Month: September 2026

Esencia exposed how Puerto Rico can approve coastal megaprojects without the public finding out.

Could the same thing happen with AI data centers installed under the sea?

You may have read or heard about a company planning to install an Artificial Intelligence (“AI”) data center around Puerto Rico’s beaches, and thought to yourself, “That doesn’t sound right. Could that really be true?” The answer: yes, it’s true.

On the other hand, you might be hearing about this for the first time by reading this article, which leads you to wonder, “How is it possible I hadn’t heard about this? With so many laws on the books, isn’t there one that requires something like this to be publicly announced in Puerto Rico? Shouldn’t there be a public hearing covered on TV and in the newspapers so I could see it and learn more?”

If you’re surprised you haven’t heard about this before, don’t be. That’s because Puerto Rico’s laws and regulations weren’t designed to guarantee that you’ll find out about projects like this one before they’re built. A recent case where we saw this happen was the Esencia tourism megaproject in Cabo Rojo. In August 2026, the Permits Management Office (“OGPe”) approved the project’s Siting Consultation – a project that represents at least a $2 billion investment on the island’s southwest coast – without holding a public hearing for that stage, despite more than 800 residents formally requesting a participatory process. The developers maintained that they already fulfilled that requirement in an earlier phase held in March 2025. Opponents point out that, since then, 10 new studies have been added to the record that never went through public scrutiny. Amid widespread opposition to the project, the Puerto Rico Senate announced it will investigate the project through its own hearings, with the first one held on September 1. If a hotel-and-residential project on land generates this much controversy, what would happen if someone tried to install AI data centers beneath our beaches, in a way that’s practically invisible? 

Today, Farrant Explains covers who proposed this project, how it could obtain permits to operate under Puerto Rico law, and how those laws compare to the United States and the European Union. We’ll also summarize the conversation we had with the leaders of a company that has considered doing this, and tell you why this should matter to you, even if you live on top of one of our mountains and never go to the beach or a pier.

I. Who is Seabase, and what do they want to do?

According to our conversation with Reilly McAdams, co-founder and Chief Executive Officer (”CEO”) of Seabase, this is a company incorporated in Delaware as Seabase Industries Inc., headquartered in Houston, that builds modular, containerized computing units designed to sit at or near the seafloor, close to ports, and cooled with seawater instead of fresh water or electricity-hungry air conditioning systems. Prior to its Delaware incorporation, the company registered two Puerto Rico corporations on March 6, 2026: Seabase Network LLC, registration number 575350, and Seabase Industries LLC, registration number 575352.

Both Puerto Rico companies list Reilly McAdams (co-founder and CEO of Seabase, according to its website), Oliver Willcox (co-founder and president), and Ashby Green (CFO) as authorized persons.

On its website, Seabase states that it differentiates itself from competitors because its architecture separates a long-life subsea platform from shorter-life computing equipment that can be replaced over time. The company also sells a product called Nori, designed to let customers reserve and monitor their equipment’s capacity.

Seabase’s co-founders, CEO Reilly McAdams and COO Ollie Willcox, were interviewed by News Is My Business in May 2026. At the time, they said the company was evaluating sites in Ponce, San Juan, and Puerto Rico’s east coast, and seeking partnerships with universities and government agencies, naming the University of Puerto Rico’s Mayagüez campus in that interview. McAdams also noted that Puerto Rico relies too heavily on infrastructure in the mainland United States, pointing out that most of the island’s computing and technological capacity is located in Miami, which makes the island highly vulnerable if an undersea fiber-optic connection were ever damaged.

During our conversations with Seabase in September 2026, the company told us that, although it has evaluated potential sites in Puerto Rico, it has not selected a specific location or advanced a project. They also told us that, while Puerto Rico “remains an attractive market, it is not currently among our primary near-term deployment locations,” and that their current work is exploring opportunities in the continental United States and internationally, including other Caribbean locations.

On the technical side, Seabase’s public materials describe its “pods” as units running between 0.5 and 3 megawatts each, in standard containers, which are aggregated into clusters of 10 to 20 megawatts, using closed seawater cooling systems instead of freshwater evaporative systems. According to McAdams, their subsea systems use a closed internal cooling loop that releases heat to the surrounding marine environment, avoiding the evaporative cooling and freshwater consumption common in many conventional data centers. This architecture, he told us, could also reduce land requirements by locating computing infrastructure at sea or within existing marine and port environments.

When asked whether this heat-releasing system would generate any impact, he replied that it’s a passive process, in which a closed internal loop transfers heat through external heat exchangers rather than pumping seawater through the data center. He added that they would model the thermal plume for each site, designing the project so that localized temperature changes remain minimal, and that they plan to be fully transparent with the public about their data and marine impact.

We also asked Seabase whether a project like this would affect public beach access, or restrict the use of boats nearby. They told us they don’t expect their projects to restrict beach access, fishing, or boating, since they would look for locations with sufficient depth and distance from shore to stay away from beaches, swimming areas, recreational boating routes, navigation channels, and important fishing grounds. Their goal, they said, is for people using the beaches and boats near these pods to essentially not know the infrastructure is there.

In short, as of today, Seabase has no immediate plans to build a data center on our beaches. However, that doesn’t rule out Seabase — or another company — expressing interest in building a data center in our waters in the future. Consequently, in this next section, Farrant Explains which laws and regulations would address this situation.

II. What Puerto Rico laws and regulations govern building an AI data center on our beaches?

As of this writing, Puerto Rico has no law that regulates the construction of AI data centers on our land or in our waters. That said, should Seabase or another company want to begin the process of obtaining permits today to build a data center at sea, there are three legal frameworks that could apply. Today, Farrant Explains through each one.

Framework 1: Environmental Review (Law 416-2004 and the OGPe/JCA process).

Puerto Rico’s most important environmental statute is the Environmental Public Policy Act (Law 416-2004). It requires public agencies to evaluate significant environmental impacts that projects may cause before granting permits. These permits are typically issued by the Permit Management Office (“OGPe”), working with the Environmental Quality Board (“JCA“), which evaluate projects under the Joint Regulation for the Evaluation and Issuance of Permits Related to Development, Land Use, and Business Operations (Regulation 9473 of the Planning Board, approved June 16, 2023) (“Joint Regulation”), and the JCA’s Regulation for the Environmental Evaluation Process (Regulation 8858 of November 23, 2016).

Under this law and its regulations, developers submit an Environmental Assessment (“EA”) for their projects or, when the environmental impact could be significant, submit an Environmental Impact Statement (“DIA,” for its Spanish acronym). Rules 2.2.2.4(c) and 3.1.3.3(a)(1) of the Joint Regulation establish that any discretionary matter requiring a public hearing, or requiring a DIA, will be adjudicated within 180 days. This mechanism, once triggered, guarantees a public hearing and a defined timeframe. The important question, however, is determining whether a project requires an EA, a DIA, or neither.

Framework 2: Site Consultation (“Consulta de Ubicación”).

A pod like Seabase’s — which houses an AI data center placed under the sea — doesn’t fit any existing zoning category. For cases like this, Rule 2.2.3.2(d) of the Joint Regulation creates a discretionary process called a “Site Consultation” precisely for uses that, by their nature or intensity, need to be located in a specific place that existing zoning maps don’t anticipate. This is the category the Joint Regulation uses for novel projects. This matters because these Consultation processes have much narrower public-disclosure requirements than the DIA process, specifically:

  1. Notice only needs to be given to adjoining property owners, by certified mail, within no more than 5 days after the application is filed (Rule 2.2.2.2(a)).
  2. Holding a public hearing is discretionary, under Rule 2.2.3.19. This rule states that a public hearing will only be held “in cases where the regulations in effect so require, or in cases the Adjudicative Board deems appropriate, in which case any interested person who requests to be heard on the matter under consideration will be allowed to participate.”
  3. Standing to challenge or intervene in a determination is limited. Rule 2.2.3.4(a) only grants standing to the property owner, optionee, or lessee — personally or through an authorized representative — in the case of private projects, or to the head of the agency or their authorized representative in the case of a public project. Likewise, subsection (c) of this Rule establishes that revocation of a consultation may be pursued by the Adjudicative Board “on its own initiative or at the request of a person with a legitimate interest,” a term that is not clearly defined.

In short: if a project is approved through a Site Consultation rather than a DIA, the public-hearing mechanisms many people assume exist would simply never be triggered here.

Framework 3: Port Zone — Ports Authority.

Section 7.3.4 of the Joint Regulation provides that, within a Port Zone (“ZP”), the Ports Authority (“Ports”) — not DRNA — is responsible for controlling and administering Puerto Rico’s ports, the navigable waters that form part of port zones, publicly owned piers, submerged lands under those piers, the maritime-terrestrial zones located within any port zone, and all buildings and structures situated there that are owned by or under the dominion of Puerto Rico. This is likely why Seabase told News Is My Business that it was in communication with the Ports Authority. Outside a ZP, DRNA’s permitting processes for maritime-terrestrial zones would apply instead, under Puerto Rico’s 1968 Piers and Ports Act, Law 151-1968. In these cases, DRNA may permit water-dependent uses such as piers and platforms, but cannot convert submerged lands into private property.

