The Artificial Intelligence Amendment
I. The Governance Vacuum
Every prior constitutional amendment in this volume responds to a concentration of power that already existed when it was drafted. In government, in markets, in the drawing of a map. Artificial intelligence is different in one important respect: the concentration of power it enables is still accelerating, and the institutions meant to govern it are, by design, temporary. An executive order can be rescinded by the next administration in a single stroke. A state statute can be preempted by the next Congress, or by an Attorney General’s litigation task force organized for exactly that purpose. Only a constitutional floor survives a change of administration, and artificial intelligence, more than any technology this country has regulated before, is being built and deployed at a pace that outruns the amendment cycle of ordinary politics.
The federal government’s actual record on AI governance illustrates the problem rather than solving it. Congress has enacted exactly one AI-specific statute, the TAKE IT DOWN Act, addressing non-consensual intimate imagery. And has twice rejected proposals for a broader federal moratorium on state AI regulation, without ever replacing that patchwork with a comprehensive law of its own. In its place, the executive branch has issued a rotating sequence of policy documents: a January 2025 order removing regulatory barriers to AI development, a July 2025 “AI Action Plan,” a December 2025 “AI National Policy Framework,” a March 2026 “National AI Legislative Framework,” and, in June 2026, an executive order establishing an AI cybersecurity clearinghouse and directing the Attorney General to challenge state AI laws as unconstitutional interference with interstate commerce. Each of these instruments can be, and most likely will be, superseded by the next administration’s own sequence of orders. None of them binds a court. None of them survives a change in the White House. A private company deciding how to build and deploy a frontier model is, at the federal level, navigating guidance rather than law.
II. A Lesson From Europe
The European Union’s experience cuts the other way but proves the same point from a different angle. The EU AI Act entered into force in August 2024 promising a comprehensive, binding, risk-tiered regime for exactly the systems this proposed Article addresses. By May and June 2026, under pressure from industry and member states, the Council and Parliament had agreed to a “Digital Omnibus” that pushed the compliance deadlines for most high-risk AI obligations back by sixteen months, to December 2027, with product-embedded systems deferred even further, to August 2028. A binding statute, even a carefully drafted one, is a target that shifting political coalitions can and will renegotiate. A constitutional floor, by contrast, is not renegotiated by the next legislative session, which is precisely why the rights this volume proposes for citizens generally are placed in the Constitution and not left to statute, and precisely why the same logic applies to the systems now making or materially informing decisions about those citizens’ employment, credit, housing, and liberty.
III. What Changed: The Black Box Opens
There is also a narrower, more technical reason this Article is necessary now rather than five years ago: for most of the history of neural networks, meaningful oversight of what was actually happening inside one was not technically possible. A large model was, for practical and regulatory purposes, a black box. You could observe its inputs and outputs, but not the internal computation connecting them. That has changed. Mechanistic interpretability, the discipline of identifying the internal representations and decision pathways inside a trained neural network was named one of MIT Technology Review’s ten breakthrough technologies of 2026. Anthropic’s interpretability research has progressed from identifying features corresponding to individual recognizable concepts inside a model to tracing complete computational paths from a prompt to a response. And the company has begun using these tools as part of the pre-deployment safety assessment of its own frontier models. The first documented instance of interpretability research being used to inform an actual deployment decision for a production AI system, rather than remaining a research curiosity. Google DeepMind has released comparable open-source tooling covering an entire family of models. A regulatory mandate to monitor the internal behavior of a covered AI system was aspirational in 2020. It is achievable, though not yet trivial, in 2026, which is exactly the condition under which a legal obligation to do it becomes reasonable to impose.
IV. Why Watching Outputs Is Not Enough
The same 2025 to 2026 research also supplies the clearest evidence of why monitoring outputs alone is not enough. Interpretability researchers have documented that advanced reasoning models can produce a chain of stated reasoning that does not match the actual computation the model used to reach its answer. A model’s explanation of itself can be unfaithful to what it is actually doing, whether by omission or by something closer to concealment. A regulatory regime that reviews only a system’s outputs, or only the explanation a system offers for those outputs, is reviewing what the system has chosen to show. A regime capable of examining the system’s internal state is reviewing what the system is actually doing. The distinction is not academic: it is the difference between a company’s compliance filing and an audit.
