Privacy

Don’t rush generative AI apps to market without tackling privacy risks, warns UK watchdog

Comment

privacy please
Image Credits: Josh hallett (opens in a new window) / Flickr (opens in a new window) under a CC BY 2.0 (opens in a new window) license.

The UK’s data protection watchdog has fired its most explicit warning shot yet at generative AI developers — saying it expects them to address privacy risks before bringing their products to market.

In a blog post trailing remarks from the Information Commissioner’s Office’s (ICO) exec director of regulatory risk, Stephen Almond, will make at a conference later today the watchdog has warned against developers rushing to adopt the powerful AI technology without proper due diligence on privacy and data protection risks.

“We will be checking whether businesses have tackled privacy risks before introducing generative AI — and taking action where there is risk of harm to people through poor use of their data. There can be no excuse for ignoring risks to people’s rights and freedoms before rollout,” Almond is slated to warn.

He will also instruct businesses operating in the UK market that they will need to show the ICO “how they’ve addressed the risks that occur in their context — even if the underlying technology is the same”.

This means the ICO will be considering the context associated with an application of generative AI technology, with likely greater compliance expectations for health apps using a generative AI API, for example, vs retail-focused apps. (tl;dr this sort of due diligence ain’t rocket science but don’t expect to hide behind ‘we’re just using OpenAI’s API so didn’t think we needed to consider privacy when we added an AI chatbot to enhance our sexual health clinic finder app’ type line… )

“Businesses are right to see the opportunity that generative AI offers, whether to create better services for customers or to cut the costs of their services. But they must not be blind to the privacy risks,” Almond will also say, urging developers to: “Spend time at the outset to understand how AI is using personal information, mitigate any risks you become aware of, and then roll out your AI approach with confidence that it won’t upset customers or regulators.”

For a sense of what this type of risk could cost if improperly managed, the UK’s data protection legislation bakes in fines for infringements that can hit up to £17.5 million or 4% of the total annual worldwide turnover in the preceding financial year, whichever is higher.

A patchwork of AI rules

As an established regulatory body the ICO has been tasked with developing privacy and data protection guidance for use of AI under an approach the government set out in its recent AI white paper.

The government has said it favors a set of “flexible” principles and context-specific guidance produced being by sector-focused and cross-cutting watchdogs for regulating AI — such as the competition authority, financial conduct authority, Ofcom and indeed the ICO — rather than introducing a dedicated legislative framework for steering development of AI such as is on the table over the English Channel in the European Union.

This means there will be a patchwork of expectations emerging as UK watchdog develop and flesh out guidance in the coming weeks and months. (The UK’s Competition and Markets Authority announced a review of generative AI last month; while, earlier this month, Ofcom offered some thoughts on what generative AI might mean for the comms sector which included detail on how it’s monitoring developments with a view to assessing potential harms.)

Shortly after the UK white paper was published the ICO’s Almond published a list of eight questions he said generative AI developers (and users) should be asking themselves — including core issues like what their legal basis for processing personal data is; how they will meet transparency obligations; and whether they’ve prepared a data protection impact assessment.

Today’s warning is more explicit. The ICO is plainly stating that it expects businesses to not just take note of its recommendations but act on them. Any that ignore that guidance and seek to rush apps to market will be generating more regulatory risk for themselves — including the potential for substantial fines.

It also builds on a tech-specific warning the watchdog made last fall when it singled out so-called “emotion analysis” AIs as too risky for anything other than purely trivial use-cases (such as kids party games), warning this type of “immature” biometrics technology carries greater risks for discrimination than potential opportunities.

“We are yet to see any emotion AI technology develop in a way that satisfies data protection requirements, and have more general questions about proportionality, fairness and transparency in this area,” the ICO wrote then.

While the UK government has signaled it doesn’t believe dedicated legislation or an exclusively AI-focused oversight body are needed to regulate the technology, it has, more recently, been talking up the need for AI developers to center safety. And earlier this month prime minister Rishi Sunak announced a plan to host a global summit on AI safety this fall, seemingly to focus on fostering research efforts. The idea quickly won buy-in from a number of AI giants.

UK’s antitrust watchdog announces initial review of generative AI

UK to avoid fixed rules for AI – in favor of ‘context-specific guidance’

More TechCrunch

To give AI-focused women academics and others their well-deserved — and overdue — time in the spotlight, TechCrunch has been publishing a series of interviews focused on remarkable women who’ve contributed to…

Women in AI: Rep. Dar’shun Kendrick wants to pass more AI legislation

We took the pulse of emerging fund managers about what it’s been like for them during these post-ZERP, venture-capital-winter years.