Beyond these three frameworks, a project like this could also fall under the following laws and processes:

1. Energy Interconnection.

A 10-20 megawatt facility like those described by Seabase would need to connect to the electrical grid, and would therefore fall under the jurisdiction of the Energy Bureau (“PREB”) and any other agency handling the interconnection study. Additionally, unlike a growing list of U.S. states, Puerto Rico has no large-load-specific tariff, nor any law or ordinance specifically regulating data centers.

On this point, Seabase told us its goal is not to “add a large new load to a grid that’s already fairly constrained. We’re evaluating models that pair computing infrastructure with new power generation and battery storage, to potentially support grid resilience and flexibility where the local system allows.”

2. Tax Incentive Decrees under Act 60

Puerto Rico’s Incentives Code, Act 60-2019, consolidates incentive programs under the Office of Business Incentives, which cover infrastructure and renewable energy projects, in addition to reviewing benefits for operating within a federal Opportunity Zone. To obtain a decree approving an incentive, the entity must apply to the Department of Economic Development and Commerce (“DDEC”), and this process does not require a public hearing.

We asked Seabase whether any of its Puerto Rico entities held, or had applied for, a tax incentive decree under Act 60. Its CEO, Reilly McAdams, told us that none of its entities holds a decree or has a pending application under Act 60 or any other tax incentive, stating that the entities are “ordinary corporate entities.”

3. Dedicated Telecommunications Infrastructure

Rule 9.11 of the Joint Regulation governs the construction, installation, and siting of telecommunications towers and facilities through the Telecommunications Bureau (“NET”), an entity under the Puerto Rico Public Service Regulatory Board (“JRSP”). Rule 9.11.11 establishes that public hearings will be required for variance requests related to the installation or siting of telecommunications towers and facilities, when these respond to technological, emergency, or public-safety needs.

While this is a much stronger standard than the one for Site Consultations, it applies to few cases. If Seabase’s or another company’s fiber-optic or connection infrastructure requires a variance, this would be the only process under the Joint Regulation that would require the entity to publish a newspaper notice and participate in a public hearing.

4. Federal Regulations and Permits

Since installing a data center at sea would take place in navigable waters of the United States, a permit would almost certainly be required under Section 10 of the Rivers and Harbors Act, 33 U.S.C. § 403, as well as a permit from the U.S. Army Corps of Engineers under Section 404 of the Clean Water Act, in addition to a license for laying submarine cables if fiber connections are placed in waters under federal jurisdiction.

III. How does Puerto Rico’s legal framework compare to that of the United States and the European Union?

  1. Compared to the United States — Puerto Rico’s environmental review process closely follows the National Environmental Policy Act (“NEPA”), to the point that Puerto Rico’s regulations address situations in which a local agency co-leads an environmental review process with a federal counterpart under NEPA.

That said, during 2026, a number of state legislatures passed laws requiring companies that want to build AI data centers to disclose their plans before construction begins. New Jersey, for example, now requires data center operators to publicly disclose how much water and energy they consume (S3379/A4096), in addition to recently passing the “Data Center Fair Share Act (A5462),” which establishes separate electricity rates for data centers.

At the federal level, Representative LaMonica McIver (D-NJ) introduced the AI Data Center Site Selection Transparency Act of 2026, which would require data center developers to disclose the location of selected sites to elected officials and the public at least 180 days before taking any definitive development step. This bill was filed because the industry has been signing nondisclosure agreements (“NDAs”) with public officials to prohibit them from speaking about these projects or their potential impact. A number of states have moved to ban public officials and developers from signing NDAs with each other.

In Puerto Rico, no one has prohibited the government from signing NDAs with these entities, and we haven’t found any bill attempting to regulate AI data centers.

  1. Compared to the European Union (“EU”). The EU regulates this completely differently: it requires ongoing sustainability reporting, rather than disclosure before a project begins. Under Article 12 of the Energy Efficiency Directive, EU member states must ensure that data centers with at least 500 kilowatts of installed information technology power make all their energy performance information public, and publish it in a shared, EU-wide database covering approximately 24 indicators. The European Commission expects to finalize an EU-wide classification and labeling process. The 10-20 MW clusters Seabase plans to use, according to its website, exceed the EU’s 500 kW minimum. As a result, if their project was built in Europe, they would have to report to the public, every year, how much water and renewable energy they use, and what their energy efficiency is. In Puerto Rico, under existing law, they would not have to disclose any of this.

In short: Puerto Rico regulates whether a project gets approved. But for an innovative project like this one, it appears the project could be approved through a legal framework that contemplates discretionary public hearings and gives the public limited standing to object. Meanwhile, U.S. states are focused on regulating whether the public is notified of these projects before they’re built. Finally, the EU regulates whether the public needs to keep being informed about the project indefinitely. Puerto Rico’s legal framework, by comparison, is much weaker at the outset of a project than these jurisdictions, and stays silent about everything else.

IV. Why should this matter to you?

Because, even though Seabase’s CEO told us Puerto Rico is not currently among its short-term priorities, there are at least 3 aspects of this story you should be aware of, regardless of what Seabase or another company does in the future.

  1. The precedent that will be set. Seabase and its leadership gave us detailed, specific answers about the logic behind their unit placement, their thermal plume modeling, and their stated interest in not impacting marine flora and fauna. This is the kind of communication and exchange that many companies don’t offer unless they’re forced to by a government or judicial authority. This exchange was a good example of how we’d expect Seabase to behave if it decides to pick this project back up in Puerto Rico. However, their good faith and willingness are not a substitute for the fact that this kind of exchange should be one required by law, and the next company that wants to come to Puerto Rico to propose building an AI data center under the water might not be as receptive to dialogue as they were. The current gap in the Joint Regulation that allows these site consultations within a process that doesn’t guarantee public hearings isn’t filled simply by a company’s willingness to answer our questions. It would also be vital to ensure there’s a legal framework in place to verify that a company actually follows through on everything it promises.
  2. Energy and water use. Seabase’s description of its approach — passive, closed-loop cooling systems that avoid pumping seawater through the system, along with its stated interest in generating and storing its own energy rather than becoming an additional burden on our current grid — sounds like a very different model from the one conventional data centers use, and one that could be much more responsible and sustainable if it’s actually implemented. However, Seabase’s proposal is, for now, simply a theoretical one, since no sites have been chosen and no environmental analysis has been completed. As a result, the challenges of building data centers on top of Puerto Rico’s fragile, collapsing water systems remain real. As a matter of fact, I’m writing these lines on the fourth consecutive night without water in my home. These challenges apply to any project Seabase or any other company might want to implement here.
  3. The urgent need to demand transparency. Our exchange with Seabase was a small example that shows the need to formalize transparency processes at a project’s pre-development stage. Seabase answered all of our questions simply because they wanted to talk with us, not because a law required it. But a future company looking to establish itself in Puerto Rico for the same purpose might not have the same willingness that Seabase showed. As a result, Puerto Rico needs to create laws similar to those several states are passing, requiring advance disclosure of this kind of project, while we wait for Congress to hopefully one day pass the AI Data Center Site Selection Transparency Act or a similar law.

V. Best Practices and Recommendations for Companies and the Public

  • Publish site-specific environmental modeling before being legally required to. During our conversation, Seabase gave us a lot of technical detail about its project and answered all of our questions. This is precisely the kind of proactive disclosure that should be the industry standard, not the exception. Developers who do this build public trust, since they do it before the law forces them to.
  • Establish robust public hearing processes. Laws should prohibit developers from self-selecting into processes that don’t require public hearings in cases like this one. A company’s leadership showing good faith isn’t the same as law, and it can certainly change once a permitting process actually begins. In a case like this, where there are real questions about the impact this kind of project could have on our residents, coastlines, marine flora and fauna, and our water and power systems, public hearing processes need to be held regardless of the developer’s good faith.
  • Voluntarily publish water and energy use projections, before an authority requires it. Data center litigation in the United States frequently centers on the use of NDAs that let companies avoid disclosing information like this.
  • Publish the review processes underway at OGPe, DRNA, and Ports (the Ports Authority), so the public doesn’t have to figure out which of these agencies has jurisdiction over each part of a project.
  • Create community communication and engagement plans. These days, people around the world are skeptical about the risks of AI and how it will affect their lives. Developers of projects like Seabase’s need to be transparent about their intentions and plans, and set and publish goals with metrics the public can verify and track.
  • Hold the government accountable. We need to make sure the government follows its own laws, holds public hearings, promotes transparency, and allows people and entities standing to intervene in administrative and judicial processes.

VI. Conclusion

Seabase’s project was never a secret one, and we’re grateful they answered all of our questions much faster and more concretely than many other companies would have. Our exchanges with them introduced us to a company that seriously considered the island for this project, evaluated it, created 2 Puerto Rico corporations, generated local interest, but then concluded that Puerto Rico is not among its short-term priorities — though they’re leaving the door open to return.

