Speaker 0
0:00 – 0:24
Welcome to CDT's Tech Talks brought to you by the Center for Democracy and Technology and the Center for Democracy and Technology Europe. This week, we are launching a special series of conversations bringing together policy experts from CDT Europe and CDT US to discuss how digital rights issues are unfolding from both sides of the pond. I'm Aimee Dupre Macabrese, and it's time to talk tech.
Speaker 1
0:26 – 0:28
Welcome to Tech Talk. Bye.
Speaker 0
0:28 – 1:10
C t t. Today's conversation is all about AI, equity, and data. As regulation ramps up and public awareness of AI's risks grows, the question remains, how do we ensure fairness, transparency, and human rights all left behind in the race to deploy AI? To talk through this, we're joined by Laura Lazaro Cabrera from CDT Europe who has led our engagement on the EU's AI Act and the European Commission's recent moves toward deregulation, and Miranda Bogan from CDT US who focuses on AI governance and technical mechanisms to ensure safety. Let's join their conversation.
Speaker 2
1:11 – 1:24
Hi, Miranda. Great to have you here. Great to chat to you. It's always great to talk to you, Laura. Fantastic. So, Miranda, let's dive right in. I know in The US, you're focusing on practitioners working on development and governance of AI.
Speaker 1
1:24 – 4:42
What are you seeing from where you stand? Yeah. So a big trend at the moment, I think we're all seeing, is that policymakers over here are really drawing back from the types of pressure that the previous administration was bringing to to practitioners that was pushing them to be really thoughtful about what they were doing. But just because that pressure is being pulled back doesn't mean that nothing's happening. Right? There's an ecosystem of practitioners that are working on AI governance, AI safety. That's really an active and vibrant scene. People are doing the work, and and they're aware that they have to build these systems thoughtfully and responsibly if people are gonna use them. And so, you know, that's a a community that feels important to focus on because they're really making critical decisions and and doing it with less and less guidance at the moment. But at the end of the day, like, what does all that work lead to? We've been doing a lot of research on different domains to try and understand what governance practices look like and the impact that they have. And even when there are robust governance practices, institutions are still gonna take on risk. Just because they're conducting risk management doesn't mean they're mitigating all risk, and that's sometimes a mistaken assumption people make. So given that, how do you encourage responsible conduct? So, to me, there are two ways to go about doing that. The first is to make it easier for those practitioners to do their work. So, looking for barriers that they're facing, helping explain complex issues, or do some analysis that will help more folks rally around, some best practices and really giving those tools to practitioners where it will help them. But another is to change that risk calculus that organizations make so that taking on risk is actually more costly, and they have to think twice about whether to do that. You can do that by making those risks and harms more salient, by telling compelling stories about how those harms manifest, by, increasing the costs, of those harms, whether that's through regulation or private levers like insurance or creating a private assurance market and using market forces to to really change how organizations think of the choices that they're making. Now those are levers that that we're drawing on that we think could really shape the market and shape practitioners. But a really concerning trend over here is that lawmakers and major investors and and prominent public figures are starting to characterize the responsible development of AI as a partisan effort that slows down innovation, and that is a bad thing to even be thoughtful about what you're building, which is it's ridiculous. And it's it's quite to the contrary. Right? You know, making sure that organizations know what it is they're building, do due diligence on what they're building so that they know what risks they're taking on. That's just basic good business practice. So it's it's just so surprising to see that being framed as something that organizations shouldn't be doing and it and that it might actually be risky for them to to do responsible AI work in the first place. Businesses don't kind of do this work on their own. That's gonna be make everyone worse off, and it's just surprising that they're trying to shame and dissuade people from building in what are obvious safeguards. This is really just good business practice.
