A Canadian government department wanted to use AI to process visa applications faster. Before they could deploy, they had to complete an Algorithmic Impact Assessment. Question 15: "Could this system's decisions affect someone's legal rights?" Yes. Question 23: "Will decisions be automatically made without human review?" Partially. Question 31: "Does the system use machine learning trained on historical data?" Yes. Final score: Level 3 (High Impact) Requirements triggered: → Explainability for every decision → Human review for all rejections → Quarterly bias testing → Public audit trail The department couldn't deploy until these were in place. Six months later: The system processed applications 40% faster. But monitoring revealed something interesting: Applications from certain countries were flagged for review at 3x the rate predicted. Because the assessment was public, a researcher noticed this gap. Investigation revealed the AI learned patterns from old data when those countries had different visa requirements. System was retrained. Assessment was updated. Public report explained what was learned. This is what good governance looks like: Not rules preventing deployment. Not audits finding problems later. But transparency creating continuous learning. The Canadian approach proves something crucial: You don't need complex regulations. You need organizations to commit publicly to their AI's impact, then govern the gap between promise and reality. Simple. Transparent. Effective. Why isn't everyone doing this? #AIRegulation #AIPolicy #DigitalGovernance #TechPolicy #RegulatoryCompliance
Tech Policy Advocacy
Explore top LinkedIn content from expert professionals.
-
-
✨New working paper on the trade-offs involved in AI transparency in news 🤖📝 How does a global news organisation disclose its use of AI? Where, when and how should readers be told when algorithms shape the news they consume? Based on a case study of the Financial Times and led by Liz Lohn we argue that transparency about AI in news is best understood as a spectrum, evolving with tech advancements, commercial, professional and ethical considerations and shifting audience attitudes. 🔗Pre-print: https://lnkd.in/gV3dPXgS 1️⃣ AI‑transparency ≠ a binary. At the FT it’s a hybrid of policy, process and practice. Senior leadership sets explicit principles, cross‑functional panels vet new applications, and AI use is signposted in internal/external tools and reinforced through training. 2️⃣ Disclosure is calibrated to context. Internally, full disclosure aims to reduce frictions and surfaces errors early; externally, labels are scaled with autonomy and oversight. No‑human‑in‑the‑loop features (e.g. Ask FT) get prominent warnings, whereas AI‑assisted, journalist‑edited outputs (e.g. bullet‑point summaries) get lighter labelling. 3️⃣ Nine factors shape what, when & how the FT discloses AI use. These include legal/provider requirements, industry benchmarking, the degree of human oversight, the nature of the task, system novelty, audience expectations & research, perceived risk, commercial sensitivities and design constraints. 4️⃣ Persistent challenges include achieving consistent labelling (especially on mobile), breaking organisational silos, keeping pace with evolving models and norms, guarding against creeping human over‑reliance, and mitigating against “transparency backfire” where disclosures reduce trust. For those of you more academically interested in this, we argue that AI transparency at the FT is shaped by isomorphic pressures – regulations, peer practices and audience expectations – and by intersecting institutional logics. Internally, managerial and commercial logics push for efficient adoption and risk management; externally, professional journalism ethics and commercial imperatives drive an aim to remain trustworthy. Crucially, we argue that AI transparency is best seen as a spectrum: optimising one factor (e.g. maximum disclosure) can undermine others (e.g. perceived trust or revenue). There does not seem to be a one‑size‑fits‑all rule; instead transparency must adapt to org context, audiences and technology. We are very grateful to the team at the Financial Times, particularly Matthew Garrahan, for supporting this study from the outset – and to the participants from the FT who volunteered their precious time to help us in understanding this issue. Feedback welcome, especially on the theoretical section and the discussion as well as literature that we will have missed! So feel free to plug your own or other people’s material, all of which will be appreciated as Liz and I work towards a journal submission.