Once that day comes, we’ll see how Puerto Rico’s legal framework analyzes and reviews it. The DIA process would guarantee a public hearing where residents can speak up. The Site Consultation process, however — which could be the one chosen to authorize a project as significant as this one — does not require holding public hearings. The transparency Seabase showed in our conversations doesn’t eliminate the need to make sure our own laws guarantee that same transparency, because we don’t want to live in a place where laws are passed to guarantee darkness.

What did you think of this article? Should Puerto Rico allow AI data centers? Do you think a development like this should go through the DIA process or the Site Consultation process? Leave us your comments.

Is Your Child a YouTube Star? There Is a New Law in Puerto Rico that Requires You to Set Aside Money for Him

Do you know how much money your child’s YouTube channel has generated—and where you’ve deposited it?

Nowadays, it’s almost impossible to scroll through YouTube, Facebook, TikTok, or Instagram without stumbling upon accounts where 4-, 6-, or 8-year-old children are genuine performers: unboxing toys, reacting to challenges, or simply living their daily lives in front of a camera operated by their parents. The content they post frequently generates income from advertising, sponsorships, and affiliate links. Until a few weeks ago, Puerto Rico had no law that guaranteed that child received a single cent of what their image generated.

That changed on June 19, 2026, when the Puerto Rico Legislature approved Senate Bill 973, and Governor Jenniffer González Colón signed it into Law 193-2026, known as the “Law for the Economic Protection of Minors in Digital Monetization.” Today, Farrant Explains what this new law establishes, how it works in practice, and how it compares to similar laws in the United States and the European Union.

What Does Law 193 Establish?

Law 193 is built on a simple premise: if a minor’s image, voice, or identity is the principal engine driving content that generates money, that minor has the right to receive a portion of those earnings when they reach adulthood, and someone is legally required to answer for the proper management of that money.

Law 193 creates several new legal categories to accomplish this. The first is the “minor content creator”—any person who has not reached 21 years of age (or less, if emancipated) and participates in the creation or production of digital content that generates direct or indirect income. The Law also defines the “responsible content creator” as the parent, mother, or legal guardian who administers the account or channel and receives the earnings. Finally, the law establishes the “protected account”: a bank account held exclusively in the minor’s name at an institution authorized by the Office of the Commissioner of Financial Institutions (OCIF) or COSSEC, separate from the parents’ property, which cannot be seized, transferred, or used for anything other than the minor’s benefit.

How Will This Work in Practice?

Article 4 of Law 193 establishes concrete percentages of earnings that the minor must receive. Every parent, mother, or guardian who receives income from monetized digital content featuring a minor must deposit, into the protected account, a minimum of thirty percent (30%) of income from each monetized piece of content. This amount increases to 50% when the minor appears primarily throughout the entire content—that is, if they are the video’s protagonist.

These funds will remain frozen until the minor turns 21, unless a court, based on the minor’s best interests, authorizes otherwise. When that moment arrives, Article 5 grants the young content creator 3 specific rights: to receive the total accumulated amount with interest, to demand that a platform deletes the content in which they appeared during their minority, and the ability to sue to recover any income that was not deposited as required by law.

News coverage or documentary content, non-profit educational use, and sporadic appearances in public spaces with no direct or indirect monetization attributable to the minor’s image is exempt from the law’s requirements.

Law 193 orders the Department of Labor and Human Resources to issue regulations covering labor aspects, including establishing daily limits on a minor’s exposure to digital production, within 180 days of the law’s passing. The Department is also authorized to impose fines of up to $1,000 for non-compliance. OCIF and COSSEC, meanwhile, will regulate everything related to opening and overseeing protected accounts.

How Does Puerto Rico Compare to the United States?

Puerto Rico didn’t invent this model—it borrowed and adapted it from several states that have been addressing this problem for years, though each has its own approach:

  • Illinois: was the first state to protect minors’ online content when it passed its Public Act 103-556 (2023), which amended its “Child Labor Law” and created what is known as the “Illinois Child Influencer Act.” This law extends the definition of child labor to minors under 16 who appear substantially in monetized content, and uses the same percentage that Puerto Rico would later adopt: if the minor appears in 100% of the content, 50% of the gross income must be held in trust. It went into effect on July 1, 2024.
  • California: protection here is much older—dating back to 1939, with the famous “Coogan Law” (California Family Code §6750-6753), created following cases of child actor exploitation in Hollywood. This law requires depositing at least 15% of earnings into what is known as a “Coogan Trust Account“. In 2024, “Assembly Bill 1880” expressly extended this protection to minors who create digital content, recognizing that “child labor” no longer occurs only on film sets.
  • Minnesota: approved in 2025 the Children in Digital Content Act, the strictest approach so far. This law prohibits minors under 14 from participating in monetized digital content, and establishes that if a minor under 14 is featured by a content creator, they must receive 100% of the compensation the creator receives for this content, minus what must be paid to any other minors. For minors between 14 and 18 years old, the law requires creating a trust account where proportional compensation must be deposited. The law also recognizes the minor’s right to request that content posted during their childhood be deleted upon reaching adulthood.
  • Utah: its House Bill 322 of 2025, known as the Minor Protection in Digital Media Act, follows the same pattern of mandatory trust and the right to request content removal upon adulthood.

The pattern in these legislations is clear: each state has enacted its law on top of existing legal frameworks in child labor protection (child labor or child actor laws), to extend those protections to the digital world. Puerto Rico essentially combined Illinois’s tiered percentages with Minnesota and Utah’s right to digital oblivion. However, unlike these states, it did not create a separate child labor licensing regime, but instead directly regulated money flow through protected accounts and left labor oversight (time and exposure limits) for future regulation by the Department of Labor.

How Does Law 193 Compare to the European Union?

The United States started legislation on this topic using labor law as its starting point. On the other hand, Europe started from image rights and data protection law—and the undisputed pioneer is France.

The “Loi Studer” (Law No. 2020-1266 of October 19, 2020) was the first comprehensive law on minor influencers. Its approach is different from Illinois or Puerto Rico: instead of setting a minimum reserve percentage, it classifies child influencers under 16 under the existing “children in entertainment” regime of the French Labor Code, requiring prior administrative authorization from DREETS before any commercial exploitation of their image. The portion of earnings exceeding what the law allows parents to receive—the “pécule”—must be deposited with the Caisse des Dépôts et Consignations, a public institution, rather than in a private bank account as in Puerto Rico or the states.

French law continued to evolve in 2023 when Parliament approved the Influencers Law (Law No. 2023-451), which regulated commercial transparency for all influencers, requiring written contracts and clear labeling of commercial content. However, this law drew criticism for being too stringent with content creators. Consequently, in November 2024, the French government issued Ordinance No. 2024-978 to modify the Influencers Law, relax commercial labeling requirements, and align regulation with the EU’s Digital Services Act (DSA). Through these laws, France maintains 2 parallel legal frameworks: the Loi Studer to protect child influencers as artistic workers, and the Influencers Law to regulate commercial transparency.

One area where France goes further than Puerto Rico is in the right to be forgotten: since 2020, the minor can directly demand from the platform—without needing parental consent—that content featuring them be deleted, even while they are still minors. Puerto Rico’s Law 193, by contrast, reserves that content removal right for when the content creator turns 21.

At the European Union level, there is still no specific law on “kidfluencers”—the matter is fragmented across the DSA (which in its Article 28 prohibits advertising targeted at minors on platforms), the Audiovisual Media Services Directive, and data protection law. However, the landscape is shifting rapidly: the European Parliament, in its resolution of November 26, 2025, on the protection of minors online, expressly asked the European Commission to prohibit platforms from monetizing or economically incentivizing “kidfluencing”—a significantly more aggressive stance than Illinois, California, or Puerto Rico, which regulate how the money is divided rather than prohibit the activity. That debate will likely be addressed in the EU’s forthcoming “Digital Fairness Act.”

In summary: the United States and Puerto Rico regulate how money is divided; France regulates work and prior authorization; and the European Union, as a bloc, is considering completely prohibiting the monetization of minors’ content.

Why Should This Matter to You?

If you manage a family account or channel where your children generate income from advertising, sponsorships, or affiliates, this law applies directly to you. Failing to deposit in a bank account the 30 or 50% that the Law requires you to set aside for your child constitutes a violation of the law for which your child could sue you when they turn 21.

On the other hand, if your business pays sponsorships or collaborations to accounts featuring child actors or Puerto Rican “family channels,” you should also understand this law. Although the obligation to set aside funds in a protected account rests primarily on the parent, mother, or guardian, a pattern of payments to parents you know repeatedly ignore this law could make you part of a lawsuit when that minor reaches adulthood.

How Can I Comply with the Law?

