Regulators in other countries have taken a more direct approach to AI regulation and been quick to both define and regulate the use of AI technology. Global firms approved to conduct business not only in the United States but abroad will therefore want to consider these when designing and or utilizing public and employee facing AI products and services.
EU Artificial Intelligence Act
For example, the EU Artificial Intelligence Act (“EU AI Act,” or “the Act”), legislation enacted by the European Union in March 2024, defines AI and the persons and entities that fall under its authority. The section below attempts to illustrate how this Act may be applicable to a firm’s AI activities, identifying certain covered roles and activities.
The EU Artificial Intelligence defines an “AI system” as:
“...a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments...”
Providers of AI Systems
- A natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model and places it on the market or puts it into service under its own name or trademark.
- Any AI system made available in the European Union.
- Irrespective of whether they are located in the EU.
- Inclusive of providers located in a third country, where output produced by the system is used in the EU.
- Examples include OpenAI, Google DeepMind, and Meta, who offer ubiquitous generative AI products and services as part of their business model.
Deployers of AI Systems
- A natural or legal person, public authority, agency or other body using an AI system under its authority.
- Excludes personal, non-professional activity.
- Located within the Union.
- Located in a third country, where output produced by the system is used in the EU.
- Examples include financial services firms who may use AI for risk monitoring and fraud detection, transportation companies who rely on AI for route optimization, or social media companies for content moderation and personalization.
Importers and Distributors
- A natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country.
- A natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the EU market.
- Examples include European subsidiaries of US-based firms (Morgan Stanley, JP Morgan, Interactive Brokers) who potentially import AI technology developed by the parent company for use in the EU.
For instance, based on the above, U.S.-based financial services firms might find themselves subject to the EU AI Act as a Deployer if they are using a third-party AI tool for risk monitoring or as an Importer or Distributor if their U.S.-based parent company develops an AI-powered summarization tool that is available to employees in the EU. If applicable, risk-based categories then determine what, when, and how AI can be utilized. According to the Act, higher-risk categories, like those that assist in determining an investor’s creditworthiness, for example, would be subject to heightened risk management, data governance, transparency, and human oversight requirements.
This broad AI regulation enacted by the EU may also be an indicator of what other countries may choose to enact. As such, financial services firms should carefully monitor and assess whether other countries’ AI laws are relevant and document any risk or compliance-related processes as part of their AI development, implementation, and deployment processes. Even firms that have chosen not to use or do not allow AI usage globally or otherwise may want to affirmatively state as much in related policies and procedures. In our view, regulators in the U.S. and abroad will expect such determinations and/or controls to be well documented.
Practical Navigational Takeaways
While AI regulation in the U.S. is somewhat disjoined and lacks specificity surrounding AI technology, other countries have delivered the opposite. Below are a few risk management considerations for firms based in the U.S. that wish to onboard AI technology that is accessible abroad, particularly customer-facing technology:
Anticipate sparse drawing of jurisdictional lines and a broad focus on outcome and potential or actual customer harm.
If you have AI-driven processes or allow employee access to AI tools, a purposeful, risk-based analysis may include documenting which AI tools are most suitable, who in your organization has access to them, and for what purpose. Consider whether training materials are a useful tool to communicate this type of information.
EU and U.S. regulators alike have begun to signal an increased focus on rights of privacy and disclosure requirements concerning a firm’s use of AI. Firms may want to research and access applicability of related regulatory actions when designing firm policies and procedures and planning internal testing.
Consider whether new AI deployments should be accounted for in firm policy. If applicable, ensure clarity on roles and responsibilities of humans involved in any such process.
Government agencies, both foreign and domestic, have enacted laws which clarify boundaries for utilizing AI irrespective of industry guidance. Be attentive to instances where use of AI is subject to additional local regulations. Consider whether this potential risk should be accounted for in firm audit or other risk management processes, particularly in cases where use is prohibited or requires disclosure.
The trend towards increased utilization of AI does not appear to be slowing. As the environment shifts from AI being a mere curiosity to a potential necessity to achieve compliance in the years ahead, regulation will likely become more nuanced and jurisdictionally challenging, potentially requiring specialized risk management and compliance teams to ensure regulatory compliance in the U.S. and across the global.