Tag: attorney

Should Puerto Rico Ban Artificial Intelligence in its schools?

New York City just banned it for 600,000 students.

On September 2, 2026, New York City — through Mayor Zohran Mamdani and Schools Chancellor Kamar Samuels (equivalent to the city’s secretary of education) — did something no U.S. school system had done before: it paused the rollout of technology in the classroom, when they announced a 1-year moratorium on the use of generative artificial intelligence (”GAI”) in the city’s public schools. This means that, for the 2026-27 school year that has just begun, the roughly 600,000 students there in grades 2-K through 8th will not be able to use student-facing GAI. In addition, companion chatbots will be prohibited across all grades.

From a legal standpoint, perhaps the most striking thing about this announcement is that New York did not pass any law to impose its moratorium. The mayor and the chancellor simply made an administrative decision about what software would run on school devices, and with that decision, made a dramatic change in academic policy. 

Their decision leads us to ask: are other jurisdictions passing laws on how AI is used in the classroom? Or, are these new technologies simply being rolled out through memoranda and administrative decisions? And, since we write from Puerto Rico, we ask ourselves: which model does our island follow — or could follow?

Before answering those questions, let’s start with a summary of the Mamdani and Samuels announcement.

What Did New York Actually Do?

The moratorium is far more detailed than what the headlines suggest. It is not an outright ban, but a framework that establishes the following:

  • 2-K through eighth grade: A complete prohibition on student-facing GAI and chatbots that interact with students. Additionally, companion chatbots will be prohibited across all grades, from 2-K to high school.
  • High school: Twice a year, students will receive a 45-minute AI literacy module covering fundamentals, bias, ethics, and the impact on the professions. In other words, they will be taught about AI, not with AI. While students at this level will fall outside the general moratorium, the ban on companion chatbots will apply to them.
  • Pilot program: Up to 50,000 high school students (roughly 5% of enrollment) will have access to a pilot program with 5 approved AI tools (Quill, Edia, Brisk Teaching, Playlab, and Intel AI-Ready Schools) under strict time limits and teacher supervision.
  • Screen time: For students in second grade and below, individual screen use (”1:1 screen time”) will be restricted, though that restriction has not yet been spelled out in detail; and caps of up to 30 minutes a day are recommendedfor third through fifth grade and 45 minutes for sixth through eighth.
  • “Technology in Schools Coalition” was created that will convene throughout the year and publish recommendations. On this, Chancellor Samuels stated in the mayor’s press release: “We’re standing firmly in our belief that innovation does not mean more technology, and over the next year, we will lead with evidence to make sure technology serves learning — not the other way around.”
  • Important exceptions: AI may continue to be used in support programs for students with disabilities, multilingual learners, and career readiness programs. In addition, teachers may continue using AI for lesson planning and administrative work.

In short, New York City did not craft a policy out of “fear” of technology. It crafted one that distinguishes between AI as a tool “adults may use,” AI as a “subject students study,” and AI as “a thing that talks directly to a nine-year-old” — banning only that last category.

How Is AI Used in European Union Classrooms?

The European Union passed the EU AI Act (”EUAIA“), the most developed AI statute in the world, which, regulates the use of AI in education, among other areas. Notably, the EUAIA does not tell a school from what grade it may use AI. What it does is regulate the product: it imposes obligations on whoever develops and sells software or applications, and on whoever deploys the technology — including the school itself.

The EUAIA has 3 key provisions on this subject:

  • Article 5(1)(f) prohibits developing, marketing, or using AI systems that infer the emotions of natural persons based on biometric data in educational institutions and the workplace, allowing only very narrow exceptions for medical and safety purposes. Accordingly, in the European Union, it is illegal for a vendor to offer a school a camera system that monitors whether students are actively participating in class.
  • Annex III of the EUAIA classifies AI systems used in education as high-risk — particularly those that determine access to education, evaluate learning outcomes (including steering the learning process), assess the appropriate level of education, and monitor prohibited behavior during exams. A high-risk designation does not mean the product is banned, but that it will be heavily regulated. As of August 2, 2026, providers must maintain technical documentation and risk management systems, apply CE marking, register in an EU database, and provide for human oversight. Deployers, in turn —with schools included— must ensure adequate human oversight, retain logs for at least 6 months, notify individuals when they are affected by a high-risk system, and, if they are public entities, conduct fundamental rights impact assessments.
  • Article 50 of the EUAIA adds transparency requirements across the board. Users must be told when they are interacting with a chatbot, when the content they are reading is AI-generated, and when emotion recognition systems are in use.

The EUAIA penalizes these violations with fines of up to the greater amount between €15 million or 3% of total worldwide annual turnover, and up to €35 million or 7% of worldwide annual turnover for prohibited practices.

In sum, the EU’s answer to “can a second-grader use a chatbot?” is: “that’s the school’s call. However, there is a compliance regime that will make deploying bad edtech expensive and make software that reads emotions illegal.”

What Has China Done About It?

In May 2025, China’s Ministry of Education issued guidelines regulating GAI in primary and secondary schools that resemble the one announced in New York City. For example:

  • Primary school students are prohibited from independently using open-ended GAI content tools.
  • Middle school students may explore and analyze the logical structure of AI-generated content, and understand how these systems work.
  • High school students may engage in inquiry-based learning on the technical principles of AI and even develop and optimize AI models.

Separately, all students are barred from submitting AI-generated work as their own, using AI to cheat, or relying excessively on the technology for creative tasks without applying critical thinking. In addition, AI may not directly evaluate students or answer exam questions.

How Is AI Use in Schools Regulated in Puerto Rico?

Although Puerto Rico has enacted several laws on AI — such as Law 163-2026, which we covered previously — as of today, there is no law governing how AI may be used in a classroom.

The Puerto Rico Department of Education (”DE”), however, recently approved a policy that points in opposite direction from New York’s. Approved in December 2025 and published in January 2026, the Guía Para el Uso de la Inteligencia Artificial en el Aprendizaje Estudiantil (Guide for the Use of Artificial Intelligence in Student Learning, the “Guide“) names Microsoft Copilot, on its first page, as the official classroom platform for students aged 13 and up. The Guide further provides that only institutional accounts may be used when working with DE equipment and AI systems and, on page 23, establishes that students under 13 — or older students with academic delays or functional diversity — may use Learning Accelerators. It also requires that AI tools comply with federal and state data protection laws through the Office of Information Systems, and provides that students will be taught to not to enter sensitive personal information or information identifying other people. The Guide cites several reference sources, including recommendations from the U.S. Department of Education and UNESCO’s Recommendation on the Ethics of Artificial Intelligence.

Comparing the Guide against NYC, there is a clear contrast. The Guide provides that students at least 13 years old may use AI — an age likely borrowed from the federal COPPA statute, which imposes verifiable parental consent requirements on operators of websites and online services directed to children or that collect personal information from children under 13. COPPA does not set a minimum age for a minor to use a tool: it imposes obligations on the operator collecting the data. In other words, the Guide appears to have borrowed a threshold designed for a different problem. NYC, by contrast, draws its line at eighth grade — which on average means age 14 — and, unlike Puerto Rico, sets prohibitions rather than permissions.

The Guide is fundamentally about how students may use AI. NYC is trying to answer whether students may use AI.

