The role of data protection authorities in the enforcement regime concerning the general-purpose artificial intelligence in the AI ACT
DOI:
https://doi.org/10.13135/2785-7867/13848Keywords:
Data protection, Independent Authorities, Generative AI, Artificial Intelligence, AI ActAbstract
The General-Purpose Artificial Intelligence (GPAI) poses challenges to data protection rules, including the legality of training data, compliance with the purpose limitation principle, transparency of data processing, and data subject rights. This article analyses the extent to which the AI Act addresses these challenges by incorporating Data Protection Authorities (DPAs) into its enforcement regime. For the purposes of this article, 'enforcement' refers to institutional and procedural measures aimed at ensuring the execution of legal obligations. I consider the extent to which the AI Act permits the involvement of DPAs in its enforcement regime with regard to GPAI models and systems to be a proxy for assessing the extent to which the AI Act can address data protection-related challenges of GPAI. As DPAs are experts in data protection and have the power to enforce data protection rules, their involvement in enforcing the AI Act could ensure that it is aligned with EU data protection law. Therefore, measures that facilitate the involvement of DPAs are considered supportive in addressing the challenges to data protection posed by GPAI, while measures that hinder the intervention of DPAs are considered detrimental. In order to provide an insight into these issues, the article is structured as follows: firstly, it introduces the relevant definitions under the AI Act. Next, it presents the main features of the enforcement regime of the AI Act in relation to the GPAI. Then, what constitutes the backbone of the analysis presented in this text, I describe those elements of this regulation that relate to possible involvement of the DPAs in the AI Act’s in relation to the GPAI. This analysis indicates that the impact of the AI Act on the enforcement of the GDPR should not adversely affect the tasks, powers or competences of DPAs under data protection law. Regarding the granting of new powers to DPAs, the analysis shows that DPAs' role in enforcing the AI Act's provisions on AI systems largely depends on Member States' decisions regarding their enforcement regimes. However, with regard to GPAI models and systems, the enforcement regime relies primarily on the AI Office, that is the Commission, and, to a limited extent, on the market surveillance authorities designated by the Member States. While some DPAs may carry on or begin to play an active role in enforcement with regard to GPAI models and systems in relation to data protection law infringements, there are no provisions in the AI Act that would directly ensure communication between DPAs and the AI Office regarding the initiation of proceedings concerning GPAI models and systems. This suggests that the AI Act could include more specific measures to address the enforcement of data protection challenges concerning GPAI. One possible solution to this challenge would be to establish a mandatory notification procedure for the DPAs and the AI Office in cases concerning GPAI systems and models. This would encourage collaboration between the DPAs and the AI Office, particularly if the DPAs are not designated as market surveillance authorities. It could also prevent inconsistent decisions being made by enforcers under the GDPR and the AI Act. In the absence of more specific measures, cooperation may depend heavily on the application of the principle of sincere cooperation and its interpretation by the Court of Justice of the European Union.


The Journal of Law, Market & Innovation is indexed in 
The Journal of Law, Market & Innovation is indexed in