Conference Agenda
Overview and details of the sessions of this conference. Please select a date or location to show only sessions at that day or location. Please select a single session for detailed view (with abstracts and downloads if available).
|
Daily Overview |
| Session | ||
AI and the Law-1: Polycentric Governance Gaps in U.S. AI and Privacy Law
| ||
| Presentations | ||
Polycentric Governance Gaps in U.S. AI and Privacy Law 1: University of Illinois at Urbana Champaign, United States of America; 2: Rutgers University, United States of America As generative AI (GenAI) rapidly reshapes how content is produced, analyzed, and distributed, it simultaneously transforms the U.S. legal, regulatory, and political governance landscape, particularly in data privacy and governance. Recent U.S. Executive Orders, including 14179 (January 23, 2025) and the December 11, 2025 follow-up, have reshaped federal priorities and procurement requirements, amplifying uncertainty as developers and policymakers navigate the complex interplay of federal government statements, state laws, and constitutional protections. State-level initiatives have further added complexity and inequity between the citizens (Roberts, 2014; Solove, 2025). While GenAI’s technical vulnerabilities are well-studied, less is known about compliance, particularly which state laws address these risks and regulate developers. Thus, this paper examines (RQ1) areas of emerging state consensus on AI privacy; (RQ2) consequences of polycentric federal and state compliance; and (RQ3) governance gaps in AI and privacy across the regulatory landscape.
In this study, we employ a qualitative legal and policy analysis to examine emerging state-level regulatory approaches to AI and privacy, building on telecommunications policy literature that comparatively considers the application of existing laws to emerging technologies (e.g., Chen & Wang, 2023). We systematically collected enacted state legislation (N=200, 28 privacy and 172 AI-related bills) between October and December 2025 and conducted a qualitative thematic analysis (Braun & Clarke, 2006) to identify patterns of convergence, divergence, and governance gaps across the evolving regulatory landscape. Two authors, with backgrounds in law and information science, jointly analyzed 10% of the dataset to develop and refine the codebook. After the final overarching themes and subthemes are determined in the codebook, authors independently coded all state-level laws following the four-eyes principle (Bavota & Russo, 2015) to ensure inter-coder reliability. Coding decisions were periodically cross-audited, resulting in agreement levels exceeding the 85% threshold commonly accepted in comparative policy research (Miles & Huberman, 1994). Our analysis identifies four major gaps in state-level AI and privacy regulation: (1) few states address inferential analytics; (2) remedies for algorithmic bias are limited; (3) emerging risks, including deepfakes, synthetic media, and voice cloning, often fall outside existing frameworks; and (4) enforcement mechanisms vary widely, from robust oversight by dedicated regulators to reliance on private litigation. These gaps create a fragmented compliance environment, leaving developers and regulators uncertain about baseline obligations (Roberts, 2014; Solove, 2025). Gaps in AI governance disproportionately affect vulnerable communities, including youth, minors, and other at-risk populations. The absence of clear obligations for developers and organizations exacerbates inequities and raises ethical and legal concerns about autonomy, consent, and accountability. Federal efforts to preempt state-level AI governance may constrain innovation and limit experimental privacy protections, highlighting tensions in U.S. federalism (Rubinstein, 2018; Medzini & Epstein, 2024). Judicial precedents (FTC v. Rite Aid Corp., 2023; Mobley v. Wordday, Inc., 2023; Cothron v. White Castle Sys., Inc., 2023) and frameworks like the NIST AI Risk Management Framework shape corporate compliance, yet polycentric regulation leaves substantial legal uncertainty. Delegating oversight to private entities concentrates power, weakens protections, and risks normalizing pervasive surveillance and secondary data use (Bannister, 2005; Sanfilippo et al., 2021), shifting the burden of managing complex AI risks onto those least equipped to do so, including vulnerable populations. Based on the study findings and the identified regulatory gaps, we propose four policy governance considerations for organizational policymakers: (1) encourage developers to implement proactive compliance structures integrating privacy-by-design, algorithmic auditing, and continuous regulatory monitoring; (2) adopt transparent governance practices, including disclosure of automated decision-making and internal risk assessment processes to strengthen accountability to users and regulators; (3) engage in multi-stakeholder governance processes with regulators, civil society, and standards bodies to support interoperable AI privacy standards and reduce regulatory fragmentation; and (4) incorporate safeguards addressing emerging risks, including inferential analytics and synthetic media misuse.
| ||
