Privacy

Don’t rush generative AI apps to market without tackling privacy risks, warns UK watchdog

Comment

privacy please
Image Credits: Josh hallett (opens in a new window) / Flickr (opens in a new window) under a CC BY 2.0 (opens in a new window) license.

The UK’s data protection watchdog has fired its most explicit warning shot yet at generative AI developers — saying it expects them to address privacy risks before bringing their products to market.

In a blog post trailing remarks from the Information Commissioner’s Office’s (ICO) exec director of regulatory risk, Stephen Almond, will make at a conference later today the watchdog has warned against developers rushing to adopt the powerful AI technology without proper due diligence on privacy and data protection risks.

“We will be checking whether businesses have tackled privacy risks before introducing generative AI — and taking action where there is risk of harm to people through poor use of their data. There can be no excuse for ignoring risks to people’s rights and freedoms before rollout,” Almond is slated to warn.

He will also instruct businesses operating in the UK market that they will need to show the ICO “how they’ve addressed the risks that occur in their context — even if the underlying technology is the same”.

This means the ICO will be considering the context associated with an application of generative AI technology, with likely greater compliance expectations for health apps using a generative AI API, for example, vs retail-focused apps. (tl;dr this sort of due diligence ain’t rocket science but don’t expect to hide behind ‘we’re just using OpenAI’s API so didn’t think we needed to consider privacy when we added an AI chatbot to enhance our sexual health clinic finder app’ type line… )

“Businesses are right to see the opportunity that generative AI offers, whether to create better services for customers or to cut the costs of their services. But they must not be blind to the privacy risks,” Almond will also say, urging developers to: “Spend time at the outset to understand how AI is using personal information, mitigate any risks you become aware of, and then roll out your AI approach with confidence that it won’t upset customers or regulators.”

For a sense of what this type of risk could cost if improperly managed, the UK’s data protection legislation bakes in fines for infringements that can hit up to £17.5 million or 4% of the total annual worldwide turnover in the preceding financial year, whichever is higher.

A patchwork of AI rules

As an established regulatory body the ICO has been tasked with developing privacy and data protection guidance for use of AI under an approach the government set out in its recent AI white paper.

The government has said it favors a set of “flexible” principles and context-specific guidance produced being by sector-focused and cross-cutting watchdogs for regulating AI — such as the competition authority, financial conduct authority, Ofcom and indeed the ICO — rather than introducing a dedicated legislative framework for steering development of AI such as is on the table over the English Channel in the European Union.

This means there will be a patchwork of expectations emerging as UK watchdog develop and flesh out guidance in the coming weeks and months. (The UK’s Competition and Markets Authority announced a review of generative AI last month; while, earlier this month, Ofcom offered some thoughts on what generative AI might mean for the comms sector which included detail on how it’s monitoring developments with a view to assessing potential harms.)

Shortly after the UK white paper was published the ICO’s Almond published a list of eight questions he said generative AI developers (and users) should be asking themselves — including core issues like what their legal basis for processing personal data is; how they will meet transparency obligations; and whether they’ve prepared a data protection impact assessment.

Today’s warning is more explicit. The ICO is plainly stating that it expects businesses to not just take note of its recommendations but act on them. Any that ignore that guidance and seek to rush apps to market will be generating more regulatory risk for themselves — including the potential for substantial fines.

It also builds on a tech-specific warning the watchdog made last fall when it singled out so-called “emotion analysis” AIs as too risky for anything other than purely trivial use-cases (such as kids party games), warning this type of “immature” biometrics technology carries greater risks for discrimination than potential opportunities.

“We are yet to see any emotion AI technology develop in a way that satisfies data protection requirements, and have more general questions about proportionality, fairness and transparency in this area,” the ICO wrote then.

While the UK government has signaled it doesn’t believe dedicated legislation or an exclusively AI-focused oversight body are needed to regulate the technology, it has, more recently, been talking up the need for AI developers to center safety. And earlier this month prime minister Rishi Sunak announced a plan to host a global summit on AI safety this fall, seemingly to focus on fostering research efforts. The idea quickly won buy-in from a number of AI giants.

UK’s antitrust watchdog announces initial review of generative AI

UK to avoid fixed rules for AI – in favor of ‘context-specific guidance’

More TechCrunch

We received countless submissions to speak at this year’s Disrupt 2024. After carefully sifting through all the applications, we’ve narrowed it down to 19 session finalists. Now we need your…

Vote for your Disrupt 2024 Audience Choice favs

Co-founder and CEO Bowie Cheung, who previously worked at Uber Eats, said the company now has 200 customers.

Healthy growth helps B2B food e-commerce startup Pepper nab $30 million led by ICONIQ Growth

Booking.com has been designated a gatekeeper under the bloc’s Digital Markets Act (DMA), meaning the online travel agency will face regulation under the bloc’s market fairness and contestability framework —…

Booking latest to fall under EU market power rules

Featured Article

‘Got that boomer!’: How cyber-criminals steal one-time passcodes for SIM swap attacks and raiding bank accounts

Estate is an invite-only website that has helped hundreds of attackers make thousands of phone calls aimed at stealing account passcodes, according to its leaked database.

