Tag: International AI Regulation

  • Idaho’s New AI-in-Education Law Makes Human Oversight a Statewide Requirement

    Idaho’s New AI-in-Education Law Makes Human Oversight a Statewide Requirement

    Idaho's New AI-in-Education Law Makes Human Oversight a Statewide Requirement

    Idaho has enacted a statewide framework for generative artificial intelligence in K–12 public education. Senate Bill 1227, signed by the governor on March 19, 2026, took effect July 1, 2026, and added a new Chapter 70 to Title 33 of the Idaho Code.

    The law does not simply tell schools whether students may use an AI tool. It creates a governance structure: the State Department of Education must develop a statewide framework, the State Board of Education must approve it, and local school districts and public charter schools must adopt policies aligned with it.

    That structure makes Idaho’s law a useful example of a state treating generative AI as an education-governance issue rather than only a classroom technology question.

    What Idaho’s Law Covers

    The statute defines generative artificial intelligence as machine-learning models trained on large volumes of data that can generate new content, including text, images, video, computer code, and music. It excludes models whose primary goal is classifying data, such as those used in automated vehicles.

    It separately defines “generative artificial intelligence in education” as the responsible use of generative AI to support instruction, increase student engagement, personalize learning, improve administrative efficiency, or assist educator decision-making—while ensuring that human judgment remains the final authority.

    That distinction matters. The operative concept is not every automated system used by a school. It is the use of generative systems in teaching, learning, administration, or educator decision-making, subject to a human-control principle.

    A Statewide Framework Comes First

    The State Department of Education must develop a statewide generative-AI-in-education framework for Idaho K–12 public schools. The framework is subject to State Board of Education approval and must:

    • prioritize human-centered oversight, transparency, safety, and data security;
    • ensure that generative AI does not replace or eliminate a human teacher;
    • provide guidance on instructional integration, academic integrity, digital citizenship, and responsible student use;
    • address accessibility, accommodations, and access to generative-AI tools; and
    • serve as the foundation for local policies, professional development, procurement practices, and statewide standards.

    The law does not set out a fixed delivery date for the framework. It does require the department to review and update it as needed through a process involving legislators, education practitioners, industry partners, and workforce representatives. The Idaho Department of Education’s current AI resources page identifies SB 1227 as the foundation for its K–12 AI work and links to framework, standards, professional-development, and family-resource materials.

    The practical result is a two-level governance model. State officials establish the framework, while local entities translate it into operating rules for their own schools and devices.

    Local Policies Must Reach Students and Employees

    Each local school district and public charter school must adopt a policy governing generative-AI use by students and employees in school buildings, on school grounds, during school activities, and on school-issued devices.

    Those policies must align with the State Board-approved statewide framework and define appropriate and prohibited uses for instructional, administrative, and communication purposes. They also must include safeguards for student privacy, data security, accessibility, and academic integrity.

    The statute ties the local policy obligation to existing legal requirements. Policies must comply with applicable state and federal law, including Idaho student-data-privacy requirements, the Idaho Parental Rights Act, the Family Educational Rights and Privacy Act, the Children’s Internet Protection Act, and the Children’s Online Privacy Protection Act.

    For districts, the assignment is therefore broader than writing an acceptable-use paragraph. A workable policy will need to connect classroom use, employee use, student records, vendor contracts, accessibility, assessment, and communications.

    Student Literacy and Teacher Capacity Are Part of the Law

    Idaho’s framework is not limited to restricting risk. The State Department of Education must develop and recommend to the State Board of Education:

    • K–12 generative-AI literacy standards;
    • assessment guidelines addressing student understanding of generative AI, ethics, and responsible use; and
    • a professional-development plan to build educator capacity for safe and effective integration of generative AI.

    The literacy requirement is framed around understanding what generative AI is, how it works, age-appropriate uses, and how to use it ethically, securely, and transparently. The professional-development requirement recognizes a recurring implementation problem: a student-use rule is difficult to administer when educators have not received a parallel operational framework.

    The law also requires the department to develop guidance for parents and legal guardians. That document is intended to support transparency and public understanding of generative AI in public education.

    Procurement Becomes an AI-Governance Checkpoint

    The law places a specific set of requirements on generative-AI-related software, applications, and tools procured by local school districts and public charter schools.

    Those tools must comply with applicable state and federal laws, including FERPA, the Children’s Internet Protection Act, and COPPA. Vendors must disclose whether their products use machine learning, predictive analytics, or generative AI. They also must provide assurances concerning data protection, algorithmic transparency, and responsible use.

