LD_COURTNEY BOWMAN_TRANSCRIPT

[00:00:00] JOHN QUINN: This is John Quinn, and this is Law Disrupted. And today we have the opportunity to speak with Courtney Bowman. Courtney is the Global Director of Privacy, is it? And Civil Liberties, is that right, Courtney? That's right. Global Director of Privacy and Civil Liberties at Palantir, something which, uh, you can tell just by the title and the nature of the company, uh, is a very important job and one that's, uh, touches on a lot of the issues that we're all reading and hearing about regarding, uh, privacy and regulation of AI.

And all the touch points relating, relating to it. And, um, I guess the big news in this area right now, I would think is the enactment of the EU AI act. Um, I mean, it seems like the final step among, uh, the European parliament, the council of Europe has now been taken, although it goes into effect over stage periods of time, over time.

Uh, and I assume Courtney, you, I mean, I'm, I know Palantir made submissions. Uh and weighed in and contributed to Uh the way that Act came out Uh, can you tell us a little bit about what Palantir's involvement in that was? 

[00:01:23] COURTNEY BOWMAN: Yeah, first off it's a pleasure to be back on your podcast sean. Thank you for inviting me Um It's worth noting that the A.

I. Act has been in progress for a number of years. The first version or a draft submitted by the E. O. Commission dates back to April 2021. And even before that, uh, there were preparatory efforts, draft white papers to help constitute some of the framework considerations for this regulation. But we've been following these developments quite closely for a while, and it's been quite a roller coaster.

Um, with the complexity of EU regulation, the, the interplay between the member states and the parliament and the commission, um, getting to resolution, it actually looked towards the end of last year that, um, some of the, the tri log discussions may have hit an impasse, um, but ultimately those were resolved.

Um, the parliament passed the, uh, the, the final, what should be the final draft, um, a couple of weeks ago on March 13th. And then there, there's a final hurdle to clear with the member states to, um, to, to go through a final review and pass the, um, this final text. But it looks like it's it should be smooth sailing from here.

And then, uh, from this point, there's still, as you suggested, a two year window of implementation. Um, so most of the provisions of the Act won't actually begin to take full effect, uh, until early 2026. So still quite a runway before we start to see this play out in practice. Um, but given the complexity of the issues at stake, uh, in the nature of the technology Behooves people who in institutions who are going to be on the hook for meeting these regulatory obligations Uh to start to think about what it will actually mean in practice for them 

[00:03:11] JOHN QUINN: Yeah, can we talk a little bit about that?

I mean I as I understand that the act Designates, uh, different sorts of applications or uses of A. I. categorizes them by levels of risk ranging from certain applications, which are just regarded as too risky and under the act will not be permitted, uh, to other uses different grades of uses that require different types of, uh, approvals and regulation.

Depending upon how, how risky they're deemed to be. Uh, and then there are, there are accompanied with some directives as I understand it, that, uh, do some kind of remarkable things in terms of potentially making, uh, authors, uh, if that's the right word, uh, creators. Of AI programs responsible for downstream uses, which suggests that you need to monitor what's being done with your, uh, your, your AI creations and applications and even, you know, from a legal standpoint and from products liability standpoint, uh, might shift burdens of proof.

That if somebody claims that they were, they were injured, that they won't have the burden of proof of proving that an AI is defective, but the burden is actually then on the creator to prove that That it's not defective, which is it's kind of remarkable shift in the burden of proof. I mean, these are some very significant changes.

[00:04:41] COURTNEY BOWMAN: Yeah, very significant and as your question suggests, fairly complex. So to try and unpack some of the issues there is a starting point. The act defines a notion of AI systems. And I think this is an important distinction because. Um, as we talked about about a year ago, and the last time I appeared, um, on the podcast, there's a distinction between AI as a type of technology and where it's situated.

And oftentimes the utility of of AI. Uh, is a function of its sort of systems level integration, how it integrates with data with end user applications and a whole slew of other pipeline in systematic considerations. So the regulation tries to approach this notion of AI systems. And as you suggested, Breaks AI systems into four different types of risk thresholds or compartments in according to where a system fits into those four different areas of risk, there's different obligations and responsibilities.