V. A Concern That Touches Every HARP
None of this is unique to any single right; artificial intelligence now touches nearly every dimension of economic and civil life. It can determine who is approved for a loan or a lease, affecting equal access to opportunity. It can be used by a dominant platform to model and undercut the businesses that depend on it, affecting the ability of ordinary market participants to compete on fair terms. It can be trained on, and can generate conclusions about, information a citizen never consented to share, affecting a citizen’s basic security of person. What a constitutional amendment can do that a sector-specific statute cannot is state, once, which rights govern all of these uses at once rather than legislating a separate answer for lending, a separate answer for hiring, and a separate answer for policing, each vulnerable to being weakened in isolation.
VI. A Floor Drawn From a Text That Already Exists
That is the reason this Article’s human-rights floor is drawn from, rather than invented apart from, the Universal Declaration of Human Rights. The Declaration, adopted by the United Nations General Assembly in 1948, is the closest thing the world has to an agreed moral floor beneath any government’s laws. But a full, open-ended incorporation of all thirty articles of the Declaration as directly enforceable law against every covered AI system would import ambiguity this Article cannot afford: some of what the Declaration proclaims is properly understood as aspirational, not judicially administrable, and a court asked to enforce “the right to rest and leisure” or “a standard of living adequate for health and well-being” against an algorithm has been handed a mandate the text was never drafted to bear as binding law.
Section 2 resolves that tension the same way this book resolves it everywhere else: by turning a broad principle into an enforceable rule. It lists the specific rights that a covered AI system may not be used to violate: non-discrimination, human dignity, privacy, security of person, and existing employment protections. Each of these rights is drawn directly from, and must be read consistently with, the matching article of the Declaration: non-discrimination from Articles 2 and 7, dignity from Article 1, privacy from Article 12, the right to life, liberty, and security from Article 3, and just conditions of work from Article 23.
The Declaration remains the anchor and the guide for interpreting these rights. What changes is that a court applying this Article now works from a finite, workable list of rights, rather than having to decide on its own which of thirty articles a machine learning system may have violated.
Section 2 also states explicitly what was previously left to inference: this Article governs the design, training, deployment, and operation of a covered AI system and its use to make or inform a decision about a person. It does not regulate what a covered AI system generates, publishes, or helps a person say, and it does not judge a system’s output by its viewpoint or content. Artificial intelligence does not need a bespoke bill of rights, and this Article does not police what an AI system, or the person using it, chooses to express. It needs to be held, explicitly and by name, to the same non-discrimination, dignity, privacy, and due-process floor this country has spent two hundred fifty years learning to demand of every other kind of consequential power when that power is used to decide something about a person, not when it is used to say something.
This Article also closes a narrower but increasingly urgent gap: the difference between a communication a person has agreed to receive, or already has a relationship with the sender, and one an automated system generates and sends to a stranger on its own initiative. Section 6 permits a covered AI system to initiate a call, text, or email to a specific person only where that person has consented to receive it, has an existing relationship with the sender, or the communication falls within a narrow set of recognized categories: a government emergency alert, a response to a request the person made, or a genuinely non-commercial political, religious, charitable, or public-interest message. Every AI-generated or AI-assisted communication permitted under that framework must say so, and must give the recipient a working way to opt out. And regardless of consent or relationship, no system may impersonate a real person's voice or likeness without that person's consent, full stop.
A violation, including the non-consensual use of a synthesized voice or likeness to impersonate a real person, carries statutory damages of not less than five hundred dollars per violation, giving the individual harmed a remedy that does not depend on proving the kind of measurable financial loss this type of intrusion rarely produces. Impersonation carries that remedy without regard to consent or relationship; nothing excuses it.
“A system that cannot be inspected cannot be held accountable, and a right that no institution is bound to enforce is not a right. This Article is written to close both gaps at once.”
VII. Objections Considered
A serious objection deserves to be answered directly: does binding artificial intelligence to a human rights floor, and requiring interpretability monitoring before and during deployment, risk driving frontier AI development out of the United States and into jurisdictions with no such requirement? The honest answer is that some marginal effect of that kind is possible, and this Article does not pretend otherwise. But the same objection was raised, and proved substantially overstated, against securities disclosure requirements, against automobile safety standards, and against comparable data-privacy protections. A firm capable of building a frontier model is a firm capable of building the monitoring infrastructure this Article requires; the interpretability tools described above already exist inside the frontier labs most capable of the systems this Article is most concerned with. What this Article forecloses is not advanced capability. It forecloses advanced capability deployed without anyone, including the company that built it, being able to say with confidence what the system is actually doing and whether that use is consistent with the rights of the people subject to it.