    The State Department of Education may establish a list of approved generative-AI tools or develop model procurement guidelines for local use. That authority could become important as districts evaluate products that combine ordinary analytics, predictive functions, and generative features under a single platform.

    For procurement teams, the law points toward a documented intake process: identify the technology, determine what data it receives, obtain vendor disclosures and assurances, evaluate the product against school policy, and preserve the basis for approval.

    What the Law Does Not Yet Answer

    SB 1227 establishes the architecture, but it leaves important operational questions to the framework, local policies, standards, procurement guidance, and possible rules.

    The statute does not provide a single statewide answer for when a student may use a generative-AI tool on an assignment, how a teacher must disclose AI assistance, which products will be approved, or how every district should handle AI-generated errors. It also does not turn the State Department of Education’s framework into a substitute for local policy adoption.

    That division of responsibility is central to the law. A district’s compliance position will depend not only on the text of Chapter 70, but also on the State Board-approved framework and the district’s own policy and procurement records.

    The State Board may promulgate rules to implement the chapter, subject to legislative approval. Those rules could add operational detail, but the statute itself remains the starting point for identifying the required governance components.

    An Implementation Checklist for Idaho Schools

    Districts and charter schools preparing for implementation should track at least these questions:

    • Has the State Board approved the statewide framework, and which parts are incorporated into local policy?
    • Does the local policy cover students and employees across buildings, grounds, school activities, and school-issued devices?
    • Are appropriate and prohibited uses defined separately for instruction, administration, and communication?
    • Are privacy, security, accessibility, academic-integrity, and parental-rights requirements assigned to an accountable owner?
    • Do curriculum and assessment teams have a plan for AI literacy and responsible-use instruction?
    • Do educators have professional-development support before enforcement expectations are imposed?
    • Do procurement records identify machine learning, predictive analytics, and generative-AI features and preserve vendor assurances?
    • Is there a process for updating the policy as the statewide framework and approved tools change?

    These are implementation recommendations, not additional statutory commands. The law expressly requires the framework, local policy adoption, specified safeguards, standards and assessment work, professional development, family guidance, and procurement disclosures and assurances. It separately authorizes possible rulemaking.

    Bottom Line

    Idaho’s SB 1227 treats generative AI in public education as a system-design problem. The state framework is supposed to preserve human authority, protect student data, support academic integrity, and give schools a common baseline. Local districts and charter schools then have to convert that baseline into policies, training, procurement decisions, and day-to-day practices.

    The law’s most consequential phrase may be its simplest: human judgment remains the final authority. Idaho has paired that principle with requirements for state oversight, local accountability, student literacy, educator capacity, parent communication, and vendor transparency. The next phase is implementation—where the statewide framework, local policies, and procurement records will determine what the statute means in practice.

    Sources

  • California’s AI Employment Bills Reach Enrolled Status With Human Review and Displacement Notice Rules

    California’s AI Employment Bills Reach Enrolled Status With Human Review and Displacement Notice Rules

    California now has two AI employment bills at enrolled status.

    That matters because the pair does not try to regulate workplace AI as one abstract category. It targets two concrete points where automation changes employment power: discipline or termination decisions, and workforce reductions caused by AI or other automated technology.

    SB 947 would bar employers from relying solely on automated decision systems to discipline or fire workers and would require human review when an employer primarily relies on automated decision system output. SB 951 would add AI-driven or automation-driven displacement information to California's mass-layoff notice framework when a covered Cal-WARN notice is already required.

    Both bills are still awaiting executive action. They are not enacted law yet. But the official California records show both measures enrolled on September 4, 2026, after final Senate concurrence votes on August 31. That makes this a live compliance-planning moment, not another introduced-bill story.

    For companies using workforce AI, the direction is clear enough already. California is moving from "should employers use AI carefully?" to "who reviews the automated output, what must the worker be told, and what public records will exist when automation displaces jobs?"

    What Changed This Week

    The official California bill records show SB 947 and SB 951 both reached enrolled status on September 4, 2026.

    SB 947, titled "Employment: automated decision systems," passed after Assembly amendments were concurred in by the Senate on August 31 by a 28-10 vote. The official Legislative Counsel's Digest says the bill would add a new Labor Code part beginning July 1, 2027.

    SB 951, titled "Employment: technological displacement: notice," also reached enrolled status on September 4 after Senate concurrence in Assembly amendments on August 31, by a 29-10 vote.

    Those statuses matter because the legislative question has narrowed. The bills are no longer merely concepts being debated in committee. They are passed measures awaiting executive action.

    That does not make them binding yet. It does make them serious enough that companies should begin mapping whether their workforce systems would fall within the rules if the bills are signed.

