Artificial intelligence in The Brønnøysund Register Centre
In the strategic plan of The Brønnøysund Register Centre, under “Ambisjoner” it is formulated that we are going to explore and in a responsible way use the possibilities artificial intelligence provides us with. As a result of this, we have decided on a policy regarding our use of artificial intelligence, created by our AI-team.
The policy provides the following guidelines that everyone at the Brønnøysund Register Centre must follow:
We should never:
- share personal information, such as information about employees and citizens in AI tools that have not been approved
- paste or use internal or sensitive information, documents or excerpts from such documents in an unapproved AI tool, unless anything else has been agreed and documented
- share user information, such as login information and passwords
- trust the AI to tell the truth
- use only AI to make decisions which in any substantial way affects individuals
- use special categories of personal data (sensitive personal data) in AI tools, unless otherwise authorised and documented
We should always:
- be critical of AI-generated results – watch out for inaccuracies, biases and false information
- verify facts
- be critical of whether AI violates copyright, especially of third parties
- specifically label content which is fully or partly created through generative AI. For instance “This illustration was by using AI”, in addition to crediting the specific AI tool
- note that we are responsible for an AI-generated text that we publish or send present as our own
- be transparent and inform about it when you are using an AI-generated text, images, codes or other content
- note that AI makes it easier for imposters to scam someone. Any suspicious incidents must be reported
If you wish to contact our AI team, please use our contact form. You can read our policy below:
The Brønnøysund Register Centre has, as one of its four strategic ambitions, to “explore and in a responsible way exploit the possibilities provided by artificial intelligence”. This should contribute to meet our social responsibility, which is to “contribute to increased added value through managing register data in a safe and clear manner, in order to create confidence and renewal of society”.
Artificial intelligence (AI) is an area within information technology which develops rapidly.
As a government agency, we depend on our users having trust in the services we provide. For this reason, it is important to secure that the use of AI is legal, fair and responsible. We must actively follow up on this use this as a basis when we consider how to use AI responsibly and transparently.
In the national strategy for artificial intelligence, the government states that AI developed and used in Norway should be based on ethical principles, and must respect human rights and democracy. This reflects a broader international focus on the role of ethics in AI, which has also been emphasised by organisations such as the OECD, the United Nations and the European Union. Based on this, as well as our own values, we have reached five basic ethical principles for the development and usage of AI. These principles set the overall direction and form the foundation of what will, over time, become a comprehensive framework for AI. The five fundamental ethical principles are:
- accountability
- transparency
- fairness
- security
- privacy protection
The purpose of the policy is to ensure that everyone in The Brønnøysund Register Centre using or developing AI systems does so in a lawful and responsible manner.
We should be able to realise the potential of AI without compromising the high level of trust that society places in us. To achieve this, all employees must develop an understanding of what AI is, the risks it involves, and how its benefits can be realised.
In order to attend to this purpose, the policy will be updated regularly, in line with the development of the technology.
This policy applies for everyone at The Brønnøysund Register Centre who are going to use digital tools with AI. This includes both employees and contract workers as well as others providing services on our behalf. As an employee of, or a person engaged by, the Brønnøysund Register Centre, you must read this policy before using AI.
The policy contains short and practical guidelines that everyone is expected to follow. In addition, separate guidelines have been developed for those who use AI for system development and for those who use AI in communication-related work.
At present, there does not exist Norwegian legislation regulating the use or the development of AI. However, the EU has passed the AI Act, which will be a part of Norwegian legislation gradually.
The AI Act is a product safety legislation that regulates the development of AI systems, and the integration of the systems in organisations.
As a government agency we are bound by other legislation, which will also be relevant in relation to the use of AI. We are, amongst other things, bound by:
- the Public Administration Act when it comes to case processing
- the Freedom of Information Act for transparency
- the Archives Act for archiving public information
- the Personal Data Act for the protection of personal information
It is important to note that the use of AI requires compliance with Norwegian regulations, and that the use of AI can bring about greater risks for some legal areas, such as personal data protection.
Algorithm
An algorithm is a set of step-by-step instructions in a specific order created to achieve something.
Machine learning
Machine learning uses mathematical and statistical methods for the creation of algorithms which are based on analysis of data. The training of a system can take place through supervised learning, unsupervised learning or reinforcement learning.
