5/16 (Thu.) 14:00 - 14:30 7F 701B

The privacy issues behind new AI generation

Since the advent of ChatGPT , generative AI has attracted everyone's attention. The sudden emergence of generative AI technologies has caught data protection regulators by surprise. As more countries investigate artificial intelligence companies like OpenAI, a clash between technological advances and privacy laws seems inevitable. For example, by March 2023, Italian data protection agency Garante stated that OpenAI's massive collection and storage of personal data to train chatbots lacked any legal basis, and accused OpenAI of failing to implement an age verification mechanism that required users to be over 13 years old. And after corrective measures operated by OpenAI, Italy reopened the ChatGPT service on April 28.

From OWASP top 10 LLM application , OpenAI bug bounty and the popular prompt injection, there are security issues worth concerning in this area. But we also find a flaw in the privacy definition between the 3 popular AI module with the same question about personal information. As lots of professionals mentioned, privacy issue is also a critical issue in this area.

This situation underscores the need for AI developers to reevaluate their data collection and use methods while complying with privacy laws. The privacy issues and considerations include:

  • General principles of data collection and processing: such as informed consent, limiting the storage time of data, ensuring that data is only used for specific purposes, and strengthening data security.
  • AI may be defined as Automated individual decision-making
  • Privacy by Design
  • Clarify role of Controller and Processor: It is popular to embed ChatGPT or other AI tools into third parties’ services or products, such as customer service chatbot. The third party using AI tool may become a data controller under GDPR while the OpenAI becomes data processor. Each of them would have different functions and burden protection responsibility.

In the last part , this paper also reviews the privacy issues from technology and different data protection laws under different jurisdiction.

Vic Huang
SPEAKER
Member
UCCU Hacker

TOPIC / TRACK
AI Security Forum

LOCATION
Taipei Nangang Exhibition Center, Hall 2
7F 701B

LEVEL
Intermediate Intermediate sessions focus on cybersecurity architecture, tools, and practical applications, ideal for professionals with a basic understanding of cybersecurity.

SESSION TYPE
Breakout Session

LANGUAGE
Chinese

SUBTOPIC
Privacy
AI
AI Security