Can consent mechanisms stretch to AI agents?
Consent is a moment. Agents are continuous. PL&B’s Nel Anna Krzeslowska reflects on this dilemma.
Consent has long been the principal mechanism through which data protection law seeks to confer control on individuals over the processing of their personal data. Consent is defined under Article 4(11) of the General Data Protection Regulation (GDPR), and in very similar terms under the UK GDPR, as freely given, specific, informed, and unambiguous indication of the data subject’s wishes. The purpose of obtaining consent was to shift an element of control onto the users of the service. Whether it has succeeded in doing so has been contested for some time. The question that has now arisen is whether the consent mechanism can be sustained in an environment where systems like agentic AI act on behalf of an individual, and where data is held across multiple services.
Continue Reading
|
UK Report subscribers, please login to access the full article |
If you wish to subscribe, please see our subscription information. |