Why the AI we rely on can’t get privacy right (yet)

While artificial intelligence (AI) powered technologies are now commonly appearing in many digital services we interact with on a daily basis, an often neglected truth is that few companies are actually building the underlying AI technology.
A good example of this is facial recognition technology, which is exceptionally complex to build and requires millions upon millions of facial images to train the machine learning models.
Consider all of the facial recognition based authentication and verification components of all the different services you use. Each service did not reinvent the wheel when making facial recognition available in their service; instead, they integrated with an AI technology provider. An obvious case of this is iOS services that have integrated FaceID, for example, to quickly log into your bank account. Less obvious cases are perhaps where you are asked to verify your identity by uploading images of your face and your identity document to a cloud service for verification, for example if you are looking to rent a car or open up a new online bank account.
We are also hearing more and more about governments using facial recognition in public forums to identify individuals in a crowd, but it is not as though each government is building their own facial recognition technology. They are purchasing the technology from an AI technology vendor.
Why is this significant? It surely makes sense for a company to rely on the expertise of an AI technology vendor rather than trying to build complicated AI models themselves, which will very likely not reach the necessary performance levels.
The significance is that, due to the fact that these AI services are built by one company and deployed by many others, the chain of responsibility to meet privacy requirements often collapses.
If a person has no direct relationship with the company that built the AI technology that is processing their personal data, then what hope does that person have to understand how their personal data is being used, how that data usage affects them, and how they can control that data usage?
What happens in practice is that the AI technology vendor seeks to tell their clients (e.g., the companies licensing the technology) how their technology works, and then they contractually require their clients to provide all required notices and to obtain all required consents from the people who are exposed to the AI technology.
Perhaps this model makes sense as it is a commonly established legal practice in the AI industry.


