Skip to menu Skip to content

Korean e-government homepage mark This site is the official e-Government website of the Republic of Korea.

zoom
100%

Notice / Press Release

Notice Detail
Title PIPC Unveils AI Privacy Risk Management Model to Usher in an Era of Trustworthy AI
Department Date 2024.12.24
Attachment press release PIPC Unveils AI Privacy Risk Management Model to Usher In an Era of Trustworthy AI.pdf
Page URL https://pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=2745
Contents

Press Release

PIPC Unveils AI Privacy Risk Management Model to Usher in an Era of Trustworthy AI

- PIPC unveils an “AI Privacy Risk Management Model for the Safe Use of AI and Data.” 

- The Risk Management Model aims to be voluntary, providing principles and risk reduction measures to support AI businesses to manage privacy risks precipitated by AI
 

December 19, 2024

(This is an unofficial translation of a press release, originally prepared in Korean.)

 

A government-led voluntary model to systematically manage privacy risks arising from the development and deployment of AI models and systems has been published.

 

The Personal Information Protection Commission (PIPC) unveils an “AI Privacy Risk Management Model for the Safe Use of AI and Data” (hereinafter, “Risk Management Model”) to support AI-powered business operators to voluntarily manage privacy risks. The Risk Management Model systematically suggests the directions, principles, risk types, and mitigation measures for managing privacy risks precipitated by AI.

 

Data processing mechanisms in the era of AI amplify existing privacy risks associated with data breaches and generate unprecedented risks, such as human rights abuse caused by deepfakes. Proper control of these risks is a prerequisite for safeguarding data subjects and using sustainable and trustworthy AI. In this regard, AI actors should take proportional and reasonable mitigation measures based on a systematic understanding of associated risks.

 

Government institutions, academia, and the research society at home and abroad have been researching overall AI risks and establishing risk management frameworks. Still, these endeavors are in the early stages. In particular, reference or guidance materials addressing privacy risks associated with AI have not been sufficient for AI actors to refer to. 

 

Against this backdrop, the PIPC has established the Risk Assessment Model based on comprehensive reviews of AI’s data processing mechanisms, privacy risk types, and AI risk management frameworks with a special focus on discussions that have been made by the Risk Assessment Division (Subcommittee 2) of the Public-Private Policy Advisory Council for AI Privacy since December 2023. The Advisory Council for AI Privacy comprises 30 AI experts with three subcommittees dealing with data processing criteria, risk assessment, and securing transparency

 

The main content of the Risk Management Model is as follows:

 

1. Procedures for AI Privacy Risk Management

 

First up, the model suggests risk management procedures for AI privacy risks. AI systems and models are used for various contexts and purposes. Data requirements and processing mechanisms vary accordingly. In this sense, identifying specific types and use cases of AI is a starting point to frame and manage risks. Then, type-and use-specific risks associated with AI can be identified, and quantitative and qualitative risks, such as risk probabilities, severity, priorities, and acceptability of potential risks, can be measured. Lastly, AI actors can develop risk-based safeguards based on the previous procedures. 

 

It is advisable for AI actors to start carrying out risk management processes from the planning and development phase of an AI model or system by incorporating Privacy by Design (PbD) principles for early detection and mitigation of risks associated with AI. Then, AI actors are encouraged to repeatedly carry out periodic risk management processes to align with shifting environments, including system upgrades.

 

2. Types of AI Privacy Risks

 

The Risk Management Model showcases types of potential risks in the context of privacy as a reference. The Model articulates newly emerging privacy infringement and noncompliance with the Personal Information Protection Act (PIPA) caused by the inherent nature, functions, and data requirements of AI technology identified as a result of academic surveys and interviews with businesses.

 

The guidance material divides the risks throughout the AI lifecycle into planning, development, and deployment phases. Privacy risks that arise from the deployment phase are grouped by generative AI and discriminative AI to be more concrete in terms of use cases and models of AI. 

 

3. Mitigation Measures for AI Privacy Risks

 

The Risk Management Model also suggests administrative and technological safeguards to reduce risks associated with AI. However, AI actors can utilize the suggestions introduced in the model according to their needs and interests. They can develop and implement optimal sets of safeguards tailored to each context based on the risks identified and measured. 