Speaker 2
4:42 – 7:31
We hear a lot of that false dichotomy being peddled here in Brussels as well. Very often, we hear innovation and robust governance or regulation being placed as two things that are completely at odds with each other. Very often, a big part of the conversation that's completely missed is the fact that businesses have a real interest and incentive in making sure that they have trustworthy products and that whatever they're developing is of interest, not just to individual consumers or people, but also to bigger entities that they're chasing after, for example, the public sector. So it's interesting to see that you're hearing the exact same thing across The Atlantic. Yeah. So, Laura, you work out of CDT's EU office. So what is going on there? How is that conversation translating into the regulatory and legislative side of things? So, interestingly, based on what you mentioned, we are in a different stage where we're not so much talking about private incentives for with governance, but more thinking about the rule setting and standard setting on AI. And here, we see three key emerging trends. So the first one and the biggest one is the implementation of the law and artificial intelligence in the EU, also known as the artificial intelligence act. It was adopted last year, but its implementation has staggered. Some of it's foreseen because the law itself sets different milestones over time for different things to come into force within the law. But but some of it has also been unforeseen on account of some of the pushback that we're seeing towards regulation. And this is quite unusual in that, typically, when European law is enacted, the focus is a 100% on implementing, and there is no discussion on whether or not the law is good or bad. Once it's set in stone, it's set in stone, and people move on to the next thing. But the AI Act experience has been quite peculiar in that there is several voices, mostly from industry, calling out the legislation as a whole and essentially pointing out things that should be removed or changed or even suspended pending further clarity on what obligations in the law should look like. So it's a bit of a pivotal moment, both in terms of what the implementation of the AI act looks like, but also in terms of the European Union's credibility on the global stage in terms of following through with the rules that they themselves set after several years of difficult negotiations. So it hasn't been a smooth road for the AI Act, and there's a lot of open questions at the moment as to whether key victories in the law, especially from a fundamental rights perspective, will be preserved. So this talk of simplification, of reopening aspects of the AI Act is getting a lot of traction, and, we're quite concerned to hear that this is something that has some credibility at least in some quarters
Speaker 1
7:32 – 7:47
of the European institutions. I know the the the code of practice that was part of the EUII act wrapped up and and some institutions have signed on, but can you what do you see that process moving forward? How do you see that process moving forward? The code of practice process was
Speaker 2
7:48 – 12:29
incredibly fraught, complex, but it was also the first of its time in that it brought together different stakeholders to try and sit down and agree on what should be the nitty gritty rules that general purpose AI model developers should follow in order to be considered to be complying with the AI Act. As a process, it was quite unique. And in the end, we ended up with a code of practice that was made up of, three chapters, notably, chapters on transparency, safety and security, and mitigations. And the conversation has now evolved from a place where we thought we were only going to have one code of practice ever to seeing the whole code of practice and the specific chapters within it as different texts that could be subject to change and amended in the future. So could be subject to evolution, and we're just the beginning in terms of setting down standards for future conversations on AI act implementation. That's been quite interesting from a civil society perspective because it's meant from the city to Europe side that we were involved in conversations and effectively negotiations with all sorts of people in the AI governance spectrum ranging from, well established academics to think tanks to industry representatives. And hearing what folks' different perspectives were in different issues and what were the red lines for people has been incredibly interesting. There has been another call for a code of practice, process, this time focusing on transparency obligations And whether or not that process will follow the structure of the first one is going to be a very interesting question to to dig in. It just goes to show what sort of dynamic approaches to policymaking around AI might be needed just because it's moving so quickly and the best practices are are evolving. So thanks for staying really plugged into that work. Thank you. And, I mean, we think that the multi stakeholder process is the is the best way forward. Having different folks in the room with, different areas of expertise and interest is really crucial to coming up with a framework that ultimately will be a compromise, but, ultimately, one