Should data protection authorities enforce the <i>AI Act</i> ? Lessons from EU-wide enforcement data
Notice bibliographique
Résumé
Most Artificial Intelligence (AI) systems involve some form of personal data processing, yet the role of Data Protection Authorities (DPAs) in enforcing the AI Act remains critically undefined. This article empirically investigates current DPAs’ role in enforcing regulations concerning AI-driven services and automated decision-making (ADM) systems to assess their suitability for enforcing the AI Act. Drawing on a dataset covering DPA activities relating to AI in all European Union Member States, we analyse multiple indicators as proxies for their activity level concerning enforcement associated with AI and ADM. Our findings suggest that, although many DPAs have some experience with AI-related enforcement, their activity level in this area varies significantly. Combining these results with a legal analysis of the AI Act’s provisions, we argue that, despite being heterogeneous, the expertise developed by DPAs represents a valuable resource for effectively enforcing the AI Act. Artificial Intelligence (AI) technologies often rely on processing personal data. However, the role of Data Protection Authorities (DPAs) within the enforcement model of the AI Act1 remains unclear. This article investigates how actively DPAs currently enforce data protection rules in cases concerning AI-based products and services and automated decision-making (ADM) systems. It is crucial to scrutinize this issue given the AI Act’s substantive scope, which covers specific ADM systems, and the institutional solutions it foresees, which might require the involvement of the DPAs in certain enforcement aspects. Drawing on evidence from documented DPA activities across EU Member States, we develop an index to quantify their activity level, identifying concrete ways they could contribute to effectively enforcing the AI Act. Our analysis addresses explicitly three key research questions: two descriptive (1 and 2) and one prescriptive (3): What role does the AI Act assign to DPAs within its enforcement model? What is the current DPA’s activity level concerning AI-driven products or services and ADM systems? Given their experience, what is the extent to which the DPAs should be involved in enforcing the AI Act? We address these questions through an empirical and legal analysis. The section ‘The role(s) of DPAS in the enforcement system of the AI Act’ presents the AI Act’s provisions regarding the potential involvement of the DPAs in its enforcement. The section ‘Methods and sources’ describes the methods and sources used for the empirical analysis, while the section ‘How active are the DPAS in the enforcement related to AI?’ presents the results. As the enforcement of the General Data Protection Regulation (GDPR) is entrusted to the national DPAs,2 thus, decentralized,3 we analyse the enforcement practices in all the Member States. We collected and analysed a unique dataset on the activities of DPAs across all EU Member States, structured by the following indicators: (i) data protection impact assessment (DPIA) blacklist inclusions (with explicit or implicit references to AI); (ii) AI-related decisions; (iii) ADM-specific decisions (concerning Article 22 of GDPR); (iv) mentions of AI in annual reports (2021–24); and (v) website search results for search terms describing AI. We decided to include the decisions concerning ADM for two reasons. Firstly, since the AI Act incorporates a right resembling the GDPR’s right to explanation, the enforcement record of DPAs under the GDPR serves as an indicator of their likely role in upholding this right under the AI Act. Secondly, experience in the enforcement of ADM is an essential proxy for enforcing prohibitions and transparency obligations concerning high-risk AI systems under the AI Act, as these systems often entail processing personal data and ADM. Therefore, alongside the indicators directly referring to AI, we also include those concerning ADM. The results of this analysis are used to evaluate the activities that the DPAs have undertaken concerning AI-related matters. We treat the collected data as a proxy for assessing the readiness of DPAs to enforce legal norms in AI- and ADM-related cases. This assessment proposes a quantitative index based on the indicators mentioned above. Member States are then divided into four groups according to their activity level: very active, active, reluctant, and inert enforcers. We then discuss the characteristics of each group. The section ‘The potential involvement of the DPAS in the enforcement of the AI Act’ presents the results of the empirical analysis of the regulatory framework of the AI Act’s enforcement model. Assuming that a higher level of AI-specific enforcement activity indicates greater institutional learning and a stronger foundation for active future enforcement, we propose evidence-based solutions for the scope of DPAs’ involvement in the AI Act’s enforcement system. Based on this analysis, we have three targeted recommendations. We limit our suggestions to those aspects of the AI Act that are linked to the types of activities scrutinized in our study, as we take into account how different the AI Act is in terms of the regulatory approach to the GDPR (eg due to its focus on product safety). Thus, while we recognize that assigning specific responsibilities to other authorities might be recommended, our recommendations focus on the extent to which the DPAs should be involved in enforcing the AI Act due to their