Solove & Keats Citron on Standing and Privacy Harms: A Critique of TransUnion v. Ramirez

Daniel J. Solove (George Washington University Law School) and Danielle Keats Citron (University of Virginia School of Law) have posted “Standing and Privacy Harms: A Critique of TransUnion v. Ramirez”
(101 Boston University Law Review Online 62 (2021)). Here is the abstract:

Through the standing doctrine, the U.S. Supreme Court has taken a new step toward severely limiting the effective enforcement of privacy laws.  The recent Supreme Court decision, TransUnion v. Ramirez (U.S. June 25, 2021) revisits the issue of standing and privacy harms under the Fair Credit Reporting Act (FCRA) that began with Spokeo v. Robins, 132 S. Ct. 1441 (2012). In TransUnion, a group of plaintiffs sued TransUnion under FCRA for falsely labeling them as potential terrorists in their credit reports. The Court concluded that only some plaintiffs had standing – those whose credit reports were disseminated. Plaintiffs whose credit reports weren’t disseminated lacked a “concrete” injury and accordingly lacked standing – even though Congress explicitly granted them a private right of action to sue for violations like this and even though a jury had found that TransUnion was at fault.

In this essay, Professors Daniel J. Solove and Danielle Keats Citron engage in an extensive critique of the TransUnion case. They contend that existing standing doctrine incorrectly requires concrete harm. For most of U.S. history, standing required only an infringement on rights. Moreover, when assessing harm, the Court has a crabbed and inadequate understanding of privacy harms. Additionally, allowing courts to nullify private rights of action in federal privacy laws is a usurpation of legislative power that upends the compromises and balances that Congress establishes in laws.  Private rights of action are essential enforcement mechanisms.

Kamalnath & Varottil on A Disclosure-Based Approach to Regulating AI in Corporate Governance

Akshaya Kamalnath (ANU College of Law) and Umakanth Varottil (NUS Law; European Corporate Governance Institute) have posted “A Disclosure-Based Approach to Regulating AI in Corporate Governance” on SSRN. Here is the abstract:

The use of technology, including artificial intelligence (AI), in corporate governance has been expanding, as corporations have begun to use AI systems for various governance functions such as effecting board appointments, enabling board monitoring by processing large amounts of data and even helping with whistle blowing, all of which address the agency problems present in modern corporations. On the other hand, the use of AI in corporate governance also presents significant risks. These include privacy and security issues, the ‘black box problem’ or the lack of transparency with AI decision-making, and undue power conferred on those who control decision-making regarding the deployment of specific AI technologies.

In this paper, we explore the possibility of deploying a disclosure-based approach as a regulatory tool to address the risks emanating from the use of AI in corporate governance. Specifically, we examine whether existing securities laws mandate corporate boards to disclose whether they rely on AI in their decision-making process. Not only could such disclosure obligations ensure adequate transparency for the various corporate constituents, but they may also incentivize boards to pay sufficient regard to the limitations or risks of AI in corporate governance. At the same time, such a requirement will not constrain companies from experimenting with the potential uses of AI in corporate governance. Normatively, and given the likelihood of greater use of AI in corporate governance moving forward, we also explore the merits of devising a specific disclosure regime targeting the intersection between AI and corporate governance.

Tschider on Legal Opacity: Artificial Intelligence’s Sticky Wicket

Charlotte Tschider (Loyola University Chicago School of Law) has posted “Legal Opacity: Artificial Intelligence’s Sticky Wicket” (Iowa Law Review, Vol. 106, 2021) on SSRN. Here is the abstract:

Proponents of artificial intelligence (“AI”) transparency have carefully illustrated the many ways in which transparency may be beneficial to prevent safety and unfairness issues, to promote innovation, and to effectively provide recovery or support due process in lawsuits. However, impediments to transparency goals, described as opacity, or the “black-box” nature of AI, present significant issues for promoting these goals.

An undertheorized perspective on opacity is legal opacity, where competitive, and often discretionary legal choices, coupled with regulatory barriers create opacity. Although legal opacity does not specifically affect AI only, the combination of technical opacity in AI systems with legal opacity amounts to a nearly insurmountable barrier to transparency goals. Types of legal opacity, including trade secrecy status, contractual provisions that promote confidentiality and data ownership restrictions, and privacy law independently and cumulatively make the black box substantially opaquer.

The degree to which legal opacity should be limited or disincentivized depends on the specific sector and transparency goals of specific AI technologies, technologies which may dramatically affect people’s lives or may simply be introduced for convenience. This Response proposes a contextual approach to transparency: Legal opacity may be limited in situations where the individual or patient benefits, when data sharing and technology disclosure can be incentivized, or in a protected state when transparency and explanation are necessary.

