[PRESS RELEASE] ARTIFICIAL INTELLIGENCE GAINING POPULARITY, CfDS UGM COLLABORATES WITH KORIKA AND GOOGLE TO MONITOR THREATS TO PERSONAL DATA SECURITY | DET #21

CfDS UGM Official YouTube Channel (5/12/2023) – The increasing utilization of artificial intelligence (AI) poses potential disruptions to the security of personal information, given AI’s ability to analyze personal data quickly and accurately. However, awareness of these threats is generally uneven among users of AI-based technology.

On Tuesday (5/12), Center for Digital Society (CfDS) UGM, in collaboration with the Indonesian Artificial Intelligence Research & Innovation Collaboration (KORIKA) and Google, addressed this issue through Digital Experts Talk #21 titled “Navigating Artificial Intelligence Innovation and the Urgency of Personal Data Protection.” Featuring Rindy (Sub Coordinator for Cooperation and Institutional Control of Personal Data, Ministry of Communication and Informatics), Alfatika Aunuriella Dini, Ph.D (Faculty of Law, Universitas Gadjah Mada), and Ardhanti Nurwidya (Board Member of the Association of Data Protection Practitioners (APPDI)), this online discussion examined the connection between personal data and the use of AI.

As a discussion starter, Rindy presented various perspectives on the still multifaceted concept of AI. Various parties, including the government and academics, have yet to agree on a single definition of AI. Nevertheless, the Ministry of Communication and Informatics has mapped the scope of AI definitions and established a legal foundation for personal data protection through the Personal Data Protection Law (UU PDP). Rindy emphasized 

that any failure in personal data protection due to AI would be the responsibility of the controller. “All data processing by AI that involves the interests of personal data subjects, whether automated AI or AI-assisted decisions, must comply with the UU PDP and all obligations for the protection of personal data contained therein,” stressed Rindy.

In alignment with the commitment of the Ministry of Communication and Informatics, Alfatika highlighted the academic urgency behind regulating personal data protection in AI usage. Legal issues surrounding AI, particularly regarding the legal status of AI, came under scrutiny. Debates include whether AI can be considered a legal entity and the accountability for AI actions. The main concern is determining whether AI actions should be attributed to AI or its creator, introducing legal complexity in accommodating AI technology and assigning responsibility. “Can personal data protection and AI technological innovation coexist? Certainly, as evidenced by the Personal Data Protection Law in Indonesia, even though there is no specific legal basis explicitly regulating AI,” said Alfatika.

Summarizing the discussion from the previous speakers, Ardhanti, representing APPDI, demonstrated their commitment. As an association comprising data protection officers (DPOs), APPDI is committed to overseeing the urgency of personal data protection issues in the context of AI usage. According to Ardhanti, ‘smart’ AI will require exposure to comprehensive data, including personal data, to sharpen the resulting analysis. “In the AI model development process, there is a risk of privacy violations, especially during the training phase and AI exposure to a large amount of data,” she said. She explained that concerns arise about whether AI models are trained with personal data that complies with regulations, whether potential data leaks have been anticipated, and the accuracy and bias of the data supplied to the AI model.

Amidst the debate on the relationship between personal data protection and AI technology, the three speakers agreed that regulations should not restrict innovation, as innovation could bring substantial benefits to Indonesia. Regulations need to support innovation while being able to address risks and negative impacts. With regulatory initiatives such as the Circular Letter for AI (SE AI), UU PDP, and the Electronic Information and Transactions Law (UU ITE), the government is expected to act as a fair ‘referee’ in protecting the public from threats to personal data security.