Supporting Regulatory Compliance via Automatic and Semi-Automatic Approaches

Università degli Studi di Trento

Industrial Innovation
Cycle: 42

In recent years, the rising complexity of digital solutions and the development of Artificial Intelligence (AI) technologies has accelerated significantly, to the point of becoming pervasive in our everyday lives. Such widespread diffusion poses great opportunities, but also risks in terms of security and privacy, leading the European Union (EU) to introduce sophisticated legal constraints.

Regulations such as NIS2, CRA, and GDPR were introduced to tackle the security and privacy risks posed by increasing digitalisation and evolving cyber threats, and were progressively complemented by additional rules targeting risks in specific domains. Then, in June 2024, the first legal framework entirely dedicated to AI applications, the EU AI Act, entered into force.  This makes the legal landscape particularly complex to analyse, requiring a tight collaboration among professionals with diverse expertise to design and deploy AI systems. 

Several tools have been developed to support regulatory analysis: the majority focus on the GDPR, leveraging both manual [4, 5] and AI-based techniques [6–9]. Following the introduction of the AI Act, interest in tools addressing this regulation has also increased [10–14]. In contrast, current approaches to support the analysis of cross-regulatory compliance are limited, and mainly based on manual methods [1,2]. The literature is even more scarce when it comes to introducing automation in the process [3].
Overall, the literature shows that building a comprehensive automated environment for compliance reasoning is challenging: the most common issues include limited automation, lack of generalizability, and partial coverage of regulations. Furthermore, the abstract and interpretable nature of legal language complicates the translation of regulatory guidelines into precise technical requirements. When considering multiple regulations, new challenges are introduced, related to the complexity of analysing the relationships between different—partially conflicting—regulations.
The candidate is required to focus on the design of a (semi-)automated AI pipeline to support compliance analysis of the EU AI Act. The framework should be able to adapt to the evolutions of the legal landscape and integrate supplementary documents to guide organizations in adjusting the norms to specific scenarios. The candidate should also investigate how using Generative AI techniques can improve the understanding of legal language and aid the interpretation of subtle language nuances. Moreover, they should consider different knowledge representation systems to determine which is most suitable for structuring legal information and reasoning over it. Finally, this research can also explore compliance with respect to other regulations in the cybersecurity field, potentially tackling cross-regulatory compliance and addressing the problem of (partially) conflicting requirements.

FBK Contact

SaFEWaRe

Are you ready to join FBK international community?

We welcome motivated applicants who are passionate about research, eager to learn, and driven by curiosity to explore new ideas.

Six reasons to become a PhD student at FBK

At FBK, our PhD program is designed to develop highly specialized researchers in a unique, stimulating environment

RESEARCH
AT FBK​

A Hub of innovation and collaboration​

TOWARD PHD EXCELLENCE

FBK stands out as one of Italy’s leading research institutions

international
network

National and international
companies and universities

learning opportunities

Explore a world of learning
at FBK

Discover Trento

One of the most Italy’s
livable city

Join FBK

A truly international
community