A significant challenge of Gen AI is its potential to produce bias or discriminatory outputs. Gen AI is prone to hallucinations and can generate false or misleading information that could harm consumers. In a legal context, questions may arise regarding the degree to which a person relies on information provided by Gen AI. These ethical dilemmas must be addressed to ensure that Gen AI is used to better society without infringing upon privacy, security, or cultural norms.
Legal developments
The rapid rise of Gen AI has also impacted legislative debates on the EU Artificial Intelligence Act (AI Act), which aims to regulate the development and use of AI in the European Union. The European Parliament substantially amended the European Commission’s initial proposal, notably introducing specific rules that apply to Gen AI systems. In particular, providers of Gen AI systems will have to train, design and develop the system in such a way that there are state-of-the-art safeguards against the generation of content in breach of EU laws. Providers must also document and provide a publicly available detailed summary of the use of copyrighted training data and comply with stronger transparency obligations.
Given the significant advances made by Gen AI and its potential impact on society, EU legislators are evidently pushing towards placing stringent requirements for those operating such AI systems. As a result, organizations deploying Gen AI must ensure that they comply with relevant regulations and guidelines, specifically those related to AI and data protection.
What can your organization do to prepare?
As the technological landscape evolves, so too does the regulatory environment. For many organizations, this rapid change poses a challenge in terms of in-house capacity and expertise. Against this background, it can be helpful to work with an external provider for a status quo analysis or ongoing support. Some steps you may consider include:
- Arrange a health check to identify general compliance gaps relating to the use of Gen AI and get recommendations on remedial actions.
- Seek expert regulatory advice on the compliant use of Gen AI in consideration of requirements issued by financial regulators.
- Have your draft AI policies and processes reviewed, carry out product risk assessments and get guidance to ensure compliance with legal and ethical requirements.
- Ensure you understand how to carry out the data protection impact assessments (DPIAs) relevant for your organization’s use of Gen AI to ensure compliance with applicable data protection legislation.
Acknowledgement
We kindly thank Cathy O’Neill for her valuable contribution to this article.