Tag: EU AI Act

Esencia exposed how Puerto Rico can approve coastal megaprojects without the public finding out.

Could the same thing happen with AI data centers installed under the sea?

You may have read or heard about a company planning to install an Artificial Intelligence (“AI”) data center around Puerto Rico’s beaches, and thought to yourself, “That doesn’t sound right. Could that really be true?” The answer: yes, it’s true.

On the other hand, you might be hearing about this for the first time by reading this article, which leads you to wonder, “How is it possible I hadn’t heard about this? With so many laws on the books, isn’t there one that requires something like this to be publicly announced in Puerto Rico? Shouldn’t there be a public hearing covered on TV and in the newspapers so I could see it and learn more?”

If you’re surprised you haven’t heard about this before, don’t be. That’s because Puerto Rico’s laws and regulations weren’t designed to guarantee that you’ll find out about projects like this one before they’re built. A recent case where we saw this happen was the Esencia tourism megaproject in Cabo Rojo. In August 2026, the Permits Management Office (“OGPe”) approved the project’s Siting Consultation – a project that represents at least a $2 billion investment on the island’s southwest coast – without holding a public hearing for that stage, despite more than 800 residents formally requesting a participatory process. The developers maintained that they already fulfilled that requirement in an earlier phase held in March 2025. Opponents point out that, since then, 10 new studies have been added to the record that never went through public scrutiny. Amid widespread opposition to the project, the Puerto Rico Senate announced it will investigate the project through its own hearings, with the first one held on September 1. If a hotel-and-residential project on land generates this much controversy, what would happen if someone tried to install AI data centers beneath our beaches, in a way that’s practically invisible? 

Today, Farrant Explains covers who proposed this project, how it could obtain permits to operate under Puerto Rico law, and how those laws compare to the United States and the European Union. We’ll also summarize the conversation we had with the leaders of a company that has considered doing this, and tell you why this should matter to you, even if you live on top of one of our mountains and never go to the beach or a pier.

I. Who is Seabase, and what do they want to do?

According to our conversation with Reilly McAdams, co-founder and Chief Executive Officer (”CEO”) of Seabase, this is a company incorporated in Delaware as Seabase Industries Inc., headquartered in Houston, that builds modular, containerized computing units designed to sit at or near the seafloor, close to ports, and cooled with seawater instead of fresh water or electricity-hungry air conditioning systems. Prior to its Delaware incorporation, the company registered two Puerto Rico corporations on March 6, 2026: Seabase Network LLC, registration number 575350, and Seabase Industries LLC, registration number 575352.

Both Puerto Rico companies list Reilly McAdams (co-founder and CEO of Seabase, according to its website), Oliver Willcox (co-founder and president), and Ashby Green (CFO) as authorized persons.

On its website, Seabase states that it differentiates itself from competitors because its architecture separates a long-life subsea platform from shorter-life computing equipment that can be replaced over time. The company also sells a product called Nori, designed to let customers reserve and monitor their equipment’s capacity.

Seabase’s co-founders, CEO Reilly McAdams and COO Ollie Willcox, were interviewed by News Is My Business in May 2026. At the time, they said the company was evaluating sites in Ponce, San Juan, and Puerto Rico’s east coast, and seeking partnerships with universities and government agencies, naming the University of Puerto Rico’s Mayagüez campus in that interview. McAdams also noted that Puerto Rico relies too heavily on infrastructure in the mainland United States, pointing out that most of the island’s computing and technological capacity is located in Miami, which makes the island highly vulnerable if an undersea fiber-optic connection were ever damaged.

During our conversations with Seabase in September 2026, the company told us that, although it has evaluated potential sites in Puerto Rico, it has not selected a specific location or advanced a project. They also told us that, while Puerto Rico “remains an attractive market, it is not currently among our primary near-term deployment locations,” and that their current work is exploring opportunities in the continental United States and internationally, including other Caribbean locations.

On the technical side, Seabase’s public materials describe its “pods” as units running between 0.5 and 3 megawatts each, in standard containers, which are aggregated into clusters of 10 to 20 megawatts, using closed seawater cooling systems instead of freshwater evaporative systems. According to McAdams, their subsea systems use a closed internal cooling loop that releases heat to the surrounding marine environment, avoiding the evaporative cooling and freshwater consumption common in many conventional data centers. This architecture, he told us, could also reduce land requirements by locating computing infrastructure at sea or within existing marine and port environments.

When asked whether this heat-releasing system would generate any impact, he replied that it’s a passive process, in which a closed internal loop transfers heat through external heat exchangers rather than pumping seawater through the data center. He added that they would model the thermal plume for each site, designing the project so that localized temperature changes remain minimal, and that they plan to be fully transparent with the public about their data and marine impact.

We also asked Seabase whether a project like this would affect public beach access, or restrict the use of boats nearby. They told us they don’t expect their projects to restrict beach access, fishing, or boating, since they would look for locations with sufficient depth and distance from shore to stay away from beaches, swimming areas, recreational boating routes, navigation channels, and important fishing grounds. Their goal, they said, is for people using the beaches and boats near these pods to essentially not know the infrastructure is there.

In short, as of today, Seabase has no immediate plans to build a data center on our beaches. However, that doesn’t rule out Seabase — or another company — expressing interest in building a data center in our waters in the future. Consequently, in this next section, Farrant Explains which laws and regulations would address this situation.

II. What Puerto Rico laws and regulations govern building an AI data center on our beaches?

As of this writing, Puerto Rico has no law that regulates the construction of AI data centers on our land or in our waters. That said, should Seabase or another company want to begin the process of obtaining permits today to build a data center at sea, there are three legal frameworks that could apply. Today, Farrant Explains through each one.

Framework 1: Environmental Review (Law 416-2004 and the OGPe/JCA process).

Puerto Rico’s most important environmental statute is the Environmental Public Policy Act (Law 416-2004). It requires public agencies to evaluate significant environmental impacts that projects may cause before granting permits. These permits are typically issued by the Permit Management Office (“OGPe”), working with the Environmental Quality Board (“JCA“), which evaluate projects under the Joint Regulation for the Evaluation and Issuance of Permits Related to Development, Land Use, and Business Operations (Regulation 9473 of the Planning Board, approved June 16, 2023) (“Joint Regulation”), and the JCA’s Regulation for the Environmental Evaluation Process (Regulation 8858 of November 23, 2016).

Under this law and its regulations, developers submit an Environmental Assessment (“EA”) for their projects or, when the environmental impact could be significant, submit an Environmental Impact Statement (“DIA,” for its Spanish acronym). Rules 2.2.2.4(c) and 3.1.3.3(a)(1) of the Joint Regulation establish that any discretionary matter requiring a public hearing, or requiring a DIA, will be adjudicated within 180 days. This mechanism, once triggered, guarantees a public hearing and a defined timeframe. The important question, however, is determining whether a project requires an EA, a DIA, or neither.

Framework 2: Site Consultation (“Consulta de Ubicación”).

A pod like Seabase’s — which houses an AI data center placed under the sea — doesn’t fit any existing zoning category. For cases like this, Rule 2.2.3.2(d) of the Joint Regulation creates a discretionary process called a “Site Consultation” precisely for uses that, by their nature or intensity, need to be located in a specific place that existing zoning maps don’t anticipate. This is the category the Joint Regulation uses for novel projects. This matters because these Consultation processes have much narrower public-disclosure requirements than the DIA process, specifically:

  1. Notice only needs to be given to adjoining property owners, by certified mail, within no more than 5 days after the application is filed (Rule 2.2.2.2(a)).
  2. Holding a public hearing is discretionary, under Rule 2.2.3.19. This rule states that a public hearing will only be held “in cases where the regulations in effect so require, or in cases the Adjudicative Board deems appropriate, in which case any interested person who requests to be heard on the matter under consideration will be allowed to participate.”
  3. Standing to challenge or intervene in a determination is limited. Rule 2.2.3.4(a) only grants standing to the property owner, optionee, or lessee — personally or through an authorized representative — in the case of private projects, or to the head of the agency or their authorized representative in the case of a public project. Likewise, subsection (c) of this Rule establishes that revocation of a consultation may be pursued by the Adjudicative Board “on its own initiative or at the request of a person with a legitimate interest,” a term that is not clearly defined.

In short: if a project is approved through a Site Consultation rather than a DIA, the public-hearing mechanisms many people assume exist would simply never be triggered here.

Framework 3: Port Zone — Ports Authority.