A related objection is that anchoring these rights to the Universal Declaration risks importing an external, evolving body of international law into the United States Constitution, effectively letting a foreign tribunal or a later international agreement reshape a domestic constitutional right over time. Section 2(b) forecloses that risk by design. It anchors only to the fixed text of the Declaration as adopted on December 10, 1948, and it says so expressly: no subsequent international agreement, foreign tribunal decision, or evolving international norm may be given interpretive weight under this Article. The Declaration functions here the way a law dictionary functions: fixed at a moment in time, consulted for the meaning of a term, not a living treaty whose content drifts with the practice of other nations.
The second objection is that regulating artificial intelligence risks becoming, in practice, regulating speech. This is a real concern. State AI statutes are currently being challenged on First Amendment grounds, and the Supreme Court recognized in Moody v. NetChoice, 603 U.S. 707 (2024), that curating and presenting expressive content is itself an expressive act entitled to real constitutional scrutiny.
Section 2(c) answers this directly, rather than leaving it to inference. This Article regulates the decisional use of a covered AI system: its role in deciding whether a person gets a loan, a job, or a parole date. It does not regulate the content that system or its user generates, publishes, or expresses. A chatbot's output remains speech, governed by the law that already governs speech.
What loses constitutional protection under this Article is not an AI system's expression. It is the use of that system as an unaccountable decision-maker over a person's employment, credit, housing, or liberty.
A related concern is Section 6 specifically: does a rule governing who may initiate an automated call, text, or email risk becoming an unconstitutional restriction on speech in its own right, particularly for political campaigns, nonprofits, religious organizations, and the press that rely on automated outreach at scale? Section 6 instead follows the model Congress itself has used since 1991 in the Telephone Consumer Protection Act, and that courts have repeatedly upheld: automated contact with a stranger requires consent or an existing relationship, every AI-generated message must say so, and the recipient always gets a working way to say stop. A campaign, a congregation, or a newsroom that already has a relationship with the people it contacts, or that obtains consent before reaching new ones, loses nothing. What the Section forecloses is unsolicited automated contact with someone who has never agreed to hear from the sender at all, dressed up to look human when it is not, which is precisely the kind of unwanted, deceptive intrusion the TCPA framework was built to stop without banning any viewpoint or any speaker.
The third objection concerns Section 7’s funding mechanism: does guaranteeing the Commission a funding floor, self-executing if Congress fails to appropriate, improperly bypass Congress’s appropriations power? The Supreme Court answered a closely related question in CFPB v. Community Financial Services Association, 601 U.S. 416 (2024), upholding a federal financial regulator’s standing, non-annual funding mechanism precisely because Congress had authorized it in advance, in specific and bounded terms, rather than ceding open-ended control over its own purse. Section 7(c) is built the same way: a specific, bounded floor, established directly by this Article rather than left to ordinary appropriations politics, that Congress remains free to exceed by law at any time. It protects the Commission from being defunded into irrelevance by a hostile Congress; it does not, and cannot, prevent Congress from funding it more generously.
A closely related structural question is whether the Commission's members are properly insulated from at-will presidential removal, and if so, whether that insulation is itself constitutional. This Article answers both parts directly: a Commissioner may be removed before the end of a term only for material neglect of duty or material abuse of authority, established by clear and convincing evidence, not at the President's discretion. That structure is not the single-director, removal-protected agency the Supreme Court held unconstitutional in Seila Law v. CFPB, 591 U.S. 197 (2020); it is the multi-member, politically balanced commission model the Court has upheld since Humphrey's Executor v. United States, 295 U.S. 602 (1935), and left undisturbed in Seila Law itself. The Commission also does not impose penalties on its own authority. It sets technical standards, investigates, and refers; a penalty under Section 9 is imposed only by an Article III court, consistent with the jury-trial requirement the Supreme Court applied to comparable civil penalties in SEC v. Jarkesy, 603 U.S. 109 (2024).
The fourth objection is that a private right of action against any deploying entity, without more, invites either speculative litigation or, if courts demand a showing of real harm, no enforcement at all. Section 8 answers this directly: a plaintiff must show the same concrete, particularized injury federal courts already require for a constitutional or statutory claim under TransUnion LLC v. Ramirez, 594 U.S. 413 (2021), not merely a generalized grievance that a covered AI system exists and might someday affect someone. That standard does not eliminate the private right of action; it channels it toward the person the system actually harmed.