Beyond the Guide, at least four bills on AI in education have been debated in the Puerto Rico Legislature, although, as of this writing (September 9, 2026), none has become law. They are:

MeasureFiledSponsorWhat it doesStatus
P. de la C. (House Bill) 4272025-03-20Rep. Tatiana Pérez Ramírez (PNP) and Rep. José F. Aponte Hernández (PNP)3-year pilot program deploying AI conversational-English tutors in 25 schools as passed by the House; the Senate committee report cuts it to 21 and adds that it begin in pre-K through third grade.Passed the House on May 12, 2025. The Senate Committee on Science, Technology and Artificial Intelligence reported it with amendments on March 10, 2026; now before Senate Rules and Calendar.
P. del S. (Senate Bill) 3482025-02-19Sen. Brenda Pérez Soto(PNP) with three co-authors: Karen Román Rodríguez (PNP), Gregorio Matías Rosario(PNP), and Rafael Santos Ortiz (PNP)Establishes AI as an instructional and work tool across the DE, creates a compliance officer, and sets a pilot program in 2 high schools per region. Sets no grade or age limit on AI use.Passed the Senate 24-0 on June 9, 2025 and the House 50-0 on reconsideration on January 29, 2026. The Senate rejected the House amendments on February 5, 2026. Now in Conference Committee.
P. del S. (Senate Bill) 8202025-10-16Sen. Brenda Pérez Soto (PNP)Establishes a media and digital literacy program across grades K-12, including algorithms, AI, and deepfakes.Passed the Senate on March 26, 2026. The House Education Committee reported it on June 11, 2026; that report was withdrawn on June 25, 2026 and the bill returned to committee.
P. de la C. (House Bill) 9682025-11-07Rep. José F. Aponte Hernández (PNP)Requires the DE and all private schools to adopt ethical AI use policies.In the House Education Committee since November 10, 2025.

Before walking through each bill, two things are worth flagging at the outset:

  1. Both the House and the Senate filed AI implementation bills (348 and 427) in early 2025, and several months later filed governance bills (820 and 968). This matters because this order, in which a technology is adopted first and governed second would force Puerto Rico simply to “govern” what it “already bought,” rather than first establishing “whether it needs to buy” and “what to buy” before deciding what to buy. This process is not being followed due to lack of legislative will: 348 was approved unanimously in both chambers, yet it has sat for seven months in Conference Committee because the 2 chambers do not agree on the text.
  2. There appear to be legislative discrepancies about age. Although the House set no minimum age in 427, the Senate Committee on Science, Technology and Artificial Intelligence added that it AI instruction can begin in grades pre-K through third. However, this is the same committee that reported on 348, whose pilot plan begins in high school. So we have 1 committee, 2 bills, 2 opposite answers to the same question, and no explanation of how it arrived at the ages and grades each one proposes.

Now, Farrant Explains each bill:

1. House Bill 427 — The Senate Wants to Start Using AI Tutors in Pre-K

On May 12, 2025, the Puerto Rico House of Representatives passed P. de la C. 427, titled Ley para la Implementación de la Inteligencia Artificial en el Programa de Inglés del Sistema Público de Enseñanza en Puerto Rico (Act for the Implementation of Artificial Intelligence in the English Program of Puerto Rico’s Public School System). Filed by PNP Representatives Tatiana Pérez Ramírez and José Aponte Hernández, it orders the creation of a 3-year pilot program to integrate an AI tool to help improve conversational English learning in Puerto Rico’s public schools, that will be administered by the DE in collaboration with PRITS.

The text the House passed provided that the pilot program would cover 25 schools and set no grade level at all. However, the marked-up text accompanying the Senate committee report of March 10, 2026 changed that to 21 schools (3 per region) and added that the pilot begins in grades pre-K through third. Those ages contrast sharply with New York’s moratorium, which bars students between second and eighth grade from using conversational AI, and with China, which prohibits primary school students from independently using GAI. If 427 is enacted with the Senate amendment, it would mean that, starting in pre-K, Puerto Rican students will interact with GAI in the classroom.

This bill is very different from what New York City, Brussels, and Beijing have done, as it proposes:

  • A 2-year pilot program giving priority to rural and hard-to-reach schools, and to students with low scores on standardized English assessments. The program would begin with a 6-month process to select the schools and tools and train teachers, followed by 3 years of tool use with continuous monitoring, and then a program evaluation.
  • Requiring that the selected AI tools be capable of real-time, personalized interaction, provide immediate feedback on pronunciation, grammar, and fluency, and be compatible with the electronic devices available in public schools.
  • Creating an Evaluation Committee appointed by the Secretary of Education.
  • Providing annual reports to the Legislature and the Governor.

Separately, Article 7 of 427 as passed by the House required the AI tool to be selected “after the due process of evaluation and competitive bidding,” and titled the article “Tools to be used; competitive bidding.” The Senate’s marked up version struck the words “and competitive bidding” from both the heading and the body, leaving only “the due process of evaluation.” As people who believe in compliance with the law and government transparency, this deletion concerns us — particularly when what is being selected here is a system that will teach English to 4-year-olds in 21 public schools.

It is also notable that 427 says nothing about whether AI systems that measure or infer the emotions of natural persons based on biometric data will be permitted — a practice prohibited under Article 5 of the EUAIA.

2. Senate Bill 348 — Artificial Intelligence as a Work and Instructional Tool for Students and Teachers in the Puerto Rico Department of Education

This bill, filed by PNP Senator Brenda Pérez Soto 3 weeks before 427, is much broader in its scope, even though its pilot plan does start in high school. With regards to AI use, it sets no age or grade whatsoever. In fact, its Articles 3 and 5 authorize AI throughout the entire Department of Education.

If enacted, this bill would allow AI to be deployed across all courses as an instructional tool, not only in English classes. The bill also proposes:

  • Creating the position of Compliance Officer, appointed by the Secretary of Education and charged with overseeing compliance with the act.
  • Creating a technology innovation and AI unit under the Undersecretariat for Academic and Programmatic Affairs.
  • Establishing a Pilot Plan in two high schools per educational region. One of the schools must be officially designated as a school under an improvement plan, and the other must not carry that designation. It is important to note here that Article 7 describes the pilot plan as one to “evaluate and implement educational and administrative strategies that promote improved academic performance at the high school level” — yet it never mentions AI. In a bill about AI, it is striking that the only article naming a school level does not say the pilot will be an AI pilot.
  • Requiring that school communities — including parents and guardians — be given orientation on the ethical and responsible use of AI.

This bill, which has already been passed by both the House and the Senate but whose amendments were rejected by the Senate on February 5, 2026 and has been in Conference Committee ever since, is notable for the following:

  1. Its Article 3(b) provides that AI will be used as a tool to support and complement teachers’ work, and adds, in parentheses, “it shall not be to replace them.” It is the only 1 of the 4 measures that says so expressly — although placing a parenthetical clarification inside a declaration of public policy is highly unusual legislative drafting.
  2. The Article 7 Pilot Plan will be in high schools and not in pre-K, as 427 currently stands. However, as noted, that article does not mention AI, and the rest of the bill sets no grade level at all.
  3. Article 3(e)(5) requires that AI be used to “identify students at possible risk of failure: students who need additional support.” This would almost certainly be done through predictive risk profiling of minors — a practice the European Union has classified as a high-risk activity under its Annex III, since it would create an AI system used to evaluate academic outcomes or determine access to education. Operating such a system in the European Union would require compliance with obligations on documentation, logging, human oversight, and a fundamental rights impact assessment. In 348, however, this is a single clause that does not include any measurement standards, no human oversight requirement, no appeal process, and no rule barring that AI output from following the student through their academic record and transcript. While systems that identify at-risk students can help head off bigger problems, they can also turn into systems of “tracking and monitoring by algorithm.”

Finally, we can’t overlook the irony that both legislative chambers passed a bill to transform education in Puerto Rico containing a word in its title — instruccional — that is not recognized by the Royal Spanish Academy Dictionary. This is not an unavoidable technical term: the word appears to be adapted from the American term instructional design, and Spanish already has “instructivo,” which the dictionary does includeThe syntax is worse. The title of the bill calls AI a “herramienta de trabajo e instruccional”, literally, “a tool for work and instructional.” That phrase uncomfortably yokes a noun phrase to a bare adjective. “Herramienta de trabajo e instrucción” would have done the job. All of it is a small sign of how much of Puerto Rico’s AI-in-education vocabulary is imported rather than drafted here.

3. Senate Bill 820 — Puerto Rico Media and Information Literacy Act

820 was also filed by PNP Senator Brenda Pérez Soto. If enacted, it would require the Department of Education to build a curriculum aimed at achieving media, digital, and statistical literacy among Puerto Rico’s public school students, so they can develop essential skills in critical thinking, information evaluation, data analysis, and technology use.

820 further provides that this instruction will be emphasized in Spanish, social studies, science, and mathematics, beginning within the next 2 academic years or sooner.

