“Times change, but you are always on the committees” – or why it is the Office for Personal Data Protection (UODO) that should oversee data and artificial intelligence, rather than the digitalisation sector appointing its own regulator

On 15 October 2024, a draft bill prepared by the Polish Ministry of Digitalisation on the Commission for the Development and Security of Artificial Intelligence was published; misleadingly, it was titled the ‘Act on Artificial Intelligence Systems’. The vagueness of the legislator’s objectives is evident not only in the title of the bill itself, but also in the name of the body whose establishment the Ministry is promoting. The name suggests that the Commission is to deal with both the development of artificial intelligence and the security of artificial intelligence (systems).

The creation of a new body is always a major event, providing a basis for celebrating it for many years to come with various ceremonies and other rituals, which in turn are an excellent alternative to substantive work. New work posts are created, into which political friends and civil servants can be placed. The creation of a new organisation also allows it, at least for a few years, to focus on itself, which serves as a good excuse for not having time to deal with the very tasks for which it was established. After all, it has to learn everything, such as the layout of the new offices and the names of its colleagues. Despite all these undoubted advantages, which I shall elaborate on later in this text, I take a critical view of the idea of creating a new, collegial office rather than expanding the remit of an existing one.

Artificial intelligence systems deal with data processing. And we already have a data authority. What is more, a significant proportion of the data processed by artificial intelligence systems is personal data. And as it happens, the data authority is called the Office for Personal Data Protection. But let us return to the beginning.

The need to regulate matters relating to artificial intelligence at national level stems from the fact that the European Union has adopted the Artificial Intelligence Act (abbreviated to ‘AIA’). To ensure the AIA functions effectively, new powers need to be assigned to authorities in the EU Member States. In accordance with Article 70(1) of the AIA, …each Member State shall establish or designate at least […] one market surveillance authority…. This provision adds that these competent national authorities shall exercise their powers independently…

The drafters of the bill have proposed the establishment of a twelve-member body with the charming name of the Commission for the Development and Safety of Artificial Intelligence. This body is to comprise one Chair of the Commission, two Deputy Chairs of the Commission and nine members of the Commission. Incidentally, the age-old question of whether the Commission Chair is a member of the Commission has been settled. Well, (this time) they are not.

The method of appointing the Commission’s members is itself interesting. The Chair and their two Deputy Chairs are appointed by the Prime Minister. The nine (remaining, in the broadest sense) members of the Commission are to be appointed individually by the Minister for Digital Affairs, the Minister for the Security Services, the President of the Office for Personal Data Protection, the President of the Office of Competition and Consumer Protection; the Financial Supervision Authority; the Ombudsman; the Ombudsman for Children’s Rights; the National Broadcasting Council; and the President of the Office of Electronic Communications. Thus, five members of the Commission are appointed directly by the government, whilst the others are of little significance, as they must retain their posts within their parent bodies, and the draft bill does not require them to have any expertise in the Commission’s intended remit. Independence from the government is therefore rather out of the question, although I do appreciate the attempt to hide the elephant behind the lamppost in the form of representatives of the Ombudsman and the Children’s Ombudsman.

Let us return, however, to the main issue – the Commission’s powers. The Commission is to be a supervisory body, and will therefore monitor, question, impose penalties and take other decisions regarding entities that use artificial intelligence systems or place such systems on the domestic market (this is where doubts arise as to whether the draft bill might inadvertently extend the Commission’s powers beyond the framework permitted by the AIA, as the AIA essentially regulates high-risk systems and general-purpose AI models and systems. This scope of powers overlaps in particular with those of the President of the Personal Data Protection Office, as any AI system processing personal data will, of course, be subject to supervision by the PUODO.

Given the very concept of artificial intelligence regulation set out in the AIA, one might venture to say that AI systems are subject to supervision by the PUODO or by a sectoral supervisory authority such as the Financial Supervision Authority or the Civil Aviation Authority, or to supervision by both the PUODO and such a sectoral supervisory authority simultaneously.

So, since we already have one or two supervisory authorities, it stands to reason that it is worth adding at least one more to ensure even better supervision. The tendency to add supervisory authorities is an established practice in the European Union for promoting innovation.

Oh, and by the way, I’ve just realised from whom this AI Commission will actually be independent. Well, it will be independent of… the other supervisory authorities, with particular emphasis on independence from the Office for Personal Data Protection.

But, but, let’s make one thing clear straight away: this independence of the Commission does not extend to the entities it supervises. For they will be subject to all the supervisory authorities at once.

Finally, can the Commission really be independent of the PUODO? It seems that, as a certain professor of mathematics once said, the vector is correct, but the direction is wrong. Let us emphasise strongly that Article 2.7 of the AIA unequivocally states that the Artificial Intelligence Act has no impact on the GDPR (apart, of course, from adding a few more requirements for the processing of various types of data and allowing the manipulation of AI algorithm results to promote various types of minorities (the latter in Article 10.5 of the AIA)). Therefore, under no circumstances does the Commission’s oversight exempt us from the oversight of the PUODO, and the PUODO must certainly be independent of the Commission, not the other way round.