that people can live with, including fundamental rights advocates such as ourselves. The second trend that we're seeing in the EU is a renewed effort to bet on AI as a technology of the future, which will fulfill the promise of European competitiveness. So we're seeing a lot of investment in the AI industry, a lot of new infrastructure being created and supported. And we perhaps got the first teaser about it during the French AI summit where European commissioner, president Ursula von der Leyen identified supercomputers, public supercomputers specifically as a core strength of the EU and announced a €10,000,000,000 investment in them. And that was going to be just the beginning of the EU's, latest foray into investing in AI adoption and AI development. Very recently, we saw the release of the apply AI AI strategy, which is a road map that brings together the different strategies that the European Union is thinking of developing in order to make sure that they're making the most of AI as a technology. And they were very explicit in that document where they said that they were going to apply an AI first approach. So it's a change of tune in terms of the conversation that was happening a few years ago when the AI act was being negotiated, and there was a dual track thinking around it. On the one hand, the risks and and the safety mitigations needed, and on the other hand, the need to enable, at least to some extent, some level of AI development and AI growth. Now the conversation is very much focused on the latter. And perhaps the third and and final theme that we're seeing emerging is AI as strategic technology for the European Union in terms of sovereignty and independence. There's been a growing realization, by EU policy makers that there is a strong reliance on critical materials, coming both from The United States and China that is increasingly proving unacceptable to several quarters, in the EU institutions. And so the AI conversation has been recast as a strategic critical conversation for the EU in in the months to to come forward. And very crucially, AI has been identified as a core technology for defense. And the strategy that I was just mentioning on applying AI, again, reiterates this and the promise that AI has to make a key difference for the EU,
Speaker 1
12:30 – 12:36
in the military field. And we're seeing the same thing over here and also around the world. It's really concerning that a technology
Speaker 2
12:36 – 13:53
like this is really being normalized in the defense conversation and more importantly in the war theater. But, unfortunately, it seems that's a trend here that's here to stay. And we're seeing a lot of, presence from, industry that is involved in the defense field settling, in Brussels or growing expanding their teams. So it it will be a key part of the equation, for civil society organizations going forward. If there was ever a time that human rights were important, it seems like it's now. This is it. This is it. And people shouldn't shy away from engaging with militarization topics, securitization conversations. Even if they're not always part of the traditional fundamental rights wheelhouse, now is certainly the time to start looking into that and seeing what the strategies that governments are are thinking about are. Because very often, the technologies that tend to be the most, intrusive or infringing of fundamental rights start in the defense area. So this is this is just the beginning. Miranda, part of your work is following how AI is being created and sold in new ways. And we're hearing a lot about agents. Could you tell us a little bit more about what they are and how they operate? Yeah. Oh, man. AI agents.
Speaker 1
13:53 – 15:29
They are all the rage these days. But, you know, we were doing a scan of the field, and it really seems that often people don't really know what they mean by AI agent, or that they're just leveraging that term for hype for marketing because that's the term of the day. A useful way of thinking about AI agents are AI systems that can set goals and act autonomously towards those goals. They're usually relying on so called reasoning, to work through plans and, take steps towards those goals. So creating kind of step by step, processes of of things they'll do, whether that's searching the Internet, sending emails, accessing databases or tools, or whatever is necessary to accomplish the task. But a simpler way to think about it, that I like to use is that agents are basically just automated decisions wrapped in language models. We've been concerned about this for a long time. The fact that the terminology has changed is creating the conditions where people are starting conversations from scratch that actually we've thought quite a bit about. So I think that's something that we really need to double down on. And they're not exactly the same as the ADM systems that we've been talking about. They might be making slightly more complex decisions. They might be, engaging in, plans over a period of time. But they raised this really similar questions. Like, do we know that the systems exist? Where are they deployed? What are they doing? What are they deciding? What sort of oversight is needed? And do people even know if they're being affected by the behavior of these systems?