The curriculum seeks to have students develop literacy in:

  • Critical evaluation of sources and verification of information.
  • Identifying disinformation and manipulation — whether false information, deepfakes, manipulated images, sensationalist headlines (clickbait), or other forms of altered content.
  • A basic understanding of how algorithms and artificial intelligence work.
  • Fact-checking and corroboration, applying fact-checking methodologies, using digital verification tools, reverse image search, consulting multiple reliable sources, and triangulating information to confirm accuracy.
  • Ethical and responsible production of digital content, including factual accuracy, proper source citation, and responsibility in disseminating information.
  • Respect for privacy, intellectual property, and digital rights.
  • Developing healthy habits in technology use.
  • Interpreting data, identifying potentially misleading statistical representations, and critically analyzing quantitative information.

Implementation would rest on a continuing teacher training program, with certifications, microcredentials, and other verifiable credentials counting as professional development hours.

This bill is the closest to what New York City announced, since it seeks to have students know and understand algorithmic systems regardless of whether they use them in class. Its statement of motives, moreover, does its own comparative-law work, citing California’s AB 873 (2023) and its 2024 expansion, along with the strategies of Finland, Sweden, and Canada.

Its weakness, however, is similar to 968’s: it is an unfunded mandate. Article 10 simply directs the DE to implement it through “the optimization of existing human, technological, financial, and infrastructure resources within the Department of Education, maximizing the use of low-cost or free virtual platforms, open educational resources, collaborative alliances with universities and nonprofit organizations, and training in hybrid and virtual formats that reduce operating costs.” It is also silent on how age-appropriate curricula will be established, or at what age it will begin — a curious omission, given that the bill’s own premise is that children’s developmental stages make them vulnerable to manipulation.

4. House Bill 968 — Act on the Ethical Use of Artificial Intelligence in Puerto Rico Educational Institutions

This AI governance bill was filed by PNP Representative José Aponte Hernández. It is very different from 427 in that it does not mandate the deployment of any tool. Instead, it requires the DE to adopt and implement policies on the ethical use of AI in public schools and to oversee compliance with them. It likewise obligates every private educational institution registered under Law 212-2018 to adopt and implement similar policies at their respective academic entities and to file those policies with the Puerto Rico Department of State within no more than 180 days of the act’s approval.

968 establishes that every policy must include the following general principles:

  • Security and protection.
  • Autonomy.
  • Privacy.
  • Transparency and explainability.
  • Diversity and inclusion.
  • Responsibility and accountability.

Article 6 also requires that, “prior to the integration of artificial intelligence systems in public schools and private educational institutions, and in each subsequent school year, students and both teaching and non-teaching staff shall receive orientation and training on the ethics and responsible use of AI technologies in instruction, including the policies adopted.”

968 stands out as a bill that will require schools to enact policies with certain principles. However, it does not say anything about what constitutes a policy that fails to comply with the act, who will review those policies, or what happens when an institution files a deficient one. Nor does 968 establish penalties or authorize private civil actions to compel compliance. It also does not establish the ages at which an educational institution may deploy AI, leaving it to the discretion of each school. 

There is also 1 provision that deserves special attention. The Privacy principle in Article 5 provides that “the informed consent of the user shall be guaranteed.” However, in a classroom, the user of the AI system is the student, and the bill says nothing about who consents when that user is a minor. It makes no reference to the Civil Code or to any other legal standard. As currently drafted, a school could satisfy this principle by obtaining informed consent from a 14-year-old. This is perhaps the most important provision across all 4 measures and, as presently written, does not require any parental involvement.

Why Should This Matter to You?

  • Because it is worth examining how these bills seek to identify at-risk students. Senate Bill 348, for instance, devotes 1 clause to it. On the other hand, the EU classifies this as a high-risk AI use requiring documentation, human oversight, and a fundamental rights impact assessment. If some version of this bill passes, this provision will likely be the one posing the greatest risk of adversely affecting a student — and it currently has no accuracy standard and no appeal process outlined in the bill.
  • Because if you work at a private school, you need to at least read House Bill 968 today. If your school is drafting an AI policy, it is worth preparing it — or revising your existing policies — along the 6 principles the bill sets out, so that you can comply with this bill if it becomes law.
  • Because vendors of educational products in Puerto Rico may already be bound by very different laws. A company built to satisfy the EUAIA’s high-risk obligations will produce a materially different product from what might be permitted in Puerto Rico. If you are considering a vendor for your educational institution, we recommend asking whether its system complies with Annex III — a fast way to learn how seriously they take these requirements, even when local law does not demand it.
  • Because if you care about parents being able to approve which educational programs their children use, you need to read 968 closely. It is the only bill that addresses informed consent, but it asks for it from the “user” — that is, the student — and says nothing about who consents on behalf of a minor. If that provision is stripped out, all that will remain for parents are the perception surveys mandated by Article 8 of 427, once the pilot has ended.
  • Because Puerto Rico needs to define at what age its children may interact with AI. Although the Guide says “13 or older” as a general rule, 427 would begin in pre-K if the Senate amendment prevails; 348 sets no grade limit at all on AI use; and 968 leaves it to each educational institution’s discretion. As a result, there is no definitive answer or position on a question that New York, Beijing, and Brussels have all treated as fundamental.
  • Because Puerto Rico appears to be charting a different course from the current consensus. The similarities among NYC, China, and the EU send a strong signal: these 3 systems, with very different policies, have independently concluded that their youngest students should not be talking to chatbots in the classroom. Those findings should be considered when a local law is taken up.

In Conclusion

New York City’s moratorium is significant because it was accomplished through a simple administrative decision, with no law at all. That was similar to what the DE did with the Guide — which set Puerto Rico on a very different course from NYC’s.

There is insufficient evidence at this time to say whether one approach is better than the other. It is a valid argument that a one-year moratorium protects a critical window in childhood development. An equally valid response is arguing that pulling AI out of classrooms widens the gap between students whose families let them access it from home and those whose families do not. House Bill 427 seeks to close that gap, and that is a legitimate goal.

In Puerto Rico’s case, however, what cannot currently be defended and needs to be reckoned with is that both legislative chambers filed bills to deploy AI in classrooms without first establishing a governance framework. The consequences of this decision are already visible: the most advanced bill has spent 7 months in Conference Committee after being passed unanimously by both the House and the Senate, precisely because there is no agreement on what it should say.

The order we propose is the one the EU used, prohibiting emotion inference in the classroom before the products arrived there, which is what New York City is doing this year: imposing a moratorium, convening a coalition, gathering evidence, and then making an informed decision.

Finally, if the Puerto Rico Legislature wants to create a lasting impact in this area, it is going to have to legislate it, and not leave it to each school’s discretion. When legislating, we believe it is essential to start with governance and principles, and then —once those are approved— begin implementation. That would avoid passing a bill that lets a kindergartner spend all day talking to and learning from a chatbot in the classroom, only to then seek a law saying whether that is appropriate and how it should be done.

If your school or educational products company wants to understand what standards apply in Puerto Rico, or wants to implement a governance policy on AI use at your institution, you can book a consultation with us today. We are here to help.

Can I be Sued for Discrimination Under Puerto Rico’s Law 100 for Using ChatGPT at Work, Even if I Never Meant to Discriminate?

In our article published 2 weeks ago, we talked about how using AI to screen résumés exposes you to laws that prohibit workplace discrimination. Today, we want to focus on the risks you face if you operate in Puerto Rico under a law that almost no vendor will mention when you’re evaluating an automated “screening” tool: Law Num. 100 of June 30, 1959, Puerto Rico’s employment discrimination law, which applies even though its text doesn’t contain the word “algorithm” — and adds consequences that neither U.S. federal law nor the European Union impose.

What Does Law 100 Presently Say?

Before 2017, Law 100 gave employees a powerful tool: it provided that an adverse action — such as failing to hire, failing to promote, or terminating someone — taken without just cause, was presumed to be discriminatory. Once the employee triggered that presumption, the burden shifted almost entirely to the employer, who then had to affirmatively prove that no discrimination had occurred.

