Prohibits developers and deployers of AI algorithms from causing or contributing to discrimination based on protected characteristics. Mandates developers and deployers to conduct pre-deployment evaluations and annual impact assessments of AI algorithms to identify potential harms or disparate impacts. Requires independent audits of AI algorithms and obligates developers to provide relevant information to deployers for compliance. Imposes transparency obligations, including public disclosures of AI practices and consumer rights, in multiple languages and accessible formats. Grants the Federal Trade Commission (FTC) enforcement authority, including rulemaking, with violations treated as unfair or deceptive acts. Provides a private right of action for individuals, enabling lawsuits for violations and barring pre-dispute arbitration agreements. Establishes federal resources for algorithm auditing, including a new occupational series and additional personnel for the FTC to handle AI-related issues.
Paper
Full text
Artificial Intelligence Civil Rights Act of 2024
ETO AGORA · U.S. federal laws · 2024
Summary
Prohibits developers and deployers of AI algorithms from causing or contributing to discrimination based on protected characteristics.
Mandates developers and deployers to conduct pre-deployment evaluations and annual impact assessments of AI algorithms to identify potential harms or disparate impacts.
Requires independent audits of AI algorithms and obligates developers to provide relevant information to deployers for compliance.
Imposes transparency obligations, including public disclosures of AI practices and consumer rights, in multiple languages and accessible formats.
Grants the Federal Trade Commission (FTC) enforcement authority, including rulemaking, with violations treated as unfair or deceptive acts.
Provides a private right of action for individuals, enabling lawsuits for violations and barring pre-dispute arbitration agreements.
Establishes federal resources for algorithm auditing, including a new occupational series and additional personnel for the FTC to handle AI-related issues.
Titles the Act as the "Artificial Intelligence Civil Rights Act of 2024" and outlines its contents.
SECTION 1. Short title; table of contents. (a) Short title.—This Act may be cited as the “Artificial Intelligence Civil Rights Act of 2024”.
(b) Table of contents.—The table of contents for this Act is as follows:
Sec. 1. Short title; table of contents. Sec. 2. Definitions. TITLE I—CIVIL RIGHTS
Sec. 101. Discrimination. Sec. 102. Pre-deployment evaluations and post-deployment impact assessments. TITLE II—COVERED ALGORITHM AND CONTRACT STANDARDS
Sec. 201. Covered algorithm standards. Sec. 202. Relationships between developers and deployers. Sec. 203. Human alternatives and other protections. TITLE III—TRANSPARENCY
Sec. 301. Notice and disclosure. Sec. 302. Study on explanations regarding the use of covered algorithms. Sec. 303. Consumer awareness. TITLE IV—ENFORCEMENT
Sec. 401. Enforcement by the Commission. Sec. 402. Enforcement by States. Sec. 403. Private right of action. Sec. 404. Severability. Sec. 405. Rules of construction. TITLE V—FEDERAL RESOURCES
Sec. 501. Occupational series relating to algorithm auditing. Sec. 502. United States Digital Service algorithm auditors. Sec. 503. Additional Federal resources.
SEC. 2. Definitions. In this Act:
(1) COLLECT; COLLECTION.—The terms “collect” and “collection”, with respect to personal data, mean buying, renting, gathering, obtaining, receiving, accessing, or otherwise acquiring such data by any means.
(2) COMMISSION.—The term “Commission” means the Federal Trade Commission.
(3) CONSEQUENTIAL ACTION.—The term “consequential action” means an act that is likely to have a material effect on, or to materially contribute to, access to, security and authentication relating to, eligibility for, cost of, terms of, or conditions related to any of the following:
(A) Employment, including hiring, pay, independent contracting, worker management, promotion, and termination.
(B) Education and vocational training, including assessment, proctoring, promotion of academic integrity, accreditation, certification, admissions, and provision of financial aid and scholarships.
(C) Housing and lodging, including rental and short-term housing and lodging, home appraisals, rental subsidies, and publicly supported housing.
(D) Essential utilities, including electricity, heat, water, municipal trash or sewage services, internet and telecommunications service, and public transportation.
