This Chapter explores the idea of axiological congruency between (ethical) values and the EU law on new technologies, with a focus on the ‘normative kinship’ between the GDPR and the AI Act. Such a comparative analysis is appropriate considering that the GDPR provided the ‘normative template’ for the design of the AI Act, as the recently enacted, ambitious, horizontal regulation, seeking to foster progress by ‘engineering’ trust in AI, while at the same time upholding a high standard of fundamental rights protection. Tracing the inception of the AI Act to the HLEG’s Guidelines, this Chapter argues that the four principles of ethics (respect of human autonomy, avoidance of harm, fairness and explicability) are axiologically rooted in the principle of human dignity, given that the fundamental threat of AI systems is that of ‘moral opacity’—a feature of highly complex automated processes which are often hidden from view for the average user. By seeking to safeguard human autonomy and agency (as key expressions of human dignity), the AI Act is ‘axiologically congruent’ with the GDPR, which also pursues the same goal through safeguards meant to shield off threats coming from various forms of personal data processing. Based on values similar to those underlying the GDPR, the AI Act nevertheless departs from the latter, in the way in which it translates values into law. As an admittedly risk-regulating instrument, it follows a logic of product safety, and is designed on the assumption that a high standard of fundamental rights protection can be achieved through technical safety standards, in particular those applied to the so-called high-risk systems. In assuming this, the AI Act is open to criticism, because it places the burden of fundamental rights protection primarily—though not exclusively—on market operators who are presumed to understand those standards and apply them correctly. For example, transparency, combined with human oversight, is, without question, an important principle (and standard) to apply, but its technical feasibility (i.e., actually programming AI systems where human oversight is possible throughout their life cycles) might not be as feasible as the AI Act assumes it will be. The Chapter concludes that the implementation of the AI Act and the case law that will emerge in connection to it will bring important insight on whether the approach of ‘standardizing values’ for the purpose of protecting fundamental rights was, indeed, the adequate regulatory route to take, in lieu of that—showcased by the GDPR—of protecting fundamental rights by creating individual entitlements.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

The Ontological Congruency in the EU’s Data Protection and Data Processing Legislation: The (Formally) Risk-Based and (Actually) Value/Rights-Oriented Method of Regulation in the AI Act

  • Ljupcho Grozdanovski

摘要

This Chapter explores the idea of axiological congruency between (ethical) values and the EU law on new technologies, with a focus on the ‘normative kinship’ between the GDPR and the AI Act. Such a comparative analysis is appropriate considering that the GDPR provided the ‘normative template’ for the design of the AI Act, as the recently enacted, ambitious, horizontal regulation, seeking to foster progress by ‘engineering’ trust in AI, while at the same time upholding a high standard of fundamental rights protection. Tracing the inception of the AI Act to the HLEG’s Guidelines, this Chapter argues that the four principles of ethics (respect of human autonomy, avoidance of harm, fairness and explicability) are axiologically rooted in the principle of human dignity, given that the fundamental threat of AI systems is that of ‘moral opacity’—a feature of highly complex automated processes which are often hidden from view for the average user. By seeking to safeguard human autonomy and agency (as key expressions of human dignity), the AI Act is ‘axiologically congruent’ with the GDPR, which also pursues the same goal through safeguards meant to shield off threats coming from various forms of personal data processing. Based on values similar to those underlying the GDPR, the AI Act nevertheless departs from the latter, in the way in which it translates values into law. As an admittedly risk-regulating instrument, it follows a logic of product safety, and is designed on the assumption that a high standard of fundamental rights protection can be achieved through technical safety standards, in particular those applied to the so-called high-risk systems. In assuming this, the AI Act is open to criticism, because it places the burden of fundamental rights protection primarily—though not exclusively—on market operators who are presumed to understand those standards and apply them correctly. For example, transparency, combined with human oversight, is, without question, an important principle (and standard) to apply, but its technical feasibility (i.e., actually programming AI systems where human oversight is possible throughout their life cycles) might not be as feasible as the AI Act assumes it will be. The Chapter concludes that the implementation of the AI Act and the case law that will emerge in connection to it will bring important insight on whether the approach of ‘standardizing values’ for the purpose of protecting fundamental rights was, indeed, the adequate regulatory route to take, in lieu of that—showcased by the GDPR—of protecting fundamental rights by creating individual entitlements.