Regulating future AI systems - enabling future AI innovation through an increased level of legal certainty in technology neutral regulation
Research Council of Finland project 09/2022-08/2026, grant number: 347221
In the AI-REG project we study ambiguity that arises from the European Artificial Intelligence Act proposal (AI Act) that has been proposed by the European Commission in April 2021. The AI Act will regulate the development and use of AI systems in Europe. Political agreement between the European Council and the European Parliament has been reached in December 2023, the AI Act was voted on by the 27 EU member states on 2.2.2024 and received full support, and the wording of the AI Act will be finalized in spring 2024. After the expected adoption of the AI Act in late spring 2024, it will enter into force in different stages starting from end of 2024.
The underlying goal of the AI Act is to ensure that Europeans could trust AI systems. The AI Act distinguishes 4 risk classes of AI systems: unacceptable-, high-, limited-, and minimal risk. AI systems which would be judged to have unacceptable risk would be outright forbidden, and high-risk AI systems would have to conform to requirements both during development of the system and in the use of such a system. In addition, in the later stages of negotiations about the AI Act, also general purpose AI models were taken into the scope of the AI Act. The AI Act is thus expected to heavily affect the development and use especially of high-risk AI systems. However, the AI Act is also ambiguous/unclear on many parts, beginnig with the definition of what will be classified as an AI system, or how a specific system would be classified as high-risk vs. low-risk system. Ambiguity means that something can be interpreted in several different ways, and ambiguity in legal regulation - although being an integral part or feature of law - is potentially problematic as it reduces legal certainty.
The AI Act is a horizontal and broad regulation proposal. In the AI-REG project we have two focus areas: 1) High risk AI-system use in public sector organizations, and 2) Development of (high-risk) AI-based healthcare technology.
In the AI-REG project, we study
- What kind of ambiguities arise from the AI Act
- What challenges and critiques are seen in the context of the AI Act
- What legal formulations and requirements cause the ambiguity
- What characteristics of AI systems make an AI system subject to ambiguity
- How does regulation affect development of AI-based healthcare technology and AI-system use in public sector organizations
- How to organizatios prepare for the upcoming AI Act, and how do they deal with ambiguity arising from the Act?
In the AI-REG project, we have a qualitative research approach
- Identification of ambiguity/unclarity that different stakeholders identify in the AI Act
- Interviews in mostly in Finland, but also Sweden and Norway, with 1) public sector organizations that use AI systems, and 2) organizations that develop AI-based healthcare technology, 3) ministries, and 4) other stakeholders of interest.
- Study how focus organizations interpret the AI Act and deal with the uncertainty that arises from the AI Act regarding requirements of compliance
- Study whether it is possible to develop a taxonomy of AI systems in the light of the AI Act that would help determine whether an AI system is in or out of the AI Act's scope and which risk category it falls into.
The People
Karin Väyrynen, Ph.D. (Principal Investigator) | Arto Lanamäki, Ph.D | Fanny Vainionpää, Ph.D. |
.
Heidi Hietala, MSc. (Ph.D. defence: 30.10.2024) |
Erkki Tervo, MSc doctoral researcher |
Upcoming Seminars
- "How to Research Emerging Tech in Information Systems" by Prof. Juho Lindman (Gothenburg University, Sweden): 4.-5.12.2024, University of Oulu, Infotech seminar
- "A cross-disciplinary introduction to law, regulation, and governance of Artificial intelligence and other technologies" by Prof. Lyria Bennett Moses (University of New South Wales, Sydney, Australia): 14.-15.1.2024, University of Oulu, Infotech seminar.
