Explorez la suite complète de produits de gouvernance de l'IA d'Enzai, conçue pour aider les organisations à gérer, superviser et déployer l'IA en toute confiance. Du processus d'intégration structuré et des inventaires centralisés de l'IA aux évaluations automatisées et à la surveillance en temps réel, Enzai fournit les éléments fondamentaux pour intégrer la gouvernance directement au sein des flux de travail quotidiens liés à l'IA, sans ralentir l'innovation.

Enzai

AI regulations

New York Assembly considers AI Consumer Protection Act

AI regulations

New York Assembly considers AI Consumer Protection Act

AI regulations

New York Assembly considers AI Consumer Protection Act

AICPA takes a risk-based approach to combating potential discrimination

Belfast

Belfast

4 minutes de lecture

By

By

Var Shankar

Var Shankar

Sujets

Despite uncertainty about the Trump administration’s approach to AI policy, states are powering ahead with new AI laws. Some of these are focused on specific use cases, like Georgia’s SB 164, which bans the use of automated decision-making tools to set employee wages. Others are more focused on the risks of frontier AI systems, such as Illinois’ HB 3506, which introduces assessment and audit requirements for developers of cutting-edge models.

Lawmakers are also increasingly looking at AI use from the lenses of consumer protection and combating discrimination. Though Colorado is the only state to date to have enacted consumer protection legislation related to AI, the Texas legislature has taken up a comprehensive proposal, with similar bills under consideration in a growing number of states.

In January, similar legislation was introduced in the New York Assembly (A768). The New York AI Consumer Protection Act (AICPA), which is primarily concerned with combating discrimination, follows the general structure of the Colorado law and the Texas proposal: it divides requirements between developers and deployers, focuses on the risks of high-risk AI systems, and requires organizational policies for responsible AI use.

Though some commentators have welcomed the bill, especially considering recent policy reversals at the federal level, other have criticized it as overly focused on procedure. For example, Jeffrey Sonnenfeld and Stephen Henriques believe that lawmakers should focus more on applying existing consumer protection laws to AI systems.

What does AICPA cover?

AICPA would regulate developers and deployers of “high-risk” AI systems. It defines high-risk systems as those that, when deployed, make or are a substantial factor in making “consequential decisions,” which include those that have a “material legal or similar effect” in fields including:

-Education enrollment or educational opportunity

-Employment or employment opportunity

-Financial or lending service

-Essential government service

-Health care service

-Housing or housing opportunity

-Insurance

-Legal service

Several AI uses are carved out from this definition of high-risk systems as exceptions.

Requirements for Developers

AICPA would require developers to exercise “reasonable care” to protect consumers from risks related to algorithmic discrimination and to publicly describe their AI systems and approaches to preventing algorithmic discrimination. It would also require them to provide deployers with documentation for high-risk systems, which includes intended uses, harmful and inappropriate uses, training data, and expected outputs.

Developers will have a “rebuttable presumption” of reasonable care if they undergo independent third-party audits by a government-approved auditor. Such audits would be focused on the potential for discrimination against protected classes.

Requirements for Deployers

Requirements for deployers would include publishing similar statements of AI use, putting in place a risk management policy and program for high-risk AI systems (equivalent to the NIST AI Risk Management Framework or ISO/IEC 42001), completing annual AI impact assessments for high-risk AI systems, and notifying consumers when an AI system is a substantial factor in decision-making.

In the case of an adverse decision, deployers would also have to provide the main reason for the decision and provide an opportunity for the impacted consumer to update any incorrect personal information used during decision-making. In certain circumstances, deployers would be able to contract with developers, so that the latter take on some of these compliance requirements.

Next Steps

If the bill is enacted, it would become effective on January 1, 2027. Though AICPA is still in an early stage of the legislative process, is likely only the first in a series of AI-related bills that New York will consider.

Enzai is here to help

Enzai’s AI GRC platform can help your company deploy AI in accordance with best practices and emerging regulations, standards and frameworks, such as EU AI Act, the Colorado AI Act, the NIST AI RMF and ISO/IEC 42001. To learn more, get in touch here.

Enzai is the leading enterprise AI governance platform, purpose-built to help organizations transition from abstract policy to operational oversight. Our AI risk management platform provides the specialized infrastructure required to manage agentic AI governance, maintain a comprehensive AI inventory, and ensure EU AI Act compliance. By automating complex workflows, Enzai empowers enterprises to scale AI adoption with confidence while maintaining alignment with global standards like ISO 42001 and NIST.

Découvrez davantage

Découvrez davantage

Rejoignez notre bulletin d'information

En vous inscrivant, vous acceptez la Politique de Confidentialité d'Enzai

Rejoignez notre bulletin d'information

En vous inscrivant, vous acceptez la Politique de Confidentialité d'Enzai

Rejoignez notre bulletin d'information

En vous inscrivant, vous acceptez la Politique de Confidentialité d'Enzai

Rejoignez notre bulletin d'information

En vous inscrivant, vous acceptez la Politique de Confidentialité d'Enzai

Conformité Intégrée Dès la Conception

Conformité Intégrée Dès la Conception

ISO 27001

Enzai est certifiée ISO 27001, et lest depuis 2023. Nous nous engageons à réaliser des audits annuels effectués par NQA et collaborons étroitement avec nos partenaires consultants en sécurité, Instil, afin de mettre à jour et de renforcer en continu notre posture de sécurité.

RGPD

ISO 27001

Enzai est certifiée ISO 27001, et lest depuis 2023. Nous nous engageons à réaliser des audits annuels effectués par NQA et collaborons étroitement avec nos partenaires consultants en sécurité, Instil, afin de mettre à jour et de renforcer en continu notre posture de sécurité.

RGPD

Gouvernance de l'IA

Gouvernance de l'IA

Infrastructure

Infrastructure

conçu pour la Confiance.

conçu pour la Confiance.

Donnez à votre organisation les moyens d'adopter, de gérer et de surveiller l'IA avec une confiance de niveau entreprise. Conçu pour les organisations réglementées opérant à grande échelle.

Connectez sans effort vos systèmes existants, vos politiques et vos flux de travail d'IA — le tout sur une plateforme unifiée.

Connectez sans effort vos systèmes existants, vos politiques et vos flux de travail d'IA — le tout sur une plateforme unifiée.