That changed with the Labor Transformation and Flexibility Act (Law 4 of 2017), which eliminated that presumption in order to align Puerto Rico with the federal standard known as McDonnell Douglas. Today, a claim under Law 100 works much like a federal one: the employee must establish a preliminary case (that they belong to a protected class, that they were qualified, that an adverse action occurred, and that similarly situated people outside that protected class were treated better). Once an employee does this, the employer must articulate a legitimate, non-discriminatory reason for the decision. If the employer does so, the burden shifts back to the employee, who must then prove that reason was pretextual.

In short: today, the burden of persuading the court that discrimination occurred rests more on the employee than on the employer.

However, AI introduces a real problem for employers even under this favorable standard. As mentioned above, the second step of the analysis requires you to be able to articulate a legitimate reason for the rejection. If your entire process was uploading résumés to a third-party tool and letting an algorithm screen them out, what is your legitimate reason for rejecting them? Answering “The system gave them a lower score” isn’t always enough — especially if the candidate can show, through statistics (as allowed under Title VII’s disparate-impact theory), that the tool’s rejection pattern — for example, disproportionately screening out women for a position — correlates with a protected category. In that scenario, your inability to explain the decision becomes the very evidence of pretext the candidate or employee needs to prevail.

That said, even though the burden of proof is no longer automatically stacked against the employer, Law 100 still has something Title VII doesn’t: harsher penalties, discussed below.

What Are the Penalties Under Law 100?

Law 100 imposes civil liability on the employer for double the damages caused (or between $500 and $2,000 if damages cannot be determined). In addition, discriminatory conduct may constitute a misdemeanor, punishable by a fine of up to $5,000 or up to 90 days in jail, or both. None of this exists under any federal anti-discrimination law. As a result — although it is uncommon for these cases to be prosecuted criminally — using AI to screen résumés could technically expose you to criminal liability in Puerto Rico. It’s a consequence many employers don’t know about or anticipate.

How Is This Regulated in Other Jurisdictions?

  • United States: there is no single federal law governing AI in employment. Instead, there’s a patchwork of local and state rules — New York City’s Local Law 144, which mandates bias audits; Illinois’s requirement to notify candidates when AI is used to analyze video interviews; Colorado’s risk assessments — layered on top of existing federal anti-discrimination laws (Title VII, ADEA, ADA) enforced by the EEOC and interpreted under the U.S. Supreme Court’s McDonnell Douglasstandard. All of these can be boiled down to: you’re allowed to use AI tools, but be ready to justify them if challenged — and know the specific compliance requirements in whatever state you operate in or evaluate candidates from.
  • European Union: if your company works with candidates or employees in the EU, or you simply want to understand where AI regulation is headed globally, it’s worth looking at the EU AI Act (Regulation (EU) 2024/1689), already in force, and likely the most comprehensive legal framework on artificial intelligence in the world today. The EU AI Act classifies AI tools used for recruitment and personnel selection — including filtering job applications and evaluating candidates — as “high-risk” systems. That means that before they can be legally used, the tool must undergo a conformity assessment, have technical documentation, risk-management systems, human-oversight mechanisms, and be registered in an EU database. Employers also have a specific obligation to inform workers and their representatives of the system’s existence before using it. In the European Union, unlike in Puerto Rico and the United States, an employer must demonstrate that its platform is safe before using it.

The difference in approach is significant. While the EU certifies the tool before it’s used, Puerto Rico and the United States require nothing upfront, but impose legal consequences if the tool produces a discriminatory result.

Why Should This Matter to You?

Because using AI that discriminates against candidates puts you at risk of paying damages — and if you’re in Puerto Rico, it puts you at risk of criminal liability.

Think about it in practical terms: if your AI tool disproportionately rejects candidates of a certain age or background, and a candidate manages to prove pretext — for example, by showing that you couldn’t coherently explain why the system screened them out — you face the possibility of having to compensate the people affected by the algorithm, and of being held criminally responsible for having used it. For a small business or a clinic, that’s a genuinely significant exposure that goes beyond what you’d anticipate if you only looked at federal law as your benchmark, or if you assumed you were covered because ChatGPT was built “without any intent to discriminate” or because you used the AI tool in “good faith.”

How Can I Comply With the Law?

  1. Always have an articulable reason for every rejection. “The system gave candidate X a lower score” isn’t enough on its own. You need to be able to explain, in concrete terms tied to the job’s qualifications, why a candidate didn’t move forward in the interview process.
  2. Demand documentation from your vendor. Ask whether the tool has been bias-audited, how often, and whether they’ll provide you that documentation. That evidence is what lets you satisfy the “articulate a legitimate reason” step if it is challenged.
  3. Keep a record of every decision. What data went in, what score or result the system produced, and what human review occurred before each final decision. That log is your evidence if you ever need to defend the process.
  4. Notify candidates that you use AI in the process. It’s good practice in Puerto Rico, and it’s already mandatory under the EU AI Act if you have candidates or employees in Europe.
  5. Run a risk assessment before adopting the tool — not after the first complaint. Ask yourself: what data was it trained on? Which protected categories might it be indirectly affecting? Remember that Law 100 protects, among others: age, race, color, sex, sexual orientation, gender identity, social or national origin, social condition, political affiliation, political or religious beliefs, being a victim (or perceived victim) of domestic violence/sexual assault/stalking, veteran status, marital status, and even certain hairstyles and hair textures associated with particular racial identities or national origins.
  6. Review your contract with the vendor. Who’s responsible if the tool produces a discriminatory result? Negotiate that clause if you can.

The Bottom Line

Since the 2017 labor reform, Law 100 no longer puts you in a worse evidentiary position than federal law. What does set Puerto Rico apart is what happens if you lose: double damages and the possibility of criminal liability, neither of which exists under Title VII. Remember, too, that if you can’t explain why your tool rejected a candidate, you may already be in violation of the law. Finally, remember that you need to keep your processes documented, make sure they’re supervised by people, and be able to explain and justify every decision. Know and formalize your processes before you’re forced to do so in front of a government agency or a court.

Do you think your current AI-driven hiring process could expose you to legal liability under Ley 100 if a candidate filed a complaint today — or do you just want to make sure your processes are compliant? Let’s talk. Book a consultation here.

About the Author

Jaime Farrant is admitted to practice law in Puerto Rico, New York, Maryland and the District of Columbia. Practice in all other jurisdictions is limited to immigration law. This article is for informational purposes only and does not constitute legal advice or create an attorney-client relationship.

ADVERTISING MATERIAL. This article constitutes advertising as defined by the professional conduct rules in New York (22 NYCRR 1200.7.1 and 1200.7.3), Maryland (Rule 19-307.1 and 19-307.2), and the District of Columbia (D.C. Rules of Professional Conduct 7.1), and the Puerto Rico Rules of Professional Conduct (Rules 7.1-7.3). It is not solicitation of prospective clients known to need legal services in a particular matter. Instead, it is general information directed to the public about the practice of law and available legal services. No attorney-client relationship is created by your reading of this article or by contacting the author. Consult qualified counsel in each jurisdiction with specific situations.

Can I Use ChatGPT to Put Bad Bunny in my business’s social media ads?

As I write this post, social media in Puerto Rico has blown up with Bad Bunny’s announcement that he will close his world tour in concert scheduled for August 22 and 23 in San Juan’s Hiram Bithorn Stadium. The amount of posts about this announcement reminded me of the many promotions posted by Puerto Rican restaurants, bars, and small businesses in their Facebook, Instagram and TikTok accounts, where they showed a photo of Bad Bunny eating at their restaurant, or having a beer at their bar. However, he was never in any of these places. These were AI-generated images, posted without his consent, for one obvious reason — to draw customers to their businesses using the likeness of arguably the most recognizable person in Puerto Rico today.  However, no business paid a license, asked permission, or, in most cases, thought twice about it.

If your business operates in Puerto Rico, New York, Maryland, or Washington D.C., the answer to whether you can legally do this depends heavily on which of these you’re in — and the gap between them is bigger than most business owners realize.

