Training of AI Systems

Paul Vogel · 2024

This chapter discusses how the training of artificial intelligence (AI) systems can be designed in a way compliant with the General Data Protection Regulation (GDPR). As with every training (and use) of AI systems, there is a processing of huge amounts of data involved, making it highly likely that these data also include personal data. Thus, the GDPR applies. As these provide for a transparent processing of as few personal data as possible, the data protection principles set forth by the GDPR seem to conflict with the characteristics of (some) AI applications. Using the example of a right to explanation for algorithmic decisions, this chapter will demonstrate that the GDPR’s risk-based approach enables developers and users of AI systems to comply with the (sometimes strict) requirements of the GDPR. The chapter will come to the conclusion that the combination of the GDPR’s one-size-fits-all and risk-based approaches do – from a data protection law perspective – generally allow for a balance between enabling innovation in the field of AI while also protecting the rights of natural persons affected by AI.

Read the paper · More papers on PaperTik