Artificial intelligence
Artificial intelligence has various definitions, some comprehensive and some narrow. What is common for the definitions is that they define technology capable of systemising and interpreting data, followed by making decisions and learning from experience.
A distinction can be made between an AI model and an AI system.
- An AI model is a mathematical or algorithmic structure trained through using data to solve specific tasks.
- An AI system is a complete package containing one or several AI models, as well as software etc. to implement and take models into practical use, for instance an app. An AI model is a part of an AI system.
AI tool
An AI tool is a ready-made AI system offered on the market by a supplier.
Traditional AI
Traditional AI is based on rules and logic, and is dependent on rules and programming defined by humans. It often focuses on tasks such as classification, decision-making and problem-solving.
Generative AI
Generative AI refers to models which can generate, or create, new content based on existing information. It is capable of generating text, images, music or other types of content. ChatGPT is an example of a generative AI system which can generate text, but there are also examples of systems which can generate images and sound, such as DALL-E and the web service Suno.
AI user
An AI user is a person using (pre-trained) AI services to solve a task. The AI user must understand how the AI system works and how its output can be used.
AI developer
An AI developer is a person developing and training new AI models to do a specific task. The person developing AI often has to relate to factors such as data quality, data amount, accuracy connected to predictions etc. The AI developer is responsible for ensuring that the model is developed according to the ethical principles and other legal requirements.
Language model
A language model is a computer program that has learned patterns in text and can therefore understand and generate language. Put simply, it predicts the most likely response based on what it has learned.
Chatbot
A chatbot is a service that allows you to interact with a language model through a chat interface. It uses the language model to answer questions and assist you with tasks.
Approved AI tools
Approved AI tools may be used to share open, internal and sensitive information. This requires internal assessments of security and privacy to be carried out by the Brønnøysund Register Centre. Examples of approved tools include Copilot Chat, Microsoft 365 Copilot and Copilot Studio.
Unapproved AI tools
Only open information may be shared in unapproved AI tools. These tools have either been assessed as not sufficiently secure for the use of internal or sensitive information, or have not yet been assessed.
By “share” or “transfer”, we mean any way of entering information into AI-enabled solutions, such as copying and pasting text, uploading documents, creating connections between AI tools, etc.
6.1. Accountability
The use of AI creates new ways of sharing data and new risks in how we perform our work. As employees, we are responsible for the outputs and actions of AI systems. It is therefore important to critically assess the results produced by AI and verify information that appears questionable. As a general rule, AI should be used as a support tool, and the final decision must always be made by us.
It is also important to remember that if AI is used as part of the basis for a decision in a case, the interaction history with the AI may be regarded as an internal document and may be subject to requests for access. Irresponsible use of AI may therefore become public knowledge. As a government agency, we have a significant responsibility to maintain sound security practices.
The level of accountability required varies depending on your role. Stricter requirements apply to AI developers than to AI users. In addition, we have separate guidelines for the use of AI in system development and communications work, which set specific requirements in these areas. If the Brønnøysund Register Centre provides its own internal AI tools, the users must receive training before using them.
6.2. Transparency
We must build trust and confidence among users and employees by being open about how we use AI, which may be an unfamiliar technology for many people. This gives us a responsibility to inform and explain the consequences for individuals.
If we use AI directly in our communication with users of our registers, for example in our guidance services, the transparency requirements of administrative law and data protection legislation will apply. It is particularly important to ensure that users understand that they are communicating with AI-based technology. This is necessary to enable individuals to exercise their rights and to challenge decisions.
This also applies to AI systems used to improve the quality of our registers, for instance by helping to detect crime. The Brønnøysund Register Centre will not use AI systems for purposes that may affect users’ rights unless we have sufficient insight into how those systems reach their decisions.
Transparency also means that employees of the Brønnøysund Register Centre must understand how the AI tools they use work. AI developers who develop systems for the Brønnøysund Register Centre must have sufficient knowledge of the solutions to explain how they work and the basis on which they produce their results.
6.3. Fairness
For us to be able to use AI in a fair way compliant with our values, it is important that we are aware of the various risks related to the AI systems. For instance, it is important to be aware of the fact that generative models, such as ChatGPT, can provide biased or discriminating statements, in addition to statements that are incorrect.
