Reference notes · Domain II · Competency II.B

Understand how other existing laws apply to AI

Beyond privacy: how intellectual-property, nondiscrimination, consumer-protection and product-liability law already reach AI — from training-data copyright and the human-authorship rule, through Title VII / ECOA / FHA disparate-impact liability, to FTC Act §5 UDAP and design/manufacturing/warning defects under product-liability regimes.

Exam weight: 4–6 questions

Performance indicators

Key terms

Human-authorship requirement
U.S. copyright protects only works of human authorship; purely AI-generated output with no human creative control is not copyrightable (U.S. Copyright Office guidance).
Training-data infringement
The unresolved question of whether copying copyrighted works to train an AI model is infringement or a permitted use (e.g., fair use in the U.S.). A central live IP dispute.
Disparate treatment
Intentional discrimination — treating someone worse because of a protected characteristic. One of two theories of discrimination liability.
Disparate impact
A facially neutral practice (including an algorithm) that disproportionately harms a protected group, without sufficient justification. Does not require intent — central to AI bias liability.
Title VII
U.S. Civil Rights Act provision barring employment discrimination based on race, color, religion, sex or national origin — reaches AI hiring and HR tools.
ECOA
Equal Credit Opportunity Act — prohibits discrimination in any aspect of a credit transaction; requires adverse-action notices, which strain opaque AI models.
FHA
Fair Housing Act — bars discrimination in housing and related services, including by algorithmic tenant-screening and targeted-advertising tools.
FTC Act §5 (UDAP)
Bars "unfair or deceptive acts or practices" in commerce. The FTC's main tool against deceptive AI claims and unfair AI uses.
Algorithmic disgorgement
An FTC remedy requiring a company to delete models and algorithms built on illegally obtained data — destroying the ill-gotten asset, not just fining it.
Product liability
Legal responsibility of makers/sellers for harm caused by defective products, via design defects, manufacturing defects, or failure-to-warn (inadequate instructions/warnings).
EU Product Liability Directive (revised)
Updated EU regime (2024) extending strict product-liability rules to software and AI systems, easing the burden of proof for claimants harmed by AI.

At a glance

This competency covers the non-privacy existing laws that already apply to AI. There is no AI carve-out here either: if an output infringes copyright, discriminates, deceives a consumer, or comes from a defective product, the ordinary law applies. Four bodies of law:

  1. Intellectual property — training-data/copyright and the human-authorship rule (II.B.1)
  2. Nondiscrimination — Title VII, ECOA, FHA; disparate impact across employment, credit, lending, housing, insurance (II.B.2)
  3. Consumer protection — FTC Act §5 UDAP, deceptive AI claims, algorithmic disgorgement (II.B.3)
  4. Product liability — design, manufacturing and warning defects; the revised EU Product Liability Directive (II.B.4)

II.B.1 — Intellectual property

Two distinct IP questions — do not merge them.

(a) Training inputs. Does copying copyrighted text, images or code to train a model infringe? In the U.S. this turns on fair use (an unsettled, fact-specific defence, heavily litigated). Other regimes use narrower exceptions — e.g., the EU’s text-and-data-mining (TDM) exception, which rights-holders can opt out of (reserve their rights). The EU AI Act requires GPAI providers to respect such opt-outs and to publish a summary of training content.

(b) AI outputs. Can AI-generated content be owned/protected? The U.S. Copyright Office position: copyright protects only human authorship. Output generated purely by a prompt, with no human creative control over the expressive elements, is not copyrightable; works with sufficient human authorship (selection, arrangement, modification) may be protected in those human-contributed parts.

II.B.2 — Nondiscrimination

Existing civil-rights statutes reach algorithmic decisions in the sectors the BOK names:

DomainStatuteWhat it reaches
EmploymentTitle VII (race, color, religion, sex, national origin); ADA, ADEAAI résumé screeners, video-interview scorers, productivity tools
Credit / lendingECOAAutomated underwriting; requires adverse-action reasons even for model-driven denials
HousingFHATenant-screening algorithms; targeted housing ads
InsuranceState unfair-trade / insurance codesAlgorithmic underwriting and pricing

Two theories of liability:

Agency posture. The EEOC has confirmed Title VII applies to AI hiring tools; the CFPB has confirmed ECOA’s adverse-action-notice duty applies even when an opaque model makes the decision (lenders cannot hide behind “the algorithm did it”). City/state rules add specifics — e.g., NYC Local Law 144 requires an independent bias audit and candidate notice for automated employment decision tools.

II.B.3 — Consumer protection

FTC Act §5 bars unfair or deceptive acts or practices (UDAP) in commerce — the FTC’s primary AI tool in the U.S. Two prongs:

Algorithmic disgorgement (model deletion). A signature FTC remedy: where a company built a model using illegally or deceptively obtained data, the FTC can require it to delete the data and the models/algorithms derived from it. This destroys the tainted asset itself — a far stronger deterrent than a fine alone (seen in matters such as Everalbum and Rite Aid).

