{"id":1895,"date":"2021-09-13T08:09:23","date_gmt":"2021-09-13T08:09:23","guid":{"rendered":"https:\/\/blogs.kcl.ac.uk\/kslr\/?p=1895"},"modified":"2022-06-07T17:25:15","modified_gmt":"2022-06-07T17:25:15","slug":"eus-new-ai-regulation-addressing-liability-concerns-and-its-interplay-with-the-gdpr-sanjana-l-b-and-sanah-javed","status":"publish","type":"post","link":"https:\/\/blogs.kcl.ac.uk\/kslr\/2021\/09\/13\/eus-new-ai-regulation-addressing-liability-concerns-and-its-interplay-with-the-gdpr-sanjana-l-b-and-sanah-javed\/","title":{"rendered":"EU\u2019s New AI Regulation: Addressing Liability Concerns and Its Interplay with the GDPR &#8211; Sanjana L B and Sanah Javed"},"content":{"rendered":"<div id=\"content\" class=\"site-content\">\n<div id=\"primary\" class=\"content-area\">\n<article id=\"post-68\" class=\"post-68 page type-page status-publish hentry\">\n<div class=\"entry-content\">\n<p style=\"text-align: center\">Sanjana L. B. and Sanah Javed<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn1\" name=\"_ftnref1\">[1]<\/a><\/p>\n<p><strong>Abstract<\/strong><\/p>\n<p>The European Union has spearheaded regulation in the digital space and the recent proposal to regulate artificial intelligence is a testament to this. Much like the GDPR, the proposed AI regulation envisages extraterritorial application. The new framework leans towards industry self-regulation, and broadly categorises artificial intelligence systems based on the risk involved in their usage. Further, the liability framework, according to the risk categories under the proposal, goes beyond the existing product liability regime. This article analyses the nuances of a long-arm liability framework under the new regulations. Additionally, the authors discuss the need for congruence between the new regulation and the GDPR, given the EU\u2019s innovation-centric approach and the relationship between AI and data.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Introduction<\/strong><\/p>\n<p>On April 21, 2021, the European Union (\u2018<strong>EU<\/strong>\u2019) put forth the \u2018Proposal for a Regulation Laying Down Harmonised Rules on Artificial Intelligence\u2019 (\u2018<strong>AI framework<\/strong>\u2019 or \u2018<strong>proposed framework<\/strong>\u2019).<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn2\" name=\"_ftnref2\"><sup>[2]<\/sup><\/a>\u00a0 The AI framework is rooted in making Artificial Intelligence (\u2018<strong>AI<\/strong>\u2019) technology ethical and enhancing the EU\u2019s position as a \u2018future-proof\u2019 and \u2018innovation-friendly\u2019 jurisdiction.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn3\" name=\"_ftnref3\"><sup>[3]<\/sup><\/a><\/p>\n<p>The broad intent behind the AI framework is to provide guidance for developing AI, and make the EU a favourable jurisdiction for developers.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn4\" name=\"_ftnref4\"><sup>[4]<\/sup><\/a>\u00a0Soft-touch regulations such as these, enable both the industry and regulators to continuously learn about the technology, its challenges, and risks,<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn5\" name=\"_ftnref5\"><sup>[5]<\/sup><\/a>\u00a0allowing regulations to withstand AI technology\u2019s constant growth.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn6\" name=\"_ftnref6\"><sup>[6]<\/sup><\/a>\u00a0Accepting industry insights, the EU has chosen to omit red lines in the AI framework,<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn7\" name=\"_ftnref7\"><sup>[7]<\/sup><\/a>\u00a0but rather impose hefty penalties. Further, the framework addresses issues surrounding liability for \u2018AI Output\u2019.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn8\" name=\"_ftnref8\"><sup>[8]<\/sup><\/a>\u00a0It proposes that providers and users of AI in third countries must also comply with the framework in cases where the AI Output is used in the EU, hence extending the liability regime outside the EU.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn9\" name=\"_ftnref9\"><sup>[9]<\/sup><\/a><\/p>\n<p>This article discusses\u00a0<em>firstly,<\/em>\u00a0the liability and responsibility mechanism under the framework for developers and users of AI; and\u00a0<em>secondly,<\/em>\u00a0the interplay of the AI framework with the General Data Protection Regulation (\u2018<strong>GDPR<\/strong>\u2019)<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn10\" name=\"_ftnref10\"><sup>[10]<\/sup><\/a><sup>\u00a0\u00a0<\/sup>and\u00a0 ways to further strengthen the AI framework, keeping in view the industry-friendly stance of the EU.<\/p>\n<p><strong>I.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 How does the proposed framework tackle liability for harms arising out of AI technology?<\/strong><\/p>\n<p>The AI framework outlines the liability on developers, distributors and third parties engaged in functioning of AI systems.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn11\" name=\"_ftnref11\"><sup>[11]<\/sup><\/a>\u00a0This, read with the Product Liability Directive, makes the producer of the technology strictly liable for any harm that arose from the use of such technology.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn12\" name=\"_ftnref12\"><sup>[12]<\/sup><\/a><\/p>\n<p>The AI framework provides that developers of \u2018high risk\u2019 AI are required to establish a risk management system where the developer must foresee the possible risks that might arise from the use of the technology.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn13\" name=\"_ftnref13\"><sup>[13]<\/sup><\/a>\u00a0Further, Articles 11 and 12 impose obligations of technical documentation and automated records. However, industry players have pointed out that when the AI is being developed, the complete scope of its functionality and usability cannot accurately be predicted.