Around The World in 80 Tokens

Whether you’re a multinational conglomerate, or a regular old mono-national mom-and-pop slop shop in a sovereign state that heavily regulates information technology and advertising content, you’ve probably had your hands full figuring out how to use generative AI within the letter of the laws and guidelines of all the territories relevant to you.

If you’re intergalactic mom-and-no-pop-shop Mom’s Friendly Robot Company / Momcorp, you’ve got issues beyond measure and should definitely read this whole article.

Our article from last week outlines a basic framework for considering what liability the usage of generative AI in the creation of public-facing materials exposes you to-it mostly hinges on the continued application of previously existing laws versus new, AI specific legislatures.

Notice we said it “mostly” hinges on non-AI specific legislation. Just because that’s where the bulk of the actual risk comes from, doesn’t mean that there aren’t laws in various jurisdictions meant specifically to regulate AI.

There are, and as time goes on they may eventually outweigh old laws to become the heavy end of the scales of justice when it comes to generative AI content liability.

To be clear: this is not legal advice and we are not attorneys - we are just analysts giving an overview we hope will be helpful.

At the top of our usual news and other media run down, you can find an interview on generative AI content liability someone who IS an attorney, on the Diligence Report podcast.

Plus, other things savvy internet investors and operators should know.

Important Happenings & New Notions

A podcast with attorney Rob Freund

We have a GREAT podcast on modern regulation and the regulatory environment with Rob Freund, who unlike us as you know from our disclaimer, is in fact, an attorney, even though this podcast is not legal advice.

Payday Lending’s New Face / Disgrace

Payday lending style apps have proliferated in the past decade, alongside increases in potentially related and compounding app-driven behavior like excessive sports gambling. It’s a dark corner of the digital world to keep an eye on when gauging the public’s economic attitudes and outlooks.

AI “Consciousness” May Be Unimportant Compared To This

LLM “sovereignty” may seem like an only slightly less lofty description of some Python and C++ code, but it might be a much more feasible state for an agent or agent swarm to reach in the next few years, and that is also…a lot to think about.

The FTC + 22 States Sue Amazon

An alleged seven year long scheme to inflate the prices advertisers paid on Amazon’s all-important golden goose, their search advertising, is the subject of the legal action.

Sloppin’ In The USA!

In 2025, over 1,000 state laws pertaining to AI were introduced, an increase of almost 40% from 2024, so the legislative patchwork is starting to weave itself across the 50 states of the union.

It’s helpful to consider a few key bastions and frontiers of this legislation, as they are both the most important legislative zones to consider now, and will likely lead the other states on legislature as their initial laws become blueprints for other state legislatures to emulate.

The first area of concern will surprise absolutely nobody, unless they are somehow unaware what the fist C in CCPA stands for.

Golden Gate Gavel

California has arguably done the most internet regulating of any state, at least in terms of user privacy if not across all dimensions, because it’s where so many modern computing and internet technology companies are headquartered.

This density of regulatable developers in their own backyard is once again a driving factor in California’s regulatory focus; unless you’re operating a frontier lab / model developer, a major consumer content platform, or or dealing with AI systems that fall under high-risk or special transparency obligations, their AI specific legislation isn’t directly relevant to you.

It is an excuse to continue engaging what seems to be some of y’all’s favorite hobby, which is picking a favorite frontier lab and stanning them like a K-Pop band.

The California legislation introduces consequences that may make this hobby kind of exciting again, given that your fandom could be based on bets as to which models might be mauled by the Legal Bear Republic.

The Transparency in Frontier AI Act aimed penalties up to $1 million per violation at any labs that don’t have sufficient risk reporting framework or fail to sufficiently protect whistleblowers; this was among the earliest US attempts at direct, law-based regulation of AI systems, though New York's RAISE Act now stands as the most direct AI model regulation on the books.

The Generative Artificial Intelligence: Training Data Transparency bill is the state’s lever for keeping frontier labs honest about what they use for training data and to compensate data holders fairly for making data available in compliance with requests. Whether or not that is going well is a matter on which there are many diverging opinions.

The California AI Transparency Act legislates proper disclosure of generative AI content and even the provision of AI detection tools at no cost to the consumer, from the AI service provider.