  • If you manage an account or channel where your children participate, open a protected account with an institution authorized by OCIF or COSSEC as soon as possible and calculate the correct percentage (30% or 50%) you need to set aside for your child.
  • Keep clear accounting of income from each piece of monetized content—advertising, sponsorships, affiliates, merchandise sales—to be able to demonstrate, if needed, that you complied with the required reserve.
  • Keep the protected account completely separate from your personal accounts. Law 193 is clear that these funds cannot be used to pay your own obligations.
  • If your business contracts with child influencers in Puerto Rico for ads, ask whether they have the protected account established before signing a contract.
  • Stay informed of regulations that the Department of Labor and Human Resources must issue within the next 180 days, as that’s when the daily limits on a minor’s exposure to content production will be defined.

In Conclusion

Law 193 makes Puerto Rico one of just a handful of jurisdictions worldwide—alongside Illinois, California, Minnesota, Utah, and France—with a law regulating how money generated by young online content creators will be protected. The principle is straightforward: if a child’s image is used to sell, that child has a right to a portion of the income received, and those funds must be deposited in an account that no one else can touch. If you manage a family or your child’s channel in Puerto Rico, now is the time to review your finances and processes, before your own son or daughter becomes and adult and sues you in court.

Do you manage a family or child channel generating income in Puerto Rico, or does your business pay sponsorships to minor content creators? Schedule a consultation with us to make sure you’re complying with Law 193 before regulations take effect.

What do you think of Law 193? How does it compare with the other laws described here? Which do you think has the best approach? Do you think it’s right that a minor has to wait until age 21 to ask YouTube and other platforms to delete their content?

About the Author

Jaime Farrant is an attorney admitted to practice law in Puerto Rico, New York, Maryland, and the District of Columbia, with an LL.M. in International Law, focusing on privacy, cybersecurity, and AI regulation for businesses and healthcare providers.

ADVERTISING MATERIAL. This article constitutes advertising as defined under the rules of professional conduct in effect in New York (22 NYCRR 1200.7.1 and 1200.7.3), Maryland (Rule 19-307.1 and 19-307.2), and the District of Columbia (D.C. Rules of Professional Conduct 7.1), as well as the Puerto Rico Rules of Professional Conduct (Rules 7.1–7.3). It does not constitute solicitation of known prospective clients who need legal services in a particular matter. Rather, it is general information directed to the public about the practice of law and available legal services. No attorney-client relationship is created by reading this article or by contacting the author.

Why Did a Puerto Rico Healthcare Company Pay $2.7 Million in HIPAA Penalties When It Doesn’t Even Treat Patients?

The most common HIPAA violation in medical offices isn’t caused by hackers. It is one caused by never writing one specific document.

In December 2024, the U.S. Department of Health and Human Services’ Office for Civil Rights (“OCR”) announced a $250,000 settlement with Inmediata Health Group, a “clearinghouse” (an intermediary that converts medical claims into the standard format insurance plans require) based in Puerto Rico that processes data for physicians, dentists, hospitals, laboratories, and health plans across the island.

What happened? Between May 2016 and January 2019, the health information of 1,565,338 people held by Inmediata became publicly accessible on the internet due to a website misconfiguration. That information included names, dates of birth, addresses, Social Security numbers, medical diagnoses, and treatment information — all indexed and accessible through Google.

OCR identified the root cause: Inmediata had never conducted an adequate risk analysis, and it wasn’t monitoring activity on its information systems.

The total cost of this website error was far more than $250,000. Between the OCR settlement, a $1.4 million multi-state settlement with 32 state attorneys general and Puerto Rico, and a $1,125,000 class-action payout, the incident cost Inmediata at least $2.7 million.

$2.7 million in penalties for not having a document required since 2005.

What Is a Risk Analysis, and Why Is It Mandatory?

HIPAA’s Security Rule, at 45 C.F.R. § 164.308(a)(1)(ii)(A), requires every covered entity and business associate to conduct “an accurate and thorough assessment of the potential risks and vulnerabilities” to the confidentiality, integrity, and availability of the electronic health information it handles.

There’s a technical detail here that many people overlook. The Security Rule splits its requirements into 2 categories: requiredand addressable. Required specifications must be implemented by every covered entity and business associate. There’s no flexibility, no alternative, and no exception for the size of the practice. A solo physician’s office has the same obligation as a hospital.

Addressable specifications, on the other hand, do allow flexibility: if your office determines a measure isn’t reasonable given its size, you can document why and adopt an alternative instead.

The Security Rule was designed to account for the size and complexity of your operation, your technical infrastructure, the cost of security measures, and the probability and severity of your risks. A small practice doesn’t need the same analysis as a hospital system. But it needs one.

OCR Is Actively Looking for These Assessments

In October 2024, OCR launched an enforcement initiative dedicated exclusively to this requirement, called the Risk Analysis Initiative. By 2026, it had already announced roughly a dozen enforcement actions.

The reasoning behind focusing on this is fairly simple. These are straightforward cases for OCR: the question they need to answer is: do you have this document or not?

If you’re a HIPAA-covered entity, you need to understand that, if OCR opens an investigation, the first document they’ll ask for is your risk analysis — and most offices can’t produce one.

Being a small practice or business doesn’t protect you from being sanctioned. For example, Bryan County Ambulance Authority (“BCAA”), an entity serving just over 14,000 people, was the first case under this initiative. It settled with HHS for $90,000 following a ransomware attack. The investigation concluded that BCAA had never conducted an adequate risk analysis. Similarly, West Georgia Ambulance, an ambulance company in Carroll County, Georgia, paid $65,000 to HHS in a settlement for failing to conduct a risk analysis, failing to maintain a security awareness training program for its employees, and failing to implement policies and procedures for the Security Rule. 500 individuals were affected by this incident.

OCR recently expanded its investigative focus from “risk analysis” to “risk management.” As a result, the question is no longer just “do you have the document?” but “can you show you acted on what you found?” An analysis done 5 years ago, filed away and never acted on, could today be seen as nearly as bad as having no analysis at all.

Why Should This Matter to You?

Here are at least 4 reasons:

First: ignorance isn’t a defense. The Security Rule has been in force for more than 20 years. OCR has been explicit in concluding that not knowing the Rule doesn’t excuse anyone. At best, it might lower the penalty, but it will not eliminate it.

Second: you face double legal exposure. Since the federal HITECH Act was passed, state attorneys general have independent authority to bring civil actions for HIPAA violations. The Inmediata case demonstrates this clearly: OCR collected $250,000 and the multi-state coalition collected $1.4 million for the same underlying facts. These are separate proceedings.

Third: Puerto Rico has an additional obligation. 2005’s Law 111, as amended, covered previously in this blog, applies to you even if you are subject to HIPAA. Its Article 2 defines “personal information file” to expressly include “medical protection protected by the HIPAA Act.” Consequently, complying with the federal notification does not relieve you of the local obligation. Law 111 requires you to report the security breach to DACO (Puerto Rico’s Department of Consumer Affairs) within a non-extendable 10-day period from detecting the breach. DACO is then required to make a public announcement of the incident within the following 24 hours. Compare this with HIPAA, which gives you up to 60 days to notify affected individuals. Puerto Rico’s clock runs much faster and does not give any extensions. Its fines range from $500 to $5,000 per violation, and they do not prevent those affected from separately suing you for damages. We previously explained this law here. Separately, Section 5 of the Federal Trade Commission (“FTC”) Act covers privacy and security representations made to the public, including what your own website says. Between OCR, the state’s attorneys general, DACO and the FTC, a single incident can lead to 4 simultenaous open legal proceedings against you. 

Fourth: This one is important, but one that doesn’t show up in any of these settlements. The first thing your cyber-liability insurer will likely ask for if you ever need to file a claim over a data breach is your risk analysis. If you don’t have one, a denied claim could cost you far more than the fine itself.

How Can You Comply with the Law?

A risk analysis isn’t a form you fill out in an afternoon, but it also doesn’t require hiring an international consulting firm. OCR’s guidance identifies the elements it should contain:

  1. Scope — every system that creates, receives, maintains, or transmits electronic health information. That includes the personal cell phone your front-desk staff uses to schedule appointments, the computer at home, and your website.
  2. Data collection — where that information lives, who touches it, where it travels.
  3. Threats and vulnerabilities — from ransomware to a laptop left in a car.
  4. Current controls — what you have in place today to mitigate each risk.
  5. Likelihood that each threat will materialize.
  6. Impact if it does.
  7. Risk level resulting from combining the two above.
  8. Documentation — in writing, with dates.
  9. Periodic review — this isn’t a one-time event.

Here are 3 practical recommendations that you can implement:

  1. Use the free federal government tool. HHS publishes the Security Risk Assessment Tool, designed specifically for small and mid-sized practices. It walks you through the elements in plain-language questions, and it’s free.
  2. Don’t forget to review your website. In risk analyses, many medical offices overlook their own website — the security of contact forms, tracking pixels, plugins, and hosting. HHS’s tool won’t ask you about this; you have to add it yourself.
  3. Document the corrective actions you’ve taken, not just the findings. With OCR’s shift toward risk management, a dated record of what you found, what you did about it, and when, is just as important as the analysis itself.
  4. Encrypt your devices, even though HIPAA doesn’t require it. Encryption is an “addressable” implementation specification under the HIPAA Security Rule. However, under Puerto Rico’s Law 111, the duty to notify is triggered only if the information was not protected by cryptographic keys beyond a password. Translation: losing a laptop with strong encryption, whose keys were not compromised, doesn’t start the 10-day clock or trigger DACO’s public announcement. This is one of the few measures that can buy you protection under 2 laws at once.

