Skip to main content

On-demand webinar coming soon...

Blog

Six takeaways from recent FTC rulings and what they mean for your AI governance program

Learn more about what the recent FTC rulings mean for the nuances of responsibilities when it comes to AI, the importance of customer data protection, and the role of consent in deploying AI

Lauren Diethelm
AI Content Marketing Specialist
February 21, 2024

Photo of the curved surface of a blue-tiled office roof.

In the ever-evolving landscape of AI regulation, recent rulings from the Federal Trade Commision (FTC) have shed light on crucial aspects that impact providers, deployers, and users of AI systems. As AI technology advances and more regulations continue to pass, it’ll become increasingly important to understand the impact of these rulings. 

Here, we’ll dive into six key takeaways from the recent FTC rulings and what they mean for your own AI governance program. 

 

1.  Deployers of AI systems have just as much of a role to play in responsible use of AI as providers

There’s a lot of emphasis placed on providers and developers of AI systems (conducting conformity assessments, etc.), but recent rulings from the FTC serve as a reminder that deployers need to be paying just as much attention. 

Things like considering and assessing risk, testing and documenting systems, vetting third party vendors, and regularly monitoring systems for change in accuracy are all things that deployers of AI systems need to be aware of. 

Deployers of AI systems also have an additional responsibility: to ensure their employees are adequately trained on the AI policies put in place. Giving users the opportunity to opt out of their data being used in an AI system, for instance, is a requirement for the use of many different AI systems – but is rendered almost useless if the employees responsible for implementing the removal of that data aren’t aware of where, when, or how to do it. 

Regardless of the type of AI you’re planning on governing in your organization, it’s important to remember and have a plan documented for your role and the responsibilities associated with it. 

 

2. Responsibilities and consequences in AI governance are nuanced

Recent rulings from the FTC have carried different levels of consequences. The orders have varied from addressing the moral obligations to protect consumers from the harms caused by bias all the way through to creating concrete policies, informing employees of those policies, and ensuring ongoing enforcement. 

The variance in these considerations means that AI governance is nuanced – there’s no one response to a breach of trust when it comes to AI, and governance committees need to be prepared to think through every angle and potential consequence before deploying a system. 

 

3. Protecting customer data remains a priority

Recent rulings and a warning to AI companies more broadly all stress the importance of protecting customer data – including making disclosures where appropriate, not selling or sharing private data, and getting consent for its use, among other things. 

These decisions also serve as a reminder that AI systems devour data. And though regulations for AI are still developing, AI systems and companies, including model-as-service companies, aren’t exempt from the existing laws that protect privacy and the use of data more broadly. This may seem obvious to most privacy professionals, but these recent rulings show that diligence is always required. 

 

4. Consent is especially key in deploying AI

These recent orders from the FTC also remind companies considering the use of AI-assisted biometric technology that they need to think through:

  • How they are informing consumers about the use of that technology

  • How users can contest their enrollment (and how employees are trained to remove contested data)

  • How to develop a consumer complaint system to allow business to effectively and promptly address their concerns

  • And the need to have robust testing in place to avoid bias against certain groups 

These considerations extend past biometric tech, which in many use-cases is considered prohibited use by the EU AI Act anyway. Regardless of the type of AI system being used or the risk level associated, all AI systems are using data provided by or connected to real people. 

Companies using AI need to ensure that they give users on both ends clear transparency into what data is collected, how it’s used, and, perhaps most importantly, clear and understandable steps for how users can opt out. 

 

5. Transparency efforts can’t be done quietly

The most recent guidance from the FTC reminds all companies, and AI companies in particular, that informing consumers of changes to their data policies through surreptitious or retroactive amendments may be unfair or deceptive.  

This means that simply checking the box of alerting consumers of changes to your policies isn’t enough – the method of that alert matters perhaps just as much. To be a meaningful effort in transparency, the consent you gather from your consumers can’t be artificial consent; it must be communicated clearly and understandably to those users.  

 

6. There’s no US federal law for AI, but that doesn’t mean there’s no enforcement

The FTC’s actions in all these cases also throw into relief the patchwork system that’s in place for AI regulation now – but that doesn’t mean companies can’t be held accountable. 

Consent and transparency are essential in deploying AI systems, and in the absence of a comprehensive federal law for AI, the FTC is prepared to weigh in, monitor, and enforce compliance with existing privacy laws to ensure both those requirements are met.

 

Understanding the complexities of AI governance

All these rulings underscore the intricate and evolving nature of AI governance. As organizations continue to embrace AI, they must recognize the shared responsibility between providers and deployers, prioritize the protection of customer data, and meticulously consider the consequences of their AI actions. 

This guide will help you ensure you’re thinking through every angle of using AI systems as you’re setting up your AI governance program. To learn how OneTrust can help you begin your work with AI governance, request a demo and speak with an expert today. 


You may also like

Webinar

Privacy Management

Scaling to new heights with AI Governance

Join OneTrust experts to learn about how to enforce responsible use policies and practice “shift-left” AI governance to reduce time-to-market.

June 25, 2024

Learn more

Webinar

AI Governance

Governing data for AI

In this webinar, we’ll break down the AI development lifecycle and the key considerations for teams innovating with AI and ML technologies.