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn14\" name=\"_ftnref14\"><sup>[14]<\/sup><\/a>\u00a0Often, AI developed for a particular purpose has the ability to go beyond that intended purpose.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn15\" name=\"_ftnref15\"><sup>[15]<\/sup><\/a>\u00a0These ex-ante obligations on the AI developers are overly burdensome because\u00a0<em>firstly<\/em>, the applicability of the framework extends to AI technology developed abroad but may be used within the EU,<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn16\" name=\"_ftnref16\"><sup>[16]<\/sup><\/a>\u00a0and\u00a0<em>secondly,<\/em>\u00a0because the scope of liability exceeds the Product Liability Directive.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn17\" name=\"_ftnref17\"><sup>[17]<\/sup><\/a><\/p>\n<p><strong>i.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/strong><strong>Extra-territorial Application of the AI framework<\/strong><\/p>\n<p>The application of the AI framework extends to cases where the AI technology is neither developed, nor deployed in the EU but AI Output is used in the EU.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn18\" name=\"_ftnref18\"><sup>[18]<\/sup><\/a>\u00a0Hence, the AI framework has broad extraterritorial application.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn19\" name=\"_ftnref19\"><sup>[19]<\/sup><\/a>\u00a0A foreign developer must ensure that in case there is a possibility that the AI Output will be used in the EU, the risk assessment, transparency, monitoring requirement and other obligations are fulfilled.<\/p>\n<p>Hence, the developer may face liability in cases where the AI Output was never intended to be introduced in the EU market. On this note, observations have been previously made on the parallels between the proposed framework and GDPR\u2019s extraterritorial application.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn20\" name=\"_ftnref20\"><sup>[20]<\/sup><\/a>\u00a0Further, it has been noted that in order to extend extra-territorial application of the framework, the AI systems produced elsewhere must have an EU nexus.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn21\" name=\"_ftnref21\"><sup>[21]<\/sup><\/a>\u00a0It is proposed that the AI framework must account for the developer\u2019s intention to make the product available in the EU market before liability can be attributed to the developer, by adopting the \u2018Offerings Test\u2019 as applied to the GDPR.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn22\" name=\"_ftnref22\"><sup>[22]<\/sup><\/a>\u00a0A connection between the AI developer\u2019s outcome of the technology and its services or output being offered in the EU<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn23\" name=\"_ftnref23\"><sup>[23]<\/sup><\/a>\u00a0must be established; if the output is available inadvertently, a significant number of developers that have no commercial presence in the EU, and therefore no nexus, would also be covered under the framework.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn24\" name=\"_ftnref24\"><sup>[24]<\/sup><\/a><\/p>\n<p><strong>ii.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/strong><strong>Going beyond the Product Liability regime<\/strong><\/p>\n<p>The European Parliament in its \u2018Recommendations on a civil liability regime for artificial intelligence\u2019<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn25\" name=\"_ftnref25\"><sup>[25]<\/sup><\/a>\u00a0acknowledges that AI has self-learning capabilities that go beyond the intention of the producer\/product developer. Hence, the operator \u2013 both at the frontend and backend must also be accountable for harms caused by AI.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn26\" name=\"_ftnref26\"><sup>[26]<\/sup><\/a>\u00a0The recommendations specify that the liability framework must work ex-ante to minimise risk or ex-post to compensate for the risk.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn27\" name=\"_ftnref27\"><sup>[27]<\/sup><\/a>\u00a0The AI framework for liability is modelled along the lines of the recommendations, however, it does more than just minimise risk; it imposes an obligation of technical documentation and record keeping, further requiring risk assessment and transparency about the manner in which the system\u2019s output takes place, raising concerns over disclosure of trade secrets and competitively sensitive information.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn28\" name=\"_ftnref28\"><sup>[28]<\/sup><\/a><\/p>\n<p>The framework indicates that the Directive on Trade Secrets<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn29\" name=\"_ftnref29\"><sup>[29]<\/sup><\/a>\u00a0will take precedence, and if information that falls within the ambit of a trade secret is required to be disclosed to the authorities, the latter are bound by confidentiality obligations.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn30\" name=\"_ftnref30\"><sup>[30]<\/sup><\/a>\u00a0However, the confidentiality obligation includes broadly worded exceptions and lacks sanctions in case the authorities breach confidentiality. Industry players value their trade secrets as it gives them a competitive edge in the market; asking them to comply with transparency obligations at the risk of losing this edge hinders their incentive to innovate.<\/p>\n<p>In response to the EU\u2019s White Paper on AI, stakeholders suggested that the AI developer\u2019s liability must be restricted to harms that arise in the development phase, and not extend to the exploitation phase, as their ability to mitigate harms in the latter case are low.