Vol.08
欧盟《人工智能法案》第九、第十、第十三条制度
查明及企业合规指引
/ 目次 /
一、《人工智能法案》主要制度查明
(一)数据治理(Article 10 Data Governance)制度
1. 数据治理制度的渊源
2. 数据治理制度的内容
3. 处理个人数据规则
(二)透明度(Article 13 Transparency)义务
1. 透明度义务的渊源
2. 透明度义务的内容
3. 披露训练数据版权规则
(三)风险管理(Article 9 Risk Management)制度
1. 风险管理制度的内容
2. 风险管理制度的法律适用问题
二、《人工智能法案》合规指引
(一)《人工智能法案》监管流程
1. 监管主体
2. 市场监督
3. 执法程序
(二)涉欧企业合规指引
1. 遵守数据处理的多重法律
2. 透明度义务方面
3. 建立全周期风险管理制度
导言
欧洲议会全体会议已于2023年6月14日表决通过了欧盟《人工智能法案》(Artificial Intelligence Act)1。该法案将进入立法的最终三方会谈阶段。《人工智能法案》在未来生效后将会成为全球首部人工智能监管法规,并可能会加剧“布鲁塞尔效应”,对各国涉欧企业产生强制约束力。《人工智能法案》对人工智能系统以风险为依据进行分级,对不同的人工智能系统采取不同监管口径。其中,高风险人工智能系统是《人工智能法案》的主要规制对象,也是合规义务较重的对象。其中,《人工智能法案》在数据治理、透明度义务、风险管理制度设置方面,对高风险人工智能系统提出了一系列要求,对我国具有一定借鉴的意义。本文旨在对上述制度的设置进行分析讨论,并为涉欧企业在未来《人工智能法案》生效后,提供一定的合规指引。

图1
风险等级分类,曾雄、梁正、张辉《欧盟人工智能的规制路径及其对我国的启示——以<人工智能法案>为分析对象》
一、《人工智能法案》主要制度查明
2020年,基于人工智能的飞速发展,为建立技术与欧盟价值观相结合的监管体制,欧盟委员会发布了《人工智能白皮书》(White Paper on Artificial Intelligence: a European approach to excellence and trust)2,强调从卓越生态系统(ecosystem of excellence)和信任生态系统(ecosystem of trust)两方面建立可信赖与安全的人工智能监管框架。《人工智能法案》正是 《人工智能白皮书》的法律延伸,《人工智能白皮书》中呼吁训练数据需安全度高、应用高风险人工智能时提供必要信息、开展事前一致性评估等要求都反映在《人工智能法案》中规定的数据治理、透明度义务和风险管理等相关制度中。下文将对高风险人工智能系统的数据治理、透明度义务和风险管理规则进行分析,了解该些制度的建立将如何实现可信赖与安全的人工智能监管框架。

图2
高风险人工智能系统范围,Trail-ml官网
(一)数据治理(Article 10 Data Governance)制度
1. 数据治理制度的渊源
数据治理是随着大数据应用的普及以及企业数字化转型而诞生的制度。在《通用数据保护条例》(General Data Protection Regulation,以下简称为GDPR)3等数据隐私法律法规出台后,数据治理成为企业的重要合规环节之一。而人工智能系统经常用于预测、评估某行为,该种预测与评估的成功与否很大程度上取决于所训练用和学习的数据量、范围和数据准确性。然而,即便所使用的数据能够满足以上要求,人工智能系统的行为仍然存在一定程度的不可预测性,这种行为即为“涌现”(Emergence)。欧盟委员会为了避免人工智能系统这一风险,在《人工智能法案》第十条中规定了一系列数据治理的要求。
欧盟数据保护执法部门(Data Protection Authorities)会确保欧盟的数据保护与治理方面的规则能够得到一致的应用,这种理念也在《人工智能法案》中得到体现。《人工智能法案》承袭了此前欧盟出台的包括GDPR、《数据保护执法指令》(Data Protection Law Enforcement Directive)4、《隐私与电子通信指令》(Privacy and Electronic Communications Directive)5等数据治理相关法律的类似表述。
2. 数据治理制度的内容
《人工智能法案》第十条6规定,如果高风险人工智能系统使用数据集进行训练,则训练、验证和测试的数据集应当使用符合第二至第五款规定的标准进行。例如,应当采用适当的数据治理措施(第十条第二款,如下图);数据集应当具有相关性、充分的代表性、适当的审查错误并在考虑到预期目的的情况下尽可能完整(第十条第三款);数据集应在人工智能系统的预期目的或可合理预见的误用所要求的范围内,考虑到高风险人工智能系统拟使用的特定的地理、场景、行为或功能环境所特有的特征或要素(第十条第四款);高风险人工智能系统的提供者在符合一定条件下可以处理特别种类的个人数据(第十条第五款)。此外,高风险人工智能系统的部署者在一定情形下应当承担本条规定的责任(第十条第六款)。

图3
《人工智能法案》第十条第二款的数据治理措施要求
该条文在最初的版本中,要求数据集应当具有相关性、代表性、无错误性与完整性。这与我国《生成式人工智能服务管理办法(征求意见稿)》第七条第二款第四项7要求一致,需要确保数据的真实性与准确性。但在客观上是不存在此类完美的数据的。彼时《人工智能法案》的该项条文也收到了葡萄牙、丹麦、比利时、西班牙、瑞典等多国要求修改“完美数据”表述的意见。最终,该条文尊重了各成员国的意见,对数据集附加了多项条件,要求“数据集应当具有相关性、充分的代表性、适当的审查错误并在考虑到预期目的的情况下尽可能完整。”
然而,《人工智能法案》的数据治理制度仍不是尽善尽美的。该法案第十条第四款要求数据集应在人工智能系统的预期目的或可合理预见的误用所要求的范围内,考虑到高风险人工智能系统拟使用的特定的地理、场景、行为或功能环境所特有的特征或要素,但并未对该些特征与要素的内涵与外延进行明确定义,这会导致在数据治理上是否符合该些特征与要素缺失客观性标准。
3. 处理个人数据规则
根据《人工智能法案》的说明备忘录,GDPR等法律不受《人工智能法案》的影响。因此,只要提供者在开发其高风险人工智能系统时使用个人数据,就必须遵守《人工智能法案》的数据处理要求以及GDPR等法律对于个人数据处理的要求。但在涉及特别种类的个人数据时,《人工智能法案》的数据治理制度设置了不同于上述的例外规则。主要体现为:GDPR第九条第一款8规定了特别种类的个人数据的概念,即为“对揭示种族或民族出身,政治观点、宗教或哲学信仰,工会成员的个人数据,以及以唯一识别自然人为目的的基因数据、生物特征数据,健康、自然人的性生活或性取向的数据”。GDPR、《数据保护执法指令》等法律明令禁止处理特别种类的个人数据。但出于高风险人工智能系统检测与纠正负面偏差的需求,在保障自然人基本权利与自由的前提下,提供者可以对特别种类的个人数据进行处理,并且提供者应当符合第十条第五款(a)至(g)项规定的条件,并起草必要性说明。
(二)透明度(Article 13 Transparency)义务
1. 透明度义务的渊源
透明度义务源自于对算法的透明度规制。GDPR首次在立法中提出算法解释权,要求算法解释权来实现算法透明度。而后欧洲议会研究服务机构发布的《算法问责及透明度监管框架》(A Governance Framework for Algorithmic Accountability and Transparency)9对于算法及其在自动化决策系统中的应用快速增长提出了全面的监管框架。欧盟《数字服务法》(Digital Service Act)10要求在线平台采取广泛的透明度措施包括推荐算法的透明度,让用户更好地了解平台是如何向他们推荐内容。透明度义务也是欧盟对人工智能系统的开发、部署和使用始终倡导的核心价值之一。自监管人工智能的政策进程开始以来,欧盟相关机构发布的《可信人工智能伦理准则》(Ethics Guidelines for Trustworthy AI issued)11、《人工智能白皮书》以及《人工智能、机器人和相关技术的伦理问题框架》(Framework of Ethical Aspects of AI, Robotics and Related Technologies)12等政策文件都分别包含了透明度的规定。
2. 透明度义务的内容
《人工智能法案》第十三条13规定对于高风险人工智能系统的设计和开发应确保其运作具有足够的透明度,使用户能够理解系统的输出并加以适当使用。透明度指在高风险人工智能系统进入市场时,应利用根据公认的最新技术水平以及可行的所有技术手段,确保该人工智能系统的输出可以被提供者和用户理解。用户应当能够通过了解人工智能系统的工作原理和数据处理情况,适当地理解和使用该人工智能系统,并能够根据第68(c)条款向受影响的人解释人工智能系统所做出的决策。
但在机器学习中,许多人工智能无法给出解决问题的步骤,而只能看到输入和输出内容,这被称为黑箱模型(black box)。由于《人工智能法案》并未定义“用户能够理解系统的输出”中“理解(interpret)”的内涵,此类黑箱模型都无法满足《人工智能法案》的透明度义务。有人认为,此处的“理解”等同于可以向用户解释(explain),解释的程度则根据不同情况而定,例如对无技术知识的自然人而言,需要对其解释导致特定结果的逻辑或有关于他的人工智能系统决策的重要影响因素。但理解是否能够等同于解释还有待商榷。14从立法目的来看,神经网络模型(DNN)就是一种黑箱模型,其因为由成千上万的人造神经元组成,以扩散方式来解决问题,算法结构十分复杂,难以被用户理解。15但若因此类人工智能系统无法满足透明度义务而被排除在欧盟市场之外,将会严重阻碍技术创新与欧洲市场发展。故《人工智能法案》第十三条在设计时存在一定不足。
此外,《人工智能法案》的透明度义务的要素与此前人工智能政策文件规定的透明度义务的要素并不一致。《可信人工智能伦理准则》中,记录义务是可追溯性的一部分,而可追溯性是透明度的要素;《人工智能白皮书》中透明度的要素之一就是保存记录、文档和数据;《人工智能、机器人和相关技术的伦理问题框架》中规定人工智能高风险技术以透明和可追溯的方式开发、部署和使用,以便其要素、流程,并按照尽可能高的适用标准记录各个阶段。规定人工智能高风险技术以透明和可追溯的方式开发、部署和使用,以便其要素、流程,并按照尽可能高的适用标准记录各个阶段。可见,技术文件和记录保存应当为透明度的要素,但在《人工智能法案》中却被列在透明度义务条款之外。笔者认为,《人工智能法案》应当延续此前人工智能政策文件采取的做法,将技术文件和记录保存作为透明度义务的一部分。