The Bottom Line

The Inmediata case isn’t a story about a sophisticated hack. It was a multimillion-dollar penalty for a website misconfiguration that nobody caught because nobody was checking. That’s exactly what a risk analysis exists to prevent.

If your office handles electronic health information — and if you use electronic billing, email, or a records system, you do — you’ve had this obligation since day one. It doesn’t matter whether you have 2 employees or 200.

The question worth asking today isn’t whether you’ll eventually be investigated. It’s simpler than that: if OCR asked for your risk analysis tomorrow morning, could you produce it?

If your answer is “no” — or “we did one years ago and I don’t know where it is” — it’s worth addressing now, before it becomes a matter of enforcement instead of planning, and before it costs you hundreds of thousands of dollars in penalties, and before your name ends up in newspapers and blogs across Puerto Rico and the mainland U.S. for failing to protect your patients’ information.

Do you have questions about whether your medical practice complies with this HIPAA rule? You can schedule a consultation with us today. We’re here to help.

About the Author

Jaime Farrant is an attorney admitted to practice law in Puerto Rico, New York, Maryland, and the District of Columbia, with an LL.M. in International Law, focusing on privacy, cybersecurity, and AI regulation for businesses and healthcare providers.

ADVERTISING MATERIAL. This article constitutes advertising as defined under the rules of professional conduct in effect in New York (22 NYCRR 1200.7.1 and 1200.7.3), Maryland (Rule 19-307.1 and 19-307.2), and the District of Columbia (D.C. Rules of Professional Conduct 7.1), as well as the Puerto Rico Rules of Professional Conduct (Rules 7.1–7.3). It does not constitute solicitation of known prospective clients who need legal services in a particular matter. Rather, it is general information directed to the public about the practice of law and available legal services. No attorney-client relationship is created by reading this article or by contacting the author.

Should Puerto Rico Ban Artificial Intelligence in its schools?

New York City just banned it for 600,000 students.

On September 2, 2026, New York City — through Mayor Zohran Mamdani and Schools Chancellor Kamar Samuels (equivalent to the city’s secretary of education) — did something no U.S. school system had done before: it paused the rollout of technology in the classroom, when they announced a 1-year moratorium on the use of generative artificial intelligence (”GAI”) in the city’s public schools. This means that, for the 2026-27 school year that has just begun, the roughly 600,000 students there in grades 2-K through 8th will not be able to use student-facing GAI. In addition, companion chatbots will be prohibited across all grades.

From a legal standpoint, perhaps the most striking thing about this announcement is that New York did not pass any law to impose its moratorium. The mayor and the chancellor simply made an administrative decision about what software would run on school devices, and with that decision, made a dramatic change in academic policy. 

Their decision leads us to ask: are other jurisdictions passing laws on how AI is used in the classroom? Or, are these new technologies simply being rolled out through memoranda and administrative decisions? And, since we write from Puerto Rico, we ask ourselves: which model does our island follow — or could follow?

Before answering those questions, let’s start with a summary of the Mamdani and Samuels announcement.

What Did New York Actually Do?

The moratorium is far more detailed than what the headlines suggest. It is not an outright ban, but a framework that establishes the following:

  • 2-K through eighth grade: A complete prohibition on student-facing GAI and chatbots that interact with students. Additionally, companion chatbots will be prohibited across all grades, from 2-K to high school.
  • High school: Twice a year, students will receive a 45-minute AI literacy module covering fundamentals, bias, ethics, and the impact on the professions. In other words, they will be taught about AI, not with AI. While students at this level will fall outside the general moratorium, the ban on companion chatbots will apply to them.
  • Pilot program: Up to 50,000 high school students (roughly 5% of enrollment) will have access to a pilot program with 5 approved AI tools (Quill, Edia, Brisk Teaching, Playlab, and Intel AI-Ready Schools) under strict time limits and teacher supervision.
  • Screen time: For students in second grade and below, individual screen use (”1:1 screen time”) will be restricted, though that restriction has not yet been spelled out in detail; and caps of up to 30 minutes a day are recommendedfor third through fifth grade and 45 minutes for sixth through eighth.
  • A “Technology in Schools Coalition” was created that will convene throughout the year and publish recommendations. On this, Chancellor Samuels stated in the mayor’s press release: “We’re standing firmly in our belief that innovation does not mean more technology, and over the next year, we will lead with evidence to make sure technology serves learning — not the other way around.”
  • Important exceptions: AI may continue to be used in support programs for students with disabilities, multilingual learners, and career readiness programs. In addition, teachers may continue using AI for lesson planning and administrative work.

In short, New York City did not craft a policy out of “fear” of technology. It crafted one that distinguishes between AI as a tool “adults may use,” AI as a “subject students study,” and AI as “a thing that talks directly to a nine-year-old” — banning only that last category.

How Is AI Used in European Union Classrooms?

The European Union passed the EU AI Act (”EUAIA“), the most developed AI statute in the world, which, regulates the use of AI in education, among other areas. Notably, the EUAIA does not tell a school from what grade it may use AI. What it does is regulate the product: it imposes obligations on whoever develops and sells software or applications, and on whoever deploys the technology — including the school itself.

The EUAIA has 3 key provisions on this subject:

  • Article 5(1)(f) prohibits developing, marketing, or using AI systems that infer the emotions of natural persons based on biometric data in educational institutions and the workplace, allowing only very narrow exceptions for medical and safety purposes. Accordingly, in the European Union, it is illegal for a vendor to offer a school a camera system that monitors whether students are actively participating in class.
  • Annex III of the EUAIA classifies AI systems used in education as high-risk — particularly those that determine access to education, evaluate learning outcomes (including steering the learning process), assess the appropriate level of education, and monitor prohibited behavior during exams. A high-risk designation does not mean the product is banned, but that it will be heavily regulated. As of August 2, 2026, providers must maintain technical documentation and risk management systems, apply CE marking, register in an EU database, and provide for human oversight. Deployers, in turn —with schools included— must ensure adequate human oversight, retain logs for at least 6 months, notify individuals when they are affected by a high-risk system, and, if they are public entities, conduct fundamental rights impact assessments.
  • Article 50 of the EUAIA adds transparency requirements across the board. Users must be told when they are interacting with a chatbot, when the content they are reading is AI-generated, and when emotion recognition systems are in use.

The EUAIA penalizes these violations with fines of up to the greater amount between €15 million or 3% of total worldwide annual turnover, and up to €35 million or 7% of worldwide annual turnover for prohibited practices.

In sum, the EU’s answer to “can a second-grader use a chatbot?” is: “that’s the school’s call. However, there is a compliance regime that will make deploying bad edtech expensive and make software that reads emotions illegal.”

What Has China Done About It?

In May 2025, China’s Ministry of Education issued guidelines regulating GAI in primary and secondary schools that resemble the one announced in New York City. For example:

  • Primary school students are prohibited from independently using open-ended GAI content tools.
  • Middle school students may explore and analyze the logical structure of AI-generated content, and understand how these systems work.
  • High school students may engage in inquiry-based learning on the technical principles of AI and even develop and optimize AI models.

Separately, all students are barred from submitting AI-generated work as their own, using AI to cheat, or relying excessively on the technology for creative tasks without applying critical thinking. In addition, AI may not directly evaluate students or answer exam questions.

How Is AI Use in Schools Regulated in Puerto Rico?

Although Puerto Rico has enacted several laws on AI — such as Law 163-2026, which we covered previously — as of today, there is no law governing how AI may be used in a classroom.

The Puerto Rico Department of Education (”DE”), however, recently approved a policy that points in opposite direction from New York’s. Approved in December 2025 and published in January 2026, the Guía Para el Uso de la Inteligencia Artificial en el Aprendizaje Estudiantil (Guide for the Use of Artificial Intelligence in Student Learning, the “Guide“) names Microsoft Copilot, on its first page, as the official classroom platform for students aged 13 and up. The Guide further provides that only institutional accounts may be used when working with DE equipment and AI systems and, on page 23, establishes that students under 13 — or older students with academic delays or functional diversity — may use Learning Accelerators. It also requires that AI tools comply with federal and state data protection laws through the Office of Information Systems, and provides that students will be taught to not to enter sensitive personal information or information identifying other people. The Guide cites several reference sources, including recommendations from the U.S. Department of Education and UNESCO’s Recommendation on the Ethics of Artificial Intelligence.

Comparing the Guide against NYC, there is a clear contrast. The Guide provides that students at least 13 years old may use AI — an age likely borrowed from the federal COPPA statute, which imposes verifiable parental consent requirements on operators of websites and online services directed to children or that collect personal information from children under 13. COPPA does not set a minimum age for a minor to use a tool: it imposes obligations on the operator collecting the data. In other words, the Guide appears to have borrowed a threshold designed for a different problem. NYC, by contrast, draws its line at eighth grade — which on average means age 14 — and, unlike Puerto Rico, sets prohibitions rather than permissions.

