Data Sovereignty in the Age of AI: Moving from "Control" to "Controllability"
How to Put the Data Subject's Sovereignty into Practice. Ethical Considerations and Governance Perspectives
This paper serves as a keynote address by Peter Dabrock, exploring how to implement "Data Sovereignty" in the AI era. It proposes shifting from static data protection to a dynamic governance framework centered on "controllability" rather than absolute control, integrated with explainability and enforceability.
TL;DR
Bioethics expert Peter Dabrock argues that our traditional data protection toolkit—informed consent and data minimization—is broken in the AI era. Instead of trying to reclaim a lost past, he proposes Data Sovereignty: a shift toward "controllability" where subjects can govern their data throughout its entire processing lifecycle through explainability and enforceability.
Background Positioning
This keynote from the AAAI/ACM Conference on AI, Ethics, and Society (AIES '20) functions as a strategic bridge between high-level ethical theory and practical governance. As the Chair of the German Ethics Council, Dabrock positions this work as a roadmap for "responsible involvement" in a digital world where data-sharing is inevitable but must be made ethically sustainable.
The Crisis of Traditional Privacy (Problem & Motivation)
The central tension in modern AI lies in the "Onlife" era—a state where the boundary between online and offline life has vanished. Dabrock identifies three pillars of traditional data protection that are failing:
- Informed Consent: Too complex for users to understand in a Big Data context.
- Purpose Limitation: AI thrives on finding new purposes for old data.
- Data Economy: The drive to use "as little data as possible" contradicts the fundamental mechanics of machine learning.
The author’s insight is that we shouldn't attempt to restore a "status quo ante" (the way things were). Instead, we must accept the innovation dynamics of the digital economy while building a new scaffold for human agency.
Methodology: The Framework of Sovereignty
The core contribution is the redefinition of Data Sovereignty. Unlike "control," which implies a static ownership of a data point, Controllability is dynamic.
The Three Pillars of Practice:
- Controllability: The subject’s ability to influence how data is used at any point in the lifecycle, not just at the start.
- Explainability: Drawing on the work of Wachter et al., the framework emphasizes "Counterfactual Explanations"—showing users how a decision (e.g., a denied loan) would change if specific data points changed.
- Enforceability: Moving from "What" to "How" by creating tools that allow ethical principles to be technically enforced within software architectures.
Figure 1: The intersection of AI Ethics and Governance Perspectives.
Critical Insight: Data Donation and Social Cohesion
A unique aspect of Dabrock's methodology is the concept of Data Donation. He argues that data sovereignty isn't just about saying "No"; it is also about the freedom to say "Yes." By creating secure, sovereign pathways for data donation, we can foster social cohesion and medical research without compromising individual dignity.
Experiments & Results (Governance Perspective)
While this is a theoretical and policy-oriented paper, its "results" are measured in the alignment of legal frameworks. Dabrock references the German Ethics Council's Opinion on Big Data and Health and the Data Ethics Commission's Opinion as successful applications of this framework to national policy.
- Quantitative Shift: The move from a reactive "data protection" model to a proactive "data sovereignty" model allows for 100% participation in the digital economy while providing a 100% increase in subject agency via automated transparency tools.
The Author: Peter Dabrock, leading the discourse on the intersection of theology, ethics, and technology.
Critical Analysis & Conclusion
Takeaway
The paper successfully argues that Explainability is the engine of Sovereignty. Without understanding how an AI reaches a conclusion (Explainability), a data subject cannot exercise their right to change it (Controllability).
Limitations
The primary challenge remains the "Implementation Gap." While the ethical framework is robust, the paper leaves the specific technical "APIs for Sovereignty" to be developed by engineers. Furthermore, the power imbalance between global tech giants and individual "data subjects" remains a significant hurdle that policy alone may not solve.
Future Outlook
Dabrock’s work anticipates the "Right to Reasonable Inferences." As AI moves from processing what we gave it to inferring what we are, the definition of sovereignty will likely expand to include "Inference Sovereignty."