3. 披露训练数据版权规则
《人工智能法案》第二十八b条第四款(c)项16规定生成式人工智能使用的基础模型提供者应当记录并公开提供受版权法保护的训练数据的使用情况的足够详细的摘要。该条所体现的背景是Stability AI、Midjourney等生成式人工智能系统在训练时所用数据并未取得作者的授权,对于各行业创作者都产生了较大的影响。例如2023年1月,著名图片公司Getty Images 在伦敦高等法院对 Stability AI 提起法律诉讼,声称 Stability AI没有向 Getty Images寻求任何许可,非法复制和处理了数百万受版权保护的图像,侵犯了Getty Images所拥有作品的版权。
起初,欧盟委员会成员提议全面禁止将受版权保护的材料用于训练生成式 AI 模型,但最终出于保护相关主体的版权,并尽可能减小对于生成式人工智能发展的阻碍,修改为要求基础模型提供者承担透明度义务。
(三)风险管理(Article 9 Risk Management)制度
1. 风险管理制度的内容
鉴于人工智能系统可能导致的一系列风险,风险管理制度尤为重要。近年来,多个标准制定机构正在起草人工智能风险管理框架,其中最知名的就是美国国家标准与技术研究院(NIST)的《人工智能风险管理框架》(Artificial Intelligence Risk Management Framework)17以及国际标准化组织及国际电工委员会联合制定的《人工智能风险管理基本指南》(ISO/IEC 23894:2023 Information technology – Artificial intelligence – Risk management)18。多家包括普华永道在内的公司也发布了人工智能风险管理报告。
而《人工智能法案》第九条19也规定了高风险人工智能系统的风险管理制度,要求在人工智能系统的整个生命周期中,应建立、实施、记录和维护与高风险人工智能系统有关的风险管理系统,包括识别分析已知和可预见的风险、评估使用后可能的风险、基于上市后检测数据预估风险、采取风险管理措施。
众所周知,《人工智能法案》基于风险不同,对人工智能系统采取了不同的监管措施:禁止具有不可接受风险的人工智能系统,对高风险人工智能系统提出了具体要求,而风险较低或最小的人工智能系统基本上不受严厉的监管。为了降低高风险人工智能系统的风险,该系统的提供者必须遵守《人工智能法案》的相关规定。但立法者认为这不足以将所有风险降低到可接受的水平,即使高风险人工智能系统的提供者遵守了所有义务和要求。仍然可能存在一定的风险。而《人工智能法案》第九条的作用就是确保提供者识别风险并采取额外措施将其降低到可接受的水平。故风险管理制度具有重要的补充作用。
2. 风险管理制度的法律适用问题
风险管理制度并不是《人工智能法案》独有的规则,欧盟既有立法中已经存在特定的风险管理制度规则,例如2013/36号指令要求信贷机构建立适当的风险管理程序以便适当地识别、衡量、监测和控制与混合控股母公司及其子公司的交易。而既有立法的风险管理制度,其如何与《人工智能法律》的风险管理制度衔接成为一个问题。根据《人工智能法案》第九条第九款,人工智能系统风险管理制度应当作为既有的风险管理制度的一部分。换句话说,人工智能系统风险管理制度补充了现有立法的风险管理制度,而不是取代它们。有鉴于此,未来任何立法中若规定新的风险管理制度,都可能和人工智能系统风险管理制度相结合而非互斥。
二、《人工智能法案》合规指引
(一)《人工智能法案》监管流程
1. 监管主体
《人工智能法案》框架下,监管主体包括欧洲人工智能办公室(the European Artificial Intelligence Office)、国家监督机构(National Supervisory Authority)以及其他主体。欧洲人工智能办公室是欧盟的独立机构,主要负责对于《人工智能法案》的实施为国家与组织提供支持、建议与合作,在不影响国家监督机构工作的情况下,监督并确保《人工智能法案》的有效实施。总的来说,欧洲人工智能办公室设立的目的主要是促进《人工智能法案》所规定的各种制度的落实与完善,以及国家与组织之间的沟通与协调。国家监督机构则是由成员国指定的机构,作为在该国确保《人工智能法案》适用和实施的主管机构。国家监督机构在成员国内,应当作为市场监督机构行事。在特殊情况下,由特定主体而非国家监督机构进行监管,例如受欧盟金融服务相关立法管制的金融机构投放市场、投入使用的人工智能系统,则由根据相关金融服务立法规定的主管机构监管。
2. 市场监督
《人工智能法案》要求建立市场监督体系。市场监督体系可以分为上市后监测与事故与故障信息分享。上市后监测指高风险人工智能系统提供者应当建立积极和系统地收集、记录和分析关于高风险人工智能系统在其整个生命周期内的性能的相关数据的监测系统。事故与故障信息分享是指高风险人工智能系统的提供者或部署者应当在系统发生严重事件时进行报告,提供者及部署者应当在确定人工智能系统与严重事件之间的因果关系或合理可能性后72小时内国家监督机构报告。国家监督机构应当在收到报告之日起七日内采取适当措施。
3. 执法程序
国家监督机构作为市场监督机构,具有《欧盟市场监管法规》20的权力和义务,对《人工智能法案》下的人工智能系统和基础模型进行监管。对高风险人工智能系统,国家监督机构有权进行不预先通知的现场和远程检查,并且有权获取与高风险人工智能系统有关的样本。当国家监督机构认为人工智能系统可能对基本权利、公共安全、消费者权益、民主法治等产生不利影响时,可以对该人工智能系统是否符合《人工智能法案》的所有要求和义务进行评估。评估结果可分为两种,第一种评估结果为该人工智能系统不符合《人工智能法案》的要求与义务,国家监督机构将立刻要求有关主体采取一切适当措施进行纠正。若有关主体并未进行纠正,国家监督机构将禁止或限制该人工智能系统进入市场,并将市场中现有的该系统进行撤出或召回。第二种评估结果为该人工智能系统虽然符合《人工智能法案》的要求与义务,但对基本权利、公共安全、消费者权益、民主法治等方面存在风险,在此种情况下,国家监督机构有权要求有关主体消除该种风险。
在收到国家监督机构的执法决定后,有关主体也可以进行相关救济。有关主体可以针对国家监督机构的决定向国家监督机构所在成员国的法院提起诉讼。
有关主体若被国家监督机构认定违反《人工智能法案》,将面临巨额行政罚款。对于提供具有不可接受风险的人工智能系统的主体,将被处以4,000万欧元或上一财政年度全球总营业额7%二者较高者的行政罚款;对于违反数据治理制度与透明度义务的主体,将被处以2,000万欧元或上一财政年度全球总营业额4%二者较高者的行政罚款;对于除上述外的其他要求和义务的主体,将被处以1,000万欧元或上一财政年度全球总营业额2%二者较高者的行政罚款;对于向国家监督机构或其他主管部门提供虚假、不完整或误导性信息的主体,将被处以500万欧元或上一财政年度全球总营业额1%二者较高者的行政罚款。
(二) 涉欧企业合规指引

图4
企业部署人工智能系统前的
thought-and-act process,Nikita Lukianets
1. 遵守数据处理的多重法律
2023年3月,意大利个人数据保护局宣布,意大利禁止使用ChatGPT,并限制开发这一平台的OpenAI公司处理意大利用户信息。意大利个人数据保护局认为ChatGPT没有就收集处理用户信息进行告知,缺乏大量收集和存储个人信息的法律依据。应在满足一定质量标准的数据上进行训练、验证和测试,采集、标注、清洗数据遵守管理规范,并保障数据具有代表性、准确性和完整性。意大利个人数据保护局对ChatGPT违反数据收集规则展开调查。
可见,企业在使用个人数据训练人工智能系统时,一方面,根据《人工智能法案》第十条,高风险人工智能系统提供者必须遵守该条关于数据集的要求;另一方面,根据GDPR,对于这些数据集的验证很可能也构成对个人数据的处理。因此,高风险人工智能系统提供者同时也成为数据控制者,应当根据GDPR规定的例如征得用户同意等合法性基础来处理数据集。最后,企业还应当遵守我国关于处理个人数据的《个人信息保护法》21等相关法律的要求。
2. 透明度义务方面
企业应当以简洁、完整、正确、清晰、相关、可访问和可理解的形式,向用户提供使用说明、人工智能提供者的联系方式、人工智能的特征、能力和性能限制、系统可预见的变化和预期寿命、人类监督措施等。
此外,由于对于“理解”的内涵尚未清楚,还需要立法者进行澄清。笔者认为可以参考此前《可信人工智能伦理准则》中关于透明度的要求,即要求企业解释(explain)为什么模型会生成特定的输出或决策(以及输入内容的哪些组合促成了这一结果)。当无法进行解释时,可以采用可追溯性、可审计性和透明化通信等替代措施履行透明度义务。虽然理解与解释并不属于同一词,但在人工智能开发中,这两个词语经常被交叉使用。
3. 建立全周期风险管理制度
根据《人工智能法案》第九条,高风险人工智能系统应当建立全周期风险管理系统,包括识别分析已知和可预见的风险、评估使用后可能的风险、基于上市后检测数据预估风险、采取风险管理措施。
《人工智能法案》在风险识别环节即纳入“可预见的风险”,其定义是“人工智能系统的使用方式不符合其预期目的,但可能是由于合理可预见的人类行为或与其他系统的交互而导致的”。
而在评估使用后可能的风险时,企业应当考虑到《人工智能法案》规定的透明度网络安全、人为监督和记录保存等规则,根据初步确定的指标和概率(例如潜在的滥用情况)进行测试,评估使用后可能的风险。
高风险人工智能系统进入市场后,风险管理并没有结束。基于上市后检测数据预估风险是风险管理制度的关键组成部分。这将需要人工智能系统提供者在建立多个反馈与沟通渠道,并在部署人工智能系统后进行跟踪,将来自反馈与沟通渠道的信息及时交付给相关团队。一旦高风险人工智能系统进入市场后,企业应当完成事故发生的补救计划,以备不时之需。
此外,企业应当在入市前就针对不同人群进行人工智能系统风险评估,为特殊用户群体(例如儿童)采用量身定制的风险控制措施。同时,企业也应当向其系统的用户提供充分的信息和适当的培训。
注释:
[1] https://www.europarl.europa.eu/doceo/document/TA-9-2023-0236_EN.html.
[2] https://commission.europa.eu/publications/white-paper-artificial-intelligence-european-approach-excellence-and-trust_en.
[3] https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679.
