Generative AI in EU Law: Liability, Privacy, Intellectual Property, and Cybersecurity

Claudio Novelli,Federico Casolari,Philipp Hacker,Giorgio Spedicato,Luciano Floridi
2024-03-16
Abstract:The advent of Generative AI, particularly through Large Language Models (LLMs) like ChatGPT and its successors, marks a paradigm shift in the AI landscape. Advanced LLMs exhibit multimodality, handling diverse data formats, thereby broadening their application scope. However, the complexity and emergent autonomy of these models introduce challenges in predictability and legal compliance. This paper delves into the legal and regulatory implications of Generative AI and LLMs in the European Union context, analyzing aspects of liability, privacy, intellectual property, and cybersecurity. It critically examines the adequacy of the existing and proposed EU legislation, including the Artificial Intelligence Act (AIA) draft, in addressing the unique challenges posed by Generative AI in general and LLMs in particular. The paper identifies potential gaps and shortcomings in the legislative framework and proposes recommendations to ensure the safe and compliant deployment of generative models, ensuring they align with the EU's evolving digital landscape and legal standards.
Computers and Society,Artificial Intelligence
What problem does this paper attempt to address?
This paper discusses the responsibility, privacy, intellectual property rights, and cybersecurity issues of generative artificial intelligence (Generative AI), especially large language models (LLMs), within the European legal framework. With the emergence of advanced LLMs such as ChatGPT, their versatility and autonomy bring challenges in predictability and legal compliance. The paper analyzes existing and proposed EU legislation, such as the Artificial Intelligence Act (AIA), to determine if it is sufficient to address these challenges and identifies possible legal loopholes and shortcomings. The article points out that current legislation may not be suitable for the complexity of LLMs, particularly in terms of liability allocation, privacy protection, intellectual property rights, and cybersecurity. The paper suggests improving the EU legal framework to ensure the safe and lawful deployment of generative models. Regarding liability, the paper discusses the limitations of the Product Liability Directive (PLD) and the Artificial Intelligence Liability Directive (AILD) and proposes the need for clearer rules to handle liability issues involving non-professional users. In terms of privacy and data protection, the paper mentions the use of personal data in LLM training and the risks of privacy infringement. Additionally, the paper addresses intellectual property issues, as LLMs may generate content similar to original works. In terms of cybersecurity, the paper emphasizes the importance of ensuring the security of LLMs and the transparency requirements for obtaining evidence in case of harm. In conclusion, this paper attempts to address how to effectively manage and regulate generative AI, particularly the use of large language models within the European legal system, in order to strike a balance between technological innovation and legal compliance, user safety, and privacy protection.