(E) Health care, including mental health care, and dental, vision, and adoption services.
(F) Credit, banking, and other financial services.
(G) Insurance.
(H) Actions of the criminal justice system, law enforcement or intelligence operations, immigration enforcement, border control (vetting, screening, and inspection), child protective services, child welfare, and family services, including risk and threat assessments, situational awareness and threat detection, investigations, watchlisting, bail determinations, sentencing, administration of parole, surveillance, use of unmanned vehicles and machines, and predictive policing.
(I) Legal services, including court-appointed counsel services and alternative dispute resolution services.
(J) Elections, including voting, redistricting, voter eligibility and registration, support or advocacy for a candidate for Federal, State, or local office, distribution of voting information, election security, and election administration.
(K) Government benefits and services, as well as identity verification, fraud prevention, and assignment of penalties.
(L) A public accommodation.
(M) Any other service, program, product, or opportunity which has a comparable legal, material, or similarly significant effect on an individual’s life as determined by the Federal Trade Commission through rules promulgated pursuant to section 553 of title 5, United States Code.
(4) COVERED ALGORITHM.—
(A) IN GENERAL.—The term “covered algorithm” means a computational process derived from machine learning, natural language processing, artificial intelligence techniques, or other computational processing techniques of similar or greater complexity, that, with respect to a consequential action—
(i) creates or facilitates the creation of a product or information;
(ii) promotes, recommends, ranks, or otherwise affects the display or delivery of information that is material to the consequential action;
(iii) makes a decision; or
(iv) facilitates human decision making.
(B) MODIFIED DEFINITION BY RULEMAKING.—The Commission may promulgate regulations under section 553 of title 5, United States Code, to modify the definition of the term “covered algorithm” as the Commission considers appropriate.
(5) COVERED LANGUAGE.—The term “covered language” means the 10 languages with the most speakers in the United States, according to the most recent data collected by the United States Census Bureau.
(6) DE-IDENTIFIED DATA.—The term “de-identified data” means information—
(A) that does not identify and is not linked or reasonably linkable to an individual or a device, regardless of whether the information is aggregated; and
(B) with respect to which any developer or deployer using such information—
(i) takes reasonable technical measures to ensure that the information cannot, at any point, be used to re-identify any individual or device that identifies or is linked or reasonably linkable to an individual;
(ii) publicly commits in a clear and conspicuous manner—
(I) to process and transfer the information solely in a de-identified form without any reasonable means for re-identification; and
(II) to not attempt to re-identify the information with any individual or device that identifies or is linked or reasonably linkable to an individual; and
(iii) contractually obligates any person that receives the information from the developer or deployer—
(I) to comply with all of the provisions of this paragraph with respect to such information; and
(II) to require that such contractual obligations be included in all subsequent instances for which the information may be received.
(7) DEPLOYER.—
(A) IN GENERAL.—The term “deployer” means any person, other than an individual acting in a non-commercial context, that uses a covered algorithm in or affecting interstate commerce.
(B) RULE OF CONSTRUCTION.—The terms “deployer” and “developer” shall not be interpreted to be mutually exclusive.
(8) DEVELOPER.—
(A) IN GENERAL.—The term “developer” means any person, other than an individual acting in a non-commercial context, that designs, codes, customizes, produces, or substantially modifies an algorithm that is intended or reasonably likely to be used as a covered algorithm for such person's own use, or use by a third party, in or affecting interstate commerce.
(B) ASSUMPTION OF DEVELOPER RESPONSIBILITIES.—In the event that a deployer uses an algorithm as a covered algorithm, and no person is considered the developer of the algorithm for purposes of subparagraph (A), the deployer shall be considered the developer of the covered algorithm for the purposes of this Act.
(C) RULE OF CONSTRUCTION.—The terms “developer” and “deployer” shall not be interpreted to be mutually exclusive.
(9) DISPARATE IMPACT.—
(A) IN GENERAL.—The term “disparate impact” means an unjustified differential effect on an individual or group of individuals on the basis of an actual or perceived protected characteristic.
