Inferential Capability Does Not Determine Legal Scope
Di cosa parla
Due regole europee usano l'idea di “inferenza” in modo diverso: la legge sull'intelligenza artificiale considera decisiva la capacità di inferire per definire cosa è regolato; il Regolamento sulla protezione dei dati (GDPR) valuta invece gli effetti di quelle inferenze sulle persone, a prescindere dalla classificazione tecnologica. Il contrasto diventa concreto con sistemi formati da più moduli che trasformano risultati in nuovi input; l'articolo propone una regola interpretativa e doveri di documentazione per stabilire quale decisione conta ai fini del GDPR e chi deve provarlo.
Cosa permette di osservare
Consente di esplorare chi rientra nelle tutele legali quando sistemi complessi combinano operazioni e come si dovrebbe assegnare l'onere della prova e gli obblighi di documentazione per decisioni che influenzano le persone.
Dalla fonte
Two instruments of EU digital law place inference at their centre and mean different things by it. Article 3(1) of the AI Act uses the capability to infer constitutively: it is the central feature separating the regulated category from conventional software. The GDPR never defines inference, yet governs it protectively: the consequences follow from the processing of personal data and from what the inference says about, or does to, a person, whether or not the technology that produced it qualifies as an AI system. The two perimeters are not concentric. Their non-coincidence remained invisible in single-shot systems; agentic architectures make it operationally acute. The thesis: inferential capability does not determine legal scope, and its absence does not create immunity. The framework is two-level. Inference performs two legal functions, constitutive and protective; the protective func…