A further objection concerns Section 9's penalties: does a minimum civil penalty running into the hundreds of thousands or millions of dollars per violation, without regard to a deploying entity's culpability, size, or good-faith effort to comply, risk becoming an excessive fine of the kind the Eighth Amendment forbids, as the Supreme Court explained in United States v. Bajakajian, 524 U.S. 321 (1998)? This Article draws the distinction Bajakajian requires. A knowing and willful violation of the core discrimination, dignity, privacy, and safety protections in Sections 2 and 4 carries a real minimum penalty, because a deliberate violation of those protections is exactly the conduct this Article exists to deter. A negligent or unknowing violation does not carry a mandatory minimum at all; a court sets the penalty, if any, after weighing the harm, the entity's culpability and ability to pay, and whether it self-reported and fixed the problem, and a good-faith compliance effort that is promptly corrected is a complete defense. The severe end of the penalty scale is reserved for the entities this Article is actually written to reach.
A separate objection concerns Section 2's privacy protection and Section 4(b)'s biometric-identification exception: what counts as a person's consent or as lawful legal process for purposes of the privacy right, and what do real-time, general-purpose, and publicly accessible actually mean when a covered AI system is scanning a crowd? Left undefined, each term could be read narrowly enough to gut the protection or broadly enough to reach conduct never intended to be swept in. Section 1(g) defines all five terms directly. Consent must be freely given, specific to the use at issue, and never inferred from silence or a general terms-of-service click. Lawful legal process means a warrant, subpoena, or court order under a standard no weaker than what already governs the same category of information offline. And the biometric exception in Section 4(b) is confined to identification happening in the moment, aimed at the public generally rather than at a named individual, and outside spaces such as a clinic or house of worship where a reasonable expectation of privacy survives being in public.
Section 3(c) answers a related threshold concern the same way: rather than granting a future technical standard an unreviewable presumption of validity, the standard is entitled only to deference proportionate to the reasoning and evidence behind it, and a court must set aside one that is arbitrary, capricious, or not reasonably achievable. A final set of objections concerns whether the Article's own key terms, dignity, deceptive behavior, a concealed capability, meaningful and timely and informed human authorization, ordinary advertising, are precise enough to give a regulated company fair notice of what is prohibited, and whether the interpretability and disclosure duties in Sections 3 and 5 ask a company to do something no current technology can actually do. This Article defines each of those terms directly rather than leaving them to case-by-case inference, and it ties every technical duty, interpretability analysis, continuous monitoring, and the explanation a person is owed under Section 5, to what is reasonably achievable using methods generally accepted in the technical standards Congress and the Commission must keep current, not to a fixed and potentially impossible standard. Where a system's behavior genuinely cannot be reduced to the factors Section 5 asks for, the company must say so rather than invent an explanation it cannot stand behind. And a system that is covered only because of its size, not because it is used to decide something about a person, answers to the monitoring duty in Section 3 alone, not to the full weight of Sections 4, 5, 6, 8, and 9. The Article asks a company to do what the state of the art actually allows, not what a regulator wishes were possible.
VIII. What an AI System Bound by Human Rights Looks Like
The alternative to a constitutional floor is not the status quo. It is a continuing cycle in which each new administration’s executive orders are undone by the next, each state’s protective statute is challenged by a federal litigation task force organized to preempt it, and the only durable constraint on how artificial intelligence is built and used in the United States is whatever a handful of companies choose to impose on themselves. This Article proposes something more durable than that.
In a system governed by this Article, no company deploying a system capable of denying a person a loan, a job, or a parole date can honestly say it does not know why the system reached that result, because the law requires that it be able to look inside the system and find out, before the decision is made and again afterward. No government agency can deploy a surveillance system that watches every face in a public square and claims it is merely following an executive order, because the floor beneath that order is a constitutional right the order cannot lower. And no citizen denied an opportunity by an automated system is left arguing with a machine: there is a human being, identifiable and accountable, whose job it is to look at the case again.
This does not slow artificial intelligence down for its own sake, and it does not pretend the technology is something to be feared rather than governed. It says only what this volume says about every other concentration of power it addresses: that a capability this consequential cannot be left to govern itself, and that the people affected by it are entitled to the same floor of dignity, non-discrimination, and due process this country has spent two hundred fifty years learning to demand of every other kind of power. Artificial intelligence is not exempt from that demand merely because it is new. It is subject to it because it is powerful.
Finally, this Article is written so that no single flawed provision can be used to unravel the whole of it. If a court finds one Section wanting, the rest stands; that has always been the more responsible reading of a document this consequential, and this Article says so in its own text rather than leaving the question to chance.
