Skip to content
Make AI Good

Graph · Strategy

Mandatory algorithmic impact assessment requirement

01 · In focus

One strategy, in the field.

The structured facts the source records about Mandatory algorithmic impact assessment requirement, the count of declared adjacencies in the corpus, and the federation map zoomed on this node and its neighbours.

strategy

6 declared connections

Kind
Strategy
Status
active
Confidence
high
Entity ID
strat-mandatory-algorithmic-impact-assessment-requirement
Network
View in network

Tags regulation, procedural-requirement, pre-deployment-audit, impact-assessment, aia, transparency-mandate, statutory-demand, environmental-impact-statement-analog

Mandatory algorithmic impact assessment requirement · 6 direct neighbours visible

02 · Connections

6 adjacencies, by relation.

Split by direction. Direct links are the ones Mandatory algorithmic impact assessment requirement’s source record names; inferred backlinks are records elsewhere in the corpus that point at this entity.

03 · Background

From the source record.

Body prose as it appears in movement-graph’s published markdown for this entity. Links to other corpus entities resolve to their graph page; links to deeper repo paths are kept as text so the page does not invent a route.

Advocate for a statutory or regulatory requirement that any organisation deploying a high-impact AI system must, before deployment, conduct and publicly disclose an algorithmic impact assessment (AIA) — a structured pre-deployment analysis of the system's likely effects on affected populations, its failure modes, its bias and fairness properties, and the mitigations in place. The requirement is modelled on the National Environmental Policy Act's environmental impact statement (a project cannot proceed until the disclosure is on file), on privacy impact assessment regimes (GDPR Article 35 DPIA, PIPEDA, CCPA), and on the public-consultation window those statutes require. The AIA regime supplies the movement with a standing evidentiary base for every downstream tactic — a published record every audit, court filing, regulator complaint, and consumer campaign can cite.

An actor chooses this strategy because deployed AI systems are evidence-poor by default and the operator controls disclosure. A mandatory AIA regime inverts that default: the operator must produce the disclosure the movement would otherwise have to fight to obtain, on a schedule the operator cannot control, in a form that must survive public comment. The strategy converts a diffuse advocacy demand ("please tell us how your system works") into a compliance obligation with legal consequences for non-disclosure. It runs upstream of every empirical-audit and DPA-complaint tactic — those tactics gain force when the operator's own AIA is the document being tested against reality, rather than being reconstructed by outside researchers from limited access.

It trades depth for procedure. An AIA regime is a disclosure requirement, not a permission requirement — the operator files the assessment and typically proceeds unless a regulator explicitly halts deployment, and the disclosure itself can be drafted defensively by the operator's compliance team to reveal only what the statute strictly requires. The strategy also runs into the standard capture pattern: the regulator interpreting the statute is often the same regulator the industry has cultivated, and the AIA's methodology can be watered down through implementing regulations to the point where it becomes a checkbox exercise. And the assessment costs money, which — depending on the threshold — can either be a real brake on the largest deployments or a compliance-tax the largest vendors absorb while blocking smaller entrants.

Ecology

Distinct from empirical audit and expose. That strategy is what civil society does after deployment, without the operator's cooperation — a reproducible test the movement runs to surface the harm. This strategy is what the operator must do before deployment, with the disclosure as the product. The two are complementary: the AIA regime generates the operator's official account of the system's expected behaviour; the empirical audit tests that account against measured reality. Discrepancies between them are the movement's strongest evidentiary product.

Distinct from community-defined benchmarks and standards. Community-defined benchmarks are civil-society-authored measures the movement builds and pushes; a mandatory AIA regime is a statutory disclosure requirement whose methodology may or may not adopt those benchmarks. The most valuable outcome for the movement is one where the AIA's required methodology incorporates the community-defined benchmarks — a regulatory adoption that graduates the benchmark from advocacy artifact to compliance instrument.

A sub-strategy inside coalition lobbying of binding regional regulation. The AIA requirement is one specific provision the regulatory-lobby coalition pushes into the statute the coalition is working. The EU AI Act's fundamental-rights impact assessment provision (Article 27), New York City Local Law 144's automated employment decision tool bias audit, Canada's Directive on Automated Decision-Making's mandatory AIA — each is an instance of this strategy landing inside a broader regulatory-lobby campaign.

Fed by freedom of information as evidence-gathering. Before an AIA regime is in place, FOIA is the movement's ad-hoc substitute for the disclosure the regime would require; after the regime is in place, FOIA remains the mechanism for testing whether the operator's AIA is complete.

Fed by civil society inside technical standards bodies. The AIA methodology the statute references is typically developed in a technical standards body (ISO/IEC, NIST, CEN-CENELEC); civil-society participation in that standards work determines how demanding the assessment methodology actually is.

Source: entities/strategies/strat-mandatory-algorithmic-impact-assessment-requirement.md — movement-graph pin 5edfc3b.