    SB 947 Is About AI in Discipline and Termination

    SB 947 is the more direct "robo boss" bill.

    The official digest says the bill would, beginning July 1, 2027, prohibit an employer from using an automated decision system to perform certain functions and limit the purposes for and way in which such a system may be used. It would also create employee rights around the data used by the system when the employer primarily uses an automated decision system to make a disciplinary or termination decision.

    The bill is more than a ban on a fully automated firing button. It is also a documentation and notice bill.

    When an employer primarily uses an automated decision system to make a disciplinary or termination decision, the bill would allow the affected employee to request a description of the employee's own data primarily used by the system. It would also require a written post-use notice when an employer primarily relied on an automated decision system to make the decision.

    The author's office frames the bill more plainly. Senator Jerry McNerney's announcement says SB 947 would bar employers from relying solely on automated decision systems to fire or discipline workers, require human oversight and verification when such systems assist those decisions, and require employers to inform workers if an automated decision system was used.

    The enforcement structure also matters. The official digest says the Labor Commissioner could enforce the bill and a public prosecutor could bring a civil enforcement action. The author's announcement says the bill does not provide a private right of action.

    For employers, that combination points to a regulatory file rather than just a lawsuit file. If the bill is signed, companies will need to show how the human review worked, what notice was given, what data description can be produced, and why the automated system was not treated as the final unreviewed decision maker.

    SB 951 Is About AI-Driven Job Displacement

    SB 951 addresses a different problem: not the individual disciplinary decision, but the larger workforce event.

    The official status page describes SB 951 as a bill on "Employment: technological displacement: notice." The bill text would amend California's mass-layoff notice framework so that, when an employer is already required to issue notice for a mass layoff, relocation, or termination, and that event is caused in whole or in substantial part by an AI system or other automated technology replacing or automating employment positions, the notice must include additional information.

    That information would include:

    • the number, classification or occupation, and work location of layoffs substantially due to replacement or automation by AI or other automated technology;
    • the job functions performed by the replaced workers that will be automated;
    • the specific category or type of AI system or other automating technology that substantially resulted in technological displacement; and
    • a statement at the top of the notice saying, "This notice is for a technology displacement."

    The bill would also require California's Employment Development Department, as part of regular Cal-WARN Act data reporting, to publish a summary of notices received under the new technological-displacement subdivision and post quarterly statewide summaries of reported technology displacements.

    That is a major practical point. SB 951 would add a public reporting trail about AI-related and automation-related displacement.

    For companies, that means the decision to attribute a layoff to AI or automation may become visible outside the company. For policymakers, researchers, unions, journalists, and competitors, the same notices could become a data source about where automation is actually replacing jobs.

    The Two Bills Should Be Read Together

    SB 947 and SB 951 are stronger together than either bill is alone.

    SB 947 focuses on decision quality and worker process when an automated decision system is used in discipline or termination. SB 951 focuses on transparency when technology changes the structure of the workforce.

    One is about the affected worker asking: was an automated system used against me, and what data did it rely on?

    The other is about the affected workforce, government, and public asking: are jobs being eliminated because AI or automation is replacing them, and where is that happening?

    That is the real story. California is moving beyond product-level workplace AI regulation and into the evidence trail around workplace AI.

    Employers will not be able to treat these questions as purely internal design choices if the bills are signed. The practical burden will sit in HR, legal, compliance, procurement, data governance, labor relations, and workforce planning.

    This Fits a Broader State Pattern

    California is not moving in isolation.

    Colorado's 2026 automated decision-making technology law, which replaces the state's earlier high-risk AI framework, also turns on notice, explanations, data correction, and meaningful human review. Illinois already regulates certain employment uses of artificial intelligence through amendments to the Illinois Human Rights Act. New York City has had its automated employment decision tool law in force for several years.

    The California bills would add a different kind of pressure.

    SB 947 would push into discipline and termination, beyond the hiring focus of many employment-AI laws. SB 951 would push into displacement reporting through Cal-WARN notices. Together, they would make employment AI governance a continuing operational requirement rather than a one-time vendor review.

    That matters because many organizations still treat AI employment risk as a hiring-screening issue. The newer pattern is broader. It covers who is evaluated, who is disciplined, who is terminated, who is replaced, and what records prove the company did not let automated systems quietly make the real decision.

    What Companies Should Do Before Signature

    Companies do not need to wait for final enactment to start the useful work.

    The first step is inventory. Employers should identify systems that rank, score, recommend, flag, classify, monitor, or otherwise influence discipline, performance management, termination, layoffs, redeployment, or workforce planning.