The Guide is fundamentally about how students may use AI. NYC is trying to answer whether students may use AI.

Beyond the Guide, at least four bills on AI in education have been debated in the Puerto Rico Legislature, although, as of this writing (September 9, 2026), none has become law. They are:

MeasureFiledSponsorWhat it doesStatus
P. de la C. (House Bill) 4272025-03-20Rep. Tatiana Pérez Ramírez (PNP) and Rep. José F. Aponte Hernández (PNP)3-year pilot program deploying AI conversational-English tutors in 25 schools as passed by the House; the Senate committee report cuts it to 21 and adds that it begin in pre-K through third grade.Passed the House on May 12, 2025. The Senate Committee on Science, Technology and Artificial Intelligence reported it with amendments on March 10, 2026; now before Senate Rules and Calendar.
P. del S. (Senate Bill) 3482025-02-19Sen. Brenda Pérez Soto(PNP) with three co-authors: Karen Román Rodríguez (PNP), Gregorio Matías Rosario(PNP), and Rafael Santos Ortiz (PNP)Establishes AI as an instructional and work tool across the DE, creates a compliance officer, and sets a pilot program in 2 high schools per region. Sets no grade or age limit on AI use.Passed the Senate 24-0 on June 9, 2025 and the House 50-0 on reconsideration on January 29, 2026. The Senate rejected the House amendments on February 5, 2026. Now in Conference Committee.
P. del S. (Senate Bill) 8202025-10-16Sen. Brenda Pérez Soto (PNP)Establishes a media and digital literacy program across grades K-12, including algorithms, AI, and deepfakes.Passed the Senate on March 26, 2026. The House Education Committee reported it on June 11, 2026; that report was withdrawn on June 25, 2026 and the bill returned to committee.
P. de la C. (House Bill) 9682025-11-07Rep. José F. Aponte Hernández (PNP)Requires the DE and all private schools to adopt ethical AI use policies.In the House Education Committee since November 10, 2025.

Before walking through each bill, two things are worth flagging at the outset:

  1. Both the House and the Senate filed AI implementation bills (348 and 427) in early 2025, and several months later filed governance bills (820 and 968). This matters because this order, in which a technology is adopted first and governed second would force Puerto Rico simply to “govern” what it “already bought,” rather than first establishing “whether it needs to buy” and “what to buy” before deciding what to buy. This process is not being followed due to lack of legislative will: 348 was approved unanimously in both chambers, yet it has sat for seven months in Conference Committee because the 2 chambers do not agree on the text.
  2. There appear to be legislative discrepancies about age. Although the House set no minimum age in 427, the Senate Committee on Science, Technology and Artificial Intelligence added that it AI instruction can begin in grades pre-K through third. However, this is the same committee that reported on 348, whose pilot plan begins in high school. So we have 1 committee, 2 bills, 2 opposite answers to the same question, and no explanation of how it arrived at the ages and grades each one proposes.

Now, Farrant Explains each bill:

1. House Bill 427 — The Senate Wants to Start Using AI Tutors in Pre-K

On May 12, 2025, the Puerto Rico House of Representatives passed P. de la C. 427, titled Ley para la Implementación de la Inteligencia Artificial en el Programa de Inglés del Sistema Público de Enseñanza en Puerto Rico (Act for the Implementation of Artificial Intelligence in the English Program of Puerto Rico’s Public School System). Filed by PNP Representatives Tatiana Pérez Ramírez and José Aponte Hernández, it orders the creation of a 3-year pilot program to integrate an AI tool to help improve conversational English learning in Puerto Rico’s public schools, that will be administered by the DE in collaboration with PRITS.

The text the House passed provided that the pilot program would cover 25 schools and set no grade level at all. However, the marked-up text accompanying the Senate committee report of March 10, 2026 changed that to 21 schools (3 per region) and added that the pilot begins in grades pre-K through third. Those ages contrast sharply with New York’s moratorium, which bars students between second and eighth grade from using conversational AI, and with China, which prohibits primary school students from independently using GAI. If 427 is enacted with the Senate amendment, it would mean that, starting in pre-K, Puerto Rican students will interact with GAI in the classroom.

This bill is very different from what New York City, Brussels, and Beijing have done, as it proposes:

  • A 2-year pilot program giving priority to rural and hard-to-reach schools, and to students with low scores on standardized English assessments. The program would begin with a 6-month process to select the schools and tools and train teachers, followed by 3 years of tool use with continuous monitoring, and then a program evaluation.
  • Requiring that the selected AI tools be capable of real-time, personalized interaction, provide immediate feedback on pronunciation, grammar, and fluency, and be compatible with the electronic devices available in public schools.
  • Creating an Evaluation Committee appointed by the Secretary of Education.
  • Providing annual reports to the Legislature and the Governor.

Separately, Article 7 of 427 as passed by the House required the AI tool to be selected “after the due process of evaluation and competitive bidding,” and titled the article “Tools to be used; competitive bidding.” The Senate’s marked up version struck the words “and competitive bidding” from both the heading and the body, leaving only “the due process of evaluation.” As people who believe in compliance with the law and government transparency, this deletion concerns us — particularly when what is being selected here is a system that will teach English to 4-year-olds in 21 public schools.

It is also notable that 427 says nothing about whether AI systems that measure or infer the emotions of natural persons based on biometric data will be permitted — a practice prohibited under Article 5 of the EUAIA.

2. Senate Bill 348 — Artificial Intelligence as a Work and Instructional Tool for Students and Teachers in the Puerto Rico Department of Education

This bill, filed by PNP Senator Brenda Pérez Soto 3 weeks before 427, is much broader in its scope, even though its pilot plan does start in high school. With regards to AI use, it sets no age or grade whatsoever. In fact, its Articles 3 and 5 authorize AI throughout the entire Department of Education.

If enacted, this bill would allow AI to be deployed across all courses as an instructional tool, not only in English classes. The bill also proposes:

  • Creating the position of Compliance Officer, appointed by the Secretary of Education and charged with overseeing compliance with the act.
  • Creating a technology innovation and AI unit under the Undersecretariat for Academic and Programmatic Affairs.
  • Establishing a Pilot Plan in two high schools per educational region. One of the schools must be officially designated as a school under an improvement plan, and the other must not carry that designation. It is important to note here that Article 7 describes the pilot plan as one to “evaluate and implement educational and administrative strategies that promote improved academic performance at the high school level” — yet it never mentions AI. In a bill about AI, it is striking that the only article naming a school level does not say the pilot will be an AI pilot.
  • Requiring that school communities — including parents and guardians — be given orientation on the ethical and responsible use of AI.

This bill, which has already been passed by both the House and the Senate but whose amendments were rejected by the Senate on February 5, 2026 and has been in Conference Committee ever since, is notable for the following:

  1. Its Article 3(b) provides that AI will be used as a tool to support and complement teachers’ work, and adds, in parentheses, “it shall not be to replace them.” It is the only 1 of the 4 measures that says so expressly — although placing a parenthetical clarification inside a declaration of public policy is highly unusual legislative drafting.
  2. The Article 7 Pilot Plan will be in high schools and not in pre-K, as 427 currently stands. However, as noted, that article does not mention AI, and the rest of the bill sets no grade level at all.
  3. Article 3(e)(5) requires that AI be used to “identify students at possible risk of failure: students who need additional support.” This would almost certainly be done through predictive risk profiling of minors — a practice the European Union has classified as a high-risk activity under its Annex III, since it would create an AI system used to evaluate academic outcomes or determine access to education. Operating such a system in the European Union would require compliance with obligations on documentation, logging, human oversight, and a fundamental rights impact assessment. In 348, however, this is a single clause that does not include any measurement standards, no human oversight requirement, no appeal process, and no rule barring that AI output from following the student through their academic record and transcript. While systems that identify at-risk students can help head off bigger problems, they can also turn into systems of “tracking and monitoring by algorithm.”

Finally, we can’t overlook the irony that both legislative chambers passed a bill to transform education in Puerto Rico containing a word in its title — instruccional — that is not recognized by the Royal Spanish Academy Dictionary. This is not an unavoidable technical term: the word appears to be adapted from the American term instructional design, and Spanish already has “instructivo,” which the dictionary does include. The syntax is worse. The title of the bill calls AI a “herramienta de trabajo e instruccional”, literally, “a tool for work and instructional.” That phrase uncomfortably yokes a noun phrase to a bare adjective. “Herramienta de trabajo e instrucción” would have done the job. All of it is a small sign of how much of Puerto Rico’s AI-in-education vocabulary is imported rather than drafted here.

3. Senate Bill 820 — Puerto Rico Media and Information Literacy Act

820 was also filed by PNP Senator Brenda Pérez Soto. If enacted, it would require the Department of Education to build a curriculum aimed at achieving media, digital, and statistical literacy among Puerto Rico’s public school students, so they can develop essential skills in critical thinking, information evaluation, data analysis, and technology use.