If you’re actually building models and providing direct AI services, than California is where you’re going to lose your gold pan and get sent back east with nothing more than a bunch of old data miner’s prospecting tales if you’re not careful and don’t engage the right legal professionals for help.

Editor’s note: Gus Chiggins is not an attorney. Classic SNL sketches are not legal advice.

The Unwild West

Apparently someone messed with Texas, because we have the Texas Responsible AI Governance Act now. I did not add “or TRAIGA” to that sentence because it’s a stupid acronym, although some people seem determined to use it

It covers a range of AI topics, including but not necessarily limited to: disclosure to users that they are interacting with AI, the manipulation of human behavior, the violation of constitutional rights, the capture and/or use of biometric data to identify users, the generation of of “certain ” sexually explicit content and CSAM, and the creation of AI-enabled social scoring practices.

I think the last two items are particularly interesting, and at least one of them is very Texan.

If your business is one that relies on answers to that classic question “@grok is this true,” that might eventually be a dependency.

The prohibition of a social credit score alludes to a bogeyman among certain American political factions, largely based on misconceptions about a system in China.

What’s interesting the that the Chinese “social credit score” as it is imagined in the worst American fever dreams is not dissimilar to FICO and other credit scores; as constructed in reality, it is something quite different: a fragmented, decentralized assemblage of systems that covers political behavior, moral conduct, and regulatory compliance far beyond anything a financial creditworthiness score tracks.

We will be curious to see if they try to fight the system of their nightmares, or the real one that is half a world away, and if this means LLM and generative AI based fintech dealing with credit scores are ever accused of running afoul of this law.

It’s worth at least briefly considering for investors in and operators of credit score adjacent tech and companies.

Rocky MountAIn High

Colorado has an artificial intelligence law that is focused on managing risks from high-risk AI systems, including bias and potential discriminatory outcomes, via the defined frameworks of Consequential Decisions by Automated Decision-Making Technology (ADMT), which can also apply to things that are not considered AI.

Essentially, developers of models and providers of AI are required to disclose risks of improper Consequential Decisions being made by their ADMT, and companies deploying ADMT are responsible for taking that advisory and doing their own necessary diligence to ensure that harm does not occur.

If you’re invested in or operating a company using AI models and services in Colorado, ensure you’re not misusing these ADMTs in anything that could be considered a Consequential Decision, or you’ll have to hope your provider failed in its duty to disclose model risks to diffuse your liability.

Utah actually pioneered something besides the Dirty Soda: approaching AI regulation explicitly as a consumer protection matter with its Artificial Intelligence Policy Act.

For non-regulated businesses, this just means that it must be made explicitly clear that a consumer is interacting with AI, but only if the consumer asks.

For state licensed and/or regulated businesses such as doctors, lawyers, and financial professionals (of which we at Daypart AI are none of) must proactively disclose that a consumer is interacting with AI immediately at the beginning of any interaction or transaction.

If you operate legal or medical enablement of information tech, this is very important to know if you have customers in Utah!

Illi-noise Complaint

Real Interstate Pl-AI-yers know not to sleep on how much trouble you can get in while generating with AI in the Land of Lincoln.

The Biometric Information Privacy Act was not explicitly enacted to apply to AI, but has been interpreted to apply to AI facial recognition tools, as evidenced by a number of class action and other court cases against technology platforms like Facebook and tech operators such as Six Flags; the results of these court cases have not been overwhelmingly in favor of one side, however.

Amendments to HB 3773 have created protections against undisclosed AI usage in hiring, and affirms previously established penalties for discrimination, including when done via algorithms or AI, not dissimilar to Colorado’s laws.

Statute of Liberty

We will keep this brief because we covered it in last week’s article, but New York state has a synthetic performer disclosure law.

Reporting, enforcement, and the whole legislative environment around this is not at all yet settled.

The aforementioned RAISE Act, which like California’s legislature is aimed at frontier labs, does not actually take effect until 2027.

You’re The Only Ten AI See

Tennessee enacted, get ready for it: the ELVIS (Ensuring Likeness, Voice, and Image Security) Act and ended up establishing an early legal framework in the US for personal property rights pertaining to likeness, image, and voice.