So at the low end, there's a notion of a minimal risk system or no risk system. And you can think about things like spam detectors, right? Um, as a I that we've been using for now decades that are tightly integrated into normal systems and operations and generally viewed as being lower risk because of the nature of what they provide.

Um, or their provenness in their various application fields, um, and then there's lower risk applications of of AI systems, uh, which are things like chat bots, um, where there there may be some associated risk, but it's deemed to be on the on the lesser scale. And they're the responsibilities more towards transparency, um, notifying end users and consumers that they're interacting with an A.

I. System. Um, then we get into the interesting echelon of risk, which are high risk A. I. Systems. And this is this is really where a lot of the action is, um, High risk AI systems, a lot of discussion in developing the regulation was building out the annexes of the regulation that specify the different classes and functions of these systems.

Um, high risk systems are going to entail some pretty significant, uh, regulatory obligations. For different set of players, as you alluded to, um, so there are system providers. You can think about these as the developers of the AI systems. Um, there are the system deployers. These are the institutions, businesses and other entities, even individuals.

Who used the AI systems and have authority control over their application? Um, and then there's another set of, of, uh, of stakeholders here, which are downstream providers. Um, so these are providers of AI systems, uh, that that integrate AI models or, um, have some downstream application. Um, that that may be removed from the where the system is constructed and how is how it was developed, but may still have consequential impact on consumer and end users applications of those systems.

So where there are high risk systems. Um, some of the obligations play out in terms of where called conformity assessments. Um, these will be, uh, pre deployment, uh, responsibilities for the providers and potentially the users of these systems to certify that they've met a set of requirements, um, to limit the liability and the risk, uh, to acknowledge, um, the, the, the challenges of deploying AI systems, um, and then specify some of the mitigations that are in place to manage the risk profile the use of these systems.

[00:08:30] JOHN QUINN: Well, when we talk about, uh, mitigating risk and, um, you know, doing the other things to show that, uh, you've taken steps to to minimize. What exactly are the risks that we're talking about here that the authors of the regulators were looking to minimize and deal with? 

[00:08:50] COURTNEY BOWMAN: Yeah, this is a particularly interesting question, given the span of time over which the regulation was being drafted and debated.

Um, I think in the early years, starting in 2021 and before, a lot of the risk that was associated with AI systems was around, um, discrimination, uh, bias and algorithmic decision making. Um, lack of transparency, lack of understanding of, of how data, um, was, uh, acquired and used for, for training various models, typically machine learning models.

Um, and then around the, the end of, of, uh, 2022, early 2023, we saw the emergence of generative AI and specifically large language models really kind of shift the landscape. And this actually resulted. In a pretty significant pivot of the direction. Well, not pivot, but, uh, an acknowledgement that these general purpose AI models and systems that were derivative of general purpose models needed to also be accounted for, um, in the construction of, of the regulation.

So this this actually resulted in some, uh, significant reconfiguring of, of, uh, the regulatory approach to think about the different risk profiles. Um, in part, because at the time and still now, um, the debate has shifted a bit. You hear a lot of rhetoric and this helps bring the conversation around to some of the regulatory questions on this side of the Atlantic.

A lot of discussion has been on, uh, what have been termed existential risks of general purpose or foundation models. Um, and, and while I don't think the, the, uh, EU commission and parliament really bit hook, hook, line, and sinker into Some of these more extreme concerns of risk. It really did, um, reconfigure how some of the regulatory landscape is adapting to concerns around.

Well, is this or is there a risk of of general purpose? A. I. Um, becoming a form of super intelligence, um, or creating very dramatic, systematic, uh, cascading effects that can break down infrastructure. Um, all of those things are, are sort of now more in play. Um, but arguably there's a question of, well, have we achieved artificial general intelligence, um, or are we at the, at the risk of, of having to deal with, um, Um, uh, super intelligence explosion that may change the way that we think about machine, uh, human interaction, all of which are kind of extreme sci fi themes, but but have been bound up in some of the regulatory discussion.

[00:11:38] JOHN QUINN: Well, that that's that's very interesting. So does the does the act sort of acknowledge or, uh, seek to address the so called existential risk? 