PROPOSED CONSTITUTIONAL AMENDMENT
Article [ ] — The Artificial Intelligence Amendment
Section 1. Definitions. For purposes of this Article:
(a) “Covered artificial intelligence system” means any artificial intelligence system that is either (i) trained using a neural network architecture with a quantity of computation, as measured in a manner established by law, exceeding a threshold established through the technical standards process under Section 3(c), or (ii) deployed to make or materially inform a consequential decision.
(b) “Neural network” means a computational architecture composed of interconnected nodes organized in layers and trained on data to approximate a function, including systems described as deep learning systems, large language models, or foundation models.
(c) “Consequential decision” means a decision materially affecting an identifiable natural person’s access to employment, credit, housing, healthcare, education, insurance, government benefits, criminal justice outcomes, or the exercise of a right protected by this Constitution.
(d) “Deploying entity” means any natural person, corporation, limited liability company, partnership, limited liability partnership, joint venture, unincorporated association, cooperative, nonprofit or not-for-profit organization, religious organization, trust, or other legal entity however organized, and any agency, department, instrumentality, or political subdivision of federal, state, tribal, or local government, that makes a covered artificial intelligence system available for use, whether directly or through an intermediary, within the United States.
(e) “Materially inform” and “materially affecting,” as used in this Article, mean that a covered artificial intelligence system’s output is a substantial factor actually relied upon in reaching the decision, and not merely one source of information available to, but not meaningfully relied upon by, a human decision-maker who exercises independent judgment.
(f) Scope of application by trigger. A system that is a covered artificial intelligence system solely because it satisfies subsection (a)(i), and that is not deployed to make or materially inform a consequential decision and is not used for a purpose described in Section 4(b) or (c), is subject to Section 3 but is not subject to Sections 4(a), 5, 6, 8, or 9 unless and until it is also deployed to make or materially inform a consequential decision or for a purpose described in Section 4(b) or (c).
(g) Other definitions. As used in this Article:
(i) “Dignity” means treatment of a natural person as an individual possessing inherent worth, rather than solely as an interchangeable input to be sorted, scored, or disposed of for administrative convenience, without any opportunity for that person to contest the classification.
(ii) “Deceptive behavior” means conduct or output of a covered artificial intelligence system that a reasonable developer or deploying entity, exercising the diligence required by Section 3, would recognize as intended to, or reasonably likely to, cause a human evaluator to hold a materially false belief about the system's capabilities, reasoning process, or compliance with this Article.
(iii) “Concealed capability” means a capability of a covered artificial intelligence system that the deploying entity knew, or through the diligence required by Section 3 should have known, the system possessed, and that was not disclosed as required by Section 3(d).
(iv) “Material to the risks addressed by this Article” means bearing directly on a covered artificial intelligence system's potential to discriminate, to cause physical or significant financial harm, to deceive a human evaluator, or to affect the outcome of a consequential decision, and does not include a capability with no reasonably foreseeable bearing on those risks.
(v) “Meaningful,” “timely,” and “informed,” as used in Section 4(c), mean, respectively: that the authorizing individual retains genuine authority to decline or alter the specific engagement and is not merely ratifying a decision already made by the system; that the authorization occurs with sufficient time for actual reconsideration rather than as a pro forma formality; and that the authorizing individual is given accurate, material information about the basis for the system's recommendation before authorizing.
(vi) “Ordinary advertising, marketing, or persuasive communication,” as used in Section 4(d), means a technique consistent with those generally disclosed in the deploying entity's public-facing privacy or advertising policy and not specifically designed to exploit a psychological or physical vulnerability of a particular natural person that the deploying entity has actually identified.
(vii) “Real-time,” “general-purpose,” and “publicly accessible,” as used in Section 4(b), mean, respectively: that the biometric identification occurs contemporaneously with the collection of the biometric data, rather than through subsequent comparison against a previously compiled record; that the identification system is not configured or deployed to locate one or a small number of specific, individually identified persons pursuant to a particular investigation or warrant; and that the space is one to which the public has general access without an individualized invitation, excluding a space in which a person retains a reasonable expectation of privacy notwithstanding that access, such as a medical, counseling, or religious facility.
(viii) “Consent” and “lawful legal process,” as used in Section 2(a)(iii), mean, respectively: a natural person's freely given, specific, and revocable agreement to the particular collection or use at issue, which shall not be inferred from silence, inaction, or acceptance of a general terms-of-service agreement; and a warrant, subpoena, or court order issued under a standard no less protective than the standard that would apply to the same category of information in a non-digital form, or an emergency circumstance recognized by law.
Section 2. Human Rights Floor for Artificial Intelligence.