activity level observed in our research. First, we advocate including DPAs as Market Surveillance Authorities (MSAs) for high-risk AI systems under Annex III, points 3–5 of the AI Act, where the intersection of data protection and AI regulation is most evident. While very active and active enforcers could fulfil the role of MSAs, given their activity level, there might be doubts concerning reluctant and inert enforcers as well. In their case, we suggest that cooperation on the EU level could play a role in equipping them with the necessary for active AI enforcement. their be in with the provisions of the AI Act, which require the DPAs or authorities to be as for the high-risk AI systems under Annex III, as the systems are used for enforcement and and and points Secondly, given their experience with ADM-related the right to under the DPAs should be as the authorities under Article of the AI Act, which the right to an in high-risk AI a with the of our DPAs are to be as for high-risk AI systems in Annex III, it be to them as for the enforcement concerning ADM based on the of systems. on our data experience, we advocate for two solutions to the enforcement framework of the GDPR and AI cooperation the EU level, and the of an of DPA decisions to transparency and This and with evidence to enforcement and assess The enforcement system of the AI Act is and on a that is and The and responsibilities of the institutional or by the AI Act be to of this is and be through the European and the of Member States, as the AI Act’s enforcement to the In this our is to evaluate the potential role of DPAs within the by the AI Act. this assessment we two key the of the AI Act and the by the European Data Protection concerning DPAs’ responsibilities under the AI Act As the in the AI Act Member States a of This in assigning responsibilities for and enforcing the AI Act, to national authorities as DPAs or the national level, Member States or the of including Given their to and data the of DPAs be one of the potential in the of for with to the AI Act’s provisions concerning ADM. provisions in the of the AI Act explicitly or the and responsibilities of DPAs as national authorities within its regulatory DPAs are to some and enforcement for specific high-risk AI systems. the AI Act Member States to to the of AI high-risk and this the are to and personal data where to the AI Act that, for AI systems with for as those used in enforcement, and in Annex points as as some of those should be the national DPA or an Article references explicitly of the effectively other the DPA to be to these to and to those of a This a for the that the should also the of DPAs a of the data protection system and is the level of an level of might be a and of the DPAs as with to these systems to be a and It is that Article the EU level the European Data Protection as the for AI systems by EU and the AI Act might DPAs with their GDPR While Article of the GDPR DPAs to and from or the AI Act a as an the of an AI and where its This to the is to with the AI Act’s on data and the of a DPA is as the for a high-risk AI its the assessing obligations dataset and transparency and or and of AI systems in and or are Article of the AI Act by decisions by high-risk AI systems the right to the for and the role of the AI system in the decision-making While the AI Act does directly assign DPAs the enforcement of this they play a role in its enforcement they are as the AI Act specific obligations enforcement authorities are to or systems in which is the AI Act that each of be and to the and national DPA of these systems also an annual to the Article of the AI Act indicates that the of an system or a system should the to it of its and the personal data in with data protection Thus, the DPAs should be to the of these obligations by the DPAs as for processing personal data in regulatory a be the DPA be and specific and to with EU data protection In to AI the AI Act also that, in the of most Member States, enforcement. Article that national which EU in the of the of high-risk AI systems and which by Member States in a and relating to AI systems under the AI Act necessary to fulfil its In other a DPA or is a potential an AI it the legal right to the AI and other for AI Act the the of does require their the is to assess a Article the (eg a to that the or the AI system in the AI Act DPAs scope to as national for and The for DPAs on their GDPR yet they However, it is essential to that this is each Member the to which as the that the DPA remains this the to DPAs as the for high-risk AI systems in of The DPAs as the given that the AI Act with EU data protection including the the and the also that a DPA should be the of for the and cooperation the Member and EU the the is it is and Member States to an The is based on the experience that DPAs have in and enforcing AI-related data protection As in have are be in the to the and of AI systems across This is the we to empirically in this the of this study, we a dataset the AI-related activities of DPAs across all Member Our to specific proxies for assessing the activity level of DPAs in AI-related cases or that be under the AI Act, as ADM. Therefore, we collected the following The types of data collected in the The types of data collected in the We automated to on these indicators for all Member States. Data from to Therefore, reports for for some Member States. are in this of Firstly, we to the data types for the enforcers the Therefore, the of DPAs should include DPAs from the Member States, DPAs in and DPAs in the analysis on national for