Navigating AI Deployment Risks Beyond Compliance: A Comprehensive Approach

The rapidly evolving world of AI technologies is becoming a crucial part of many companies’ modus operandi, leading to improved operational efficiencies and enhanced customer experiences. However, as companies continue to embrace AI, it is important to not only view compliance as crucial but also adopt a comprehensive risk management strategy.

AI deployment is under serious scrutiny from government enforcers, with recent cases and agency guidance highlighting the destructive outcomes of not implementing suitable safeguards.

The Federal Trade Commission (FTC) recently filed a complaint against Rite Aid regarding the company’s use of AI-based facial-recognition surveillance technology. The basis of the complaint was an alleged violation of Section 5 of the FTC Act. The FTC claimed that Rite Aid’s AI technology unfairly identified innocent customers as suspected shoplifters, leading to increased surveillance and false allegations of criminal activity, among other harms.

The misidentifications were reported to disproportionately affect women and people of color. The FTC criticized Rite Aid’s failure to conduct adequate due diligence before purchasing and deploying the technology and for not providing appropriate training and oversight for employees using the system. Another point of contention was the lack of regular surveillance of the system’s accuracy.

Additional regulations that apply to AI deployments can come regardless of the business sector. Laws covering bias in AI-based employment tools and those monitoring potential new requirements for AI usage are some to note. The Securities and Exchange Commission is also keen on discouraging misleading claims about deployments of AI technology by public companies.

While the risk of government enforcement when AI deployment goes wrong is significant, there are other harms businesses should sidestep, such as the suspension of operations, reputational damage, and potential lawsuits from various parties.

The jeopardy associated with AI deployment exceeds that of government enforceability, underlining an essential need for businesses to manage these risks comprehensively. Resources such as the National Institute of Standards and Technology’s AI Risk Management Framework or possibly ISO standards 42001 and 23894 have been suggested as tools that can offer support in setting up this all-encompassing program.

In conclusion, the successful integration of AI technologies into business operations will require prudent risk management, beyond mere compliance, to avoid potential legal and reputational repercussions.