Industry executives and experts share their predictions for 2024. Read them in this 16th annual VMblog.com series exclusive.
In 2024: GDPR Will Be Key to the Future of AI
By Gary Dempsey, Vice President Emerging Technology, IDA Ireland (Ireland’s inward investment agency)
By any measure, AI is one of the fastest-growing segments in technology today with staggering predictions of its future size. One report looking at key AI segments like machine learning, robotics, vision and others forecasts a worldwide market reaching $738.8 billion by 2030. However, such a potentially disruptive technology also brings challenges.
“The public trust of AI will be a consideration going forward,” notes Dr. Paul Galvin, who leads the Life Sciences Interface Group at the Tyndall National Institute in Cork, Ireland and the ENTIRE European Digital Innovation Hub, which provides technical and training supports on digital transformation for companies and public organisations. Therefore, a key to achieving growth in AI in 2024 and beyond, particularly in the important European market, will be paying close attention to the General Data Protection Regulation (GDPR).
Passed by the EU in mid 2018, GDPR will provide a blueprint for overcoming some of AI’s biggest challenges. As Galvin explains, “A big concern with AI is how personal data is used, who has access to it, and most importantly, the transparency of the decision-making process.” Particularly in regions with privacy concerns, GDPR is the route to future-proof AI technology there, but accommodating privacy needs will and should be considered for any AI solution anywhere.
The new normal
For U.S. firms wishing to exploit the power of AI in their products for the European market, the GDPR story is illustrative of today’s sensitivity to how user data is protected. The regulation has since been joined with similar efforts in American states such as the California Privacy Rights Act (CPRA) and demonstrates how privacy will be fundamental in AI’s expansion next year and beyond.
GDPR enforces a broad definition of personal data covering any information that relates to an identifiable, living individual stored anywhere. Such personal data is subject to a significant number of protections that fully apply to certain AI products, present and future, with some financial implications and technology revisions for those who ignore GDPR’s current requirements.
Protection is expanding to encompass AI itself, as seen in the EU’s AI Act, soon to be finalized. This and similar regulations will be the new normal when it comes to AI and handling user data.
Keeping it legal
Given GDPR’s regulations, U.S.-based AI companies eying the European market will likely soon become rigorous in how they adhere to privacy requirements. The difficulty for these businesses is having a lawful data set or a data set that can be used lawfully. It’s a challenging prospect for business, particularly when you’re a startup,
According to Doug McMahon, partner at international law firm McCann FitzGerald; “From the ground up, you should be building in privacy,” he advises. “There might be imperfect compliance at the development stages but ultimately the application of the large language model needs to be compliant at the end point of the process.” The guiding principle should be “trustworthy AI,” he says.
In fact, it’s been mentioned that the likely transparency requirements for AI that interacts with humans, such as chatbots and emotion-detection systems, will lead to global disclosure on most websites and apps. McMahon advises that: “The first piece of advice is look at your training dataset and make sure you have a proper data protection notice available on your website to give to users, and make sure that there’s an opt-out mechanism if you’re the creator of the AI dataset.”
GDPR compliance isn’t optional
By 2024, any company wanting to sell AI products in the European market will need to look again at GDPR and the other privacy regulations, in order to reduce the risk of fines and achieve a more competitive position. American companies can sell their AI solutions into Europe from their domestic locales but “from a data protection perspective, it would be ideal to have a base in the EU because the company’s European customers will have questions about your GDPR compliance. Being established in Europe and directly subject to GDPR will help you sell into Europe,” notes McMahon.
Next year, this will likely inspire concerted effort on the part of U.S.-based AI hopefuls to better understand GDPR as well as how and where to set up the most potentially successful overseas office. Issues such as optimal hiring locales, finding good employees, taxes, patent regulations and other business elements will become more important as American companies seek to exploit the attractive European market.
And it’s truly a compelling geography from an AI business potential perspective. One researcher predicted that growth in AI and machine learning, will be close to that in North America. Specifically, from 2021 to 2028, growth in the European market for AI and ML could reach approximately 40% annually. With GDPR and other privacy regulations here to stay, they will be a necessary part of designing, building and marketing new AI products that succeed.
##
ABOUT THE AUTHOR
Gary Dempsey is VP of technology, consumer and business services for IDA Ireland. In this role he assists companies with their evaluation of Ireland as a location for International operations across a range of sectors including; media & communications; e-commerce; internet; consumer products; B2C, B2B, professional business services and industrial products & services.