[00:11:48] COURTNEY BOWMAN: Well, I think to the ex credit, it does a pretty moderated job of handling this issue and and addresses the emergence of of general purpose, what are also called frontier foundation models in a pretty reasonable way.

I think there's still a lot of work to be done to tease out. What constitutes the right level of risk profile. So it does, um, identify different categories of risk for these general purpose models and has toyed with with different thresholds of identifying high risk general purpose a models according to the essentially the size of the model.

Um, how many point floating point operators are involved in the construction of A large language model or a generative AI AI model, uh, and from there, it's really looking at, um, starting to grapple with some of the increasingly well documented risks of large language models and generative AI. Things like hallucinations were confabulations, but but less so with the kind of super intelligence concerns that have been raised by some figures in the space.

[00:12:56] JOHN QUINN: Yeah, I mean, one of the things that's always struck me about the discussions about existential risk. And, uh, you know, other than the, uh, the example of the, uh, AI that decides we need to turn every manufacturing facility into one that makes paper clips. That's the example. That's always cited that we get overwhelmed with the number of paper clips, but the discussion of the existential threats of AI, Yeah.

Is really kind of fleshed out in specifics what this might look like, how an AI might actually quote unquote take over and become a threat to humanity. 

[00:13:33] COURTNEY BOWMAN: Yeah, I think that's one of the problems with treating existential risk is a serious thing. Um, Very few people that I've seen have really put those pieces together, um, and arguably, I think that's a, that's a relic of the fact that this is a concern that I think resides more in the, in the space of science fiction than it does in, in actual.

Um, technology, uh, uh, risk profile and deployment where I do think there are significant and potentially growing risks in the application of of these general purpose AI AI models is in the ability to accelerate and scale things like, um, disinformation and misinformation campaigns. Yeah. Um, so one version of that is to create misinformation before general generative AI.

You really had to have an army of people kind of building, um, seemingly plausible content and then distributing it through various channels. Um, with generative AI, you can do this pretty much at scale with with the models themselves and we've seen concerns and real issues around things like election interference.

Um a proliferation of deep fakes on the internet Um and and fake content on social media and you you you start to to develop a pretty robust Set of concerns around what that looks like in in sensitive environments Um and sensitive events like like election, right? Um the the other I think real concern and set of risks that have been raised and are discussed uh in national security settings, but also in You Uh, in settings around critical infrastructure, um, or around cyber security threats, the ability to proliferate significant cyber security attacks on on institutions.

Um, and that's something that generative A. I. Is we're already seeing versions of this play out. Um, so those are those are the real kind of, yeah, high risk scenarios. Um, there's something different from paper clips consuming us all. 

[00:15:39] JOHN QUINN: Yeah. Uh, does, does the AI acts, uh, in some form seek to address misinformation, deep fakes, cybersecurity?

Are those acknowledged to be risks that need to be addressed at different levels of, of, uh, of AI and AI applications? 

[00:15:57] COURTNEY BOWMAN: Yeah, it does. It does touch on, on these issues, um, in, in the notion of general purpose AI systems, um, and, and acknowledging the, the, the kind of risk profile of. These types of, of, um, attacks or, um, erosions of, of public trust, um, at the same time, and this is one of the points of, of ongoing tension in the final throws of, of getting the, the text across the line, um, there's a significant nod towards, uh, the need to create regulatory space for innovation, um, and I think it's worth Taking this into consideration as you think about the broader landscape of of eu regulation, um that uh, They're part of the motivation here is to create a competitive landscape for european firms to compete against um, uh innovative technology coming from from the u.

s Uh, and so there there there's some critiques about the the final draft of the eu regulation that it's too accommodating to industry Um and partially that's the response to industry lobbying Um, particularly from from French and, uh, German, um, uh, industry associations and significant players in the generative AI space to create that, that opening, um, for these technologies to grow and flourish and create economic opportunities.

[00:17:21] JOHN QUINN: Yeah, I know that's a, that's a tension and discussion of regulation of AI generally, including, uh, in this community, you can go up to the, in the Bay area, uh, and talk to people there. And that's something that's top of mind in the AI community and In the Bay Area that an example that's often cited this crypto, you know, we can't let what happened to crypto happen to AI.

