


Tightening regulations, in addition to the geopolitical tensions and current circumstances in the world, keep information security high on the leadership agenda. Leaking information security is the CEO’s problem more than anyone else’s, as we have recently seen in Finland, where an executive received a suspended jail term for violating the GDPR. It is the top executives who ultimately take responsibility.
Let’s not forget that the legal implications are not the only consequences – a firm leaking sensitive personal data while neglecting to fix information security problems is deemed to lose customers and rapidly go bankrupt. This, of course, will have an impact on everyone on the payroll.
The European Commission will complement the cyber security regulatory framework with new legislative acts, including revamped networks and information systems directive, NIS2, and digital operational resilience act, DORA. Artificial intelligence will also receive a dedicated EU regulation, namely EU AI Act. Currently it is in the proposal stage and under review in the member states.
The ethos of the AI Act resembles that of the GDPR. It is regulating AI from the data protection standpoint and complements the GDPR this way. The EU seems to have chosen its approach to AI as one placing human rights in the center. While it remains to be seen how this approach works in the competitive global AI market, it does require actions from organizations utilizing or planning to utilize AI based solutions, or provide AI based services or products within the EU.
“Trying to just prevent the use of generative AI leads to shadow use – therefore, a better way may be to allow the use while providing governance and secure environments.”
Why is data protection an important aspect of AI? AI solutions are often based on vast amounts of personal data. This does not only expose risks relating to the proper use of the data but also makes it an attractive target for adversaries. It is likely that AI systems used in sectors such as insurance are considered high-risk, as defined by the AI Act, and hence will require extra measures.
Data breaches are not the only information security risks with AI. There are others more AI specific, including e.g. model poisoning, whereby an AI model is compromised with bad data. A special case is generative AI, such as ChatGPT. Many organizations are keen to utilize these solutions but there are risks, such as those relating to intellectual property rights and information leakages.
Trying to just prevent the use of generative AI leads to shadow use – therefore, a better way may be to allow the use while providing governance and secure environments. Whereas the focus has previously been on defining AI’s ethical principles, the efforts are now steered to governance mechanisms. Standardized frameworks are only evolving, but some best practices can already be found. A useful starting point is identifying the risk and applying governance activities accordingly. Explainability and transparency are key concepts, as well as keeping a human in the loop.
I argue many regulated sectors, such as financial services industry, are quite well positioned for tightening cyber regulations. However, the AI Act may require some extra efforts. The information asymmetry between data science teams and management is usually significant and hence adequate governance methods are required.
This is not to say that the utilization of AI should be prevented. AI solutions, such as generative AI, will have a positive impact on productivity and they may even have societal significance. Therefore, I encourage to better understand them and take the appropriate measures to provide those solutions securely and responsibly.