Section 7.3.4 of the Joint Regulation provides that, within a Port Zone (“ZP”), the Ports Authority (“Ports”) — not DRNA — is responsible for controlling and administering Puerto Rico’s ports, the navigable waters that form part of port zones, publicly owned piers, submerged lands under those piers, the maritime-terrestrial zones located within any port zone, and all buildings and structures situated there that are owned by or under the dominion of Puerto Rico. This is likely why Seabase told News Is My Business that it was in communication with the Ports Authority. Outside a ZP, DRNA’s permitting processes for maritime-terrestrial zones would apply instead, under Puerto Rico’s 1968 Piers and Ports Act, Law 151-1968. In these cases, DRNA may permit water-dependent uses such as piers and platforms, but cannot convert submerged lands into private property.

Beyond these three frameworks, a project like this could also fall under the following laws and processes:

1. Energy Interconnection.

A 10-20 megawatt facility like those described by Seabase would need to connect to the electrical grid, and would therefore fall under the jurisdiction of the Energy Bureau (“PREB”) and any other agency handling the interconnection study. Additionally, unlike a growing list of U.S. states, Puerto Rico has no large-load-specific tariff, nor any law or ordinance specifically regulating data centers.

On this point, Seabase told us its goal is not to “add a large new load to a grid that’s already fairly constrained. We’re evaluating models that pair computing infrastructure with new power generation and battery storage, to potentially support grid resilience and flexibility where the local system allows.”

2. Tax Incentive Decrees under Act 60

Puerto Rico’s Incentives Code, Act 60-2019, consolidates incentive programs under the Office of Business Incentives, which cover infrastructure and renewable energy projects, in addition to reviewing benefits for operating within a federal Opportunity Zone. To obtain a decree approving an incentive, the entity must apply to the Department of Economic Development and Commerce (“DDEC”), and this process does not require a public hearing.

We asked Seabase whether any of its Puerto Rico entities held, or had applied for, a tax incentive decree under Act 60. Its CEO, Reilly McAdams, told us that none of its entities holds a decree or has a pending application under Act 60 or any other tax incentive, stating that the entities are “ordinary corporate entities.”

3. Dedicated Telecommunications Infrastructure

Rule 9.11 of the Joint Regulation governs the construction, installation, and siting of telecommunications towers and facilities through the Telecommunications Bureau (“NET”), an entity under the Puerto Rico Public Service Regulatory Board (“JRSP”). Rule 9.11.11 establishes that public hearings will be required for variance requests related to the installation or siting of telecommunications towers and facilities, when these respond to technological, emergency, or public-safety needs.

While this is a much stronger standard than the one for Site Consultations, it applies to few cases. If Seabase’s or another company’s fiber-optic or connection infrastructure requires a variance, this would be the only process under the Joint Regulation that would require the entity to publish a newspaper notice and participate in a public hearing.

4. Federal Regulations and Permits

Since installing a data center at sea would take place in navigable waters of the United States, a permit would almost certainly be required under Section 10 of the Rivers and Harbors Act, 33 U.S.C. § 403, as well as a permit from the U.S. Army Corps of Engineers under Section 404 of the Clean Water Act, in addition to a license for laying submarine cables if fiber connections are placed in waters under federal jurisdiction.

III. How does Puerto Rico’s legal framework compare to that of the United States and the European Union?

  1. Compared to the United States — Puerto Rico’s environmental review process closely follows the National Environmental Policy Act (“NEPA”), to the point that Puerto Rico’s regulations address situations in which a local agency co-leads an environmental review process with a federal counterpart under NEPA.

That said, during 2026, a number of state legislatures passed laws requiring companies that want to build AI data centers to disclose their plans before construction begins. New Jersey, for example, now requires data center operators to publicly disclose how much water and energy they consume (S3379/A4096), in addition to recently passing the “Data Center Fair Share Act (A5462),” which establishes separate electricity rates for data centers.

At the federal level, Representative LaMonica McIver (D-NJ) introduced the AI Data Center Site Selection Transparency Act of 2026, which would require data center developers to disclose the location of selected sites to elected officials and the public at least 180 days before taking any definitive development step. This bill was filed because the industry has been signing nondisclosure agreements (“NDAs”) with public officials to prohibit them from speaking about these projects or their potential impact. A number of states have moved to ban public officials and developers from signing NDAs with each other.

In Puerto Rico, no one has prohibited the government from signing NDAs with these entities, and we haven’t found any bill attempting to regulate AI data centers.

  1. Compared to the European Union (“EU”). The EU regulates this completely differently: it requires ongoing sustainability reporting, rather than disclosure before a project begins. Under Article 12 of the Energy Efficiency Directive, EU member states must ensure that data centers with at least 500 kilowatts of installed information technology power make all their energy performance information public, and publish it in a shared, EU-wide database covering approximately 24 indicators. The European Commission expects to finalize an EU-wide classification and labeling process. The 10-20 MW clusters Seabase plans to use, according to its website, exceed the EU’s 500 kW minimum. As a result, if their project was built in Europe, they would have to report to the public, every year, how much water and renewable energy they use, and what their energy efficiency is. In Puerto Rico, under existing law, they would not have to disclose any of this.

In short: Puerto Rico regulates whether a project gets approved. But for an innovative project like this one, it appears the project could be approved through a legal framework that contemplates discretionary public hearings and gives the public limited standing to object. Meanwhile, U.S. states are focused on regulating whether the public is notified of these projects before they’re built. Finally, the EU regulates whether the public needs to keep being informed about the project indefinitely. Puerto Rico’s legal framework, by comparison, is much weaker at the outset of a project than these jurisdictions, and stays silent about everything else.

IV. Why should this matter to you?

Because, even though Seabase’s CEO told us Puerto Rico is not currently among its short-term priorities, there are at least 3 aspects of this story you should be aware of, regardless of what Seabase or another company does in the future.

  1. The precedent that will be set. Seabase and its leadership gave us detailed, specific answers about the logic behind their unit placement, their thermal plume modeling, and their stated interest in not impacting marine flora and fauna. This is the kind of communication and exchange that many companies don’t offer unless they’re forced to by a government or judicial authority. This exchange was a good example of how we’d expect Seabase to behave if it decides to pick this project back up in Puerto Rico. However, their good faith and willingness are not a substitute for the fact that this kind of exchange should be one required by law, and the next company that wants to come to Puerto Rico to propose building an AI data center under the water might not be as receptive to dialogue as they were. The current gap in the Joint Regulation that allows these site consultations within a process that doesn’t guarantee public hearings isn’t filled simply by a company’s willingness to answer our questions. It would also be vital to ensure there’s a legal framework in place to verify that a company actually follows through on everything it promises.
  2. Energy and water use. Seabase’s description of its approach — passive, closed-loop cooling systems that avoid pumping seawater through the system, along with its stated interest in generating and storing its own energy rather than becoming an additional burden on our current grid — sounds like a very different model from the one conventional data centers use, and one that could be much more responsible and sustainable if it’s actually implemented. However, Seabase’s proposal is, for now, simply a theoretical one, since no sites have been chosen and no environmental analysis has been completed. As a result, the challenges of building data centers on top of Puerto Rico’s fragile, collapsing water systems remain real. As a matter of fact, I’m writing these lines on the fourth consecutive night without water in my home. These challenges apply to any project Seabase or any other company might want to implement here.
  3. The urgent need to demand transparency. Our exchange with Seabase was a small example that shows the need to formalize transparency processes at a project’s pre-development stage. Seabase answered all of our questions simply because they wanted to talk with us, not because a law required it. But a future company looking to establish itself in Puerto Rico for the same purpose might not have the same willingness that Seabase showed. As a result, Puerto Rico needs to create laws similar to those several states are passing, requiring advance disclosure of this kind of project, while we wait for Congress to hopefully one day pass the AI Data Center Site Selection Transparency Act or a similar law.

V. Best Practices and Recommendations for Companies and the Public

  • Publish site-specific environmental modeling before being legally required to. During our conversation, Seabase gave us a lot of technical detail about its project and answered all of our questions. This is precisely the kind of proactive disclosure that should be the industry standard, not the exception. Developers who do this build public trust, since they do it before the law forces them to.
  • Establish robust public hearing processes. Laws should prohibit developers from self-selecting into processes that don’t require public hearings in cases like this one. A company’s leadership showing good faith isn’t the same as law, and it can certainly change once a permitting process actually begins. In a case like this, where there are real questions about the impact this kind of project could have on our residents, coastlines, marine flora and fauna, and our water and power systems, public hearing processes need to be held regardless of the developer’s good faith.
  • Voluntarily publish water and energy use projections, before an authority requires it. Data center litigation in the United States frequently centers on the use of NDAs that let companies avoid disclosing information like this.
  • Publish the review processes underway at OGPe, DRNA, and Ports (the Ports Authority), so the public doesn’t have to figure out which of these agencies has jurisdiction over each part of a project.
  • Create community communication and engagement plans. These days, people around the world are skeptical about the risks of AI and how it will affect their lives. Developers of projects like Seabase’s need to be transparent about their intentions and plans, and set and publish goals with metrics the public can verify and track.
  • Hold the government accountable. We need to make sure the government follows its own laws, holds public hearings, promotes transparency, and allows people and entities standing to intervene in administrative and judicial processes.

VI. Conclusion

Seabase’s project was never a secret one, and we’re grateful they answered all of our questions much faster and more concretely than many other companies would have. Our exchanges with them introduced us to a company that seriously considered the island for this project, evaluated it, created 2 Puerto Rico corporations, generated local interest, but then concluded that Puerto Rico is not among its short-term priorities — though they’re leaving the door open to return.

Once that day comes, we’ll see how Puerto Rico’s legal framework analyzes and reviews it. The DIA process would guarantee a public hearing where residents can speak up. The Site Consultation process, however — which could be the one chosen to authorize a project as significant as this one — does not require holding public hearings. The transparency Seabase showed in our conversations doesn’t eliminate the need to make sure our own laws guarantee that same transparency, because we don’t want to live in a place where laws are passed to guarantee darkness.

What did you think of this article? Should Puerto Rico allow AI data centers? Do you think a development like this should go through the DIA process or the Site Consultation process? Leave us your comments.

Should Puerto Rico Ban Artificial Intelligence in its schools?

New York City just banned it for 600,000 students.

On September 2, 2026, New York City — through Mayor Zohran Mamdani and Schools Chancellor Kamar Samuels (equivalent to the city’s secretary of education) — did something no U.S. school system had done before: it paused the rollout of technology in the classroom, when they announced a 1-year moratorium on the use of generative artificial intelligence (”GAI”) in the city’s public schools. This means that, for the 2026-27 school year that has just begun, the roughly 600,000 students there in grades 2-K through 8th will not be able to use student-facing GAI. In addition, companion chatbots will be prohibited across all grades.

From a legal standpoint, perhaps the most striking thing about this announcement is that New York did not pass any law to impose its moratorium. The mayor and the chancellor simply made an administrative decision about what software would run on school devices, and with that decision, made a dramatic change in academic policy. 

Their decision leads us to ask: are other jurisdictions passing laws on how AI is used in the classroom? Or, are these new technologies simply being rolled out through memoranda and administrative decisions? And, since we write from Puerto Rico, we ask ourselves: which model does our island follow — or could follow?

Before answering those questions, let’s start with a summary of the Mamdani and Samuels announcement.

What Did New York Actually Do?

The moratorium is far more detailed than what the headlines suggest. It is not an outright ban, but a framework that establishes the following:

  • 2-K through eighth grade: A complete prohibition on student-facing GAI and chatbots that interact with students. Additionally, companion chatbots will be prohibited across all grades, from 2-K to high school.
  • High school: Twice a year, students will receive a 45-minute AI literacy module covering fundamentals, bias, ethics, and the impact on the professions. In other words, they will be taught about AI, not with AI. While students at this level will fall outside the general moratorium, the ban on companion chatbots will apply to them.
  • Pilot program: Up to 50,000 high school students (roughly 5% of enrollment) will have access to a pilot program with 5 approved AI tools (Quill, Edia, Brisk Teaching, Playlab, and Intel AI-Ready Schools) under strict time limits and teacher supervision.
  • Screen time: For students in second grade and below, individual screen use (”1:1 screen time”) will be restricted, though that restriction has not yet been spelled out in detail; and caps of up to 30 minutes a day are recommendedfor third through fifth grade and 45 minutes for sixth through eighth.
  • A “Technology in Schools Coalition” was created that will convene throughout the year and publish recommendations. On this, Chancellor Samuels stated in the mayor’s press release: “We’re standing firmly in our belief that innovation does not mean more technology, and over the next year, we will lead with evidence to make sure technology serves learning — not the other way around.”
  • Important exceptions: AI may continue to be used in support programs for students with disabilities, multilingual learners, and career readiness programs. In addition, teachers may continue using AI for lesson planning and administrative work.

In short, New York City did not craft a policy out of “fear” of technology. It crafted one that distinguishes between AI as a tool “adults may use,” AI as a “subject students study,” and AI as “a thing that talks directly to a nine-year-old” — banning only that last category.

How Is AI Used in European Union Classrooms?

The European Union passed the EU AI Act (”EUAIA“), the most developed AI statute in the world, which, regulates the use of AI in education, among other areas. Notably, the EUAIA does not tell a school from what grade it may use AI. What it does is regulate the product: it imposes obligations on whoever develops and sells software or applications, and on whoever deploys the technology — including the school itself.

The EUAIA has 3 key provisions on this subject:

  • Article 5(1)(f) prohibits developing, marketing, or using AI systems that infer the emotions of natural persons based on biometric data in educational institutions and the workplace, allowing only very narrow exceptions for medical and safety purposes. Accordingly, in the European Union, it is illegal for a vendor to offer a school a camera system that monitors whether students are actively participating in class.
  • Annex III of the EUAIA classifies AI systems used in education as high-risk — particularly those that determine access to education, evaluate learning outcomes (including steering the learning process), assess the appropriate level of education, and monitor prohibited behavior during exams. A high-risk designation does not mean the product is banned, but that it will be heavily regulated. As of August 2, 2026, providers must maintain technical documentation and risk management systems, apply CE marking, register in an EU database, and provide for human oversight. Deployers, in turn —with schools included— must ensure adequate human oversight, retain logs for at least 6 months, notify individuals when they are affected by a high-risk system, and, if they are public entities, conduct fundamental rights impact assessments.
  • Article 50 of the EUAIA adds transparency requirements across the board. Users must be told when they are interacting with a chatbot, when the content they are reading is AI-generated, and when emotion recognition systems are in use.

The EUAIA penalizes these violations with fines of up to the greater amount between €15 million or 3% of total worldwide annual turnover, and up to €35 million or 7% of worldwide annual turnover for prohibited practices.

In sum, the EU’s answer to “can a second-grader use a chatbot?” is: “that’s the school’s call. However, there is a compliance regime that will make deploying bad edtech expensive and make software that reads emotions illegal.”

What Has China Done About It?

In May 2025, China’s Ministry of Education issued guidelines regulating GAI in primary and secondary schools that resemble the one announced in New York City. For example:

  • Primary school students are prohibited from independently using open-ended GAI content tools.
  • Middle school students may explore and analyze the logical structure of AI-generated content, and understand how these systems work.
  • High school students may engage in inquiry-based learning on the technical principles of AI and even develop and optimize AI models.

Separately, all students are barred from submitting AI-generated work as their own, using AI to cheat, or relying excessively on the technology for creative tasks without applying critical thinking. In addition, AI may not directly evaluate students or answer exam questions.

How Is AI Use in Schools Regulated in Puerto Rico?

Although Puerto Rico has enacted several laws on AI — such as Law 163-2026, which we covered previously — as of today, there is no law governing how AI may be used in a classroom.

The Puerto Rico Department of Education (”DE”), however, recently approved a policy that points in opposite direction from New York’s. Approved in December 2025 and published in January 2026, the Guía Para el Uso de la Inteligencia Artificial en el Aprendizaje Estudiantil (Guide for the Use of Artificial Intelligence in Student Learning, the “Guide“) names Microsoft Copilot, on its first page, as the official classroom platform for students aged 13 and up. The Guide further provides that only institutional accounts may be used when working with DE equipment and AI systems and, on page 23, establishes that students under 13 — or older students with academic delays or functional diversity — may use Learning Accelerators. It also requires that AI tools comply with federal and state data protection laws through the Office of Information Systems, and provides that students will be taught to not to enter sensitive personal information or information identifying other people. The Guide cites several reference sources, including recommendations from the U.S. Department of Education and UNESCO’s Recommendation on the Ethics of Artificial Intelligence.

Comparing the Guide against NYC, there is a clear contrast. The Guide provides that students at least 13 years old may use AI — an age likely borrowed from the federal COPPA statute, which imposes verifiable parental consent requirements on operators of websites and online services directed to children or that collect personal information from children under 13. COPPA does not set a minimum age for a minor to use a tool: it imposes obligations on the operator collecting the data. In other words, the Guide appears to have borrowed a threshold designed for a different problem. NYC, by contrast, draws its line at eighth grade — which on average means age 14 — and, unlike Puerto Rico, sets prohibitions rather than permissions.

The Guide is fundamentally about how students may use AI. NYC is trying to answer whether students may use AI.