-
Public blockchains present a compelling opportunity for financial institutions (FIs) to access open, interoperable infrastructure that can support innovation across payments, tokenization, and capital markets. However, their adoption in regulated financial services remains constrained by a set of structural risks and concerns that are inherent in their design. These risks are not easily mitigated by individual institutions and instead require coordinated action across the technology stack and regulatory environment. This report identifies key challenges FIs face in the use of public blockchains, and focuses on four that appear straightforward, but remain unresolved: transaction front-running, transaction omission or censorship, the receipt of unsolicited tokens, and the risk of gas fees being paid to sanctioned entities. These challenges persist due to differences in perspective, risk tolerance, and design philosophies between FIs and the broader public blockchain ecosystem. The report also identified other challenges, many of which are also experienced by non-institutional public blockchain participants. These tend to be better understood, with solutions under active development. However, even in these cases, FIs often have more stringent and nuanced requirements. For such challenges, we focus on highlighting the considerations of FIs to help ensure solutions can better address institutional needs. To evaluate potential responses, this report introduces a layered framework spanning application, smart contract, token standard, blockchain network, network governance, and regulatory layers. A key insight is that solutions that are most accessible to FIs, such as those at the application and smart contract layers, primarily mitigate symptoms rather than solve the root causes. By contrast, more effective and durable solutions reside at the protocol and governance layers, where FIs have limited direct control. Therefore, meaningful progress depends on collaboration between FIs, protocol developers, and policymakers. In the near term, FIs can adopt a range of practical mitigations, including engaging with private transaction pools, designing smart contracts with enhanced controls, and implementing operational processes to manage token flows and compliance risks. While these measures can reduce exposure, they cannot fully eliminate the underlying challenges. Over the medium to long term, more fundamental improvements are required at the blockchain network and governance layers. These include innovations such as encrypted mempools to reduce information leakage, mechanisms to improve transaction inclusion and prioritization, and adjustments to incentive structures to better align network behavior with desired outcomes. However, implementing such changes in decentralized systems is complex and requires broad ecosystem support. Report by Kinexys by J.P. Morgan and MIT Digital Currency Initiative (DCI)
-
#blockchain | #defi : The US Commodity Futures Trading Commission (CFTC) has recently released a comprehensive report addressing the challenges and opportunities in the rapidly evolving world of Decentralized Finance (DeFi). The report underscores the critical need for clear lines of responsibility and accountability within the DeFi space, urging policymakers to take proactive measures in areas such as #antimoneylaundering and #digitalidentity . Key Recommendations from the CFTC Report: 1️⃣ Resource Assessment and Mapping: Emphasizing the importance of technical capacity, the report calls for increased understanding of DeFi. Mapping existing DeFi structures will aid in highlighting interconnections, threat vectors, and potential cybersecurity vulnerabilities. The goal is to develop continuous data gathering, monitoring, information sharing, and regulatory partnerships. 2️⃣ Regulatory Perimeter Examination: The CFTC encourages a thorough examination of the regulatory perimeter, using the mapped data to determine the inclusion of DeFi products and services within the US financial regulatory framework. This includes assessing compliance levels, identifying regulatory gaps, and potentially expanding frameworks to address associated risks. 3️⃣ Risk Identification and Prioritization: The report delves into various risks such as asymmetric information, operational vulnerabilities, liquidity mismatches, and market manipulation. Understanding the financial and technological complexity of DeFi compositions is crucial. This includes evaluating risks related to algorithmic failures, concentration, and illicit finance. 4️⃣ Policy Responses: To address identified risks, the CFTC proposes a range of potential policy responses. These include measures like disclosure, regulatory reporting, third-party auditing, entry restrictions, governance regulation, and more. Striking the right balance between #innovation and risk mitigation is at the core of these proposed responses. 5️⃣ Engagement and Collaboration: Fostering greater engagement and collaboration with domestic and international standard setters, regulatory efforts, and DeFi builders is highlighted as a key step. This collaborative approach aims to create a well-informed and adaptive regulatory environment for the evolving DeFi landscape. The CFTC's report marks a significant milestone in the ongoing dialogue surrounding DeFi regulation. As the industry continues to mature, these recommendations provide a solid foundation for shaping policies that balance innovation and risk management. 💡🌐 #DeFi #Regulation #InnovationInTheFuture
-
