Freedom House Regulating AI to Protect Internet Freedom M any of the debates surrounding AI have their roots in long-standing policy questions related to internet governance: How can regulation effectively protect people from malicious state and nonstate actors, while fostering a competitive and innovative private sector? What legal responsibilities should companies bear when they fail to prevent their products from being used in harmful ways? The lessons learned from the past decade of deliberations regarding government oversight, the need for robust global civil society engagement, and the problem of overreliance on self-regulation collectively provide a roadmap for this new era. Given the ways in which AI is already contributing to digital repression, a well-designed regulatory framework is urgently necessary to protect human rights in the digital age. Regulators take aim at AI Only a limited number of companies currently have the financial and computational resources necessary to develop AI systems using complex large language models. Similarly, few governments have the regulatory capacity and technical literacy to design robust rules governing the rollout of generative AI. While governments across the democratic spectrum, from Indonesia to the United Arab Emirates, have begun launching high-level strategies or frameworks around AI broadly, many have yet to transfer these pronouncements into legislation. As the technology’s benefits and harms become more apparent, policymakers may look to early examples from China, the EU, and the United States for guidance on their own legislation. The CCP has invested heavily in the AI industry while ensuring that the companies in question will serve its authoritarian priorities. The Cyberspace Administration of China (CAC), a powerful regulatory body, has embarked on a yearslong effort to integrate CCP censorship goals into the country’s content recommendation algorithms, synthetic media, and generative AI tools. For example, the CAC approved 41 suppliers of generative AI services in June 2023, and five chatbots were released to the public in August. @freedomhouse The lessons learned from the past decade of deliberations on internet governance provide a roadmap for this new era. Such applications are required to adhere to or promote “core socialist values” and exclude content that is deemed undesirable by the CCP. Similar rules have long been in place for Chinese social media companies. Since 2021, the EU has developed a sprawling framework that could serve as a global model for AI governance, just as Brussels’s General Data Protection Regulation has become a key reference for data protection laws around the world. The draft Artificial Intelligence Act, which was in final negotiations as of August 2023, would tailor obligations based on the level of risk associated with particular technologies, including facial recognition, recommendation algorithms on social media, chatbots, AI tools that can generate images and videos, and the use of AI in political campaigning. AI products that are deemed to present an unacceptable risk would be banned altogether, including social credit systems, predictive policing tools, and certain uses of biometric surveillance. Technologies with a “high” or “limited” risk would be subject to a spate of pre- and post-market requirements, such as registration and increased transparency. In the United States, the Biden administration began its development of AI governance with a push for industry selfregulation. The Blueprint for an AI Bill of Rights, released in October 2022, laid out a set of principles to guide AI design, use, and deployment. The guidelines include protections against abusive data practices, ineffective and unsafe systems, and algorithmic discrimination, which occurs freedomhouse.org 19

Select target paragraph3