Beyond the Guide, at least four bills on AI in education have been debated in the Puerto Rico Legislature, although, as of this writing (September 9, 2026), none has become law. They are:

MeasureFiledSponsorWhat it doesStatus
P. de la C. (House Bill) 4272025-03-20Rep. Tatiana Pérez Ramírez (PNP) and Rep. José F. Aponte Hernández (PNP)3-year pilot program deploying AI conversational-English tutors in 25 schools as passed by the House; the Senate committee report cuts it to 21 and adds that it begin in pre-K through third grade.Passed the House on May 12, 2025. The Senate Committee on Science, Technology and Artificial Intelligence reported it with amendments on March 10, 2026; now before Senate Rules and Calendar.
P. del S. (Senate Bill) 3482025-02-19Sen. Brenda Pérez Soto(PNP) with three co-authors: Karen Román Rodríguez (PNP), Gregorio Matías Rosario(PNP), and Rafael Santos Ortiz (PNP)Establishes AI as an instructional and work tool across the DE, creates a compliance officer, and sets a pilot program in 2 high schools per region. Sets no grade or age limit on AI use.Passed the Senate 24-0 on June 9, 2025 and the House 50-0 on reconsideration on January 29, 2026. The Senate rejected the House amendments on February 5, 2026. Now in Conference Committee.
P. del S. (Senate Bill) 8202025-10-16Sen. Brenda Pérez Soto (PNP)Establishes a media and digital literacy program across grades K-12, including algorithms, AI, and deepfakes.Passed the Senate on March 26, 2026. The House Education Committee reported it on June 11, 2026; that report was withdrawn on June 25, 2026 and the bill returned to committee.
P. de la C. (House Bill) 9682025-11-07Rep. José F. Aponte Hernández (PNP)Requires the DE and all private schools to adopt ethical AI use policies.In the House Education Committee since November 10, 2025.

Before walking through each bill, two things are worth flagging at the outset:

  1. Both the House and the Senate filed AI implementation bills (348 and 427) in early 2025, and several months later filed governance bills (820 and 968). This matters because this order, in which a technology is adopted first and governed second would force Puerto Rico simply to “govern” what it “already bought,” rather than first establishing “whether it needs to buy” and “what to buy” before deciding what to buy. This process is not being followed due to lack of legislative will: 348 was approved unanimously in both chambers, yet it has sat for seven months in Conference Committee because the 2 chambers do not agree on the text.
  2. There appear to be legislative discrepancies about age. Although the House set no minimum age in 427, the Senate Committee on Science, Technology and Artificial Intelligence added that it AI instruction can begin in grades pre-K through third. However, this is the same committee that reported on 348, whose pilot plan begins in high school. So we have 1 committee, 2 bills, 2 opposite answers to the same question, and no explanation of how it arrived at the ages and grades each one proposes.

Now, Farrant Explains each bill:

1. House Bill 427 — The Senate Wants to Start Using AI Tutors in Pre-K

On May 12, 2025, the Puerto Rico House of Representatives passed P. de la C. 427, titled Ley para la Implementación de la Inteligencia Artificial en el Programa de Inglés del Sistema Público de Enseñanza en Puerto Rico (Act for the Implementation of Artificial Intelligence in the English Program of Puerto Rico’s Public School System). Filed by PNP Representatives Tatiana Pérez Ramírez and José Aponte Hernández, it orders the creation of a 3-year pilot program to integrate an AI tool to help improve conversational English learning in Puerto Rico’s public schools, that will be administered by the DE in collaboration with PRITS.

The text the House passed provided that the pilot program would cover 25 schools and set no grade level at all. However, the marked-up text accompanying the Senate committee report of March 10, 2026 changed that to 21 schools (3 per region) and added that the pilot begins in grades pre-K through third. Those ages contrast sharply with New York’s moratorium, which bars students between second and eighth grade from using conversational AI, and with China, which prohibits primary school students from independently using GAI. If 427 is enacted with the Senate amendment, it would mean that, starting in pre-K, Puerto Rican students will interact with GAI in the classroom.

This bill is very different from what New York City, Brussels, and Beijing have done, as it proposes:

  • A 2-year pilot program giving priority to rural and hard-to-reach schools, and to students with low scores on standardized English assessments. The program would begin with a 6-month process to select the schools and tools and train teachers, followed by 3 years of tool use with continuous monitoring, and then a program evaluation.
  • Requiring that the selected AI tools be capable of real-time, personalized interaction, provide immediate feedback on pronunciation, grammar, and fluency, and be compatible with the electronic devices available in public schools.
  • Creating an Evaluation Committee appointed by the Secretary of Education.
  • Providing annual reports to the Legislature and the Governor.

Separately, Article 7 of 427 as passed by the House required the AI tool to be selected “after the due process of evaluation and competitive bidding,” and titled the article “Tools to be used; competitive bidding.” The Senate’s marked up version struck the words “and competitive bidding” from both the heading and the body, leaving only “the due process of evaluation.” As people who believe in compliance with the law and government transparency, this deletion concerns us — particularly when what is being selected here is a system that will teach English to 4-year-olds in 21 public schools.

It is also notable that 427 says nothing about whether AI systems that measure or infer the emotions of natural persons based on biometric data will be permitted — a practice prohibited under Article 5 of the EUAIA.

2. Senate Bill 348 — Artificial Intelligence as a Work and Instructional Tool for Students and Teachers in the Puerto Rico Department of Education

This bill, filed by PNP Senator Brenda Pérez Soto 3 weeks before 427, is much broader in its scope, even though its pilot plan does start in high school. With regards to AI use, it sets no age or grade whatsoever. In fact, its Articles 3 and 5 authorize AI throughout the entire Department of Education.

If enacted, this bill would allow AI to be deployed across all courses as an instructional tool, not only in English classes. The bill also proposes:

  • Creating the position of Compliance Officer, appointed by the Secretary of Education and charged with overseeing compliance with the act.
  • Creating a technology innovation and AI unit under the Undersecretariat for Academic and Programmatic Affairs.
  • Establishing a Pilot Plan in two high schools per educational region. One of the schools must be officially designated as a school under an improvement plan, and the other must not carry that designation. It is important to note here that Article 7 describes the pilot plan as one to “evaluate and implement educational and administrative strategies that promote improved academic performance at the high school level” — yet it never mentions AI. In a bill about AI, it is striking that the only article naming a school level does not say the pilot will be an AI pilot.
  • Requiring that school communities — including parents and guardians — be given orientation on the ethical and responsible use of AI.

This bill, which has already been passed by both the House and the Senate but whose amendments were rejected by the Senate on February 5, 2026 and has been in Conference Committee ever since, is notable for the following:

  1. Its Article 3(b) provides that AI will be used as a tool to support and complement teachers’ work, and adds, in parentheses, “it shall not be to replace them.” It is the only 1 of the 4 measures that says so expressly — although placing a parenthetical clarification inside a declaration of public policy is highly unusual legislative drafting.
  2. The Article 7 Pilot Plan will be in high schools and not in pre-K, as 427 currently stands. However, as noted, that article does not mention AI, and the rest of the bill sets no grade level at all.
  3. Article 3(e)(5) requires that AI be used to “identify students at possible risk of failure: students who need additional support.” This would almost certainly be done through predictive risk profiling of minors — a practice the European Union has classified as a high-risk activity under its Annex III, since it would create an AI system used to evaluate academic outcomes or determine access to education. Operating such a system in the European Union would require compliance with obligations on documentation, logging, human oversight, and a fundamental rights impact assessment. In 348, however, this is a single clause that does not include any measurement standards, no human oversight requirement, no appeal process, and no rule barring that AI output from following the student through their academic record and transcript. While systems that identify at-risk students can help head off bigger problems, they can also turn into systems of “tracking and monitoring by algorithm.”

Finally, we can’t overlook the irony that both legislative chambers passed a bill to transform education in Puerto Rico containing a word in its title — instruccional — that is not recognized by the Royal Spanish Academy Dictionary. This is not an unavoidable technical term: the word appears to be adapted from the American term instructional design, and Spanish already has “instructivo,” which the dictionary does include. The syntax is worse. The title of the bill calls AI a “herramienta de trabajo e instruccional”, literally, “a tool for work and instructional.” That phrase uncomfortably yokes a noun phrase to a bare adjective. “Herramienta de trabajo e instrucción” would have done the job. All of it is a small sign of how much of Puerto Rico’s AI-in-education vocabulary is imported rather than drafted here.

3. Senate Bill 820 — Puerto Rico Media and Information Literacy Act

820 was also filed by PNP Senator Brenda Pérez Soto. If enacted, it would require the Department of Education to build a curriculum aimed at achieving media, digital, and statistical literacy among Puerto Rico’s public school students, so they can develop essential skills in critical thinking, information evaluation, data analysis, and technology use.

820 further provides that this instruction will be emphasized in Spanish, social studies, science, and mathematics, beginning within the next 2 academic years or sooner.