[4] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016L0680.
[5] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02002L0058-20091219.
[6] Artificial Intelligence Act, Article 10:
1. High-risk AI systems which make use of techniques involving the training of models with data shall be developed on the basis of training, validation and testing data sets that meet the quality criteria referred to in paragraphs 2 to 5 as far as this is technically feasible according to the specific market segment or scope of application.
Techniques that do not require labelled input data such as unsupervised learning and reinforcement learning shall be developed on the basis of data sets such as for testing and verification that meet the quality criteria referred to in paragraphs 2 to 5.
2. Training, validation and testing data sets shall be subject to data governance appropriate for the context of use as well as the intended purpose of the AI system.
Those measures shall concern in particular,
(a) the relevant design choices;
(aa) transparency as regards the original purpose of data collection;
(b) data collection processes;
(c) relevant data preparation processing operations, such as annotation, labelling, cleaning, updating enrichment and aggregation;
(d) the formulation of assumptions, notably with respect to the information that the data are supposed to measure and represent;
(e) an assessment of the availability, quantity and suitability of the data sets that are needed;
(f) examination in view of possible biases that are likely to affect the health and safety of persons, negatively impact fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations (‘feedback loops’) and appropriate measures to detect, prevent and mitigate possible biases;
(fa) appropriate measures to detect, prevent and mitigate possible biases;
(g) the identification of relevant data gaps or shortcomings that prevent compliance with this Regulation, and how those gaps and shortcomings can be addressed.
3. Training datasets, and where they are used, validation and testing datasets, including the labels, shall be relevant, sufficiently representative, appropriately vetted for errors and be as complete as possible in view of the intended purpose. They shall have the appropriate statistical properties, including, where applicable, as regards the persons or groups of persons in relation to whom the high-risk AI system is intended to be used. These characteristics of the datasets shall be met at the level of individual datasets or a combination thereof.
4. Datasets shall take into account, to the extent required by the intended purpose or reasonably foreseeable misuses of the AI system, the characteristics or elements that are particular to the specific geographical, contextual behavioural or functional setting within which the highrisk AI system is intended to be used.
5. To the extent that it is strictly necessary for the purposes of ensuring negative bias detection and correction in relation to the high-risk AI systems, the providers of such systems may exceptionally process special categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679, Article 10 of Directive (EU) 2016/680 and Article 10(1) of Regulation (EU) 2018/1725, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons, including technical limitations on the re-use and use of state-of-the-art security and privacy-preserving. In particular, all the following conditions shall apply in order for this processing to occur:
(a) the bias detection an correction cannot be effectively fulfilled by processing synthetic or anonymised data;
(b) the data are pseudonymised;
(c) the provider takes appropriate technical and organisational measures to ensure that the data processed for the purpose of this paragraph are secured, protected, subject to suitable safeguards and only authorised persons have access
to those data with appropriate confidentiality obligations; (d) the data processed for the purpose of this paragraph are not to be transmitted, transferred or otherwise accessed by other parties;
(e) the data processed for the purpose of this paragraph are protected by means of appropriate technical and organizational measures and deleted once the bias has been corrected or the personal data has reached the end of its retention period;
(f) effective and appropriate measures are in place to ensure availability, security and resilience of processing systems and services against technical or physical incidents;
(g) effective and appropriate measures are in place to ensure physical security of locations where the data are stored and processed, internal IT and IT security governance and management, certification of processes and products; Providers having recourse to this provision shall draw up documentation explaining why the processing of special
categories of personal data was necessary to detect and correct biases.
6 a. Where the provider cannot comply with the obligations laid down in this Article because that provider does not have access to the data and the data is held exclusively by the deployer, the deployer may, on the basis of a contract, be made responsible for any infringement of this Article.
《人工智能法案》第十条:
1. 利用数据训练模型的高风险人工智能系统应在训练、验证和测试数据集的基础上进行开发。只要根据具体的市场部门或应用范围,使得在技术上是可行的,这些数据集就应符合本条第2至5款所述的质量标准。
例如非监督学习和强化学习等不需要标记输入数据的技术,应在符合本条第2至5款所述质量标准的测试和验证数据集的基础上开发。
2. 训练、验证和测试数据集应受到符合人工智能系统使用环境和预期目的的数据治理。
这些措施应特别涉及
(a) 相关的设计选择;
(aa) 数据收集的原始目的的透明度义务;
(b) 数据收集程序;
(c) 数据预处理程序,如注解、标记、清理、更新丰富和汇总;
(d) 假设的制定,特别是数据所要表征和衡量的信息;
(e) 评估所需数据集的可用性、数量和适宜性;
(f) 针对可能影响的自然人的健康和安全、可能对基本权利产生负面影响或可能导致欧盟法律所禁止的歧视的可能的偏差,特别是当输出的数据影响到未来程序的输入时(“反馈循环”)进行审查,以及;
(fa) 采取适当措施,检测、预防和减轻可能的偏差;
(g) 确定妨碍遵守本条例的相关数据缺口或缺陷,以及如何解决该些缺口和缺陷。
3. 包括标签在内,训练的数据集,以及在使用时的验证和测试的数据集,应具有相关性、充分的代表性、进行适当的错误审查,并在考虑到预期目的的情况下尽可能完整。它们应具有适当的统计特性,包括在适用的情况下的与高风险人工智能系统拟使用的自然人或自然人群体有关的统计特性。单个数据集或其组合均应满足上述特征。
4. 数据集应在人工智能系统的预期目的或可合理预见的误用所要求的范围内,考虑到高风险人工智能系统拟使用的特定的地理、场景、行为或功能环境所特有的特征或要素。
5. 在为确保高风险人工智能系统的负面的偏差检测和纠正的必要性的前提下,该些系统的提供者可以例外地处理欧盟2016/679号条例第9(1)条、欧盟2016/680号指令第10条和欧盟2018/1725号条例第10(1)条中提到的特别种类的个人数据,但必须对自然人的基本权利和自由采取适当的保障措施,包括对于重复使用的技术限制以及使用最先进的安全和隐私保护。特别注意的是,为了进行该种特别种类的个人数据处理,应同时符合下列条件:
(a) 通过处理合成的或匿名的数据,不能有效地实现偏差检测和纠正;
(b) 数据是假名化的;
(c) 提供者采取适当的技术和组织措施,确保为本款之目的而处理的数据是安全的且受到保护与适当的保障,只有被授权且负有适当的保密义务的人才能访问该些数据;
(d) 为本款之目的而处理的数据不会被其他方传输、转移或以其他方式获取;
(e) 为本款之目的而处理的数据通过适当的技术和组织措施加以保护,并在纠正偏差后或个人数据的保留期结束后予以删除;
(f) 采取有效和适当的措施,确保处理技术或物理事故的系统和服务的可用性、安全性和适应性;
(g) 采取有效和适当的措施,确保存储和处理数据的地点的物理安全、内部信息技术和信息技术安全治理和管理、流程和产品的认证。
诉诸本条款的提供者应起草文件解释处理特别种类的个人数据以检测和纠正偏见的必要性。
6 a.因数据只由部署者持有,提供者无法访问数据,导致提供者不能遵守本条规定的义务的,部署者可根据合同对任何违反本条的行为承担责任。
[7] 《生成式人工智能服务管理办法(征求意见稿)》第七条第二款第四项:用于生成式人工智能产品的预训练、优化训练数据,应满足以下要求:……(四)能够保证数据的真实性、准确性、客观性、多样性……
[8] GDPR, Article 9 Paragraph 1: Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited.
《通用数据保护条例》第九条第一款:禁止处理揭示种族或民族出身,政治观点、宗教或哲学信仰,工会成员的个人数据,以及以唯一识别自然人为目的的基因数据、生物特征数据,健康、自然人的性生活或性取向的数据。
[9]https://www.europarl.europa.eu/thinktank/en/document/EPRS_STU(2019)624262.
[10]https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022R2065.
[11]https://digital-strategy.ec.europa.eu/en/library/ethics-guidelines-trustworthy-ai.
[12]https://www.europarl.europa.eu/doceo/document/TA-9-2020-0275_EN.html.
[13] Artificial Intelligence Act, Article 13:
1. High-risk AI systems shall be designed and developed in such a way to ensure that their operation is sufficiently transparent to enable providers and users to reasonably understand the system’s functioning. Appropriate transparency shall be ensured in accordance with the intended purpose of the AI system, with a view to achieving compliance with the relevant obligations of the provider and user set out in Chapter 3 of this Title.
Transparency shall thereby mean that, at the time the high-risk AI system is placed on the market, all technical means available in accordance with the generally acknowledged state of art are used to ensure that the AI system’s output is interpretable by the provider and the user. The user shall be enabled to understand and use the AI system appropriately by generally knowing how the AI system works and what data it processes, allowing the user to explain the decisions taken by the AI system to the affected person pursuant to Article 68(c).
2. High-risk AI systems shall be accompanied by intelligible instructions for use in an appropriate digital format or made otherwise available in a durable medium that include concise, correct, clear and to the extent possible complete information that helps operating and maintaining the AI system as well as supporting informed decision-making by users and is reasonably relevant, accessible and comprehensible to users .
3. To achieve the outcomes referred to in paragraph 1, information referred to in paragraph 2 shall specify:
(a) the identity and the contact details of the provider and, where applicable, of its authorised representatives;
(aa) where it is not the same as the provider, the identity and the contact details of the entity that carried out the conformity assessment and, where applicable, of its authorized representative;
(b) the characteristics, capabilities and limitations of performance of the high-risk AI system, including, where appropriate:
(ii) the level of accuracy, robustness and cyber security referred to in Article 15
against which the high-risk AI system has been tested and validated and which can be expected, and any clearly known and foreseeable circumstances that may have an impact on that expected level of accuracy, robustness and cybersecurity;
(iii) any clearly known or foreseeable circumstance, related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety, fundamental rights or the environment, including, where appropriate, illustrative examples of such limitations and of scenarios for which the system should not be used;
(iiia) the degree to which the AI system can provide an explanation for decisions it takes;
(v) relevant information about user actions that may influence system performance, including type or quality of input data, or any other relevant information in terms of the training, validation and testing data sets used, taking into account the intended purpose of the AI system.
(e) any necessary maintenance and care measures to ensure the proper functioning of that AI system, including as regards software updates, through its expected lifetime.
(ea) a description of the mechanisms included within the AI system that allows users to properly collect, store and interpret the logs in accordance with Article 12(1).
(eb) The information shall be provided at least in the language of the country where the AI system is used.
