ADVERTISEMENT

From principles to practice: Making an AI bill of rights work in a downstream Philippines

Published Aug 12, 2026 01:38 pm
Indonesia to begin social media ban for users under 16 - 2
Indonesia to begin social media ban for users under 16 - 2
Written with Edsel F. Tupaz
House Bills 2827 and 3195, both filed under the Twentieth Congress, enumerate five fundamental rights every Filipino should enjoy in relation to AI systems -- the right to know, to remedy, to protection from unsafe systems, to privacy, and to freedom from algorithmic discrimination. These are the right commitments. But the Philippines has a long tradition of well-written laws that go unenforced. An AI Bill of Rights risks becoming the latest entry in that tradition.
AI bills are rich in rights but poor in mechanisms. By design, “bills of rights” and other catalogs of rights found in other jurisdictions tend to be stated as fundamental principles. In many cases, these catalogs of rights are operationalized elsewhere or downstream, such as through court procedure or statute. To be sure, principles without enforcement mechanisms remain aspirational rather than operational. Rights-based approaches are not intended to function as standalone instruments. Canada’s AIDA and the US Blueprint failed to gain traction not because rights are wrong. It is because rights alone would not answer the questions “enforced by whom, how, and against what?” Rights define only what must be protected, and not the manner in which protection is delivered. That is the work of risk-based frameworks and risk-based governance. The Philippines will have rights on paper, but the real question is whether applying any set of “AI rights” can stop AI-powered risks and harms on the ground. The answer may lie in clear and comprehensible obligations that translate AI rights into tangible standards that agencies can meaningfully enforce. This is not to abandon rights-based approaches – it is to complete them. An AI bill of rights is a necessary but not a sufficient condition for effective AI governance.
What rights promise - and what they don't
Two AI bills currently pending in Congress enumerate rights borrowed closely from the US AI Bill of Rights – rights to protection from unsafe systems, freedom from algorithmic discrimination, privacy, the right to know, and the right to remedy. The problem, however, is not how these rights are written. The problem is how to progressively realize AI rights. This typifies a “rights implementation gap”. In the pending bills, there are no corresponding obligations on deployers, no standards for what “unsafe” means in practice, and no complaint pathway to address algorithmic discrimination. The right to know illustrates this most clearly: companies deploying AI in customer service are not required to disclose that an AI is handling the interaction, what it does, or how it reaches its decisions. A right without a corresponding obligation is a declaration, not a guarantee to realize it.
The implementation gap
The Bangko Sentral ng Pilipinas (BSP) Complaint Assistant Mechanism (BSP-CAM) case shows how a right can exist in plain sight and remain unenforceable in key aspects. The Consumer Assistance Mechanism (CAM) is a mature, legally grounded complaints system– covering all BSP-supervised financial institutions, with escalation pathways, and adjudication mechanisms under RA 11765 and BSP Circular No. 1048. When a Philippine lending platform that simultaneously develops and deploys its own AI credit scoring system denies credit to a Filipino borrower and its own complaint system fails to be responsive, the borrower can escalate the case to BSP-CAM under the “right to know.” The borrower lodges a complaint with BSP invoking the right to know the reasons for credit denial. But here the right to know may fall short of delivering desirable outcomes. The BSP-CAM was designed for human decisions – unauthorized charges, deceptive practices, and unresolved disputes, but it does not know how to examine the manner in which AI systems reach their decision, nor does it know how to compel the lending platform to disclose the algorithmic decision-making process. Because BSP-CAM will not go outside its comfort zone, the lending platform will not feel obliged to disclose the criteria, the algorithmic process, or even that an AI made a decision that affected the rights and interests of consumers. Here, BSP-CAM’s implementation gap arises. The gap between the right (to know) and the desired outcome becomes evident. BSP-CAM would frame the issue as whether a credit should be issued – not how the decision was made. The institution exists. The right exists. But the institution is unable to bridge both. Perhaps BSP-CAM is aware of the right, but it is not willing and able to apply it to the case before it. Is this a statutory void? Or is it a capacity issue?
Rights aimed at the wrong stage
The rights-realization gap --the growing distance between rights on paper and their actual fulfillment as conditions change-- is not new. AI has simply reopened it in ways existing mechanisms were never designed to handle.
There is more. Rights-based approaches in the Philippine context seem to be aimed at the wrong phase in the AI development lifecycle. So far, pending legislation seeking to adopt AI bills of rights is targeting system design where the frontier developer is most active, instead of governing the deployment and use phases where the local actor – that’s us – is impacted. The deployment phase is where AI systems reach into the territorial laws and jurisdiction of Philippine courts.