The curriculum seeks to have students develop literacy in:

  • Critical evaluation of sources and verification of information.
  • Identifying disinformation and manipulation — whether false information, deepfakes, manipulated images, sensationalist headlines (clickbait), or other forms of altered content.
  • A basic understanding of how algorithms and artificial intelligence work.
  • Fact-checking and corroboration, applying fact-checking methodologies, using digital verification tools, reverse image search, consulting multiple reliable sources, and triangulating information to confirm accuracy.
  • Ethical and responsible production of digital content, including factual accuracy, proper source citation, and responsibility in disseminating information.
  • Respect for privacy, intellectual property, and digital rights.
  • Developing healthy habits in technology use.
  • Interpreting data, identifying potentially misleading statistical representations, and critically analyzing quantitative information.

Implementation would rest on a continuing teacher training program, with certifications, microcredentials, and other verifiable credentials counting as professional development hours.

This bill is the closest to what New York City announced, since it seeks to have students know and understand algorithmic systems regardless of whether they use them in class. Its statement of motives, moreover, does its own comparative-law work, citing California’s AB 873 (2023) and its 2024 expansion, along with the strategies of Finland, Sweden, and Canada.

Its weakness, however, is similar to 968’s: it is an unfunded mandate. Article 10 simply directs the DE to implement it through “the optimization of existing human, technological, financial, and infrastructure resources within the Department of Education, maximizing the use of low-cost or free virtual platforms, open educational resources, collaborative alliances with universities and nonprofit organizations, and training in hybrid and virtual formats that reduce operating costs.” It is also silent on how age-appropriate curricula will be established, or at what age it will begin — a curious omission, given that the bill’s own premise is that children’s developmental stages make them vulnerable to manipulation.

4. House Bill 968 — Act on the Ethical Use of Artificial Intelligence in Puerto Rico Educational Institutions

This AI governance bill was filed by PNP Representative José Aponte Hernández. It is very different from 427 in that it does not mandate the deployment of any tool. Instead, it requires the DE to adopt and implement policies on the ethical use of AI in public schools and to oversee compliance with them. It likewise obligates every private educational institution registered under Law 212-2018 to adopt and implement similar policies at their respective academic entities and to file those policies with the Puerto Rico Department of State within no more than 180 days of the act’s approval.

968 establishes that every policy must include the following general principles:

  • Security and protection.
  • Autonomy.
  • Privacy.
  • Transparency and explainability.
  • Diversity and inclusion.
  • Responsibility and accountability.

Article 6 also requires that, “prior to the integration of artificial intelligence systems in public schools and private educational institutions, and in each subsequent school year, students and both teaching and non-teaching staff shall receive orientation and training on the ethics and responsible use of AI technologies in instruction, including the policies adopted.”

968 stands out as a bill that will require schools to enact policies with certain principles. However, it does not say anything about what constitutes a policy that fails to comply with the act, who will review those policies, or what happens when an institution files a deficient one. Nor does 968 establish penalties or authorize private civil actions to compel compliance. It also does not establish the ages at which an educational institution may deploy AI, leaving it to the discretion of each school. 

There is also 1 provision that deserves special attention. The Privacy principle in Article 5 provides that “the informed consent of the user shall be guaranteed.” However, in a classroom, the user of the AI system is the student, and the bill says nothing about who consents when that user is a minor. It makes no reference to the Civil Code or to any other legal standard. As currently drafted, a school could satisfy this principle by obtaining informed consent from a 14-year-old. This is perhaps the most important provision across all 4 measures and, as presently written, does not require any parental involvement.

Why Should This Matter to You?

  • Because it is worth examining how these bills seek to identify at-risk students. Senate Bill 348, for instance, devotes 1 clause to it. On the other hand, the EU classifies this as a high-risk AI use requiring documentation, human oversight, and a fundamental rights impact assessment. If some version of this bill passes, this provision will likely be the one posing the greatest risk of adversely affecting a student — and it currently has no accuracy standard and no appeal process outlined in the bill.
  • Because if you work at a private school, you need to at least read House Bill 968 today. If your school is drafting an AI policy, it is worth preparing it — or revising your existing policies — along the 6 principles the bill sets out, so that you can comply with this bill if it becomes law.
  • Because vendors of educational products in Puerto Rico may already be bound by very different laws. A company built to satisfy the EUAIA’s high-risk obligations will produce a materially different product from what might be permitted in Puerto Rico. If you are considering a vendor for your educational institution, we recommend asking whether its system complies with Annex III — a fast way to learn how seriously they take these requirements, even when local law does not demand it.
  • Because if you care about parents being able to approve which educational programs their children use, you need to read 968 closely. It is the only bill that addresses informed consent, but it asks for it from the “user” — that is, the student — and says nothing about who consents on behalf of a minor. If that provision is stripped out, all that will remain for parents are the perception surveys mandated by Article 8 of 427, once the pilot has ended.
  • Because Puerto Rico needs to define at what age its children may interact with AI. Although the Guide says “13 or older” as a general rule, 427 would begin in pre-K if the Senate amendment prevails; 348 sets no grade limit at all on AI use; and 968 leaves it to each educational institution’s discretion. As a result, there is no definitive answer or position on a question that New York, Beijing, and Brussels have all treated as fundamental.
  • Because Puerto Rico appears to be charting a different course from the current consensus. The similarities among NYC, China, and the EU send a strong signal: these 3 systems, with very different policies, have independently concluded that their youngest students should not be talking to chatbots in the classroom. Those findings should be considered when a local law is taken up.

In Conclusion

New York City’s moratorium is significant because it was accomplished through a simple administrative decision, with no law at all. That was similar to what the DE did with the Guide — which set Puerto Rico on a very different course from NYC’s.

There is insufficient evidence at this time to say whether one approach is better than the other. It is a valid argument that a one-year moratorium protects a critical window in childhood development. An equally valid response is arguing that pulling AI out of classrooms widens the gap between students whose families let them access it from home and those whose families do not. House Bill 427 seeks to close that gap, and that is a legitimate goal.

In Puerto Rico’s case, however, what cannot currently be defended and needs to be reckoned with is that both legislative chambers filed bills to deploy AI in classrooms without first establishing a governance framework. The consequences of this decision are already visible: the most advanced bill has spent 7 months in Conference Committee after being passed unanimously by both the House and the Senate, precisely because there is no agreement on what it should say.

The order we propose is the one the EU used, prohibiting emotion inference in the classroom before the products arrived there, which is what New York City is doing this year: imposing a moratorium, convening a coalition, gathering evidence, and then making an informed decision.

Finally, if the Puerto Rico Legislature wants to create a lasting impact in this area, it is going to have to legislate it, and not leave it to each school’s discretion. When legislating, we believe it is essential to start with governance and principles, and then —once those are approved— begin implementation. That would avoid passing a bill that lets a kindergartner spend all day talking to and learning from a chatbot in the classroom, only to then seek a law saying whether that is appropriate and how it should be done.

If your school or educational products company wants to understand what standards apply in Puerto Rico, or wants to implement a governance policy on AI use at your institution, you can book a consultation with us today. We are here to help.

Can I be sued over an algorithm that I didn’t even program?

Learn how the settlement Meta reached with 52 attorneys general could set a standard that impacts your business.

The United States has no federal artificial intelligence statute. There is no American equivalent of the EU AI Act, no agency that certifies AI models, and no registry of high-risk systems. And yet, on August 26, 2026, Meta — the parent company of Facebook, Instagram and WhatsApp, among others — agreed to subject Instagram and Facebook to an algorithmic governance regime with mandatory error thresholds, annual third-party testing, and an independent auditor who reports to state attorneys general.

It did not take a federal AI law to get there. Instead, it required the political will of a bipartisan coalition of state attorneys general determined to litigate against Meta, and that litigation produced a settlement agreement whose effects will be felt across every state and territory, Puerto Rico included.

That is the point worth absorbing for anyone working in AI governance: while we waited for comprehensive federal legislation, algorithmic regulation in the United States arrived through consumer protection litigation.

What was the case that led to this outcome?

The settlement was reached inside a consolidated proceeding, In re Social Media Adolescent Addiction/Personal Injury Products Liability Litigation (MDL 3047, Northern District of California), which consolidated several state lawsuits against Meta on 2 legal theories:

  1. Unfair and deceptive practices, under what are known as state “UDAP” statutes (Unfair and Deceptive Acts or Practices). The states alleged that Meta designed its platforms to maximize the time adolescents would spend on them — through notification mechanics, infinite scrolling, and social rewards — while publicly representing that its products were safe and that its protective tools worked as advertised.
  2. COPPA violations. COPPA is the federal privacy statute protecting children under 13, and the states alleged Meta collected children’s data without verifiable parental consent, among other failures.

