The dangers of computational law and cybersecurity; perspectives from engineering and the AI Act

Ludvigsen, Kaspar Rosager and Nagaraja, Shishir and Daly, Angela (2022) The dangers of computational law and cybersecurity; perspectives from engineering and the AI Act. Other. arXiv.org, Ithaca, NY. (https://doi.org/10.48550/arXiv.2207.00295)

[thumbnail of Ludvigsen-etal-arXiv-2022-The-dangers-of-computational-law-and-cybersecurity-perspectives-from-engineering-and-the-AI-Act]
Preview
Text. Filename: Ludvigsen_etal_arXiv_2022_The_dangers_of_computational_law_and_cybersecurity_perspectives_from_engineering_and_the_AI_Act.pdf
Preprint
License: Creative Commons Attribution 4.0 logo

Download (727kB)| Preview

Abstract

Computational Law has begun taking the role in society which has been predicted for some time. Automated decision-making and systems which assist users are now used in various jurisdictions, but with this maturity come certain caveats. Computational Law exists on the platforms which enable it, in this case digital systems, which means that it inherits the same flaws. Cybersecurity addresses these potential weaknesses. In this paper we go through known issues and discuss them in the various levels, from design to the physical realm. We also look at machine-learning specific adversarial problems. Additionally, we make certain considerations regarding computational law and existing and future legislation. Finally, we present three recommendations which are necessary for computational law to function globally, and which follow ideas in safety and security engineering. As indicated, we find that computational law must seriously consider that not only does it face the same risks as other types of software and computer systems, but that failures within it may cause financial or physical damage, as well as injustice. Consequences of Computational Legal systems failing are greater than if they were merely software and hardware. If the system employs machine-learning, it must take note of the very specific dangers which this brings, of which data poisoning is the classic example. Computational law must also be explicitly legislated for, which we show is not the case currently in the EU, and this is also true for the cybersecurity aspects that will be relevant to it. But there is great hope in EU's proposed AI Act, which makes an important attempt at taking the specific problems which Computational Law bring into the legal sphere. Our recommendations for Computational Law and Cybersecurity are: Accommodation of threats, adequate use, and that humans remain in the centre of their deployment.