enforcement, including it the of the results for these Secondly, although automated is in this a to Therefore, we our indicators to the DPA a concerning AI or that we one the section Our focus on enforcement this as to of ADM and by our of covering all Member we to have all the decisions and on this we have the most dataset to on the activities of DPAs concerning AI and ADM. it is that the DPAs different to their decisions and the in the search This is in the of DPAs that of their or that a search covering the of the decisions on their also have search Therefore, we to these data and indicators that to all Member States despite in to their and on their to these it necessary to the search with despite our to from the data we used the of in with the key In some due to a of to DPAs’ we on for to the of the data we our findings with the results of on and as as with from While these sources all the decisions by the they to we collected the decisions in this and to those we This the of the results. The collected data are used as a proxy to assess the activity level of specific DPAs regarding the enforcement of AI and ADM. The following for the analysis of this data. The to the results in to the specific The to the results in to the specific we an index that the of these indicators the activity level of the DPAs regarding the enforcement of AI-related The to the indicators are as blacklist inclusions AI-related decisions ADM-specific decisions in annual reports search results these that a DPA’s activity in decisions a greater impact on the mentions of AI in reports or As decisions are they should in assessing DPAs’ However, we also that identifying the decisions the most data for analysis (eg due to in website search or DPAs their Therefore, we that the as the of AI-related and ADM-specific be to the blacklist indicator a of while the in annual reports and search have a of The index is the following The index have a and the of all indicators and the index this The higher the the greater the DPA’s activity level concerning enforcing AI-driven products and services and the provisions that be for enforcing the AI Act. the Member States in which enforcement is divided the national and and with in relating to and are based on the national level and we on the in In our search and multiple in the AI and ADM Therefore, we a of to of these The of all the indicators and the The of all the indicators and the While our index the of AI-related enforcement, a of regulatory also the of decisions DPAs’ decisions or on the of decisions they with and and of and the and impact of DPAs’ We address these in this the of legal is and This the assessment to the which AI Act be to DPAs on a or The we propose in the section ‘The potential involvement of the DPAS in the enforcement of the AI Act’ the for in targeted or to authorities or are In the quantitative index the approach that AI Act enforcement the a could the by enforcement. The of our empirical analysis is to the Member States according to their activity level in enforcing AI-related matters. The Member States are divided into four The very active enforcers in The active enforcers The reluctant enforcers The inert enforcers This section on the characteristics of each of enforcement activities undertaken by Member States to each to the DPAs’ of activity through concrete decisions and other The we the very active the and In the of all these we one or in the of and in the of all these of these DPAs also other of activity in our study, in findings on the website and the DPAs’ annual The issue of is the most with the DPAs in this different the characteristics of this we have and as is for its active approach to AI to most the the is for regarding the of with data protection The decisions concerning and are the of this While other DPAs their to on the these The is also one of the DPAs into activities in a of In to these the is also very active in the other in our First, is one of the where AI is mentioned directly on the the mentions of AI in annual reports from to with the multiple findings on the a on the DPA’s in AI-driven as as the and by their to personal data indicators active approach to enforcement. The DPA is also one of the most active enforcers in the area of AI. We decisions relating to AI and ADM to some However, it is that the DPA is active the in AI-related In the by the the AI the on AI or ADM the AI one of many aspects of the regarding the DPA for for as it specific It should be that, in the also on the intersection of the GDPR and GDPR of processing that Artificial a of how to that products and services AI with the The focus is on the legal for processing, data and the DPA’s active approach to enforcing AI is from the mentions of AI on its website and in its annual reports from to include sources concerning and on to data The of DPAs for which we one or in the and or one in one and multiple in the also on other indicators in our This from across the and Member States, as and the types of DPAs that to this we and as In decisions relating to AI include concerning a and a regarding the concerning the processing of we one in which an concerning the of and by the of and as as one in which an concerning ADM also an of data processing It is also one of the that explicitly mentions AI in its of types of processing a a certain level of experience with enforcing AI-based services and an active approach to this The of the Member States, and in this is we an in The DPA that a the We also an on the This which in to a for on the issue of potential with the AI We also an on data to to by This also in to the which that a system Article 22 of the the the DPA for on AI, as as on how to to processing of personal data for AI on its The the and which we have as enforcers. In of the AI-related or we one in of these In we The and characteristics as by the of results on their However, to be active in terms of the assessment based on this It should be that the search specific in involved potential of provisions, including Article 22 of the GDPR and the of The as an and related to the processing of data from of with to the the DPA that the solutions to the of The DPA of GDPR provisions in this case, of Article and a that AI solutions are in the Data Protection is active in enforcing AI We could decisions concerning AI or Article 22 of the GDPR that two have regarding the of AI and by The annual reports of the DPA also a to enforcement activities concerning AI. and AI mentioned all or mentioned in a results given the to issue or for an to the Data Protection Act that the to its as the transparency of its This reluctant approach to enforcement in of the decisions being by the that for other European However, there are that the is its The of inert enforcers all of which are Member States. most of these and we could decisions concerning AI or ADM. In the of and we one relating to ADM. However, results on other indicators these a to those in this group. the relating to the it should be that these DPAs have on AI-related activities on their and in their annual reports (eg in and on this It is to assess the activity level of some of the inert enforcers regarding AI due to the of the DPAs’ is an of its is also linked to its of a search DPAs with be in this area (eg and the inert and the In case, this is linked to identifying a relating to ADM. despite the of decisions concerning ADM or AI. However, we observed the DPA in other Our findings that, while all DPAs are active in AI-related enforcement to some there are in their level of In this we our results to the of how DPAs should be involved in enforcing the AI Act, given their activity level in AI-related As in the section ‘The role(s) of DPAS in the enforcement system of the AI the AI Act directly Member States to as in certain or addresses the of the DPAs in the enforcement of the AI Act (eg in the of AI regulatory Therefore, our suggestions the involvement of which is under the AI Act’s an empirical our indicates that of the DPAs have experience with enforcement in cases AI-based as AI personal data processing it is to an in the of and decisions by DPAs regarding AI-driven given that cases the of many DPAs in this This the of DPAs as a of those in Article of the AI Act, them to also other key high-risk we DPAs in the of AI systems used in and of to and to and of essential and services and and of Annex of the AI As these involve ADM based on personal the of DPAs is to enforcement. In the of other high-risk AI as products or of products Annex of the AI suggest that DPAs should have a role and be as This does that there is role for the DPAs in the enforcement concerning systems, as the AI and the of EU require the to with the scope of the DPAs as is in with their experience in terms of the enforcement concerning ADM and should for a the enforcement of the GDPR and the AI Act with to high-risk ADM systems. The for DPAs as be by that DPAs should be by the data regarding the of a in cases high-risk AI systems that personal data. Article of the GDPR the ‘The the processing where a data protection impact assessment under Article indicates that the processing in a in the of by the to the This could that high-risk AI systems under the AI Act fulfil this as systems are as Therefore, the GDPR and AI Act enforcement in this could be Our is the of the DPAs as authorities for the cases concerning the enforcement of Article of the AI right to an of The empirical results of our and the that DPAs have experience enforcing ADM the of DPAs as for related to this This the to the expertise that many DPAs have to for the of enforcing the AI Act. a legal this is also by its to and in to Article 22 of the it the right to an of ADM to the extent that the right is for under Union Therefore, to enforcement, it be to assign relating to this to the Article to the of systems in Annex Therefore, the DPAs to be as for the of the enforcement concerning high-risk AI systems in Annex III, as we suggest them for the cases concerning Article be Our analysis also that DPAs’ experience varies significantly. We one DPA concerning AI in Member States. the of DPA activity regarding AI and ADM enforcement, we a of associated with reluctant and inert enforcers as While active DPAs could from under the AI Act ‘The role(s) of DPAS in the enforcement system of the AI Act’ assigning these to reluctant enforcers to of the AI Act across the However, an enforcement system based on national the GDPR’s to a the AI entail concerning in the activity level Member and inert enforcement from aspects of the for a of and or necessary While these the scope of our study, it should be that often one enforcement in a given Member Therefore, this be a concerning the enforcement of EU specific to data the of the related to enforcement, some enforcement by active to in activity enforcers in different Member States is to cooperation the level of the EU The we the that, in the of the is used to and as the and are in some DPAs’ annual cooperation DPAs to the authorities to solutions to or the DPA active a on its website to the DPA’s very active for and the DPA reluctant a to the DPA’s very active We argue that the of a