logo SBA

ETD

Archivio digitale delle tesi discusse presso l’Università di Pisa

Tesi etd-08292026-124329


Tipo di tesi
Tesi di laurea magistrale
Autore
GALVAO ESPIRITO SANTO, JULIA
URN
etd-08292026-124329
Titolo
Governing AI-Enabled Development: From the GDPR Accountability Gap to AI Act Classification Instability
Dipartimento
GIURISPRUDENZA
Corso di studi
DIRITTO DELL'INNOVAZIONE PER L'IMPRESA E LE ISTITUZIONI
Relatori
.
relatore Prof. Favaro, Tamara
Parole chiave
  • agentic AI
  • AI Act classification,
  • AI agents,
  • AI enabled development,
  • AI governance,
  • capability drift
  • decentralised software development,
  • GDPR accountability,
  • provider deployer allocation,
  • shadow AI,
  • shadow IT,
Data inizio appello
14/09/2026
Consultabilità
Non consultabile
Data di rilascio
14/09/2096
Riassunto (Inglese)
This thesis examines how decentralised, AI-enabled development affects the organisational visibility that GDPR accountability and the EU AI Act's role and risk classification framework each presuppose. AI-enabled development platforms, operating through code-visible, code-abstracted or visual-orchestration interfaces, allow non-specialist employees to create or substantially modify operational artefacts by connecting existing organisational access to external services and models, without the provisioning or release events through which such systems have traditionally become visible to central IT. The resulting artefacts can also change after deployment through ordinary conversational instructions, a process this thesis terms capability drift, altering the data an artefact accesses, the actions it can perform or its degree of runtime autonomy without generating any event the organisation would recognise as a material change.
Adopting a doctrinal and conceptual approach supported by a functional technical typology, the thesis argues that this phenomenon does not alter what either regime requires, but weakens an organisation's practical capacity to identify, govern and demonstrate compliance with obligations that remain unchanged. Under the GDPR, the organisation remains controller of processing an employee initiates, but may be unable to reconstruct the means, risks and safeguards relevant to that processing once called upon to do so, producing what the thesis identifies as an accountability gap. Under the EU AI Act, the same absence of visibility, compounded by an unresolved boundary between configuring an existing platform and developing a distinct AI system, and by runtime behaviour drift in agentic systems, produces instability in the organisation's role and in the risk classification of the systems it operates.
The thesis's contribution lies in identifying capability drift and the disappearance of conventional development events as a single structural mechanism linking these two, otherwise distinct, legal difficulties. It closes with a brief consideration of whether conventional governance responses, prohibition, employee disclosure and monitoring, could restore the visibility both regimes require, and suggests, without developing the point further, that infrastructure-level visibility may be a more promising direction than policy-layer intervention for future research.
Riassunto (Italiano)
File