Past Webinars and Seminars
- Regulatory Sandboxes Under the EU AI Act: What Are They, How Will They Serve Their Purpose, and Practical and Ethical Considerations in Health Care: 13 November 2024, 10:00-14:00 EET
- Webinar: Euroopan tekoälysäädös: havaintoja Suomen julkiselta- ja terveyssektorilta; 6. November, 8:30-10:00 EET. In the seminar, we will share some of our findings regarding the European AI Act and its impact on Finnish public- and healthcare sector organizatios (in Finnish). The slides (in Finnish) can be found here: AI-REG webinar slides
- Seminar: "How to publish in top-IS journals" by Prof. Mikko Siponen (The University of Alabama, USA): 16.-17.5.2024, University of Oulu, Infotech seminar
- Seminar: "AI Regulation for Non-Lawyers" by Prof. Mika Viljanen (University of Turku, Finland): 20.-21.11.2023, University of Oulu, Infotech seminar
- Seminar: "AI-Enabled Futures" by Prof. Dirk Hovorka (University of Sydney, Australia): 19.+20.6.2023, University of Oulu. Infotech seminar
News
19.11.2024: Today, we are presenting some of our research insights at the Arctic AI Day in Oulu, Finland, with 165 in-person registrations! We will talk about The European AI Act - and compliance concerns for organiztions under the open texture of law.
13.11.2024: Our panel on Regulatory Sandboxes under the AI Act: What are they, how will they serve their purose, and practical and ethical considerations in healthcare was a success. Our panelists shared their insights, and there was a very lively discussion ongoing also among the almost 50 participants. Thanks to our panelists as well as all participants.
6.11.2024: Today, we gave a webinar titled "The European AI Act: observations from the Finnish public sector and healthcare sector" (in Finnish), where we presented some of our Finidngs on how Finnish public sector organizations have been and are preparing for the AI Act since 2023, what kind of practices they employ, and what kind of strategies they take to face the dilemma between AI innovation and legal compliance. We also shared some early observations from the healthcare sector, and what kind of actors on the EU- and national level are expected to provide further guideance in how to interpret and comply with the AI Act. We are really happy that the seminar drew an interested audience from numerous organizations, sectors, and ministries. The discussion afterwards was really enlightening!
30.10.2024: What a great day! AI-REG researcher Heidi Hietala (M3S research group, supervisor Prof. Tero Päivärinta) successfully defended her Ph.D. thesis titled "Collective Ambidexterity in the Public Sector: Collaborating Towards Innovativeness and Efficienty in Digital Service Ecosystems". Congratulations from the whole AI-REG team! Also, our article "Not Inevitable: Navigating Labor Discplacement and Reinstatement in the Pursuit of AI for Social Good" was published in the Communications of the Association for Information Systems today. With this article, we participate in a very current and important debate on the effect of AI on job displacement in the future.
1.10.2024: Good news from the International Conference on Information Systems: Or paper titled " Dialectics of Reconception: Framing Compliant AI Innovation in the Public Sector" has been accepted for publication. The work was led by Heidi Hietala, and we look forward to continue collaboration with Raffaele Ciriello from Sydney Business School.
11.9.2024: Our paper titled ", led by Erkki Tervo titled "Increasing Understanding about the Role of Regulatory Intermediaries in Regulation - A Scoping Review and Implications for the European AI Act" got accepted Mediterreanean Conference on Information Systems.
4.9.2024: Arto presented a paper "Mechanisms without Critical Realism" at the Scandinavian Conference on Information Systems (SCIS 2024), held in Uddevalla, Sweden. The paper was written together with professor Mikko Siponen from The University of Alabama.
25.6.2024: Arto participated in the European Conference on Information Systems (ECIS 2024) in Pafos, Cyprus. He was one of the panelists in the "Regulation, Governance and Digital Responsibility: Research Frontiers" workshop. Together with Elena Parmiggiani of NTNU, Norway, they presented the paper "Practices of Anticipation: How Public Sector Organizations Anticipate Artificial Intelligence and Its Regulation" in the track "Futures: A Novel Site of Inquiry and Imagination." He also had another paper presentation "The European Union's Regulatory Challenge: Conceptualizing Purpose in Artificial Intelligence" in the track "Impact of Artificial Intelligence on Organizations and Society."
28.5.2024: We are excited to start our 3-day research visit with Prof. Jonny Holmström and the SCDI AI Business Lab (https://www.umu.se/en/department-of-informatics/scdi-ai-business-lab/) at Umeå University, Sweden! Looking forward to three exciting days of research collaboration!
17.5.2024: Professor Mikko Siponen (The University of Alabama, USA) held a two-day Infotech doctoral seminar "How to Publish in Top Information Systems Journals." The seminar was attended by doctoral researchers from the universities of Oulu, Jyväskylä, and Vaasa. Thank you, Mikko, for this highly insightful seminar!
19.04.2024: We shared some of our findings on the AI Act and how Finnish public Sector organizations approached the AI Act in a workshop organized for Norwegian public sector organizations by Skatteforsk (Centre for Tax Research) and the AI4Users projects.
18.04.2024: Karin and Arto had the pleasure to give a guest lecture in Lauri Tuovinen's course "AI Ethics, Privacy and Legislation" (https://opas.peppi.oulu.fi/en/course/521256S/16805?period=2023-2024), where we talked about the AI Act and what it means for organizations, discussed ambiguity stemming from the AI Act at this stage and what kind of mechanisms can be expected to arise around the AI Act that help organizations move forward amidst that ambiguity, and what the overlap between legal regulation and ethics is.
16.04.2024:We are happy to have two papers accepted at the European Conference on Information Systems (ECIS)! One paper addresses challenges related to the AI Act conceptualization of AI systems as having a specific intended purpose, which was challenged through the arrival of chatGPT and heavily influenced the policy process of the AI Act (Lanamäki et al., 2024).. The other paper addresses different practices that Finnish public sector organizations engaged in when anticiating the future AI Act, and we found that organizations operate both under regulatory shifts and uncertainty related to what the AI Act will look like in the end and uncertainty about how it then will be interpreted (over time), but also under uncertainty related to future technological development in the context of AI. They form expectations about the AI Act, map responsibilities, consider governance and stragizing, but also pro-actively seek to influence the future. (Vainionpää et al., 2024).
26.02.2024: Today, we gave a talk at the ICT Research Breakfast at the Faculty for Information Technology and Electrical Engineering, University of Oulu, on the AI Act. We had more than 50 participantes on-site and on-line, and some really inspiring discussion.
"Have you heard about the EU AI Act? It's a forthcoming EU regulation on artificial intelligence that all 27 member states approved this month. This regulation aims to prevent AI risks by supporting the development and deployment of trustworthy AI Made-In-Europe. Our presentation will briefly introduce the AI Act and discuss the main compliance concerns for organizations working with AI. We'll also cover the challenges of regulating rapidly evolving AI technologies, focusing on general-purpose AI systems that significantly influenced the AI Act process. Additionally, we'll discuss how legal compliance should be understood under the open texture of law. We are currently studying the AI Act and related ambiguity and uncertainty in our ongoing Academy-project (AI-REG, 2022-2026)."
21.10.2023: We were happy to welcome Prof. Mika Viljanen, Professor of private law at the University of Turku, who gave a 2-day Infotech-seminar called "AI regulation for non-lawyers". Thank you, Mika, for sharing your expertise with us and a very interdisciplinary group of participants! :)
10.10.2023: Karin participated in a 2-day visit to the European Parliament, arranged by MEP Miapetra Kumpula-Natri. 2 days full of expert talks by those who have been and are involved in negotiating the AI Act, new insights into the process and the latest status updates, and so so many interesting discussions with all the other expert participants. I am very grateful to have been invited to this! <3 Some pictures can be found here
03.10.2023: Good news from ICIS - our literature review on challenges and critique about the AI Act, with propositions for new research avenues for IS, has been accepted at the International Conference on Information Systems, which will be held in December in India.
14.10.2023: The reserach visit to Sydney has been fantastic!! Some impressions can be found here
01.10. 2023: Karin and Arto landed in Sydney to start their 2 week research visit with Prof. Lyria Bennet Moses (University of New South Wales, Department of Law and Justice). They are looking forward to exciting discussions with legal scholars, and will also visit the University of Sydney School of Business (Prof. Dirk Hovorka) and look forward to discussions with IS scholars as well.