In the US, How – or If – you can use Deepfakes Depends Entirely on Where You Live

Unlike Puerto Rico, which just amended its “Right to One’s Own Image” statute (Law 139-2011, as amended by Law 163-2026) to explicitly cover AI-generated deepfakes by penalizing their unauthorized commercial use with damages of up to $100,000 per violation if the use was intentional or with gross negligence, the United States has no uniform federal right of publicity. Each state decides for itself whether — or how — to protect someone’s name, voice, or likeness from unauthorized commercial use. That means that the same AI-generated Bad Bunny photo can be a serious legal problem in one state and close to unregulated in the state next door.

New York: The Strongest Protections of All

New York has protected this right since long before generative AI existed. Civil Rights Law §§ 5051 makes it a misdemeanor — and a civil cause of action — to use a living person’s name, portrait, picture, likeness, or voice for advertising or trade purposes without their prior written consent. Section 51 lets the injured person seek an injunction, actual damages, and, if the defendant knowingly used their likeness, exemplary (punitive) damages at the jury’s discretion.

On top of that foundation, New York has added two AI-specific layers in the last 2 years:

  • The Digital Replica Contracts Act (General Obligations Law § 5-302): voids contract provisions that let an employer replace a performer’s actual performance with a digital replica, unless the performer was represented by counsel or a union and the terms are stated clearly in a separately signed agreement.
  • The Synthetic Performer Disclosure Law (General Business Law § 396-b), effective June 9, 2026: requires advertisers to conspicuously disclose when an ad contains a “synthetic performer” created using generative AI. Civil penalties run $1,000 for a first violation and $5,000 for each subsequent one.

Put together, a New York business running that “Bad Bunny at my bar” photo is exposed on two fronts: a §§ 50–51 claim from Bad Bunny himself (or his estate, for that matter, since New York also protects deceased performers’ digital replicas under Civil Rights Law § 50-f), and a separate disclosure penalty if the ad used a synthetic element and didn’t label it.

Maryland: Barely Any Legal Protections at All

This is likely to surprise business owners coming from New York or Puerto Rico: Maryland has no right of publicity under its statutes or common law. It’s one of only a handful of states (along with Alaska, Kansas, and North Carolina) where this right doesn’t exist as such. A bill that would have created a civil cause of action for unauthorized use of someone’s identity via AI or deepfakes — House Bill 1425/Senate Bill 905 — did not pass in the 2025 session. It’s been reintroduced as House Bill 184 for the 2026 session, but as of this writing, it has not been approved.

Maryland does have a deepfake statute — Senate Bill 141 (2026), effective June 1, 2026 — but it is narrowly limited to election-related deepfakes intended to influence voting or misrepresent election facts. It has nothing to say about a restaurant using an AI-generated photo of a celebrity to sell arepas, margaritas or mofongo.

Practically, this means that today, a Bad Bunny impersonation ad run by a Maryland business faces essentially no exposure under Maryland state law specifically built for this problem. That could change if HB 184 passes, and it’s also worth remembering that Bad Bunny himself could still bring a claim in a state where he does have rights like New York, depending on where the harm occurred.

Washington D.C.: Regulated by Common-Law, Not a Statute

D.C. has no right-of-publicity statute either. What it has is a common-law claim for misappropriation, drawn from the Restatement (Second) of Torts § 652C, as applied in Vassiliades v. Garfinckel’s, Brooks Bros., 492 A.2d 580 (D.C. 1985). To win, a plaintiff has to show both that the defendant benefited from using their identity and that there’s a recognizable public or commercial value in that identity — the exact opposite of a bright-line statute like New York’s. This makes outcomes far less predictable and cases more expensive to bring, since there’s no statutory damages figure to point to and no per-violation civil penalty to threaten a defendant with.

How is This Regulated in the European Union?

The European Union has taken an approach very different than the patchwork of state laws in the US through its enactment of the EU AI Act, which applies across all Union states. The EU AI Act does not establish a standalone private right of action for damages; rather, it imposes administrative transparency obligations. Under Article 50 of the Act, providers of Al systems that generate or manipulate image, audio, or video content constituting a deepfake must clearly disclose that the content has been artificially generated or altered. An exception applies when such content is part of an obviously artistic, satirical, or fictional work, provided it is not presented in a misleading manner. Failure to comply with these transparency requirements constitutes a serious infringement, subject to administrative fines of up to €15 million or 3% of the undertaking’s total worldwide annual turnover for the preceding financial year, whichever is higher.

Why Should This Matter to You?

If you run a business — or advise clients who do — across any of these jurisdictions, the question “can I use an AI image of a celebrity in my ad” doesn’t have one answer, and responses range from “yes, expect a lawsuit and pay damages of up to $100,000” (Puerto Rico), to “yes, expect a lawsuit and possible punitive damages” (New York) to “there’s currently no statute built for this” (Maryland) to “it depends on how a judge applies a 40-year-old privacy tort” (D.C.), or “you must publish in your campaign that its content was artificially generated” (EU). Consequently, a marketing decision that’s clearly reckless in Manhattan might be legally uneventful across in Maryland — for now.

These differences are exactly the kinds of gaps that generative AI has widened. Tools like ChatGPT, Claude, Midjourney, and similar platforms make it trivial to generate a photorealistic image of a real, identifiable person for a fraction of what a licensing deal would have cost a few years ago. The law in most of the United States hasn’t caught up uniformly, which means your exposure depends less on what you did and more on where you did it.

How Can You Comply With the Law?

  • If you operate in New York, treat any AI-generated image or voice of a real person in your advertising as requiring the same written consent you’d need for a real photo — Civil Rights Law § 51 doesn’t distinguish between a real photograph and a generative AI recreation.
  • If your New York ad uses a synthetic performer (not a real, identifiable person, but a “no such person exists” AI-generated model), confirm you’re including the conspicuous disclosure required by GBL § 396-b before it airs.
  • If you operate in Maryland, don’t assume the absence of a right-of-publicity statute means zero risk — track HB 184, and remember a claim can still be brought in a state where the depicted person has stronger rights.
  • If you operate in D.C., document your process for obtaining consent regardless of the weaker legal baseline; a misappropriation claim can still succeed, and consent is always the safer route.
  • If you operate in Puerto Rico, make sure your processes clearly document that the use was authorized.
  • If you operate across multiple states, apply the strictest applicable standard (in this example, New York’s) to any content you plan to run across state lines or online, since your audience — and any resulting claim — isn’t limited to where your business is physically located.
  • If your campaign will be shown in the European Union, you will have to divulge that it was artificially generated.

The Bottom Line

Puerto Rico, New York, Maryland, D.C., and the European Union sit at very different points on the right-of-publicity spectrum — from New York’s statutes with real teeth, to Maryland’s near-total absence of protection, to D.C.’s uncertain common-law doctrine. If your business uses generative AI in marketing and you operate in more than one of these jurisdictions, the safest approach is to assume the strictest rule applies everywhere your content is seen, not just where you’re physically located.

Does your business use AI-generated content in advertising across New York, Maryland, or D.C.? Schedule a consultation today to review your exposure in each jurisdiction where you operate.

About the Author

Jaime Farrant is admitted to practice law in Puerto Rico, New York, Maryland and the District of Columbia. Practice in other jurisdictions is limited to immigration law. This article is for informational purposes only and does not constitute legal advice or create an attorney-client relationship. Laws referenced are current as of August 15, 2026.   

ADVERTISING MATERIAL. This article constitutes advertising as defined by the professional conduct rules in New York (22 NYCRR 1200.7.1 and 1200.7.3), Maryland (Rule 19-307.1 and 19-307.2), and the District of Columbia (D.C. Rules of Professional Conduct 7.1), and the Puerto Rico Rules of Professional Conduct (Rules 7.1-7.3). It is not solicitation of prospective clients known to need legal services in a particular matter. Instead, it is general information directed to the public about the practice of law and available legal services. No attorney-client relationship is created by your reading of this article or by contacting the author. Consult qualified counsel in each jurisdiction with specific situations.

Your Security Camera Vendor Wants to Cover Your Bathroom – Is that Worth 3 Years in Jail?

A security vendor offers you a great deal: a full camera package for your office or clinic, including units for “every room” — bathrooms included. Before you say yes, here’s the one word that should stop you: no.