Things are changing too fast. It's premature to try to. Uh, you know, put too many limits or regulations in place. And I had read that, that there was a pivot in the development of the AI act. When you have this, I'm forgetting the name of the French generative AI company. That's gotten some real traction.

Mistral Mistral had gotten some real traction and a feeling like the act as it was then, uh, emerging or developing would handicap the development of these nascent, uh, but very promising. European generative AI companies and that their influencer lobbying actually had some impact on, uh, changing the direction of this, of the act.

[00:18:28] COURTNEY BOWMAN: Yeah, I think that's, I think that's right. There's a pretty significant influence in the, uh, the final stages of, uh, coming to resolution on the, the act text. I think one other point to identify here is that this act is intentionally. Constructed as part of a broader framework of other regulatory mechanisms.

Um, so there are, there are points at which, um, the act is meant to intersect with existing regulation, like the general data protection regulation, um, which, uh, it's article 22, um, already places restrictions or ability for data subjects to Um, to opt out of, uh, uh, decision making that's solely based on on automated processing of information through artificial intelligence or other means that that means things like automated profiling, uh, and other application of of technology.

Um, but then there's a whole slew of kind of alphabet soup of of other acts that are under development or or close to resolution. There's the Digital Services Act. Um, there's the ai liability directive, uh, the digital marketing act and the the digital governance act Um, all these are meant to deal with different, uh components and pieces of the digital landscape um to provide the sort of regulatory tapestry um that uh Is is meant to fulfill multiple purposes not just regulate but also to to create space for competitiveness Um, and, uh, for for for innovation in the European marketplace and for anyone who wants to play in the European marketplace, 

[00:20:12] JOHN QUINN: right?

We haven't had any, uh, despite a lot of talk and, uh, Senator Schumer's closed door hearings with the great and good from the U. S. Tech world. A lot of the bills being introduced in Congress. We don't really seem to see any significant progress. In Washington, which I mean to some of us is no surprise. I mean, we have no national privacy Uh, legislation, uh, despite years and years of hand wringing over the impact of social media.

We have no national, uh, legislation address addressing social media. And, um, there is a point of view that really, we're not going to see that, uh, out of Washington and that this will be another example of. What's been called the Brussels effect that in Brussels and the EU sets a standard. Which in effect becomes a global standard, which is kind of what's happened to GDPR, which everyone has to comply with because you're not going to write off the continent of Europe.

You're not going to write off the EU and you're not going to have different compliance regimes for different continents. So in effect, everybody, uh, seeks to comply with the Brussels standards, whether it's GDPR and maybe now potentially the European AI. 

[00:21:29] COURTNEY BOWMAN: Yeah, I, I think, I think in some sense, that's.

That's very true. Um, but, but I'm, I'm actually slightly more optimistic around the action at the federal level. Um, and I'll, I'll, I'll try to articulate why. It is. It is very much the case that Congress is far from passing any kind of comprehensive regulation or legislation on artificial intelligence. As you noted, Senator Schumer's what was called safe innovation framework was a big push around the middle of last year.

Um, and then there were some, some side shows. Um, uh, Senators Hawley and Blumenthal introduced a bipartisan framework, um, that I think was, was meant to partially steer, uh, the Schumer, uh, effort, um, to, towards addressing a certain set of issues like, um, consumer protections and, and child protections and, uh, in digital services and AI online, uh, as well as national security interests.

Um, but. While congress has has kind of faltered and and failed to make progress on on these issues There have been a number of efforts that have moved forward apace Um, uh, so specifically nist, uh rolled out its ai Uh framework which is meant to provide sort of principled Principles based approach, um, for, for addressing some of the, the issues around artificial intelligence.

NIST stands for, remind us what NIST stands for. The National Institute of Science and Technology. 

[00:23:04] JOHN QUINN: Okay. 

[00:23:05] COURTNEY BOWMAN: And this is a, is a, is a, um, a standards bearing body, um, uh, and traditionally has a role in helping to, to define different standards and protocols for, for technology applications. Um, Around the same time that this introduced its, uh, its artificial intelligence, uh, risk management framework, the White House also put out an A.