3a. In order to comply with the obligations laid down in this Article, providers and users shall ensure a sufficient level of AI literacy in line with Article 4(b).
《人工智能法案》第十三条:
1. 高风险人工智能系统的设计和开发应确保其运作具有足够的透明度,使提供者和使用者能够合理地了解系统的运作;根据人工智能系统的预期目的,应确保适当的透明度以确保提供者和使用者遵守本篇第三章规定的相关义务。
因此,透明度应指在高风险人工智能系统进入市场时,应利用根据公认的最新技术水平以及可行的所有技术手段,确保该人工智能系统的输出可以被提供者和用户理解。用户应当能够通过了解人工智能系统的工作原理和数据处理情况,适当地理解和使用该人工智能系统,并能够根据第68(c)条款向受影响的人解释人工智能系统所做出的决策。
2. 高风险人工智能系统应附有以适当的数字格式或持续存在的媒介提供的可理解的使用说明,使用说明包括简明、正确、清晰和尽可能完整的信息,以辅助操作和维护人工智能系统以及支持用户的知情决策,使用说明应对用户有合理的相关性、可访问性和可理解性。
3. 为了实现第1款中提到的结果,第2款中提到的信息应说明:
(a) 提供者及其授权代表(如适用)的身份和详细联系方式;
(aa) 如果进行合格评估的实体不是提供者,应说明其及其授权代表(如适用)的身份和详细联系方式;
(b) 高风险人工智能系统的特点、能力和性能限制,包括(如适用):
(ii) 该系统已经过测试和验证可以预期达到的第15条所指的准确度、稳健性和网络安全水平,以及可能对预期的准确度、稳健性和网络安全产生影响的任何明确已知和可预见的情况;
(iii) 任何明确的已知或可预见的情况,包括:与按照高风险人工智能系统的预期目的或在可合理预见的误用条件下使用该系统有关,可能对健康和安全、基本权利或环境造成的风险,以及酌情说明该系统的该种限制和不应被使用的场景的示例;
(iiia) 人工智能系统能够为其做出的决定进行解释的程度;
(v)可能影响系统性能的用户行为的相关信息,包括输入数据的类型或质量,或考虑到人工智能系统的预期目的,所使用的训练、验证和测试数据集方面的任何其他相关信息。
(e) 为确保该人工智能系统在其预期使用寿命内正常运作的任何必要的维护和保养措施,包括软件更新措施。
(ea) 关于人工智能系统内所包含的允许用户根据第12条第1款适当地收集、储存和解释日志机制的说明。
(eb) 这些信息应至少以使用人工智能系统的国家的语言提供。
3a. 为了遵守本条规定的义务,提供者和使用者应根据第4(b)条的规定,确保有足够的人工智能知识水平。
[14] Stefan Larsson, Fredrik Heintz, Transparency in Artificial Intelligence, Internet Policy Review, 9(2).
[15] Yavar Bathaee, The Artificial Intelligence Black Box and The Failure of Intent and Causation, Harvard Journal of Law & Technology Volume 31, Number 2 Spring 2018.
[16] Artificial Intelligence Act, Article 28b:
4. Providers of foundation models used in AI systems specifically intended to generate, with varying levels of autonomy, content such as complex text, images, audio, or video (“generative AI”) and providers who specialise a foundation model into a generative AI system, shall in addition
c) without prejudice to Union or national or Union legislation on copyright, document and make publicly available a sufficiently detailed summary of the use of training data protected under copyright law.
《人工智能法案》第二十八b条:
4. 在人工智能系统中使用基础模型,专门用于以不同程度的自主性生成复杂的文本、图像、音频或视频等内容(“生成式人工智能”)的提供者,以及将基础模型专门用于生成性人工智能系统的提供者,应当:
c) 在不影响欧盟、国家或欧盟版权立法的情况下,记录并公开提供受版权法保护的训练数据的使用情况的足够详细的摘要。
[17]https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10.
[18] https://www.iso.org/standard/77304.html.
[19] Artificial Intelligence Act, Article 9:
1. A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems, throughout the entire lifecycle of the AI system. The risk management system can be integrated into, or a part of, already existing risk management procedures relating to the relevant Union sectoral law insofar as it fulfils the requirements of this article.
2. The risk management system shall consist of a continuous iterative process run throughout the entire lifecycle of a high-risk AI system, requiring regular review and updating of the risk management process, to ensure its continuing effectiveness, and documentation of any significant decisions and actions taken subject to this Article. It shall comprise the following steps:
(a) identification, estimation and evaluation of the known and the reasonably foreseeable risks that the high risk AI system can pose to the health or safety of natural persons, their fundamental rights including equal access and opportunities, democracy and rule of law or the environment when the high-risk AI system is used in accordance with its intended purpose and under conditions of reasonably foreseeable misuse;
(c) evaluation of emerging significant risks as described in point (a) and identified based on the analysis of data gathered from the post-market monitoring system referred to in Article 61;
(d) adoption of appropriate and targeted risk management measures designed to address the risks identified pursuant to points a and b of this paragraph in accordance with the provisions of the following paragraphs.
3. The risk management measures referred to in paragraph 2, point (d) shall give due consideration to the effects and possible interactions resulting from the combined application of the requirements set out in this Chapter 2, with a view to mitigate risks effectively while ensuring an appropriate and proportionate implementation of the requirements.
4. The risk management measures referred to in paragraph 2, point (d) shall be such that relevant residual risk associated with each hazard as well as the overall residual risk of the high-risk AI systems is reasonably judged to be acceptable, provided that the high-risk AI system is used in accordance with its intended purpose or under conditions of reasonably foreseeable misuse. Those residual risks and the reasoned judgements made shall be communicated to the deployer.
In identifying the most appropriate risk management measures, the following shall be ensured:
(a) elimination or reduction of identified risks as far as technically feasible through
adequate design and development of the high-risk AI system, involving when relevant, experts and external stakeholders;
(b) where appropriate, implementation of adequate mitigation and control measures addressing significant risks that cannot be eliminated;
(c) provision of the required information pursuant to Article 13, and, where appropriate, training to deployers.
In eliminating or reducing risks related to the use of the high-risk AI system, providers shall take into due consideration the technical knowledge, experience, education and training the deployer may need, including in relation to the presumable context of use.
5. High-risk AI systems shall be tested for the purposes of identifying the most appropriate and targeted risk management measures and weighing any such measures against the potential benefits and intended goals of the system. Testing shall ensure that high-risk AI systems perform consistently for their intended purpose and they are in compliance with the requirements set out in this Chapter.
6. Testing procedures shall be suitable to achieve the intended purpose of the AI system.
7. The testing of the high-risk AI systems shall be performed, prior to the placing on the market or the putting into service. Testing shall be made against prior defined metrics, and probabilistic thresholds that are appropriate to the intended purpose or reasonably foreseeable misuse of the high-risk AI system.
8. When implementing the risk management system described in paragraphs 1 to 7, providers shall give specific consideration to whether the high risk AI system is likely to adversely impact vulnerable groups of people or children.
9. For providers and AI systems already covered by Union law that require them to establish a specific risk management, including credit institutions regulated by Directive 2013/36/EU, the aspects described in paragraphs 1 to 8 shall be part of or combined with the risk management procedures established by that Union law.
《人工智能法案》第九条:
1. 对于高风险的人工智能系统,应在人工智能系统的整个生命周期内建立、实施、记录和维护风险管理系统。只要符合本条的要求,该风险管理系统可以被整合到与欧盟相关部门法有关的现有风险管理程序或作为其一部分。
2.风险管理系统应包括一个贯穿高风险人工智能系统整个生命周期的持续迭代过程,要求定期审查和更新风险管理程序,以确保其持续有效,并根据本条规定记录任何重要决定和行动。它应包括以下步骤:
(a) 识别、预估和评估高风险人工智能系统在按照其预期目的和在可合理预见的误用条件下使用时,可能对自然人的健康或安全、基本权利(包括平等的机会)、民主和法治或环境构成的已知和可合理预见的风险;
(c) 评估(a)点所述的新出现的重大风险,并根据对第61条所述的市场后监测系统收集的数据的分析来确定;
(d) 采取适当的和有针对性的风险管理措施,以便根据以下各款的规定,解决根据本款(a)项和(b)项(笔者注:最新草案已删除(b)项)确定的风险。
3.第2款(d)项提及的风险管理措施应适当考虑综合应用本法案第二章规定的要求所产生的影响和可能的相互作用,以便有效地减轻风险,同时确保适当和相称地实施该些要求。
4.第2款(d)项中提到的风险管理措施应使与高风险人工智能系统的每个与危险相关的残留风险以及全部残留风险被合理地判断为可以被接受,但高风险人工智能系统是按照其预定目的或在可合理预见的误用条件下使用的情形除外。这些残留风险和风险管理措施所做的合理判断应传达给部署者。
最合适的风险管理措施应具有以下内容:
(a) 在技术上可行的情况下,通过专家和外部利益相关方参与充分设计和开发高风险的人工智能系统来消除或减少已确定的风险;
(b) 在适当情况下,实施适当的缓解和控制措施,以解决无法消除的重大风险;
(c)第13条提供所需的信息,并在适当时对部署人员进行培训。
在消除或减少与使用高风险人工智能系统有关的风险时,提供者应适当考虑部署者可能需要的技术知识、经验、教育和培训,包括与假定的使用环境有关的知识。
5. 应对高风险人工智能系统进行测试,以确定最适当和最有针对性的风险管理措施,并将任何此类措施与该系统的潜在利益和预期目标进行权衡。测试应确保高风险人工智能系统为其预期目的持续运行,并且它符合本章规定的要求。
6.测试程序应适合于实现人工智能系统的预期目的。
7.高风险人工智能系统的测试应在投放市场或投入使用前进行。应根据事先确定的指标和概率阈值进行测试,这些指标和阈值应与高风险人工智能系统的预期目的或可合理预见的误用条件相适应。
8.在实施第1至7款所述的风险管理系统时,提供者应具体考虑高风险人工智能系统是否有可能对弱势群体或儿童产生不利影响。
9.对于已经根据欧盟法律要求建立特定风险管理的提供者和人工智能系统,包括受第2013/36/EU号指令监管的信贷机构,第1至8款所述的方面应是该欧盟法律所规定的风险管理程序的一部分或与之相结合。
[20] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32019R1020.
[21]http://www.npc.gov.cn/npc/c30834/202108/a8c4e3672c74491a80b53a172bb753fe.shtml.