05.-12.05.2023: Arto has visited Legal Tech Lab (hosted by Prof. Riikka Koulu and Prof. Suvi Sankari), and has had numerous discussions with legal scholars which was an eye-opening experience and has a big influence on the direction the project will go.
Publications
- Lanamäki, A., Väyrynen, K., Hietala, H., Parmiggiani, E., Vassilakopoulou, P. (2024). Not Inevitable: Navigating Labor Displacement and Reinstatement in the Pursuit of AI for Social Good. Communications of the Association for Information Systems. Vol. 55. https://aisel.aisnet.org/cais/vol55/iss1/30/
- Hietala, H., Ciriello, R., Vainionpää, F., Väyrynen, K., and Lanamäki, A. (2024). Dialectics of Reconception: Framing Compliant AI Innovation in the Public Sector. International Conference on Information Systems (ICIS), forthcoming
- Tervo, E., Väyrynen, K., and Iivari, N. (2024). Increasing Understanding about the Role of Regulatory Intermediaries in Regulation - A Scoping Review and Implications for the European AI Act. Proceedings of the Mediterreanean Conference on Information Systems (MCIS).
- Lanamäki, A., & Siponen, M. (2024). Mechanisms without Critical Realism. Proceedings of the Scandinavian Conference on Information Systems (SCIS 2024), Uddevalla, Sweden. https://urn.fi/URN:NBN:fi:oulu-202409035694
- Lanamäki, A., Väyrynen, K., and Vainionpää, F. (2024). The European Union's Regulatory Challenge: Conceptualizing Purpose in Artificial Intelligence. Proceedings of the European Conference on Information Systems (ECIS). https://oulurepo.oulu.fi/handle/10024/49234
- Vainionpää, F., Väyrynen, K., Lanamäki, A., and Parmiggiani, E. (2024). Practices of Anticipation: How Public Sector Organizations Anticipate Artificial Intelligence and Its Regulation. Proceedings of the European Conference on Information Systems (ECIS). https://oulurepo.oulu.fi/handle/10024/49294
- Vainionpää, F., Väyrynen, K., Lanamäki, A., and Bhandari, A. (2023). A Review of Challenges and Criticisms of the European Artificial Intelligence Act. Proceedings of the International Conference on Information Systems (ICIS). https://urn.fi/URN:NBN:fi:oulu-202402061598
- Väyrynen, K., Lanamäki, A., Laari-Salmela, S., Iivari, N., Kinnula, M. (2022) Policy Ambiguity: a Problem, a Tool, or an Inherent Part of Policymaking? Proceedings of the International Conference on Informaiton Systems (ICIS), Copenhagen, Denmark. AIS Electronic Library (AISeL) - ICIS 2022 Proceedings: Policy Ambiguity: a Problem, a Tool, or an Inherent Part of Policymaking? (aisnet.org)
- Konttila, J., Väyrynen, K. (2022). Challenges of current regulation of AI-based healthcare technology (AIHT) and potential consequences of the European AI Act proposal. Proceedings of the 13th Scandinavian Conference on Information Systems (SCIS), Denmark. jultika.oulu.fi/Record/nbnfi-fe2022092059659
Master's Theses
- Nova Sky (2024): Systematic Review of Regulatory Sanboxes: Implications for the European AI Act. https://oulurepo.oulu.fi/handle/10024/50797
- Collins Ikwueze (2024): Artificial Intelligence as a Service: A Systematic Review of Literature from the Customer’s Perspective. https://oulurepo.oulu.fi/handle/10024/49628
- Huotari, Anne (2023); Utilizing Artificial Intelligence in Perioperative Patient Flow: Systematic Literature Review. http://jultika.oulu.fi/Record/nbnfioulu-202306152496
- Bhandari, Aayush (2023): Legal Regulation in Empirical Research in the Information Systems Basket of 8 Journals: A Systematic Literature Review: http://jultika.oulu.fi/Record/nbnfioulu-202306292773