BELGIUM Trends and Developments Contributed by: Benjamin Docquir and Margo Cornette, Osborne Clarke
Principles under the AIA and the GDPR The GDPR sets out seven data protection princi - ples: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality. The AIA outlines general principles that apply to all AI systems and specific obligations to imple - ment these principles in specific ways. These principles are influenced by the OECD AI Prin - ciples and the seven ethical principles for AI developed by the High-Level Expert Group on Artificial Intelligence (HLEG-AI). Recital 27 refers to the following principles: human agency and oversight, technical robustness and safety, pri - vacy and data governance, transparency, diver - sity, non-discrimination, fairness and social and environmental wellbeing. These principles are further concretised in various articles of the AIA: Article 10 prescribes data governance practices for high-risk AI systems, Article 13 addresses transparency, Articles 14 and 26 introduce human oversight and monitoring requirements and Article 27 mandates fundamental rights impact assessments for certain high-risk AI systems. Human oversight and automated decision- making The provisions related to human oversight in the AIA and automated decision-making in the GDPR are important, especially in the healthcare sector, where the integration of AI systems has significantly transformed decision-making pro - cesses. AI systems in healthcare can be catego - rised as fully automated and partially automated decision-making tools, each with distinct levels of human oversight. Fully automated decision- making systems function independently, mak - ing decisions without human intervention. For example, an AI insulin management system autonomously adjusts insulin delivery by ana -
lysing data from sensors and fitness trackers, geolocation data from smartphones and hand- gesture sensing data. The system identifies patterns in individual behaviour and regulates insulin levels accordingly. In contrast, partially automated medical decision systems involve AI systems that make initial decisions but require human input in specific situations. For exam - ple, an AI system that monitors cardiac patients continuously analyses personalised heart rate data collected from wearable or implantable devices. When it detects arrhythmias, it auto - matically transmits the relevant information to the patient’s cardiologist, who then decides on the appropriate course of action. The below only provides a general overview of the different pro - visions. Article 22 of the GDPR grants data subjects the right not to be subjected to decisions based solely on automated processing, including profil - ing, which produce legal effects or similarly sig - nificant effects. The only situations where such automated decision-making is allowed are those in which it is necessary for entering into or per - forming a contract, when there is authorisation by European or member state law or when there is explicit consent from the data subject. In any case, measures must be implemented to protect fundamental rights, such as ensuring the right for meaningful human intervention on the part of the data controller to express his or her point of view and contest the decision. Similarly, the AIA aims to protect fundamental rights and freedoms by ensuring appropriate human oversight and intervention, known as the “human-in-the-loop” effect. Indeed, Article 14 of the AIA requires that high-risk AI systems be designed and developed to allow for effective human overview during their use, including appropriate human-machine interface tools. Further, Article 26(1) requires deployers of AI systems to implement technical
35
CHAMBERS.COM
Powered by FlippingBook