A reckoning is coming for emerging venture funds, and that, VCs say, is a good thing

It’s been a busy weekend for union organizing efforts at U.S. Apple stores, with the union at one store voting to authorize a strike, while workers at another store voted…

Workers at a Maryland Apple store authorize strike

Alora Baby is not just aiming to manufacture baby cribs in an environmentally friendly way but is attempting to overhaul the whole lifecycle of a product

Alora Baby aims to push baby gear away from the ‘landfill economy’

Bumble founder and executive chair Whitney Wolfe Herd raised eyebrows this week with her comments about how AI might change the dating experience. During an onstage interview, Bloomberg’s Emily Chang…

Go on, let bots date other bots

Welcome to Week in Review: TechCrunch’s newsletter recapping the week’s biggest news. This week Apple unveiled new iPad models at its Let Loose event, including a new 13-inch display for…

Why Apple’s ‘Crush’ ad is so misguided

The U.K. Safety Institute, the U.K.’s recently established AI safety body, has released a toolset designed to “strengthen AI safety” by making it easier for industry, research organizations and academia…

U.K. agency releases tools to test AI model safety

AI startup Runway’s second annual AI Film Festival showcased movies that incorporated AI tech in some fashion, from backgrounds to animations.

At the AI Film Festival, humanity triumphed over tech

Rachel Coldicutt is the founder of Careful Industries, which researches the social impact technology has on society.

Women in AI: Rachel Coldicutt researches how technology impacts society

SAP Chief Sustainability Officer Sophia Mendelsohn wants to incentivize companies to be green because it’s profitable, not just because it’s right.

SAP’s chief sustainability officer isn’t interested in getting your company to do the right thing

Here’s what one insider said happened in the days leading up to the layoffs.

Tesla’s profitable Supercharger network is in limbo after Musk axed the entire team

StrictlyVC events deliver exclusive insider content from the Silicon Valley & Global VC scene while creating meaningful connections over cocktails and canapés with leading investors, entrepreneurs and executives. And TechCrunch…

Meesho, a leading e-commerce startup in India, has secured $275 million in a new funding round.

Meesho, an Indian social commerce platform with 150M transacting users, raises $275M

Some Indian government websites have allowed scammers to plant advertisements capable of redirecting visitors to online betting platforms. TechCrunch discovered around four dozen “gov.in” website links associated with Indian states,…

Scammers found planting online betting ads on Indian government websites

Around 550 employees across autonomous vehicle company Motional have been laid off, according to information taken from WARN notice filings and sources at the company.  Earlier this week, TechCrunch reported…

Motional cut about 550 employees, around 40%, in recent restructuring, sources say

The company is describing the event as “a chance to demo some ChatGPT and GPT-4 updates.”

OpenAI’s ChatGPT announcement: What we know so far

The deck included some redacted numbers, but there was still enough data to get a good picture.

Pitch Deck Teardown: Cloudsmith’s $15M Series A deck

Unlike ChatGPT, Claude did not become a new App Store hit.

Anthropic’s Claude sees tepid reception on iOS compared with ChatGPT’s debut

Welcome to Startups Weekly — Haje‘s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. Look,…

Startups Weekly: Trouble in EV land and Peloton is circling the drain

Scarcely five months after its founding, hard tech startup Layup Parts has landed a $9 million round of financing led by Founders Fund to transform composites manufacturing. Lux Capital and Haystack…

Founders Fund leads financing of composites startup Layup Parts

AI startup Anthropic is changing its policies to allow minors to use its generative AI systems — in certain circumstances, at least.  Announced in a post on the company’s official…

Anthropic now lets kids use its AI tech — within limits

Zeekr’s market hype is noteworthy and may indicate that investors see value in the high-quality, low-price offerings of Chinese automakers.

The buzziest EV IPO of the year is a Chinese automaker

Venture capital has been hit hard by souring macroeconomic conditions over the past few years and it’s not yet clear how the market downturn affected VC fund performance. But recent…

VC fund performance is down sharply — but it may have already hit its lowest point

The person who claims to have 49 million Dell customer records told TechCrunch that he brute-forced an online company portal and scraped customer data, including physical addresses, directly from Dell’s…

Threat actor says he scraped 49M Dell customer addresses before the company found out

The social network has announced an updated version of its app that lets you offer feedback about its algorithmic feed so you can better customize it.

Bluesky now lets you personalize main Discover feed using new controls

Microsoft will launch its own mobile game store in July, the company announced at the Bloomberg Technology Summit on Thursday. Xbox president Sarah Bond shared that the company plans to…

Microsoft is launching its mobile game store in July

Smart ring maker Oura is launching two new features focused on heart health, the company announced on Friday. The first claims to help users get an idea of their cardiovascular…

Oura launches two new heart health features

Keeping up with an industry as fast-moving as AI is a tall order. So until an AI can do it for you, here’s a handy roundup of recent stories in the world…

This Week in AI: OpenAI considers allowing AI porn

Garena is quietly developing new India-themed games even though Free Fire, its biggest title, has still not made a comeback to the country.

Garena is quietly making India-themed games even as Free Fire’s relaunch remains doubtful

The U.S.’ NHTSA has opened a fourth investigation into the Fisker Ocean SUV, spurred by multiple claims of “inadvertent Automatic Emergency Braking.”

Fisker Ocean faces fourth federal safety probe