It is important to remember that AI systems do not possess human qualities such as morality, reason or judgement. As a result, they cannot think, reflect or show empathy, even if they may appear to do so. This affects the quality of the responses produced by AI. Generative language models are probability-based models. This means that each word in a response is generated based on probabilities rather than facts. If an AI system does not know the answer to a question, it may still generate a response, even if that response is incorrect.
To minimise these risks, human supervision and evaluation of AI-generated responses are essential. This is particularly important where AI is used as part of a task performance and may have direct consequences for the rights and interests of natural or legal persons. Human supervision and evaluation can help ensure that AI systems do not undermine human autonomy or cause other unintended adverse effects.
6.4. Security
The introduction of AI may enhance existing security risks, or create new risks. When using AI, we are to follow both security instructions, control systems for security and underlying operational documentation related to the use of AI.
If an AI tool is to be used with anything other than open data, the necessary assessments must be carried out. These include assessments of the technical architecture, data flows, access management, logging and security controls. AI tools must be sufficiently secure to prevent unauthorised access to our data.
Several of the approved AI tools are access-controlled, which means that not everyone has access to them. This is a deliberate decision. Not all employees should have access to all approved AI tools. Access is granted only to those who have demonstrated a need and completed the required training.
6.5. Privacy protection
Even though transparency is a principle in decision-making, all individuals have a right to privacy. We must ensure that privacy protection is attended to, when working with AI.
Personal data is any information that can be linked to a natural person, either directly or indirectly. This includes, among other things, names, addresses, telephone numbers, e-mail addresses and national identity numbers. It also includes information that, on its own, is not sufficient to identify an individual, but which may do so when combined with information from other sources.
We are not permitted to share personal data without a specific legal basis. Personal data may be shared in approved AI tools, as we have sufficient safeguards in place to ensure that the information remains within the Brønnøysund Register Centre’s environment.
Special categories of personal data (sensitive personal data) must not be used in any AI tools. This includes, among other things, information relating to health, trade union membership, religion and ethnicity. Including special categories of personal data in AI processes increases the risk of creating new combinations of personal data.
We also hold personal data that is regarded as sensitive information within our registers, such as bankruptcy or distraint-related information. This information must not be shared with AI tools either.
7.1. What can we share and transfer to artificial intelligence?
AI systems learn from the data provided to them. In generative AI tools such as ChatGPT, prompts and instructions may be used to improve the service. This means that information entered into such language models could become accessible to other users of the service, including users outside our organisation. We must therefore not share or transfer information that is, or may be, internal or sensitive to any AI system that has not been approved for internal use.
Internal information can be for instance accounting figures, budgets, notes or minutes from meetings, presentations, agreements etc. or information about others, such as clients, partners etc. The crucial point is whether the information we share is something we normally would not have shared with someone unknown.
Information may be considered sensitive either because we do not want others to know about our organisation, or because we are legally required to keep it confidential. Confidentiality rules are intended to ensure that such information is not disclosed to unauthorised persons. As a general rule, great care should be taken when using classified information as input to AI models. Sharing information with such AI systems may also be irreversible. This may affect individuals’ rights under data protection legislation, such as the right to have personal data erased. The right to know what data has been collected and used may also be compromised if we do not have control over how personal data is processed by the AI system.
We apply a precautionary approach: if there is any doubt as to whether information is internal or sensitive, or contains personal data, it must not be shared in unapproved AI tools.
7.2. The use of results from artificial intelligence
AI based on language models is trained using large quantities of data which are not necessarily quality-assured or verified. This means that results from the use of AI systems can be inaccurate and sometimes incorrect. Because of this, it is important to be critical of the results, and verify them to the fullest extent possible. It is particularly important to be aware of this if AI is being used as a means within decision-making, which might have consequences for an individual. If the data being used to train an AI system reflects unwanted social prejudice, this might bring about biased results. It is therefore important that we are aware of these risks, and that AI dos not replace human assessments and decisions required by law. Since AI algorithms are trained using external material, the generated result may breach the copyrights of others. This can include text, images, audio/music, videos etc. The result of the use of AI should therefore not be published unless you are confident that they do not violate others’ rights. It should be marked that the results are generated by AI. For example, AI-generated text should be labelled with a statement such as: “This text was created with the help of AI.” You should also specify which AI tool was used.