Speaker 2
15:29 – 15:53
Language is so important when it comes to this conversation. And often, I think it is either used deliberately or even weaponized to keep some levels of expertise outside of the room. And then, in fact, it turns out that the many things that we should be worried about are very traditional concerns that have been emerging around technology for a very long time. And at the same time, sometimes a new frame can actually
Speaker 1
15:54 – 17:40
reopen the possibility of engaging on a topic. So, it's definitely two sides of the coin, but, you know, it's at the moment, this reframing has been a bit challenging because AI agents overall represent a spectrum of different tools, and some of them actually look more similar to chatbots. And so it can be difficult to tease apart what systems we're actually talking about. So a chatbot that has access to the web, is often thought of as an agent because it can take a user prompt, turn it into a plan, conduct search queries, retrieve information, summarize that information, and it all feels like interacting with the chatbot, but it's actually doing a more complex thing on the back end. That's not quite the same as a system that's, comparing a circumstance to a set of guidance or rules and making a determination about someone or making a transaction, which might also be called an AI agent. So I know there are active conversations around how to define these systems that policymakers are already starting to think about, And that'll be tricky because it's a pretty big umbrella at the moment, and and there's a wide range of types of behavior that we might see from these systems. And that's kind of what the people developing them mean to do. They're trying to build general purpose assistance and tools that can act on people's behalf. And intrinsic to that is a lot of ambiguity around what that means. So this is gonna be something that we're watching for sure. But I think the main thing to remember is that even if it sounds new, a lot of these issues are actually similar, and we shouldn't start from a blank page every time. There's so much insight that advocates and researchers have brought to conversations around AI systems, automated decision systems for years now that can really serve as a foundation for these conversations.
Speaker 2
17:41 – 18:46
What you're saying right now is really bringing to the fore for me many of the conversations that were had in the context of the AI act being negotiated and even during the implementation and the code of practice process under non purpose a models where the generality of a particular artifact or model was almost seen as being fundamentally in a position to the idea of regulating that particular model because of the variety of potential use cases of context of deployment. And this was a strategy that was very often used to say, well, if somebody else gets to run with this and do whatever they like with it, then why should we, as the developers, be responsible for any of the consequences? Or why should we be casting our minds into the future and try to imagine every possible reasonably foreseeable risk that could attach to a product like this? And it was a real challenge because this is a new type of technology. And while we've had new technology for a long time, some aspects of the generality that can be inherent to some of these advanced models are really tricky to grapple with in terms of regulation.
Speaker 1
18:46 – 19:07
Yeah. One of those challenges is really who should be responsible when something happens in one of those downstream uses. And I know earlier this year, the commit the EU Commission shelved a legislative proposal that had rules around AI liabilities. So what's playing out there? What are the what are the current conversations on liability? There was a lot happening,
Speaker 2
19:07 – 22:46
earlier this year on that. So, to maybe go back in time a little, from the very beginning that the commission started thinking about regulating AI as a whole, they were also thinking about specific liability rules for AI systems and potentially even AI models. So the AI act as a proposal emerged with a sister proposal that was strictly about AI liability. And the liability proposal stalled in parliament for a very long time until the final text of the AI act was agreed, which at the time was a decision that made sense considering that a lot of the content of the liability proposal would ultimately be influenced or decided by the text of the AI act itself. And earlier this year, during the French GA summit, the commission officially pulled the proposal, as you mentioned, officially owing to a lack of consensus or agreement between member states. And the liability law wasn't the only one to be pulled. There were several others that were cut at that time, but it certainly sent a very clear signal that the time for regulation in the EU, at least when it came to AI, was done. And at the moment, when it comes to the AI agents conversation, there's a lot of enthusiasm, but there is also a lot of unanswered questions. The AI act doesn't explicitly address them, and there's a lot of theory and discussion about how they would be regulated. Increasingly, the consensus is that at least commercially available AI agents will both be an AI system on the one hand and a general purpose AM model on the other hand. So they will, in fact, be what is known as a general purpose AI system put together, and that has a lot of implications in terms of what obligations attached to providers and how they're ultimately governed. So the taxonomy here will matter a lot, and there are still a lot of open questions as to what the ultimate definition of these AI agents, at least in EU law, will be. The liability question also needs quite a bit of unpacking. Since the AI liability law was shelved, there is no dedicated proposal or live legislative instrument that will specifically look at liability in the context of AI. What we do have, however, is general product liability rules, which recently what underwent their review process and were revamped to be more adapted to the digital age. And they cover AI, or at least that's the the product they're sending that we also share. But it's not tailor made for AI, and so there will be a few challenges there in terms of how the law grapples with some of the challenges that are simply inherent to AI, including opacity and and complexity. So how different actors in the AI supply chain map out to onto existing liability taxonomies in EU law, which remains very manufacturer focused, that's going to be quite an interesting question. And when it comes to agents, the challenge is only exacerbated because it's very difficult to trace harm to specific actors, specifically when it comes to multi agent systems and delegation of tasks. So this is gonna require a lot of intellectual flexibility, and, ultimately, a lot of research and legal discussion to try and figure out whether or not these systems are even subject to liability. And if so, how? It will definitely raise questions of human oversight, human in the loop.