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn31\" name=\"_ftnref31\"><sup>[31]<\/sup><\/a>\u00a0AI functionality may change beyond the developer\u2019s initial intent on the basis of the self-learning capabilities of the technology making the requirements of technical documentation and record keeping impractical.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn32\" name=\"_ftnref32\"><sup>[32]<\/sup><\/a><\/p>\n<p>Further, extending these obligations to developers in cases where merely the AI Output is used in the EU would increase compliance burdens.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn33\" name=\"_ftnref33\"><sup>[33]<\/sup><\/a>\u00a0Obligations in this regard must only extend to users of the technology<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn34\" name=\"_ftnref34\"><sup>[34]<\/sup><\/a>\u00a0or those directly involved with usage of AI Output. Hence, the ex-ante framework must impose merely a basic due diligence obligation on the developer and impose the burden of risk assessment on the deployer of AI technology, especially in cases where the AI is multi-purpose and risks cannot adequately be predicted by the developer.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn35\" name=\"_ftnref35\"><sup>[35]<\/sup><\/a><\/p>\n<p><strong>II.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Attaining congruence between the AI framework and the GDPR?<\/strong><\/p>\n<p>The AI framework is expected to demonstrate the \u2018Brussels Effect\u2019 like the GDPR,<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn36\" name=\"_ftnref36\"><sup>[36]<\/sup><\/a>\u00a0as it aims to set a standard for ethical technology.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn37\" name=\"_ftnref37\"><sup>[37]<\/sup><\/a>\u00a0However, while the AI framework takes a self-regulatory approach, the GDPR is stricter with its extraterritorial application, close oversight and robust sanctions, despite industries having lobbied for self-regulation.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn38\" name=\"_ftnref38\"><sup>[38]<\/sup><\/a>\u00a0There is a need to reconcile provisions in both frameworks owing to AI\u2019s dependency on large datasets and the EU\u2019s strict enforcement of data rights under the GDPR<\/p>\n<p><strong>i.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/strong><strong>Relationship between data protection and AI regulation<\/strong><\/p>\n<p>AI systems are dependent on data sets<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn39\" name=\"_ftnref39\"><sup>[39]<\/sup><\/a>\u00a0as AI processes data for the algorithmic training phase, and the usage phase.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn40\" name=\"_ftnref40\"><sup>[40]<\/sup><\/a>\u00a0Therefore, AI development presupposes the access to, and creation of, massive data sets.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn41\" name=\"_ftnref41\"><sup>[41]<\/sup><\/a><\/p>\n<p>When AI processes personal data, the provisions of the GDPR will apply.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn42\" name=\"_ftnref42\"><sup>[42]<\/sup><\/a>\u00a0The key points of concern between AI and data protection include the risk of re-identification of data subjects, profiling, and classification of inferred personal information as \u2018personal data\u2019.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn43\" name=\"_ftnref43\"><sup>[43]<\/sup><\/a>\u00a0Further, the concepts of consent and purpose limitation under the GDPR\u00a0<em>may\u00a0<\/em>be consistent with AI applications, subject to whether consent is specific to AI-related processing or application, whether consent to profiling practices becomes a prerequisite to availing services, the degree of freedom available to a data subject when providing such consent, and freedom to withdraw consent.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn44\" name=\"_ftnref44\"><sup>[44]<\/sup><\/a><\/p>\n<p>Further, the AI framework imposes obligations of high accuracy, transparency, and security on high-risk AI systems when it comes to data governance<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn45\" name=\"_ftnref45\"><sup>[45]<\/sup><\/a>\u00a0\u2013 all of which must be enabled by access to accurate, complete and representative data sets.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn46\" name=\"_ftnref46\"><sup>[46]<\/sup><\/a>\u00a0Given the close relationship between AI and data, any new rules to regulate AI must take into consideration the rights and obligations under the GDPR and their interaction with obligations under the new rules.<\/p>\n<p><strong>ii.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/strong><strong>How does the AI framework fit into the GDPR?<\/strong><\/p>\n<p>A potential concern arising from the GDPR\u2019s interplay with the AI framework is the grounds to process \u2018special categories of personal data\u2019 (\u2018<strong>SCPD<\/strong>\u2019)<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn47\" name=\"_ftnref47\"><sup>[47]<\/sup><\/a>.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn48\" name=\"_ftnref48\"><sup>[48]<\/sup><\/a>\u00a0Processors are prohibited from processing SCPD except as provided under a limited list of grounds in the GDPR.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn49\" name=\"_ftnref49\"><sup>[49]<\/sup><\/a>\u00a0The AI framework allows providers of AI to process SCPD to carry out bias monitoring, detection and correction in high-risk AI.