The UK’s data regulator, the Information Commissioner’s Office (ICO), has warned organizations and companies using and developing generative AI — with OpenAI’s ChatGPT getting most of the harsh spotlight — to follow laws of data protection or else shoulder the consequences.
“Organisations developing or using generative AI should be considering their data protection obligations from the outset, taking a data protection by design and by default approach,” the ICO’s executive director of regulatory risk, Stephen Almond, said in a blog post on Monday.
“This isn’t optional — if you’re processing personal data, it’s the law.”
Generative AI Under Fire for Privacy Concerns
Almond’s warning — which presented eight questions that AI developers should ask themselves to comply with regulators — comes less than a week after Italy’s regulators banned ChatGPT over privacy breach concerns.
If the company falls foul of the GDPR, it could mean a €20 million (about $22 million) fine for OpenAI.
The UK’s ICO is known for its no-nonsense approach to how organizations process user data. For instance, it fined facial recognition database Clearview AI over £7.5 million (about $9.3 million) in May 2022 for unlawfully processing UK residents’ data.
Likewise, it now looks like Germany’s watchdog might ban ChatGPT, too, for similar reasons.
Citing OpenAI CEO Sam Altman’s reaction, Almond said that “it is important to take a step back and reflect on how personal data is being used by a technology that has left its own chief ‘a bit scared.'”
Almond notes that organizations considering using or developing large language model (LLM) AI technology should consider data protection obligations by “design and default.”
Several organizations and entities already fall under this scrutiny, for instance, those that announced they will supplement their products and infrastructure with GTP-4 — including Duolingo, Be My Eyes, Stripe, Morgan Stanley, and even the nation of Iceland.
ICO’s Eight Questions for Those Leveraging Generative AI
OpenAI’s most powerful generative AI to date — GPT-4, which powers ChatGPT’s latest version — was revealed on March 14.
Weeks later, an open letter titled “Pause Giant AI Experiments” by the Future of Life Institute NGO was signed by nearly two thousand tech experts and academics, including Elon Musk and Apple’s co-founder Steve Wozniak.
The letter called on civic leaders to institute a half-year hiatus on the development of further generative AI systems like GTP-4.5 and 5 due to security concerns, among others.
Among the eight questions Almond set out are those that address transparency, individual rights, compliance, security risks and more:
- What is your lawful basis for processing personal data?
- Are you a controller, joint controller or a processor?
- Have you prepared a Data Protection Impact Assessment (DPIA)?
- How will you ensure transparency?
- How will you mitigate security risks?
- How will you limit unnecessary processing?
- How will you comply with individual rights requests?
- Will you use generative AI to make solely automated decisions?
When answering these criteria, AI developers need to identify and confirm:
- They are processing data lawfully, such as via legitimate interests or consent
- AI developers must “assess and mitigate any data protection risks,” via the DPIA process
- Information about any processing must remain public in most cases
- Cybersecurity must be considered, such as potential “model inversion and membership inference, data poisoning and other forms of adversarial attacks”
- Data collection should be limited to what is necessary
- The processes must comply with the UK GDPR
The Future of Life Institute’s open letter proposed a “pause,” or time to think over the summer without having to rush into releasing the next iteration of GPT. “Society has hit pause on other technologies with potentially catastrophic effects on society,” the letter reads. “We can do so here. Let’s enjoy a long AI summer, not rush unprepared into a fall.”
For further information on compliance, the UK ICO pointed AI Developers to its updated Guidance on AI and Data Protection and risk toolkit. For any other questions, it is recommended that developers contact the UK ICO directly.