Meta denied all liability, and the agreement signed last week contains no admission of wrongdoing. Nevertheless, Meta will pay a guaranteed minimum of roughly $12.7 billion to what may be 48 states, the District of Columbia and 3 territories — Puerto Rico among them — distributed over the next 10 years. That figure could rise, according to Meta, to approximately $18 billion if other platforms meet certain conditions.

Five pieces of AI governance hidden inside a consumer protection settlement

Beyond a payment of a magnitude that would be catastrophic for the vast majority of companies worldwide, the more significant fact may be this: under the agreement, Meta committed — potentially for the next decade — to what is arguably the first AI governance framework established inside a legal proceeding. This agreement will need to be studied by every business, and particularly by those that market to minors or that know their websites and apps are used by minors.

The governance framework the agreement establishes:

1. A model with a written error threshold.

Meta is required to deploy age estimation methods — trained classifiers, not sign-up forms — and to meet maximum false positive rates: roughly 10% for minors aged 16 and 17, and 3% for the 13-to-15 group, with wider tolerances during the first year for proprietary methods. The agreement also requires Meta to build and test a dedicated model to detect users under 13, with annual detection targets.

This is remarkable. An American judicial settlement is fixing the minimum statistical performance of a machine learning model, by age group, in concrete numbers — leaving none of the ambiguity that “reasonable” or “commercially appropriate” criteria would have allowed.

2. Annual algorithmic audit by an independent third party.

An independent auditor will verify, on an annual basis, the false positive rates, the volumes of underage account detection, the effectiveness of the account-linking models, and the efficacy of the usage pauses, and will report to the states. In practice, this is an algorithmic system audit analogous to the one Article 37 of the European Digital Services Act (“DSA”) requires annually of very large platforms — with the difference that, in the United States, the requirement did not arrive through legislation but embedded in a consent judgment.

3. Purpose limitation on the model’s data.

Data collected to estimate age must be deleted immediately after the age determination is made, protected under the company’s highest standards, and may not be used for advertising, marketing, or to optimize recommendation models.

4. A right to contest an automated decision.

If the system misclassifies your age, Meta must offer a clear and conspicuous mechanism to appeal that determination, and must resolve it within a reasonable time.

5. The recommendation system becomes a regulated object.

Meta must offer a chronological feed — with no algorithmic personalization — on a reasonably accessible basis, present it actively to new teen accounts within the first 10 days, and remind users every 90 days. Supervising parents can lock that feed as the default. Add to this that teens will, by default, be unable to see how many likes or reactions posts receive; the pauses at 60 and 90 minutes of use; the overnight block; and the silencing of notifications during school hours.

The agreement does not treat the recommendation algorithm as an untouchable trade secret, but as a product feature that a regulator can order switched off where it is found to be defective, deceptive or abusive.

The global view: Europe reached a similar determination first, but through a different legal route

If these terms sound familiar to anyone who works with European regulation, that is because they are. On April 29, 2026, the European Commission preliminarily found that Meta had breached the Digital Services Act precisely for failing to identify, assess or mitigate the risk of children under 13 accessing Instagram and Facebook. The Commission estimated that between 10% and 12% of children under 13 in the EU use those platforms, and criticized a reporting tool for underage accounts that required up to seven clicks. Fines under the DSA can reach 6% of a company’s total worldwide annual turnover.

The European instruments worth remembering for these matters include:

  • DSA. Article 28 requires privacy, safety and security measures for minors and bars advertising based on profiling directed at minors; Articles 34 and 35 require assessment and mitigation of systemic risks, including effects on the physical and mental well-being of minors; Article 37 imposes annual independent audits; and Article 38 requires very large platforms to offer at least one recommender option not based on profiling. In other words: the chronological feed the states extracted from Meta by settlement is already a legal obligation in Europe.
  • GDPR. Article 8 governs children’s consent; Article 5(1)(b) and (c), purpose limitation and data minimisation; Article 22 and Recital 71, automated decision-making, which “should not concern a child”; Article 25, data protection by design and by default; and Article 35, impact assessments. In February 2025,the European Data Protection Board issued a statement on age assurance setting out 10 principles that anticipate, almost point for point, what the Meta settlement now requires: proportionality, minimisation, demonstrable effectiveness, safeguards against automated decision-making, and the warning that age assurance “should not provide additional means for service providers to identify, locate, profile or track natural persons.”
  • AI Act. Less applicable than one would expect, and it is worth understanding why. Article 5 — in force since February 2, 2025 — prohibits AI systems that exploit vulnerabilities arising from age in order to materially distort behaviour and cause significant harm, which describes the states’ theory about Meta’s addictive design. But the high-risk obligations under Annex III — the ones that bring risk management, data governance, technical documentation, human oversight and accuracy requirements — were deferred by the Digital Omnibus agreed in 2026, and now begin on December 2, 2027.

So, as things stand, the European instrument designed expressly to govern AI does not yet fully apply to these systems, while an American court settlement, negotiated under consumer protection laws dating to the 1970s, is already formally setting error thresholds and audits. Consequently, AI governance did not arrive through the creation of a purpose-built legal framework, as everyone assumed it would.

Why should this matter to me?

  1. Because you do not need an AI law for someone to demand AI governance from you. Any deceptive practices statute — Puerto Rico’s included — can be used to ask whether your model does what you said it does. If your company claims its system “detects fraud with 99% accuracy” or that its algorithm “does not discriminate,” that is a legally enforceable representation, and the burden of proving it is yours.
  2. Because the evidentiary standard in these cases has shifted. Meta did not lose because of what it did. Its legal exposure came because of the distance between its public representations and its own internal documents. In algorithmic governance cases, you generate the adverse evidence yourself: your evaluation metrics, your risk memos, the service tickets and complaints nobody inside the company ever addressed.
  3. Because numerical obligations are now being normalized. Once a public settlement establishes that an age classifier must operate at a 3% false positive rate for the 13-to-15 age group, that number becomes the reference point for the next case, the next contract, and the next negotiation with an enterprise customer.
  4. Because transatlantic convergence is becoming real. This settlement and the European regulatory framework point at the same approach — one that looks at the defects, risks and harms a product causes, and imposes nearly identical remedies. If you build for both markets, designing twice will increasingly be seen as wasted money: to be safe and to limit liability, you will have to operate to the most demanding standard.

How can I comply?

  1. Inventory your automated systems. Not just what you call “AI.” Include your scoring models, classifiers, recommendation engines and segmentation rules, among others. You cannot govern what you have not counted.
  2. Define the metrics before you deploy, not after. What is the acceptable error rate? For which subgroups? Who measures it, and how often? Write it down before a regulator or a court writes it for you.
  3. Build purpose limitation into your data pipeline. Data collected for compliance — verification, security, fraud prevention — must not be recycled for training, marketing or profiling. Beyond writing policies to that effect, create technical documentation that substantiates it.
  4. Build a mechanism to respond to individual complaints. Every automated decision affecting a person needs a visible route of appeal and a human being to handle it. This is already required in Europe under the GDPR, and it will increasingly be expected in the states.
  5. Prepare for an audit you cannot control. Assume that at some point a third party will ask for your evaluation documentation, your decision logs and your model change history. If that does not exist today, we recommend you build it within the next three months.
  6. Review your model vendors. If your classifier is built or maintained by a third party, their error rates are your error rates. Ask for certifications and keep them.
  7. If you are in Puerto Rico, start now — do not wait for a local AI statute. We already have Act 163 of 2026, which amended the Right to One’s Own Image Act to expressly cover representations generated, cloned or simulated by artificial intelligence, commonly known as deepfakes. And, if your business offers services to people in the European Union, the GDPR and the DSA apply to you even if your office is in San Juan, Aguadilla or Ponce.

Conclusion

For years, the conversation about AI governance in the United States circled around a single question: when will a federal AI law arrive? The Meta settlement suggests that this was the wrong question.

Algorithmic regulation arrived with no AI statute, no specialized agency and no legislative process. It arrived as a negotiated remedy inside a case, with numbers, deadlines and an auditor. And it arrived with a principle that applies to any organization deploying models, whether it has 50 employees or 50,000: if you cannot measure your system, you cannot defend it.

Europe built this order through regulations. The United States just wrote it into a consent judgment. The result, for whoever builds the products, is very nearly the same.

Want to know whether your business’s automated systems can withstand this kind of scrutiny? You can book a consultation with us today. We are here to help.

About the Author

Jaime Farrant is an attorney admitted to practice in Puerto Rico, New York, Maryland and the District of Columbia, with an LL.M. in International Law, focused on privacy, cybersecurity and artificial intelligence regulation for businesses and healthcare providers.