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn50\" name=\"_ftnref50\"><sup>[50]<\/sup><\/a><\/p>\n<p>Providers of high-risk AI need to, on the one hand, carefully monitor bias in algorithms, and on the other hand comply with the GDPR on processing SCPD. The GDPR permits processing of SCPD when the data subject provides explicit consent for specific purposes, and for substantial public interest;<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn51\" name=\"_ftnref51\"><sup>[51]<\/sup><\/a>\u00a0however, as discussed above, algorithm training for AI systems requires massive data sets,<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn52\" name=\"_ftnref52\"><sup>[52]<\/sup><\/a>\u00a0and therefore, it is not\u00a0 feasible for AI developers to obtain explicit consent from individual data subjects when they train their systems.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn53\" name=\"_ftnref53\"><sup>[53]<\/sup><\/a>\u00a0However, providers of high-risk AI may be permitted to process SCPD under the public interest ground due to risks of biased algorithms,<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn54\" name=\"_ftnref54\"><sup>[54]<\/sup><\/a>\u00a0subject to the safeguards mentioned in the GDPR.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn55\" name=\"_ftnref55\"><sup>[55]<\/sup><\/a><\/p>\n<p>Processing SCPD under the AI framework is permitted when \u2018strictly necessary\u2019;<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn56\" name=\"_ftnref56\"><sup>[56]<\/sup><\/a>\u00a0but the AI framework itself is not a legal ground to process SCPD.<a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftn57\" name=\"_ftnref57\"><sup>[57]<\/sup><\/a>\u00a0Without a corresponding provision under the GDPR to allow providers to process SCPD for obligations under the AI framework, uncertainties may still persist for AI providers and data subjects. This, coupled with extraterritorial application and the hefty penalties for non-compliance under both frameworks warrants clarity from the regulators. Therefore, the \u00a0authors suggest that the GDPR be suitably modified to establish that obligations of high-risk AI providers under the AI framework can be a valid ground to process SCPD, subject to safety and privacy standards. This will help the industry conduct bias monitoring while still being compliant with the GDPR.<\/p>\n<p><strong>Conclusion<\/strong><\/p>\n<p>The AI framework seeks to be forward-looking; and its ramifications will be far-reaching. The authors note above that the application of the AI framework merely on the basis of AI Output appears to be extraneous and therefore to enforce extraterritoriality without hindering global innovation, the AI framework must borrow the \u2018Offering Test\u2019 from the GDPR to determine liability. Further, as obligations under the AI framework will need high-risk AI providers to process SCPD, there is a need to ensure congruence between the AI framework and the GDPR. To this end, modifying the latter to enable high-risk AI providers to process SCPD will help achieve effective bias monitoring, detection, and correction.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Footnotes<\/strong><\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref1\" name=\"_ftn1\">[1]<\/a>\u00a0Sanjana L. B., V-year student, Symbiosis Law School, Hyderabad, and Sanah Javed, Associate, Trilegal. All views expressed in this article are the authors\u2019 personal views.<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref2\" name=\"_ftn2\"><sup>[2]<\/sup><\/a>\u00a0Commission, \u2018Proposal for a Regulation of the European Parliament and of the Council Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act) and Amending Certain Union Legislative Acts\u2019 COM (2021) 206 final (AI framework)<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref3\" name=\"_ftn3\"><sup>[3]<\/sup><\/a>\u00a0\u2018Europe fit for the Digital Age: Commission proposes new rules and actions for excellence and trust in Artificial Intelligence\u2019 (<em>European Commission Press Corner,\u00a0<\/em>21 April 2021) &lt;<a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/IP_21_1682\">https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/IP_21_1682<\/a>&gt; accessed 12 June 2021.<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref4\" name=\"_ftn4\"><sup>[4]<\/sup><\/a>\u00a0Natasha Lomas, \u2018Europe Lays Out Plan for Risk-Based AI Rules to Boost Trust and Uptake\u2019 (<em>TechCrunch,\u00a0<\/em>21 April 2021) &lt;<a href=\"https:\/\/techcrunch.com\/2021\/04\/21\/europe-lays-out-plan-for-risk-based-ai-rules-to-boost-trust-and-uptake\/\">https:\/\/techcrunch.com\/2021\/04\/21\/europe-lays-out-plan-for-risk-based-ai-rules-to-boost-trust-and-uptake\/<\/a>&gt; accessed 12 June 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref5\" name=\"_ftn5\"><sup>[5]<\/sup><\/a>\u00a0Denmark and Others, Innovation and Trust worthy AI: Two Sides of the Same Coin, (Position Paper, 2020) 2<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref6\" name=\"_ftn6\"><sup>[6]<\/sup><\/a>\u00a0In a recent event by the Center for Data and Innovation on May 05, 2021, Mr. Kilian Gross, AI Policy Development and Coordination, DG CONNECT, European Commission, also affirmed that the framework envisions a \u2018future-proof\u2019 regulation; See \u2018What\u2019s Next on EU\u2019s proposed AI framework\u2019 (<em>DataInnovation<\/em>, 5 May 2021) &lt;<a href=\"https:\/\/www.youtube.com\/watch?v=vdcSKXeiDAU&amp;t=2s\">https:\/\/www.youtube.com\/watch?v=vdcSKXeiDAU&amp;t=2s<\/a>&gt; accessed 21 June 2021\u00a0 ; Adam Satariano, \u2018Europe Proposes Strict Rules for Artificial Intelligence\u2019 (<em>The New York Times,\u00a0<\/em>21 April 2021) &lt;<a