Desafíos actuales de la Inteligencia Artificial

48 Desafíos actuales de la Inteligencia Artificial that special category data is broader than just information about a person’s racial or ethnic origin.” 89 The European Court of Justice (CJEU) decided in the Case C-184/20 90 that “if an organisation can infer or deduce special category data, the information supporting that inference should also be treated as special category data In a machine learning context.” 91 This ruling implies that proxy variables may be qualified as special category data under the GDPR. 92 When it comes to generative AI, since it typically generates outputs unrelated to individ- uals’ personal information, it is unlikely that this provision would apply to generative AI. For instance, if content produced by generative AI is racist or homophobic but not specifically tied to an individual, it would not fall under the scope of the GDPR. However, if the content is related to an individual, Article 9 of the GDPR may be breached, as providers often cannot invoke the exemptions outlined in Article 9(2) of the GDPR. The EU AI Act, specifying the relationship of the data minimization principle and data governance obligations under its Article 10(5), stipulates that the providers of AI systems may exceptionally process special categories of personal data, but only to the extent that it is strict- ly necessary for the purposes of ensuring bias monitoring, detection, and correction related to these high-risk AI systems, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons, such as pseudonymization or encryption. According to Article 6(1)(f) of the GDPR, legitimate interest might serve as a lawful ground for processing to avoid biased data and discrimination. However, this legitimate interest alone is not sufficient, as it must also meet the exemption requirements under Article 9(2) of the GDPR, which is not al- ways feasible 93 Article 10(5) of the EU AI Act might be invoked as an exemption under Article 9(2)(g) of the GDPR; however, ensuring safeguards for the data subject’s fundamental rights could be challenging, especially when processing large amounts of special categories of data. 3. CONCLUSIONS Overall, the EU AI Act and the GDPR follow similar regulatory objectives, aiming to protect individuals’ rights and ensure ethical practices in technology and data use however, there are some tensions between them that need careful navigation. In cases of overlap, statutory provisions must be interpreted and applied with special consideration. However, such an interpretation may result in different understandings and bring about legal uncertainty, which could compromise the applicability of these two regulations. Therefore, a harmonized guideline is necessary for coherent and effective application. 89 ‘Key Issue 6: Interplay with GDPR - EU AI Act’. 90 ECJ, Case C-184/20, ECLI:EU:C:2022:601 91 ‘Key Issue 6: Interplay with GDPR - EU AI Act’. 92 ‘Key Issue 6: Interplay with GDPR - EU AI Act’. 93 ‘International: The interplay between the AI Act and the GDPR - AI series part 1’.

RkJQdWJsaXNoZXIy NTEwODM=