(B) UNJUSTIFIED DIFFERENTIAL EFFECT.—For purposes of subparagraph (A), with respect to the action, policy, or practice of a person, a differential effect is unjustified if—
(i) the person fails to demonstrate that such action, policy, or practice causing the differential effect is necessary to achieve a substantial, legitimate, and nondiscriminatory interest; or
(ii) in the event the person demonstrates such interest, an alternative action, policy, or practice could serve such interest with less differential effect.
(C) APPLICATION TO COVERED ALGORITHMS.—With respect to demonstrating that a covered algorithm causes or contributes to a differential effect, the covered algorithm is presumed to be not separable for analysis and may be analyzed holistically as a single action, policy, or practice, unless the developer or deployer proves that the covered algorithm is separable by a preponderance of the evidence.
(10) HARM.—The term “harm”, with respect to a consequential action, means a non-de minimis adverse effect on an individual or group of individuals—
(A) on the basis of a protected characteristic;
(B) that involves the use of force, coercion, harassment, intimidation, or detention; or
(C) that involves the infringement of a right protected under the Constitution of the United States.
(11) INDEPENDENT AUDITOR.—
(A) IN GENERAL.—The term “independent auditor” means an individual that conducts a pre-deployment evaluation or impact assessment of a covered algorithm in a manner that exercises objective and impartial judgment on all issues within the scope of such evaluation or assessment.
(B) EXCLUSION.—An individual is not an independent auditor of a covered algorithm if such individual—
(i) is or was involved in using in a commercial context, developing, offering, licensing, or deploying the covered algorithm;
(ii) at any point during the pre-deployment evaluation or impact assessment, has an employment relationship (including a contractor relationship) with a developer or deployer that uses, offers, or licenses the covered algorithm; or
(iii) at any point during the pre-deployment evaluation or impact assessment, has a direct financial interest or a material indirect financial interest in a developer or deployer that uses, offers, or licenses a covered algorithm, not including routine payment for the auditing services described in subparagraph (A).
(12) INDIVIDUAL.—The term “individual” means a natural person in the United States.
(13) PERSONAL DATA.—
(A) IN GENERAL.—The term “personal data”—
(i) means information that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or an individual's device; and
(ii) shall include derived data and unique persistent identifiers.
(B) EXCLUSION.—The term “personal data” does not include de-identified data.
(14) PROCESS.—The term “process”, with respect to personal data, means to conduct or direct any operation or set of operations performed on such data, including analyzing, organizing, structuring, retaining, storing, using, or otherwise handling such data.
(15) PROTECTED CHARACTERISTIC.—The term “protected characteristic” means any of the following actual or perceived traits of an individual or group of individuals:
(A) Race.
(B) Color.
(C) Ethnicity.
(D) National origin or nationality.
(E) Religion.
(F) Sex (including a sex stereotype, pregnancy, childbirth, or a related medical condition, sexual orientation or gender identity, and sex characteristics, including intersex traits).
(G) Disability.
(H) Limited English proficiency.
(I) Biometric information.
(J) Familial status.
(K) Source of income.
(L) Income level (not including the ability to pay for a specific good or service being offered).
(M) Age.
(N) Veteran status.
(O) Genetic information or medical conditions.
(P) Any other classification protected by Federal law.
(16) PUBLIC ACCOMMODATION.—
(A) IN GENERAL.—The term “public accommodation” means—
(i) a business that offers goods or services to the general public, regardless of whether the business is operated for profit or operates from a physical facility;
(ii) a park, road, or pedestrian pathway open to the general public;
(iii) a means of public transportation; or
(iv) a publicly owned or operated facility open to the general public.
(B) EXCLUSIONS.—The term “public accommodation” does not include a private club or establishment described in section 101(b)(2).
(17) STATE.—The term “State” means each of the 50 States, the District of Columbia, Puerto Rico, the United States Virgin Islands, Guam, American Samoa, and the Commonwealth of the Northern Mariana Islands.
(18) STATE DATA PROTECTION AUTHORITY.—The term “State data protection authority” means an independent public authority of a State that supervises, investigates, and regulates data protection and security law in the State, including handling complaints lodged against persons for violations of State and relevant Federal laws.
