Security Requirements for Fully Automated AI Systems to Exercise and Ensure the Rights of Data Subjects
Junhyung Park, Gunsang You, Yeontae Ji, Heung Youl Youm · 2024
As the commercialization of AI has increased, various services using it are being provided, and it is approaching our lives relatively closely. Humans used the results presented by the AI system to make human decisions. However, systems are also being developed in which artificial intelligence makes all decisions without human decision-making and systems that process personal data within these systems. Various personal information threats can occur in AI systems that process personal information, and each country is making efforts to encourage the safe use of AI by enacting AI guidelines and laws to protect personal information. Recently, in Korea, the Personal Information Protection Act was revised to establish procedures for exercising data subjects' rights regarding fully automated decisions using artificial intelligence. This is to guarantee the rights of data subjects, such as viewing and correction of personal information in the general personal information processing process, as well as the rights of data subjects in fully automated systems that process personal information. Therefore, in this paper, we aim to contribute to ensuring the rights of information subjects by identifying security threats that violate the rights of information subjects in fully automated systems by the AI system stage and analyzing the requirements to mitigate them.