Given judicial hesitation and tenuous long-arm jurisdiction over frontier developers in Silicon Valley or Shenzhen, the better candidate for jurisdictional purposes is the onshore deployer, if not the user. The Philippines should bridge AI rights with enforceable, function-specific obligations that address and manage the closest supply chain actors. AI rights should be feasible to enforce. Specifying which functions to oversee and govern, and locating these functions within the onshore deployer, will transform rights from merely declarative statements to operationalizable controls. enforceable.
The institutional logic that works: Is data privacy law the answer?
One can look closer to home. The Data Privacy Act of 2012 can demonstrate that rights can be successfully operationalized. The law treats data controllers and data processors as key governance actors, and imposes clear obligations on each in relation to “data subjects”. Under the Act, the National Privacy Commission serves as the policy, rule-making, adjudication, and enforcement body for privacy laws. When the NPC issued its advisory on AI systems that process personal data (Advisory No. 2024-04), it provided an agency interpretation and application of general data privacy principles into AI systems, and provided the building blocks for AI governance. A 2012 law is underpinning AI governance today.
The AI advisory is useful but, understandably, too privacy-focused. A BPO using AI-enabled workforce management software is not primarily a privacy issue. However, unlike the NPC, DOLE has no guidelines on algorithmic fairness in workplaces. This is a case where rights-based approaches currently fail: One agency can be in a position to implement a right, while another agency will not give attention to the same right, even if all their stakeholders are similarly impacted. Remedial legislation is rigid and slow to move. Advisories and department orders, on the other hand, are flexible and quick. AI governance needs both the statute, which serves as the stable normative foundation, and subordinate regulation, which comprises the adaptive operational layer. Lawmakers can look to the logic of the DPA for a steady stream of local use cases for AI rights realization in the form of ground-level agency-specific regulation. It is not only faster. It is more contextual.
Rights realization: Translating rights into enforceable obligations
The right to know and the right against algorithmic discrimination become enforceable when financial institutions have clearly defined obligations toward consumers. Section 8(c) of RA 11765, otherwise known as the Financial Products and Services Consumer Protection Act, obliges financial service providers to be transparent and provide proper disclosure of their products and services. Section 8(d) obliges financial service providers to provide fair and respectful treatment of clients. AI governance and enforcement pathways can be adopted within existing statutory authority. There is no need to await the grandeur of an all-encompassing law. BSP-CAM already has the complaint pathways, mediation, and adjudication infrastructure– these are all existing provisions that give it the AI-specific mandate it needs. The question is whether an agency like the BSP-CAM is able and confident enough to fill the gap. How will a forthcoming “AI Bill of Rights” build confidence among agencies to govern AI under their existing legal mandates?
Rights only exist where they are enforced
The Philippines does not need to abandon its quest for an AI bill of rights. It needs to complete it. The rights enumerated in several bills that have been pending since the 19th Congress – to know, to remedy, to be protected from unsafe systems– are necessary normative commitments. The Data Privacy Act proved that rights can be operationalized even with old black letter law. The BSP has the institutional infrastructure to do the same for AI in lending under existing statutory authority without waiting for a monolithic AI law, especially in the face of clear and present dangers that affect everyday consumers. The same logic extends to DOLE for algorithmic labor management, to DICT for digital infrastructure involving new AI systems, and to other agencies within their respective subject matter jurisdiction. At the end of the day, AI rights in the Philippines will succeed not by how well its rights are written but on whether anyone has the willingness and confidence to uphold them.
*The authors acknowledge the supervision of Ze Shen Chin of AI Standards Lab and a Research Affiliate at the Oxford Martin School AI Governance Initiative, as well as Lenz Dagohoy and Lexley Villasis of AI Safety Diliman.
AI Safety Diliman is supported by Kairos, an AI safety field-building nonprofit focused on strengthening the global AI safety and policy talent pipeline, and is fiscally sponsored by the Berkeley Existential Risk Initiative, an entity that supports academic and field-building efforts to reduce catastrophic risks associated with advanced technologies.
** Yanro Ferrer is a Fellow at AI Safety Diliman under the 1st cohort of its AI Governance Accelerator, focusing on non-frontier AI governance and AI risk-based frameworks in AI policy in the Global South. He is also a lecturer at Ateneo de Manila University, where he teaches and researches digital sociology, technology, and contemporary online cultures.
Alongside his academic work, he drafts bills and conducts legislative research for a member of the House of Representatives of the Philippines, contributing to policy discussions at the intersection of technology, regulation, and public institutions.
***Atty. Edsel Tupaz is Lead Researcher and Fellow at the AI Governance Accelerator Program of AI Safety Diliman. He is a Senior Partner at Gorriceta Africa Cauton & Saavedra and leads its Data Privacy, Cybersecurity, and & AI Initiatives practice.