(19) TRANSFER.—The term “transfer”, with respect to personal data, means to disclose, release, disseminate, make available, license, rent, or share such data orally, in writing, electronically, or by any other means.
TITLE I—Civil rights
SEC. 101. Discrimination. (a) In general.—A developer or deployer shall not offer, license, promote, sell, or use a covered algorithm in a manner that—
(1) causes or contributes to a disparate impact in;
(2) otherwise discriminates in; or
(3) otherwise makes unavailable,
the equal enjoyment of goods, services, or other activities or opportunities, related to a consequential action, on the basis of a protected characteristic. (b) Exceptions.—This section shall not apply to—
(1) the offer, licensing, or use of a covered algorithm for the sole purpose of—
(A) a developer’s or deployer’s self-testing (or auditing by an independent auditor at a developer's or deployer's request) to identify, prevent, or mitigate discrimination, or otherwise to ensure compliance with obligations, under Federal law; or
(B) expanding an applicant, participant, or customer pool to raise the likelihood of increasing diversity or redressing historic discrimination; or
(2) any private club or other establishment not in fact open to the public, as described in section 201(e) of the Civil Rights Act of 1964 (42 U.S.C. 2000a(e)).
SEC. 102. Pre-deployment evaluations and post-deployment impact assessments. (a) Pre-Deployment evaluations.—Prior to deploying, licensing, or offering a covered algorithm (including deploying a material change to a previously-deployed covered algorithm or a material change made prior to deployment) for a consequential action, a developer or deployer shall conduct a pre-deployment evaluation in accordance with the following:
(1) PRELIMINARY EVALUATION.—
(A) PLAUSIBILITY OF HARM.—
(i) DEVELOPERS.—The developer shall conduct a preliminary evaluation of the plausibility that any expected use of the covered algorithm may result in a harm.
(ii) DEPLOYERS.—The deployer shall conduct a preliminary evaluation of the plausibility that any intended use of the covered algorithm may result in a harm.
(B) RESULTS.—Based on the results of the preliminary evaluation, the developer or deployer shall—
(i) in the event that a harm is not plausible, record a finding of no plausible harm, including a description of the developer’s expected use or the deployer’s intended use of the covered algorithm, how the preliminary evaluation was conducted, and an explanation for the finding, and submit such record to the Commission; and
(ii) in the event that a harm is plausible, conduct a full pre-deployment evaluation as described in paragraph (2).
(C) PREVIOUSLY-DEPLOYED COVERED ALGORITHMS.—When conducting a preliminary evaluation of a material change to, or new use of, a previously-deployed covered algorithm, the developer or deployer may limit the scope of the evaluation to whether use of the covered algorithm may result in a harm as a result of the material change or new use.
(2) FULL PRE-DEPLOYMENT EVALUATION.—
(A) FOR DEVELOPERS.—
(i) INDEPENDENT AUDITOR EVALUATION.—If a developer determines a harm is plausible during the preliminary evaluation described in paragraph (1), the developer shall engage an independent auditor to conduct a pre-deployment evaluation.
