Legal Challenges in AI Deployment: Leveraging Security Standards for Compliance in the EU Context
2024 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE credits
Student thesis
Abstract [en]
Artificial Intelligence (AI) is becoming increasingly more advanced, and its development, implementation, and use are rapidly increasing, as well as its significance to industries and society. However, AI also raises legal, ethical, and security concerns, e.g., the impact on human rights, privacy, bias, and cybersecurity of AI systems because of its increased importance. European Union have new upcoming regulations, such as the AI Act, and old ones for example the GDPR, that is highly relevant to secure use of AI systems. Since AI systems inherit cybersecurity risks from conventional computing, specific security standards can be leveraged to comply with regulations concerning AI systems, such as ISO 27000 series. There is currently little research on the applicability of ISO 27000 series on legal aspects of AI. Therefore, study will explore how the security standard ISO 270001 can address regulatory requirements, and legal and security challenges on AI systems and work as a facilitator. The study will conduct qualitative research with survey as the research strategy. The required data to answered to research questions was collected through 10 semi-structured interviews with experts in cybersecurity, ISO 27000 or compliance. The data was analyzed using thematic analysis and resulted in 3 main themes, named Security challenges with AI, ISO 27000 and AI and Legal challenges, and 8 sub-themes. The result and discussion showed that the identified security challenges can be connected to legal requirements, and further be mitigated through comprehensive work with ISO 27001. However, the standard does not promote to include AI in the standardization work. ISO 27000 series can work both to identify and mitigate risks associated with AI, and further work as a compliance facilitator.
Place, publisher, year, edition, pages
2024.
Keywords [en]
Artificial Intelligence, compliance, ISO 27000, GDPR, AI Act
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:su:diva-242760OAI: oai:DiVA.org:su-242760DiVA, id: diva2:1955692
2025-04-302025-04-30