Regulatory basis: This document is grounded in United States law and federal policy applicable to Abkus operations in the U.S. market
β including state comprehensive privacy statutes, FTC enforcement under Section 5 of the FTC Act,
the NIST AI Risk Management Framework, Executive Order 14110 on safe and trustworthy AI, and the Blueprint
for an AI Bill of Rights β rather than Brazilian judicial regulations.
1. Regulatory foundations and the constitutional stature of privacy
For Abkus products and services offered in the United States, data protection and responsible
AI are anchored in a layered U.S. legal baseline: constitutional limits on government and
commercial surveillance, sector-specific federal rules where applicable, state comprehensive
privacy laws, and emerging AI governance standards developed by federal agencies and the
National Institute of Standards and Technology (NIST).
U.S. courts have recognized informational privacy interests under the Fourth Amendment (e.g., Carpenter v. United States, 585 U.S. 296 (2018)) and due-process protections under
the Fifth and Fourteenth Amendments. For private-sector processing, state laws such as the
California Consumer Privacy Act as amended by the CPRA, the Virginia Consumer Data Protection
Act (VCDPA), the Colorado Privacy Act (CPA), and comparable statutes impose purpose
limitation, data minimization, security, and consumer rights that mirror LGPD-style principles
in the Brazilian framework.
Dual-pillar regulatory baseline (U.S.)
| State privacy principle (typical U.S. statute) | Reinforcement under NIST AI RMF / federal AI policy |
|---|
| Purpose limitation | Map AI use cases to documented, legitimate business purposes; prohibit secondary use
without notice and choice. |
| Data minimization | Collect and retain only data necessary for the stated AI function (NIST GOVERN 1.3). |
| Consumer rights | Honor access, deletion, correction, and opt-out rights under applicable state law
(e.g., CPRA, VCDPA). |
| Security | Implement reasonable administrative, technical, and physical safeguards (FTC
Safeguards Rule where applicable). |
| Non-discrimination | Prohibit unlawful disparate impact in automated decisions affecting employment,
housing, credit, or public accommodations. |
| Transparency | Disclose material use of AI; provide meaningful notice under state AI disclosure laws
(e.g., Colorado AI Act, Utah AI Policy Act). |
| Accountability | Maintain human oversight, documented impact assessments, and vendor due diligence (EO
14110, OMB M-24-10 principles for federal contractors). |
| Accuracy | Validate outputs for high-impact decisions; monitor drift and error rates (NIST
MEASURE function). |
| Prevention | Identify and mitigate systemic risks before deployment (NIST MAP and MANAGE
functions). |
| De-identification | Apply robust de-identification before external LLM processing when feasible;
re-identification risk assessment required. |
Abkus treats personal data as a liberty interest protected by law β not as an unrestricted
training asset β and designs human-centric systems accordingly.
2. Ethical framework: human centrality and algorithmic vulnerability
U.S. policy documents β including the White House Blueprint for an AI Bill of Rights and
NIST's Trustworthy AI characteristics β converge on the same anthropological question: AI must
expand human agency, not replace accountable human judgment in consequential decisions.
Stages of algorithmic vulnerability (U.S. context)
- Economic concentration: asymmetries in access to capital, land, and platform
power.
- Labor and industrial relations: automated management, surveillance, and wage-setting
risks.
- Consumer markets: opaque pricing, dark patterns, and informational gaps.
- Cross-border data flows: dependence on foreign infrastructure and model providers.
- Algorithmic governance: individuals facing opaque automated scoring, ranking,
or profiling with limited recourse.
Abkus intervenes at the product layer by refusing designs that concentrate decision power in
unreviewable models and by documenting human override paths in every high-impact workflow.
Human dignity mandate
- Technology as means, people as ends.
- Algorithms lack moral agency and cannot bear legal responsibility for professional
judgments.
- Human prudential judgment remains irreducible in financial, legal, health, and
management contexts.
Under U.S. equal-protection and anti-discrimination law (Title VII, Fair Housing Act, ECOA,
ADA), Abkus prohibits proxy discrimination and biased automated workflows. Where local law
requires it (e.g., NYC Local Law 144 for automated employment decision tools), independent
bias audits and public summaries are performed before deployment.
3. Risk taxonomy and prohibited practices
Risk-based regulation (U.S. framework)
Abkus maps product AI features to a U.S. risk taxonomy aligned with the NIST AI Risk Management
Framework, state high-risk AI laws (e.g., Colorado AI Act), and FTC guidance on automated
decision systems β not CNJ Resolution 615/2025.