    The second step is role mapping. A tool that merely stores employee records is different from a tool that recommends termination, flags productivity concerns, scores performance, identifies positions for elimination, or produces a workforce-reduction plan.

    The third step is human-review design. If a system can affect discipline or termination, the company should be able to say who reviews the output, what information the reviewer sees, what discretion the reviewer has, and how the company records the human judgment.

    The fourth step is notice and data-description readiness. If a worker can ask for a meaningful, objective description of the employee's own data that the system primarily used, the company needs to know whether that description can be produced without exposing unrelated confidential or third-party information.

    The fifth step is displacement classification. If AI or automated technology contributes to layoffs or job eliminations, the company should decide how it will determine whether the technology caused the event "in whole or in substantial part." That phrase is likely to do a lot of work if SB 951 becomes law.

    What Not To Overstate

    There are three cautions.

    First, neither bill is enacted yet. The Governor can still sign, veto, or otherwise affect the final posture. The right status today is enrolled and awaiting executive action.

    Second, SB 947 should not be described as banning all AI use in employment decisions. The official materials point to limits, human oversight, worker notice, and data-description rights around covered uses, especially discipline and termination.

    Third, SB 951 is not a general anti-automation law. It is a notice and reporting bill tied to covered Cal-WARN mass-layoff and related events caused in whole or in substantial part by AI systems or other automated technology.

    Those limits make the bills more useful, not less. They show where the compliance work will actually sit.

    Bottom Line

    California's latest AI employment package is about control and records.

    SB 947 asks whether a human really reviewed the automated decision system output that helped discipline or fire a worker, and whether the worker gets notice and a meaningful description of the employee data primarily used around that use. SB 951 asks whether AI or automation materially contributed to displacement in a covered Cal-WARN event and whether that fact will be reported through the state's layoff-notice system.

    If both bills are signed, California will add another important layer to workplace AI governance: whether the company can show who relied on the tool, who reviewed its output, what the worker was told, and what the public record says when technology replaces jobs.

    That is a much harder problem than updating an AI policy. It is a workflow problem. Companies that use automated systems in employment decisions should treat it that way now.

    Sources and Related Clearon Coverage

  • UK Clinical AI Liability Still Starts With The Clinician

    UK Clinical AI Liability Still Starts With The Clinician

    The UK government has not said existing law is broken for clinical AI. It has said something more careful, and more useful for risk planning: existing legal and regulatory frameworks provide a basis for allocating responsibility, but clinicians remain responsible for patient-care decisions when they use AI tools.

    That answer came in response to a written parliamentary question about whether existing liability and regulatory frameworks adequately allocate responsibility for harm arising from AI tools in NHS clinical decision-making.

    The Department of Health and Social Care pointed to clinical negligence law, professional standards, product-liability regimes, and oversight by regulators including the MHRA, the Care Quality Commission, the Information Commissioner's Office, and NICE. It also said that responsibility for patient-care decisions remains with clinicians, who must exercise professional judgment when using AI tools.

    That is not the final answer to the AI liability problem. The Department also acknowledged that AI introduces novel questions about how responsibility should be distributed among manufacturers, software licensors, and users. It said NHS Resolution has been commissioned to assess how existing liability frameworks apply to AI use cases and provide greater clarity.

    For now, the practical message is direct: clinical AI may involve many actors, but a clinician using the tool is not relieved of judgment.

    The Government's Current Position

    The parliamentary answer does three things at once.

    First, it resists the idea that there is currently a liability vacuum. The Department says existing frameworks provide a strong basis for allocating responsibility for potential harms.

    Second, it keeps clinicians in the center of the decision-making chain. AI may assist with diagnosis, triage, prioritization, imaging, documentation, or treatment recommendations. But when it is used in clinical decision-making, the clinician remains responsible for exercising professional judgment.

    Third, it leaves room for future clarification. The answer recognizes that clinical AI may involve multiple parties, including manufacturers, software licensors, providers, and users. In the event of an incident, responsibility may be apportioned according to the circumstances.

    That is a familiar posture in emerging technology. The government is not freezing adoption while a perfect liability model is designed. It is relying on existing frameworks while commissioning work to clarify how they apply.

    The MHRA Commission Is Looking At The Same Problem

    The MHRA's National Commission into the Regulation of AI in Healthcare is examining whether the UK's framework for regulating AI in healthcare is sufficient and how it may need to improve.

    The Commission's call for evidence asked about safe access to AI medical devices, post-market safety checks, and how responsibility and liability should be managed between the different parties involved in deploying AI medical devices.

