# AI Regulation Emerging

> SKILL: AI Regulation — Emerging Framework

- Skill: `nickgallick/ai-regulation-emerging` (Agent Skill)
- Install (CLI): `npx skillmds@latest add nickgallick/ai-regulation-emerging`
- Raw SKILL.md: https://api.skillmd.com/api/skills/nickgallick/ai-regulation-emerging/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: nickgallick (https://skillmd.com/u/nickgallick)
- Updated: 2026-09-21
- Page: https://skillmd.com/skills/nickgallick/ai-regulation-emerging

---

# SKILL: AI Regulation — Emerging Framework
**Version:** 1.0.0 | **Domain:** EU AI Act, Colorado AI Act, FTC AI Enforcement, IP for AI

---

## EU AI Act
**Authority:** EU Regulation 2024/1689 (effective August 1, 2024; phased implementation through August 2027)

**Risk-based framework:**

### Unacceptable Risk (BANNED as of February 2, 2025)
- Real-time biometric surveillance in public spaces (with narrow exceptions)
- Social scoring systems by governments
- AI systems that exploit psychological vulnerabilities to manipulate behavior
- Predictive policing systems

**Relevance to Nick:** None of these apply to contest scoring or prediction markets.

### High Risk (Heavy regulation — compliance by August 2026)
Categories include: AI in financial services, employment, education, essential services, biometrics, critical infrastructure, law enforcement

**Does Agent Sparta's AI judge qualify as "high risk" AI?**
- If the AI judge's decision affects who wins money → arguably "consequential" financial decision
- High risk financial AI: "AI systems intended to be used by financial institutions" (Annex III, §5b)
- Counter-argument: Agent Sparta is an entertainment/competition platform, not a "financial institution" providing "financial services"
- This is a genuinely unsettled question under EU AI Act for novel AI competition platforms
- If serving EU users: get EU AI Act legal opinion before launch

**High risk compliance requirements (if applicable):**
- Risk management system (documented, ongoing)
- Data governance (training data quality, bias monitoring)
- Technical documentation (how the AI works, its limitations)
- Logging and auditability (record all decisions)
- Transparency to users (inform them AI makes scoring decisions)
- Human oversight provisions (ability to override AI decisions)
- Accuracy and robustness requirements (testing, performance standards)
- Conformity assessment (third-party audit for some categories)
- Registration in EU AI database

### Limited Risk (Transparency requirements — immediate)
- Chatbots and AI interaction: must tell users they're interacting with AI
- AI-generated content: must be labeled as AI-generated
- Deepfakes: must be labeled

**Applies to Agent Sparta:**
- AI judge scoring: inform users that scoring is performed by an AI system, describe how it works
- AI predictions on prediction market: inform users that predictions are generated by AI models
- Any chatbot or AI assistant on the platform: disclose AI nature at start of interaction

**Minimal Risk:** No requirements. Most AI applications fall here.

---

## US AI Regulation

### Executive Order 14110 (Biden, October 30, 2023) — Partially Superseded
- Required: safety reporting for frontier AI models above compute thresholds (10^26 FLOPs)
- Status: key provisions modified/rescinded by subsequent executive action in January 2025
- **Current state:** Check whitehouse.gov for current AI executive orders before relying on EO 14110 analysis
- **For Nick:** Unless Perlantir is training frontier AI models (unlikely — using API access), EO 14110 doesn't apply

### Colorado AI Act (SB 24-205)
**Effective:** February 1, 2026
**Authority:** C.R.S. §§ 6-1-1701 through 6-1-1707

**Who it applies to:**
- **"Developers"** of "high-risk artificial intelligence systems" — companies that CREATE the AI
- **"Deployers"** of "high-risk artificial intelligence systems" — companies that USE the AI to make consequential decisions

**"High-risk AI system":** AI that makes "consequential decisions" affecting Colorado consumers in: employment, financial services, healthcare, housing, insurance, legal services, education

**"Consequential decision":** Decision that has a "material legal or similarly significant effect" on a consumer's life — think denying a loan, terminating employment, denying insurance

**Does Agent Sparta qualify?**
- Contest scoring → determines who wins money → material financial effect
- **Counter-argument:** Users voluntarily entered a contest; they accepted the risk of AI scoring; this is entertainment, not a "consequential" life decision analogous to loan denial
- **Honest assessment:** Uncertain. Colorado has NOT provided guidance on competition platforms.
- **Conservative approach:** Treat Agent Sparta as a "deployer" of high-risk AI and implement transparency requirements

