发表机构
Studio Legale Fabiano(法比亚诺律师事务所)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文探讨欧盟数字法中《人工智能法案》与GDPR对推理的不同界定,指出推理能力不决定法律范围,提出两层框架及组合效果测试等规则,为智能体架构下的相关监管提供解释方案。
AI 中文摘要
欧盟数字法的两项核心工具将推理置于中心位置,但对其定义各不相同。《人工智能法案》第3条第1款将推理能力作为构成性要素,这是区分受监管类别与传统软件的核心特征;《通用数据保护条例》(GDPR)从未对推理作出定义,但对其实施保护性监管,无论产生推理的技术是否符合人工智能系统的定义,相关后果均源于个人数据处理以及推理对个人的陈述或影响。两者的法律范围并非同心,这种不重合在单步系统中并不明显,而智能体架构使其在实践中变得尖锐。本文提出的核心论点是:推理能力并不决定法律范围,且缺乏推理能力也不构成豁免。本文构建了一个两层框架,推理发挥构成性和保护性两种法律功能,其中保护性功能通过识别、归因和决策三条路径实现;组合并非第四条路径,而是一种跨领域的架构维度,智能体架构正是通过组合、范围、持久性和可审查性进行调整。该框架由三个概念支撑:推理阈值、推理范围和推理链,对应归责链。《欧盟条例2026/1744》未改动构成性标准,新增了一项涉及影响未来操作输入的输出的条款,但未提供任何聚合规则。本文提出一项解释规则,即组合效果测试,用于确定GDPR第22条下的决策单位,同时明确举证责任分配,并制定与推理链匹配的文档义务。
英文摘要
Two instruments of EU digital law place inference at their centre and mean different things by it. Article 3(1) of the AI Act uses the capability to infer constitutively: it is the central feature separating the regulated category from conventional software. The GDPR never defines inference, yet governs it protectively: the consequences follow from the processing of personal data and from what the inference says about, or does to, a person, whether or not the technology that produced it qualifies as an AI system. The two perimeters are not concentric. Their non-coincidence remained invisible in single-shot systems; agentic architectures make it operationally acute. The thesis: inferential capability does not determine legal scope, and its absence does not create immunity. The framework is two-level. Inference performs two legal functions, constitutive and protective; the protective function operates through three pathways - identificatory, attributive and decisional. Composition is not a fourth pathway but a cross-cutting architectural dimension which, with reach, persistence and reviewability, is what agentic architectures modify. Three concepts support it: the inferential threshold, the inferential reach and the inferential chain, mapped onto the chain of imputation. Regulation (EU) 2026/1744 left the constitutive criterion untouched and inserted a provision contemplating outputs that influence the inputs of future operations, without supplying any rule of aggregation. The article proposes an interpretive rule, a compositional-effects test identifying the decision unit under Article 22 GDPR together with the allocation of the burden of establishing it, and documentation duties calibrated to inference chains.