Skip to main content

Showing 1–13 of 13 results for author: Pandit, H J

.
  1. arXiv:2503.05787  [pdf, other

    cs.CY

    Mapping the Regulatory Learning Space for the EU AI Act

    Authors: Dave Lewis, Marta Lasek-Markey, Delaram Golpayegani, Harshvardhan J. Pandit

    Abstract: The EU AI Act represents the world's first transnational AI regulation with concrete enforcement measures. It builds on existing EU mechanisms for regulating health and safety of products but extends them to protect fundamental rights and to address AI as a horizontal technology across multiple application sectors. We argue that this will lead to multiple uncertainties in the enforcement of the AI… ▽ More

    Submitted 28 May, 2025; v1 submitted 27 February, 2025; originally announced March 2025.

  2. arXiv:2503.05758  [pdf

    cs.CY cs.AI

    ADAPT Centre Contribution on Implementation of the EU AI Act and Fundamental Right Protection

    Authors: Dave Lewis, Marta Lasek-Markey, Harshvardhan J. Pandit, Delaram Golpayegani, Darren McCabe, Louise McCormack, Joshua Hovsha, Deirdre Ahern, Arthit Suriyawongku

    Abstract: This document represents the ADAPT Centre's submission to the Irish Department of Enterprise, Trade and Employment (DETE) regarding the public consultation on implementation of the EU AI Act.

    Submitted 22 February, 2025; originally announced March 2025.

  3. arXiv:2501.14756  [pdf, other

    cs.CY cs.AI

    Towards An Automated AI Act FRIA Tool That Can Reuse GDPR's DPIA

    Authors: Tytti Rintamaki, Harshvardhan J. Pandit

    Abstract: The AI Act introduces the obligation to conduct a Fundamental Rights Impact Assessment (FRIA), with the possibility to reuse a Data Protection Impact Assessment (DPIA), and requires the EU Commission to create of an automated tool to support the FRIA process. In this article, we provide our novel exploration of the DPIA and FRIA as information processes to enable the creation of automated tools. W… ▽ More

    Submitted 23 December, 2024; originally announced January 2025.

    Comments: Presented at CLAIRvoyant (ConventicLE on Artificial Intelligence Regulation) Workshop 2024

  4. arXiv:2501.10391  [pdf, other

    cs.CY cs.AI

    Developing an Ontology for AI Act Fundamental Rights Impact Assessments

    Authors: Tytti Rintamaki, Harshvardhan J. Pandit

    Abstract: The recently published EU Artificial Intelligence Act (AI Act) is a landmark regulation that regulates the use of AI technologies. One of its novel requirements is the obligation to conduct a Fundamental Rights Impact Assessment (FRIA), where organisations in the role of deployers must assess the risks of their AI system regarding health, safety, and fundamental rights. Another novelty in the AI A… ▽ More

    Submitted 19 December, 2024; originally announced January 2025.

    Comments: Presented at CLAIRvoyant (ConventicLE on Artificial Intelligence Regulation) Workshop 2024

  5. arXiv:2501.05617  [pdf, other

    cs.CY cs.DL

    Datasheets for Healthcare AI: A Framework for Transparency and Bias Mitigation

    Authors: Marjia Siddik, Harshvardhan J. Pandit

    Abstract: The use of AI in healthcare has the potential to improve patient care, optimize clinical workflows, and enhance decision-making. However, bias, data incompleteness, and inaccuracies in training datasets can lead to unfair outcomes and amplify existing disparities. This research investigates the current state of dataset documentation practices, focusing on their ability to address these challenges… ▽ More

    Submitted 9 January, 2025; originally announced January 2025.

    Comments: Irish Conference on Artificial Intelligence and Cognitive Science (AICS), December 2024, Ireland

  6. arXiv:2501.04014  [pdf, other

    cs.DL cs.AI cs.CY

    AICat: An AI Cataloguing Approach to Support the EU AI Act

    Authors: Delaram Golpayegani, Harshvardhan J. Pandit, Dave Lewis

    Abstract: The European Union's Artificial Intelligence Act (AI Act) requires providers and deployers of high-risk AI applications to register their systems into the EU database, wherein the information should be represented and maintained in an easily-navigable and machine-readable manner. Given the uptake of open data and Semantic Web-based approaches for other EU repositories, in particular the use of the… ▽ More

    Submitted 19 December, 2024; originally announced January 2025.

    Comments: Presented at 37th International Conference on Legal Knowledge and Information Systems (JURIX) 2024

  7. arXiv:2412.15451  [pdf, ps, other

    cs.CR cs.CY

    How to Manage My Data? With Machine--Interpretable GDPR Rights!