 

Administrative safeguards include: 

● sources and history management of training datasets; 

● establishing a use policy applicable; 

● carrying out tests for privacy infringements by the AI Privacy Red Team and taking measures accordingly; 

● coming up with plans for data subjects to report inappropriate answers generated by an AI model; and 

● carrying out privacy impact assessment when training datasets are highly likely to contain sensitive data or a vast amount of personal information.  

 

Technical safeguards include: 

● pre-processing of datasets to be trained on an AI model (unnecessary data reduction, pseudonymization, anonymization techniques, and de-duplication); 

● adding safeguards through fine-tuning of an AI model; 

● applying prompt and output filtering; and 

● implementing differential privacy. 

 

Meanwhile, the PIPC exerted efforts to formulate policies based on scientific demonstrations by conducting policy research on how to analyze the effects of privacy risk reduction techniques for Large Language Models (LLMs) in order to take the specificity of Korean LLMs into account given insufficient volumes of research on them.

 

4. Management Framework for AI Privacy Risks

 

Last but not least, the Model suggests a risk management framework. Privacy protection, AI governance, cybersecurity, safety and trust, and other digital governance factors are correlated in the AI landscape. In this sense, reshaping an existing privacy governance framework is much needed. To do so, a CPO's roles and a sense of responsibility have become more important than ever before. Moreover, forming a dedicated team to carry out professional assessments regarding associated risks from multiple angles and formulate policies that enable systematic risk management is ideal.

 

Moreover, AI-powered business operators and entities can clarify the scope of their authorities and accountabilities in the AI value chain and make a cooperation system feasible with other businesses and entities. By doing so, they can prepare themselves to respond to privacy risk dynamics and respect the rights of data subjects effectively. 

 

The data protection supervisory authority is set to update this model by continuously considering technological advancements in AI, future amendments or enactment of the PIPA, and global trends. Moreover, guidance materials specialized in detailed target audiences and sectors, such as small-scale organizations, start-ups, fine-tuning and Retrieval Augmented Generation (RAG), and other AI development types, will be materialized very soon.

 

For future endeavors, the PIPC has a plan to communicate with AI-powered businesses to monitor technological advancements through its pro-innovation support schemes, including the Prior Adequacy Review Scheme, Regulatory Sandbox Program, and Personal Information Safety Zone, and difficulties through active communication with AI-powered businesses. Building upon the accumulated cases and experiences, it will also overhaul the PIPA to align with the era of AI.

 

Professor Sangchul Park of the Seoul National University, who took the lead in discussions on the Risk Management Model, said, “Global divides and tensions are palpable between rapidly advancing AI technology and existing privacy regulations. We are at the critical juncture to respond to the AI landscape that is shifting at a breakneck pace.” He also added, “the Risk Management Model holds significance in that it suggests a flexible and systematic privacy risk management system with experts from various domains to align with the recent trends in global AI governance frameworks and the relevant research results.” 

 

Head of LG AI Research Kyunghoon Bae, who is also a co-chairperson of the Public-Private Advisory Council for AI, argued that “It is meaningful that this Government-led Risk Management Model gives Korea a leading edge in the AI privacy landscape where global discussions have been actively made.” The co-chairperson of the Council added, “I hope PIPC’s support for AI-powered businesses to bring innovation and safeguard privacy continues.”

 

Chairperson Haksoo Ko of the PIPC emphasized, "Due to uncertainties in the AI landscape where data is utilized from the cradle to the grave, taking proportional and risk-based management is required to holistically minimize risks rather than one-size-fits-all regulations.” He added that “I hope the Risk Management Model serves as a compass for AI businesses to have a better understanding of privacy risks caused by AI and systematically manage them accordingly."

 

* A PDF file, formatted for better readability, is attached.

Previous
PIPC Sanctions Twelve General Insurance Companies for Non-Compliance with PIPA
Next
PIPC Unveils Guidelines on Generating and Utilizing Synthetic Data