Skip to main content
Page header background image

Legal Updates

Compliance-Forward Approach to Developing and Deploying AI and GAI

Business Law Update

This summer, the European Union and Colorado passed significant legislation regarding the regulation of artificial intelligence (AI), and other U.S. states, including California, have similar laws working through the legislative process. These regulations aim to establish consumer protections and ethical standards for AI systems, particularly those posing high risks to health, safety, or fundamental rights. Although many compliance deadlines are years away, these laws provide a roadmap for organizations to start evaluating and incorporating AI and generative AI (GAI).

Risk Classification

Both the EU AI Act and the Colorado AI Act use a risk-based approach to regulate AI systems, applying different obligations based on potential harms. The EU AI Act identifies high-risk AI systems in use cases including, among others:

  • Education and Vocational Training: Determining access, admission, or assignment to institutions, evaluating learning outcomes and steering learning processes, and monitoring student behavior.
  • Employment, Workers Management, and Self-Employment: Recruiting or selecting candidates, creating and placing job ads, filtering or analyzing applications, evaluating candidates, promoting or terminating employees, allocating tasks, and monitoring performance.
  • Public and Private Services: Assessing eligibility for benefits and services, evaluating creditworthiness (excluding fraud detection), classifying emergency calls, and assessing insurance risk.

Similarly, the Colorado AI Act regulates high-risk AI uses that influence consequential decisions, including those related to:

  • Education enrollment or opportunities
  • Employment or employment opportunities
  • Financial or lending services
  • Essential government services
  • Healthcare services
  • Housing
  • Insurance
  • Legal services

Compliance Requirements

To comply with these laws, companies developing or deploying AI systems will need to adhere to requirements such as developing risk management policies, protecting data, and documenting potential risks. These compliance measures are complex and time-consuming, and being proactive allows companies to systematically address the obligations without an impending deadline. While most compliance deadlines for high-risk AI systems are set for 2026, companies can start preparing now, as doing so provides them with a competitive advantage, by both building trust internally as well as showing a strong public commitment to high ethical and compliance standards.

Four Actions to Take Now

  1. Define AI Use: Identify business areas where AI and GAI can be used, and document use cases. Understand the required data types and expected outputs, as well as how those outputs can be used.
  2. Establish a Risk-Based Evaluation Process: Develop a process to evaluate AI development and deployment based on risks associated with both intended and unintended uses. Regularly reevaluate AI systems to account for legislative changes and technological advancements to ensure appropriate risk classification and identify applicable compliance obligations.
  3. Refresh or Create a Data Governance Program: Review or establish a data governance program to ensure alignment with AI use cases. As new AI systems are evaluated, understand how data will be used, created, and stored and update the program as needed. Creating or updating an enterprise-wide, unified language with respect to data empowers companies to provide strong guidance to employees when interacting with AI systems.
  4. Assess and Monitor AI Systems: Create guidelines for human review of AI systems, as well as for assessing AI systems for discrimination, bias, fairness, and other unintended results. Consider adopting external tools to monitor those results if AI is critical to your business or your customer offerings.

By beginning preparations now, companies can navigate the regulatory complexities of AI regulation more effectively, integrate ethical standards into their AI processes, and gain a competitive advantage. When the 2026 deadlines arrive, companies will not only be compliant, but also well-positioned to leverage AI and GAI both ethically and responsibly.

This article may be reproduced, in whole or in part, with the prior permission of Thompson Hine LLP and acknowledgement of its source and copyright. This publication is intended to inform clients about legal matters of current interest. It is not intended as legal advice. Readers should not act upon the information contained in it without professional counsel.

This document may be considered attorney advertising in some jurisdictions.

© 2024 THOMPSON HINE LLP. ALL RIGHTS RESERVED.

Services