Speaker 1
22:47 – 23:54
But I know researchers are concerned that just putting a human in the loop in these systems won't necessarily provide the oversight that would be necessary because they might be subject to automation bias. They might be overwhelmed with the number of, examples they're being given to review, and end up deferring to to an AI system. And then, ultimately, they're just there as a liability sponge, and that wouldn't actually necessarily lead to the accountability people would like. And so really thinking about what would it mean to have meaningful oversight of these systems, especially if that is going to pertain to questions of liability. We'll be curious to see how that plays out. Well, it sounds like there are both ongoing conversations to try and grapple with new types of technology and systems, but also this pulling back, and attempts to, you know, simplify and and, leave room for for the strategic deployment of this technology. So those seem like there's somewhat intention, and and we'll definitely look to, you guys to to keep us all apprised of what's going on in the EU.
Speaker 2
23:55 – 24:07
So, Miranda, let's now turn to privacy. The conversation in the last few years has been about privacy and copyright implications of massive training datasets to create advanced AI models.
Speaker 1
24:08 – 28:51
Where are we at right now? Yeah. You're right. So much of the attention over the last few years has been about the training datasets, these massive datasets scraped from the Internet and and elsewhere to really build these frontier AI models. But from my perspective, this is too narrow a focus, for a couple of reasons. So the first is that AI developers for some time have been focused on scaling their foundation models, so including more and more data, using more and more computational power to increase the capabilities of these models. But that's not actually how the development is playing out at the technical level. That was a focus for a long time, but, increasingly, there's an additional focus on using computational power and data to fine tune systems and to use inference. Right? So, basically, letting the AI models think more, so to speak, before they produce an output, which is adding a lot of capability to models without requiring tons and tons more training data. So that raises a lot of questions around, you know, just what do we think about the relationship between training data, training compute, and systemic, risk or other types of harms from foundation models. But the more interesting thing that I've been thinking about quite a lot recently is that it used to be the case that these models were deployed, anyone could use them, and they behaved sort of similarly no matter who was interacting with them. You know, there's some inherent randomness to the way foundation models, operate. But on the whole, they're generally acting in the the same way no matter which user was interacting. But recently, in the last year or so, a lot of the key players have been introducing new features to their tools. They are introducing the ability for the system to reference their chat history or to personalize the experience in other ways. Because what they're saying is there's a lot of user demand for that, that people would like the systems to respond in a way that's pertinent to their particular circumstances. This is another place where we're seeing this sort of rhetorical slipperiness because what we used to think of as personalization is now being called memory and, you know, thinking about AI memory. And it's as if it's a whole new conversation, but so much is is actually the same as what we've been thinking about on the consumer Internet and, digital apps, and and questions around, do people understand what data is being retained and how it's being used to shape people's experiences? And it's just so clear that the introduction of memory or personalization can lead to the exact same harms that we've seen in other products and recommender systems, like filter bubbles, discrimination, exploitation. And the problem is that users find it appealing, so it's likely they'll opt in. So we can't really rely on consent as the safeguard here. We have to think about what are the other safeguards that are needed as as these companies are creating what they're thinking of as data flywheels, where users are interacting more and more with their products, which generate more data that the companies can use to further train and fine tune their models, but also enable these personalized experiences, which will really change how we think about what the issues for advanced AI really are. Because in addition to the privacy implications, which I think you and I are quite familiar with, this is actually really disruptive to the way we evaluate risks of AI at a technical level, so evaluations. You know, many of the technical evaluations and benchmarks that researchers are using to understand these frontier models are static. They're they're trying to measure particular capabilities or characteristics of the models themselves, But these models are being incorporated into these broader systems. And once you add a personalization layer, they're actually behaving differently across these different contexts, which makes it so, so hard to to research them. And this is, again, a challenge that we've seen in other domains. So researcher access to platform data is something that we've grappled with, and we're gonna grapple with it again. But I think even researchers haven't fully updated their paradigm of how they understand what it is they even need to measure about a system to understand its behavior and harms. And so this is just the tip of the iceberg because these products are pretty new. What you say
