Искусственный интеллект · 1 декабря 2024 · 5 мин чтения

Strengthening of AI regulation

December 2024 saw developments indicating increased regulation of AI in different countries: both those with specific laws for AI (Spain) and those operating under general regulations (USA).

Из выпуска мониторинга No. 12, December 2024 · выпуск целиком, PDF · на сайте Института Гайдара

December 2024 saw developments indicating increased regulation of AI in different countries: both those with specific laws for AI (Spain) and those operating under general regulations (USA).

The US experience

On December 3, 2024, the Federal Trade Commission published a draft consent order1 with U.S. company IntelliVision Technologies. The company is prohibited from disseminating misrepresenting information about the accuracy and efficacy of its AI software (used in home security systems and smart home touch panels) for facial recognition, as well as its performance across individuals with different genders, ethnicities, and skin tones.

The FTC alleges that the company did not have evidence to support its claims that its software is highly accurate and unbiased, and that its anti-spoofing technology ensures the system can't be tricked by a photo or video image. For example, according to the National Institute of Standards and Technology's 2019- 2023 testing results, the error rate of the company's technology's algorithms varies depending on demographic characteristics,2 including a person's region of birth. The company also trained the AI on a meaningfully smaller number of images than it claimed. Meanwhile, AI developers and service providers are subject to general principles regarding unfair advertising. If the agreement is finally adopted, its violation threatens the company with a fine of more than $51,000.

This is the second major AI facial recognition case brought by the FTC in a year. In December 2023, Rite Aid will be prohibited from using facial recognition technology for surveillance purposes for five years to settle the charges that the retailer failed to implement comprehensive safeguards that resulted in the surveillance technology mistakenly identifying people, especially women and dark-skinned3 people, as shoplifters.

Experience of Spain

On December 4, 2024, Organic Law4 5/2024 on the right to protection in the use of AI and other technologies in the provision of legal services entered into force in Spain. Monitoring No. 7 has already raised the issue of the use of AI in courts.

Spain establishes the right of a person to be informed in a clear, simple, understandable and publicly accessible form about how digital platforms use artificial intelligence to make recommendations and decisions in legal services. For example, how AI is used to select lawyers and law firms.

Experience of Brazil

On December 10, 2024, the Brazilian5 Senate passed a law regulating the use of AI. The definition of AI system in this document is in line with the OECD definition updated in March (see Monitoring No. 3).

The Law borrows from the approach6 implemented in the EU AI Act adopted in June (also analyzed in Monitoring No. 3): regulation is based on the level of risk of AI systems: the higher the risk, the higher the requirements for the development and use of the system. The Brazilian law identifies the same risk-based categories of AI as in the EU:

1) Prohibited AI systems with excessive risk.

2) Authorized high-risk AI systems.

3) General-purpose AI systems, among which generative AI and AI with systemic, i.e. potentially large-scale risk are identified.

At the same time, the composition of prohibited systems differs: Brazil includes in this category the distribution of materials on the exploitation of minors, which is more of a criminal offense, but does not include the expansion of facial recognition systems based on images from the Internet and the detection of emotions in education and work (which is categorized as high-risk). The composition of high-risk AI systems in Brazil is expected to be clarified at the bylaw level, the law contains examples: security, medicine, courts, etc., but the law does not include the expansion of facial recognition systems based on images from the Internet and emotion detection in education and work (which is categorized as high-risk).

The law establishes the right of everybody to be informed about their interaction with an AI system, including automated systems. For high-risk AI systems, the rights to clarification, to challenge the system's decisions and to have them reviewed by a human being are additionally provided for.

The requirements for developers of highrisk AI systems in Brazil are also higher than general-purpose AI: for example, its accuracy assessment and safety tests are required. At the same time, the requirements are more lenient and framework-based compared to the EU. For example, risk assessment, mitigation measures and evaluation of their effectiveness are required for high-risk AI, but the assessment procedure (criteria, frequency) is not defined.

Russia’s experience

In Russia, currently legislative regulation of AI use is carried out only through experimental7 legal regimes.


From the monitoring issue No. 12, December 2024. Download the full issue (PDF) · issue page at the Gaidar Institute

Читайте также

Искусственный интеллект

AI under cover

1 мая 2026
Искусственный интеллект

Trust the system

1 марта 2026