820 further provides that this instruction will be emphasized in Spanish, social studies, science, and mathematics, beginning within the next 2 academic years or sooner.

The curriculum seeks to have students develop literacy in:

  • Critical evaluation of sources and verification of information.
  • Identifying disinformation and manipulation — whether false information, deepfakes, manipulated images, sensationalist headlines (clickbait), or other forms of altered content.
  • A basic understanding of how algorithms and artificial intelligence work.
  • Fact-checking and corroboration, applying fact-checking methodologies, using digital verification tools, reverse image search, consulting multiple reliable sources, and triangulating information to confirm accuracy.
  • Ethical and responsible production of digital content, including factual accuracy, proper source citation, and responsibility in disseminating information.
  • Respect for privacy, intellectual property, and digital rights.
  • Developing healthy habits in technology use.
  • Interpreting data, identifying potentially misleading statistical representations, and critically analyzing quantitative information.

Implementation would rest on a continuing teacher training program, with certifications, microcredentials, and other verifiable credentials counting as professional development hours.

This bill is the closest to what New York City announced, since it seeks to have students know and understand algorithmic systems regardless of whether they use them in class. Its statement of motives, moreover, does its own comparative-law work, citing California’s AB 873 (2023) and its 2024 expansion, along with the strategies of Finland, Sweden, and Canada.

Its weakness, however, is similar to 968’s: it is an unfunded mandate. Article 10 simply directs the DE to implement it through “the optimization of existing human, technological, financial, and infrastructure resources within the Department of Education, maximizing the use of low-cost or free virtual platforms, open educational resources, collaborative alliances with universities and nonprofit organizations, and training in hybrid and virtual formats that reduce operating costs.” It is also silent on how age-appropriate curricula will be established, or at what age it will begin — a curious omission, given that the bill’s own premise is that children’s developmental stages make them vulnerable to manipulation.

4. House Bill 968 — Act on the Ethical Use of Artificial Intelligence in Puerto Rico Educational Institutions

This AI governance bill was filed by PNP Representative José Aponte Hernández. It is very different from 427 in that it does not mandate the deployment of any tool. Instead, it requires the DE to adopt and implement policies on the ethical use of AI in public schools and to oversee compliance with them. It likewise obligates every private educational institution registered under Law 212-2018 to adopt and implement similar policies at their respective academic entities and to file those policies with the Puerto Rico Department of State within no more than 180 days of the act’s approval.

968 establishes that every policy must include the following general principles:

  • Security and protection.
  • Autonomy.
  • Privacy.
  • Transparency and explainability.
  • Diversity and inclusion.
  • Responsibility and accountability.

Article 6 also requires that, “prior to the integration of artificial intelligence systems in public schools and private educational institutions, and in each subsequent school year, students and both teaching and non-teaching staff shall receive orientation and training on the ethics and responsible use of AI technologies in instruction, including the policies adopted.”

968 stands out as a bill that will require schools to enact policies with certain principles. However, it does not say anything about what constitutes a policy that fails to comply with the act, who will review those policies, or what happens when an institution files a deficient one. Nor does 968 establish penalties or authorize private civil actions to compel compliance. It also does not establish the ages at which an educational institution may deploy AI, leaving it to the discretion of each school. 

There is also 1 provision that deserves special attention. The Privacy principle in Article 5 provides that “the informed consent of the user shall be guaranteed.” However, in a classroom, the user of the AI system is the student, and the bill says nothing about who consents when that user is a minor. It makes no reference to the Civil Code or to any other legal standard. As currently drafted, a school could satisfy this principle by obtaining informed consent from a 14-year-old. This is perhaps the most important provision across all 4 measures and, as presently written, does not require any parental involvement.

Why Should This Matter to You?

  • Because it is worth examining how these bills seek to identify at-risk students. Senate Bill 348, for instance, devotes 1 clause to it. On the other hand, the EU classifies this as a high-risk AI use requiring documentation, human oversight, and a fundamental rights impact assessment. If some version of this bill passes, this provision will likely be the one posing the greatest risk of adversely affecting a student — and it currently has no accuracy standard and no appeal process outlined in the bill.
  • Because if you work at a private school, you need to at least read House Bill 968 today. If your school is drafting an AI policy, it is worth preparing it — or revising your existing policies — along the 6 principles the bill sets out, so that you can comply with this bill if it becomes law.
  • Because vendors of educational products in Puerto Rico may already be bound by very different laws. A company built to satisfy the EUAIA’s high-risk obligations will produce a materially different product from what might be permitted in Puerto Rico. If you are considering a vendor for your educational institution, we recommend asking whether its system complies with Annex III — a fast way to learn how seriously they take these requirements, even when local law does not demand it.
  • Because if you care about parents being able to approve which educational programs their children use, you need to read 968 closely. It is the only bill that addresses informed consent, but it asks for it from the “user” — that is, the student — and says nothing about who consents on behalf of a minor. If that provision is stripped out, all that will remain for parents are the perception surveys mandated by Article 8 of 427, once the pilot has ended.
  • Because Puerto Rico needs to define at what age its children may interact with AI. Although the Guide says “13 or older” as a general rule, 427 would begin in pre-K if the Senate amendment prevails; 348 sets no grade limit at all on AI use; and 968 leaves it to each educational institution’s discretion. As a result, there is no definitive answer or position on a question that New York, Beijing, and Brussels have all treated as fundamental.
  • Because Puerto Rico appears to be charting a different course from the current consensus. The similarities among NYC, China, and the EU send a strong signal: these 3 systems, with very different policies, have independently concluded that their youngest students should not be talking to chatbots in the classroom. Those findings should be considered when a local law is taken up.

In Conclusion

New York City’s moratorium is significant because it was accomplished through a simple administrative decision, with no law at all. That was similar to what the DE did with the Guide — which set Puerto Rico on a very different course from NYC’s.

There is insufficient evidence at this time to say whether one approach is better than the other. It is a valid argument that a one-year moratorium protects a critical window in childhood development. An equally valid response is arguing that pulling AI out of classrooms widens the gap between students whose families let them access it from home and those whose families do not. House Bill 427 seeks to close that gap, and that is a legitimate goal.

In Puerto Rico’s case, however, what cannot currently be defended and needs to be reckoned with is that both legislative chambers filed bills to deploy AI in classrooms without first establishing a governance framework. The consequences of this decision are already visible: the most advanced bill has spent 7 months in Conference Committee after being passed unanimously by both the House and the Senate, precisely because there is no agreement on what it should say.

The order we propose is the one the EU used, prohibiting emotion inference in the classroom before the products arrived there, which is what New York City is doing this year: imposing a moratorium, convening a coalition, gathering evidence, and then making an informed decision.

Finally, if the Puerto Rico Legislature wants to create a lasting impact in this area, it is going to have to legislate it, and not leave it to each school’s discretion. When legislating, we believe it is essential to start with governance and principles, and then —once those are approved— begin implementation. That would avoid passing a bill that lets a kindergartner spend all day talking to and learning from a chatbot in the classroom, only to then seek a law saying whether that is appropriate and how it should be done.

If your school or educational products company wants to understand what standards apply in Puerto Rico, or wants to implement a governance policy on AI use at your institution, you can book a consultation with us today. We are here to help.

Can I be sued over an algorithm that I didn’t even program?

Learn how the settlement Meta reached with 52 attorneys general could set a standard that impacts your business.

The United States has no federal artificial intelligence statute. There is no American equivalent of the EU AI Act, no agency that certifies AI models, and no registry of high-risk systems. And yet, on August 26, 2026, Meta — the parent company of Facebook, Instagram and WhatsApp, among others — agreed to subject Instagram and Facebook to an algorithmic governance regime with mandatory error thresholds, annual third-party testing, and an independent auditor who reports to state attorneys general.

It did not take a federal AI law to get there. Instead, it required the political will of a bipartisan coalition of state attorneys general determined to litigate against Meta, and that litigation produced a settlement agreement whose effects will be felt across every state and territory, Puerto Rico included.

That is the point worth absorbing for anyone working in AI governance: while we waited for comprehensive federal legislation, algorithmic regulation in the United States arrived through consumer protection litigation.

What was the case that led to this outcome?

The settlement was reached inside a consolidated proceeding, In re Social Media Adolescent Addiction/Personal Injury Products Liability Litigation (MDL 3047, Northern District of California), which consolidated several state lawsuits against Meta on 2 legal theories:

  1. Unfair and deceptive practices, under what are known as state “UDAP” statutes (Unfair and Deceptive Acts or Practices). The states alleged that Meta designed its platforms to maximize the time adolescents would spend on them — through notification mechanics, infinite scrolling, and social rewards — while publicly representing that its products were safe and that its protective tools worked as advertised.
  2. COPPA violations. COPPA is the federal privacy statute protecting children under 13, and the states alleged Meta collected children’s data without verifiable parental consent, among other failures.

