cd /news/ai-policy/towards-privacy-preserving-ai-explan… · home topics ai-policy article
[ARTICLE · art-77752] src=law.kuleuven.be ↗ pub= topic=ai-policy verified=true sentiment=· neutral

Towards Privacy-Preserving AI Explanations: Reconciling the Obligations to Provide AI Explanations with the Data Protection Obligations under European Union Regulatory Frameworks

A doctoral project at CiTiP investigates a tension between EU regulations requiring explainable AI (XAI) under the GDPR and AI Act and the data protection obligations those same laws impose, finding that XAI methods can enable privacy attacks such as membership inference, model inversion, and attribute inference. The research, focused on AI-enabled clinical decision support systems, concludes that the current legal framework does not provide a clear, adequate, or comprehensive approach to addressing these privacy risks and offers regulatory recommendations to reconcile the obligations.

read1 min views11 publishedJul 27, 2026
Towards Privacy-Preserving AI Explanations: Reconciling the Obligations to Provide AI Explanations with the Data Protection Obligations under European Union Regulatory Frameworks
Image: Law (auto-discovered)

PROJECT TITLE : Towards Privacy-Preserving AI Explanations: Reconciling the Obligations to Provide AI Explanations with the Data Protection Obligations under European Union Regulatory Frameworks

*Keywords: *** Data protection, black-box algorithms, Explainable AI, privacy risks, right to explanation

The GDPR and the AI Act require the provision of meaningful explanations for automated decisions while also requiring personal data protection. This doctoral project investigates a tension between these two requirements: the methods for explainable AI (XAI) used to comply with the explanation obligations under Articles 13-15 and 22 of the GDPR and Article 86 of the AI Act may themselves enable privacy attacks (including membership inference, model inversion, and attribute inference) that constitute a data protection violation (e.g., under Article 32 GDPR on data security, as well as a violation of Article 15 AI Act, regarding robustness and cybersecurity). Through a legal analysis based on technical scholarship, this research assesses whether the GDPR and the AI Act provide a clear, adequate, and comprehensive framework to address privacy risks in XAI. It examines this tension in the context of AI-enabled clinical decision support systems (CDSS), in light of the interplay between the MDR, the AI Act, and the GDPR, and formulates concrete regulatory recommendations (interpretative, legislative, and standardizing) to reconcile the EU legal provisions requiring AI explanations with that aiming at data protection.

For more information on the project, you can consult: Time span: | 2026-06-16 - Ongoing | Assigned by: | CiTiP | Promoter: | |

**Co-promoter:****Staff:**Contact:

── more in #ai-policy 4 stories · sorted by recency
── more on @citip 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/towards-privacy-pres…] indexed:0 read:1min 2026-07-27 ·