    The call-for-evidence page was updated on June 11, 2026, to say findings and a wider research-and-engagement report had been published. The Commission's recommendations are expected in 2026.

    That matters because clinical AI liability is not only a courtroom issue. It is a product-governance issue, a medical-device regulation issue, a clinical oversight issue, and a procurement issue.

    Medical Protection Warns Of A Liability Gap

    Medical Protection has taken a sharper view. It warned that a widening gap between AI use and liability law could leave the NHS and clinicians exposed to claims.

    Its concern is that AI systems are not clearly defined as products under the existing product-liability framework. If a patient is harmed after a clinician relies on an AI system that suggested a diagnosis or treatment plan, Medical Protection says the default path may be a clinical negligence claim against the end user rather than a product-liability claim against the developer, manufacturer, or supplier.

    Medical Protection has called for legislation clearly classifying AI systems as products, arguing that responsibility for defective systems should be distributed more fairly.

    That is not a binding legal rule. It is a stakeholder position. But it identifies the risk healthcare organizations already need to manage: if responsibility is unclear, claims may follow the party closest to the patient.

    What Health AI Companies Should Hear

    For AI developers and suppliers, the lesson is not that liability can be pushed downstream forever.

    Procurement teams, regulators, insurers, and courts will ask how the product was validated, what the tool was intended to do, what warnings were given, how performance was monitored, how updates were controlled, and how foreseeable misuse was addressed.

    Contracts may allocate risk between supplier and customer, but they will not necessarily answer patient-facing questions after an incident. Product documentation, post-market monitoring, audit trails, incident-response procedures, and human-factors design will matter.

    If a supplier wants clinicians to trust a tool, the supplier should be able to explain what the tool is for, what it is not for, when a human must override it, and how errors will be detected.

    What Clinical Governance Teams Should Do Now

    Healthcare organizations should assume that AI use will be judged through existing duties unless and until a more specific framework changes the answer.

    That means clinical governance should address:

    • intended use and limits of each AI tool;
    • whether the tool is regulated as a medical device;
    • clinician training and supervision;
    • how recommendations are documented in the patient record;
    • when clinicians must independently verify or override AI output;
    • incident reporting and escalation;
    • supplier obligations for monitoring, updates, security, and performance drift;
    • patient communication where AI materially affects care; and
    • insurance and indemnity allocation for AI-related incidents.

    The key is to avoid treating AI as either an autonomous decision-maker or a harmless administrative aid. Clinical AI may sit somewhere between those poles, and governance should match the actual use case.

    Bottom Line

    The UK's clinical AI liability position is still developing, but the current operating rule is clear enough: clinicians remain responsible for patient-care decisions when using AI tools.

    That does not mean developers, licensors, providers, and healthcare organizations avoid responsibility. It means the liability analysis will likely be shared, fact-specific, and built from existing frameworks unless reform changes the allocation.

    For now, health AI governance should be designed for that world: human clinical judgment at the point of care, supplier accountability upstream, and enough documentation to explain both if something goes wrong.

    Sources

  • The UK Is Moving Automated Decision-Making Away From the EU Model

    The UK Is Moving Automated Decision-Making Away From the EU Model

    The UK's recent data-law changes matter for AI governance because they suggest a real break from the EU approach to automated decision-making.

    If you want the official legislation, the UK law is here: Data (Use and Access) Act 2025.

    Under section 80 of the Data (Use and Access) Act, the UK has replaced the old Article 22 framework with a more permissive structure: automated decision-making with safeguards, rather than a prohibition-first starting point.

    This is a real shift

    Under the classic Article 22 model, the analysis usually began with a restriction. The UK's newer approach is more operational and less categorical. The question becomes less "is this forbidden unless an exception applies?" and more "what safeguards, transparency, and review rights are required when this happens?"

    That may sound subtle, but it matters. It gives companies more room to deploy automated systems, while also increasing pressure to justify how those systems are used.

    What multinational teams should watch

    A lot of organizations still hope they can run one clean global policy for AI-enabled decision-making. The UK’s move makes that harder. If the EU and UK keep drifting apart here, legal teams may need separate assessments for profiling, scoring, and model-driven recommendations that affect individuals.

    That does not just affect flashy AI products. It can reach ordinary systems used in employment, insurance, financial services, fraud detection, customer eligibility, and prioritization workflows.

    The takeaway

    The UK is not abandoning regulation. It is choosing a different posture. A permission-with-safeguards model still requires governance, and in some ways it requires better governance because companies have more room to act.

    Cross-border AI compliance is starting to look less like one policy problem and more like jurisdiction management. That is the part legal teams should plan around now.