Speaker 2
28:52 – 29:37
is incredibly concerning in that we've also seen that memory is being sold as a feature, not a bug. So the days of outrage back when the Cambridge Analytica scandal happened where the extent of micro targeting of people in terms of political advertising on social media platforms was revealed, That seems to have now been forgotten completely by the folks who are trying to to sell this this technology and these different elements that might make it, in their view, more user friendly and for which there might actually be a demand. And that is a real question. To what extent will consumers, everyday people decide to activate these features and derive any real benefit from them? I think the companies are framing these features as
Speaker 1
29:38 – 30:55
really useful additions to tools that will work on behalf of users that they can use as assistants and agents to achieve their own goals, which is all well and good. But we're also, at the same time, seeing many of these companies introduce third party apps, you know, shopping features, product recommendations. And it's just so easy to see how this will lead to a very similar situation as what you were talking about of how might all of the data that these companies will ultimately have, how might that end up being misused either by those companies or by third parties or by honestly, some researchers even are concerned that the models themselves will misuse them somehow, which is, you know, a new dimension of of concern here. But, you know, all all of that is going to be amplified by by the addition of personalization. Absolutely. And, Laura, we know in in Europe that GDPR has become a lightning rod in the context of AI training and development, and it is gonna be even more salient, thinking about this, you know, personalization, layer. So how has GDPR stood the test of time, and what relevance do you see it having for some of these changes that we're seeing in AI systems, personalization, more advanced more advanced models?
Speaker 2
30:55 – 32:42
So our EU, data protection law, also known as general data protection regulation, or for those of us more familiar, with it, more affectionately known as the GDPR, has been the crosshairs, for quite a long time. And something that people tend to forget when having this conversation is that in reality, data protection did not come about with GDPR. It is a fundamental right that can be found in the Charter of Fundamental Rights of the European Union, which is a regional, fundamental rights law or human rights law. And it's also found in the treaty on the functioning of the European Union, which is one of the foundational treaties, that came to build the EU as such and as we know it today. So very often, that the of the GDPR will focus on the GDPR as the source of all evil, forgetting that the GDPR is merely the operationalization of the fundamental right to data protection. And they seem to think that you can have that right unaffected without GDPR, but there have been many verse versions of what is now known as GDPR in the past. GDPR is just the latest currently valid iteration. So I always try to remind people of that when they start going on a rant against GDPR because of the many, many obligations that it imposes on different folks in the data pipeline. I'm always telling the people that complain that, actually, we're very happy to have GDPR here. And if we're unhappy with the core purpose, the core mission of GDPR, then we're saying we're unhappy with the level of fundamental rights guaranteed in the European Union. And that's a completely different conversation, but the two are inter related. So it's always useful to recall that. Going back
Speaker 1
32:42 – 33:17
to the conversation we were having earlier about how companies will take on risk, and you need to really change their risk calculus. I think GDPR was able to do that more than other laws because of the fines it imposed, basically, for for lack of compliance. They're really compelling, and that really does get companies to think differently. So it might impose a cost on them doing business, but at the same time, if that requires them to build the right infrastructure, be more thoughtful about how they're using user data, that's probably worth it. And it's an interesting model to think about moving forward. It has been such a useful tool
Speaker 2
33:17 – 40:38