June 04, 2024

Learn more

Webinar

AI Governance

Embedding trust by design across the AI lifecycle

In this webinar, we’ll look at the AI development lifecycle and key considerations for governing each phase.

May 07, 2024

Learn more

Webinar

AI Governance

Navigating AI policy in the US: Insights on the OMB Announcement

This webinar will provide insights for navigating the pivotal intersection of the newly announced OMB Policy and the broader regulatory landscape shaping AI governance in the United States. Join us as we unpack the implications of this landmark policy on federal agencies and its ripple effects across the AI ecosystem.

April 18, 2024

Learn more

Webinar

AI Governance

Data privacy in the age of AI

In this webinar, we’ll discuss the evolution of privacy and data protection for AI technologies.

April 17, 2024

Learn more

Resource Kit

AI Governance

OneTrust's journey to AI governance resource toolkit

What actually goes into setting up an AI governance program? Download this resource kit to learn how OneTrust is approaching our own AI governance, and our experience may help shape yours.

April 11, 2024

Learn more

Interactive Tool

Privacy Management

OneTrust Data Privacy Maturity Model self-assessment

This self-assessment will help you to gauge the maturity of your privacy program and understand the areas the areas of improvement that can further mature your privacy operations.

April 01, 2024

Learn more

Webinar

AI Governance

AI in (re)insurance: Balancing innovation and legal challenges

Learn the challenges AI technology poses for the (re)insurance industry and gain insights on balancing regulatory compliance with innovation.

March 14, 2024

Learn more

Webinar

Privacy Management

Fintech, data protection, AI and risk management

Watch this session for insights and strategies on buiding a strong data protection program that empowers innovation and strengthens consumer trust.

March 13, 2024

Learn more

Webinar

Privacy Management

Managing cybersecurity in financial services

Get the latest insights from global leaders in cybersecurity managment in this webinar from our Data Protection in Financial Services Week 2024 series.

March 12, 2024

Learn more

Webinar

AI Governance

Government keynote: The state of AI in financial services

Join the first session for our Data Protection in Financial Services Week 2024 series where we discuss the current state of AI regulations in the EU.

March 11, 2024

Learn more

White Paper

AI Governance

Getting started with AI governance: Practical steps and strategies

Download this white paper to explore key drivers of AI and the challenges organizations face in navigating them, ultimately providing practical steps and strategies for setting up your AI governance program.

March 08, 2024

Learn more

Webinar

AI Governance

Revisiting IAPP DPI Conference – Key global trends and their impact on the UK

Join OneTrust and PA Consulting as they discuss key global trends and their impact on the UK, reflecting on the topics from IAPP DPI London.

March 06, 2024

Learn more

Webinar

AI Governance

AI regulations in North America

In this webinar, we’ll discuss key updates and drivers for AI policy in the US; examining actions being taken by the White House, FTC, NIST, and the individual states. 

March 05, 2024

Learn more

In-Person Event

Responsible AI

Data Dialogues: Implementing Responsible AI

Learn how privacy, GRC, and data professionals can assess AI risk, ensure transparency, and enhance explainability in the deployment of AI and ML technologies.

February 23, 2024

Learn more

AI Governance

Catch it Live: See the All-New Features in OneTrust's Winter Release

See the latest OneTrust platform features that improve on customers' ability to build trust, ensure compliance, and manage risk.

February 22, 2024

Learn more

Webinar

AI Governance

Global trends shaping the AI landscape: What to expect

In this webinar, OneTrust DataGuidance and experts will examine global developments related to AI, highlighting key regulatory trends and themes that can be expected in 2024.

February 13, 2024

Learn more

eBook

Privacy Management

Understanding the Data Privacy Maturity Model

Data privacy is a journey that has evolved from a regulatory compliance initiative to a customer trust imperative. This eBook provides an in-depth look at the Data Privacy Maturity Model and how the business value of a data privacy program can realised as it matures.

February 07, 2024

Learn more

Webinar

AI Governance

The EU AI Act

In this webinar, we’ll break down the four levels of AI risk under the AI Act, discuss legal requirements for deployers and providers of AI systems, and so much more.

February 06, 2024

Learn more

Webinar

Responsible AI

Preparing for the EU AI Act: Part 2

Join Sidley and OneTrust DataGuidance for a reactionary webinar to unpack the recently published, near-final text of the EU AI Act.

February 05, 2024

Learn more

Data Sheet

Privacy Automation

An overview of the Data Privacy Maturity Model

Data privacy is evolving from a regulatory compliance initiative to a customer trust imperative. This data sheet outlines the four stages of the Data Privacy Maturity Model to help you navigate this shift.

February 05, 2024

Learn more

Checklist

AI Governance

Questions to add to existing vendor assessments for AI

Managing third-party risk is a critical part of AI governance, but you don’t have to start from scratch. Use these questions to adapt your existing vendor assessments to be used for AI.

January 31, 2024

Learn more

Webinar

AI Governance

Getting started with AI Governance

In this webinar we’ll look at the AI Governance landscape, key trends and challenges, and preview topics we’ll dive into throughout this masterclass.