Greenleaf on China’s Completed Personal Information Protection Law

Graham Greenleaf (University of New South Wales) has posted “China’s Completed Personal Information Protection Law: Rights Plus Cyber-security” ((2021) 172 Privacy Laws & Business International Report 20-23) on SSRN. Here is the abstract:

On 20 August 2021 the Standing Committee of China’s National People’s Congress (SC-NPC, not the NPC itself) enacted the Personal Information Protection Law (PIPL), the culmination of over a decade of incremental legislative reform. Businesses were required to adjust rapidly to the law’s starting date of 1 November 2021. Since the first draft of the PIPL was released by the SC-NPC in October 2020, it was revised in a succession of drafts. One purpose of this article is to detail these changes. The other purpose is to place the PIPL in the context of China’s near-complete cyber-security laws, of which it is part.

Of the 74 sections in the final Law, half have had non-trivial amendments since the first draft. Some of the amendments are significant, although none involve fundamental changes to the direction of the first draft. Significant amendments include: tightening controls over automated decision-making; right of data portability added; possibility of litigation by ‘privacy NGOs’; special obligations on providers of platform services; extra-territoriality is potentially extra-vague; local representatives required within PRC; and other forms of data localisation widened.

The argument is made that these export conditions are not ‘just Chinese adequacy’ but something considerably different, which seem to open the way for China to negotiate mutual data export agreements, multilateral or bilateral.

PIPL also plays a role in China’s emerging cyber-security structure. The Cybersecurity Law (CSL) of 2016, the Data Security Law (DSL) of 2021, and other more subordinate parts of China’s array of legislation, are other parts of this emerging structure.

Huang on How VR and Metaverses Connect with Chinese Law

Yujun Huang (University of Washington; Macau University of Science and Technology) has posted “Comparative Study: How Metaverse Connect with China Laws” on SSRN. Here is the abstract:

This paper is divided into three parts. The first part introduces the background, concept and development of the “metaverse”. The second part describes the possible disputes over rights and obligations in the metaverse scenario, including disputes over civil rights such as identity rights, personality rights, property rights, intellectual property rights and tort liability, and then explains and analyzes the Chinese laws that may apply to govern these disputes. In the third part, some dispute resolution proposals for resolving disputes that may exist in the metaverse world are presented.

Kazim et Al. on the UK’s National AI Strategy

Emre Kazim (University College London) et al. have posted “Innovation and Opportunity: Review of the UK’s National AI Strategy” on SSRN. Here is the abstract:

The publication of the UK’s National Artificial Intelligence (AI) Strategy represents a step-change in the national industrial, policy, regulatory, and geo-strategic agenda. Although there is a multiplicity of threads to explore, in terms of actionable steps, this text can be read primarily as a ‘signalling’ document. Indeed, we read the National AI Strategy as a vision for innovation (research, SMEs) and opportunity (industry, economy), underpinned by a trust framework that has innovation and opportunity at the forefront of any standard and regulatory framework. In this white paper, we provide an overview of the structure of the document and offer an emphasised commentary on various standouts. Following this, we offer our initial thoughts and feedback on strategic points of contention in the strategy. Our main takeaways are:

Innovation First: a clear signal is that innovation is at the forefront of UK’s data priorities.
Alternative Ecosystem of Trust: the opportunity is for the UK’s regulatory-market norms to become a preferred ecosystem for innovation and trust but this is very much dependent upon the regulatory system and delivery frameworks required.

Defence, Security and Risk: security and risk are discussed in terms of utilisation of AI (capabilities and in the modernisation and operations of the MoD), and governance (understanding of long term risk and defence against the malign use of AI).

Revision of Data Protection: the signal is that the UK is indeed seeking to position itself as less stringent regarding data protection and the documentation of processes and accountabilities to individual citizens.

EU Disalignment – Atlanticism?: a focus on innovation and economic advancement is continuously touted raising the questions regarding a step back in terms of data protection rights.
We conclude with further notes on data flow continuity, the feasibility of a sector approach to regulation, legal liability, and the lack of a method of engagement for stakeholders. Whilst the strategy sends important signals for fostering and growing innovation, achieving ethical innovation is a harder challenge and will require a carefully evolved framework built with appropriate expertise.

