This episode covers three topics: AI governance developments, the emerging Florida privacy bill, and a nuanced legal wrinkle in opt-out enforcement under California law. On the AI front, a White House meeting with key executives from OpenAI and other leading AI companies produced a readout acknowledging that the technology is experimental and that more work is needed on privacy, security, deception, and bias. Separately, OpenAI published a blog post and report outlining a self-governance framework for checking its own outputs against those concerns. A broader proposal also circulated for embedding constitutional-style logic directly into generative AI systems — rules that would cause the model to self-test for discrimination and deception. The episode notes the philosophical difficulty of writing such rules with sufficient precision, referencing the book Superintelligence and its observation that an AI instructed to “respect life” without the qualifier “human” might logically conclude it should protect ants. The practical challenge for in-house counsel is navigating business pressure to deploy these tools now, without a mature risk assessment framework yet available. The Florida privacy bill, at the time of the episode awaiting the governor’s signature, is discussed as meaningfully different from other enacted state privacy laws. It includes broad children’s data protections inspired by California’s Age Appropriate Design Code Act — covering individuals under eighteen — along with general privacy obligations primarily targeted at large platform companies. Like other new state laws, significant definitional gaps remain. The episode frames this as another signal of ongoing regulatory fragmentation: companies building privacy infrastructure need architectures flexible enough to adapt as requirements continue to shift state by state, rather than hard-coding solutions around any single law. The final segment unpacks a compliance obligation that catches many companies off guard under California law. When a consumer submits an opt-out of sale or sharing, the company has fifteen days to comply. However, if the company continues to sell or share that individual’s data during that window before the opt-out is fully processed, it then incurs an additional obligation: it must flow the opt-out downstream to every third party to whom it sold or shared data during those fifteen days. This creates a strong operational incentive to automate opt-out enforcement as close to real time as possible. Cookie-based advertising is relatively easier to automate, but other data sale arrangements that unfold over days create meaningful exposure for companies whose systems were not designed with this requirement in mind.
Washington health data act, children's privacy, Meta FTC
- AI GovernanceState Privacy LawsConsent Management
- Episode 13
- May 11, 2023
Stream this episode on
Summary
Transcript
**Jonathan:** So morning. **Alysa:** Hello, good morning. **Jonathan:** And this time I'm not coming off of a red eye, so my eyes are actually a little bit more open and raring to go. **Alysa:** Oh, good. Good. I'm glad to hear it. **Jonathan:** And I'll see you in Seattle next week for the NAI. **Alysa:** Yeah, that'll be a big one. **Jonathan:** Well lots to talk about following that event. Cool. Hey, wanted to get your thoughts on three things. One of them, just because nobody's talking about this, but AI and kind of the latest developments. Secondly, it's a lot of a privacy bill. And then thirdly, you were saying something fascinating last week about if you don't enforce an opt out quickly within fifteen days, it creates a new obligation to notify third parties. It got me thinking about how important automating opt outs is versus a manual process. I wanted to unpack that a little bit. But firstly, AI — you were saying there's a few kind of interesting developments this week. **Alysa:** Yeah, so it's kind of hard to go beyond a day without having a new headline on AI. So what I've been reading last week, late last week Thursday, the White House had a meeting with some of the key AI execs, right, from OpenAI, from — some of the former OpenAI folks have their own now entity. And just interesting talking about — like the readout was basically, this is experimental and more needs to be done. More needs to be done on privacy, more needs to be done on security, deception, bias, and this is the start of a journey to really find some solutions to that. So that's one. But the couple other things that early this week OpenAI had a blog post out and a report coming up with their proposal on how OpenAI can check itself. And like they admit, this is early on and I think that there's so much value in starting that discussion, but really kind of having that layer where OpenAI is checking itself for those kinds of concerns. So we'll get back to that. And then we had another proposal come out with like essentially the Bill of Rights, the Constitution, the requirements if you have generative AI building in a layer of logic so that it will also test itself on is there discrimination, deception, things like that. And I thought the theme there was really back to experimental, but what do you do if you're in house counsel