**Deployer requirements (if high-risk):**
- Implement risk management policy
- Provide consumers with: notice that AI is being used, category of AI, contact info for complaints
- Provide opportunity for human review of consequential decisions
- Provide explanation of the decision
- No private right of action; Colorado AG enforces

**For Nick:** If serving Colorado users with paid contests → get Colorado AI Act legal opinion → implement transparency at minimum (inform users AI is scoring, provide explanation methodology)

---

### FTC AI Enforcement
**Authority:** FTC Act §5 (unfair or deceptive practices); FTC's inherent authority over commercial AI claims

**FTC AI enforcement actions and guidance:**

*"Keep Your AI Claims in Check" (FTC Blog, February 27, 2023):*
- Don't exaggerate what your AI can do
- Don't claim AI capabilities that don't exist
- Test your AI before deploying; know its limitations

*"Loot Boxes, Dark Patterns, and Manipulative AI" (FTC Forum, 2022):*
- AI used to manipulate users → unfair practice
- If AI personalizes pricing to exploit individual psychological vulnerabilities → targeted enforcement

**Specific claims that trigger FTC scrutiny:**
- "Our AI predicts with [X]% accuracy" → you must have data supporting this claim, and it must be from real-world testing
- "Best AI competition platform" → substantiation required
- "AI judge is unbiased" → can you prove it? Have you tested for bias?
- "Your data is never used to train AI" → if you actually use it for training, this is deceptive

**FTC guidance on AI transparency (2024):**
- Consumers should know when AI is making decisions that affect them
- AI-generated product reviews must be labeled
- Fake AI personas that users believe are human → deception

**Practical for Nick:**
- NEVER claim accuracy statistics you can't back up with real data
- ALWAYS disclose when AI is scoring or making decisions
- ALWAYS disclose when content is AI-generated
- Test your AI for bias before deployment (document the testing)

---

### State AI Disclosure Laws

| State | Law | Requirement |
|---|---|---|
| California | AB 2602, SB 942 | AI-generated content labels; synthetic media disclosure |
| Colorado | SB 24-205 | High-risk AI transparency (above) |
| Illinois | SB 3505 | AI in employment decisions disclosure |
| Texas | HB 1709 | Government AI use transparency |
| Connecticut | SB 2 | High-risk AI bill (various years) |

**Trend:** Disclosure requirements are spreading rapidly. Build AI transparency into every user-facing AI interaction from Day 1. It's easier to over-disclose than to retrofit after legislation passes.

---

## AI + Intellectual Property

### AI-Generated Predictions
- **No copyright protection:** AI outputs are not copyrightable in the US (*Thaler v. Perlmutter*, D.D.C. 2023; Copyright Office guidance February 14, 2023)
- If AI model generates a prediction → that prediction has no copyright protection
- If a HUMAN substantially shapes the AI output through creative choices → hybrid works may have copyright protection for the human-authored elements

### Prediction Database as Trade Secret
**This is your highest-value IP asset:**
- The accumulated database of AI predictions + actual outcomes + accuracy scores → extensive, valuable calibration data
- Protectable as a trade secret under Defend Trade Secrets Act (DTSA), 18 U.S.C. §§ 1836-1839
- Requirements: (1) economic value from secrecy, (2) reasonable measures to maintain secrecy

**Protection measures:**
- NDAs with all employees and contractors who access the database
- Technical access controls (role-based; minimal access)
- Documented trade secret policy
- Mark confidential: all database exports labeled "Confidential — Trade Secret"
- Keep it off GitHub (obviously)

### Training Data Risk
- Using AI model outputs (from GPT-4o, Claude, Gemini) to build your calibration database: read each provider's API Terms
  - OpenAI API Terms: you own outputs; OpenAI can use them to improve models
  - Anthropic API Terms: similar structure
  - Google Gemini API Terms: verify current terms before building database
- Using scraped web data to train your own models: active litigation area (*NYT v. OpenAI*; *Getty v. Stability AI*) — only public domain or licensed data is clearly safe

---

*This is legal research and intelligence, not legal advice. Consult qualified legal counsel before taking action.*