II.B.4 — Product liability

When an AI-enabled product causes physical or economic harm, product-liability doctrine applies. The three classic defect theories:

EU Product Liability Directive (revised 2024). The modernised PLD explicitly brings software and AI systems within strict product liability, treats software updates and self-learning as relevant, and eases the claimant’s burden of proof (disclosure duties and presumptions of defectiveness/causation where AI complexity makes proof excessively difficult). Defectiveness can arise after sale through updates or the system’s own learning. A separate AI Liability Directive proposal addressed fault-based claims but was later withdrawn — so the revised PLD is the operative EU instrument the exam expects.

US sectoral privacy laws — which sector holds the data

The US has no comprehensive federal privacy law, so the first question in any US fact pattern is which sector the data sits in. Each of these applies to AI without ever mentioning it, and an option set will typically offer all four against a scenario that fits exactly one.

LawReachesThe limit that gets tested
HIPAA (1996)Protected health information held by covered entities — health plans, clearinghouses and most providers — and their business associatesIt is an entity-scoped law, not a health-data law. A vendor training a model on a hospital’s patient records is a business associate and needs a BAA (and is directly liable post-HITECH). The same health data in a consumer wellness app is outside HIPAA entirely — the FTC Act, the Health Breach Notification Rule and state law do the work there.
GLBANonpublic personal information at financial institutionsThe Privacy Rule and Safeguards Rule sit alongside ECOA and FCRA in any lending or banking scenario.
FERPAEducation records at federally funded institutionsReaches edtech through the school official exception — a proctoring or grading vendor is bound through the institution.
COPPAPersonal information from children under 13 onlineUS age is 13. GDPR Art. 8 defaults to 16, with member-state discretion down to 13 — so a single global consent age is wrong twice over.

Illinois BIPA deserves separate mention because it behaves unlike the rest: informed written consent before collecting biometric identifiers, a published retention schedule, no sale — and a private right of action with statutory damages. Individuals sue directly, which is why one state’s law produces the largest US biometric liabilities. Face or voice data in a US scenario should always raise it.

Sector-specific regulators (know they exist)

Beyond the horizontal regimes above, several sector regulators already govern AI within their remit — the exam expects you to recognise which regulator owns which context:

Regulator / instrumentSectorAI relevance
Federal Reserve SR 11-7 (2011)Banking (US)The original model risk management guidance: model inventory, independent validation, “effective challenge”, ongoing monitoring — the template AI governance borrowed from
FDAMedical devices (US)AI/ML-based software as a medical device (SaMD): pre-market review plus predetermined change control plans so learning models can update within approved bounds
OSHAWorkplace safety (US)Guidance on industrial robot and robotic-system safety
EEOC / FTC / CFPB / DOJEmployment, consumer, creditJoint 2023 statement: existing authorities fully apply to AI — “there is no AI exemption”
EU Digital Services Act (DSA)Online platforms (EU)Adjacent to the AI Act: recommender-system transparency, ad-targeting limits, and systemic-risk assessments for very large platforms — algorithmic accountability for platforms rather than AI products

US federal AI instruments — what they do and do NOT do

A recurring item shape gives you a list of US instruments and asks which is least likely to help with a specific problem. The trap is that the AI-sounding one is usually the wrong answer, because it is about research and coordination rather than about regulating anyone’s conduct.

InstrumentWhat it actually does
National Artificial Intelligence Initiative Act (NAIIA), 2020Establishes a national initiative to advance AI research and development — coordination, funding, a National AI Initiative Office. It creates no obligations on private deployers and gives no guidance on discrimination, hiring or consumer protection.
Fair Credit Reporting Act (FCRA)Governs consumer reporting agencies and background screening — reaches AI-driven screening and scoring products.
Americans with Disabilities Act (ADA)Prohibits disability discrimination, including where an AI screening tool disadvantages disabled applicants.
EEOC enforcement actionsApply Title VII, the ADA and the ADEA to algorithmic hiring tools directly.

A note on executive orders. US AI policy has also moved through presidential executive orders — EO 14110 on safe, secure and trustworthy AI (2023) was rescinded in January 2025 and replaced by a deregulatory order. Treat the EO route as volatile: it directs federal agencies and can be reversed by the next administration, so it is a poor thing to memorise. What persists across administrations is the agencies’ existing statutory authority — Title VII, ECOA, the FHA, FTC Act §5 — which is why the 2023 joint statement that there is “no AI exemption” has outlasted the orders.

How this shows up later

Sources

Practise this competency

24 exam-style questions and 9 flashcards cover II.B, each question with every option explained. Sign in with Google to take them and keep your progress across devices.

Practise II.B free

Rest of Domain II

All 13 competency notes · Blueprint to source map · How to pass the AIGP

Study the whole syllabus free

Reference notes for all 13 competencies, 305 exam-style questions, flashcards and full-length timed mocks. Sign in with Google to save your progress across devices — which stores your email address and display name. See what is kept, and how to delete it.

Start studying free →