Using sensitive data to de-bias AI systems: Article 10(5) of the EU AI Act

摘要(出版方所载原文摘要) In June 2024, the EU AI Act came into force. The AI Act includes obligations for the provider of an AI system. Article 10 of the AI Act includes a new obligation for providers to evaluate whether their training, validation and testing datasets meet certain quality criteria, including an appropriate examination of biases in the datasets and correction measures. With the obligation comes a new provision in Article 10(5) AI Act, allowing providers to collect sensitive data to fulfil the obligation. Article 10(5) AI Act aims to prevent discrimination. In this paper, I investigate the scope and implications of Article 10(5) AI Act. The paper primarily concerns European Union law, but may be relevant in other parts of the world, as policymakers aim to regulate biases in AI systems. ...

2026年9月25日 · 1 分钟 · Marvin van Bekkum(荷兰拉德堡德大学 Radboud University)

Rebuilding the pyramid: The AI Act's risk-based approach using a binary decision diagram

摘要(出版方所载原文摘要) The risk-based approach of the AI Act (AIA) results in a complex normative structure, in which the applicable subset of rules for a specific AI system is determined by the general scope of application and the classification of the system into particular risk levels. A pyramid of risks, a widely accepted explanation of the risk-based approach proposed by the European Commission, fails to provide a comprehensive classification process and does not accurately reflect the risk levels (either directly or indirectly) recognized in the AIA or the relation between classification criteria. This paper proposes a corrective solution to rebuild the pyramid of risks. Given that each AI system must be classified into one risk level and the AIA assigns a specific subset of rules to each risk level, an adaptation of the Commission ’ s risk levels was necessary. Two types of exceptions are included in the list of prohibited AI practices, which significantly impact the classification process. The exception stricto sensu (in a strict sense) is the result of a balancing of interests, whereas the exception lato sensu (in a broader sense) is due to the absence of excessive regulatory risks. The transparency requirements, identified by the pyramid as a “ limited-risk level, ” operate in parallel with the risk-based approach and do not constitute an independent risk level. Furthermore, as the AIA assigns a specific subset of rules to AI systems used in critical areas that do not pose significant risks, it is necessary to recognize a separate risk level (non-high risk). By analyzing the pyramid of risks, this study suggests representing the classification process as a binary decision diagram. This ensures that the risk-based approach is clearly defined and can help regulators and regulatees classify AI systems in accordance with the AIA. ...

2026年9月25日 · 2 分钟 · Gustavo Gil Gasiola(德国卡尔斯鲁厄理工学院 KIT)

Permitted by design? Article 10(5) AIA, sensitive data, and the legal illusion of bias correction

摘要:该文官方摘要暂未公开,本页暂不载摘要原文;取得后补录。 出处:Permitted by design? Article 10(5) AIA, sensitive data, and the legal illusion of bias correction,International Data Privacy Law, Vol. 16, Issue 1 (2026)。 作者:Arnoud Engelfriet(荷兰阿姆斯特丹自由大学 VU Amsterdam) 收录:SSCI 收录(Law 类);据 WoS Journal Info 聚合页核验。 直链:10.1093/idpl/ipaf035 (DOI 解析;题录经 Crossref API 逐条比对一致) 主题:欧盟人工智能法与敏感数据治理

2026年9月25日 · 1 分钟 · Arnoud Engelfriet(荷兰阿姆斯特丹自由大学 VU Amsterdam)

Assessing the implementation of China's personal information protection law: a two-year review

摘要:该文官方摘要暂未公开,本页暂不载摘要原文;取得后补录。 出处:Assessing the implementation of China’s personal information protection law: a two-year review,International Data Privacy Law, Vol. 15, Issue 1 (2025), pp. 18 起。 作者:Guosong Shao、Qi Huang、Qin Xiang、Chengxin Peng 收录:SSCI 收录(Law 类);据 WoS Journal Info 聚合页核验。 直链:10.1093/idpl/ipae022 (DOI 解析;题录经 Crossref API 逐条比对一致) 主题:中国数据保护与 AI 训练数据的法律基础

2026年9月25日 · 1 分钟 · Guosong Shao、Qi Huang、Qin Xiang、Chengxin Peng

How the Legal Basis for AI Training Is Framed in Data Protection Guidelines and Interventions: Comparative Perspectives and the Prospect of Global Convergence

摘要:该文官方摘要已随文上线(见下「直链」Oxford Academic 文章页),本页待取件后补录原文。 出处:How the Legal Basis for AI Training Is Framed in Data Protection Guidelines and Interventions: Comparative Perspectives and the Prospect of Global Convergence,International Data Privacy Law, Vol. 16, Issue 2 (2026)。 作者:Wenlong Li(浙江大学光华法学院)、Yueming Zhang(比利时根特大学)、Qingqing Zheng、Aolan Li 收录:SSCI 收录(Law 类);据 WoS Journal Info 聚合页核验。 直链:10.1093/idpl/ipaf032 (DOI 解析;题录经 Crossref API 逐条比对一致) 主题:中国数据保护与 AI 训练数据的法律基础

2026年9月25日 · 1 分钟 · Wenlong Li(浙江大学光华法学院)、Yueming Zhang(比利时根特大学)、Qingqing Zheng、Aolan Li

Same text, different meaning: China's risk-based approach to data protection

摘要(出版方所载原文摘要) This article analyzes the divergence between China’s Personal Information Protection Law (PIPL) and the EU’s General Data Protection Regulation (GDPR), despite their textual similarities. It argues that China’s approach to data protection is shaped by distinct domestic understandings of “risk,” rooted in past legislation, judicial practices, and social concerns. Using focal point theory, the authors identify three key dimensions of risk in China: large-scale participation, economic loss, and threats from third parties. These focal points explain why China’s risk-based approach prioritizes different enforcement goals than the GDPR. The article also shows how these differences manifest in several areas, including the definition of personal information, the regulation of automated decision-making, and the design of enforcement authorities. Ultimately, the article challenges the assumption that legal diffusion through the “Brussels Effect” leads to uniform global standards. Instead, it highlights how domestic cultural and institutional factors reshape transplanted laws, creating seemingly performative enforcement that reflects localized regulatory logics. ...