Kevin Klyman: "📣📣 We just published the third annual Foundation Model Transparency Index! Our comprehensive study shows that AI companies have become less transparent in 2025. Some highlights from the paper: ➡️ Transparency on the decline: The average transparency score for AI companies declined from 58/100 in 2024 to 40/100 in 2025. xAI scores lower than any company we have ever assessed, releasing almost no information about its practices or its flagship model. ➡️ Companies withhold key information: Top tech companies release little or no information about the environmental impact of AI, whose data they use to build their systems, or whether the risk mitigations they put in place actually work. We definitively show that this information is not publicly available and that companies refuse to release it. ➡️ Companies share the capabilities of their models, but do not adequately evaluate risks. Just 4 of 13 companies comprehensively evaluated risks prior to release of their foundation model and report results upon release, and only IBM releases an externally reproducible risk evaluation. ➡️ Companies have changed their practices to release less information. In 2024, Meta and Mistral released technical reports alongside their flagship models (Llama 2 and Mistral 7B), but in 2025 neither released technical reports (for Llama 4 and Mistral Medium 3 respectively). As a result, Meta no longer discloses which risk mitigations it uses, quantitative evaluations of those risk mitigations, the amount and type of hardware it used to train its model, or prohibited model behaviors. ➡️ Our method: We break down transparency of AI companies into 100 indicators, develop concrete definitions and rubrics for those indicators, and send each company a transparency report template to fill out. This year 7 companies filled out the transparency report, and we independently assessed 6 other companies. We then worked with these companies to help them improve their disclosures, often resulting in companies disclosing new information to the public. You can read the full paper in the comments below! Thanks to the team behind the index - Alex Wan, Sayash Kapoor, Nestor Maslej, Shayne Longpre, Betty Xiong, Percy Liang, Rishi Bommasani! I'd also like to thank Stanford Institute for Human-Centered Artificial Intelligence (HAI) for supporting this work, Loredana Fattorini for making the visuals, and the Foundation Model Transparency Index board for their guidance Dr. Rumman Chowdhury, Daniel Ho, Arvind Narayanan, Danielle Allen and Daron Acemoglu. "
-
Explainable AI strengthens accountability and integrity in automation by making algorithmic reasoning transparent, ensuring fair governance, detecting bias, supporting compliance, and nurturing trust that sustains responsible innovation. Organizations that aim to integrate AI responsibly face a common challenge: understanding how decisions are made by their systems. Without clarity, compliance becomes fragile and ethics remain theoretical. Explainable AI brings visibility into this process, translating complex model logic into a language that regulators, auditors, and executives can actually understand. Transparency is not a luxury. It is a structural requirement for building trust in automated decision-making. When models are explainable, teams can trace outcomes, identify hidden biases, and take timely corrective action before risk escalates. This level of insight also helps align technology with existing regulatory frameworks, from GDPR principles to sector-specific governance standards. Embedding explainability within AI governance frameworks creates a bridge between innovation and responsibility. It helps organizations evolve without compromising accountability, ensuring that progress remains both human-centered and sustainable. #ExplainableAI #EthicalAI #AIGovernance #Compliance #Trust
-
G7 cybersecurity agencies, including Cybersecurity and Infrastructure Security Agency, have released a “Software Bill of Materials for AI: Minimum Elements,” which provides a practical baseline for what organizations should expect in an AI SBOM. It is not mandatory and does not create new requirements, but it details recommended minimum elements to improve cyber and supply chain transparency for AI systems. Some of the recommended elements include: ✅ Model information - model name, version, producer, hash value/hash algorithm, license, training properties, and model description/known limitations. ✅ Dataset information - dataset provenance, sensitivity, license, hash, and dependency relationships. ✅ Security properties - security controls, compliance information, cybersecurity policy information, and vulnerability references. ✅ Infrastructure details - software and hardware dependencies needed to run and support the AI system. Why does this matter? Imagine your organization is using a third-party AI model in a customer support workflow. A new vulnerability or licensing issue emerges around one of the model’s dependencies, training datasets, or deployment frameworks. Without an AI SBOM, your team may not know whether you are exposed. With one, especially when tied into your asset inventory, model registry, third-party risk process, or vulnerability management workflow, the security team can quickly answer: ❓ Where is this model used ❓Which version is deployed ❓Who produced it ❓What datasets or dependencies are involved ❓What security controls are in place No Log4j-era guessing. It is the foundation for robust management of AI supply chain risk. Closely related is the important community work led by Helen Oakley , alongside Daniel Bardenstein and Dmitry R., on AI BOM implementation. At RSAC2025, Helen introduced an open-source tool for generating AI SBOMs for Hugging Face models using the CycloneDX format, with human-readable quality indicators. That community work is complementary to the CISA/G7 guidance, which gives us a public-sector consensus baseline for cyber and supply chain transparency. The SBOM for AI / AIBOM work on GitHub gives teams a practical path to implementation mapping fields to CycloneDX and SPDX AI Profile-compatible formats and integrating into engineering and risk workflows. The CISO takeaway: 💠 Use the CISA/G7 minimum elements as the baseline. Start asking AI vendors and internal AI teams for AI SBOMs. 💠 Use the AIBOM community work to understand how AI BOMs can be implemented in practice. 💠 And tie the output into third-party risk, model governance, vulnerability management, and incident response. AI supply chain transparency is a critical AI security control, not just a documentation exercise. Sources: https://lnkd.in/enH9vK3t https://lnkd.in/ebV-_2Hv https://lnkd.in/eydmfD98
