A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

Fexco

'Gdpr For A.I': The Eu Artificial Intelligence Act

In 2018 the EU GDPR turned the data and privacy world upside down. Now, Brussels has targeted its regulatory crosshairs on the burgeoning world of artificial intelligence. In April 2021, the EU published the draft Artificial Intelligence Act (‘A.I. Act’). Nicknamed ‘GDPR for A.I.’ the Act, when it comes into force, will be the world’s first comprehensive regulation governing the use of A.I. and will be a game changer for many providers in this area. For many companies, who are using A.I. to process personal data, there will also be a significant crossover between existing GDPR obligations and forthcoming obligations under the A.I. Act.

Using a risk-based approach the A.I. Act divides artificial intelligence into unacceptable risk, high risk, and limited and minimal risk. Any A.I. activity that falls into ‘unacceptable risk’ will be banned outright, while any activity in the ‘high risk’ category will be subject to extensive compliance obligations. Seven high risk areas (such as using A.I. for core private and public services) are prescribed by the Act, a list to which the EU Commission can add to. Where limited and minimal risk apply, there will no significant changes for companies.

In practice, the high risk category is the one which will impact companies the most. Where this risk rating applies, companies must ensure the quality and accuracy of A.I. algorithms, guard against bias and discrimination, build in transparency to A.I. processing, allow for human oversight, guarantee that algorithms’ logic can be explained, and retain a full audit trail of the risk assessment conducted and the various measures taken to ensure on-going compliance.

“The compliance world is about to get a lot more complicated and the EU is not for turning. The A.I. Act is coming and companies need to start thinking about it now”

For A.I. companies doing business in the EU, this represents an existential moment: if they cannot prove compliance with the Act, they will not be allowed to sell their product within the EU. It is also a problem with a fixed timeline: the EU plans to pass the A.I. Act into law in October of this year, before giving a two-year implementation period during which companies will be expected to get their house in order. Q4 of 2024, then, is likely to be D-Day.

As regards the Acts interaction with the GDPR there are a number of important areas to consider, which compliance and IT managers will need to be aware of:

• Firstly, there are many contexts where A.I. is being used to process personal data, meaning that both the GDPR and the A.I Act will apply to that same activity.

• Secondly, the A.I. Act is worryingly silent on how it will interact with the GDPR, something which needs to clarified by guidance.

• The A.I. Act requires providers of A.I. to conduct risk assessments. This will be in addition to the requirement to conduct DPIAs, which will mean dual risk assessments being conducted.

• In addition to privacy software, the A.I Act is going to require companies to invest in A.I. compliance software that can perform the difficult task of risk-assessing, monitoring and validating A.I. tools. Currently, there is a lack of such omnibus software, so managers will have to watch out for emerging technology solutions in this area.

The compliance world is about to get a lot more complicated and the EU is not for turning. The A.I. Act is coming and companies need to start thinking about it now.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
Top