(ii) PRE-DEPLOYMENT EVALUATION REQUIREMENTS.—The evaluation required under clause (i) shall include a detailed review and description, sufficient for an individual having ordinary skill in the art to understand the functioning, risks, uses, benefits, limitations, and other pertinent attributes of the covered algorithm, including—
(I) the covered algorithm’s design and methodology, including the inputs the covered algorithm is designed to use to produce an output and the outputs the covered algorithm is designed to produce;
(II) how the covered algorithm was created, trained, and tested, including—
(aa) any metric used to test the performance of the covered algorithm;
(bb) defined benchmarks and goals that correspond to such metrics, including whether there was sufficient representation of demographic groups that are reasonably likely to use or be affected by the covered algorithm in the data used to create or train the algorithm, and whether there was sufficient testing across such demographic groups;
(cc) the outputs the covered algorithm actually produces in testing;
(dd) a description of any consultation with relevant stakeholders, including any communities that will be impacted by the covered algorithm, regarding the development of the covered algorithm, or a disclosure that no such consultation occurred;
(ee) a description of which protected characteristics, if any, were used for testing and evaluation, and how and why such characteristics were used, including—
(AA) whether the testing occurred in comparable contextual conditions to the conditions in which the covered algorithm is expected to be used; and
(BB) if protected characteristics were not available to conduct such testing, a description of alternative methods the developer used to conduct the required assessment;
(ff) any other computational algorithm incorporated into the development of the covered algorithm, regardless of whether such precursor computational algorithm involves a consequential action; and
(gg) a description of the data and information used to develop, test, maintain, or update the covered algorithm, including—
(AA) each type of personal data used, each source from which the personal data was collected, and how the each type of personal data was inferred and processed;
(BB) the legal authorization for collecting and processing the personal data; and
(CC) an explanation of how the data (including personal data) used is representative, proportional, and appropriate to the development and intended uses of the covered algorithm;
(III) the potential for the covered algorithm to produce a harm or to have a disparate impact in the equal enjoyment of goods, services, or other activities or opportunities, and a description of such potential harm or disparate impact;
(IV) alternative practices and recommendations to prevent or mitigate harm and recommendations for how the developer could monitor for harm after offering, licensing, or deploying the covered algorithm; and
(V) any other information the Commission deems pertinent to prevent the covered algorithm from causing harm or having a disparate impact in the equal enjoyment of goods, services, or other activities or opportunities, as prescribed by rules promulgated by the Commission pursuant to section 553 of title 5, United States Code.
(iii) REPORT.—The independent auditor shall submit to the developer a report on the evaluation conducted under this subparagraph, including the findings and recommendations of such independent auditor.
(B) FOR DEPLOYERS.—
(i) INDEPENDENT AUDITOR EVALUATION.—If a deployer determines a harm is plausible during the preliminary evaluation described in paragraph (1), the deployer shall engage an independent auditor to conduct a pre-deployment evaluation.
(ii) PRE-DEPLOYMENT EVALUATION REQUIREMENTS.—The evaluation required under clause (i) shall include a detailed review and description, sufficient for an individual having ordinary skill in the art to understand the functioning, risks, uses, benefits, limitations, and other pertinent attributes of the covered algorithm, including—
(I) the manner in which the covered algorithm makes or contributes to a consequential action and the purpose for which the covered algorithm will be deployed;
(II) the necessity and proportionality of the covered algorithm in relation to its planned use, including the intended benefits and limitations of the covered algorithm and a description of the baseline process being enhanced or replaced by the covered algorithm, if applicable;
(III) the inputs that the deployer plans to use to produce an output, including—
(aa) the type of personal data and information used and how the personal data and information will be collected, inferred, and processed;
(bb) the legal authorization for collecting and processing the personal data; and
(cc) an explanation of how the data used is representative, proportional, and appropriate to the deployment of the covered algorithm;
(IV) the outputs the covered algorithm is expected to produce and the outputs the covered algorithm actually produces in testing;
(V) a description of any additional testing or training completed by the deployer for the context in which the covered algorithm will be deployed;
(VI) a description of any consultation with relevant stakeholders, including any communities that will be impacted by the covered algorithm, regarding the deployment of the covered algorithm;
(VII) the potential for the covered algorithm to produce a harm or to have a disparate impact in the equal enjoyment of goods, services, or other activities or opportunities in the context in which the covered algorithm will be deployed and a description of such potential harm or disparate impact;
(VIII) alternative practices and recommendations to prevent or mitigate harm in the context in which the covered algorithm will be deployed and recommendations for how the deployer could monitor for harm after offering, licensing, or deploying the covered algorithm; and
(IX) any other information the Commission deems pertinent to prevent the covered algorithm from causing harm or having a disparate impact in the equal enjoyment of goods, services, or other activities or opportunities as prescribed by rules promulgated by the Commission pursuant to section 553 of title 5, United States Code.
(iii) REPORT.—The independent auditor shall submit to the deployer a report on the evaluation conducted under this subparagraph, including the findings and recommendations of such independent auditor.
(b) Deployer annual impact assessment.—After the deployment of a covered algorithm, a deployer shall, on an annual basis, conduct an impact assessment in accordance with the following:
(1) PRELIMINARY IMPACT ASSESSMENT.—The deployer shall conduct a preliminary impact assessment of the covered algorithm to identify any harm that resulted from the covered algorithm during the reporting period and—
(A) if no resulting harm is identified by such assessment, shall record a finding of no harm, including a description of the developer's expected use or the deployer's intended use of the covered algorithm, how the preliminary evaluation was conducted, and an explanation for such finding, and submit such finding to the Commission; and
(B) if a resulting harm is identified by such assessment, shall conduct a full impact assessment as described in paragraph (2).
(2) FULL IMPACT ASSESSMENT.—In the event that the covered algorithm resulted in harm during the reporting period, the deployer shall engage an independent auditor to conduct a full impact assessment with respect to the reporting period, including—
(A) an assessment of the harm that resulted or was reasonably likely to have been produced during the reporting period;
(B) a description of the extent to which the covered algorithm produced a disparate impact in the equal enjoyment of goods, services, or other activities or opportunities, including the methodology for such evaluation, of how the covered algorithm produced or likely produced such disparity;
(C) a description of the types of data input into the covered algorithm during the reporting period to produce an output, including—
(i) documentation of how data input into the covered algorithm to produce an output is represented and complete descriptions of each field of data; and
(ii) whether and to what extent the data input into the covered algorithm to produce an output was used to train or otherwise modify the covered algorithm;
(D) whether and to what extent the covered algorithm produced the outputs it was expected to produce;
(E) a detailed description of how the covered algorithm was used to make a consequential action;
(F) any action taken to prevent or mitigate harms, including how relevant staff are informed of, trained about, and implement harm mitigation policies and practices, and recommendations for how the deployer could monitor for and prevent harm after offering, licensing, or deploying the covered algorithm; and
(G) any other information the Commission deems pertinent to prevent the covered algorithm from causing harm or having a disparate impact in the equal enjoyment of goods, services, or other activities or opportunities as prescribed by rules promulgated by the Commission pursuant to section 553 of title 5, United States Code.
(3) REPORTS.—
(A) TO THE DEPLOYER.—After the engagement of the independent auditor, the independent auditor shall submit to the deployer a report on the impact assessment conducted under paragraph (2), including the findings and recommendations of such independent auditor.
(B) TO THE DEVELOPER.—Not later than 30 days after the submission of a report on an impact assessment under subparagraph (A), a deployer shall submit to the developer of the covered algorithm a summary of such report, subject to the trade secret and privacy protections described in subsection (e)(3).
(c) Developer annual review of assessments.—A developer shall, on an annual basis, review each impact assessment summary submitted by a deployer of its covered algorithm under subsection (b)(3)(B) for the following purposes:
(1) To assess how the deployer is using the covered algorithm, including the methodology for assessing such use.
(2) To assess the type of data the deployer is inputting into the covered algorithm to produce an output and the types of outputs the covered algorithm is producing.
(3) To assess whether the deployer is complying with any relevant contractual agreement with the developer and whether any remedial action is necessary.
(4) To compare the covered algorithm’s performance in real-world conditions versus pre-deployment testing, including the methodology used to evaluate such performance.
(5) To assess whether the covered algorithm is causing harm or is reasonably likely to be causing harm.
(6) To assess whether the covered algorithm is causing, or is reasonably likely to be causing, a disparate impact in the equal enjoyment of goods, services, or other activities or opportunities, and, if so, how and with respect to which protected characteristic.
(7) To determine whether the covered algorithm needs modification.
(8) To determine whether any other action is appropriate to ensure that the covered algorithm remains safe and effective.
(9) To undertake any other assessment or responsive action the Commission deems pertinent to prevent the covered algorithm from causing harm or having a disparate impact in the equal enjoyment of goods, services, or other activities or opportunities, as prescribed by rules promulgated by the Commission pursuant to section 553 of title 5, United States Code.
(d) Joint developer and deployer obligations.—If a person is both the developer and deployer of a covered algorithm, the person may conduct combined pre-deployment evaluations and annual assessments, provided that each combined evaluation or assessment satisfies all requirements for both developers and deployers.
