Conference Agenda
Overview and details of the sessions of this conference. Please select a date or location to show only sessions at that day or location. Please select a single session for detailed view (with abstracts and downloads if available).
|
Daily Overview |
| Session | ||
AI and the Law-3: The High-Risk of 'Small AI Harms': A Policy Analysis of International Approaches to AI Governance
| ||
| Presentations | ||
The High-Risk of ‘Small AI Harms’: A Policy Analysis of International Approaches to AI Governance York University, Canada In May 2024, Colorado’s Artificial Intelligence Act was signed into law (State of Colorado, 2024). The Act “requires a developer of a high-risk artificial intelligence system […] to protect consumers from […] algorithmic discrimination”. (Ibid) The Act defines a high-risk system as “any (AI) system that, when deployed, makes […] a consequential decision” (Ibid, section 17.9(a)). Similarly, in September 2025, California signed the Transparency in Frontier Artificial Intelligence Act into law (State of California, 2025). The act emphasizes “catastrophic risk”, whereby an AI model might “[…] materially contribute to the death of, or serious injury to, more than 50 people or more than one billion dollars […] in damage […]” (Section 2.25.1.22757.11(c)). AI governance efforts internationally include similar approaches to addressing potential AI harms. For example, the EU AI Act has a risk-based framework that includes “prohibited” and “high-risk” AI areas of concern, along with those labeled “limited” and “minimal” risk (EU, 2021). In Canada, the proposed Artificial Intelligence and Data Act focuses on “high-impact” applications, attempting to “mitigate risks of harm and biased output related to high-impact (AI) systems” (Government of Canada, 2023). As AI governance approaches consistently attempt to address so-called high-impact concerns, policy scholars question whether so-called smaller or low(er)-impact harms are overlooked (Citron and Solove, 2022). The challenge of creating an exhaustive definition of potential protections online is a longstanding challenge. For example, when Schwartz and Solove (2011) wrote about the policy challenge of defining forms of personally identifiable information (as opposed to non/less-identifiable data), they described difficulties ensuring predetermined lists are complete, especially as new technologies and demands rapidly change. A similar challenge may exist when attempting to generate an exhaustive list of potential AI harms. This paper begins with a comparative policy analysis of the risk-based frameworks developed in the aforementioned policy contexts to address AI harms. The analysis will follow with policy recommendations for expanding these frameworks to address so-called smaller/lower-impact concerns that may also contribute to AI harms. The goal of these recommendations will not necessarily be to finalize an exhaustive list, but rather to emphasize the extent to which current operationalizations of AI harm may overlook concerns associated with areas less often discussed. The research question is therefore: to what extent are international approaches to AI governance considering the potential risks of small harms? This project is guided by disciplinary approaches, including information and communication studies, political science and policy studies. The preliminary policy analysis reveals that the Colorado AI Act includes eight high-risk classifications, whereas the California law does not include similar classifications. The EU AI Act includes eight classifications as high-risk, whereas the Canadian proposal includes seven. Preliminary policy recommendations for addressing small harms emphasize the importance of acknowledging two conceptualizations of a cumulative effect of so-called smaller harms (see Citron and Solove, 2022). The first emphasizes cumulative effects resulting from smaller instances of AI-related activities adding up to larger potential harms for the individual. A second conceptualization recognizes how smaller concerns on an individual level may raise larger concerns when added up across groups of people (Ibid). For example, this paper will address (among other challenges) generative AI systems that retain and reuse user inputs (Vekaria et al., 2025), dynamic pricing models that differentiate consumers (Chenavaz & Dimitrov, 2025), and disinformation concerns that may threaten democracy and societal stability (PAI, 2023). Indeed, it is arguable that the current organization of the aforementioned policy reveals a broader AI governance pattern. Attention may be focused on systems whose impacts are more easily identifiable due to common institutional consideration, while new/unique AI interactions within everyday contexts remains less of a focus. Furthermore, even with newly emerged policy mechanisms, including conformity assessment and enforcement protocols, current approaches are still oriented toward self-regulation (Kaminski, 2023), which leads to the question of whether the current approach meaningfully strengthens accountability. As policymakers attempt to balance innovation incentives with protections, and as companies balance prioritizing growth with compliance, current AI governance mechanisms may struggle to fully anticipate potential harms, leaving many possibilities unaddressed. Overall, this paper highlights how current high-risk based frameworks are lacking as opposed to robust. This paper aims to offer insights into the limitations of current AI governance and argues for more inclusive approaches that recognize the broader consequences of widely deployed AI systems, providing guidance for policymakers toward balancing innovation and public protection.
| ||