欧盟《人工智能法案》第九、第十、第十三条制度
查明及企业合规指引
/ 目次 /
一、《人工智能法案》主要制度查明
(一)数据治理(Article 10 Data Governance)制度
1. 数据治理制度的渊源
2. 数据治理制度的内容
3. 处理个人数据规则
(二)透明度(Article 13 Transparency)义务
1. 透明度义务的渊源
2. 透明度义务的内容
3. 披露训练数据版权规则
(三)风险管理(Article 9 Risk Management)制度
1. 风险管理制度的内容
2. 风险管理制度的法律适用问题
二、《人工智能法案》合规指引
(一)《人工智能法案》监管流程
1. 监管主体
2. 市场监督
3. 执法程序
(二)涉欧企业合规指引
1. 遵守数据处理的多重法律
2. 透明度义务方面
3. 建立全周期风险管理制度
导言
欧洲议会全体会议已于2023年6月14日表决通过了欧盟《人工智能法案》(Artificial Intelligence Act)1。该法案将进入立法的最终三方会谈阶段。《人工智能法案》在未来生效后将会成为全球首部人工智能监管法规,并可能会加剧“布鲁塞尔效应”,对各国涉欧企业产生强制约束力。《人工智能法案》对人工智能系统以风险为依据进行分级,对不同的人工智能系统采取不同监管口径。其中,高风险人工智能系统是《人工智能法案》的主要规制对象,也是合规义务较重的对象。其中,《人工智能法案》在数据治理、透明度义务、风险管理制度设置方面,对高风险人工智能系统提出了一系列要求,对我国具有一定借鉴的意义。本文旨在对上述制度的设置进行分析讨论,并为涉欧企业在未来《人工智能法案》生效后,提供一定的合规指引。

图1
风险等级分类,曾雄、梁正、张辉《欧盟人工智能的规制路径及其对我国的启示——以<人工智能法案>为分析对象》
一、《人工智能法案》主要制度查明
2020年,基于人工智能的飞速发展,为建立技术与欧盟价值观相结合的监管体制,欧盟委员会发布了《人工智能白皮书》(White Paper on Artificial Intelligence: a European approach to excellence and trust)2,强调从卓越生态系统(ecosystem of excellence)和信任生态系统(ecosystem of trust)两方面建立可信赖与安全的人工智能监管框架。《人工智能法案》正是 《人工智能白皮书》的法律延伸,《人工智能白皮书》中呼吁训练数据需安全度高、应用高风险人工智能时提供必要信息、开展事前一致性评估等要求都反映在《人工智能法案》中规定的数据治理、透明度义务和风险管理等相关制度中。下文将对高风险人工智能系统的数据治理、透明度义务和风险管理规则进行分析,了解该些制度的建立将如何实现可信赖与安全的人工智能监管框架。

图2
高风险人工智能系统范围,Trail-ml官网
(一)数据治理(Article 10 Data Governance)制度
1. 数据治理制度的渊源
数据治理是随着大数据应用的普及以及企业数字化转型而诞生的制度。在《通用数据保护条例》(General Data Protection Regulation,以下简称为GDPR)3等数据隐私法律法规出台后,数据治理成为企业的重要合规环节之一。而人工智能系统经常用于预测、评估某行为,该种预测与评估的成功与否很大程度上取决于所训练用和学习的数据量、范围和数据准确性。然而,即便所使用的数据能够满足以上要求,人工智能系统的行为仍然存在一定程度的不可预测性,这种行为即为“涌现”(Emergence)。欧盟委员会为了避免人工智能系统这一风险,在《人工智能法案》第十条中规定了一系列数据治理的要求。
欧盟数据保护执法部门(Data Protection Authorities)会确保欧盟的数据保护与治理方面的规则能够得到一致的应用,这种理念也在《人工智能法案》中得到体现。《人工智能法案》承袭了此前欧盟出台的包括GDPR、《数据保护执法指令》(Data Protection Law Enforcement Directive)4、《隐私与电子通信指令》(Privacy and Electronic Communications Directive)5等数据治理相关法律的类似表述。
2. 数据治理制度的内容
《人工智能法案》第十条6规定,如果高风险人工智能系统使用数据集进行训练,则训练、验证和测试的数据集应当使用符合第二至第五款规定的标准进行。例如,应当采用适当的数据治理措施(第十条第二款,如下图);数据集应当具有相关性、充分的代表性、适当的审查错误并在考虑到预期目的的情况下尽可能完整(第十条第三款);数据集应在人工智能系统的预期目的或可合理预见的误用所要求的范围内,考虑到高风险人工智能系统拟使用的特定的地理、场景、行为或功能环境所特有的特征或要素(第十条第四款);高风险人工智能系统的提供者在符合一定条件下可以处理特别种类的个人数据(第十条第五款)。此外,高风险人工智能系统的部署者在一定情形下应当承担本条规定的责任(第十条第六款)。

图3
《人工智能法案》第十条第二款的数据治理措施要求
该条文在最初的版本中,要求数据集应当具有相关性、代表性、无错误性与完整性。这与我国《生成式人工智能服务管理办法(征求意见稿)》第七条第二款第四项7要求一致,需要确保数据的真实性与准确性。但在客观上是不存在此类完美的数据的。彼时《人工智能法案》的该项条文也收到了葡萄牙、丹麦、比利时、西班牙、瑞典等多国要求修改“完美数据”表述的意见。最终,该条文尊重了各成员国的意见,对数据集附加了多项条件,要求“数据集应当具有相关性、充分的代表性、适当的审查错误并在考虑到预期目的的情况下尽可能完整。”
然而,《人工智能法案》的数据治理制度仍不是尽善尽美的。该法案第十条第四款要求数据集应在人工智能系统的预期目的或可合理预见的误用所要求的范围内,考虑到高风险人工智能系统拟使用的特定的地理、场景、行为或功能环境所特有的特征或要素,但并未对该些特征与要素的内涵与外延进行明确定义,这会导致在数据治理上是否符合该些特征与要素缺失客观性标准。
3. 处理个人数据规则
根据《人工智能法案》的说明备忘录,GDPR等法律不受《人工智能法案》的影响。因此,只要提供者在开发其高风险人工智能系统时使用个人数据,就必须遵守《人工智能法案》的数据处理要求以及GDPR等法律对于个人数据处理的要求。但在涉及特别种类的个人数据时,《人工智能法案》的数据治理制度设置了不同于上述的例外规则。主要体现为:GDPR第九条第一款8规定了特别种类的个人数据的概念,即为“对揭示种族或民族出身,政治观点、宗教或哲学信仰,工会成员的个人数据,以及以唯一识别自然人为目的的基因数据、生物特征数据,健康、自然人的性生活或性取向的数据”。GDPR、《数据保护执法指令》等法律明令禁止处理特别种类的个人数据。但出于高风险人工智能系统检测与纠正负面偏差的需求,在保障自然人基本权利与自由的前提下,提供者可以对特别种类的个人数据进行处理,并且提供者应当符合第十条第五款(a)至(g)项规定的条件,并起草必要性说明。
(二)透明度(Article 13 Transparency)义务
1. 透明度义务的渊源
透明度义务源自于对算法的透明度规制。GDPR首次在立法中提出算法解释权,要求算法解释权来实现算法透明度。而后欧洲议会研究服务机构发布的《算法问责及透明度监管框架》(A Governance Framework for Algorithmic Accountability and Transparency)9对于算法及其在自动化决策系统中的应用快速增长提出了全面的监管框架。欧盟《数字服务法》(Digital Service Act)10要求在线平台采取广泛的透明度措施包括推荐算法的透明度,让用户更好地了解平台是如何向他们推荐内容。透明度义务也是欧盟对人工智能系统的开发、部署和使用始终倡导的核心价值之一。自监管人工智能的政策进程开始以来,欧盟相关机构发布的《可信人工智能伦理准则》(Ethics Guidelines for Trustworthy AI issued)11、《人工智能白皮书》以及《人工智能、机器人和相关技术的伦理问题框架》(Framework of Ethical Aspects of AI, Robotics and Related Technologies)12等政策文件都分别包含了透明度的规定。
2. 透明度义务的内容
《人工智能法案》第十三条13规定对于高风险人工智能系统的设计和开发应确保其运作具有足够的透明度,使用户能够理解系统的输出并加以适当使用。透明度指在高风险人工智能系统进入市场时,应利用根据公认的最新技术水平以及可行的所有技术手段,确保该人工智能系统的输出可以被提供者和用户理解。用户应当能够通过了解人工智能系统的工作原理和数据处理情况,适当地理解和使用该人工智能系统,并能够根据第68(c)条款向受影响的人解释人工智能系统所做出的决策。
但在机器学习中,许多人工智能无法给出解决问题的步骤,而只能看到输入和输出内容,这被称为黑箱模型(black box)。由于《人工智能法案》并未定义“用户能够理解系统的输出”中“理解(interpret)”的内涵,此类黑箱模型都无法满足《人工智能法案》的透明度义务。有人认为,此处的“理解”等同于可以向用户解释(explain),解释的程度则根据不同情况而定,例如对无技术知识的自然人而言,需要对其解释导致特定结果的逻辑或有关于他的人工智能系统决策的重要影响因素。但理解是否能够等同于解释还有待商榷。14从立法目的来看,神经网络模型(DNN)就是一种黑箱模型,其因为由成千上万的人造神经元组成,以扩散方式来解决问题,算法结构十分复杂,难以被用户理解。15但若因此类人工智能系统无法满足透明度义务而被排除在欧盟市场之外,将会严重阻碍技术创新与欧洲市场发展。故《人工智能法案》第十三条在设计时存在一定不足。
此外,《人工智能法案》的透明度义务的要素与此前人工智能政策文件规定的透明度义务的要素并不一致。《可信人工智能伦理准则》中,记录义务是可追溯性的一部分,而可追溯性是透明度的要素;《人工智能白皮书》中透明度的要素之一就是保存记录、文档和数据;《人工智能、机器人和相关技术的伦理问题框架》中规定人工智能高风险技术以透明和可追溯的方式开发、部署和使用,以便其要素、流程,并按照尽可能高的适用标准记录各个阶段。规定人工智能高风险技术以透明和可追溯的方式开发、部署和使用,以便其要素、流程,并按照尽可能高的适用标准记录各个阶段。可见,技术文件和记录保存应当为透明度的要素,但在《人工智能法案》中却被列在透明度义务条款之外。笔者认为,《人工智能法案》应当延续此前人工智能政策文件采取的做法,将技术文件和记录保存作为透明度义务的一部分。
3. 披露训练数据版权规则
