to make sure AI “behaves itself”. The right thing to do from a human and moral perspective is now being enshrined in countries’ and regions’ and US states’ laws. There can be severe penalties for failures. Reputation damage is also a very significant risk organizations will want to avoid. As with data privacy, ‘baking in’ compliant use of AI technology (this most valuable of tools to be welcomed, but also trained and controlled with robust guardrails) from the very start of a new project/imitative/programme is key. In the same way that data privacy became a Board level issue when the EU’s GDPR came into force in 2018, use of AI technology is following suit. Financial services regulators, data privacy regulators, national and state legislatures – everyone, it seems, is interested in AI. Further informationLinks to further reading on AI regulation are below. US:
EU: Watch this space for future thought leadership events, briefings and updates. We can help organizations, globally, stay the right side of the regulatory compliance line. We have a global footprint of experts, with a deep sector expertise in financial services and other sectors, who are ready to help. If you have any questions about this legal alert, please feel free to contact any of the attorneys listed below or the Eversheds Sutherland attorney with whom you regularly work. Ansprechpartner
Mary Jane Wilson-Bilik Partner Washington, DC, Vereinigte Staaten von Amerika Lorna Doggett Partner London, Vereinigtes Königreich Deepa S. Menon Partner Washington, DC, Vereinigte Staaten von Amerika Carolyn Sullivan Senior Associate London, Vereinigtes Königreich Francis X. Nolan IV Partner New York, Vereinigte Staaten von Amerika Melissa L. Fox Partner Atlanta, United States Michael Bahar Partner Washington, DC, Vereinigte Staaten von Amerika Brandi A. Taylor Partner San Francisco, United States | San Diego, Vereinigte Staaten von Amerika Tanvi Shah Senior Associate San Diego, Vereinigte Staaten von Amerika | San Francisco, United States Janell R. Johnson Counsel Washington, DC, Vereinigte Staaten von Amerika Rebekah Whittington O'Brien Associate Atlanta, United States Publikationen
News
Events und Trainings
legal updates 29. Mai 2026 Consumer Lens - Session 1 | The Rise of European Class Actions podcasts and webcasts 29. Mai 2026 Tax NOLs in Cross-Border Structures Webinar legal updates 28. Mai 2026 EU Pay Transparency Directive legal updates 27. Mai 2026 Trade secrets and the Digital Omnibus: key risks and safeguards client news 02. Juni 2026 Next stop, public ownership: Eversheds Sutherland advises DfT on GTR transi... kanzlei-news 01. Juni 2026 Eversheds Sutherland strengthens restructuring offering with senior partner... kanzlei-news 01. Juni 2026 Eversheds Sutherland strengthens Commercial Advisory practice with technolo... client news 28. Mai 2026 Eversheds Sutherland advises Schroders Greencoat on acquisition of Dutch bi... virtual Spanish employment law training 02. Juni 2026 2pm - 5pm (BST) Virtual virtual UK employment law training 09. Juni 2026 1pm - 4pm (BST) Virtual virtual Nordic (Denmark, Finland, Norway and Sweden) employment law training 16. Juni 2026 12.45pm - 4pm (BST) Virtual virtual Introduction to Swiss employment law 23. Juni 2026 2pm - 5pm (GMT) Virtual |