The loss or corruption of data in a business is rarely “just” a technical problem. In practice it is a serious legal and financial crisis: production downtime, loss of trust among business partners and, in extreme cases, administrative fines running into millions. The scope of liability, however, depends above all on what kind of data has been lost or corrupted. The law treats the loss of source code or technical documentation quite differently from a leak of employee records or a customer database. The first step in assessing liability for a breach of the integrity or availability of data is therefore its unambiguous legal classification.
Implementing artificial intelligence in an organisation does not begin with choosing a tool, but with answering the question of who we are in the AI value chain and what we are responsible for. This article sets out the relationship between the GDPR and the AI Act: from the roles of provider, deployer and controller, through algorithmic risks, the limits of lawfulness in the workplace and the rights of individuals, to the DPIA, the FRIA and the AI Governance model. It reflects the legal position following the entry into force of the Polish Act on Artificial Intelligence Systems and the postponement of the AI Act application dates by Regulation (EU) 2026/1744.
Artificial intelligence (AI) is currently finding widespread use in healthcare. A prime example is the Polish National Health Fund (NFZ) initiative, which utilizes AI to analyze patient data stored in the Fund’s databases. This data is then analyzed with the support of machine learning tools to make strategic decisions regarding the health of Poles. This approach will certainly simplify the work of doctors by searching for and analyzing the desired information, undoubtedly reducing their workload. However, such a solution may raise several issues and legal requirements related to regulations regarding the protection and processing of personal data.
Siri, Cortana, Google and other applications use human voice to do a variety of things, e.g. searching for information, sending emails, calling somebody. Voice-based technologies are increasingly applied in legal environment and legal services, for example in legal advice rendered online and in legal translations. At the same time, new applications of innovative technologies caused the necessity to define the approach to privacy issues anew. The cases of Edward Snowden and Julian Assange showed us how meaningful privacy and its protection is and made us realize the excessive amount of personal data processed and stored daily. This is why privacy and its protection will soon become one of the most important personal rights. The issue of voice protection comes to the fore in this context. Voice is, obviously, a personal right. What is more, voice is becoming a tool used by most applications both for mundane activities as well as more complex ones, like ROSS AI operating on IBM’s Watson, which can do legal research and is learning to understand law with every research conducted by it. What if it was possible for such applications as Watson to use the voice of a specific lawyer and, with the use of voice sample, produce speech of a different content, for example in the form of legal advice? Well, practically it is possible, since last November Adobe presented Adobe VoCo to the world, which (when having a voice sample) is able to read various content differing from the conent sampled. The present article will try to shed some light to the issue of the risk involved with voice cloning technology in legal environment and will analyse whether law can adequately protect human voice as a personal right.