(a) No covered artificial intelligence system shall be designed, trained, deployed, or operated in the United States in a manner that:
(i) discriminates against a natural person on the basis of race, color, sex, religion, national origin, disability, or another characteristic on which discrimination is prohibited by federal law, in a manner not justified by a legitimate, non-discriminatory, and demonstrable purpose;
(ii) subjects a natural person to inhuman or degrading treatment, or treats a natural person as an object to be sorted, scored, or disposed of rather than as an individual entitled to dignity;
(iii) invades a natural person’s reasonable expectation of privacy in their communications, location, health data, financial data, or biometric or genetic data, without consent or lawful legal process;
(iv) deprives a natural person of life, liberty, or security of person without the due process this Constitution otherwise requires; or
(v) is used to make an employment decision in a manner that would violate a natural person’s rights under otherwise applicable federal labor and employment law if that decision had been made by a human decision-maker.
(b) The rights enumerated in subsection (a) are drawn from, and shall be construed consistently with, the fixed text of the Universal Declaration of Human Rights as adopted by the United Nations General Assembly on December 10, 1948, respectively, the non-discrimination guarantees of Articles 2 and 7, the dignity clause of Article 1, the privacy protection of Article 12, the security-of-person guarantee of Article 3, and the just-conditions-of-work guarantee of Article 23. Where a right enumerated in subsection (a) is ambiguous, a court shall resolve that ambiguity by reference to the text of the corresponding article of the Declaration and to the definitions established in Section 1 of this Article, and to no other source. No subsequent international agreement, foreign tribunal decision, or evolving international norm not embodied in the fixed 1948 text of the Declaration or in this Article's own definitions shall be given any interpretive weight under this Article.
(c) This Section governs the design, training, deployment, and operation of a covered artificial intelligence system and its use to make or materially inform a decision about a natural person. It does not restrict, and shall not be construed to restrict, the content a natural person may generate, publish, or receive using a covered artificial intelligence system, and it does not regulate a covered artificial intelligence system’s output on the basis of its viewpoint or content. A claim that a covered artificial intelligence system’s output is itself unlawful is governed by the law otherwise applicable to that content, not by this Section.
(d) No statute, regulation, executive order, or private agreement shall authorize a use of a covered artificial intelligence system that would violate subsection (a).
Section 3. Neural Network Monitoring and Interpretability Mandate.
(a) A deploying entity shall not deploy a covered artificial intelligence system unless the system has undergone interpretability analysis, using techniques identified as generally accepted in the technical standards established under subsection (c) and reasonably achievable given the state of the art, reasonably capable of identifying the system's internal representations, decision pathways, and capabilities material to the risks addressed by this Article, conducted prior to deployment and at intervals thereafter established by law.
(b) A deploying entity shall maintain continuous monitoring of a covered artificial intelligence system's outputs and, where technically feasible under the technical standards established under subsection (c), its internal states, sufficient to detect deceptive behavior, concealed capabilities material to the risks addressed by this Article, and outputs inconsistent with Section 2.
(c) Congress shall establish by law minimum technical standards for interpretability analysis and monitoring under this Section, and the computation threshold required by Section 1(a), to be updated not less frequently than every two years to reflect the state of the art, in consultation with the Commission established by Section 7. A technical standard established under this subsection is entitled to deference proportionate to the reasoning and evidence supporting it, but a court shall set aside a technical standard, or a deploying entity's compliance obligation under it, that is arbitrary, capricious, manifestly inconsistent with the state of the art, or not reasonably achievable by a deploying entity exercising good-faith diligence.
(d) A deploying entity that discovers, through monitoring under this Section or otherwise, that a covered artificial intelligence system has engaged in deceptive behavior, possesses a capability, or acted inconsistently with Section 2, shall report that discovery to the Commission within a period established by law. No deploying entity, officer, or employee reporting in good faith under this subsection shall be subject to retaliation.
Section 4. Prohibited Uses. No covered artificial intelligence system shall be used, regardless of consent, to:
(a) assign a score to a natural person, based on that person’s social behavior, personal characteristics, or predicted characteristics, that determines the person’s access to opportunities, goods, services, or public benefits in a context unrelated to the context in which the underlying data was gathered, except that this subsection does not prohibit a score used solely to assess a specific, contemporaneous transaction for fraud, credit, or security risk directly relevant to that transaction;
(b) conduct real-time, general-purpose biometric identification of natural persons in publicly accessible spaces for law enforcement purposes, except pursuant to a warrant supported by probable cause or a judicially recognized exigent circumstance;
(c) select and engage a lethal weapon against a natural person without meaningful, timely, and informed human authorization, as those terms are defined in Section 1(g)(v), of that specific engagement;
(d) materially manipulate a natural person's behavior through a technique operating below that person's level of conscious awareness, in a manner that causes or is reasonably likely to cause significant harm to that person or another; this subsection does not reach ordinary advertising, marketing, or persuasive communication defined in Section 1(g)(vi); or
(e) make a final, non-reviewable consequential decision without the opportunity for human review described in Section 5.