Given all this, do we consider it a good idea to establish a new supervisory authority that can look behind the scenes of any institution wishing to use artificial intelligence systems?

Well, in my view, creating a new supervisory authority is a bad idea. The purpose of artificial intelligence is data processing. And as we mentioned at the outset, we already have a data processing protection authority.

The GDPR is based on the assessment and management of data processing risks, with a focus on quality management systems in the form of codes of conduct and certification options. The AIA requires the management of risks associated with data processing by AI precisely within the framework of quality management systems. The Office for Personal Data Protection (PUODO) deals with digitised data processing and is handling the first cases in Poland concerning artificial intelligence (incidentally, following our complaint on behalf of Dr Łukasz Olejnik). It would seem only logical to extend the Authority’s remit to cover artificial intelligence systems and to increase its budget. There would be no need to create new structures from scratch, or to recruit and train further swathes of civil servants. The economies of scale resulting simply from avoiding duplication of processes would be obvious. But let us set taxpayers’ money aside for a moment and consider the practicality of both options.

The PUODO + Commission option is undoubtedly beneficial for us, as lawyers. This is because we would not only see a doubling of the number of proceedings, but also be faced with the need to draft correspondence to synchronise the proceedings with one another, as well as – and perhaps above all – having to refer to one set of proceedings in another or challenge the outcomes of those proceedings against one another. Large global players are also likely to benefit from this dual scenario. Indeed, it would suffice for the decisions of the two authorities to contradict one another for it to be claimed that the Poles themselves do not know what they want from artificial intelligence. Medium-sized and small domestic entities will, of course, find themselves caught in the middle, as parallel proceedings may be conducted against them. Of course, purely hypothetically, the rulings of both authorities might be the same, or at least similar in terms of penalties and injunctions. But what sort of mutual independence would that be, and what use would a second authority be if it merely parroted the first? It is obvious that the justification for the existence of a second authority lies in its reaching better – or at least different – findings and decisions than the first authority. After all, how else can one demonstrate one’s independence other than by differing in a striking way?

However sarcastic my tone may be, the problem of conflicting rulings and divergent appeal routes is plain to see. Contradictory interpretations by different bodies and divergent appeal routes do not serve the market well. It should be added that, in practice, the draft bill introduces yet another supervisory body – the Chair of the Commission. The Chair has specific powers of their own, which they may exercise without waiting for the position of the Children’s Ombudsman’s representative on the Commission.

Under a scenario where the PUODO’s powers are expanded, a number of the challenges described above would disappear. Conflicts of position and jurisdictional disputes between the Office’s departments would have to be resolved amongst themselves before a decision is issued. The Office has been assessing data processing for six years now, including automated decisions and the impact of processing on the rights and freedoms of natural persons. It adjudicates on matters relating to artificial intelligence. It also carries out research and awareness-raising activities, including those concerning artificial intelligence. More supervisory authorities mean more problems for the market. Fewer supervisory authorities mean fewer problems. Another particular drawback of establishing the Commission will be the blurring of responsibility and accountability for the actions of the supervisory authorities. Whatever one may say about the Office for Personal Data Protection, the President of the Office is always a single individual. That individual bears the brunt of criticism, as well as reputational and political responsibility, and has control over the chain of command (decision-making). The concept of a specific collegial body, with direct access for the authorities, as promoted in the draft bill, tends to blur personal responsibility and makes it more difficult to hold such a body to account for its decisions.

A typical wakeboarding injury is a knee injury. A friend of mine, a multiple Polish wakeboarding champion, once told me that he refers everyone who injures their knee to one specific surgeon. So that the surgeon can learn. And he himself went under the knife with that same surgeon after his latest injury.

In Poland, the Personal Data Protection Office acts as the ‘data surgeon’. The Provincial Administrative Court in Warsaw and the Supreme Administrative Court, meanwhile, act as the ‘data courts’. That is why it makes no sense to multiply supervisory bodies and introduce new authorities that would compete with the PUODO, such as an artificial intelligence commission and a body within that commission in the form of the Commission Chair, whose status (questionable independence) and scope of powers appear not to meet the requirements of the EU Act on Artificial Intelligence. Nor does it make sense to split the appeal process and create competition between the administrative courts and the competition court.

There is no need to appoint a second surgeon to carry out the same operations simultaneously. And given that, as we mentioned at the outset, twelve people will be holding the scalpel of this second surgeon at the same time – including nine who will be voting on the incisions in their spare time, away from other paid work – all that remains is to wish the patients, that is, the supervised entities, the best of health.

Maciej Gawroński

The author is a Polish Attorney-at-law and managing partner at GP Partners; a recipient of the M. Serzycki Award; a former expert to the European Commission on cloud computing contracts; a former expert to the Article 29 Working Party on data transfers; a supporting expert to the European Data Protection Board; a recommended arbitrator of the Court of Arbitration at the Polish Chamber of Commerce, and the author of Wolters Kluwer Polska’s most popular legal books in 2017 and 2018 *GDPR: A Guide with Templates* (2017) and *A Handbook on Drafting Letters* (2022). He is the author of numerous presentations and publications on artificial intelligence. He is leading Poland’s first legal action against OpenAI in connection with ChatGPT.