🤖 AI Summary
Current AI regulation predominantly emphasizes the legality of data collection while overlooking how even legally sourced data can yield unreliable inferences due to threats such as construct invalidity, confounding bias, sampling bias, distributional shift, and fairness trade-offs. This work proposes a novel regulatory framework centered on inferential validity, translating insights from measurement theory and critical data studies into actionable mechanisms for the first time. It positions validity assessment as a prerequisite for both the authorization of high-risk AI systems and proportionality reviews. Integrating the right to informational self-determination—as affirmed in India’s Puttaswamy judgment—causal inference principles, and AI governance design, the framework transcends conventional regulatory paradigms, offering a theoretical foundation and practical pathway for enhancing AI transparency, enabling post-deployment monitoring, and supporting structured risk–benefit evaluations grounded in epistemic considerations.
📝 Abstract
Artificial intelligence (AI) systems increasingly mediate decisions affecting individuals and societies. Existing data protection frameworks address certain privacy-related harms, particularly those arising from data leakage, re-identification, and profiling. However, they inadequately capture a more fundamental risk: unreliable or unjustified inference produced by AI systems even when data collection and processing are legitimate. This article argues that modern AI raises distinct concerns of construct validity, confounding, representativeness, distribution shift, and fairness trade-offs that require specialised regulatory attention. In the context of AI, transparency and explainability acquire distinct and significantly more challenging meanings than in conventional software. A substantial body of work in critical data studies and the measurement-theoretic literature has diagnosed these epistemological limitations. This article's contribution is to derive from that diagnosis a structured and operationalizable regulatory framework. We argue that validity of inference should function as a precondition for proportionality assessment and deployment approval --- a move that existing frameworks, including the EU AI Act's domain-based risk tiers, do not make. We ground this argument in the constitutional principle of informational self-determination articulated in the Indian Supreme Court's \emph{Puttaswamy} judgement, extending its reach from data collection to the legitimacy of use of data. Effective governance must therefore incorporate AI-specific validity assessment, post-deployment monitoring, and proportionality assessments grounded in structured articulation of both epistemic risk and potential benefit.