Take-Aways (AI)
  • Data pro­tec­tion super­vi­so­ry aut­ho­ri­ties are given access to docu­ments that must be crea­ted to com­ply with the AI Regulation.
  • You can request tech­ni­cal inve­sti­ga­ti­ons by mar­ket sur­veil­lan­ce aut­ho­ri­ties for AI and will be infor­med about serious incidents.
  • High-risk AI systems must be regi­stered in an EU data­ba­se; non-public regi­stra­ti­ons can be view­ed by super­vi­so­ry authorities.
  • Data pro­tec­tion super­vi­so­ry aut­ho­ri­ties must be invol­ved and report­ing obli­ga­ti­ons must be pro­vi­ded for real labo­ra­to­ries with per­so­nal data and for bio­me­tric remo­te identification.

The Ger­man Fede­ral Com­mis­sio­ner for Data Pro­tec­tion and Free­dom of Infor­ma­ti­on (BfDI; the data pro­tec­tion super­vi­so­ry aut­ho­ri­ty for fede­ral public bodies) has sum­ma­ri­zed the key points of the AI Act in a publication.

Much is not new, but the comm­ents on the role of the data pro­tec­tion super­vi­so­ry aut­ho­ri­ties are interesting:

As aut­ho­ri­ties respon­si­ble for the pro­tec­tion of fun­da­men­tal rights, they recei­ve Access to docu­ments requi­red for the ful­fill­ment of their tasks, which must be crea­ted to com­ply with the AI Regu­la­ti­on. The data pro­tec­tion super­vi­so­ry aut­ho­ri­ties are also sup­port­ed in their exi­sting super­vi­so­ry acti­vi­ties by, if neces­sa­ry, Request tech­ni­cal inve­sti­ga­ti­ons by the mar­ket sur­veil­lan­ce aut­ho­ri­ties for AI can. In addi­ti­on, they are also Reports of serious inci­dents to be infor­med. Some high-risk AI systems must in prin­ci­ple be noti­fi­ed by the pro­vi­ders in an EUData­ba­se be regi­stered. The­se regi­stra­ti­ons are not public in cer­tain cases, but the data pro­tec­tion super­vi­so­ry aut­ho­ri­ties are allo­wed to view them.

A fur­ther addi­ti­on is plan­ned for the super­vi­si­on of sta­te law enforce­ment aut­ho­ri­ties. For exam­p­le, the docu­men­ta­ti­on of the use of bio­me­tric remo­te iden­ti­fi­ca­ti­on systems must be dis­c­lo­sed to the com­pe­tent data pro­tec­tion super­vi­so­ry aut­ho­ri­ty upon request. In addi­ti­on, sum­ma­ri­zed annu­al reports on the use of bio­me­tric remo­te iden­ti­fi­ca­ti­on systems must be sub­mit­ted to the data pro­tec­tion super­vi­so­ry authorities.

A fur­ther task for the data pro­tec­tion super­vi­so­ry aut­ho­ri­ties ari­ses in the con­text of real-world labo­ra­to­ries, which are pro­vi­ded for in the AI Regu­la­ti­on to pro­mo­te inno­va­ti­on. Real-world labo­ra­to­ries are inten­ded to pro­vi­de a con­trol­led envi­ron­ment that faci­li­ta­tes the deve­lo­p­ment, trai­ning, test­ing and vali­da­ti­on of inno­va­ti­ve AI systems for a limi­t­ed peri­od of time. If per­so­nal data is pro­ce­s­sed in such a real-world labo­ra­to­ry, the data pro­tec­tion super­vi­so­ry aut­ho­ri­ties must be invol­ved.

The­re are fur­ther expl­ana­ti­ons on the com­plex super­vi­so­ry struc­tu­re, which is basi­cal­ly regu­la­ted on a sec­to­ral basis in that the com­pe­tent mar­ket sur­veil­lan­ce aut­ho­ri­ties of the Mem­ber Sta­tes have a super­vi­so­ry func­tion. Howe­ver, it is still unclear who is respon­si­ble for AI systems with a gene­ral pur­po­se and for high-risk AI systems in the are­as of cri­ti­cal infras­truc­tu­re, edu­ca­ti­on and trai­ning, employee manage­ment and basic pri­va­te ser­vices and public services.