is an essential to the enforcement system for the AI Act and Member States. As we the DPAs should be as under the AI Act with to high-risk systems in Annex What is the the activities of the DPAs and the AI the of which include one from each Member The AI Act the to be as an in the AI authorities be to AI on a where the are of to Given the DPAs’ activity and the key role in the approach the AI-driven we advocate for their in the AI for high-risk AI systems. This enforcement the GDPR and the AI Act, as as national this to the regulatory framework and does impact the of the AI Our to the aspects of enforcement based on our the enforcement of EU data protection presents one of which is identifying cases in other Member States. While automated the search for decisions by concerning to these decisions be greater and transparency from the analysis of the decision-making practices of the enforcement is due to the of the We the decisions by the of these the and other of the Given the of many of the services and products in it is to for decisions and a to to the decisions of The could be developed by the in cooperation with the could also the This is of Member concerning enforcing the AI Act, as it enforcement by transparency regarding cases AI-driven services and products across the Our with the DPAs’ under the AI Act, that this regulation regarding the role the DPAs play in its enforcement system. we a unique dataset data on indicators relating to enforcing data protection in to AI-driven services and this we the activity level by the DPAs regarding the enforcement related to AI. We propose a index based on which Member States are divided into four The the very active the and DPAs one or in concerning AI-related and ADM-specific as as activity in other The active enforcers and are the DPAs that we as one or in the AI-related and ADM-specific one in one and multiple in the as as in different The the reluctant the and We could one in of the for these Member States. the inert we could AI-related or ADM-specific decisions in the of and In the of and we one ADM-related However, their on other indicators in an to that of the other inert enforcers. Based on these we propose two solutions regarding the involvement of DPAs in enforcing the AI Act. First, given the level of DPA activity regarding AI-related enforcement, we advocate DPAs as The DPAs should be for enforcing the provisions concerning high-risk AI systems in Annex III, points of the AI Act. The the enforcement of some high-risk under the AI Act and the enforcement of solutions from data protection (eg our Secondly, given that many DPAs have experience enforcing provisions we suggest them as the authorities for the enforcement of Article of the AI Act. This article the right to an regarding the of AI systems for high-risk we advocate for two solutions which could to address the of enforcement systems of the AI Act and the cooperation enforcers to the associated with reluctant and inert DPAs as Our research the of the within for many of the Thus, including the of the DPAs in the of the as the AI might be as a to enforcement. we propose an to decisions by This transparency in the enforcement model under the GDPR to a the AI Act. We to the and the for their as as the and the and EU This research and is by the research of the
Récupéré en direct depuis OpenAlex et désinversé. Les résumés ne sont pas conservés dans cette base de données : les index inversés représentent 8,6 Go des 9,3 Go de texte de la base, et le serveur dispose de 13 Go libres.
Comment cette classification a été obtenuedéplier
Prédiction machine sur la base complète
Imitation des enseignantsNi prévalence calibrée, ni vérité terrain. Validation humaine à venir. Le volet Gemma est une étiquette directe du modèle pour chaque travail de la base, lue sur la notice réduite au titre. Le volet Codex est un classifieur appris des 10 348 étiquettes directes de Codex et calibré sur les taux pondérés de l'échantillon; les champs sans appui suffisant ne portent aucun appel Codex. Le mode candidate est l'union des deux volets; le consensus est leur intersection. Ces sorties portent le statut machine_predicted_unvalidated et ne sont pas des étiquettes humaines.
Scores du classifieur distillé par catégorie (deux têtes)
| Catégorie | Codex | Gemma |
|---|---|---|
| Métarecherche | 0,088 | 0,132 |
| Méta-épidémiologie (sens strict) | 0,001 | 0,001 |
| Méta-épidémiologie (sens large) | 0,001 | 0,002 |
| Bibliométrie | 0,002 | 0,003 |
| Études des sciences et des technologies | 0,009 | 0,032 |
| Communication savante | 0,032 | 0,030 |
| Science ouverte | 0,004 | 0,012 |
| Intégrité de la recherche | 0,028 | 0,027 |
| Charge utile insuffisante (le modèle a refusé de juger) | 0,009 | 0,002 |
Scores machine (provisoires)
Les deux têtes enseignantes du modèle étudiant, lues sur ce travail. Un score ordonne la base pour la relecture; il n'affirme jamais une catégorie, et le statut de validation accompagne chaque rangée tel quel.
Scores de référence d'un modèle non mature (critères de maturité non atteints, 7 itérations). Un score ordonne; il n'affirme jamais une catégorie.
score_only:v0-immature-baseline · tel quel depuis la passe de notation : score_only signifie que le nombre peut ordonner les travaux, et qu'aucune étiquette de catégorie n'en découleClassification
machine, non validéePrédiction automatique; un appel candidat d’une seule source (Gemma direct ou Codex distillé), pas un consensus.
Le détail, modèle par modèle et score par score, se trouve en fin de page sous « Comment cette classification a été obtenue ».