-
📣 The EU just took a big step toward real AI transparency. The European Commission has released a template for General-Purpose AI (GPAI) providers to publicly summarize the data used to train their models. This isn't about exposing trade secrets, it's about setting a common baseline for trust and accountability. Why this matters: 🔹 It gives developers, regulators, and rights-holders a shared format to compare disclosures. 🔹 It finally enables informed discussions around copyright, consent, and bias. 🔹 It puts structure around Article 53 of the AI Act, moving from principles to practice. 🔹 And crucially, it offers a proportional, phased approach: companies have until August 2026 to comply. But let’s be honest: the debate isn’t over Some industry voices fear the template could edge too close to revealing competitive know‑how or even “facilitate theft” by mapping where value lies. Expect pushback and iterative refinement as practice meets principle. Still, not moving was never an option (in my humble opinion) opacity was eroding public trust and legal certainty. 💢 I have been involved in responsible AI development for decades, as a Digital EU Ambassador, I see this as a pragmatic and much-needed move. The future of AI depends on earned trust and that starts with clarity. 🔗 Press release: https://lnkd.in/eQMtadZq 🔗 Explanatory notice + template: https://lnkd.in/egsr-smw The below picture was created by Adobe Stock
-
Our paper on transparency reports for large language models has been accepted to AI Ethics and Society! We’ve also released transparency reports for 14 models. If you’ll be in San Jose on October 21, come see our talk on this work. These transparency reports can help with: 🗂️ data provenance ⚖️ auditing & accountability 🌱 measuring environmental impact 🛑 evaluations of risk and harm 🌍 understanding how models are used Mandatory transparency reporting is among the most common AI policy proposals, but there are few guidelines available describing how companies should actually do it. In February, we released our paper, “Foundation Model Transparency Reports,” where we proposed a framework for transparency reporting based on existing transparency reporting practices in pharmaceuticals, finance, and social media. We drew on the 100 transparency indicators from the Foundation Model Transparency Index to make each line item in the report concrete. At the time, no company had released a transparency report for their top AI model, so in providing an example we had to build a chimera transparency report with best practices drawn from 10 different companies. In May, we published v1.1 of the Foundation Model Transparency Index, which includes transparency reports for 14 models, including OpenAI’s GPT-4, Anthropic’s Claude 3, Google’s Gemini 1.0 Ultra, and Meta’s Llama 2. The transparency reports are available as spreadsheets on our GitHub and in an interactive format on our website. We worked with companies to encourage them to disclose additional information about their most powerful AI models and were fairly successful – companies shared more than 200 new pieces of information, including potentially sensitive information about data, compute, and deployments. 🔗 Links to these resources in comment below! Thanks to my coauthors Rishi Bommasani, Shayne Longpre, Betty Xiong, Sayash Kapoor, Nestor Maslej, Arvind Narayanan, Percy Liang at Stanford Institute for Human-Centered Artificial Intelligence (HAI), MIT Media Lab, and Princeton Center for Information Technology Policy
-
When I was leading the blockchain/DLT implications for insurance workstream at EIOPA some years ago, data protection—particularly GDPR-related issues—frequently emerged as a key area of uncertainty and a potential barrier to innovation. For example, some solutions never progressed beyond the proof-of-concept stage due to significant legal uncertainty surrounding data protection legislation. In the diagnostic work, we also highlighted the importance of engaging with other supervisory authorities beyond the insurance domain, including data protection bodies. That’s why I’m pleased to see that the European Data Protection Board (EDPB) has just adopted guidelines on the processing of personal data through blockchains. The Board emphasises the importance of supporting organisations in ensuring compliance with the GDPR when using these technologies. The guidelines explain how blockchain works, assess various architectures, and examine their implications for personal data processing. Key points include the need to implement technical and organisational measures from the earliest design stages, and to assess the roles and responsibilities of all actors involved in blockchain-related processing of personal data. Organisations are also advised to conduct a Data Protection Impact Assessment (DPIA) before initiating blockchain-based processing where a high risk to individuals’ rights and freedoms is likely. The EDPB stresses that personal data should not, by default, be accessible to an indefinite number of people. The guidelines provide examples of techniques for data minimisation, as well as approaches for handling and storing personal data. As a general principle, storing personal data on a blockchain should be avoided where it would conflict with data protection rules. Finally, the Board underscores the importance of upholding individuals’ rights—particularly in terms of transparency, rectification, and erasure of personal data. Do you think it is helpful to increase legal certainty? __________ ♻️ Found this useful? Repost it for your colleagues and subscribe to my insurtech4good.com newsletter to stay updated on the latest InsurTech news.