No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

AI Regulations Are Coming; How Should Companies Prepare?

As regulators try to keep up with technology, companies should get serious about their policies

by King & Spalding
November 14, 2023
in Compliance
ai generated drawing of legislator examining robot

Image created using OpenAI


Federal regulators have indicated they won’t make the same under-regulation mistake with AI that they made with data privacy regulation, which still doesn’t exist on the federal level. A group of experts from King & Spalding explore what companies need to know to get ahead of coming regulations.

Generative AI has captured the world’s attention, and regulators are no exception. Indeed, the FTC and other regulators are increasingly active on multiple fronts — from large scale antitrust enforcement efforts, to issues as small as online subscriptions and customer reviews. When it comes to generative AI, recent developments suggest that these same regulators are intent on pushing for strict regulation sooner rather than later to guard against what they perceive to be a threat to competition and consumer protection.

The Biden Administration has also acted, issuing an executive order seeking to curb some of the risks of this rapidly spreading technology. (Read more about the order.) 

Regulators keen to avoid ‘grave mistakes’ of under-regulation

In written remarks at the BBB’s National Advertising Division annual conference in September, the FTC’s Bureau of Consumer Protection Director Samuel Levine stated that the FTC would take “a comprehensive and proactive approach” on generative AI legislation. Levine contrasted this approach with the “grave mistakes” on policy choices regarding privacy regulation, where the FTC waited on Congress to enact legislation, which decades later, still does not exist. 

And in early October, the FTC conducted a virtual roundtable on AI and content creation. In her opening remarks, FTC Chairwoman Lina Khan noted that there is no “AI exemption” and that the FTC intends to leverage all available current laws to address potentially unfair or deceptive business practices. She expressed specific concern that generative AI could “incentivize the endless surveillance of our personal data” and “turbocharge fraud.”

cubist style art of robot holding a pencil
Leadership and Career

Want to Be Part of the Generative AI Revolution? Start With Treating It Like an Assistant.

by Dave Cumberland
October 31, 2023

Integrating AI into internal communications can streamline how teams talk to each other

Read moreDetails

How should companies plan for, and react to, potential generative AI regulation?

Companies using — or contemplating using — generative AI should involve internal compliance and legal teams early and often to minimize potential data privacy risks that may be quickly evolving as the FTC attempts to keep up with generative AI technology. In-house legal teams can assist by identifying relevant stakeholders, company policies and changing data privacy or other relevant laws and regulations.

In the event a company determines an internal or government investigation is necessary, keep the following in mind as the scope and scale of the investigation is evaluated:

  • Identify company policies that may be relevant to the investigation process, as these should be carefully considered and any deviations documented before the investigation is launched. Bear in mind that as rulemaking emerges, there may be some lag time between the implementation of those changes and making necessary updates to policies and procedures. In that case, be sure your policies and procedures have appropriately flagged places where the business should check-in with legal and compliance about the latest state of the law and rules.
  • Determine scope and purpose. As much as possible, relevant time periods, business units, employees and goals for the investigation should be determined at the outset. While the scope often expands or changes based on the facts identified, it may be counterproductive and unduly burdensome on the company for the investigation to take on an unnecessarily broad scope, which may impede the efficient and timely resolution of the critical issues.
  • Preserve data and consider the challenges with AI-related data, especially any underlying training data used in building the AI-model. Whether the investigation stems from a subpoena or other legal process, steps should be taken immediately to preserve all potentially relevant data and documents. Engage stakeholders early to understand the scope of what data may be in play (e.g., how data was sourced, model evaluation metrics, training and evaluation scripts). Recommended steps often include implementing back-end holds on emails and other electronically stored documents, communicating preservation obligations to employees and relevant parties (e.g., board members) and suspending routine document retention and/or deletion policies. Given the prevalence of communicating by text message or other messaging applications, as well as the recent focus by regulators on obligations to preserve and produce such communications, consideration of whether to collect data from employees’ mobile devices also may be necessary.
  • Define roles and structure. Decisions about who should be directing, conducting and/or receiving updates about investigation findings are critical for any matter. This includes identifying whether key stakeholders may be witnesses to relevant facts, whether the independence and integrity of the investigation will receive scrutiny (and, relatedly, whether outside counsel should be retained), whether the internal investigation will be conducted at the direction of counsel under attorney-client privilege and what company personnel will need to assist with fact gathering. When it comes to generative AI, given the specialization and engineering involved in some programs, special consideration should be given to subject matter experts within the company that can assist with understanding how the technology operates in the specific environment at issue.
Emily Apte, counsel in King & Spalding’s Austin office, advises and defends clients in complex white-collar criminal and regulatory matters involving federal government, state government and internal investigations, as well as provides crisis management counseling. 
A partner in King & Spalding’s Austin office, Grant Nichols focuses on government investigations, independent investigations and complex white-collar criminal defense matters. 
Luke Roniger, a senior associate in the firm’s trial and global disputes group in Austin, focuses his practice on complex civil litigation and international arbitration. 
Nicholas “Nick” Maietta, an associate in King & Spalding’s data, privacy and security practice in Washington, D.C., focuses on artificial intelligence, privacy and security compliance. 

Tags: Artificial Intelligence (AI)Machine Learning
Previous Post

New OIG Guidance: Let Compliance Officers Stay in Their Lane

Next Post

AI & the Human Touch: Embracing a Symbiotic Future

King & Spalding

King & Spalding

King & Spalding is an international law firm headquartered in Atlanta, where the firm has been based since its founding in 1885. The firm currently boasts 1,200 lawyers in 23 offices around the world, including in North America, the Middle East and Europe.

Related Posts

news roundup new

Few Business Leaders Feel Fully Prepared for Challenges of 2025

by Staff and Wire Reports
June 20, 2025

Data center operators not using full slate of available sustainability tactics; companies continue to use AI without policies

robot nurturing a good idea

Innovation vs. Compliance: In the Age of AI, Why Not Both?

by Asha Palmer
June 17, 2025

As governments scramble to regulate AI, forward-thinking companies are writing their own compliance playbooks

human robot working as team pie chart

Smart Machines, Smarter Humans: Why Compliance Still Needs a Human Touch

by Roman Eloshvili
June 17, 2025

From the 2008 financial crisis to everyday judgment calls, the case for keeping humans in the compliance loop

surrealist businessmen on platforms doing tug of war

Regulation vs. Innovation: The Tug-of-War Defining Finance’s Future

by Alex Tsepaev
June 6, 2025

AI compliance creates a global patchwork where EU fines reach €35 million while the US encourages growth — leaving financial...

Next Post
human and robot finger touching

AI & the Human Touch: Embracing a Symbiotic Future

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights