Do training and deploying an AI model need separate lawful bases?
Answered
Often yes. The ICO says it usually makes sense to separate research and development (including training and model selection) from deployment, because they are distinct purposes with different circumstances and risks. Identify a purpose and lawful basis for each operation.
From the guidance
Primary (how) ICO: How do we ensure lawfulness in AI?
Section: How should we distinguish purposes between AI development and deployment?
Read this in ICO: How do we ensure lawfulness in AI? (opens in new tab)
Secondary (normative) ICO: How do we ensure lawfulness in AI?
Section: What should we consider when deciding lawful bases?
Read this in ICO: How do we ensure lawfulness in AI? (opens in new tab)
Related questions
- Can attackers steal my model or training data through the API? Security and safe use of tools
- What lawful basis can a public authority use for AI that processes personal data?
- Can I use AI to process personal data?
- Can I reuse existing personal data to train or run an AI system?
- How much human oversight do I need when using AI in decision making?