(e) Reporting and retention requirements.—
(1) REPORTING.—A developer or deployer that conducts a full pre-deployment evaluation, full impact assessment, or developer annual review of assessments shall—
(A) not later than 30 days after completion, submit the evaluation, assessment, or review to the Commission;
(B) upon request, make the evaluation, assessment, or review available to Congress; and
(C) not later than 30 days after completion—
(i) publish a summary of the evaluation, assessment, or review on the website of the developer or deployer in a manner that is easily accessible to individuals; and
(ii) submit such summary to the Commission.
(2) RETENTION.—A developer or deployer shall retain all evaluations, assessments, and reviews described in this section for a period of not fewer than 5 years.
(3) TRADE SECRETS AND PRIVACY.—A developer or deployer—
(A) may redact and segregate any trade secret (as defined in section 1839 of title 18, United States Code) from public disclosure under this subsection; and
(B) shall redact and segregate personal data from public disclosure under this subsection.
(f) Rulemaking.—
(1) AUTHORITY.—The Commission may, in accordance with section 553 of title 5, United States Code, promulgate such rules as may be necessary to carry out this section.
(2) ADDITIONAL REGULATIONS.—Not later than 18 months after the date of enactment of this Act, the Commission shall—
(A) promulgate rules, pursuant to section 553 of title 5, United States Code, specifying—
(i) what information and factors a developer or deployer shall consider in making the preliminary evaluation or preliminary impact assessment described in subsections (a)(1) and (b)(1), respectively;
(ii) what information a developer or deployer shall include in a summary of an evaluation, assessment, or developer review described in subsection (e)(1)(C); and
(iii) the extent to and process by which a developer may request additional information from a deployer, including the purposes for which a developer is permitted to use such additional information; and
(B) in promulgating such rules, consider the need to protect the privacy of personal data, as well as the need for information sharing by developers and deployers to comply with this section and inform the public.
TITLE II—Covered algorithm and contract standards
SEC. 201. Covered algorithm standards. (a) Covered algorithm use.—A developer or deployer shall do the following:
(1) Take reasonable measures to prevent and mitigate any harm identified by a pre-deployment evaluation described in section 102(a) or an impact assessment described in section 102(b).
(2) Take reasonable measures to ensure that an independent auditor has all necessary information to complete an accurate and effective pre-deployment evaluation described in section 102(a) or an impact assessment described in section 102(b).
(3) With respect to a covered algorithm, consult stakeholders, including any communities that will be impacted by the covered algorithm, regarding the development or deployment of the covered algorithm prior to the deploying, licensing, or offering the covered algorithm.
(4) With respect to a covered algorithm, certify that, based on the results of a pre-deployment evaluation described in section 102(a) or an impact assessment described in section 102(b)—
(A) use of the covered algorithm is not likely to result in harm or disparate impact in the equal enjoyment of goods, services, or other activities or opportunities;
(B) the benefits from the use of the covered algorithm to individuals affected by the covered algorithm likely outweigh the harms from the use of the covered algorithm to such individuals; and
(C) use of the covered algorithm is not likely to result in deceptive practices.
(5) Ensure that any covered algorithm of the developer or deployer functions—
(A) at a level that would be considered reasonable performance by an individual with ordinary skill in the art; and
(B) in a manner that is consistent with its expected and publicly-advertised performance, purpose, or use.
(6) Ensure any data used in the design, development, deployment, or use of the covered algorithm is relevant and appropriate to the deployment context and the publicly-advertised purpose or use.
(7) Ensure use of the covered algorithm as intended is not likely to result in a violation of this Act.
(b) Deceptive marketing of a product or service.—It shall be unlawful for a developer or deployer to engage in false, deceptive, or misleading advertising, marketing, or publicizing of a covered algorithm of the developer or deployer.
(c) Off-Label use.—
(1) DEVELOPERS.—It shall be unlawful for a developer to knowingly offer or license a covered algorithm for any consequential action other than those evaluated in the pre-deployment evaluation described in section 102(a).
(2) DEPLOYERS.—It shall be unlawful for a deployer to knowingly use a cov [Truncated]