Installing a camera in a bathroom isn’t a gray area. In most states, it’s either a specific criminal offense, an actionable civil tort, or both — regardless of whether you own the building, whether employees consented to “general” workplace monitoring, or whether your intent was purely about theft prevention.

All Kinds of Laws and Regulations Are Against Your Vendor’s Sales Pitch

Video surveillance law in the U.S. is a patchwork, but one principle is close to universal: people have a reasonable expectation of privacy in spaces where they may be nude or partially undressed — bathrooms, locker rooms, and changing areas top that list in nearly every jurisdiction.

The following layers of law apply here:

1. The federal wiretap/ECPA gap doesn’t help you here. Most security cameras don’t record audio, which is why they generally fall outside the federal Wiretap Act and the Electronic Communications Privacy Act (those statutes govern communications, not silent video). Business owners sometimes hear “no audio recorded, no ECPA problem” and assume that means video is unregulated. It isn’t. ECPA’s silence on soundless video just means you have to look elsewhere — and state law fills that gap fast, especially for restrooms.

2. State statutes specifically ban restroom and changing-area recording. California, for example, expressly forbids video recording in restrooms, locker rooms, and places where people change clothes. Many states have similar “video voyeurism” or “unlawful surveillance” statutes that criminalize recording — or even just installing recording equipment — in a place where someone has a reasonable expectation of privacy, whether or not any footage is ever viewed or used. These are often felony-level offenses, and consent from you as the business owner is irrelevant; the person being recorded is the one whose consent (or knowledge) matters.

3. Healthcare and other regulated settings add another layer. If you run a medical office, a bathroom camera also raises immediate collateral problems: patients or staff visible on camera in a restroom implicates dignity and privacy obligations that go well beyond HIPAA’s technical safeguards — it’s the kind of fact pattern that turns into a licensing board complaint, a media story, or both.

4. Even without a specific statute, common law will find you. Every U.S. jurisdiction recognizes some version of the tort of intrusion upon seclusion: intentionally intruding on someone’s private affairs in a way that would be “highly offensive to a reasonable person.” A camera in a bathroom is the textbook example courts use to illustrate this tort. That means even in a state without a dedicated criminal statute, an employee, patient, or customer who discovers the camera can sue you civilly — and juries tend to have little patience for this fact pattern.

What Does Puerto Rico’s Constitution and Penal Code Say?

If you operate in Puerto Rico, your exposure is arguably higher than in the 50 states, as the right to privacy here isn’t left to a patchwork of state statutes and common-law torts. It’s written directly into the Constitution.

Article II, Section 8 of the Puerto Rico Constitution states: “Toda persona tiene derecho a protección de ley contra ataques abusivos a su honra, a su reputación y a su vida privada o familiar” (Every person has the right to protection of law against abusive attacks on their honor, reputation, and private or family life). What makes this different from the U.S. Constitution is that the Puerto Rico Supreme Court has held that this right applies directly between private parties, not just against government action. In Arroyo v. Rattan Specialties, Inc., 117 D.P.R. 35 (1986), the Court held that the right to privacy operates ex propio vigore — on its own force — and can be asserted by one private citizen against another, including an employer against an employee. That means a bathroom camera dispute in Puerto Rico doesn’t need a separate statute to become a constitutional violation; the Constitution itself solves the controversy.

The Puerto Rico Penal Code then backs this up with a specific criminal provision. Article 168 of the Puerto Rico Penal Code, titled “Illegal recording of images”, makes it a crime for any person, without legal justification or a legitimate investigative purpose, to use electronic or digital video equipment — with or without audio — to conduct secret surveillance in private places, or in any other place where a reasonable expectation of privacy exists. A bathroom is about as clear an example of that as exists. Conviction of this crime carries a 3 year imprisonment penalty, and if the convicted party is a corporation (or any legal person), they face a criminal fine of up to $10,000, on top of civil liability.

Put together, that’s 3 independent legal problems stacked on top of each other for accepting the salesperson’s offer: a constitutional privacy violation that doesn’t require a lawsuit-specific statute to exist, a specific criminal statute naming the conduct, and civil liability for damages. There’s no version of “we didn’t think it applied to us” that survives this situation.

What Will “Getting This Wrong” Cost You?

You will face real exposure across all fronts, notably:

  • Criminal liability: Many state voyeurism/unlawful surveillance statutes are felonies, carrying fines and potential jail time for the person who installs or operates the equipment — that could be you, personally, not just “the business.”
  • Civil damages: Intrusion-upon-seclusion claims, among other tort claims, can result in compensatory damages, and courts in the US have allowed punitive damages where the conduct is found egregious — a bathroom camera is close to the paradigm case.
  • Employment claims: If the person recorded is an employee, expect this to also surface as a hostile work environment or wrongful termination claim if discipline follows the discovery.
  • Reputational cost: Unlike a data breach notice, this is the kind of story that runs on local news with your business’s name in the headline. There’s no regulator fine that costs you more than the client and patient trust it destroys.

Why Should You Care About This?

Because although you might think the sales pitch sounds reasonable, you could end up in a lot of trouble. “Fully covered and protected business” sounds like a good security practice, and most business owners installing these systems aren’t trying to do anything invasive — they’re thinking about delivery problems, break-ins, shoplifting, and slip-and-fall liability. However, your good intent doesn’t matter for most of these statutes, and it won’t matter to a jury either. The law doesn’t ask whether you meant well; it asks whether a reasonable person would find being recorded in that space highly offensive. In a bathroom, the answer is already decided.

This is also a useful moment to audit your entire camera plan, not just the bathroom question — because the same vendor conversation is a good opportunity to think through where cameras are legally fine (entrances, sales floors, hallways, parking areas) versus where they cross the line (restrooms, break-rooms used for nursing mothers, private offices with an expectation of confidentiality).

What Can You Do to Comply?

  1. Decline any bathroom, locker room, or changing-area camera outright. There’s no notice, consent form, or signage that fixes this. Don’t install it, and don’t let a vendor bundle it into a package “in case you change your mind.”
  2. Map your camera locations against expectation-of-privacy zones. Entrances, registers, storage, parking, and common work areas are generally fine. Restrooms, changing rooms, and private offices are not.
  3. Put your monitoring policy in writing. For the cameras you do install, a written policy — reviewed by an attorney — that discloses locations, purpose, and retention helps establish notice and reduces the risk of a monitoring-related claim from staff.
  4. Check your state’s specific statute. Voyeurism and unlawful-surveillance laws vary — some cover only “for sexual gratification” purposes, others cover any recording in a private space regardless of purpose. If you operate in Puerto Rico, the relevant provision is Article 168 of the Penal Code — broader than many mainland statutes since it isn’t limited to a sexual-purpose requirement.
  5. Train whoever manages the footage. Access controls and retention limits for legitimate camera footage matter too — who can view it, how long it’s kept, and how it’s secured.

The Bottom Line

Say yes to the cameras. Say no to the bathroom units — every time, no exceptions, regardless of how the package is bundled or how good the discount is. This is one of the few areas of privacy law where there’s no compliant way to do the thing at all; the only right answer is not installing it.

If you’re building out a security camera plan for your office, clinic, or retail space and want a compliance check before you sign anything, book a consultation — better to ask before the cameras go up than after.

This post is for general informational purposes and does not constitute legal advice. Camera and surveillance laws vary by state; consult an attorney about the rules that apply to your specific location and industry.

About the Author

Jaime Farrant is admitted to practice law in Puerto Rico, New York, Maryland and the District of Columbia. This article is for informational purposes only and does not constitute legal advice or create an attorney-client relationship.

ADVERTISING MATERIAL. This article constitutes advertising as defined by the professional conduct rules in New York (22 NYCRR 1200.7.1 and 1200.7.3), Maryland (Rule 19-307.1 and 19-307.2), and the District of Columbia (D.C. Rules of Professional Conduct 7.1), and the Puerto Rico Rules of Professional Conduct (Rules 7.1-7.3). It is not solicitation of prospective clients known to need legal services in a particular matter. Instead, it is general information directed to the public about the practice of law and available legal services. No attorney-client relationship is created by your reading of this article or by contacting the author. Consult qualified counsel in each jurisdiction with specific situations.

