- Data protection supervisory authorities are given access to documents that must be created to comply with the AI Regulation.
- You can request technical investigations by market surveillance authorities for AI and will be informed about serious incidents.
- High-risk AI systems must be registered in an EU database; non-public registrations can be viewed by supervisory authorities.
- Data protection supervisory authorities must be involved and reporting obligations must be provided for real laboratories with personal data and for biometric remote identification.
The German Federal Commissioner for Data Protection and Freedom of Information (BfDI; the data protection supervisory authority for federal public bodies) has summarized the key points of the AI Act in a publication.
Much is not new, but the comments on the role of the data protection supervisory authorities are interesting:
As authorities responsible for the protection of fundamental rights, they receive Access to documents required for the fulfillment of their tasks, which must be created to comply with the AI Regulation. The data protection supervisory authorities are also supported in their existing supervisory activities by, if necessary, Request technical investigations by the market surveillance authorities for AI can. In addition, they are also Reports of serious incidents to be informed. Some high-risk AI systems must in principle be notified by the providers in an EUDatabase be registered. These registrations are not public in certain cases, but the data protection supervisory authorities are allowed to view them.
A further addition is planned for the supervision of state law enforcement authorities. For example, the documentation of the use of biometric remote identification systems must be disclosed to the competent data protection supervisory authority upon request. In addition, summarized annual reports on the use of biometric remote identification systems must be submitted to the data protection supervisory authorities.
A further task for the data protection supervisory authorities arises in the context of real-world laboratories, which are provided for in the AI Regulation to promote innovation. Real-world laboratories are intended to provide a controlled environment that facilitates the development, training, testing and validation of innovative AI systems for a limited period of time. If personal data is processed in such a real-world laboratory, the data protection supervisory authorities must be involved.
There are further explanations on the complex supervisory structure, which is basically regulated on a sectoral basis in that the competent market surveillance authorities of the Member States have a supervisory function. However, it is still unclear who is responsible for AI systems with a general purpose and for high-risk AI systems in the areas of critical infrastructure, education and training, employee management and basic private services and public services.