Meta denied all liability, and the agreement signed last week contains no admission of wrongdoing. Nevertheless, Meta will pay a guaranteed minimum of roughly $12.7 billion to what may be 48 states, the District of Columbia and 3 territories — Puerto Rico among them — distributed over the next 10 years. That figure could rise, according to Meta, to approximately $18 billion if other platforms meet certain conditions.

Five pieces of AI governance hidden inside a consumer protection settlement

Beyond a payment of a magnitude that would be catastrophic for the vast majority of companies worldwide, the more significant fact may be this: under the agreement, Meta committed — potentially for the next decade — to what is arguably the first AI governance framework established inside a legal proceeding. This agreement will need to be studied by every business, and particularly by those that market to minors or that know their websites and apps are used by minors.

The governance framework the agreement establishes:

1. A model with a written error threshold.

Meta is required to deploy age estimation methods — trained classifiers, not sign-up forms — and to meet maximum false positive rates: roughly 10% for minors aged 16 and 17, and 3% for the 13-to-15 group, with wider tolerances during the first year for proprietary methods. The agreement also requires Meta to build and test a dedicated model to detect users under 13, with annual detection targets.

This is remarkable. An American judicial settlement is fixing the minimum statistical performance of a machine learning model, by age group, in concrete numbers — leaving none of the ambiguity that “reasonable” or “commercially appropriate” criteria would have allowed.

2. Annual algorithmic audit by an independent third party.

An independent auditor will verify, on an annual basis, the false positive rates, the volumes of underage account detection, the effectiveness of the account-linking models, and the efficacy of the usage pauses, and will report to the states. In practice, this is an algorithmic system audit analogous to the one Article 37 of the European Digital Services Act (“DSA”) requires annually of very large platforms — with the difference that, in the United States, the requirement did not arrive through legislation but embedded in a consent judgment.

3. Purpose limitation on the model’s data.

Data collected to estimate age must be deleted immediately after the age determination is made, protected under the company’s highest standards, and may not be used for advertising, marketing, or to optimize recommendation models.

4. A right to contest an automated decision.

If the system misclassifies your age, Meta must offer a clear and conspicuous mechanism to appeal that determination, and must resolve it within a reasonable time.

5. The recommendation system becomes a regulated object.

Meta must offer a chronological feed — with no algorithmic personalization — on a reasonably accessible basis, present it actively to new teen accounts within the first 10 days, and remind users every 90 days. Supervising parents can lock that feed as the default. Add to this that teens will, by default, be unable to see how many likes or reactions posts receive; the pauses at 60 and 90 minutes of use; the overnight block; and the silencing of notifications during school hours.

The agreement does not treat the recommendation algorithm as an untouchable trade secret, but as a product feature that a regulator can order switched off where it is found to be defective, deceptive or abusive.

The global view: Europe reached a similar determination first, but through a different legal route

If these terms sound familiar to anyone who works with European regulation, that is because they are. On April 29, 2026, the European Commission preliminarily found that Meta had breached the Digital Services Act precisely for failing to identify, assess or mitigate the risk of children under 13 accessing Instagram and Facebook. The Commission estimated that between 10% and 12% of children under 13 in the EU use those platforms, and criticized a reporting tool for underage accounts that required up to seven clicks. Fines under the DSA can reach 6% of a company’s total worldwide annual turnover.

The European instruments worth remembering for these matters include:

  • DSA. Article 28 requires privacy, safety and security measures for minors and bars advertising based on profiling directed at minors; Articles 34 and 35 require assessment and mitigation of systemic risks, including effects on the physical and mental well-being of minors; Article 37 imposes annual independent audits; and Article 38 requires very large platforms to offer at least one recommender option not based on profiling. In other words: the chronological feed the states extracted from Meta by settlement is already a legal obligation in Europe.
  • GDPR. Article 8 governs children’s consent; Article 5(1)(b) and (c), purpose limitation and data minimisation; Article 22 and Recital 71, automated decision-making, which “should not concern a child”; Article 25, data protection by design and by default; and Article 35, impact assessments. In February 2025,the European Data Protection Board issued a statement on age assurance setting out 10 principles that anticipate, almost point for point, what the Meta settlement now requires: proportionality, minimisation, demonstrable effectiveness, safeguards against automated decision-making, and the warning that age assurance “should not provide additional means for service providers to identify, locate, profile or track natural persons.”
  • AI Act. Less applicable than one would expect, and it is worth understanding why. Article 5 — in force since February 2, 2025 — prohibits AI systems that exploit vulnerabilities arising from age in order to materially distort behaviour and cause significant harm, which describes the states’ theory about Meta’s addictive design. But the high-risk obligations under Annex III — the ones that bring risk management, data governance, technical documentation, human oversight and accuracy requirements — were deferred by the Digital Omnibus agreed in 2026, and now begin on December 2, 2027.

So, as things stand, the European instrument designed expressly to govern AI does not yet fully apply to these systems, while an American court settlement, negotiated under consumer protection laws dating to the 1970s, is already formally setting error thresholds and audits. Consequently, AI governance did not arrive through the creation of a purpose-built legal framework, as everyone assumed it would.

Why should this matter to me?

  1. Because you do not need an AI law for someone to demand AI governance from you. Any deceptive practices statute — Puerto Rico’s included — can be used to ask whether your model does what you said it does. If your company claims its system “detects fraud with 99% accuracy” or that its algorithm “does not discriminate,” that is a legally enforceable representation, and the burden of proving it is yours.
  2. Because the evidentiary standard in these cases has shifted. Meta did not lose because of what it did. Its legal exposure came because of the distance between its public representations and its own internal documents. In algorithmic governance cases, you generate the adverse evidence yourself: your evaluation metrics, your risk memos, the service tickets and complaints nobody inside the company ever addressed.
  3. Because numerical obligations are now being normalized. Once a public settlement establishes that an age classifier must operate at a 3% false positive rate for the 13-to-15 age group, that number becomes the reference point for the next case, the next contract, and the next negotiation with an enterprise customer.
  4. Because transatlantic convergence is becoming real. This settlement and the European regulatory framework point at the same approach — one that looks at the defects, risks and harms a product causes, and imposes nearly identical remedies. If you build for both markets, designing twice will increasingly be seen as wasted money: to be safe and to limit liability, you will have to operate to the most demanding standard.

How can I comply?

  1. Inventory your automated systems. Not just what you call “AI.” Include your scoring models, classifiers, recommendation engines and segmentation rules, among others. You cannot govern what you have not counted.
  2. Define the metrics before you deploy, not after. What is the acceptable error rate? For which subgroups? Who measures it, and how often? Write it down before a regulator or a court writes it for you.
  3. Build purpose limitation into your data pipeline. Data collected for compliance — verification, security, fraud prevention — must not be recycled for training, marketing or profiling. Beyond writing policies to that effect, create technical documentation that substantiates it.
  4. Build a mechanism to respond to individual complaints. Every automated decision affecting a person needs a visible route of appeal and a human being to handle it. This is already required in Europe under the GDPR, and it will increasingly be expected in the states.
  5. Prepare for an audit you cannot control. Assume that at some point a third party will ask for your evaluation documentation, your decision logs and your model change history. If that does not exist today, we recommend you build it within the next three months.
  6. Review your model vendors. If your classifier is built or maintained by a third party, their error rates are your error rates. Ask for certifications and keep them.
  7. If you are in Puerto Rico, start now — do not wait for a local AI statute. We already have Act 163 of 2026, which amended the Right to One’s Own Image Act to expressly cover representations generated, cloned or simulated by artificial intelligence, commonly known as deepfakes. And, if your business offers services to people in the European Union, the GDPR and the DSA apply to you even if your office is in San Juan, Aguadilla or Ponce.

Conclusion

For years, the conversation about AI governance in the United States circled around a single question: when will a federal AI law arrive? The Meta settlement suggests that this was the wrong question.

Algorithmic regulation arrived with no AI statute, no specialized agency and no legislative process. It arrived as a negotiated remedy inside a case, with numbers, deadlines and an auditor. And it arrived with a principle that applies to any organization deploying models, whether it has 50 employees or 50,000: if you cannot measure your system, you cannot defend it.

Europe built this order through regulations. The United States just wrote it into a consent judgment. The result, for whoever builds the products, is very nearly the same.

Want to know whether your business’s automated systems can withstand this kind of scrutiny? You can book a consultation with us today. We are here to help.

About the Author

Jaime Farrant is an attorney admitted to practice in Puerto Rico, New York, Maryland and the District of Columbia, with an LL.M. in International Law, focused on privacy, cybersecurity and artificial intelligence regulation for businesses and healthcare providers.

ATTORNEY ADVERTISING. This article constitutes advertising as defined under the rules of professional conduct in force in New York (22 NYCRR 1200.7.1 and 1200.7.3), Maryland (Rule 19-307.1 and 19-307.2) and the District of Columbia (D.C. Rules of Professional Conduct 7.1), as well as the Puerto Rico Rules of Professional Conduct (Rules 7.1-7.3). It does not constitute solicitation of known potential clients in need of legal services in a particular matter. Rather, it is general information directed to the public about the practice of law and the legal services available. No attorney-client relationship is created by reading this article or by contacting the author.