href=\"https:\/\/www.nytimes.com\/2021\/04\/16\/business\/artificial-intelligence-regulation.html\">https:\/\/www.nytimes.com\/2021\/04\/16\/business\/artificial-intelligence-regulation.html<\/a>&gt; accessed 12 June 2021 ; Javier Espinoza and Madhumita Murgia, \u2018Europe Attempts to Take Leading Role in Regulating Uses of AI\u2019 (<em>Financial Times,\u00a0<\/em>24 April 2021) &lt;<a href=\"https:\/\/www.ft.com\/content\/360faa3e-4110-4f38-b618-dd695deece90\">https:\/\/www.ft.com\/content\/360faa3e-4110-4f38-b618-dd695deece90<\/a>&gt; accessed 12 June 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref7\" name=\"_ftn7\"><sup>[7]<\/sup><\/a>\u00a0Tom Simonite, \u2018How Tech Companies Are Shaping the Rules Governing AI\u2019 (<em>Wired,\u00a0<\/em>16 May 2019) &lt;<a href=\"https:\/\/www.wired.com\/story\/how-tech-companies-shaping-rules-governing-ai\/\">https:\/\/www.wired.com\/story\/how-tech-companies-shaping-rules-governing-ai\/<\/a>&gt; accessed 16 June 2021; See also, Friederike Reinhold and Angela M\u00fcller, \u2018AlgorithmWatch\u2019s response to the European Commission\u2019s proposed regulation on Artificial Intelligence \u2013 A major step with major gaps\u2019 (<em>AlgorithmWatch,<\/em>\u00a0April 2021) &lt;<a href=\"https:\/\/algorithmwatch.org\/en\/response-to-eu-ai-regulation-proposal-2021\/\">https:\/\/algorithmwatch.org\/en\/response-to-eu-ai-regulation-proposal-2021\/<\/a>&gt; accessed 12 June 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref8\" name=\"_ftn8\"><sup>[8]<\/sup><\/a>\u00a0AI framework, art 3(1); AI \u2018Output\u2019 is understood as \u201c<em>content, predictions, recommendations or decisions influencing the environment they interact with<\/em>\u201d that are derived from AI.<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref9\" name=\"_ftn9\"><sup>[9]<\/sup><\/a>\u00a0AI framework, recital 11<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref10\" name=\"_ftn10\"><sup>[10]<\/sup><\/a>\u00a0Council Regulation (EC) 2016\/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/EC (General Data Protection Regulation) [2016] OJ L119\/1 (GDPR)<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref11\" name=\"_ftn11\"><sup>[11]<\/sup><\/a>\u00a0AI framework, chapter II-III<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref12\" name=\"_ftn12\"><sup>[12]<\/sup><\/a>\u00a0Council Directive of 25 July 1985 on the Appropriation of the laws, regulations and administrative provisions of the Member States concerning liability for defective products (85\/374\/EEC),\u00a0<a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:31985L0374&amp;from=EN\">https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:31985L0374&amp;from=EN<\/a>\u00a0(Product Liability Directive)<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref13\" name=\"_ftn13\"><sup>[13]<\/sup><\/a>\u00a0AI framework, art 9<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref14\" name=\"_ftn14\"><sup>[14]<\/sup><\/a>\u2018Recommendations for Regulating AI\u2019, Google, 7, 9 &lt;<a href=\"https:\/\/ai.google\/static\/documents\/recommendations-for-regulating-ai.pdf\">https:\/\/ai.google\/static\/documents\/recommendations-for-regulating-ai.pdf<\/a>&gt; accessed 16 June 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref15\" name=\"_ftn15\"><sup>[15]<\/sup><\/a>\u00a0Ibid<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref16\" name=\"_ftn16\"><sup>[16]<\/sup><\/a>\u00a0Marc MacCarthy and Kenneth Propp, \u2018Machines learn that Brussels writes the rules: The EU\u2019s new AI regulation\u2019 (<em>LawfareBlog<\/em>, April 28, 2021) &lt;<a href=\"https:\/\/www.lawfareblog.com\/machines-learn-brussels-writes-rules-eus-new-ai-regulation\">https:\/\/www.lawfareblog.com\/machines-learn-brussels-writes-rules-eus-new-ai-regulation<\/a>&gt; accessed 16 June 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref17\" name=\"_ftn17\"><sup>[17]<\/sup><\/a>\u00a0European Parliament, Annex to \u2018Resolution of 20 October 2020 with recommendations to the Commission on Civil Liability Regime for Artificial Intelligence (2020\/2014(INL)) Civil Liability Regime for Artificial Intelligence\u2019, para B (8), 2020 &lt;<a href=\"https:\/\/www.europarl.europa.eu\/doceo\/document\/TA-9-2020-0276_EN.html#title1\">https:\/\/www.europarl.europa.eu\/doceo\/document\/TA-9-2020-0276_EN.html#title1<\/a>&gt; accessed 16 June 2021 (Annex to Civil Liability Regime)<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref18\" name=\"_ftn18\"><sup>[18]<\/sup><\/a>\u00a0\u2018New Horizons: European Commission Proposes Measures to Regulate AI\u2019 (<em>JDSupra<\/em>, April 27, 2021) &lt;<a href=\"https:\/\/www.jdsupra.com\/legalnews\/new-horizons-european-commission-4961736\/\">https:\/\/www.jdsupra.com\/legalnews\/new-horizons-european-commission-4961736\/<\/a>&gt; accessed 16 June 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref19\" name=\"_ftn19\"><sup>[19]<\/sup><\/a>\u00a0Dan Whitehead, \u2018Why the EU\u2019s AI regulation is a groundbreaking proposal\u2019 (<em>IAPP<\/em>, April 22, 2021) &lt;<a href=\"https:\/\/iapp.org\/news\/a\/why-the-eus-ai-regulation-is-a-ground-breaking-proposal\/\">https:\/\/iapp.org\/news\/a\/why-the-eus-ai-regulation-is-a-ground-breaking-proposal\/<\/a>&gt; accessed 16 June 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref20\" name=\"_ftn20\"><sup>[20]<\/sup><\/a>\u00a0Blanca Escribano and Peter Katko, \u2018European draft Regulation on Artificial Intelligence: Key questions answered\u2019 (<em>EY<\/em>, 15 May 2021) &lt;<a href=\"https:\/\/www.ey.com\/en_es\/law\/european-draft-regulation-on-artificial-intelligence-key-questions-answered\">https:\/\/www.ey.com\/en_es\/law\/european-draft-regulation-on-artificial-intelligence-key-questions-answered<\/a>&gt; accessed 16 June 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref21\" name=\"_ftn21\"><sup>[21]<\/sup><\/a>\u00a0Julia M Wilson and others, \u2018New Draft Rules on Use of Artificial Intelligence\u2019 (<em>BakerMcKenzie<\/em>, 14 May 2021) &lt;<a href=\"https:\/\/www.bakermckenzie.com\/en\/insight\/publications\/2021\/05\/new-draft-rules-on-the-use-of-ai\">https:\/\/www.bakermckenzie.com\/en\/insight\/publications\/2021\/05\/new-draft-rules-on-the-use-of-ai<\/a>&gt; accessed 16 June 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref22\" name=\"_ftn22\"><sup>[22]<\/sup><\/a>\u00a0The \u2018Offering Test\u2019 suggests that the law applies only in case the offerings are available in the EU. Any inadvertent or incidental service would not bring the entity within the framework of the GDPR.