State Regulations Target Automated Decision Making in AI

Automated Decision Making: A Focus of State AI Regulation

As the landscape of artificial intelligence (AI) continues to evolve, state and local legislatures are increasingly prioritizing the regulation of automated decision making. With no comprehensive AI regulation at the federal level, various states are taking the initiative to establish their own legal frameworks aimed at preventing algorithmic discrimination and protecting consumer rights.

Understanding Automated Decision Making

Automated decision making refers to the use of AI, machine learning systems, and algorithms to make decisions with minimal or no human intervention. This practice raises concerns about the potential for bias and discrimination, particularly in critical areas such as employment and consumer rights.

State legislatures are eager to address the perceived risks associated with AI systems making consequential decisions that could adversely affect consumers. Many existing state privacy laws empower consumers to opt-out of data processing for profiling based on automated decisions that have significant impacts.

Current State Regulations

Several states, including Colorado, Illinois, and New York City, have enacted laws targeting automated decision making in AI systems. These regulations aim to mitigate the risk of discrimination against consumers based on protected classes.

Colorado

The Colorado AI Act, effective February 1, 2026, is recognized as the most comprehensive AI legislation in the United States. It applies to both private and government entities involved in developing and deploying high-risk AI systems. Key obligations include:

  • Implementing a duty of reasonable care to protect consumers from known risks of algorithmic discrimination.
  • Conducting annual impact assessments for high-risk AI systems.
  • Disclosing foreseeable risks associated with the use of these systems.

Illinois

In Illinois, amendments to the Human Rights Act will come into effect on January 1, 2026, regulating automated decision making in employment contexts. Employers using AI systems that result in discrimination against consumers based on protected classes may face legal repercussions.

New York City

New York City’s Local Law 144 regulates the use of automated employment decision tools (AEDTs). Key requirements include:

  • Conducting an independent bias audit of AEDTs before their use.
  • Providing candidates with advance notice and the option to opt-out of using AEDTs.

State Privacy Laws and Their Implications

State privacy laws impose specific obligations on businesses engaged in profiling activities. These laws typically grant consumers the right to opt-out of profiling that leads to significant legal effects. Key obligations include:

  • Providing consumers with clear privacy notices detailing their rights.
  • Conducting data protection assessments for processing activities that pose heightened risks.
  • Responding to opt-out requests within a specified timeframe.

Future Developments

As more states consider similar regulations, consumers can expect ongoing changes in state privacy laws, potentially introducing new rights related to automated decision making. States like Connecticut, Massachusetts, New Mexico, New York, and Texas are currently drafting laws that mirror the Colorado AI Act.

In conclusion, as the regulatory landscape for AI continues to develop, it is crucial for stakeholders to stay informed about these changes to ensure compliance and protect consumer rights. The focus on automated decision making illustrates a growing recognition of the need for transparency and accountability in AI systems.

More Insights

CII Advocates for Strong AI Accountability in Financial Services

The Chartered Insurance Institute (CII) has urged for clear accountability frameworks and a skills strategy for the use of artificial intelligence (AI) in financial services. They emphasize the...

Regulating AI in APAC MedTech: Current Trends and Future Directions

The regulatory landscape for AI-enabled MedTech in the Asia Pacific region is still developing, with existing frameworks primarily governing other technologies. While countries like China, Japan, and...

New York’s AI Legislation: Key Changes Employers Must Know

In early 2025, New York proposed the NY AI Act and the AI Consumer Protection Act to regulate the use of artificial intelligence, particularly addressing algorithmic discrimination in employment...

Managing AI Risks: Effective Frameworks for Safe Implementation

This article discusses the importance of AI risk management frameworks to mitigate potential risks associated with artificial intelligence systems. It highlights various types of risks, including...

Essential Insights on the EU Artificial Intelligence Act for Tech Companies

The European Union has introduced the Artificial Intelligence Act (AI Act), which aims to manage the risks and opportunities associated with AI technologies across Europe. This landmark regulation...

South Korea’s Landmark AI Basic Act: A New Era of Regulation

South Korea has established itself as a leader in AI regulation in Asia with the introduction of the AI Basic Act, which creates a comprehensive legal framework for artificial intelligence. This...

EU AI Act and DORA: Mastering Compliance in Financial Services

The EU AI Act and DORA are reshaping how financial entities manage AI risk by introducing new layers of compliance that demand transparency, accountability, and quantifiable risk assessments...

AI Governance: Bridging the Transatlantic Divide

Artificial intelligence (AI) is rapidly reshaping economies, societies, and global governance, presenting both significant opportunities and risks. This chapter examines the divergent approaches of...

EU’s Ambitious Plan to Boost AI Development

The EU Commission is launching a new strategy to reduce barriers for the deployment of artificial intelligence (AI) across Europe, aiming to enhance the region's competitiveness on a global scale. The...