I. Bill of Rights, which was a similarly oriented kind of principles of based framework for uh, Laying out civil rights, civil liberties considerations in the in the advancement of of AI technologies. Um, and then with the the prominence of growing prominence of generative AI, the White House also pushed a voluntary commitment framework that brought in a lot of the big tech companies, um, to address issues of safety, security generative AI application.

So these were voluntary commitments. Um, to Mostly focused on on generative AI included things like commitments to, um, build in testing, evaluation and red teaming exercises to manage and mitigate some of the risks. But actually, I think one of the most significant developments that was pushed out of the executive branch was the executive order on safe, secure and trustworthy development and use of artificial intelligence.

This was rolled out by the White House. In october 2023, um, it happened to be rolled out around the same time that the eu ai ai act seemed to be Stumbling a bit. Uh, and for a moment, it seemed like the the u. s. Um has stepped in with A pretty significant push towards, um, AI regulation effectively what the executive order does is it lays out a 270 day timeline for effectively every department of federal government.

Um, to start to enact its own set of plans under its existing authorities for addressing some of the risks and challenges and opportunities associated with, with artificial intelligence. Um, so it calls on departments to, uh, um, to elect or appoint, um, uh, A. I. chief A. I. officers. Um, it lays out a framework for the various, uh, divisions of federal government and regulatory bodies.

Um, to start to gather public information, um, and build out, uh, additional, um, uh, policies and principles and practices that align with their existing regulatory, uh, and departmental authorities. Um, and this, this is, uh, has actually been moving at quite a rapid clip. Um, there's been a, a fairly consistent, um, drumbeat of, um, requests for information from various departments, um, to, to start to, um, um, Gather public, uh, opinion as well as industry, um, and, and other institutions and roll that into, um, sector specific considerations for these different divisions of government to, to oversee, um, AI development and deployment and usage.

Um, and so I think in some ways this is, this is actually aligns with. One of the probably the most significant ways the U. S. Typically regulates technology, which is a sectoral approach. It's all clear to me that a comprehensive approach to regulating a I would work as well as maybe it works in the U.

Single marketplace just because we traditionally we focus more on sectoral authorities and the nature of A. I. S. Is a bit different. It's a bit different from privacy interests in that Um, A. I. Is a more of a constellation of technologies. Um, it's amorphous. It's constantly evolving, um, as opposed to a single thing that you can regulate through, uh, through a single kind of regulatory mechanism.

[00:27:03] JOHN QUINN: So, by sectoral, you mean the regulation of a in the health care field might be very different than, say, regulation of a in the finance or banking or insurance. Verticals that different rules and different approaches would apply 

[00:27:18] COURTNEY BOWMAN: and different traditions, uh, different, different legal traditions, different enforcement traditions, different considerations, right?

[00:27:26] JOHN QUINN: You know, we, we did at our firm, we did a survey of the 50 states, which we've kept current and that's, uh. Remarkable, the state's legislature sometimes sort of grandly referred to as the laboratories of democracy, but it's about half of them that have some version of regulation of AI in some cities, including, by the way, New York City and Portland, Oregon, I think, and both of those, uh, it's related to employment decision making and the concern about biased data sets.

Uh, and that's, that's the most common thing in the state regulation, but some of them also address the issue of, uh, deep fakes, uh, and, uh, disclosures to consumers that you're dealing with an AI. So, we are seeing some act, some activity. They're bubbling along on the state level. Do you have any observations on what's happening in the States?

[00:28:20] COURTNEY BOWMAN: Yeah, I think that's, that's. That's spot on. It's sort of a similar parallel phenomenon to what happened with, uh, uh, consumer data protection post GDPR. Um, in the absence of any federal movement, we started to see the steps, the states step into the breach, um, uh, starting with California, and that seems to be a, uh, um, recurring theme with, with a, with AI.

I think in the 2023 legislative session, California, Yeah. Um, introduce several, um, AI, uh, regulatory efforts. I think one of the most 

[00:28:57] JOHN QUINN: pretty comprehensive, uh, some of them pretty comprehensive, thoughtful bills. 

