遇见数据集

Privacy, Data Protection, Risk, and Compliance in the Age of Generative AI Systems: A Systematic Mapping Study

收藏
Zenodo2026-02-02 更新2026-05-26 收录
官方服务:

资源简介:

Research Context: Generative Artificial Intelligence (GenAI), particularly Large Language Models (LLMs), has advanced rapidly across domains, raising concerns about privacy, data protection, risk management, and regulatory compliance. Despite its transformative potential, adoption remains immature and challenged by ethical, technical, and legal limitations. Practical Problem: Organizations, developers, and end users face increasing risks of privacy violations, re-identification, model inversion, and lack of transparency. Current regulatory frameworks such as GDPR and LGPD struggle to address GenAI’s complexity, leaving gaps between technical mechanisms and legal requirements. Proposed Solution: To better understand these challenges, we conducted a systematic mapping study focused on privacy-preserving mechanisms, risk management frameworks, and compliance models applicable to GenAI systems. Our analysis identifies state-of-the-art approaches, their advantages, and limitations, highlighting how they may support trustworthy adoption. Related IS Theory: The study is grounded in theories of information systems governance, data protection by design, and responsible AI, aligned with sociotechnical perspectives that integrate technological, organizational, and regulatory aspects of information systems. Research Method: Following a systematic mapping protocol, we searched four major digital libraries (ACM DL, IEEE Xplore, ScienceDirect, Springer Link), applied predefined inclusion and exclusion criteria, and performed quality assessment. From 1,138 initial studies, 44 were analyzed in depth, and 15 met all quality thresholds. Summary of Results: The findings indicate four main categories of privacy-preserving techniques (differential privacy, federated learning, cryptographic approaches, and synthetic data), five risk management frameworks (e.g., NIST AI RMF, MITRE AI Security), and compliance mechanisms (DPIA, CA, FRIA). Comparative analyses reveal trade-offs between technical robustness, scalability, and regulatory alignment. Contributions and Impact to IS area: This study consolidates mechanisms to address privacy, risk, and compliance in GenAI, highlighting gaps at the intersection of technical safeguards and legal requirements. It supports scholars and practitioners in designing responsible AI systems and informs IS research agendas, organizational policies, and regulatory strategies for intelligent information systems.

提供机构:
SBC
创建时间:
2025-10-06
二维码
社区交流群
二维码
科研交流群
商业服务