Werner on Algorithmic and Human Collusion

Tobias Werner (Heinrich Heine University Dusseldorf) has posted “Algorithmic and Human Collusion” on SSRN. Here is the abstract:

As self-learning pricing algorithms become popular, there are growing concerns among academics and regulators that algorithms could learn to collude tacitly on non-competitive prices and thereby harm competition. I study popular reinforcement learning algorithms and show that they develop collusive behavior in a simulated market environment. To derive a counterfactual that resembles traditional tacit collusion, I conduct market experiments with human participants in the same environment. Across different treatments, I vary the market size and the number of firms that use a self-learned pricing algorithm. I provide evidence that oligopoly markets can become more collusive if algorithms make pricing decisions instead of humans. In two-firm markets, market prices are weakly increasing in the number of algorithms in the market. In three-firm markets, algorithms weaken competition if most firms use an algorithm and human sellers are inexperienced.

Guerra, Parisi & Pi on Liability for Robots II: An Economic Analysis

Alice Guerra (University of Bologna – Department of Economics), Francesco Parisi (University of Minnesota – Law School), and Daniel Pi (University of Maine – School of Law) have posted “Liability for Robots II: An Economic Analysis” (Journal of Institutional Economics 2021) on SSRN. Here is the abstract:

This is the second of two companion papers that discuss accidents caused by robots. In the first paper (Guerra et al., 2021), we presented the novel problems posed by robot accidents, and assessed the related legal approaches and institutional opportunities. In this paper, we build on the previous analysis to consider a novel liability regime, which we refer to as “manufacturer residual liability” rule. This makes operators and victims liable for accidents due to their negligence—hence, incentivizing them to act diligently; and makes manufacturers residually liable for non-negligent accidents—hence, incentivizing them to make optimal investments in R&D for robots’ safety. In turn, this rule will bring down the price of safer robots, driving unsafe technology out of the market. Thanks to the percolation effect of residual liability, operators will also be incentivized to adopt optimal activity levels in robots’ usage.

Recommended.

Weissinger on AI, Complexity, and Regulation

Laurin Weissinger (Tufts University – The Fletcher School of Law and Diplomacy) has posted “AI, Complexity, and Regulation” (OUP Handbook on AI Governance, Forthcoming) on SSRN. Here is the abstract:

Regulating and governing AI will remain a challenge due to the inherent intricacy of how AI is deployed and used in practice. Regulation effectiveness and efficiency is inversely proportional to system complexity and the clarity of objectives: the more complicated an area is and the harder objectives are to operationalize, the more difficult it is to regulate and govern. Safety regulations, while often concerned with complex systems like airplanes, benefit from measurable, clear objectives and uniform subsystems. AI has emergent properties, and is not just “a technology” but interwoven with organizations, people, and the wider social context. Furthermore, objectives like “fairness” are not only difficult to grasp and classify but they will change their meaning case-by-case.

The inherent complexity of AI systems will continue to complicate regulation and governance but with appropriate investment, monetary and otherwise, complexity can be tackled successfully. However, due to the considerable power imbalance between users of AI in comparison to those AI systems are used on, successful regulation might be difficult to create and enforce. As such, AI regulation is more of a political and socio-economic problem than a technical one.

Richards on Why Privacy Matters

Neil M. Richards (Washington University School of Law) has posted “Why Privacy Matters: An Introduction” (Oxford Press 2021) on SSRN. Here is the abstract:

Everywhere we look, companies and governments are spying on us–seeking information about us and everyone we know. Ad networks monitor our web-surfing to send us “more relevant” ads. The NSA screens our communications for signs of radicalism. Schools track students’ emails to stop school shootings. Cameras guard every street corner and traffic light, and drones fly in our skies. Databases of human information are assembled for purposes of “training” artificial intelligence programs designed to predict everything from traffic patterns to the location of undocumented migrants. We’re even tracking ourselves, using personal electronics like Apple watches, Fitbits, and other gadgets that have made the “quantified self” a realistic possibility. As Facebook’s Mark Zuckerberg once put it, “the Age of Privacy is over.” But Zuckerberg and others who say “privacy is dead” are wrong. In Why Privacy Matters, Neil Richards explains that privacy isn’t dead, but rather up for grabs.

Richards shows how the fight for privacy is a fight for power that will determine what our future will look like, and whether it will remain fair and free. If we want to build a digital society that is consistent with our hard-won commitments to political freedom, individuality, and human flourishing, then we must make a meaningful commitment to privacy. Privacy matters because good privacy rules can promote the essential human values of human identity, political freedom, and consumer protection. If we want to preserve our commitments to these precious yet fragile values, we will need privacy rules. Richards explains why privacy remains so important and offers strategies that can help us protect it from the forces that are working to undermine it. Pithy and forceful, this is essential reading for anyone interested in a topic that sits at the center of so many current problems.