[00:29:03] COURTNEY BOWMAN: Yeah. Yeah. And in addressing a lot of the core considerations that fall out of the AI act in the EU.

So, um, Looking at things like, um, different versions of impact assessments and transparency requirements, um, for different types of decision making and automated automated tooling, um, I think Connecticut also seems to seems to have introduced some some pretty compelling approaches. That deal with notice and transparency, um, and, uh, and assessment frameworks.

Um, so I, I would anticipate that state and as you noted, even local level government governments, um, start to introduce more regulation. But as you suggested, a lot of the action at the local level has been very, very specific to local issues. So dealing with things like biometrics, facial recognition. Um, uh, voting, uh, and other, other, uh, parochial issues have been sort of central concerns.

Um, I think the challenge with AI, uh, regulation at the state and local level is that you're gonna see a pretty, um, disparate set of competencies at the technical level. Um, and how that translates into the ability to regulate, competently regulate these types of technologies is an open question. Um, at least in the federal government, I think there's a bit more resources to upskill on the technology and, uh, and hire, uh, and train people.

On the right set of aptitudes, so it's possible that we see a pretty mixed set of approaches at the state and local level. 

[00:30:42] JOHN QUINN: Right? I think when we talked before. We made reference to the fact that, uh, under the New York law, you had to show that you had to demonstrate or certify. Have your data set audited to show it was an unbiased data set.

Yeah, if you're going to use AI and making employment decisions, and I think you remarked upon the fact that that's no simple problem to and probably the regulators who wrote that didn't really realize the complexities of the problem. You know the woman who, uh, there's a book called The Brussels Effect, and I'm just blanking on her.

Na, her name, she's a professor at Columbia Law School. I met her and I'm very embarrassed that I'm not remembering her name. Maybe I'll see if I can edit this and add her name. But she acknowledges in the forward to her book that, uh, she gives a nod to a paper that was written. Called the California effect where somebody wrote, uh, an article showing and those of us in the legal world know, there's some truth to that, that things, innovative regulations, policies, you know, historically.

Kind of started in California, you'll have the most quote unquote progressive or comprehensive approach to dealing with a problem, whether it's regulation of gas emissions and automobiles and how soon you've got to have so many electric cars and the rest, or in the case of privacy, where California has a very comprehensive privacy law that includes private rights of action and liquidated damages and all the rest of it.

How a lot of this sort of starts in California and then spreads and then just like. But the EU is too big a market to write off. California is too big a market to write off. So California sets what becomes a de facto national standard. 

[00:32:29] COURTNEY BOWMAN: Yeah, I think that's, that's very much the case. Um, California definitely punches above its weight class and has been able to exert a lot of pressure, not just because of the size of the economy, but also the sheer force of the technology industry that's, that resides there.

[00:32:46] JOHN QUINN: That industry, where I think. The Bay Area, at least to my perception, really seems to be the hotbed of AI right now. I mean, those who, like Mark Twain said that reports of his death were premature. I think during the pandemic, we all read about reports of the death of San Francisco. If you go up there now, And you talk to people in the AI community, the reports of the death of San Francisco were certainly premature.

I mean, I have a sense that every night there are people getting together and enormous collaboration and organizations, both formal and informal. And if you talk to people there, the tech people there, they're not super embracing of regulation. 

[00:33:25] COURTNEY BOWMAN: No, I think I think that's true. And some come some comments from some of the big players in the generative AI space have been, you know, open AI, for example, suggested that they may forego the European marketplace if the regulation came out in an unfavorable way.

I think they've walked back from that posture. But it certainly is that is the case that, um, California has looked upon the regulatory landscape with concern about how it's how it's approached and how onerous that approach is going to be um, I think one one thing that is worth calling out that it maybe should have mentioned earlier is that in the absence of of uh Strict regulatory action and legislative developments, sorry, uh, strict legislative developments, um, the regulators are still doing some work in the space.

Um, so we've started to see, um, under existing regulatory authorities, section, section 5 authorities of the FTC, uh, for unfairness and deceptive practices. Um, real attempts to go after some of the big tech companies for, uh, uh, potentially deceptive for allegedly deceptive practices, misrepresentation of AI capabilities.

