No. 150: The GDPR and the US Algorithmic Accountability Act: Evaluating Their Adequacy in Regulating AI-Based Decision-Making
Abstract
Artificial intelligence (AI) is rapidly reshaping social, economic, and legal life, raising urgent questions about accountability, fairness, and protecting fundamental rights. While the European Union’s General Data Protection Regulation (GDPR) and the newly adopted Artificial Intelligence Act (AI Act) constitute the most ambitious attempts worldwide to regulate AI, their adequacy in practice remains contested. Across the Atlantic, the United States has proposed the Algorithmic Accountability Act (AAA) as a procedural mechanism for algorithmic oversight, yet its uncertain legislative fate and fragmented state-level rules reveal significant governance gaps.
This thesis critically examines the extent to which these frameworks provide adequate safeguards for AI-powered decision-making. It analyzes the doctrinal foundations of the GDPR, the AI Act’s risk-based obligations, and the AAA’s impact-assessment model, situating them within broader ethical principles such as transparency, fairness, accountability, and human dignity. The study highlights both convergences and divergences through a comparative analysis of EU and U.S. approaches, supported by case studies on recruitment algorithms, credit scoring, and public-sector surveillance. It shows that while the GDPR and AI Act enshrine strong rights and prohibitions, ambiguities in provisions such as Article 22 GDPR and AI Act enforcement uncertainty limit their effectiveness. Conversely, the AAA offers a promising model of procedural accountability but suffers from a narrow scope, weak enforcement, and legislative fragility.
The thesis argues that existing frameworks remain only partially adequate: They address key risks but leave persistent gaps in enforcement, redress, and protection for vulnerable groups. To close these gaps, it recommends harmonizing definitions of “high-risk” and “automated decision systems,” mandating stronger transparency obligations (including data disclosure), embedding stakeholder participation, and fostering international regulatory cooperation. By situating its analysis within the broader debate on digital humanism, the thesis underscores that effective AI governance requires robust legal frameworks and ethical commitments to fairness, autonomy, and human dignity.