Regulatory basis: This document is grounded in United States law and federal
policy applicable to Abkus operations in the U.S. market β including state comprehensive
privacy statutes, FTC enforcement under Section 5 of the FTC Act, the NIST AI Risk Management Framework,
Executive Order 14110 on safe and trustworthy AI, and the Blueprint for an AI Bill of Rights β rather
than Brazilian judicial regulations.
1. Regulatory foundations and the constitutional stature of privacy
For Abkus products and services offered in the United States, data protection and responsible AI are
anchored in a layered U.S. legal baseline: constitutional limits on government and commercial
surveillance, sector-specific federal rules where applicable, state comprehensive privacy laws, and
emerging AI governance standards developed by federal agencies and the National Institute of Standards
and Technology (NIST).
U.S. courts have recognized informational privacy interests under the Fourth Amendment (e.g., Carpenter v. United States, 585 U.S. 296 (2018)) and due-process protections under the
Fifth and Fourteenth Amendments. For private-sector processing, state laws such as the California
Consumer Privacy Act as amended by the CPRA, the Virginia Consumer Data Protection Act (VCDPA), the
Colorado Privacy Act (CPA), and comparable statutes impose purpose limitation, data minimization,
security, and consumer rights that mirror LGPD-style principles in the Brazilian framework.
Dual-pillar regulatory baseline (U.S.)
| State privacy principle (typical U.S. statute) | Reinforcement under NIST AI RMF / federal AI policy |
|---|
| Purpose limitation | Map AI use cases to documented, legitimate business purposes; prohibit secondary use without notice and choice. |
| Data minimization | Collect and retain only data necessary for the stated AI function (NIST GOVERN 1.3). |
| Consumer rights | Honor access, deletion, correction, and opt-out rights under applicable state law (e.g., CPRA, VCDPA). |
| Security | Implement reasonable administrative, technical, and physical safeguards (FTC Safeguards Rule where applicable). |
| Non-discrimination | Prohibit unlawful disparate impact in automated decisions affecting employment, housing, credit, or public accommodations. |
| Transparency | Disclose material use of AI; provide meaningful notice under state AI disclosure laws (e.g., Colorado AI Act, Utah AI Policy Act). |
| Accountability | Maintain human oversight, documented impact assessments, and vendor due diligence (EO 14110, OMB M-24-10 principles for federal contractors). |
| Accuracy | Validate outputs for high-impact decisions; monitor drift and error rates (NIST MEASURE function). |
| Prevention | Identify and mitigate systemic risks before deployment (NIST MAP and MANAGE functions). |
| De-identification | Apply robust de-identification before external LLM processing when feasible; re-identification risk assessment required. |
Abkus treats personal data as a liberty interest protected by law β not as an unrestricted training
asset β and designs human-centric systems accordingly.
2. Ethical framework: human centrality and algorithmic vulnerability
U.S. policy documents β including the White House Blueprint for an AI Bill of Rights and NIST's
Trustworthy AI characteristics β converge on the same anthropological question: AI must expand human
agency, not replace accountable human judgment in consequential decisions.
Stages of algorithmic vulnerability (U.S. context)
- Economic concentration: asymmetries in access to capital, land, and platform power.
- Labor and industrial relations: automated management, surveillance, and wage-setting risks.
- Consumer markets: opaque pricing, dark patterns, and informational gaps.
- Cross-border data flows: dependence on foreign infrastructure and model providers.
- Algorithmic governance: individuals facing opaque automated scoring, ranking, or profiling with limited recourse.
Abkus intervenes at the product layer by refusing designs that concentrate decision power in
unreviewable models and by documenting human override paths in every high-impact workflow.
Human dignity mandate
- Technology as means, people as ends.
- Algorithms lack moral agency and cannot bear legal responsibility for professional judgments.
- Human prudential judgment remains irreducible in financial, legal, health, and management contexts.
Under U.S. equal-protection and anti-discrimination law (Title VII, Fair Housing Act, ECOA, ADA),
Abkus prohibits proxy discrimination and biased automated workflows. Where local law requires it
(e.g., NYC Local Law 144 for automated employment decision tools), independent bias audits and
public summaries are performed before deployment.
3. Risk taxonomy and prohibited practices
Risk-based regulation (U.S. framework)
Abkus maps product AI features to a U.S. risk taxonomy aligned with the NIST AI Risk Management Framework,
state high-risk AI laws (e.g., Colorado AI Act), and FTC guidance on automated decision systems β not CNJ
Resolution 615/2025.