<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref23\" name=\"_ftn23\"><sup>[23]<\/sup><\/a>\u00a0Dino Wilkinson, \u2018New guidance on the application of the GDPR outside Europe\u2019 (<em>Clyde &amp; Co<\/em>., 27 November 2019) &lt;<a href=\"https:\/\/www.clydeco.com\/en\/insights\/2019\/11\/new-guidance-on-the-application-of-the-gdpr-outsid\">https:\/\/www.clydeco.com\/en\/insights\/2019\/11\/new-guidance-on-the-application-of-the-gdpr-outsid<\/a>&gt; accessed 16 June 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref24\" name=\"_ftn24\"><sup>[24]<\/sup><\/a>\u00a0Dan Whitehead, \u2018AI &amp; Algorithms (Part 3): Why the EU Regulation is a groundbreaking proposal\u2019 (<em>Engage<\/em>, 3 May 2021) &lt;<u>https:\/\/www.engage.hoganlovells.com\/knowledgeservices\/news\/ai-algorithms-part-3-why-the-eus-ai-regulation-is-a-groundbreaking-proposal<\/u>&gt; accessed 28 July 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref25\" name=\"_ftn25\"><sup>[25]<\/sup><\/a>\u00a0European Parliament, \u2018Resolution of 20 October 2020 with recommendations to the Commission on Civil Liability Regime for Artificial Intelligence (2020\/2014(INL)) Civil Liability Regime for Artificial Intelligence\u2019, 2020 &lt;<a href=\"https:\/\/www.europarl.europa.eu\/doceo\/document\/TA-9-2020-0276_EN.html#title1\">https:\/\/www.europarl.europa.eu\/doceo\/document\/TA-9-2020-0276_EN.html#title1<\/a>&gt; accessed 16 June 2021 (Civil Liability Regime)<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref26\" name=\"_ftn26\"><sup>[26]<\/sup><\/a>\u00a0Ibid, para 12<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref27\" name=\"_ftn27\"><sup>[27]<\/sup><\/a>\u00a0Annex to Civil Liability Regime (n 17)<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref28\" name=\"_ftn28\"><sup>[28]<\/sup><\/a>\u00a0Nazrin Huseinzade, \u2018Algorithm Transparency: How to Eat the Cake and Have it Too\u2019 (<em>European Law Blog<\/em>, 27 January, 2021) &lt;<a href=\"https:\/\/europeanlawblog.eu\/2021\/01\/27\/algorithm-transparency-how-to-eat-the-cake-and-have-it-too\/\">https:\/\/europeanlawblog.eu\/2021\/01\/27\/algorithm-transparency-how-to-eat-the-cake-and-have-it-too\/<\/a>&gt; accessed 16 June 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref29\" name=\"_ftn29\"><sup>[29]<\/sup><\/a>\u00a0Council Directive (2016\/943) of 8 June 2016 on the protection of undisclosed know-how and business information (trade secrets) against their unlawful acquisition, use and disclosure,\u00a0<a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32016L0943&amp;from=EN\">https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:32016L0943&amp;from=EN<\/a>; AI framework, para 3.5, explanatory memorandum and art 70(1)(a)<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref30\" name=\"_ftn30\"><sup>[30]<\/sup><\/a>\u00a0AI framework, art 70<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref31\" name=\"_ftn31\"><sup>[31]<\/sup><\/a>\u00a0Nazrin Huseinzade (n 28)<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref32\" name=\"_ftn32\"><sup>[32]<\/sup><\/a>\u00a0\u2018Recommendations for Regulating AI\u2019, Google, 7, 9 &lt;https:\/\/ai.google\/static\/documents\/recommendations-for-regulating-ai.pdf&gt; accessed 28 July 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref33\" name=\"_ftn33\"><sup>[33]<\/sup><\/a>\u00a0Sam Shaed, Europe\u2019s proposed A.I. law could cost its economy $36 billion, think tank warns (CNBC, 26 July 2021) &lt;<a href=\"https:\/\/www-cnbc-com.cdn.ampproject.org\/c\/s\/www.cnbc.com\/amp\/2021\/07\/26\/aia-europes-proposed-ai-law-could-cost-its-economy-36-billion.html\">https:\/\/www-cnbc-com.cdn.ampproject.org\/c\/s\/www.cnbc.com\/amp\/2021\/07\/26\/aia-europes-proposed-ai-law-could-cost-its-economy-36-billion.html<\/a>&gt; accessed 28 July 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref34\" name=\"_ftn34\"><sup>[34]<\/sup><\/a>\u00a0\u2018Recommendations for Regulating AI\u2019, Google, 7, 9 &lt;https:\/\/ai.google\/static\/documents\/recommendations-for-regulating-ai.pdf&gt; accessed 28 July 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref35\" name=\"_ftn35\"><sup>[35]<\/sup><\/a>\u00a0Ibid<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref36\" name=\"_ftn36\"><sup>[36]<\/sup><\/a>\u00a0Anu Braford,\u00a0<em>The Brussels Effect: How the European Union Rules the World\u00a0<\/em>(OUP 2020) 131<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref37\" name=\"_ftn37\"><sup>[37]<\/sup><\/a>\u00a0Jeremy Kahn, \u2018Europe Proposes Strict A.I. Regulation Likely to Have an Impact Around The World\u2019 (<em>Fortune,<\/em>\u00a021 April 2021) &lt;<a href=\"https:\/\/fortune.com\/2021\/04\/21\/europe-artificial-intelligence-regulation-global-impact-google-facebook-ibm\/\">https:\/\/fortune.com\/2021\/04\/21\/europe-artificial-intelligence-regulation-global-impact-google-facebook-ibm\/<\/a>&gt; accessed 12 June 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref38\" name=\"_ftn38\"><sup>[38]<\/sup><\/a>\u00a0<em>Bradford\u00a0<\/em>(n 36) 133, 138, 139<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref39\" name=\"_ftn39\"><sup>[39]<\/sup><\/a>\u00a0\u2018Big Data is Too Big Without AI\u2019 (<em>Maryville University<\/em>) &lt;<a href=\"https:\/\/online.maryville.edu\/blog\/big-data-is-too-big-without-ai\/\">https:\/\/online.maryville.edu\/blog\/big-data-is-too-big-without-ai\/<\/a>&gt; accessed 12 June 2021.