《人工智能法案》第二十八b条第四款(c)项16规定生成式人工智能使用的基础模型提供者应当记录并公开提供受版权法保护的训练数据的使用情况的足够详细的摘要。该条所体现的背景是Stability AI、Midjourney等生成式人工智能系统在训练时所用数据并未取得作者的授权,对于各行业创作者都产生了较大的影响。例如2023年1月,著名图片公司Getty Images 在伦敦高等法院对 Stability AI 提起法律诉讼,声称 Stability AI没有向 Getty Images寻求任何许可,非法复制和处理了数百万受版权保护的图像,侵犯了Getty Images所拥有作品的版权。
起初,欧盟委员会成员提议全面禁止将受版权保护的材料用于训练生成式 AI 模型,但最终出于保护相关主体的版权,并尽可能减小对于生成式人工智能发展的阻碍,修改为要求基础模型提供者承担透明度义务。
(三)风险管理(Article 9 Risk Management)制度
1. 风险管理制度的内容
鉴于人工智能系统可能导致的一系列风险,风险管理制度尤为重要。近年来,多个标准制定机构正在起草人工智能风险管理框架,其中最知名的就是美国国家标准与技术研究院(NIST)的《人工智能风险管理框架》(Artificial Intelligence Risk Management Framework)17以及国际标准化组织及国际电工委员会联合制定的《人工智能风险管理基本指南》(ISO/IEC 23894:2023 Information technology – Artificial intelligence – Risk management)18。多家包括普华永道在内的公司也发布了人工智能风险管理报告。
而《人工智能法案》第九条19也规定了高风险人工智能系统的风险管理制度,要求在人工智能系统的整个生命周期中,应建立、实施、记录和维护与高风险人工智能系统有关的风险管理系统,包括识别分析已知和可预见的风险、评估使用后可能的风险、基于上市后检测数据预估风险、采取风险管理措施。
众所周知,《人工智能法案》基于风险不同,对人工智能系统采取了不同的监管措施:禁止具有不可接受风险的人工智能系统,对高风险人工智能系统提出了具体要求,而风险较低或最小的人工智能系统基本上不受严厉的监管。为了降低高风险人工智能系统的风险,该系统的提供者必须遵守《人工智能法案》的相关规定。但立法者认为这不足以将所有风险降低到可接受的水平,即使高风险人工智能系统的提供者遵守了所有义务和要求。仍然可能存在一定的风险。而《人工智能法案》第九条的作用就是确保提供者识别风险并采取额外措施将其降低到可接受的水平。故风险管理制度具有重要的补充作用。
2. 风险管理制度的法律适用问题
风险管理制度并不是《人工智能法案》独有的规则,欧盟既有立法中已经存在特定的风险管理制度规则,例如2013/36号指令要求信贷机构建立适当的风险管理程序以便适当地识别、衡量、监测和控制与混合控股母公司及其子公司的交易。而既有立法的风险管理制度,其如何与《人工智能法律》的风险管理制度衔接成为一个问题。根据《人工智能法案》第九条第九款,人工智能系统风险管理制度应当作为既有的风险管理制度的一部分。换句话说,人工智能系统风险管理制度补充了现有立法的风险管理制度,而不是取代它们。有鉴于此,未来任何立法中若规定新的风险管理制度,都可能和人工智能系统风险管理制度相结合而非互斥。
二、《人工智能法案》合规指引
(一)《人工智能法案》监管流程
1. 监管主体
《人工智能法案》框架下,监管主体包括欧洲人工智能办公室(the European Artificial Intelligence Office)、国家监督机构(National Supervisory Authority)以及其他主体。欧洲人工智能办公室是欧盟的独立机构,主要负责对于《人工智能法案》的实施为国家与组织提供支持、建议与合作,在不影响国家监督机构工作的情况下,监督并确保《人工智能法案》的有效实施。总的来说,欧洲人工智能办公室设立的目的主要是促进《人工智能法案》所规定的各种制度的落实与完善,以及国家与组织之间的沟通与协调。国家监督机构则是由成员国指定的机构,作为在该国确保《人工智能法案》适用和实施的主管机构。国家监督机构在成员国内,应当作为市场监督机构行事。在特殊情况下,由特定主体而非国家监督机构进行监管,例如受欧盟金融服务相关立法管制的金融机构投放市场、投入使用的人工智能系统,则由根据相关金融服务立法规定的主管机构监管。
2. 市场监督
《人工智能法案》要求建立市场监督体系。市场监督体系可以分为上市后监测与事故与故障信息分享。上市后监测指高风险人工智能系统提供者应当建立积极和系统地收集、记录和分析关于高风险人工智能系统在其整个生命周期内的性能的相关数据的监测系统。事故与故障信息分享是指高风险人工智能系统的提供者或部署者应当在系统发生严重事件时进行报告,提供者及部署者应当在确定人工智能系统与严重事件之间的因果关系或合理可能性后72小时内国家监督机构报告。国家监督机构应当在收到报告之日起七日内采取适当措施。
3. 执法程序
国家监督机构作为市场监督机构,具有《欧盟市场监管法规》20的权力和义务,对《人工智能法案》下的人工智能系统和基础模型进行监管。对高风险人工智能系统,国家监督机构有权进行不预先通知的现场和远程检查,并且有权获取与高风险人工智能系统有关的样本。当国家监督机构认为人工智能系统可能对基本权利、公共安全、消费者权益、民主法治等产生不利影响时,可以对该人工智能系统是否符合《人工智能法案》的所有要求和义务进行评估。评估结果可分为两种,第一种评估结果为该人工智能系统不符合《人工智能法案》的要求与义务,国家监督机构将立刻要求有关主体采取一切适当措施进行纠正。若有关主体并未进行纠正,国家监督机构将禁止或限制该人工智能系统进入市场,并将市场中现有的该系统进行撤出或召回。第二种评估结果为该人工智能系统虽然符合《人工智能法案》的要求与义务,但对基本权利、公共安全、消费者权益、民主法治等方面存在风险,在此种情况下,国家监督机构有权要求有关主体消除该种风险。
在收到国家监督机构的执法决定后,有关主体也可以进行相关救济。有关主体可以针对国家监督机构的决定向国家监督机构所在成员国的法院提起诉讼。
有关主体若被国家监督机构认定违反《人工智能法案》,将面临巨额行政罚款。对于提供具有不可接受风险的人工智能系统的主体,将被处以4,000万欧元或上一财政年度全球总营业额7%二者较高者的行政罚款;对于违反数据治理制度与透明度义务的主体,将被处以2,000万欧元或上一财政年度全球总营业额4%二者较高者的行政罚款;对于除上述外的其他要求和义务的主体,将被处以1,000万欧元或上一财政年度全球总营业额2%二者较高者的行政罚款;对于向国家监督机构或其他主管部门提供虚假、不完整或误导性信息的主体,将被处以500万欧元或上一财政年度全球总营业额1%二者较高者的行政罚款。
(二) 涉欧企业合规指引

图4
企业部署人工智能系统前的
thought-and-act process,Nikita Lukianets
1. 遵守数据处理的多重法律
2023年3月,意大利个人数据保护局宣布,意大利禁止使用ChatGPT,并限制开发这一平台的OpenAI公司处理意大利用户信息。意大利个人数据保护局认为ChatGPT没有就收集处理用户信息进行告知,缺乏大量收集和存储个人信息的法律依据。应在满足一定质量标准的数据上进行训练、验证和测试,采集、标注、清洗数据遵守管理规范,并保障数据具有代表性、准确性和完整性。意大利个人数据保护局对ChatGPT违反数据收集规则展开调查。
可见,企业在使用个人数据训练人工智能系统时,一方面,根据《人工智能法案》第十条,高风险人工智能系统提供者必须遵守该条关于数据集的要求;另一方面,根据GDPR,对于这些数据集的验证很可能也构成对个人数据的处理。因此,高风险人工智能系统提供者同时也成为数据控制者,应当根据GDPR规定的例如征得用户同意等合法性基础来处理数据集。最后,企业还应当遵守我国关于处理个人数据的《个人信息保护法》21等相关法律的要求。
2. 透明度义务方面
企业应当以简洁、完整、正确、清晰、相关、可访问和可理解的形式,向用户提供使用说明、人工智能提供者的联系方式、人工智能的特征、能力和性能限制、系统可预见的变化和预期寿命、人类监督措施等。
此外,由于对于“理解”的内涵尚未清楚,还需要立法者进行澄清。笔者认为可以参考此前《可信人工智能伦理准则》中关于透明度的要求,即要求企业解释(explain)为什么模型会生成特定的输出或决策(以及输入内容的哪些组合促成了这一结果)。当无法进行解释时,可以采用可追溯性、可审计性和透明化通信等替代措施履行透明度义务。虽然理解与解释并不属于同一词,但在人工智能开发中,这两个词语经常被交叉使用。
3. 建立全周期风险管理制度
根据《人工智能法案》第九条,高风险人工智能系统应当建立全周期风险管理系统,包括识别分析已知和可预见的风险、评估使用后可能的风险、基于上市后检测数据预估风险、采取风险管理措施。
《人工智能法案》在风险识别环节即纳入“可预见的风险”,其定义是“人工智能系统的使用方式不符合其预期目的,但可能是由于合理可预见的人类行为或与其他系统的交互而导致的”。
而在评估使用后可能的风险时,企业应当考虑到《人工智能法案》规定的透明度网络安全、人为监督和记录保存等规则,根据初步确定的指标和概率(例如潜在的滥用情况)进行测试,评估使用后可能的风险。
高风险人工智能系统进入市场后,风险管理并没有结束。基于上市后检测数据预估风险是风险管理制度的关键组成部分。这将需要人工智能系统提供者在建立多个反馈与沟通渠道,并在部署人工智能系统后进行跟踪,将来自反馈与沟通渠道的信息及时交付给相关团队。一旦高风险人工智能系统进入市场后,企业应当完成事故发生的补救计划,以备不时之需。
此外,企业应当在入市前就针对不同人群进行人工智能系统风险评估,为特殊用户群体(例如儿童)采用量身定制的风险控制措施。同时,企业也应当向其系统的用户提供充分的信息和适当的培训。
注释:
[1] https://www.europarl.europa.eu/doceo/document/TA-9-2023-0236_EN.html.
[2] https://commission.europa.eu/publications/white-paper-artificial-intelligence-european-approach-excellence-and-trust_en.
[3] https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679.
[4] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016L0680.