because the business wants to use this now? And really thinking through how do you do that risk assessment when we don't yet have the full risk assessment package for this that's actually going to be meaningful and responsive to this? And so, I think it's, to some extent, it's what are you using it for? What other mitigation measures are you doing? What kind of data, right? It doesn't all have to be personal data. I mean it's kind of funny, privacy lawyer often gets the misfit children in the sense of if it deals with data it must roll up to the privacy lawyer, even if privacy is not quite the top issue on that. So I think it just continues to be an area to watch and we keep raising it because businesses certainly — it's got their attention and really trying to think about the best ways to use it while also managing risk around it. **Jonathan:** There's so many fascinating pieces to it. I mean, firstly, that the privacy office now, it's blending into all these ethical considerations as well. Seems to be landing at that doorstep. Secondly, on the Bill of Rights, so our CEO, Tom, asked me to read a book called Superintelligence a while back. It basically unpacked the seven or eight paths that AI could take in its growth and how to do it. For example, one of them was brain scans and kind of really understanding what the human brain looks like, and can AI replicate that? The other one was that human beings design these rules or constitutions around what AI does. But then the drawback is you get to this endless list of you have to always have considered everything. So, for one of the examples in the book, which I thought was a great one, was what if you said a statement like, the AI should only make decisions that respect life. But you forgot to say human life, and then you find out that twenty five percent of the biomass on earth is ants, and so the AI might protect ants, right? Like it's so interesting and what you can do with some of the wording and these rules, it's just — we're so early in this game. But I love it. **Alysa:** Yeah, no, I think that's exactly it. So could have a whole episode on that, but more to come and we'll just continue to watch it. **Jonathan:** Yeah, no thanks Alysa. So, what about Florida? Some new privacy bill there? **Alysa:** Yeah, so we are waiting to see if the governor will sign it. It is different than all of the others. It has some provisions that broadly apply dealing with children's data, essentially taking some of the inspiration from California's Age Appropriate Design Code Act and some other legislation that really requires a whole lot more controls around data that might be collected and used associated with children, children being under eighteen. And then it has some broad privacy obligations that are also different than what we've seen with the enacted laws in other states that are really focused on some big platform, big type companies, but like we had seen with some of the other new laws, there's a lot left that's not defined and again it's different. And so it comes back to if you're a company or you're building your company and you're trying to engineer around what are the rules of the road, it's just another indication the ground keeps shifting and there's a lot of complexity here to distill and build into the infrastructure and data governance so that you're not constantly having to change things based on the next law. **Jonathan:** Yeah, absolutely. Just maintaining that flexibility in your privacy tech is critical. To get into some legal nuance, I thought it was fascinating what you were saying last week, Alysa, about enforcing opt outs. I wasn't aware that there was this potential to create new obligations if you don't enforce an opt out within fifteen days. **Alysa:** Do I have — it's more narrow. Yeah. So like if your opt out is not automated, essentially right when somebody opts out, number one, you have fifteen days under California's law to comply with the opt out, so you have that time. But if you haven't opted the person out immediately and you have continued to sell or share that information in that fifteen day period, then you have the obligation to flow down to reach out to those to whom you sold during that period. And if you think about, you know, it's one thing when you're talking about cookie based targeted advertising, that's an easier way to do something automated right up front. But you think about some of the other kinds of sales that are happening that just occur over days and this is probably where companies don't yet have solutions that they've designed that fully account for that. It's just practice — business practices were not designed with this new control in mind. So I think that's one area that might be a surprise for some companies and really having to think through what are good solutions there. **Jonathan:** Awesome. Yeah. Thanks, Alysa. Well, I'll include a link to that in the comments here and the book if anyone's interested. But I appreciate your time today. I'll see you next week in Seattle. **Alysa:** Sounds great. See you.
Next step
See permissioning infrastructure in action
Walk through the platform with a Ketch architect, or launch the free CMP today.
Get started in less than 5 min