<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref40\" name=\"_ftn40\"><sup>[40]<\/sup><\/a>\u00a0\u2018Artificial Intelligence and Data Protection \u2013 How the GDPR Regulates AI\u2019 (<em>Centre for Information Policy Leadership,<\/em>\u00a0March 2020) &lt;<a href=\"https:\/\/www.informationpolicycentre.com\/uploads\/5\/7\/1\/0\/57104281\/cipl-hunton_andrews_kurth_legal_note_-_how_gdpr_regulates_ai__12_march_2020_.pdf\">https:\/\/www.informationpolicycentre.com\/uploads\/5\/7\/1\/0\/57104281\/cipl-hunton_andrews_kurth_legal_note_-_how_gdpr_regulates_ai__12_march_2020_.pdf<\/a>&gt; accessed 12 June 2021, 4 stating that the \u2018algorithmic training phase\u2019 refers to the phase where AI is trained using data sets to create a model, identify patterns and connect various data points.<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref41\" name=\"_ftn41\"><sup>[41]<\/sup><\/a>\u00a0Giovanni Sartor and Francesca Lagioia,\u00a0<em>The impact of the General Data Protection Regulation (GDPR) on artificial intelligence\u00a0<\/em>(European Union 2020) 16<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref42\" name=\"_ftn42\"><sup>[42]<\/sup><\/a>\u00a0Artificial Intelligence and Data Protection \u2013 How the GDPR Regulates AI\u2019 (<em>Centre for Information Policy Leadership,<\/em>\u00a0March 2020) &lt;<a href=\"https:\/\/www.informationpolicycentre.com\/uploads\/5\/7\/1\/0\/57104281\/cipl-hunton_andrews_kurth_legal_note_-_how_gdpr_regulates_ai__12_march_2020_.pdf\">https:\/\/www.informationpolicycentre.com\/uploads\/5\/7\/1\/0\/57104281\/cipl-hunton_andrews_kurth_legal_note_-_how_gdpr_regulates_ai__12_march_2020_.pdf<\/a>&gt; accessed 12 June 2021, 4<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref43\" name=\"_ftn43\"><sup>[43]<\/sup><\/a>\u00a0Sartor and Lagigoia (n 41) 74-76<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref44\" name=\"_ftn44\"><sup>[44]<\/sup><\/a>\u00a0Ibid<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref45\" name=\"_ftn45\"><sup>[45]<\/sup><\/a>\u00a0AI framework, art 10<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref46\" name=\"_ftn46\"><sup>[46]<\/sup><\/a>\u00a0Mark MacCarthy and Kenneth Propp, \u2018Machines learn that Brussels writes the rules: The EU\u2019s new AI regulation\u2019 (<em>Brookings,<\/em>\u00a04 May 2021) &lt;<a href=\"https:\/\/www.brookings.edu\/blog\/techtank\/2021\/05\/04\/machines-learn-that-brussels-writes-the-rules-the-eus-new-ai-regulation\/\">https:\/\/www.brookings.edu\/blog\/techtank\/2021\/05\/04\/machines-learn-that-brussels-writes-the-rules-the-eus-new-ai-regulation\/<\/a>&gt; accessed 12 June 2021<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref47\" name=\"_ftn47\"><sup>[47]<\/sup><\/a>\u00a0SCPD includes data revealing ethnic or racial identities, religious beliefs, sexual orientation, and biometric data, among others.<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref48\" name=\"_ftn48\"><sup>[48]<\/sup><\/a>\u00a0GDPR, art 9<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref49\" name=\"_ftn49\"><sup>[49]<\/sup><\/a>\u00a0GDPR, art 9(2)<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref50\" name=\"_ftn50\"><sup>[50]<\/sup><\/a>\u00a0AI framework, art 10(5), recital 44<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref51\" name=\"_ftn51\"><sup>[51]<\/sup><\/a>\u00a0GDPR, art 9(2)(a), art 9(2)(g)<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref52\" name=\"_ftn52\"><sup>[52]<\/sup><\/a>\u00a0Sartor and Lagigoia (n 41) 16<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref53\" name=\"_ftn53\"><sup>[53]<\/sup><\/a>\u00a0Sartor and Lagigoia (n 41) 49<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref54\" name=\"_ftn54\"><sup>[54]<\/sup><\/a>\u00a0AI framework, recital 44<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref55\" name=\"_ftn55\"><sup>[55]<\/sup><\/a>\u00a0GDPR, art 9(2)(g)<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref56\" name=\"_ftn56\"><sup>[56]<\/sup><\/a>\u00a0AI framework, art 10(5)<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ftnref57\" name=\"_ftn57\"><sup>[57]<\/sup><\/a>\u00a0AI framework, recital 41<\/p>\n<p><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68#_ednref15\" name=\"_edn15\"><\/a><\/p>\n<div class=\"at-below-post-page addthis_tool\" data-url=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?page_id=68\"><\/div>\n<\/div>\n<footer class=\"entry-footer\"><span class=\"edit-link\"><a class=\"post-edit-link\" href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/wp-admin\/post.php?post=68&amp;action=edit\">Edit<\/a><\/span><\/footer>\n<\/article>\n<p>&nbsp;<\/p>\n<\/div>\n<div id=\"secondary\" class=\"widget-area\" role=\"complementary\">\n<aside id=\"recent-comments-2\" class=\"widget widget_recent_comments\">\n<h1 class=\"widget-title\">Recent Comments<\/h1>\n<ul id=\"recentcomments\"><\/ul>\n<\/aside>\n<aside id=\"archives-2\" class=\"widget widget_archive\">\n<h1 class=\"widget-title\">Archives<\/h1>\n<ul>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=202107\">July 2021<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=202103\">March 2021<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=202012\">December 