    Authors: Beatriz Esteves, Harshvardhan J. Pandit, Georg P. Krog, Paul Ryan

    Abstract: The EU GDPR is a landmark regulation that introduced several rights for individuals to obtain information and control how their personal data is being processed, as well as receive a copy of it. However, there are gaps in the effective use of rights due to each organisation developing custom methods for rights declaration and management. Simultaneously, there is a technological gap as there is no… ▽ More

    Submitted 19 December, 2024; originally announced December 2024.

    Comments: Presented at 37th International Conference on Legal Knowledge and Information Systems (JURIX) 2024

  8. arXiv:2406.18211  [pdf, other

    cs.CY cs.AI

    AI Cards: Towards an Applied Framework for Machine-Readable AI and Risk Documentation Inspired by the EU AI Act

    Authors: Delaram Golpayegani, Isabelle Hupont, Cecilia Panigutti, Harshvardhan J. Pandit, Sven Schade, Declan O'Sullivan, Dave Lewis

    Abstract: With the upcoming enforcement of the EU AI Act, documentation of high-risk AI systems and their risk management information will become a legal requirement playing a pivotal role in demonstration of compliance. Despite its importance, there is a lack of standards and guidelines to assist with drawing up AI and risk documentation aligned with the AI Act. This paper aims to address this gap by provi… ▽ More

    Submitted 26 June, 2024; originally announced June 2024.

  9. arXiv:2405.04528  [pdf, other

    cs.CR

    Implementing ISO/IEC TS 27560:2023 Consent Records and Receipts for GDPR and DGA

    Authors: Harshvardhan J. Pandit, Jan Lindquist, Georg P. Krog

    Abstract: The ISO/IEC TS 27560:2023 Privacy technologies - Consent record information structure provides guidance for the creation and maintenance of records regarding consent as machine-readable information. It also provides guidance on the use of this information to exchange such records between entities in the form of 'receipts'. In this article, we compare requirements regarding consent between ISO/IEC… ▽ More

    Submitted 1 May, 2024; originally announced May 2024.

  10. arXiv:2404.13426  [pdf, other

    cs.CY

    Data Privacy Vocabulary (DPV) -- Version 2

    Authors: Harshvardhan J. Pandit, Beatriz Esteves, Georg P. Krog, Paul Ryan, Delaram Golpayegani, Julian Flake

    Abstract: The Data Privacy Vocabulary (DPV), developed by the W3C Data Privacy Vocabularies and Controls Community Group (DPVCG), enables the creation of machine-readable, interoperable, and standards-based representations for describing the processing of personal data. The group has also published extensions to the DPV to describe specific applications to support legislative requirements such as the EU's G… ▽ More

    Submitted 27 August, 2024; v1 submitted 20 April, 2024; originally announced April 2024.

    Comments: Accepted for Presentation in The 23rd International Semantic Web Conference (ISWC 2024)

  11. arXiv:2208.05786  [pdf, ps, other

    cs.CY

    Proposals for Resolving Consenting Issues with Signals and User-side Dialogues

    Authors: Harshvardhan J. Pandit

    Abstract: Consent dialogues are a source of annoyance, malicious intent, dark patterns, illegal practices and a plethora of other issues. This work presents known problems based on GDPR requirements grouped into two categories: (i) UI/UX for consenting; and (ii) power imbalance in expressing consent. To resolve this, it presents two proposals: First, the use of automation through privacy signals to better g… ▽ More

    Submitted 9 August, 2022; originally announced August 2022.

  12. A Common Semantic Model of the GDPR Register of Processing Activities

    Authors: Paul Ryan, Harshvardhan J. Pandit, Rob Brennan

    Abstract: The creation and maintenance of a Register of Processing Activities (ROPA) is an essential process for the demonstration of GDPR compliance. We analyse ROPA templates from six EU Data Protection Regulators and show that template scope and granularity vary widely between jurisdictions. We then propose a flexible, consolidated data model for consistent processing of ROPAs (CSM-ROPA). We analyse the… ▽ More

    Submitted 1 February, 2021; originally announced February 2021.

  13. arXiv:2008.00877  [pdf

    cs.CY cs.CR

    Towards a Semantic Model of the GDPR Register of Processing Activities

    Authors: Paul Ryan, Harshvardhan J. Pandit, Rob Brennan

    Abstract: A core requirement for GDPR compliance is the maintenance of a register of processing activities (ROPA). Our analysis of six ROPA templates from EU data protection regulators shows the scope and granularity of a ROPA is subject to widely varying guidance in different jurisdictions. We present a consolidated data model based on common concepts and relationships across analysed templates. We then an… ▽ More

    Submitted 3 August, 2020; originally announced August 2020.