ATTORNEY ADVERTISING. This article constitutes advertising as defined under the rules of professional conduct in force in New York (22 NYCRR 1200.7.1 and 1200.7.3), Maryland (Rule 19-307.1 and 19-307.2) and the District of Columbia (D.C. Rules of Professional Conduct 7.1), as well as the Puerto Rico Rules of Professional Conduct (Rules 7.1-7.3). It does not constitute solicitation of known potential clients in need of legal services in a particular matter. Rather, it is general information directed to the public about the practice of law and the legal services available. No attorney-client relationship is created by reading this article or by contacting the author.

Can I be Sued for Discrimination Under Puerto Rico’s Law 100 for Using ChatGPT at Work, Even if I Never Meant to Discriminate?

In our article published 2 weeks ago, we talked about how using AI to screen résumés exposes you to laws that prohibit workplace discrimination. Today, we want to focus on the risks you face if you operate in Puerto Rico under a law that almost no vendor will mention when you’re evaluating an automated “screening” tool: Law Num. 100 of June 30, 1959, Puerto Rico’s employment discrimination law, which applies even though its text doesn’t contain the word “algorithm” — and adds consequences that neither U.S. federal law nor the European Union impose.

What Does Law 100 Presently Say?

Before 2017, Law 100 gave employees a powerful tool: it provided that an adverse action — such as failing to hire, failing to promote, or terminating someone — taken without just cause, was presumed to be discriminatory. Once the employee triggered that presumption, the burden shifted almost entirely to the employer, who then had to affirmatively prove that no discrimination had occurred.

That changed with the Labor Transformation and Flexibility Act (Law 4 of 2017), which eliminated that presumption in order to align Puerto Rico with the federal standard known as McDonnell Douglas. Today, a claim under Law 100 works much like a federal one: the employee must establish a preliminary case (that they belong to a protected class, that they were qualified, that an adverse action occurred, and that similarly situated people outside that protected class were treated better). Once an employee does this, the employer must articulate a legitimate, non-discriminatory reason for the decision. If the employer does so, the burden shifts back to the employee, who must then prove that reason was pretextual.

In short: today, the burden of persuading the court that discrimination occurred rests more on the employee than on the employer.

However, AI introduces a real problem for employers even under this favorable standard. As mentioned above, the second step of the analysis requires you to be able to articulate a legitimate reason for the rejection. If your entire process was uploading résumés to a third-party tool and letting an algorithm screen them out, what is your legitimate reason for rejecting them? Answering “The system gave them a lower score” isn’t always enough — especially if the candidate can show, through statistics (as allowed under Title VII’s disparate-impact theory), that the tool’s rejection pattern — for example, disproportionately screening out women for a position — correlates with a protected category. In that scenario, your inability to explain the decision becomes the very evidence of pretext the candidate or employee needs to prevail.

That said, even though the burden of proof is no longer automatically stacked against the employer, Law 100 still has something Title VII doesn’t: harsher penalties, discussed below.

What Are the Penalties Under Law 100?

Law 100 imposes civil liability on the employer for double the damages caused (or between $500 and $2,000 if damages cannot be determined). In addition, discriminatory conduct may constitute a misdemeanor, punishable by a fine of up to $5,000 or up to 90 days in jail, or both. None of this exists under any federal anti-discrimination law. As a result — although it is uncommon for these cases to be prosecuted criminally — using AI to screen résumés could technically expose you to criminal liability in Puerto Rico. It’s a consequence many employers don’t know about or anticipate.

How Is This Regulated in Other Jurisdictions?

  • United States: there is no single federal law governing AI in employment. Instead, there’s a patchwork of local and state rules — New York City’s Local Law 144, which mandates bias audits; Illinois’s requirement to notify candidates when AI is used to analyze video interviews; Colorado’s risk assessments — layered on top of existing federal anti-discrimination laws (Title VII, ADEA, ADA) enforced by the EEOC and interpreted under the U.S. Supreme Court’s McDonnell Douglasstandard. All of these can be boiled down to: you’re allowed to use AI tools, but be ready to justify them if challenged — and know the specific compliance requirements in whatever state you operate in or evaluate candidates from.
  • European Union: if your company works with candidates or employees in the EU, or you simply want to understand where AI regulation is headed globally, it’s worth looking at the EU AI Act (Regulation (EU) 2024/1689), already in force, and likely the most comprehensive legal framework on artificial intelligence in the world today. The EU AI Act classifies AI tools used for recruitment and personnel selection — including filtering job applications and evaluating candidates — as “high-risk” systems. That means that before they can be legally used, the tool must undergo a conformity assessment, have technical documentation, risk-management systems, human-oversight mechanisms, and be registered in an EU database. Employers also have a specific obligation to inform workers and their representatives of the system’s existence before using it. In the European Union, unlike in Puerto Rico and the United States, an employer must demonstrate that its platform is safe before using it.

The difference in approach is significant. While the EU certifies the tool before it’s used, Puerto Rico and the United States require nothing upfront, but impose legal consequences if the tool produces a discriminatory result.

Why Should This Matter to You?

Because using AI that discriminates against candidates puts you at risk of paying damages — and if you’re in Puerto Rico, it puts you at risk of criminal liability.

Think about it in practical terms: if your AI tool disproportionately rejects candidates of a certain age or background, and a candidate manages to prove pretext — for example, by showing that you couldn’t coherently explain why the system screened them out — you face the possibility of having to compensate the people affected by the algorithm, and of being held criminally responsible for having used it. For a small business or a clinic, that’s a genuinely significant exposure that goes beyond what you’d anticipate if you only looked at federal law as your benchmark, or if you assumed you were covered because ChatGPT was built “without any intent to discriminate” or because you used the AI tool in “good faith.”

How Can I Comply With the Law?

  1. Always have an articulable reason for every rejection. “The system gave candidate X a lower score” isn’t enough on its own. You need to be able to explain, in concrete terms tied to the job’s qualifications, why a candidate didn’t move forward in the interview process.
  2. Demand documentation from your vendor. Ask whether the tool has been bias-audited, how often, and whether they’ll provide you that documentation. That evidence is what lets you satisfy the “articulate a legitimate reason” step if it is challenged.
  3. Keep a record of every decision. What data went in, what score or result the system produced, and what human review occurred before each final decision. That log is your evidence if you ever need to defend the process.
  4. Notify candidates that you use AI in the process. It’s good practice in Puerto Rico, and it’s already mandatory under the EU AI Act if you have candidates or employees in Europe.
  5. Run a risk assessment before adopting the tool — not after the first complaint. Ask yourself: what data was it trained on? Which protected categories might it be indirectly affecting? Remember that Law 100 protects, among others: age, race, color, sex, sexual orientation, gender identity, social or national origin, social condition, political affiliation, political or religious beliefs, being a victim (or perceived victim) of domestic violence/sexual assault/stalking, veteran status, marital status, and even certain hairstyles and hair textures associated with particular racial identities or national origins.
  6. Review your contract with the vendor. Who’s responsible if the tool produces a discriminatory result? Negotiate that clause if you can.

The Bottom Line

Since the 2017 labor reform, Law 100 no longer puts you in a worse evidentiary position than federal law. What does set Puerto Rico apart is what happens if you lose: double damages and the possibility of criminal liability, neither of which exists under Title VII. Remember, too, that if you can’t explain why your tool rejected a candidate, you may already be in violation of the law. Finally, remember that you need to keep your processes documented, make sure they’re supervised by people, and be able to explain and justify every decision. Know and formalize your processes before you’re forced to do so in front of a government agency or a court.

Do you think your current AI-driven hiring process could expose you to legal liability under Ley 100 if a candidate filed a complaint today — or do you just want to make sure your processes are compliant? Let’s talk. Book a consultation here.

About the Author

Jaime Farrant is admitted to practice law in Puerto Rico, New York, Maryland and the District of Columbia. Practice in all other jurisdictions is limited to immigration law. This article is for informational purposes only and does not constitute legal advice or create an attorney-client relationship.

ADVERTISING MATERIAL. This article constitutes advertising as defined by the professional conduct rules in New York (22 NYCRR 1200.7.1 and 1200.7.3), Maryland (Rule 19-307.1 and 19-307.2), and the District of Columbia (D.C. Rules of Professional Conduct 7.1), and the Puerto Rico Rules of Professional Conduct (Rules 7.1-7.3). It is not solicitation of prospective clients known to need legal services in a particular matter. Instead, it is general information directed to the public about the practice of law and available legal services. No attorney-client relationship is created by your reading of this article or by contacting the author. Consult qualified counsel in each jurisdiction with specific situations.

Can I Use ChatGPT to Put Bad Bunny in my business’s social media ads?