1 hour ago
‘Got that boomer!’: How cyber-criminals steal one-time passcodes for SIM swap attacks and raiding bank accounts

Website builder Squarespace is going private in an all-cash deal that values the company on an equity basis at $6.6 billion, or a $6.9 billion enterprise valuation. The acquiring company…

Permira is taking Squarespace private in $6.9 billion deal

AI-powered tools like OpenAI’s Whisper have enabled many apps to make transcription an integral part of their feature set for personal note-taking, and the space has quickly flourished as a…

Buymeacoffee’s founder has built an AI-powered voice note app

Airtel, India’s second-largest telco, is partnering with Google Cloud to develop and deliver cloud and GenAI solutions to Indian businesses.

Google partners with Airtel to offer cloud and genAI products to Indian businesses

To give AI-focused women academics and others their well-deserved — and overdue — time in the spotlight, TechCrunch has been publishing a series of interviews focused on remarkable women who’ve contributed to…

Women in AI: Rep. Dar’shun Kendrick wants to pass more AI legislation

We took the pulse of emerging fund managers about what it’s been like for them during these post-ZERP, venture-capital-winter years.

A reckoning is coming for emerging venture funds, and that, VCs say, is a good thing

It’s been a busy weekend for union organizing efforts at U.S. Apple stores, with the union at one store voting to authorize a strike, while workers at another store voted…

Workers at a Maryland Apple store authorize strike

Alora Baby is not just aiming to manufacture baby cribs in an environmentally friendly way but is attempting to overhaul the whole lifecycle of a product

Alora Baby aims to push baby gear away from the ‘landfill economy’

Bumble founder and executive chair Whitney Wolfe Herd raised eyebrows this week with her comments about how AI might change the dating experience. During an onstage interview, Bloomberg’s Emily Chang…

Go on, let bots date other bots

Welcome to Week in Review: TechCrunch’s newsletter recapping the week’s biggest news. This week Apple unveiled new iPad models at its Let Loose event, including a new 13-inch display for…

Why Apple’s ‘Crush’ ad is so misguided

The U.K. Safety Institute, the U.K.’s recently established AI safety body, has released a toolset designed to “strengthen AI safety” by making it easier for industry, research organizations and academia…

U.K. agency releases tools to test AI model safety

AI startup Runway’s second annual AI Film Festival showcased movies that incorporated AI tech in some fashion, from backgrounds to animations.

At the AI Film Festival, humanity triumphed over tech

Rachel Coldicutt is the founder of Careful Industries, which researches the social impact technology has on society.

Women in AI: Rachel Coldicutt researches how technology impacts society

SAP Chief Sustainability Officer Sophia Mendelsohn wants to incentivize companies to be green because it’s profitable, not just because it’s right.

SAP’s chief sustainability officer isn’t interested in getting your company to do the right thing

Here’s what one insider said happened in the days leading up to the layoffs.

Tesla’s profitable Supercharger network is in limbo after Musk axed the entire team

StrictlyVC events deliver exclusive insider content from the Silicon Valley & Global VC scene while creating meaningful connections over cocktails and canapés with leading investors, entrepreneurs and executives. And TechCrunch…

Meesho, a leading e-commerce startup in India, has secured $275 million in a new funding round.

Meesho, an Indian social commerce platform with 150M transacting users, raises $275M

Some Indian government websites have allowed scammers to plant advertisements capable of redirecting visitors to online betting platforms. TechCrunch discovered around four dozen “gov.in” website links associated with Indian states,…

Scammers found planting online betting ads on Indian government websites

Around 550 employees across autonomous vehicle company Motional have been laid off, according to information taken from WARN notice filings and sources at the company.  Earlier this week, TechCrunch reported…

Motional cut about 550 employees, around 40%, in recent restructuring, sources say

The company is describing the event as “a chance to demo some ChatGPT and GPT-4 updates.”

OpenAI’s ChatGPT announcement: What we know so far

The deck included some redacted numbers, but there was still enough data to get a good picture.

Pitch Deck Teardown: Cloudsmith’s $15M Series A deck

Unlike ChatGPT, Claude did not become a new App Store hit.

Anthropic’s Claude sees tepid reception on iOS compared with ChatGPT’s debut

Welcome to Startups Weekly — Haje‘s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. Look,…

Startups Weekly: Trouble in EV land and Peloton is circling the drain

Scarcely five months after its founding, hard tech startup Layup Parts has landed a $9 million round of financing led by Founders Fund to transform composites manufacturing. Lux Capital and Haystack…

Founders Fund leads financing of composites startup Layup Parts

AI startup Anthropic is changing its policies to allow minors to use its generative AI systems — in certain circumstances, at least.  Announced in a post on the company’s official…

Anthropic now lets kids use its AI tech — within limits

Zeekr’s market hype is noteworthy and may indicate that investors see value in the high-quality, low-price offerings of Chinese automakers.

The buzziest EV IPO of the year is a Chinese automaker

Venture capital has been hit hard by souring macroeconomic conditions over the past few years and it’s not yet clear how the market downturn affected VC fund performance. But recent…

VC fund performance is down sharply — but it may have already hit its lowest point