[5] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02002L0058-20091219.
[6] Artificial Intelligence Act, Article 10:
1. High-risk AI systems which make use of techniques involving the training of models with data shall be developed on the basis of training, validation and testing data sets that meet the quality criteria referred to in paragraphs 2 to 5 as far as this is technically feasible according to the specific market segment or scope of application.
Techniques that do not require labelled input data such as unsupervised learning and reinforcement learning shall be developed on the basis of data sets such as for testing and verification that meet the quality criteria referred to in paragraphs 2 to 5.
2. Training, validation and testing data sets shall be subject to data governance appropriate for the context of use as well as the intended purpose of the AI system.
Those measures shall concern in particular,
(a) the relevant design choices;
(aa) transparency as regards the original purpose of data collection;
(b) data collection processes;
(c) relevant data preparation processing operations, such as annotation, labelling, cleaning, updating enrichment and aggregation;
(d) the formulation of assumptions, notably with respect to the information that the data are supposed to measure and represent;
(e) an assessment of the availability, quantity and suitability of the data sets that are needed;
(f) examination in view of possible biases that are likely to affect the health and safety of persons, negatively impact fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations (‘feedback loops’) and appropriate measures to detect, prevent and mitigate possible biases;
(fa) appropriate measures to detect, prevent and mitigate possible biases;
(g) the identification of relevant data gaps or shortcomings that prevent compliance with this Regulation, and how those gaps and shortcomings can be addressed.
3. Training datasets, and where they are used, validation and testing datasets, including the labels, shall be relevant, sufficiently representative, appropriately vetted for errors and be as complete as possible in view of the intended purpose. They shall have the appropriate statistical properties, including, where applicable, as regards the persons or groups of persons in relation to whom the high-risk AI system is intended to be used. These characteristics of the datasets shall be met at the level of individual datasets or a combination thereof.
4. Datasets shall take into account, to the extent required by the intended purpose or reasonably foreseeable misuses of the AI system, the characteristics or elements that are particular to the specific geographical, contextual behavioural or functional setting within which the highrisk AI system is intended to be used.
5. To the extent that it is strictly necessary for the purposes of ensuring negative bias detection and correction in relation to the high-risk AI systems, the providers of such systems may exceptionally process special categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679, Article 10 of Directive (EU) 2016/680 and Article 10(1) of Regulation (EU) 2018/1725, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons, including technical limitations on the re-use and use of state-of-the-art security and privacy-preserving. In particular, all the following conditions shall apply in order for this processing to occur:
(a) the bias detection an correction cannot be effectively fulfilled by processing synthetic or anonymised data;
(b) the data are pseudonymised;
(c) the provider takes appropriate technical and organisational measures to ensure that the data processed for the purpose of this paragraph are secured, protected, subject to suitable safeguards and only authorised persons have access
to those data with appropriate confidentiality obligations; (d) the data processed for the purpose of this paragraph are not to be transmitted, transferred or otherwise accessed by other parties;
(e) the data processed for the purpose of this paragraph are protected by means of appropriate technical and organizational measures and deleted once the bias has been corrected or the personal data has reached the end of its retention period;
(f) effective and appropriate measures are in place to ensure availability, security and resilience of processing systems and services against technical or physical incidents;
(g) effective and appropriate measures are in place to ensure physical security of locations where the data are stored and processed, internal IT and IT security governance and management, certification of processes and products; Providers having recourse to this provision shall draw up documentation explaining why the processing of special
categories of personal data was necessary to detect and correct biases.
6 a. Where the provider cannot comply with the obligations laid down in this Article because that provider does not have access to the data and the data is held exclusively by the deployer, the deployer may, on the basis of a contract, be made responsible for any infringement of this Article.
《人工智能法案》第十条:
1. 利用数据训练模型的高风险人工智能系统应在训练、验证和测试数据集的基础上进行开发。只要根据具体的市场部门或应用范围,使得在技术上是可行的,这些数据集就应符合本条第2至5款所述的质量标准。
例如非监督学习和强化学习等不需要标记输入数据的技术,应在符合本条第2至5款所述质量标准的测试和验证数据集的基础上开发。
2. 训练、验证和测试数据集应受到符合人工智能系统使用环境和预期目的的数据治理。
这些措施应特别涉及
(a) 相关的设计选择;
(aa) 数据收集的原始目的的透明度义务;
(b) 数据收集程序;
(c) 数据预处理程序,如注解、标记、清理、更新丰富和汇总;
(d) 假设的制定,特别是数据所要表征和衡量的信息;
(e) 评估所需数据集的可用性、数量和适宜性;
(f) 针对可能影响的自然人的健康和安全、可能对基本权利产生负面影响或可能导致欧盟法律所禁止的歧视的可能的偏差,特别是当输出的数据影响到未来程序的输入时(“反馈循环”)进行审查,以及;
(fa) 采取适当措施,检测、预防和减轻可能的偏差;
(g) 确定妨碍遵守本条例的相关数据缺口或缺陷,以及如何解决该些缺口和缺陷。
3. 包括标签在内,训练的数据集,以及在使用时的验证和测试的数据集,应具有相关性、充分的代表性、进行适当的错误审查,并在考虑到预期目的的情况下尽可能完整。它们应具有适当的统计特性,包括在适用的情况下的与高风险人工智能系统拟使用的自然人或自然人群体有关的统计特性。单个数据集或其组合均应满足上述特征。
4. 数据集应在人工智能系统的预期目的或可合理预见的误用所要求的范围内,考虑到高风险人工智能系统拟使用的特定的地理、场景、行为或功能环境所特有的特征或要素。
5. 在为确保高风险人工智能系统的负面的偏差检测和纠正的必要性的前提下,该些系统的提供者可以例外地处理欧盟2016/679号条例第9(1)条、欧盟2016/680号指令第10条和欧盟2018/1725号条例第10(1)条中提到的特别种类的个人数据,但必须对自然人的基本权利和自由采取适当的保障措施,包括对于重复使用的技术限制以及使用最先进的安全和隐私保护。特别注意的是,为了进行该种特别种类的个人数据处理,应同时符合下列条件:
(a) 通过处理合成的或匿名的数据,不能有效地实现偏差检测和纠正;
(b) 数据是假名化的;
(c) 提供者采取适当的技术和组织措施,确保为本款之目的而处理的数据是安全的且受到保护与适当的保障,只有被授权且负有适当的保密义务的人才能访问该些数据;
(d) 为本款之目的而处理的数据不会被其他方传输、转移或以其他方式获取;
(e) 为本款之目的而处理的数据通过适当的技术和组织措施加以保护,并在纠正偏差后或个人数据的保留期结束后予以删除;
(f) 采取有效和适当的措施,确保处理技术或物理事故的系统和服务的可用性、安全性和适应性;
(g) 采取有效和适当的措施,确保存储和处理数据的地点的物理安全、内部信息技术和信息技术安全治理和管理、流程和产品的认证。
诉诸本条款的提供者应起草文件解释处理特别种类的个人数据以检测和纠正偏见的必要性。
6 a.因数据只由部署者持有,提供者无法访问数据,导致提供者不能遵守本条规定的义务的,部署者可根据合同对任何违反本条的行为承担责任。
[7] 《生成式人工智能服务管理办法(征求意见稿)》第七条第二款第四项:用于生成式人工智能产品的预训练、优化训练数据,应满足以下要求:……(四)能够保证数据的真实性、准确性、客观性、多样性……
[8] GDPR, Article 9 Paragraph 1: Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited.
《通用数据保护条例》第九条第一款:禁止处理揭示种族或民族出身,政治观点、宗教或哲学信仰,工会成员的个人数据,以及以唯一识别自然人为目的的基因数据、生物特征数据,健康、自然人的性生活或性取向的数据。
[9]https://www.europarl.europa.eu/thinktank/en/document/EPRS_STU(2019)624262.
[10]https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022R2065.
[11]https://digital-strategy.ec.europa.eu/en/library/ethics-guidelines-trustworthy-ai.
[12]https://www.europarl.europa.eu/doceo/document/TA-9-2020-0275_EN.html.
[13] Artificial Intelligence Act, Article 13:
1. High-risk AI systems shall be designed and developed in such a way to ensure that their operation is sufficiently transparent to enable providers and users to reasonably understand the system’s functioning. Appropriate transparency shall be ensured in accordance with the intended purpose of the AI system, with a view to achieving compliance with the relevant obligations of the provider and user set out in Chapter 3 of this Title.
Transparency shall thereby mean that, at the time the high-risk AI system is placed on the market, all technical means available in accordance with the generally acknowledged state of art are used to ensure that the AI system’s output is interpretable by the provider and the user. The user shall be enabled to understand and use the AI system appropriately by generally knowing how the AI system works and what data it processes, allowing the user to explain the decisions taken by the AI system to the affected person pursuant to Article 68(c).
2. High-risk AI systems shall be accompanied by intelligible instructions for use in an appropriate digital format or made otherwise available in a durable medium that include concise, correct, clear and to the extent possible complete information that helps operating and maintaining the AI system as well as supporting informed decision-making by users and is reasonably relevant, accessible and comprehensible to users .
3. To achieve the outcomes referred to in paragraph 1, information referred to in paragraph 2 shall specify:
(a) the identity and the contact details of the provider and, where applicable, of its authorised representatives;
(aa) where it is not the same as the provider, the identity and the contact details of the entity that carried out the conformity assessment and, where applicable, of its authorized representative;
(b) the characteristics, capabilities and limitations of performance of the high-risk AI system, including, where appropriate:
(ii) the level of accuracy, robustness and cyber security referred to in Article 15
against which the high-risk AI system has been tested and validated and which can be expected, and any clearly known and foreseeable circumstances that may have an impact on that expected level of accuracy, robustness and cybersecurity;
(iii) any clearly known or foreseeable circumstance, related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety, fundamental rights or the environment, including, where appropriate, illustrative examples of such limitations and of scenarios for which the system should not be used;
(iiia) the degree to which the AI system can provide an explanation for decisions it takes;
(v) relevant information about user actions that may influence system performance, including type or quality of input data, or any other relevant information in terms of the training, validation and testing data sets used, taking into account the intended purpose of the AI system.
(e) any necessary maintenance and care measures to ensure the proper functioning of that AI system, including as regards software updates, through its expected lifetime.
(ea) a description of the mechanisms included within the AI system that allows users to properly collect, store and interpret the logs in accordance with Article 12(1).
(eb) The information shall be provided at least in the language of the country where the AI system is used.
