Laws for AI
In March 2024, the OECD released a Clarifying Memorandum on an updated11 definition of an AI system.12
Из выпуска мониторинга No. 3, March 2024 · выпуск целиком, PDF · на сайте Института Гайдара

OECD
In March 2024, the OECD released a Clarifying Memorandum on an updated1 definition of an AI system.2
The previous definition of an AI system is modified (p. 4): “An AI system is a machine system that, for explicit or implicit purposes, deduces from the input data it receives how to generate outputs such as predictions, content, recommendations or decisions that can affect the physical or virtual environment. AI systems3 vary in their levels of autonomy and4 adaptability once operationalized”.
The definition is expanding as AI practices evolve. For example, the OECD considered content-generating AI systems to be such a significant type that they were given a separate mention in the definition, although their work can be seen as a sequence of decisions to output certain words/pixels/sounds if desired. In principle, the definition of AI systems usually covers machine recognition of objects and speech, language information processing, intelligent decision support systems, and intelligent robotic systems (pp. 6, 9).
The OECD believes that goal setting for AI can always be traced back to the person who initiates the development of an AI system, even if the goals are set implicitly. However, some AI systems may develop implicit sub-goals and set goals for other systems.
The experience of EU and US
On March 13, 2024, the European5 Parliament approved the draft AI law.6
The bill identifies the following types of AI:
1. Prohibited AI practices (8 categories), e.g. to build or extend facial recognition systems using images from the Internet or surveillance cameras.
2. Authorized high-risk AI systems, such as remote biometric identification systems.
3. General-purpose AI, among which stand out AI models with systemic risk.
4. Certain AI systems (4 categories) that interact with individuals or produce synthetic content, such as generating deepfakes.
The requirements for permitted types of AI vary according to their risk: the higher the risk, the greater and more complex the requirements, from labeling to risk management systems.
In the US, bills aimed at the AI general regulation were introduced in the Vermont and7 Virginia legislatures in January 2024.
The legislative initiatives of these US states are markedly similar - right down to the overlapping language - but there are some basic divergences as well:
1. The Virginia bill has a narrower list of persons subject to regulation than Vermont's: it only addresses developers and operators of high-risk AI systems, whereas Vermont's bill also contemplates regulations for developers of generative AI systems.
2. The Vermont's bill is more detailed in its definitions and broad in its requirements for developers and operators of high-risk AI systems, specifically spelling out factors for algorithmic discrimination, while Virginia's only references a statutory prohibit.
3. The scope of liability in the Virginia bill is shifted from developers to operators of highrisk AI systems compared to Vermont: for example, avoidance of any risk of algorithmic discrimination in Virginia is mandated only for the latter, whereas in Vermont both.
In terms of comparing the approaches to AI regulation in the EU and the reviewed US states, the following can be pointed out:
1. Approach to AI regulation in the EU relative to U.S. states:
а) Much more comprehensive: the regulation applies not only to high-risk and generative AI (in terms of, for example, deepfakes), but also imposes requirements on other types of AI. б) Stricter: certain AI practices (e.g., recognizing emotions in the workplace) are prohibited, regardless of the standards and requirements for AI systems.
In principle, emotion recognition in the workplace could meet the definition of an important decision (employment) and therefore fall within the spectrum of high-risk AI systems in the US state bills considered, if it affects, for example, layoffs in the case of downsizing, but even then the AI system operator is limited only by the obligation to notify employees of the operation and purpose of such a system.
2. In terms of the criteria for high-risk AI systems, the same trend is generally evident: in the EU, they are broader, and consequently the regime is stricter. The broader definition is achieved by including elements of product safety and critical infrastructure security among the high-risk areas, whereas in the US states considered, it concerns only certain human interests.
3. None of the considered definitions of AI systems is clear enough from the point of view of identifying the qualifying AI features. As a consequence, the narrowing of the subject of regulation to high-risk/risk-bearing (e.g., to a person's personal space) AI systems may be due to the currently unresolved problem of clearly separating AI from familiar devices (e.g., temperature sensors on devices) and humanmade models (e.g., econometric models).
Russia’s experience
In Russian legislation, AI is defined, in particular, in Federal Law No. 123-FZ dated 24.04.2020: it is a set of technological solutions that allows imitating human cognitive functions (including self-learning and search for solutions without a predetermined algorithm) and obtaining, when performing specific tasks, results comparable, at least, to the results of human intellectual activity. Furthermore, AI technologies include computer vision, natural language processing, speech recognition and synthesis, intellectual decision support and promising methods of artificial intelligence.
It should be noted that the Russian definition of AI technologies largely overlaps with the directions of application of AI systems listed by the OECD; having said that, the very definition of AI based on imitation of cognitive abilities and comparison with the results of human intellectual activity looks controversial, as they are not measurable unambiguously and differ between people.
- https://www.oecd-ilibrary.org/docserver/623da898-en.pdf?expires=1710851224&id=id&accname=guest&checksum=E0A20405C7B511BB50F0E6BB10A86556.AI system is a machine system that is capable, for a given set of human- defined goals, of making predictions, recommendations or decisions that affect the real or virtual environment. AI systems are designed to operate at different levels of autonomy. ↑
- The autonomy of an AI system, meanwhile, refers to the degree to which it can learn or act without human input after processes have been automated by humans (p. 6). ↑
- Adaptability refers to AI systems that are able to change their behavior after interacting with inputs and data after enactment (p. 6). ↑
- https://www.europarl.europa.eu/news/en/press-room/20240308IPR19015/artificial-intelligence-act-meps-adopt-landmark-law. ↑
- https://www.europarl.europa.eu/RegData/seance_pleniere/textes_adoptes/definitif/2024/03-13/0138/P9_TA(2024)0138_EN.pdf. ↑
- https://legislature.vermont.gov/Documents/2024/Docs/BILLS/H-0710/H-0710%20As%20Introduced.pdf; https://lis.virginia.gov/cgi-bin/legp604.exe?241+ful+HB747H1. ↑
From the monitoring issue No. 3, March 2024. Download the full issue (PDF) · issue page at the Gaidar Institute