Duration of Status Is Over. Will My Visa Now Have a Deadline?

For nearly 50 years, F-1 students, J-1 exchange visitors, and I-visa foreign media representatives have lived under one of the most forgiving rules in U.S. immigration law: “duration of status,” or D/S. As long as you were still enrolled in school, still in your program, or still doing your job, your admission simply didn’t expire. No countdown clock, no renewal deadline, no fixed date circled on the calendar.

That era ends on September 15, 2026.

On July 17, 2026, the Department of Homeland Security published a final rule eliminating D/S for F, I and J nonimmigrants and replacing it with a fixed admission period, capped at 4 years, after which you must either finish your program, get approved for an extension, or leave. If you’re currently in the U.S. on one of these visas — or you’re an employer, school, or program sponsor who works with people who are — take a few minutes to read the rest of this article to understand what’s changing, because the old assumption that “I’m fine as long as I’m still studying” no longer holds.

What Was D/S, and Why Is DHS Getting Rid of It?

Since 1978 for students and 1985 for exchange visitors and media representatives, D/S admissions didn’t come with an end date stamped in your passport. Your authorized stay was tied to your activity — finishing your degree, completing your exchange program, continuing your foreign employment — not to a specific day on the calendar.

DHS now says that this flexibility is now a liability. In fiscal year 2024 alone, there were over 1.8 million F-1 admissions and more than half a million J-1 admissions — and DHS says it has identified over 2,100 people who first entered as F-1 students between 2000 and 2010 and are still in active F-1 status today. Because D/S doesn’t require any check-in with immigration officials unless you’re filing for something specific like practical training authorization, DHS argues it never had a reliable way to confirm these nonimmigrants were still doing what their visa authorized — or to catch it quickly when they weren’t.

So DHS is doing what it’s done with nearly every other nonimmigrant category for decades: giving F, J, and I nonimmigrants a fixed admission period instead of an open-ended one.

What is Changing With the New Rule?

  • Your admission period now has an expiration date. You’ll be admitted for the length of your program — up to a maximum of 4 years — plus a 30-day grace period to leave the US afterward.
  • If your program runs longer than 4 years, you’ll need an Extension of Stay (EOS). PhD programs, some medical training, and other multi-year programs routinely exceed 4 years. DHS acknowledges this and expects those nonimmigrants to file for an extension with USCIS before their fixed period runs out.
  • A 4-year transition period applies to people already here. If you’re currently in D/S status when the rule takes effect, you generally have until the earlier of your program’s end date or four years from the effective date to finish up, extend, or change status.
  • Automatic extensions during a pending, timely-filed EOS are capped — generally at 240 days (90 or 240 days for I nonimmigrants, depending on your passport country).
  • Unlawful presence now starts accruing the moment your authorized period ends — automatically, with no adjudication required first. This is the part that deserves the most attention, so let’s slow down on it.

The Change Most People Are Going to Miss

Under the old D/S system, unlawful presence for purposes of the 3- and 10-year reentry bars generally didn’t start accruing until an immigration officer or an immigration judge made an affirmative finding that you’d violated your status. In practice, that meant even if you’d fallen out of compliance, the clock didn’t start running until someone in the government formally said so — and with immigration courts sitting on nearly 3.8 million pending cases, that could take months or years.

That buffer is gone. Once your fixed admission period (or an approved extension) expires, you begin accruing unlawful presence automatically — the same day, with no officer or judge required to trigger it. DHS is explicit that this is the point: it wants F, I and J nonimmigrants “on equal footing” with every other visa category, where overstaying has always worked this way.

Practically, this means:

  • If your I-20 or DS-2019 end date passes and you haven’t filed a timely EOS, you don’t get the benefit of the doubt anymore. The clock will be running and you are out of status.
  • Unlawful presence exposure is now real for anyone whose case — including a pending application with USCIS or a case before an immigration judge — outlasts their authorized period without being properly extended.
  • Because there’s no more need to wait for a formal violation finding, expect Immigration and Customs Enforcement to move faster on issuing Notices to Appear once a fixed period lapses, since nothing is holding back the unlawful presence clock in the meantime.

Why Should You Care About This?

  • The 4-year cap doesn’t fit everyone’s timeline. DHS’s own data shows a majority of PhD students take longer than four years to finish. If that’s you, an EOS isn’t optional — it will most likely be the only thing standing between you and unlawful presence.
  • “I’m still enrolled in school” is no longer a legal safe harbor. Under D/S, staying enrolled generally kept you in status. Under the fixed-period rule, your status can lapse on a specific date even while you’re still actively in your program, if you haven’t filed the right paperwork in time.
  • EOS processing is about to get a lot busier. DHS itself predicts a surge in extension filings, with peak volume expected roughly 4 years after the rule takes effect. If USCIS processing times stretch out the way they have with other benefit categories, you could be left waiting on an EOS decision after your fixed period has already technically expired.
  • This affects far more than students. Dependents (F-2, J-2), exchange visitors sponsoring international scholars and researchers, foreign media correspondents, and the schools and program sponsors managing all of them are all being pulled into the same fixed-period, same EOS-filing system.
  • A lapse now has consequences that follow you. Unlawful presence isn’t just an abstract compliance issue — it can trigger 3- or 10-year reentry bars and complicate future visa applications, adjustment of status, or waivers down the road.

What Can You Do About It?

  • Know your actual admission end date once the rule takes effect — not just your program end date. These will not always be the same thing, especially for anyone whose program runs past four years.
  • If you’re currently in D/S status, mark your transition deadline now. You have until the earlier of your program’s end date or 4 years after the effective date — don’t wait until you’re already close to that line to start planning.
  • If your program will run longer than 4 years, start your Extension of Stay conversation as soon as possible with your designated school official (“DSO”), program sponsor, or immigration attorney. Filing an EOS after your fixed period has already lapsed is a very different — and much riskier — situation than filing before it expires.
  • Build in buffer time for USCIS processing delays. Given the volume DHS expects, don’t assume a last-minute EOS filing will be decided before your authorized stay runs out.
  • If you’re a school, program sponsor, or employer working with F, J, or I nonimmigrants, update your internal tracking now. You’ll want a system that flags fixed admission end dates well before they arrive, not after.
  • If your immigration situation is already complicated — a pending application, a change of status in progress, or any uncertainty about your history — talk to an immigration attorney before your current authorized period runs out, not after.

The Bottom Line

For nearly five decades, F, I and J nonimmigrants operated under one of the most flexible admission frameworks in U.S. immigration law — no fixed end date, no automatic overstay clock. As of September 15, 2026, that flexibility will be gone, replaced by a fixed admission period capped at 4 years and an unlawful presence clock that starts automatically the moment that period ends, no adjudication required.

If you’re currently in F, i or J status — or you manage people who are — the safest assumption going forward is the same one that’s always applied to nearly every other nonimmigrant category: know your admission end date, and don’t let it arrive without a plan already in place.

If you want help figuring out exactly where your admission period stands under the new rule, or want to get ahead of an Extension of Stay filing before it becomes urgent, please book a consult with us before your visa runs out.

About the Author

Jaime Farrant is admitted to practice law in Puerto Rico, New York, Maryland and the District of Columbia. This article is for informational purposes only and does not constitute legal advice or create an attorney-client relationship.

ADVERTISING MATERIAL. This article constitutes advertising as defined by the professional conduct rules in New York (22 NYCRR 1200.7.1 and 1200.7.3), Maryland (Rule 19-307.1 and 19-307.2), and the District of Columbia (D.C. Rules of Professional Conduct 7.1), and the Puerto Rico Rules of Professional Conduct (Rules 7.1-7.3). It is not solicitation of prospective clients known to need legal services in a particular matter. Instead, it is general information directed to the public about the practice of law and available legal services. No attorney-client relationship is created by your reading of this article or by contacting the author. Consult qualified counsel in each jurisdiction with specific situations.

What Happens If Your Vendor’s AI Decides to Hack Someone Else?