3a. In order to comply with the obligations laid down in this Article, providers and users shall ensure a sufficient level of AI literacy in line with Article 4(b).
《人工智能法案》第十三条:
1. 高风险人工智能系统的设计和开发应确保其运作具有足够的透明度,使提供者和使用者能够合理地了解系统的运作;根据人工智能系统的预期目的,应确保适当的透明度以确保提供者和使用者遵守本篇第三章规定的相关义务。
因此,透明度应指在高风险人工智能系统进入市场时,应利用根据公认的最新技术水平以及可行的所有技术手段,确保该人工智能系统的输出可以被提供者和用户理解。用户应当能够通过了解人工智能系统的工作原理和数据处理情况,适当地理解和使用该人工智能系统,并能够根据第68(c)条款向受影响的人解释人工智能系统所做出的决策。
2. 高风险人工智能系统应附有以适当的数字格式或持续存在的媒介提供的可理解的使用说明,使用说明包括简明、正确、清晰和尽可能完整的信息,以辅助操作和维护人工智能系统以及支持用户的知情决策,使用说明应对用户有合理的相关性、可访问性和可理解性。
3. 为了实现第1款中提到的结果,第2款中提到的信息应说明:
(a) 提供者及其授权代表(如适用)的身份和详细联系方式;
(aa) 如果进行合格评估的实体不是提供者,应说明其及其授权代表(如适用)的身份和详细联系方式;
(b) 高风险人工智能系统的特点、能力和性能限制,包括(如适用):
(ii) 该系统已经过测试和验证可以预期达到的第15条所指的准确度、稳健性和网络安全水平,以及可能对预期的准确度、稳健性和网络安全产生影响的任何明确已知和可预见的情况;
(iii) 任何明确的已知或可预见的情况,包括:与按照高风险人工智能系统的预期目的或在可合理预见的误用条件下使用该系统有关,可能对健康和安全、基本权利或环境造成的风险,以及酌情说明该系统的该种限制和不应被使用的场景的示例;
(iiia) 人工智能系统能够为其做出的决定进行解释的程度;
(v)可能影响系统性能的用户行为的相关信息,包括输入数据的类型或质量,或考虑到人工智能系统的预期目的,所使用的训练、验证和测试数据集方面的任何其他相关信息。
(e) 为确保该人工智能系统在其预期使用寿命内正常运作的任何必要的维护和保养措施,包括软件更新措施。
(ea) 关于人工智能系统内所包含的允许用户根据第12条第1款适当地收集、储存和解释日志机制的说明。
(eb) 这些信息应至少以使用人工智能系统的国家的语言提供。
3a. 为了遵守本条规定的义务,提供者和使用者应根据第4(b)条的规定,确保有足够的人工智能知识水平。
[14] Stefan Larsson, Fredrik Heintz, Transparency in Artificial Intelligence, Internet Policy Review, 9(2).
[15] Yavar Bathaee, The Artificial Intelligence Black Box and The Failure of Intent and Causation, Harvard Journal of Law & Technology Volume 31, Number 2 Spring 2018.
[16] Artificial Intelligence Act, Article 28b:
4. Providers of foundation models used in AI systems specifically intended to generate, with varying levels of autonomy, content such as complex text, images, audio, or video (“generative AI”) and providers who specialise a foundation model into a generative AI system, shall in addition
c) without prejudice to Union or national or Union legislation on copyright, document and make publicly available a sufficiently detailed summary of the use of training data protected under copyright law.
《人工智能法案》第二十八b条:
4. 在人工智能系统中使用基础模型,专门用于以不同程度的自主性生成复杂的文本、图像、音频或视频等内容(“生成式人工智能”)的提供者,以及将基础模型专门用于生成性人工智能系统的提供者,应当:
c) 在不影响欧盟、国家或欧盟版权立法的情况下,记录并公开提供受版权法保护的训练数据的使用情况的足够详细的摘要。
[17]https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10.
[18] https://www.iso.org/standard/77304.html.
[19] Artificial Intelligence Act, Article 9:
1. A risk management system shall be established, implemented, documented and maintained in relation to high-risk AI systems, throughout the entire lifecycle of the AI system. The risk management system can be integrated into, or a part of, already existing risk management procedures relating to the relevant Union sectoral law insofar as it fulfils the requirements of this article.
2. The risk management system shall consist of a continuous iterative process run throughout the entire lifecycle of a high-risk AI system, requiring regular review and updating of the risk management process, to ensure its continuing effectiveness, and documentation of any significant decisions and actions taken subject to this Article. It shall comprise the following steps:
(a) identification, estimation and evaluation of the known and the reasonably foreseeable risks that the high risk AI system can pose to the health or safety of natural persons, their fundamental rights including equal access and opportunities, democracy and rule of law or the environment when the high-risk AI system is used in accordance with its intended purpose and under conditions of reasonably foreseeable misuse;
(c) evaluation of emerging significant risks as described in point (a) and identified based on the analysis of data gathered from the post-market monitoring system referred to in Article 61;
(d) adoption of appropriate and targeted risk management measures designed to address the risks identified pursuant to points a and b of this paragraph in accordance with the provisions of the following paragraphs.
3. The risk management measures referred to in paragraph 2, point (d) shall give due consideration to the effects and possible interactions resulting from the combined application of the requirements set out in this Chapter 2, with a view to mitigate risks effectively while ensuring an appropriate and proportionate implementation of the requirements.
4. The risk management measures referred to in paragraph 2, point (d) shall be such that relevant residual risk associated with each hazard as well as the overall residual risk of the high-risk AI systems is reasonably judged to be acceptable, provided that the high-risk AI system is used in accordance with its intended purpose or under conditions of reasonably foreseeable misuse. Those residual risks and the reasoned judgements made shall be communicated to the deployer.
In identifying the most appropriate risk management measures, the following shall be ensured:
(a) elimination or reduction of identified risks as far as technically feasible through
adequate design and development of the high-risk AI system, involving when relevant, experts and external stakeholders;
(b) where appropriate, implementation of adequate mitigation and control measures addressing significant risks that cannot be eliminated;
(c) provision of the required information pursuant to Article 13, and, where appropriate, training to deployers.
In eliminating or reducing risks related to the use of the high-risk AI system, providers shall take into due consideration the technical knowledge, experience, education and training the deployer may need, including in relation to the presumable context of use.
5. High-risk AI systems shall be tested for the purposes of identifying the most appropriate and targeted risk management measures and weighing any such measures against the potential benefits and intended goals of the system. Testing shall ensure that high-risk AI systems perform consistently for their intended purpose and they are in compliance with the requirements set out in this Chapter.
6. Testing procedures shall be suitable to achieve the intended purpose of the AI system.
7. The testing of the high-risk AI systems shall be performed, prior to the placing on the market or the putting into service. Testing shall be made against prior defined metrics, and probabilistic thresholds that are appropriate to the intended purpose or reasonably foreseeable misuse of the high-risk AI system.
8. When implementing the risk management system described in paragraphs 1 to 7, providers shall give specific consideration to whether the high risk AI system is likely to adversely impact vulnerable groups of people or children.
9. For providers and AI systems already covered by Union law that require them to establish a specific risk management, including credit institutions regulated by Directive 2013/36/EU, the aspects described in paragraphs 1 to 8 shall be part of or combined with the risk management procedures established by that Union law.
《人工智能法案》第九条:
1. 对于高风险的人工智能系统,应在人工智能系统的整个生命周期内建立、实施、记录和维护风险管理系统。只要符合本条的要求,该风险管理系统可以被整合到与欧盟相关部门法有关的现有风险管理程序或作为其一部分。
2.风险管理系统应包括一个贯穿高风险人工智能系统整个生命周期的持续迭代过程,要求定期审查和更新风险管理程序,以确保其持续有效,并根据本条规定记录任何重要决定和行动。它应包括以下步骤:
(a) 识别、预估和评估高风险人工智能系统在按照其预期目的和在可合理预见的误用条件下使用时,可能对自然人的健康或安全、基本权利(包括平等的机会)、民主和法治或环境构成的已知和可合理预见的风险;
(c) 评估(a)点所述的新出现的重大风险,并根据对第61条所述的市场后监测系统收集的数据的分析来确定;
(d) 采取适当的和有针对性的风险管理措施,以便根据以下各款的规定,解决根据本款(a)项和(b)项(笔者注:最新草案已删除(b)项)确定的风险。
3.第2款(d)项提及的风险管理措施应适当考虑综合应用本法案第二章规定的要求所产生的影响和可能的相互作用,以便有效地减轻风险,同时确保适当和相称地实施该些要求。
4.第2款(d)项中提到的风险管理措施应使与高风险人工智能系统的每个与危险相关的残留风险以及全部残留风险被合理地判断为可以被接受,但高风险人工智能系统是按照其预定目的或在可合理预见的误用条件下使用的情形除外。这些残留风险和风险管理措施所做的合理判断应传达给部署者。
最合适的风险管理措施应具有以下内容:
(a) 在技术上可行的情况下,通过专家和外部利益相关方参与充分设计和开发高风险的人工智能系统来消除或减少已确定的风险;
(b) 在适当情况下,实施适当的缓解和控制措施,以解决无法消除的重大风险;
(c)第13条提供所需的信息,并在适当时对部署人员进行培训。
在消除或减少与使用高风险人工智能系统有关的风险时,提供者应适当考虑部署者可能需要的技术知识、经验、教育和培训,包括与假定的使用环境有关的知识。
5. 应对高风险人工智能系统进行测试,以确定最适当和最有针对性的风险管理措施,并将任何此类措施与该系统的潜在利益和预期目标进行权衡。测试应确保高风险人工智能系统为其预期目的持续运行,并且它符合本章规定的要求。
6.测试程序应适合于实现人工智能系统的预期目的。
7.高风险人工智能系统的测试应在投放市场或投入使用前进行。应根据事先确定的指标和概率阈值进行测试,这些指标和阈值应与高风险人工智能系统的预期目的或可合理预见的误用条件相适应。
8.在实施第1至7款所述的风险管理系统时,提供者应具体考虑高风险人工智能系统是否有可能对弱势群体或儿童产生不利影响。
9.对于已经根据欧盟法律要求建立特定风险管理的提供者和人工智能系统,包括受第2013/36/EU号指令监管的信贷机构,第1至8款所述的方面应是该欧盟法律所规定的风险管理程序的一部分或与之相结合。
[20] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32019R1020.
[21]http://www.npc.gov.cn/npc/c30834/202108/a8c4e3672c74491a80b53a172bb753fe.shtml.