for civil society and just people more generally, whether or not they have an interest in data protection law or not. Because the core victory that the GDPR has is give people way more agency about the way their data is handled in the digital age and more control. So the GDPR will give you, avenues to directly interact with the entities that are processing your data, ask them for information, ask them for access to your data, ask for restrictions of processing of your data. So allow consent for one use, but then object to another use. But at the same time, it also gives you a few avenues to complain to different authorities that exist that you known as data protection authorities if you feel that your rights haven't been respected or that the GDPR as a whole has been infringed. And it lastly gives you access to judicial avenues as well, which is, an aspect of the GDPR enforcement that we don't often talk about because of how costly it is and daunting it can be for both civil society folks, but also regular people. But it's there. And so if somebody considers that their rights in their GDPR have been infringed and they've suffered some level of harm, they can go to court and they can ask for compensation. And as you rightly mentioned, companies now have to factor that in in terms of their compliance cost, which is one way of having to think proactively about what they should be doing to to avoid these certifies. But when it comes to GDPR, it really wasn't created with, AI as such in mind, but it did foresee the challenges that new technologies would bring to the protection and enforcement of fundamental rights. For example, the lack of transparency involved in some of these processing activities, the many hands problem, the the diversity and number of actors that could be involved in any given processing operation, and also the mass use of of data and profiling down to the most intimate, intricate, unexpected personal characteristics. So in that sense, the GDPR was always built to be future proof, and it has to the test of time whether people like it or not. And it's a conversation that we've been repeatedly having, unfortunately, when it comes to the AI context. So there's several implications on AI, when it comes to data protection law. So one consideration, for example, is the extent and sensitivity of personal data that's fed into a model, but also going into automated decision making territory, as you were mentioning, the extent to which outputs can be used to take decisions on a person's life with next to no human oversight or control. And, also, when it comes to large language models or generative AI, the role of personal data is even more complex For a while in the EU, there was an ongoing debate as to whether even models could process personal data in the traditional sense. That debate was fortunately resolved by the EU data protection regulator that sits above all member states, And they answered that question in the affirmative. They said, yes. A model can absolutely process personal data if they can, for example, regurgitate information or personal data can be extracted from the model, and that's subject to a threshold of effort level needed to be able to extract the data to have it regurgitated. But for a while, we even saw data protection authorities arguing that the way that models work meant inherently that they couldn't be processing data in the traditional sense. Enormous implications for data protection law so as to make it irrelevant in the age of AI. And we're very happy that that opinion, didn't fly and that we got some very, decisive arguments in favor of models being subject to data protection law, basically. It was a really laughable analysis. It was. And the fact that it was coming from a data protection authority was all the more puzzling. But for a while, it seemed that this was a plausible line of argument or at least a line of argument that could be successful. And it was a very scary time. So we're very happy to have had it confirmed that, no. Indeed, models can process personal data. And, of course, with models, the challenge is you can't be sure at any given time that a model won't regurgitate personal data ever again no matter how many attacks are thrown at it or strategies are developed to try and make personal data essentially extractable. The one caveat is that it's all based on training data. So European data protection law, when it thinks about, how models process personal data, they will be thinking about how training data is extracted. But the personal data in question needs to have been in the training data to begin with, which is an interesting nuance, that, that I'm sure we'll see tested through the courts. But more generally, there's a lot of relevance to data protection law even in in traditional settings or in the traditional sense when it comes to personalization, which as we've discussed is not new and frankly is not at odds with data protection. So something that we were often at pains to demystify is this notion that data protection prevents all sorts of processing of personal data. I mean, the simplest, easiest legal basis to have under GDPR when it comes to processing of personal data is consent. If you can get someone to consent within the terms of the meeting of consent, set in data protection law, you're fine. And that is honestly the best way we think for any technology, to to lawfully process personal data. Because otherwise, you're getting into more uncertain territory of what the legal basis is. Is it because the commercial interest that the entity has enables them to use this particular type of data? Is it because there's another, legal basis in national law for the entity to perform a public task that legitimizes this use of data? All of these questions can be really thorny and really intricate. So really with consent, you're just taking those concerns out of the window, and you're making it much easier on yourself if you are an entity that processes things. But there's challenges at the same time. So for example, under GDPR for consent to be valid, it needs to be specific, informed, and explicit among many other objectives that I'm not mentioning here to make, the