EU Act ‘must empower those affected by AI systems to take action’

Independent research organistion the Ada Lovelace Institute has published a series of proposals on how the European Union (EU) can amend its forthcoming Artificial Intelligence Act (AIA) to empower those affected by the technology on both an individual and collective level.
The proposed amendments also aim to expand and reshape the meaning of “risk” within the regulation, which the Institute has said should be based on “reasonably foreseeable” purpose and extend beyond its current focus on individual rights and safety to also include systemic and environmental risks.
“Regulating AI is a difficult legal challenge, so the EU should be congratulated for being the first to come out with a comprehensive framework,” said Alexandru Circiumaru, European public policy lead at the Ada Lovelace Institute. “However, the current proposals can and should be improved, and there is an opportunity for EU policymakers to significantly strengthen the scope and effectiveness of this landmark legislation.”
As it currently stands, the AIA, which was published by the European Commission (EC) on 21 April 2021, adopts a risk-based, market-led approach to regulating the technology, focusing on establishing rules around the use of “high-risk” and “prohibited” AI practices.
However, digital civil rights experts and organisations have claimed that the regulatory proposal is stacked in favour of organisations – both public and private – that develop and deploy AI technologies, which are essentially being tasked with box-ticking exercises, while ordinary people are offered little in the way of protection or redress.
They claimed that ultimately, the proposal will do little to mitigate the worst abuses of AI technology and will essentially act as a green light for a number of high-risk use cases because of its emphasis on technical standards and how it approaches mitigating risk.
Published on 31 March 2022, the Ada Lovelace Institute’s proposed amendments to deal with these issues include recognising “affected persons” as distinct actors in the text of the AIA, which currently only recognises “providers” – those putting an AI system on the market – and “users” – those deploying the AI system.
It said the AIA should also be used to create a comprehensive remedies framework around “affected persons”, including a right for individuals to bring complaints, a right to bring collective action, and a right to information to supplement what is already provided under the General Data Protection Regulation (GDPR).
“The EU AI Act, once adopted, will be the first comprehensive AI regulatory framework in the world. This makes it a globally significant piece of legislation with historic impact far beyond its legal jurisdiction,” said Imogen Parker, associate director at the Institute.
“The stakes for everyone are high with AI, which is why it is so vital the EU gets this right and makes sure the Act truly works for people and society.”
The Ada Lovelace Institute further recommends renaming “users” as “deployers” to further highlight the distinction between those using the tech and those it is being used on, as well as determining risk based on the system’s “reasonably foreseeable purpose“, rather than the “intended purpose” as defined by the provider itself.
“The current approach may not offer adequate clarity about when a deployer has moved beyond the intended purpose,” the Institute said. “Changing the language to ‘reasonably foreseeable purpose’ would require providers to consider more fully the range of potential uses for their technology. It would also encourage greater clarity in setting the limits of the systems that providers put on the market as to how far deployers can experiment with an AI system without incurring extra obligations.


