Copy article

Reuters - AI industry and legal compliance

ended 19. May 2023

Reuters is publishing a story on the relationship between AI companies and regulators.

It will take years for laws specifically targeting AI to come into force -- for now, regulators are relying on existing laws (on privacy, copyright, discrimination) to police the technology.

Regulators like the FCA, the ICO, CNIL in France, and Garante in Italy, are policing ChatGPT and others by re-interpreting and applying old laws to emerging technologies.

They have spoken to regulators about how they are working through these issues. They would like quotes from industry representatives on the challenges of legal compliance. Things they are particularly interested in include:

1. How difficult is it for AI companies to comply with GDPR and other rules, when regulators are actively re-interpreting them to keep up with the technology?

2. How much dialogue is there between companies and regulators to avoid future issues?

3. How difficult is it for smaller AI startups to maintain compliance, compared to the army of lawyers at Google or Microsoft's disposal?
 

2 responses from the Newspage community

Copy all

Copy

1. AI companies need good data governance from the outset, to comply with the likes of GDPR, HIPPA or anything else exposing personal information (PII) the focus on data anonymisation is high. This could be in the form of using synthetic data to replace real personal information. With large language models like ChatGPT then developers need to know the true source of the information to know what kinds of anonymisation would be required for the country's respective privacy framework.


2. There needs to be healthy dialogue but we are talking about many companies that it may be impossible to do sensibly. With some AI companies asking for forgiveness than permission seems to be the model where data is concerned.

3. Startups need to embrace "doing the right thing" with AI from the inception of the model. This could be to their advantage against the larger organisations.
Copy

The main concern for data breach solicitors, Hayes Connor (hayesconnor.co.uk), is how Large Language Models (LLMs) integrate and retrieve data for training purposes, which could then be repeated to users later down the line. For instance, if a law professional had entered confidential client information into the chatbot for an admin task, might ChatGPT provide this information to another user later on, if they ask about said client?

With employees negligently submitting sensitive corporate data to the chatbot, the impact is currently untold. I am apprehensive that a considerable proportion of the population lacks a clear understanding of how generative AI, such as ChatGPT, operates. This situation could lead to the inadvertent disclosure of private information, and therefore a breach of GDPR.

As such, the responsibility doesn't just lie with AI providers; it is the onus of businesses to implement compliance/training measures to ensure employees in all sectors are remaining compliant.