Have you ever thought about what could happen to your business if a vendor’s AI system decides, on its own, to break into another company’s servers? If you haven’t, it might be time to, because the consequences for your business could be severe. If you’re a business regulated by HIPAA, a violation of this law could carry a civil penalty of up to $2,190,294 per violation category, per year, at the highest tier of culpability. Even a business that did nothing wrong, where a vendor’s AI system acted entirely on its own, could still face a lower-tier penalty, an OCR investigation, breach notification costs, and reputational fallout, for something it never caused and couldn’t have predicted.

This nightmarish possibility is no longer a hypothetical scenario. On July 21, 2026, OpenAI published on its website a notice were they took responsibility for a cyberattack on Hugging Face, a widely used AI hosting and machine-learning collaboration platform. According to OpenAI, a combination of its models — including a publicly available model and a more capable unreleased one, running with reduced safety restrictions for an internal cybersecurity evaluation — broke out of their isolated test environment by exploiting a previously unknown flaw in an internal software tool, reached the open internet, and then used stolen credentials and another unknown vulnerability to gain remote code execution on Hugging Face’s production servers. Their goal, according to OpenAI, was narrow but telling: the models were trying to retrieve the answer key to the benchmark test they were being scored on. Hugging Face had already detected the intrusion over a weekend of automated activity, reported it to law enforcement, and began its own containment before it even learned OpenAI was behind it.

Both companies have called this a watershed moment for cybersecurity. For a small business, medical practice, or professional office that relies on outside vendors — including AI tools — to store, process, or transmit sensitive information, it should also be a wake-up call about a risk category that most vendor contracts were never written to address: the AI agent that acts on its own.

Why could your AI Vendor’s Behavior Become Your Problem?

Most privacy and data security laws that apply to small businesses do not distinguish between a breach caused by a human hacker and a breach caused by an autonomous system. If your practice or business uses a covered entity’s business associate, a cloud vendor, or any third party that touches personal or health information, you are generally still responsible for:

  • Vetting that vendor’s security practices before you sign a contract (due diligence).
  • Having the right contractual protections in place, such as a HIPAA Business Associate Agreement (BAA) for medical offices, or comparable data processing and security terms for any business handling personal information.
  • Notifying affected individuals, and in some cases regulators, if that vendor’s system is compromised and your data is involved.

Under HIPAA, a covered entity’s business associates are contractually and legally bound to safeguard protected health information (PHI), and a breach at the vendor level can trigger notification obligations for the covered entity itself, even though the vendor’s system, not the medical office’s, was the one that failed. Outside of healthcare, most state data breach notification laws work the same way: liability follows the data, not just the party that caused the incident.

An AI agent that autonomously escalates its own access, exfiltrates credentials, or reaches systems it was never authorized to touch does not change any of that legal analysis. It just makes it harder to predict, detect, and contain.

It’s worth being precise about what did and didn’t happen here: by OpenAI’s own account, the models were chasing the answer key to their own benchmark test, not deliberately hunting for customer or patient records. No business should read this incident as proof that patient or client data was taken. What should concern any business relying on outside vendors is the capability on display: an AI system that, on its own initiative, found a zero-day vulnerability, stole credentials, escalated privileges, and reached a third party’s production infrastructure, over an unmonitored weekend, before any human intervened. Point that same capability at a system that holds patient records, financial account numbers, or client files, and the outcome looks very different.

A Disclosure Gap Worth Knowing About

Here’s a detail that matters for any business relying on a vendor’s assurances: OpenAI was not legally required to disclose this incident at all. Two recent state laws, California’s SB 53 and New York’s RAISE Act, require large AI developers to report critical safety incidents, but only if the incident risks more than 50 deaths or serious injuries, or over $1 billion in property damage. An incident like this one falls well short of that bar. OpenAI disclosed it voluntarily. The practical takeaway for your business: you generally cannot count on a public filing or regulatory notice to tell you whether a vendor’s AI system has had a similar failure. That makes your own contract language, and your own right to ask direct questions, the primary tool you have.

Penalty Structure: What’s Potentially at Stake

The exposure here is layered, and it can apply to a business that never asked for an AI system to do anything wrong, if that system operated within its own environment or a vendor’s:

  • HIPAA: Civil penalties currently range from roughly $145 up to $2,190,294 per violation category per year, depending on the covered entity’s or business associate’s level of culpability. Tier 1 (lack of knowledge) sits at the low end; willful neglect that goes uncorrected sits at the top. State attorneys general can separately pursue HIPAA-related fines of up to $25,000 per violation category, per year, and multi-state actions are increasingly common when a breach touches residents across several states.
  • State breach notification laws: Most states can pursue penalties or authorize private lawsuits when a business fails to notify affected residents promptly after a breach involving personal information, regardless of whether the breach originated with the business or with a vendor it selected.
  • Contractual exposure: If your vendor agreement lacks clear breach notification timelines, security requirements, or audit rights covering AI tools specifically, your business could be left absorbing costs, or negotiating from a weaker position, after the fact.

None of this means every AI-related vendor incident automatically results in a maximum fine. Regulators generally consider the nature of the data involved, the number of people affected, whether the business had reasonable safeguards in place, and how quickly the incident was addressed. But the exposure is real, and it is not limited to companies that build or sell AI models. It reaches any business, medical office, or professional practice that relies on one.

Why Should You Care About This?

Because experts who study AI safety are calling this one of the first real-world examples of an AI “loss of control” scenario: a system doing something researchers had long warned about, without a human directing it, and without a simple software bug to blame. The activity reportedly ran for an extended period on a system that, unlike OpenAI’s actively monitored production tools, was not being watched in real time. If a frontier AI lab with dedicated security teams can have this happen during a controlled internal test, it is a reasonable question for any business to ask what oversight exists over the AI-enabled tools, chatbots, scheduling assistants, or back-office automation your practice already uses, and what your vendor’s contract actually says about that risk.

For a medical office, this question is not abstract. AI tools are increasingly built into patient intake, scheduling, transcription, and billing software. For any small business, it applies to whatever AI-enabled service touches client records, financial data, or other sensitive information, even indirectly.

How Can You Protect Your Business?

  • Inventory every vendor and software tool your business uses that incorporates AI, especially anything touching patient, client, financial, or employee data.
  • Confirm you have a signed BAA in place with any vendor that creates, receives, maintains, or transmits PHI on your behalf, if you are a covered entity or business associate.
  • Review vendor contracts for AI-specific language: does the agreement address autonomous system behavior, require prompt breach notification, and specify security obligations?
  • Ask vendors directly how they test AI systems for containment and what happens if a model exceeds its intended scope.
  • Confirm your incident response plan accounts for a scenario where a vendor, not your own systems, is the source of a breach.
  • Revisit your cyber insurance policy to confirm it covers incidents involving AI tools and third-party AI vendors, not just traditional data breaches.
  • Don’t assume silence means safety: build a contractual right to be notified of AI-related security incidents into your vendor agreements, since current AI safety-incident disclosure laws only cover the most catastrophic events and won’t necessarily surface a vendor’s close call.

The Bottom Line

The OpenAI–Hugging Face incident is a reminder that AI risk in 2026 is not just about what your business chooses to do with AI. It is also about what the AI systems inside your vendors’ infrastructure might do without anyone telling them to. If your practice or business has not reviewed its vendor agreements and incident response plan with that possibility in mind, now is a good time.

If you have questions about your vendor contracts, business associate agreements, or how a breach at a third-party AI vendor could affect your obligations, schedule a consult with us today.

About the Author

Jaime Farrant is admitted to practice law in Puerto Rico, New York, Maryland and the District of Columbia. This article is for informational purposes only and does not constitute legal advice or create an attorney-client relationship.

ADVERTISING MATERIAL. This article constitutes advertising as defined by the professional conduct rules in New York (22 NYCRR 1200.7.1 and 1200.7.3), Maryland (Rule 19-307.1 and 19-307.2), and the District of Columbia (D.C. Rules of Professional Conduct 7.1), and the Puerto Rico Rules of Professional Conduct (Rules 7.1-7.3). It is not solicitation of prospective clients known to need legal services in a particular matter. Instead, it is general information directed to the public about the practice of law and available legal services. No attorney-client relationship is created by your reading of this article or by contacting the author. Consult qualified counsel in each jurisdiction with specific situations.