Unacceptable risk Prohibited applications
Uses that violate fundamental rights or applicable U.S. law and must not be deployed:
- no meaningful human review or override path
- criminal-risk profiling of individuals without due process safeguards
- automated legal classification of persons for adjudicative effect
- biometric emotion recognition in employment, education, or access decisions where
prohibited
- practices posing unacceptable risk to civil liberties or equal protection
High risk Strict controls required
Consequential decisions requiring impact assessment, documentation, and continuous
oversight:
- profiling that materially affects employment, housing, credit, or insurance
- automated evaluation or weighting of evidence in legal or compliance workflows
- interpretation of facts as criminal or regulatory violations without human sign-off
- automated judgments on legal standard application or binding precedent
- biometric monitoring of behavior in high-stakes contexts
Low risk Auxiliary tools
Lower harm potential, with periodic review and in-product transparency:
- drafting support text and summaries
- routine procedural or administrative task assistance
- operational support workflows without autonomous final decisions
- information extraction from systems and documents
- decision-pattern detection for analytics (non-binding)
- qualified precedent or knowledge-base search
- managerial, jurimetric, and statistical reporting
- retrospective performance analysis
- audio and video transcription
- document anonymization and redaction assistance
Controls by tier (U.S.)
| Requirement | High risk | Low risk |
|---|
| Supervision | Continuous monitoring, incident response, and executive accountability. | Periodic review and change logs. |
| Assessment | Algorithmic impact assessment (AIA) / DPIA where required by state law or contract. | Lightweight change review checklist. |
| Transparency | Public or customer-facing summary of purpose, limits, and oversight mechanisms. | In-product notice that AI assisted the output. |
| Re-review | Annual reclassification at minimum; immediate review after material model change. | Review when scope or data sources change materially. |
Unacceptable-risk features are prohibited in Abkus products for the U.S. market.
All AI capabilities are tier-classified before release and reclassified when scope, data, or models
change materially.
4. Governance protocols and infrastructure
Abkus maintains an internal AI system inventory β purpose, owner, data categories, model
version, and risk tier β consistent with federal AI inventory expectations under Executive
Order 14110 and NIST GOVERN 1.2. This registry is the operational "source of truth" for
auditability and customer due diligence.
Algorithmic impact assessment checklist (high-risk systems)
- βData typology: personal, sensitive, and derived data categories processed.
- βMethodology: model type, training data provenance, and validation approach.
- βSecurity: encryption, tenant isolation, access controls, and vendor SOC 2
/ equivalent review.
- βMitigation: bias testing, red-teaming, rollback, and human-escalation paths.
Integration standards
Products implement privacy by design and privacy by default (FTC guidance; state statute
requirements). For customer-facing AI features, Abkus discloses:
- Model or service name and functional description.
- Version or release identifier.
- Internal registry identifier for enterprise customers upon request.
- Last material update date.
5. Human supervision and user responsibility
AI is advisory. Abkus mandates human-in-the-loop controls for irreversible or high-impact
actions, consistent with FTC guidance on AI claims and state laws governing automated
consequential decisions.
Obligations of users and customer administrators
- Non-binding outputs: AI suggestions do not constitute final professional, legal,
financial, or medical decisions.
- Decision authority: licensed professionals and authorized customer personnel
retain final authority.
Large language models and generative AI
- De-identification at source: regulated, confidential, or attorney-client data
must not be sent to external LLMs without contractual safeguards and de-identification where required.
- Vendor compliance: data processing agreements must prohibit unauthorized training
on customer content (enterprise API terms, zero-retention options where available).
Responsibilization layer
Under U.S. tort, contract, and sector-specific liability rules, the human user and the
deploying organization remain responsible for decisions taken on the basis of AI outputs.
Abkus, as processor or service provider where applicable, maintains security and contractual
accountability; customers acting as controllers retain compliance obligations under applicable
state privacy law.
6. Roadmap for institutional implementation
Existing Abkus AI features follow a phased compliance roadmap aligned with state law effective
dates and NIST AI RMF maturity targets. New high-risk features must meet this framework before
general availability.
- Transparency and adaptability: prefer auditable, configurable models and documented
pipelines over opaque black boxes.
- Technical isolation: tenant segregation, encryption in transit and at rest, and
least-privilege access.
- De-identification: mandatory before external API calls when personal data is
involved.
Internal AI governance function
- Trigger audits when incidents, customer complaints, or regulatory inquiries arise.
- Reclassify risk tiers when models, data sources, or use cases change.
- Maintain the AI system inventory and vendor register.
- Standardize training on bias, security, and critical review for internal operators.
- Update impact-assessment templates and public transparency summaries annually.
Success is measured by service to a free, fair, and accountable digital economy. No efficiency
gain justifies reducing human dignity. In the age of algorithms, Abkus reaffirms that
technology serves people β and that people remain accountable for the decisions they approve.