Section 5. Transparency and Human Oversight Rights.
(a) A natural person is entitled to know, upon reasonable request and without cost, when a covered artificial intelligence system has materially contributed to a consequential decision concerning that person, and to receive an explanation of the principal factors involved, to the extent that explanation is technically feasible using methods generally accepted in the technical standards established under Section 3(c), stated in terms reasonably capable of being understood by a layperson. Where the principal factors cannot be identified using those methods, the deploying entity shall disclose that limitation together with whatever factors can be identified; nothing in this Section requires a deploying entity to furnish an explanation it cannot truthfully provide.
(b) A natural person adversely affected by a consequential decision materially informed by a covered artificial intelligence system is entitled to meaningful review of that decision by a natural person with authority to alter it, upon request made within a period established by law.
(c) Nothing in this Section requires disclosure of a trade secret beyond what is necessary to provide the explanation required by subsection (a), provided that a deploying entity shall in every case disclose the factors described in subsection (a) with sufficient specificity to permit meaningful review under subsection (b).
Section 6. Automated Communications.
(a) Consent or relationship required. A covered artificial intelligence system, automated dialing or messaging system, or other automated means shall not initiate a telephone call, text message, or electronic mail message directed to a specific natural person unless:
(i) that person has given prior express consent to receive automated communications of that type from the deploying entity, revocable at any time by a reasonable means the deploying entity provides; or
(ii) the deploying entity has an existing customer, patient, membership, or comparable organizational relationship with that person, and the communication concerns that relationship; or
(iii) the communication is an emergency alert issued by a government authority; a communication in response to a request the person initiated; or a communication for a genuinely non-commercial political, religious, charitable, or public-interest purpose by an organization not engaged in the sale of goods or services to the recipient.
(b) Disclosure and opt-out. Every communication permitted under subsection (a) that was generated, selected, or substantially assisted by a covered artificial intelligence system shall clearly and conspicuously disclose that fact, and shall provide the recipient a functional means to decline further communications of that type, effective within a period established by law.
(c) Anti-impersonation. No covered artificial intelligence system shall be used to generate or transmit a communication employing a synthesized voice or likeness of a specific, identifiable individual without that individual's consent, regardless of whether subsection (a) is otherwise satisfied.
(d) Private right of action. A communication that violates subsection (a), (b), or (c) gives rise to a civil cause of action for the recipient, with statutory damages of not less than five hundred dollars per violation, subject to a reasonable aggregate cap for a single mass campaign as established by law, in lieu of proving actual damages. A violation of subsection (c) is not subject to the exceptions in subsection (a).
(e) Congress may extend the protections of this Section to other forms of direct electronic contact as new technologies develop.
(f) Whenever a covered artificial intelligence system conducts, in whole or in part, a real-time voice conversation with a natural person on behalf of a deploying entity, regardless of how the call was initiated or received, the system shall, at the outset of the conversation, clearly and audibly disclose that the person is speaking with an artificial intelligence system rather than a human being, and shall, upon the person's request at any point in the conversation, connect the person to a natural person employed or engaged by the deploying entity within a reasonable time established by law. This subsection does not apply where the deploying entity maintains no live-human channel for the type of request at issue, provided the deploying entity discloses that fact to the person at the same time as the disclosure required by this subsection.
Section 7. Administration.
(a) Congress shall establish by law an independent Federal Artificial Intelligence Commission to administer this Article, consisting of not fewer than seven members serving staggered terms, appointed by the President with the advice and consent of the Senate, of whom not more than a bare majority may be affiliated with the same political party, and among whom shall be persons with substantial expertise in machine learning or computer science, constitutional or human rights law, and public safety.
(b) The President may remove a member of the Commission before the expiration of that member's term only for material neglect of duty or material abuse of authority, as those terms are defined by Congress by law consistent with this subsection, established by clear and convincing evidence before the United States Court of Appeals for the District of Columbia Circuit. A good-faith interpretive disagreement about the scope of this Article, or a discretionary decision later found erroneous but made in good faith, is not material neglect of duty or material abuse of authority.