[00:34:38] JOHN QUINN: Yeah, we just saw the SEC within the last week and brought two complaints against companies for touting their, their AI capabilities, kind of like they brought similar complaints against people for. Greenwashing saying they were green and ESG friendly when they weren't now, the SEC is making clear that if you claim that you're using AI, uh, in your business, and it's important to your business, you better actually be using AI, which, you know, it raises definitional questions.

There's a lot of different things that get called AI. 

[00:35:10] COURTNEY BOWMAN: Exactly. And in a similar vein, the FTC has pursued action against companies, uh, looking at their, their mechanisms for acquiring the data that they use to train models. Right. Um, so, so the FTC has, has introduced a new instrument of algorithmic deletion or disgorgement, um, for ill gotten, uh, uh, training data.

Mm hmm. Um, uh, and I think there are a few, a few cases that, that they pursued this mechanism under. Mm hmm. But it is interesting to observe that the regulators. Aren't kind of holding their powder. They're they're they're looking at this space as fertile for uh, Exercise of existing authorities 

[00:35:53] JOHN QUINN: and these issues also being teed up in courts So you may not call it regulation, but court decisions.

I mean we are there's all these cases that have been brought uh challenging the use of copyrighted material whether it's literary works visual works or musical works to train datasets in a generative You AI applications, and there must be dozens of cases now in the U. S. I mean, one of the well known ones is the New York Times versus open a I, and we're going to have an answer from the courts.

The courts are going to answer that about whether that is under copyright law, fair use or not. So we will, we will know that. And there are similar issues. I think products liability issues. You know, the autonomous car, uh, you know, back in 2018, there was, I think, uh, what was it? Uh, uh, I forget. It was, uh, uh, uh, Uber vehicle.

I think it was an Uber vehicle in Arizona, uh, did not recognize a pedestrian. There was a human copilot in the car, but she wasn't paying attention. She was on her phone. The vehicle struck and killed the pedestrian, you know, from the standpoint of products, liability law that, you know, raise a question, who's at fault here, you know, the state of Arizona and its wisdom charged the woman with involuntary manslaughter.

Um, you know, that's a, that's not the final, uh, time we're going to have courts ruling on issues like that, but these are going to be teed up in courts. 

[00:37:28] COURTNEY BOWMAN: Yeah, there's going to be, I think, a lot of complexity and teasing apart the chain of liability and responsibility, especially as you think about the kind of integrated, uh, characteristics of, of AI as components of broader systems, breaking apart those different components of liability and figuring out who's at, who's at fault at what level.

Not just factoring the technology companies, but also the end users and what their what their expectations are, how their expectations are represented in the packaging of these goods. Are all going to be thorny issues and um, I don't think we have clear resolution on this It's going to take some time to work work through this.

[00:38:10] JOHN QUINN: Yeah, and now within the last week we have the un Adopting some resolutions, which I I haven't read them the reports. Uh, I read seemed to suggest it was mostly focused on On making sure the benefits of AI are shared globally. But there are also, I gather some gestures towards making sure that it's, that it's safe, the world is kept safe from ai, uh, and you of course there have been, the issue comes up, there's some people who are advocates that we really need some global regulatory authority for ai.

That AI doesn't recognize national boundaries and it calls to mind for me. After the Second World War, after Hiroshima and Nagasaki, there was a similar conversation that this is, you know, nuclear weapons are too dangerous. It can't be left to any country. We should find some mechanism to surrender, you know, put sovereignty over nuclear weapons with some international body.

Um, and it really did go anywhere. I know Oppenheimer, Robert Oppenheimer supported that, uh, but it didn't really get anywhere. Well, but that we're not having that same similar conversation with respect to AI. Do you think that's overblown? 

[00:39:26] COURTNEY BOWMAN: My sense is it is I I think the nuclear analogy starts to break down for a number of reasons.

Um, The the first is that you think about nuclear technology and the explosive potential of a fusion and vision Bombs as a discrete moment in time once you reach Vision or fusion capability and can build a bomb. You built the bomb, right? Whereas AI is is going to be a continuously developing technology.