Developers or users deploying AI systems to create, publish, and/or distribute an unauthorized AI simulation of an individual's voice or likeness face immediate civil liability, allowing for lawsuits from the individual or their estate.

In certain cases, it can also be prosecuted as a misdemeanor.

~~International Waters Begin~~

~~International Waters End~~

Lol Remember Brexit

We’re actually going to cover the UK before the part you’ve all been waiting for (Europe) because it’s really just one big footnote that can boiled down to: they said goodbye to all that, including unified AI regulation.

The UK has not enact any comprehensive, standalone AI specific regulation, nor create any new body specifically to regulate AI, and is relying on all existing laws, regulatory bodies, and frameworks to just apply themselves appropriately.

Do not Google United Kingdom PPP or “why isn’t my nan planning to retire in Spain anymore.”

Euro Trippin’

Here it is-the main event. The Giants of GDPR. The Pioneers of Poison Not Being Legal To Put In Food. Where FIFA sleeps.

The two key pieces are the EU AI Act, and the Revised Product Liability Directive via AI being defined as a “product” under this framework; depending on what purpose and party we’re looking at here, one of these two will be the relevant course to litigation and remedy.

Feature

The EU AI Act

Revised Product Liability Directive (PLD)

Primary Purpose

Preventative safety and fundamental rights protection.

Compensatory justice for harmed individuals.

Who Brings the Case?

State regulators and surveillance watchdogs.

Consumers, injured parties, or consumer protection groups in class action suits.

What is the Penalty?

Regulatory fines (up to €35M or 7% of global revenue) paid to the state.

Financial damages paid directly to the harmed consumer.

Type of Harm Covered

Societal risks, systemic risks, and fundamental rights violations.

Personal injury, psychological harm, property damage, and loss/corruption of valuable data.

If the damage caused can be established as merely likely to be linked to the AI product, and the system and usage in question are deemed to be sufficiently technically complex that outside parties may not understand them well, it can even invert the burden of proof so that the AI maker must prove harm was NOT done.

As you can see, you have a lot of exposure to consumer law suits under the PLD, and you may feel relieved the AI Act itself only exposes you to regulatory penalties paid to state actors, or surprised that what may seem to be the secondary law could actually be the real danger.

This is where you could be wrong; because the PLD allows that a product can be judged defective, and subject to the PLD, if it violates EU safety standards and turns the AI Act into a two-stage trap.

Once your product, or usage of a product, violates a safety or cybersecurity stipulation of the EU AI Act, it could be judged defective under the PLD, and subject you to the two prongs of state regulatory penalties and consumer damages.

Please consult with legal experts who know this jurisdiction well as soon as possible if you are building or using AI tools in the Eurozone!

The Great FAIrewall

While we’re on a real “you’re going to get in trouble” hot streak, we may as well cover the generative AI specific regulations in the People’s Republic of China.

Much of this just mirrors long running tenants of their government’s regulation, of technology and otherwise.

Everything must be aligned with the CCPs most up-to-date version of of “socialism” and not touch on any specific political topics the party is currently sensitive to.

Users cannot be anonymous and must, in fact, be easy to identify and trace.

International data sharing is highly limited and controlled.

As with algorithms before them, AI models must be fully submitted to the government for security and impact validation, and the government can order specific, direct changes to the model.

If you operate any of this technology in China, you certainly already knew this. If you didn’t know this, well, this is probably why your company doesn’t and maybe never will operate or build this technology in China, and if they do, there will most likely be a separate China-specific version of the product.

Brazil

Their economic trajectory hasn’t been what many thought it would be 20 years ago, and so here they are as a final footnote-but Brazil does have its own AI law that specifies strict liability for what it judges to be high-risk AI systems, and regular fault based liability for what it judges to be lower risk AI systems.

Wow, What A Tour, Tip Your Guide!

It’s been a pleasure sailing our AI ship around the world together, but remember: even if you found this very helpful, consult or retain legal professionals with real expertise in this if at any point you believe you are currently or will soon be exposed to liability and penalty for generative AI usage, either under existing regulatory frameworks we discussed last week, or AI specific laws discussed this week.

And as always, another thing this has NOT been is financial advice, NOR are any of us certified financial professionals.