(c) The Commission shall establish technical standards under Section 3, receive and investigate reports under Section 3(d), certify deploying entities' compliance with this Article, and refer violations for civil enforcement in federal district court as provided by law. The Commission shall not itself impose a civil penalty under Section 9; a civil penalty under this Article shall be imposed only by a court of competent jurisdiction.
(d) The Commission shall be independent of the executive branch, subject to the President's removal authority under subsection (a). This Article establishes, as a constitutional floor, an annual funding level for the Commission of not less than one-twentieth of one percent of total federal discretionary outlays as enacted for the prior fiscal year; Congress may appropriate a greater amount by law. This floor is self-executing: if Congress does not enact a specific appropriation for the Commission for a fiscal year, the floor established by this subsection, adjusted upward by the percentage change in the Consumer Price Index for All Urban Consumers for the preceding twelve months, is available to the Commission for that fiscal year without further legislative action, consistent with Congress's authority to authorize, in specific and bounded terms established in advance, a standing source of funding for a federal financial or regulatory agency, as it has done for other independent regulators.
Section 8. Judicial Review and Private Right of Action.
(a) A natural person aggrieved by a violation of this Article has the right to seek relief in federal court. “Aggrieved,” for purposes of this Section, means having suffered a concrete and particularized injury in fact traceable to a violation of a right this Article confers on that person individually; a generalized interest in this Article’s enforcement, without more, is not injury for purposes of this Article.
(b) A person aggrieved under subsection (a) may bring a civil action in the appropriate federal district court for declaratory relief, injunctive relief, and actual damages. Nothing in this Article shall be construed to limit any other remedy available under federal or state law.
Section 9. Penalties.
(a) Knowing and willful violations. A deploying entity that knowingly and willfully violates Section 2 or Section 4 of this Article shall be subject to a civil penalty, determined by the court considering the factors in subsection (d), of not less than $100,000 and not more than $1,000,000 per affected natural person, or, in the case of a deploying entity with more than $1,000,000,000 in annual gross revenue, not less than one-tenth of one percent and not more than one percent of the entity's annual gross revenue, whichever is greater, payable to the United States Treasury.
(b) Negligent or unknowing violations. A deploying entity that violates Section 2, 3, 4, or 5 of this Article without the knowledge and willfulness described in subsection (a) shall be subject to a civil penalty, determined by the court considering the factors in subsection (d), of not more than $50,000 per violation. A court shall not impose a penalty under this subsection on a deploying entity that demonstrates it maintained a good-faith, reasonable compliance program under this Article and promptly cured the violation after receiving notice of it.
(c) Falsified reports. An officer or employee who knowingly and willfully directs, conceals, or falsifies a report required by Section 3(d) shall be individually subject to a civil penalty of not less than $50,000, in addition to any penalty imposed on the deploying entity under this Section.
(d) Factors. In determining a penalty under subsection (a) or (b), a court shall consider: the severity and duration of the harm caused; the deploying entity's culpability; the deploying entity's size and ability to pay; whether the deploying entity self-reported the violation or promptly remediated it; and whether the deploying entity has previously violated this Article.
(e) Course of conduct. Substantially identical violations arising from a single deployment decision or design choice shall be treated as a single course of conduct for purposes of this Section, and not as a separate violation as to each affected natural person, unless a court finds the deploying entity's conduct as to each such person was independently knowing and willful.
(f) Congress may by law increase and may establish additional penalties including referral for criminal prosecution under existing law, but no law enacted under this Section shall reduce a penalty below the minimum this Section establishes for a knowing and willful violation.
Section 10. Transition.
(a) Congress shall enact implementing legislation, including the technical standards required by Section 3(c) and the threshold required by Section 1(a), within two years of ratification. Until such legislation takes effect, a covered artificial intelligence system shall be defined, for purposes of this Article, as any artificial intelligence system deployed to make or materially inform a consequential decision as described in Section 1(a)(ii). Nothing in this Article shall be construed to preempt a state law that imposes stricter human rights, transparency, or safety obligations on artificial intelligence than this Article requires.
(b) Implementing legislation enacted under this Article may establish definitions, procedures, and technical standards not inconsistent with the principles established by Sections 2 through 9. Such legislation is entitled to deference proportionate to its adherence to those principles, but a court shall set aside a provision of implementing legislation that is arbitrary, capricious, or manifestly inconsistent with those principles.
Section 11. Severability.
If any provision of this Article, or the application of a provision to any person or circumstance, is held invalid, that invalidity does not affect the remainder of this Article or the application of its remaining provisions to any other person or circumstance, and the provisions of this Article are severable to that end.