January 16, 2024

Learn more

Webinar

AI Governance

First Annual Generative AI Survey: Business Rewards vs. Security Risks Panel Discussion

OneTrust sponsored the first annual Generative AI survey, published by ISMG, and this webinar breaks down the key findings of the survey’s results.

January 12, 2024

Learn more

Report

AI Governance

ISMG's First annual generative AI study - Business rewards vs. security risks: Research report

OneTrust sponsored the first annual ISMG generative AI survey: Business rewards vs. security risks.

January 04, 2024

Learn more

Webinar

AI Governance

Building your AI inventory: Strategies for evolving privacy and risk management programs

In this webinar, we’ll talk about setting up an AI registry, assessing AI systems and their components for risk, and unpack strategies to avoid the pitfalls of repurposing records of processing to manage AI systems and address their unique risks. 

December 19, 2023

Learn more

Webinar

Responsible AI

Preparing for the EU AI Act

Join Sidley and OneTrust DataGuidance for a reactionary webinar on the EU AI Act.

December 14, 2023

Learn more

Webinar

Consent & Preferences

Marketing Panel: Balance privacy and personalization with first-party data strategies

Join this on-demand session to learn how you can leverage first-party data strategies to achieve both privacy and personalization in your marketing efforts.

December 04, 2023

Learn more

Webinar

AI Governance

Revisiting IAPP DPC: Top trends from IAPP's privacy conference in Brussels

Join OneTrust and KPMG webinar to learn more about the top trends from this year’s IAPP Europe DPC. 

November 28, 2023

Learn more

eBook

AI Governance

Navigating the draft EU AI Act

With the use of AI proliferating at an exponential rate, the EU is in the process of rolling out a comprehensive, industry-agnostic regulation that looks to minimize AI’s risk while maximizing its potential.

November 17, 2023

Learn more

eBook

Responsible AI

Conformity assessments under the proposed EU AI Act: A step-by-step guide

Conformity Assessments are a key and overarching accountability tool introduced by the EU AI Act. Download the guide to learn more about the Act, Conformity Assessments, and how to perform one.

November 17, 2023

Learn more

Webinar

Responsible AI

OneTrust AI Governance: Championing responsible AI adoption begins here

Join this webinar demonstrating how OneTrust AI Governance can equip your organization to manage AI systems and mitigate risk to demonstrate trust.

November 14, 2023

Learn more

White Paper

AI Governance

AI playbook: An actionable guide

What are your obligations as a business when it comes to AI? Are you using it responsibly? Learn more about how to go about establishing an AI governance team. 

October 31, 2023

Learn more

Infographic

AI Governance

The Road to AI Governance: How to get started

AI Governance is a huge initiative to get started with for your organization. From data mapping your AI inventory to revising assessments of AI systems, put your team in a position to ensure responsible AI use across all departments.

October 06, 2023

Learn more

White Paper

AI Governance

How to develop an AI governance program

Download this white paper to learn how your organization can develop an AI governance team to carry out responsible AI use in all use cases.

October 06, 2023

Learn more

eBook

Responsible AI

AI, Chatbots, and beyond: Your questions answered

We answer your questions about AI and chatbot privacy concerns and how it is changing the global regulatory landscape.

August 08, 2023

Learn more

Webinar

Responsible AI

Unpacking the EU AI Act and its impact on the UK

Prepare your business for EU AI Act and its impact on the UK with this expert webinar. We explore the Act's key points and requirements, building an AI compliance program, and staying ahead of the rapidly changing AI regulatory landscape.

July 12, 2023

Learn more

Webinar

Responsible AI

AI, chatbots and beyond: Combating the data privacy risks

Prepare for AI data privacy and security risks with our expert webinar. We will delve into the evolving technology and how to ensure ethical use and regulatory compliance.

June 27, 2023

Learn more

Webinar

AI Governance

The EU's AI Act and developing an AI compliance program

Join Sidley and OneTrust DataGuidence as we discuss the proposed EU AI Act, the systems and organizations that it covers, and how to stay ahead of upcoming AI regulations.

May 30, 2023

Learn more

White Paper

AI Governance

Data protection and fairness in AI-driven automated data processing applications: A regulatory overview

With AI systems impacting our lives more than ever before, it's crucial that businesses understand their legal obligations and responsible AI practices.  

May 15, 2023

Learn more

Webinar

AI Governance

AI regulation in the UK – The current state of play

Join OneTrust and their panel of experts as they explore Artificial Intelligence regulation within the UK, sharing invaluable insights into where we are and what’s to come.

March 20, 2023

Learn more

Regulation Book

AI Governance

AI Governance: A consolidated reference

Download this reference book and have foundational AI governance documents at your fingertips as you position your organization to meet emerging AI regulations and guidelines.

Learn more

Webinar

AI Governance

AI governance masterclass

Navigate global AI regulations and identify strategic steps to operationalize compliance with the AI governance masterclass series.

Learn more

Webinar

AI Governance

Mature your data privacy program

OneTrust DataGuidance and Sidley are joined by industry experts for the annual Data Protection in Financial Services Week.

Learn more