Um, there's lots of different classes of, of, of artificial intelligence, lots of different types of machine learning and other techniques that are going to evolve over time. Um, and that's, that's It's going to be a continuous thing, um, with maybe no discrete moment that defines the thing that should be regulated.

And this is the piece where some of the discussion that we started, uh, with. I think it's relevant around superintelligence people have been using this concept of superintelligence explosion is kind of a bogeyman that represents this, this moment, this trigger of regulatory significance or governance significance.

Um, and because I think that that concern is largely inflated, I'm not sure that approaching AI is a kind of general regulatory proposition. Um, Um, something that can be regulated across all jurisdictions across all sectors for all time is a useful concept just just because this is such an amorphous, um, multifaceted technology.

That really only starts to make sense from a regulatory or oversight perspective when you put it in context and there's so many different contexts that matter. That that I think you kind of have to start to break down the conversation into those environments. And the way that I like to frame this is think about AI as a tool.

And when you start to think about it as a tool, you think about regulating it in the context of use. Um, where the traditions and cultures and, uh, and existing standards really do matter in defining, um, the, the normative aspects of, of tool usage. Um, and then I think you get a little bit closer to making sense out of, out of what AI is capable of, how it should be managed and how it's on reusers should be governed.

[00:41:51] JOHN QUINN: Makes sense. So in terms of regulation and the frontier of AI and regulation of uses of AI, are there some things which you think haven't been addressed, which need to be addressed? I mean, we've talked about, we've touched on a number of things, at least in the European AI Act and in court decisions like bias and transparency and privacy and intellectual property, copyright, deep fakes, cyber security.

These are all issues that are on the table and to one degree or another people are aware of trying to address. Are there some other issues out there that you think are on the frontier that Regulators and lawmakers are going to and courts are going to have to start grappling with 

[00:42:37] COURTNEY BOWMAN: So so I think a lot of attention has been paid to broad principles um that they get to Important notions and ideals for for managing this technology.

So things like accountability and uh, and um fairness uh transparency Um, what what I think there's been a dearth of is translating a lot of those principles into best practices, um, that in best practices that matter in the systems context that I was talking about earlier, and particularly if you start to think about breaking these these concepts down, um, in the use of of generative AI, large language models, I think one of the most significant regulatory challenges is going to be figuring out what are the right frameworks for it.

Instituting testing and evaluation and validation, um, approaches and methodologies to ensure that these AI capabilities are doing the thing that they're supposed to do or doing it in a reliable and trustworthy way. Um, in a way that stands up to the liability risk, but also the consumer expectations. Um, I think there's a whole class of challenges around testing and evaluation.

There's just lots of different ways of doing that that aren't necessarily one size fits all. Um, so I think there's going to need to be some real regulatory and interpretative work to figure out what it means to do meaningful testing, validation and evaluation of AI tools. Uh, and that's just at the, at the kind of outset when you think about deploy, developing and deploying the technologies, then there's a whole other set of concerns around maintenance.

Um, one of the things that we know from. Uh, just the nature of these of these technologies, particularly machine learning based technologies is that they have this characteristics that's that we call brittleness. Um, they erode over time. Um, they erode because their computer code that's built up on certain classes of data that the data itself, um, starts to lose its fidelity with respect to the world that it's meant to represent over time.

The models themselves start to break down because they no longer reflect Um the the nature of the application for which they were designed um, so that you you really start to get into these challenges of how you ensure that Models that have been proven to work at the outset continue to work as expected One, two, three, five years down the road All those issues I think are are are still in in pretty significant need of of governance and oversight 

[00:45:17] JOHN QUINN: fascinating You Fascinating.

How to test, test to what standard and maintenance, especially with respect to machine learning. This has been fascinating. Courtney, thanks so much for joining us. We've been speaking with Courtney Bowman, who is global director of privacy and civil liberties at Palantir. This is John Quinn, and this has been Law Disrupted.

Thank you for listening to Law Disrupted with me, John Quinn. If you enjoyed the show, please subscribe and leave a rating and review on your chosen podcast app. To stay up to date with the latest episodes, you can sign up for email alerts at our website. law disrupted. fm or follow me on x at jbq law or at Quinn Emanuel.

Thank you for tuning 

in.