Unacceptable risk Prohibited applications
Uses that violate fundamental rights or applicable U.S. law and must not be deployed:
- no meaningful human review or override path
- criminal-risk profiling of individuals without due process safeguards
- automated legal classification of persons for adjudicative effect
- biometric emotion recognition in employment, education, or access decisions where prohibited
- practices posing unacceptable risk to civil liberties or equal protection
High risk Strict controls required
Consequential decisions requiring impact assessment, documentation, and continuous oversight:
- profiling that materially affects employment, housing, credit, or insurance
- automated evaluation or weighting of evidence in legal or compliance workflows
- interpretation of facts as criminal or regulatory violations without human sign-off
- automated judgments on legal standard application or binding precedent
- biometric monitoring of behavior in high-stakes contexts
Low risk Auxiliary tools
Lower harm potential, with periodic review and in-product transparency:
- drafting support text and summaries
- routine procedural or administrative task assistance
- operational support workflows without autonomous final decisions
- information extraction from systems and documents
- decision-pattern detection for analytics (non-binding)
- qualified precedent or knowledge-base search
- managerial, jurimetric, and statistical reporting
- retrospective performance analysis
- audio and video transcription
- document anonymization and redaction assistance
Controls by tier (U.S.)
| Requirement | High risk | Low risk |
|---|
| Supervision | Continuous monitoring, incident response, and executive accountability. | Periodic review and change logs. |
| Assessment | Algorithmic impact assessment (AIA) / DPIA where required by state law or contract. | Lightweight change review checklist. |
| Transparency | Public or customer-facing summary of purpose, limits, and oversight mechanisms. | In-product notice that AI assisted the output. |
| Re-review | Annual reclassification at minimum; immediate review after material model change. | Review when scope or data sources change materially. |
Unacceptable-risk features are prohibited in Abkus products for the U.S. market. All AI
capabilities are tier-classified before release and reclassified when scope, data, or models change
materially.
4. Governance protocols and infrastructure
Abkus maintains an internal AI system inventory β purpose, owner, data categories, model version,
and risk tier β consistent with federal AI inventory expectations under Executive Order 14110 and
NIST GOVERN 1.2. This registry is the operational "source of truth" for auditability and customer
due diligence.
Algorithmic impact assessment checklist (high-risk systems)
- βData typology: personal, sensitive, and derived data categories processed.
- βMethodology: model type, training data provenance, and validation approach.
- βSecurity: encryption, tenant isolation, access controls, and vendor SOC 2 / equivalent review.
- βMitigation: bias testing, red-teaming, rollback, and human-escalation paths.
Integration standards
Products implement privacy by design and privacy by default (FTC guidance; state statute requirements).
For customer-facing AI features, Abkus discloses:
- Model or service name and functional description.
- Version or release identifier.
- Internal registry identifier for enterprise customers upon request.
- Last material update date.
5. Human supervision and user responsibility
AI is advisory. Abkus mandates human-in-the-loop controls for irreversible or high-impact actions,
consistent with FTC guidance on AI claims and state laws governing automated consequential decisions.
Obligations of users and customer administrators
- Non-binding outputs: AI suggestions do not constitute final professional, legal, financial, or medical decisions.
- Decision authority: licensed professionals and authorized customer personnel retain final authority.
Large language models and generative AI
- De-identification at source: regulated, confidential, or attorney-client data must not be sent to external LLMs without contractual safeguards and de-identification where required.
- Vendor compliance: data processing agreements must prohibit unauthorized training on customer content (enterprise API terms, zero-retention options where available).
Responsibilization layer
Under U.S. tort, contract, and sector-specific liability rules, the human user and the deploying
organization remain responsible for decisions taken on the basis of AI outputs. Abkus, as processor
or service provider where applicable, maintains security and contractual accountability; customers
acting as controllers retain compliance obligations under applicable state privacy law.
6. Roadmap for institutional implementation
Existing Abkus AI features follow a phased compliance roadmap aligned with state law effective dates
and NIST AI RMF maturity targets. New high-risk features must meet this framework before general
availability.
- Transparency and adaptability: prefer auditable, configurable models and documented pipelines over opaque black boxes.
- Technical isolation: tenant segregation, encryption in transit and at rest, and least-privilege access.
- De-identification: mandatory before external API calls when personal data is involved.
Internal AI governance function
- Trigger audits when incidents, customer complaints, or regulatory inquiries arise.
- Reclassify risk tiers when models, data sources, or use cases change.
- Maintain the AI system inventory and vendor register.
- Standardize training on bias, security, and critical review for internal operators.
- Update impact-assessment templates and public transparency summaries annually.
Success is measured by service to a free, fair, and accountable digital economy. No efficiency gain
justifies reducing human dignity. In the age of algorithms, Abkus reaffirms that technology serves
people β and that people remain accountable for the decisions they approve.