PROJECT TITLE : Towards Privacy-Preserving AI Explanations: Reconciling the Obligations to Provide AI Explanations with the Data Protection Obligations under European Union Regulatory Frameworks
*Keywords: *** Data protection, black-box algorithms, Explainable AI, privacy risks, right to explanation
The GDPR and the AI Act require the provision of meaningful explanations for automated decisions while also requiring personal data protection. This doctoral project investigates a tension between these two requirements: the methods for explainable AI (XAI) used to comply with the explanation obligations under Articles 13-15 and 22 of the GDPR and Article 86 of the AI Act may themselves enable privacy attacks (including membership inference, model inversion, and attribute inference) that constitute a data protection violation (e.g., under Article 32 GDPR on data security, as well as a violation of Article 15 AI Act, regarding robustness and cybersecurity). Through a legal analysis based on technical scholarship, this research assesses whether the GDPR and the AI Act provide a clear, adequate, and comprehensive framework to address privacy risks in XAI. It examines this tension in the context of AI-enabled clinical decision support systems (CDSS), in light of the interplay between the MDR, the AI Act, and the GDPR, and formulates concrete regulatory recommendations (interpretative, legislative, and standardizing) to reconcile the EU legal provisions requiring AI explanations with that aiming at data protection.
For more information on the project, you can consult: Time span: | 2026-06-16 - Ongoing | Assigned by: | CiTiP | Promoter: | |
**Co-promoter:****Staff:**Contact: