Artificial Intelligence: The French CNIL's Action Plan for Regulating AI Systems
Introduction
In light of recent developments in the field of artificial intelligence (AI)—and in particular generative AI systems such as ChatGPT—the National Commission on Information Technology and Civil Liberties (CNIL) has published an action plan aimed at deploying AI systems that Privacy of individuals. Generative AI is an emerging field of AI that enables the creation of text, images, and other content based on user instructions. In this article, we will examine the details of this action plan and its significance for the protection of Privacy discuss.
The role of the CNIL
In recent years, the CNIL has already carried out extensive work to prevent and address the challenges associated with AI. In 2023, the CNIL will continue its efforts to regulate advanced cameras and expand its work to include generative AI, large language models, and their derivative applications, such as chatbots. The CNIL’s action plan focuses on four main areas:
Understanding how AI systems work and their impact on individuals.
Promoting and regulating the development of privacy-friendly AI.
Support for and collaboration with innovative players in the AI ecosystem in France and Europe.
Auditing and monitoring AI systems to protect individuals.
These measures also serve to prepare for the implementation of the European AI Regulation, which is currently under discussion.
The protection of personal data as a key challenge
As AI continues to advance, it is giving rise to an increasing number of challenges in the areas of data protection and the protection of individual freedoms. As early as 2017, the CNIL addressed the issues raised by this technology in its report on the ethical challenges of algorithms and artificial intelligence.
Generative AI has made significant strides in recent months, particularly in the areas of text generation and conversation. Through the use of large language models such as GPT-3, BLOOM, or Megatron NLG, and chatbots derived from them—such as ChatGPT or Bard—these systems can generate text that closely resembles that created by humans. There have also been significant developments in the field of image and speech generation. Although these models and technologies are already being used in various industries, their functionality, capabilities, and limitations—as well as the associated legal, ethical, and technical challenges—are still the subject of intense debate.
The CNIL has published its action plan for regulating artificial intelligence to highlight the importance of protecting personal data in the development and use of these tools. In particular, it focuses on generative AI.
What are generative AIs?
Generative AIs are systems capable of creating text, images, and other content (music, videos, speech, etc.) based on instructions from human users. These systems can generate new content from the data used to train them. Thanks to the extensive training dataset, they can produce results that are already very close to human-created content. However, it is important for users to clearly specify their requests in order to achieve the desired results. Consequently, a specific area of expertise is emerging regarding the formulation of user requests (prompt engineering).
The CNIL's action plan in four steps
In recent years, the CNIL has carried out extensive work on AI regulation, taking into account various types of AI systems and their use cases. Its action plan focuses on four main objectives:
- Functionality and effects of AI on the Privacy and rights of individuals
- Establishment of a legal framework for the use of AI systems that ensures the Data protection guaranteed
- Support for and Collaboration with AI Innovators in France and Europe
- Review and oversight of AI systems to ensure the rights and protection of individuals
“What I like about the action plan is that it aims first to develop an understanding of how AI systems work and also whether and what kind of impact they have on individuals,” comments Marcus Belke, CEO of the 2B Advice Group, a group of companies that has been offering data protection solutions for 20 years. “What’s missing, however, is an agenda item on the opportunities AI offers for data protection,” Marcus Belke continues.
The CNIL will step up its oversight measures and, in particular, examine the use of generative AI to ensure that companies that develop, train, or use AI systems have taken appropriate measures to protect personal data. Its goal is to establish clear and protective rules for the handling of personal data in AI systems.
Through these comprehensive measures, the CNIL aims to contribute to the development of privacy-friendly AI systems while ensuring that the Privacy and protect the rights of European citizens.
With its action plan, the CNIL hopes to support data protection officers (DPOs) in addressing the challenges associated with artificial intelligence (AI). By providing clear guidelines and measures to ensure data protection in AI systems, data protection officers in companies and organizations can be better prepared to address the implications of AI technologies. The CNIL’s action plan provides a foundation for establishing a privacy-friendly framework for the use of AI and helps data protection officers implement effective data protection measures and safeguard the rights and freedoms of data subjects. The CNIL’s work is therefore a valuable tool for data protection officers to address the data protection challenges associated with AI and to ensure the protection of personal data.





