Privacy Commissioner Michael Webster today outlined expectations for New Zealand government agencies, businesses and organizations that use generative artificial intelligence (AI).
“We expect all government agencies using systems that are able to capture the personal information of New Zealanders to create new content will consider the implications of using generative AI before launching,” he said. say.
AI’s use of personal information of New Zealanders is regulated under the Privacy Act 2020.
It is the Secretary’s role to ensure that the privacy rights of New Zealand citizens are protected, so she has called on companies and institutions to review their obligations regarding the use of generative AI before they begin.
Webster outlined seven pieces of advice that can help companies and organizations approach the promise of AI in a way that respects people’s privacy rights.
1. Get senior leader approval
Companies and organizations should involve senior leaders and privacy officers when deciding whether or how to implement generative AI systems.
2.
Consider whether generative AI tools are necessary and appropriate
Considering potential privacy implications, consider whether it is necessary and appropriate to use generative AI tools, or whether another approach can be taken.
3.
Conduct a privacy impact assessment
Evaluate the privacy implications before deploying any system. This should also include seeking feedback from affected communities and groups including Maori. Ask your provider to clarify information and evidence about how privacy protections are built into their systems.
Four. be transparent
Be clear and candid when communicating to your customers and clients that you are using generative AI and how you are managing the privacy risks that come with it. Generative AI is a new technology, and many people may not feel comfortable using it or understand the risks. To maintain consumer confidence and the organization’s social license to use her AI, it is essential to provide information in plain language about the generative AI systems you are using.
Five.
Create procedures for accuracy and personal access
How your institution will take reasonable steps to ensure that information is accurate before it is used or disclosed, and how your institution will respond to requests from individuals to access and correct their personal information. Develop procedures on how to respond.
6. Ensure human review before acting
Human review of the output of generative AI tools before any action is taken by government agencies reduces the risk of acting on inaccurate information. When reviewing output data, you should also assess the risk of re-identification of input information.
7
Prevent private and sensitive information from being held or disclosed by generative AI tools
Do not enter any personal or sensitive information into the Generative AI Tool unless you have expressly confirmed that the information entered is not retained or disclosed by the provider. Alternatively, information that allows re-identification may be removed from the input data. We strongly warn against using sensitive or sensitive data for training purposes.
“We expect government agencies to do due diligence and privacy analysis to assess how they are complying with the law before committing to using generative AI,” says Webster.
“Generative AI is covered by the Privacy Act 2020 and my office is working to ensure that it is complied with and will investigate as necessary.
“The secretary has previously sent a letter outlining a warning to agencies against prematurely jumping into the use of generative AI without proper evaluation, and a government-wide response to the growing challenges posed by this tool. suggesting the need.
For more information on Generative Artificial Intelligence, please visit our website.
© Scoop Media
