I thank Senators Ruane and Higgins for these amendments, as well as Senator Stephenson. I will take amendments Nos. 43, 44 and 45 together.
While the amendments are framed differently, they seek to achieve the same objective, namely, to require the AI register maintained by the office to be publicly accessible. Transparency is an important objective and one that is strongly reflected throughout the AI Act and this Bill. However, in considering these amendments, it is important to view the national arrangements in the context of the broader transparency framework already established at European level. In particular, Article 71 of the AI Act requires the establishment of a European database of certain high-risk AI systems. That database is intended to provide a significant level of public transparency, and will contain information that is publicly accessible, reachable and user-friendly.
Public authorities deploying certain categories of high-risk AI systems are also required under the AI Act to register those systems in the EU database, ensuring a substantial degree of transparency regarding the use of such systems. The AI register established under section 43 serves a different purpose. It is intended primarily as a regulatory and supervisory tool to assist the office in carrying out its oversight functions. It may contain information relating to prohibited AI practices, serious incidents, ongoing investigations, enforcement activities and other notifications received under the AI Act.
For that reason, information held on the register may include material that is commercially sensitive, security related, subject to confidentiality obligations, related to ongoing supervisory or enforcement activity, or may involve data protection considerations. While I support the objective of transparency, I do not consider it appropriate at this stage to place a statutory obligation on the office to make the entire register publicly accessible. Such a requirement could create difficulties for information required for careful assessment before publication, where disclosure could prejudice investigations, undermine supervisory activity, compromise security interests or affect legitimate commercial interests.
As the office becomes established and experienced in gaining and operating the regime, it may be appropriate to consider whether certain information contained in the register could be published in a manner that promotes transparency, while also protecting confidentiality, information, security considerations, commercial interests and personal data. I also do not consider it necessary to prescribe in primary legislation the specific means by which information would be published. The office should retain flexibility regarding how information is made available to the public, as technologies and publication practices evolve. Accordingly, I am satisfied the Bill strikes the appropriate balance between transparency, accountability and effective regulation.
I do not propose to accept either amendment.
It is important to distinguish between transparency and publication. The Government supports transparency. However, a regulatory register may contain information relating to, as I said, investigations, commercially sensitive information and so on. The Bill seeks to strike a balance between public transparency and effective regulatory oversight.
On section 44, I thank the Senator for the amendment. Having transparency and accountability around deployment of high-risk AI systems by public bodies is a legitimate and shared objective. The Bill already pursues that directly. The AI Act establishes obligations in relation to fundamental rights impact assessments for specific categories of high-risk AI systems. Those obligations are directed towards ensuring that the deployer assesses and mitigates risks before deployment and that competent authorities can exercise appropriate oversight, where required. I refer to the requirement in Article 27 for a fundamental rights impact assessment for every high-risk AI system deployed by a public body prior to its first use. This obligation applies primarily to public bodies and private organisations providing public services and users of certain high-risk AI systems, identified in annexe III of the Act. The purpose of the assessment is to identify and evaluate any potential negative effects that the AI system could have on individuals' fundamental rights and freedoms before it is deployed.
The assessment must describe how the organisation intends to use the AI system and the processes in which it can be involved. It must also explain how often the system will be used and over what period. The organisation must identify the individuals or groups who may be affected by the system and consider any risks of harm that could arise from it. These risks should be assessed in light of information provided by the AI system's provider, including any known limitations, risks or conditions of use.
In addition, the organisation must explain what human oversight measures will be put in place to supervise AI systems and ensure that the human decision-makers can intervene, where necessary. It must also document the actions that will be taken if risks materialise, including governance arrangements, procedures for managing incidents and the mechanisms through which affected individuals can make complaints and seek redress.
Where an organisation has already completed a data protection impact assessment under GDPR or the data protection directive for law enforcement functions, the fundamental rights impact assessment does not replace that work. Instead, it should build upon and complement the existing data protection impact assessment, DPIA, ensuring that the broader fundamental rights considerations are also addressed. In practical terms, the provision of Article 27 of the AI Act requires organisations to think systematically about how high-risk AI systems may affect people, identify and mitigate potential risks, establish appropriate oversight and complaints mechanisms, document their findings and demonstrate compliance before the system is put into operation.
Last year, the Department of Public Expenditure, Infrastructure, Public Service Reform and Digitalisation published its guidelines for the responsible use of AI in the public service to provide practical information and resources for all public servants and Government officials on how to design, develop, deploy and maintain AI solutions responsibly. Additionally, under Article 71 of the AI Act, the European Commission, in collaboration with member states, is required to set up and maintain an accessible and public available EU database containing information concerning high-risk AI systems and the market surveillance authorities, MSAs, are obliged to report on serious incidents to the EU AI office and our own AI office.
As I mentioned, the AI Act and this Bill already contain a broader framework for the fundamental rights oversight through the designation of relevant fundamental rights bodies, the powers of market surveillance authorities, complaints mechanisms, incident reporting obligations and enforcement powers. In particular, section 43 establishes the AI register, maintained by the AI office, and subsection (2) sets out an exhaustive list of what it must contain. These are: prohibited practices under Article 5; serious incidents reported under Article 73; high-risk AI systems referred to in annexe III in accordance with Article 49(5); and any other AI-related incidents or notifications required to be reported under the regulation.
While I support the objective of ensuring that the office is visibly overseeing fundamental rights impact assessments carried out by public bodies deploying high-risk systems, I am satisfied that this objective is already met in the Bill. Section 60(2)(c), read with Article 27(3), already ensures that every such notification made by a public body deployer is sent to the office, through the relevant market surveillance authorities, and the existing paragraph (d) of section 43(2) already captures that material within the register. On this occasion, I oppose the amendment.