audience's life easier. But this means that for the consent to be valid, you need to fulfill a lot of requirements that are very rarely fulfilled in their entirety. And so it's unclear if even if a person were to give consent, whether the model, for example, would be able to observe the scope of the consent that was given. For instance, if you gave an instruction that I want you to process information that I'm a vegetarian specifically for the purposes of looking up restaurants in the neighborhood, we can't be sure that that information will be used for anything else. And in fact, I I don't know that this option to restrict the type of personal data that is processed about a person is even available. I mean, either it's memorized or it's not. But I don't know that there is a sort of gradation of types of purposes that you could use it or not use it for. We just had a workshop with with experts talking about that exact topic,
Speaker 1
40:39 – 41:04
and one of the main takeaways was there are so many places where there are going to be expectations or requirements to segment data to only be allowed to be used in certain circumstances. And developers of AI really need to be building the systems to accommodate for that. And some of the ways that they might go about enabling personalization won't have that confidence and are gonna be much more of a mess of data all mushed together,
Speaker 2
41:05 – 43:19
which wouldn't be compatible with these legal frameworks or expectations, it sounds like. Absolutely. Because when you have so much information or so many personal characteristics together, then it's difficult to know whether any particular recommendation or output is being received because it corresponds to this distinct type of data or data category, for instance, dietary preferences, or whether it's a result of these different memories or personal attributes or traits that you've fed into the model over time. And so it it becomes more than just the sum of the parts. It becomes something else entirely. And from a data subject agency perspective, that's a nightmare because then it's really hard to exercise consent in respect of each of these different elements. And this brings me to the question of data subject rights. The whole premise of data protection law is, yes, you can process the data so long as you have the legal basis that allows you to do it lawfully. But at the same time, you need to be able to comply with a full range of data subject rights. Some of which are conditional, but some others are absolute. So this will mean that if a model is processing personal data, for example, they will need to be able to guarantee that they can fulfill data subject rights, such as restriction of processing, which I mentioned, or access information, so access to the full range of personal data held by the model and the purposes for which it is used. And this is going to be incredibly difficult to fulfill satisfactorily, at least to the standard of the GDPR. And there are real questions at the moment as to whether this is even possible, whether a model is even susceptible of having achieving this high level of compliance. So, I mean, where we're landing and where many privacy advocates are landing in this conversation is increasingly viewing AI, as a normal technology and basically not falling into the trap of AI exceptionalism when it comes to data protection compliance. So instead of making data protection fit the reality of AI, really what we're thinking about is how do we do we make AI fit the reality of data protection law as it is and has been developed over years, even decades, based on core rights that were foundational
Speaker 1
43:19 – 44:43
to the EU as a block. And that's a difficult conversation to have in the current climate because many people would like it to be the other way around. It's just such a good reminder that this is not a new conversation. We've been having this conversation for years and decades, and there's always something new to think about. But going back to fundamental rights seems like a good way to go of this is the foundation we should be building on, and we want technology to serve that, not to challenge it. And how do we build that technology in a way that allows us all to have our rights respected while also advancing the frontier of technology and enabling interesting and helpful and, really amazing sometimes new experiences. And I think like we said at the beginning, those can go hand in hand. But if we rush to doing it and we don't do it carefully, then I think there's gonna be a lot of backlash against the technology, and that's not gonna serve anyone. So, you know, thank you for helping remind us why, this is a conversation that we need to continue to have and pulling on those that expertise from from these other related topics, even if the tech looks different now, is just the most important thing. So, it's so good to talk to you about this. This is so fun, and thanks. Thank you, Miranda, for keeping us so grounded and centered and basically,
Speaker 2
44:44 – 44:48
conscious of the different narratives that are taking place and how we should not get duped.
Speaker 0
44:49 – 45:10
That's it for today's episode of Tech Talks. Check out more of Sidity's work by visiting us online at sedity.org and cdt.orgeu. You can also find us on various social media at sendemtech, that's c e n d e m tech, and CEDT EU. Thanks for listening, and see you next time.