2026年9月25日 · 1 分钟 · Xiaodong Ding(中国人民大学)、Hao Huang(美国加州大学伯克利分校)、Zhengyu Shi、Yeliang Wang

AI-augmented government transformation: Organisational transformation and the sociotechnical implications of artificial intelligence in public administrations

摘要(出版方所载原文摘要) Implementing artificial intelligence (AI) in public settings requires a fundamental transformation of various social and technical aspects within public administration. However, the transformative efforts required for AI integration and use in government remain underexplored. This study introduces the concept of ‘AI-augmented government transformation,’ building on sociomateriality and sociotechnical theory, and develops a theoretical framework to explore this phenomenon. By applying this framework and drawing insights from expert interviews, we identify the strategic shifts and socio-technical adaptations essential for integrating AI into public administrations. Our analysis highlights the importance of opening the ‘black box’ of AI to gain a deep understanding of its underlying technologies and their materialities. The findings reveal complex interdependencies between AI materiality and the social and technical systems that public administrations must navigate. Specifically, AI, as a novel materiality, introduces new organizational dynamics, enhances employee capabilities, and alters operational routines and practices. These changes complement technical ones, such as upgrades and advancements in data collection and processing. By investigating the complexities of AI-augmented government transformation, this research offers novel and practical insights for policymakers and practitioners navigating the challenges and opportunities of AI integration. ...

2026年9月25日 · 2 分钟 · Luca Tangi、A. Paula Rodriguez Müller(欧盟委员会联合研究中心 JRC)、Marijn Janssen

AI as Governance

摘要(出版方所载原文摘要) Political scientists have had remarkably little to say about artificial intelligence (AI), perhaps because they are dissuaded by its technical complexity and by current debates about whether AI might emulate, outstrip, or replace individual human intelligence. They ought to consider AI in terms of its relationship with governance. Existing large-scale systems of governance such as markets, bureaucracy, and democracy make complex human relations tractable, albeit with some loss of information. AI’s major political consequences can be considered under two headings. First, we may treat AI as a technology of governance, asking how AI’s capacities to classify information at scale affect markets, bureaucracy, and democracy. Second, we might treat AI as an emerging form of governance in its own right, with its own particular mechanisms of representation and coordination. These two perspectives reveal new questions for political scientists, encouraging them to reconsider the boundaries of their discipline. ...

2026年9月25日 · 1 分钟 · Henry Farrell(美国约翰斯·霍普金斯大学 SAIS)

Governance of Generative AI

摘要(出版方所载原文摘要) The rapid and widespread diffusion of generative artificial intelligence (AI) has unlocked new capabilities and changed how content and services are created, shared, and consumed. This special issue builds on the 2021 Policy and Society special issue on the governance of AI by focusing on the legal, organizational, political, regulatory, and social challenges of governing generative AI. This introductory article lays the foundation for understanding generative AI and underscores its key risks, including hallucination, jailbreaking, data training and validation issues, sensitive information leakage, opacity, control challenges, and design and implementation risks. It then examines the governance challenges of generative AI, such as data governance, intellectual property concerns, bias amplification, privacy violations, misinformation, fraud, societal impacts, power imbalances, limited public engagement, public sector challenges, and the need for international cooperation. The article then highlights a comprehensive framework to govern generative AI, emphasizing the need for adaptive, participatory, and proactive approaches. The articles in this special issue stress the urgency of developing innovative and inclusive approaches to ensure that generative AI development is aligned with societal values. They explore the need for adaptation of data governance and intellectual property laws, propose a complexity-based approach for responsible governance, analyze how the dominance of Big Tech is exacerbated by generative AI developments and how this affects policy processes, highlight the shortcomings of technocratic governance and the need for broader stakeholder participation, propose new regulatory frameworks informed by AI safety research and learning from other industries, and highlight the societal impacts of generative AI. ...

2026年9月25日 · 2 分钟 · Araz Taeihagh(新加坡国立大学李光耀公共政策学院 LKYSPP)

Personal data controllers and device producers: Mind the gap

摘要(出版方所载原文摘要) It seemed well established that producing a smart device could not, by itself, render someone a personal data controller in the absence of subsequent influence over the processing operations (the influence thesis). In contrast, legal scholars have introduced a new interpretation of European data protection law that seeks to apply the General Data Protection Regulation (GDPR) to the processing operations of smart devices even if no entity influences the processing remotely after the release of the product. This approach classifies producers as personal data controllers for device-based processing (producer-controller thesis). The proponents of the producer-controller thesis highlight the increasing importance of smart devices that store data locally and the need for protecting consumers’ rights in that context. However, as this paper claims, the GDPR is not the proper legal instrument for addressing the safety standards of smart products that process data locally. These considerations relate to legislative texts that prescribe product requirements, such as the AI Act and the Cyber Resilience Act. On those grounds, the present work criticises the producer-controller thesis. As this paper concludes, expanding the concept of ‘controller’ to encompass producers of smart devices does not enhance the protection of the data subjects and does not fit within the current data protection framework of the European Union. ...

2026年9月25日 · 2 分钟 · Efstratios Koulierakis(希腊雅典大学法学院 NKUA 法律·信息学与人工智能实验室)