2020<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=202007\">July 2020<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=202006\">June 2020<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=202005\">May 2020<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=202004\">April 2020<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=202003\">March 2020<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201907\">July 2019<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201408\">August 2014<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201406\">June 2014<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201404\">April 2014<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201403\">March 2014<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201402\">February 2014<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201401\">January 2014<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201312\">December 2013<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201311\">November 2013<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201306\">June 2013<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201305\">May 2013<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201304\">April 2013<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201303\">March 2013<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201302\">February 2013<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201301\">January 2013<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201207\">July 2012<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201206\">June 2012<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201205\">May 2012<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201204\">April 2012<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201203\">March 2012<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201202\">February 2012<\/a><\/li>\n<li><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?m=201201\">January 2012<\/a><\/li>\n<\/ul>\n<\/aside>\n<aside id=\"categories-3\" class=\"widget widget_categories\">\n<h1 class=\"widget-title\">Categories<\/h1>\n<ul>\n<li class=\"cat-item cat-item-5\"><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?cat=5\">Constitutional and Public Law<\/a><\/li>\n<li class=\"cat-item cat-item-164\"><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?cat=164\">Forum Articles<\/a><\/li>\n<li class=\"cat-item cat-item-35\"><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?cat=35\">Human Rights<\/a>\n<ul class=\"children\">\n<li class=\"cat-item cat-item-40\"><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?cat=40\">Children&#8217;s Rights<\/a><\/li>\n<li class=\"cat-item cat-item-41\"><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?cat=41\">Homophobia<\/a><\/li>\n<li class=\"cat-item cat-item-42\"><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?cat=42\">Housing Rights<\/a><\/li>\n<li class=\"cat-item cat-item-37\"><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?cat=37\">Labour Rights<\/a><\/li>\n<li class=\"cat-item cat-item-38\"><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?cat=38\">Migrants&#8217; Rights<\/a><\/li>\n<li class=\"cat-item cat-item-39\"><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?cat=39\">Protest<\/a><\/li>\n<\/ul>\n<\/li>\n<li class=\"cat-item cat-item-4\"><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?cat=4\">Legal Theory<\/a><\/li>\n<li class=\"cat-item cat-item-1\"><a href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/?cat=1\">Uncategorized<\/a><\/li>\n<\/ul>\n<\/aside>\n<\/div>\n<\/div>\n<div class=\"footer-wrap clear\"><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Sanjana L. B. and Sanah Javed[1] Abstract The European Union has spearheaded regulation in the digital space and the recent proposal to regulate artificial intelligence is a testament to this. Much like the GDPR, the proposed AI regulation envisages extraterritorial application. The new framework leans towards industry self-regulation, and broadly categorises artificial intelligence systems based&hellip; <a class=\"more-link\" href=\"https:\/\/blogs.kcl.ac.uk\/kslr\/2021\/09\/13\/eus-new-ai-regulation-addressing-liability-concerns-and-its-interplay-with-the-gdpr-sanjana-l-b-and-sanah-javed\/\">More <span class=\"screen-reader-text\">EU\u2019s New AI Regulation: Addressing Liability Concerns and Its Interplay with the GDPR &#8211; Sanjana L B and Sanah Javed<\/span><\/a><\/p>\n","protected":false},"author":873,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[164],"tags":[],"class_list":["post-1895","post","type-post","status-publish","format-standard","hentry","category-forum-articles"],"_links":{"self":[{"href":"https:\/\/blogs.kcl.ac.uk\/kslr\/wp-json\/wp\/v2\/posts\/1895","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.kcl.ac.uk\/kslr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.kcl.ac.uk\/kslr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.kcl.ac.uk\/kslr\/wp-json\/wp\/v2\/users\/873"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.kcl.ac.uk\/kslr\/wp-json\/wp\/v2\/comments?post=1895"}],"version-history":[{"count":5,"href":"https:\/\/blogs.kcl.ac.uk\/kslr\/wp-json\/wp\/v2\/posts\/1895\/revisions"}],"predecessor-version":[{"id":1982,"href":"https:\/\/blogs.kcl.ac.uk\/kslr\/wp-json\/wp\/v2\/posts\/1895\/revisions\/1982"}],"wp:attachment":[{"href":"https:\/\/blogs.kcl.ac.uk\/kslr\/wp-json\/wp\/v2\/media?parent=1895"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.kcl.ac.uk\/kslr\/wp-json\/wp\/v2\/categories?post=1895"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.kcl.ac.uk\/kslr\/wp-json\/wp\/v2\/tags?post=1895"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}