As I write this post, social media in Puerto Rico has blown up with Bad Bunny’s announcement that he will close his world tour in concert scheduled for August 22 and 23 in San Juan’s Hiram Bithorn Stadium. The amount of posts about this announcement reminded me of the many promotions posted by Puerto Rican restaurants, bars, and small businesses in their Facebook, Instagram and TikTok accounts, where they showed a photo of Bad Bunny eating at their restaurant, or having a beer at their bar. However, he was never in any of these places. These were AI-generated images, posted without his consent, for one obvious reason — to draw customers to their businesses using the likeness of arguably the most recognizable person in Puerto Rico today.  However, no business paid a license, asked permission, or, in most cases, thought twice about it.

If your business operates in Puerto Rico, New York, Maryland, or Washington D.C., the answer to whether you can legally do this depends heavily on which of these you’re in — and the gap between them is bigger than most business owners realize.

In the US, How – or If – you can use Deepfakes Depends Entirely on Where You Live

Unlike Puerto Rico, which just amended its “Right to One’s Own Image” statute (Law 139-2011, as amended by Law 163-2026) to explicitly cover AI-generated deepfakes by penalizing their unauthorized commercial use with damages of up to $100,000 per violation if the use was intentional or with gross negligence, the United States has no uniform federal right of publicity. Each state decides for itself whether — or how — to protect someone’s name, voice, or likeness from unauthorized commercial use. That means that the same AI-generated Bad Bunny photo can be a serious legal problem in one state and close to unregulated in the state next door.

New York: The Strongest Protections of All

New York has protected this right since long before generative AI existed. Civil Rights Law §§ 50–51 makes it a misdemeanor — and a civil cause of action — to use a living person’s name, portrait, picture, likeness, or voice for advertising or trade purposes without their prior written consent. Section 51 lets the injured person seek an injunction, actual damages, and, if the defendant knowingly used their likeness, exemplary (punitive) damages at the jury’s discretion.

On top of that foundation, New York has added two AI-specific layers in the last 2 years:

  • The Digital Replica Contracts Act (General Obligations Law § 5-302): voids contract provisions that let an employer replace a performer’s actual performance with a digital replica, unless the performer was represented by counsel or a union and the terms are stated clearly in a separately signed agreement.
  • The Synthetic Performer Disclosure Law (General Business Law § 396-b), effective June 9, 2026: requires advertisers to conspicuously disclose when an ad contains a “synthetic performer” created using generative AI. Civil penalties run $1,000 for a first violation and $5,000 for each subsequent one.

Put together, a New York business running that “Bad Bunny at my bar” photo is exposed on two fronts: a §§ 50–51 claim from Bad Bunny himself (or his estate, for that matter, since New York also protects deceased performers’ digital replicas under Civil Rights Law § 50-f), and a separate disclosure penalty if the ad used a synthetic element and didn’t label it.

Maryland: Barely Any Legal Protections at All

This is likely to surprise business owners coming from New York or Puerto Rico: Maryland has no right of publicity under its statutes or common law. It’s one of only a handful of states (along with Alaska, Kansas, and North Carolina) where this right doesn’t exist as such. A bill that would have created a civil cause of action for unauthorized use of someone’s identity via AI or deepfakes — House Bill 1425/Senate Bill 905 — did not pass in the 2025 session. It’s been reintroduced as House Bill 184 for the 2026 session, but as of this writing, it has not been approved.

Maryland does have a deepfake statute — Senate Bill 141 (2026), effective June 1, 2026 — but it is narrowly limited to election-related deepfakes intended to influence voting or misrepresent election facts. It has nothing to say about a restaurant using an AI-generated photo of a celebrity to sell arepas, margaritas or mofongo.

Practically, this means that today, a Bad Bunny impersonation ad run by a Maryland business faces essentially no exposure under Maryland state law specifically built for this problem. That could change if HB 184 passes, and it’s also worth remembering that Bad Bunny himself could still bring a claim in a state where he does have rights like New York, depending on where the harm occurred.

Washington D.C.: Regulated by Common-Law, Not a Statute

D.C. has no right-of-publicity statute either. What it has is a common-law claim for misappropriation, drawn from the Restatement (Second) of Torts § 652C, as applied in Vassiliades v. Garfinckel’s, Brooks Bros., 492 A.2d 580 (D.C. 1985). To win, a plaintiff has to show both that the defendant benefited from using their identity and that there’s a recognizable public or commercial value in that identity — the exact opposite of a bright-line statute like New York’s. This makes outcomes far less predictable and cases more expensive to bring, since there’s no statutory damages figure to point to and no per-violation civil penalty to threaten a defendant with.

How is This Regulated in the European Union?

The European Union has taken an approach very different than the patchwork of state laws in the US through its enactment of the EU AI Act, which applies across all Union states. The EU AI Act does not establish a standalone private right of action for damages; rather, it imposes administrative transparency obligations. Under Article 50 of the Act, providers of Al systems that generate or manipulate image, audio, or video content constituting a deepfake must clearly disclose that the content has been artificially generated or altered. An exception applies when such content is part of an obviously artistic, satirical, or fictional work, provided it is not presented in a misleading manner. Failure to comply with these transparency requirements constitutes a serious infringement, subject to administrative fines of up to €15 million or 3% of the undertaking’s total worldwide annual turnover for the preceding financial year, whichever is higher.

Why Should This Matter to You?

If you run a business — or advise clients who do — across any of these jurisdictions, the question “can I use an AI image of a celebrity in my ad” doesn’t have one answer, and responses range from “yes, expect a lawsuit and pay damages of up to $100,000” (Puerto Rico), to “yes, expect a lawsuit and possible punitive damages” (New York) to “there’s currently no statute built for this” (Maryland) to “it depends on how a judge applies a 40-year-old privacy tort” (D.C.), or “you must publish in your campaign that its content was artificially generated” (EU). Consequently, a marketing decision that’s clearly reckless in Manhattan might be legally uneventful across in Maryland — for now.

These differences are exactly the kinds of gaps that generative AI has widened. Tools like ChatGPT, Claude, Midjourney, and similar platforms make it trivial to generate a photorealistic image of a real, identifiable person for a fraction of what a licensing deal would have cost a few years ago. The law in most of the United States hasn’t caught up uniformly, which means your exposure depends less on what you did and more on where you did it.

How Can You Comply With the Law?

  • If you operate in New York, treat any AI-generated image or voice of a real person in your advertising as requiring the same written consent you’d need for a real photo — Civil Rights Law § 51 doesn’t distinguish between a real photograph and a generative AI recreation.
  • If your New York ad uses a synthetic performer (not a real, identifiable person, but a “no such person exists” AI-generated model), confirm you’re including the conspicuous disclosure required by GBL § 396-b before it airs.
  • If you operate in Maryland, don’t assume the absence of a right-of-publicity statute means zero risk — track HB 184, and remember a claim can still be brought in a state where the depicted person has stronger rights.
  • If you operate in D.C., document your process for obtaining consent regardless of the weaker legal baseline; a misappropriation claim can still succeed, and consent is always the safer route.
  • If you operate in Puerto Rico, make sure your processes clearly document that the use was authorized.
  • If you operate across multiple states, apply the strictest applicable standard (in this example, New York’s) to any content you plan to run across state lines or online, since your audience — and any resulting claim — isn’t limited to where your business is physically located.
  • If your campaign will be shown in the European Union, you will have to divulge that it was artificially generated.

The Bottom Line

Puerto Rico, New York, Maryland, D.C., and the European Union sit at very different points on the right-of-publicity spectrum — from New York’s statutes with real teeth, to Maryland’s near-total absence of protection, to D.C.’s uncertain common-law doctrine. If your business uses generative AI in marketing and you operate in more than one of these jurisdictions, the safest approach is to assume the strictest rule applies everywhere your content is seen, not just where you’re physically located.

Does your business use AI-generated content in advertising across New York, Maryland, or D.C.? Schedule a consultation today to review your exposure in each jurisdiction where you operate.

About the Author

Jaime Farrant is admitted to practice law in Puerto Rico, New York, Maryland and the District of Columbia. Practice in other jurisdictions is limited to immigration law. This article is for informational purposes only and does not constitute legal advice or create an attorney-client relationship. Laws referenced are current as of August 15, 2026.   

ADVERTISING MATERIAL. This article constitutes advertising as defined by the professional conduct rules in New York (22 NYCRR 1200.7.1 and 1200.7.3), Maryland (Rule 19-307.1 and 19-307.2), and the District of Columbia (D.C. Rules of Professional Conduct 7.1), and the Puerto Rico Rules of Professional Conduct (Rules 7.1-7.3). It is not solicitation of prospective clients known to need legal services in a particular matter. Instead, it is general information directed to the public about the practice of law and available legal services. No attorney-client relationship is created by your reading of this article or by contacting the author. Consult qualified counsel in each jurisdiction with specific situations.