HB Ad Slot
HB Mobile Ad Slot
Under the GDPR, are companies that transmit personal information to AIs as part of ‘prompts’ acting as controllers or processors?
Tuesday, August 1, 2023

Data is typically added to an AI to explain a problem, situation, or request (“input data”). Some AI providers, particularly those that provide natural language or large language models, refer to “prompts” as a subset of input data that describes the instructions that have been provided to the AI model (i.e., “please summarize the following ten documents”) as opposed to other types of input data that the user intends the AI will leverage (i.e., the ten documents that the AI is being asked to summarize).

There are a variety of different scenarios where an organization might consider including personal information in a prompt. These include things such as asking an AI to analyze customer transactions, prepare reports, classify consumers into certain purchasing groups or segments, or assigning probability scores to predict some aspect of an individual’s behavior (e.g., propensity to purchase, likelihood to be retained as an employee, etc.). Some organizations have also considered using AI in other ways that may impact individuals, like making pricing decisions or determining if an individual qualifies for an open job position.

Whether an organization that puts personal information in an AI prompt or provides the AI access to personal information as part of input data is a controller or a processor depends on the degree to which the organization determines the purpose for which the AI will be used and what personal information will be included in the prompt. The following chart discusses these variables in the context of using an AI to process personal information.

 

HB Ad Slot
HB Ad Slot
HB Mobile Ad Slot
HB Ad Slot
HB Mobile Ad Slot
 
NLR Logo
We collaborate with the world's leading lawyers to deliver news tailored for you. Sign Up to receive our free e-Newsbulletins

 

Sign Up for e-NewsBulletins