Related Tags

AI Bill of Rights AI Bill of RIghts
ADVERTISEMENT
.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1561_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ static_articles_1562_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1563_widget.title }}

{{ articles_filter_1564_widget.title }}

.mb-article-details { position: relative; } .mb-article-details .article-body-preview, .mb-article-details .article-body-summary{ font-size: 17px; line-height: 30px; font-family: "Libre Caslon Text", serif; color: #000; } .mb-article-details .article-body-preview iframe , .mb-article-details .article-body-summary iframe{ width: 100%; margin: auto; } .read-more-background { background: linear-gradient(180deg, color(display-p3 1.000 1.000 1.000 / 0) 13.75%, color(display-p3 1.000 1.000 1.000 / 0.8) 30.79%, color(display-p3 1.000 1.000 1.000) 72.5%); position: absolute; height: 200px; width: 100%; bottom: 0; display: flex; justify-content: center; align-items: center; padding: 0; } .read-more-background a{ color: #000; } .read-more-btn { padding: 17px 45px; font-family: Inter; font-weight: 700; font-size: 18px; line-height: 16px; text-align: center; vertical-align: middle; border: 1px solid black; background-color: white; } .hidden { display: none; }
function initializeAllSwipers() { // Get all hidden inputs with cms_article_id document.querySelectorAll('[id^="cms_article_id_"]').forEach(function (input) { const cmsArticleId = input.value; const articleSelector = '#article-' + cmsArticleId + ' .body_images'; const swiperElement = document.querySelector(articleSelector); if (swiperElement && !swiperElement.classList.contains('swiper-initialized')) { new Swiper(articleSelector, { loop: true, pagination: false, navigation: { nextEl: '#article-' + cmsArticleId + ' .swiper-button-next', prevEl: '#article-' + cmsArticleId + ' .swiper-button-prev', }, }); } }); } setTimeout(initializeAllSwipers, 3000); const intersectionObserver = new IntersectionObserver( (entries) => { entries.forEach((entry) => { if (entry.isIntersecting) { const newUrl = entry.target.getAttribute("data-url"); if (newUrl) { history.pushState(null, null, newUrl); let article = entry.target; // Extract metadata const author = article.querySelector('.author-section').textContent.replace('By', '').trim(); const section = article.querySelector('.section-info ').textContent.replace(' ', ' '); const title = article.querySelector('.article-title h1').textContent; // Parse URL for Chartbeat path format const parsedUrl = new URL(newUrl, window.location.origin); const cleanUrl = parsedUrl.host + parsedUrl.pathname; // Update Chartbeat configuration if (typeof window._sf_async_config !== 'undefined') { window._sf_async_config.path = cleanUrl; window._sf_async_config.sections = section; window._sf_async_config.authors = author; } // Track virtual page view with Chartbeat if (typeof pSUPERFLY !== 'undefined' && typeof pSUPERFLY.virtualPage === 'function') { try { pSUPERFLY.virtualPage({ path: cleanUrl, title: title, sections: section, authors: author }); } catch (error) { console.error('ping error', error); } } // Optional: Update document title if (title && title !== document.title) { document.title = title; } } } }); }, { threshold: 0.1 } ); function showArticleBody(button) { const article = button.closest("article"); const summary = article.querySelector(".article-body-summary"); const body = article.querySelector(".article-body-preview"); const readMoreSection = article.querySelector(".read-more-background"); // Hide summary and read-more section summary.style.display = "none"; readMoreSection.style.display = "none"; // Show the full article body body.classList.remove("hidden"); } document.addEventListener("DOMContentLoaded", () => { let loadCount = 0; // Track how many times articles are loaded const offset = [1, 2, 3, 4, 5, 6, 7, 8, 9, 10]; // Offset values const currentUrl = window.location.pathname.substring(1); let isLoading = false; // Prevent multiple calls if (!currentUrl) { console.log("Current URL is invalid."); return; } const sentinel = document.getElementById("load-more-sentinel"); if (!sentinel) { console.log("Sentinel element not found."); return; } function isSentinelVisible() { const rect = sentinel.getBoundingClientRect(); return ( rect.top < window.innerHeight && rect.bottom >= 0 ); } function onScroll() { if (isLoading) return; if (isSentinelVisible()) { if (loadCount >= offset.length) { console.log("Maximum load attempts reached."); window.removeEventListener("scroll", onScroll); return; } isLoading = true; const currentOffset = offset[loadCount]; window.loadMoreItems().then(() => { let article = document.querySelector('#widget_1690 > div:nth-last-of-type(2) article'); intersectionObserver.observe(article) loadCount++; }).catch(error => { console.error("Error loading more items:", error); }).finally(() => { isLoading = false; }); } } window.addEventListener("scroll", onScroll); });

Sign up by email to receive news.