GDPR is killing AI development? Prof. Grzegorz Sibiga: The European Union has overregulated the market
Million-dollar fines in Europe do not impress American digital giants who train artificial intelligence models on billions of data. The European Union is clearly losing in the global technology race. In Poland, the Personal Data Protection Office has not been able to cope with algorithm errors for three years, and courts are starting to detect AI “hallucinations” in procedural documents. – Data protection regulations were created in a completely different technological era, and an attempt to modify them again is a desire to reconcile fire with water – says Prof. in the “Rozmowa Wprost” podcast. Grzegorz Sibiga from the Polish Academy of Sciences.
Artificial intelligence is changing many aspects of our lives, but it is also greatly interfering with our rights. The key problem highlighted by prof. Grzegorz Sibiga, there is an anachronism of the current regulations. Although the General Data Protection Regulation (GDPR) is associated with modernity, its structural core remembers completely different times.
FULL CONVERSATION:
– Today we are trying to match the rights and obligations created for the old realities to the reality of AI algorithms – emphasizes Prof. Sibiga in the “Rozmowa Wprost” podcast.
In the context of artificial intelligence, the discussion about personal data falls into two completely separate areas:
- Input data: Data used at the model training stage (often obtained en masse from the Internet using the so-called web-scraping) and information entered by users in the form of prompts.
- Output: AI-generated results that may contain personal data, process them or directly affect the legal and life situation of specific people.
The current legal framework has difficulty coping with this architecture, which creates fundamental conflicts between business and regulators.
The European Union cannot keep up
Europe sees a risk of losing competitiveness towards the United States or China. The impetus for change was the famous reports of Mario Draghi and Enrico Letta, which clearly indicated that although the high standard of protection of fundamental rights is a reason to be proud, it generates gigantic costs and barriers to innovation.
The European Commission’s response is the package of legislative proposals presented under a collective name Digital Omnibus. It provides for, among others: extensive modifications of the GDPR in terms of artificial intelligence. However, this is not an attempt to annihilate the existing rules, but to make them more flexible. Prof. Sibiga remains skeptical about further changes to the same regulations: “The European Commission is trying to reconcile fire with water. In my opinion, the right path would be a complete, thorough review of the regulations and the creation of completely new legal structures dedicated to AI, instead of permanently modifying what already exists.”
Purpose of personal data processing
For companies developing AI systems, a key barrier is the EU principle of purpose limitation. Since the 1990s, there has been a dogma in European law that personal data is collected for a strictly defined purpose and cannot be changed during processing.
In the case of AI models, this principle breaks down completely. Few data are initially collected in order to train neural networks on them. Information goes online for communication, business or social purposes, and AI providers then use it for machine learning.
Another problem is transparency – GDPR requires detailed information to each person about the processing of their data. In the era of mass training of models on billions of records from the network, fulfilling this obligation becomes technically and logistically impossible.
Three years of helplessness of the Personal Data Protection Office and the problem of AI hallucinations
For three years, the President of the Personal Data Protection Office has been unable to resolve the precedent-setting case of a Polish citizen who discovered that generative AI was creating false information about him. This citizen exercised the standard right to rectification of data (Article 16 of the GDPR), requesting that the technology provider delete the so-called “hallucinations”.
The regulator is stuck because the architecture of the LLM models makes it impossible to simply “cut out” or change a single fact embedded in the neural network’s weights. Prof. Sibiga criticizes the current penalty policy of the Personal Data Protection Office. Although the office imposes more and more severe penalties, almost none of them concern complex AI processes, but simple facts that do not raise any doubts.
– Punishment should be an absolute last resort. The role of the regulator should first be to explain to the market how to apply the regulations in the new reality, present clear guidelines and standards, give time for adaptation, and only then draw consequences – emphasizes the expert.
A landmark decision of the Supreme Administrative Court
Artificial intelligence has also entered courtrooms, which is confirmed by the famous decision of the Supreme Administrative Court (I FZ 104/26). The court sharply criticized a professional attorney who used generative AI to prepare an appeal without verifying the result. The pleading contained numerous legal “hallucinations”, which directly harmed the client’s interests. The Supreme Administrative Court pointed out that in this way the letter could be prepared by the client himself without the help of an expensive lawyer or legal advisor.
“It is expected that the use of AI by applicants will become more and more common in the judicial practice of courts. However, in the court’s opinion, the unreflective use of AI tools by a professional representative when preparing pleadings submitted to the court on behalf of the principal should be assessed very critically,” said the Supreme Administrative Court.
– This case shows that legal self-governments (barristers, legal advisors) must respond urgently by introducing clear ethical principles regarding the use of AI tools in everyday professional practice – says Prof. Sibig.
The Supreme Administrative Court criticized the attorney’s action. He stated that his work came down to the use of AI tools that are also available to people who do not practice law. He also emphasized that such action is not ethical, especially since he receives remuneration for his services.
Who should decide about the future of AI?
The exemplary model for creating a framework for artificial intelligence should be interdisciplinary. The future of technology cannot be designed only by politicians or lawyers. IT specialists, programmers and ethicists should also be invited to act in this area.
Crucially, this voice must be strongly correlated with signals coming from the market. If European start-ups openly admit that they can implement the same project in the US twice as fast and cheaper due to less legal rigor, Europe must treat these concerns as a serious warning. Without flexibility and understanding of technology, EU legislation will win the battle for clarity and respect for rules, but will lose the battle for the technological future.
