Change search
Link to record
Permanent link

Direct link
Publications (10 of 45) Show all publications
Colonna, L. (2026). Artificial Intelligence in Education (AIED): Towards More Effective Regulation. European Journal of Risk Regulation, 17(1), 161-181
Open this publication in new window or tab >>Artificial Intelligence in Education (AIED): Towards More Effective Regulation
2026 (English)In: European Journal of Risk Regulation, ISSN 1867-299X, E-ISSN 2190-8249, Vol. 17, no 1, p. 161-181Article in journal (Refereed) Published
Abstract [en]

This paper critically assesses the effectiveness of the EU AI Act in regulating artificial intelligencein higher education (AIED), with a focus on how it interacts with existing education regulation. Itexamines the growing use of high-risk AI systems – such as those used in admissions, assessment,academic progression, and exam proctoring – and identifies key regulatory frictions that arisewhen AI regulation and education regulation pursue overlapping but potentially conflicting aims.Central to this analysis is the concept of human oversight: while the AI Act frames oversight as asafeguard for accountability and fundamental rights, education regulation emphasises theprofessional autonomy of teachers and their role in maintaining pedagogical integrity. Yet, theregulatory role of teachers in AI-mediated environments remains unclear. Applying Mousmouti’seffectiveness test, the paper evaluates the AI Act along four dimensions – purpose, coherence,results, and structural integration with the broader legal framework – and argues that legaleffectiveness in this context requires a more precise alignment between AI and educationregulation.

Keywords
AI Act, AIED, education regulation, effectiveness, GDPR
National Category
Law
Identifiers
urn:nbn:se:su:diva-246349 (URN)10.1017/err.2025.10039 (DOI)001560564100001 ()2-s2.0-105014780936 (Scopus ID)
Available from: 2025-09-01 Created: 2025-09-01 Last updated: 2026-06-11Bibliographically approved
Colonna, L. (2026). Free and Open Source Software in education and the Interoperable Europe Act: Advancing digital autonomy?. Computer Law & Security Review, 61, Article ID 106305.
Open this publication in new window or tab >>Free and Open Source Software in education and the Interoperable Europe Act: Advancing digital autonomy?
2026 (English)In: Computer Law & Security Review, ISSN 2212-473X, Vol. 61, article id 106305Article in journal (Refereed) Published
Abstract [en]

This paper examines how the Interoperable Europe Act (IEA) shapes the legal framework for the adoption of Free and OpenSource Software (FOSS) in public education, specifically evaluating its contribution to advancing digital autonomy in this context. It argues that the IEA represents a landmark effort to build a more integrated and collaborative EU digital public sector by requiring interoperability across trans European digital public services and promoting the reuse of resources, with particular promise for the educational sector who has grown increasingly dependent on digital infrastructure provided by private technology companies. At the same time, the paper argues that the potential of the IEA to support digital autonomy in educational contexts is limited by its scope and by its failure to fully address key barriers to FOSS adoption in schools and universities, including complex procurement procedures, licensing challenges, and operational barriers within the educational sector. Ultimately, these limitations indicate that its impact is likely to remain modest unless complemented by broader reforms at the national and institutional levels.

Keywords
Interoperability, Free and open source software, Digital sovereignty, Digital autonomy, Public sector
National Category
Law
Identifiers
urn:nbn:se:su:diva-254273 (URN)10.1016/j.clsr.2026.106305 (DOI)001729709400001 ()2-s2.0-105033419503 (Scopus ID)
Funder
Wallenberg AI, Autonomous Systems and Software Program – Humanity and Society (WASP-HS)
Available from: 2026-04-17 Created: 2026-04-17 Last updated: 2026-04-21Bibliographically approved
Colonna, L. (2025). Complex Normativity: Understanding the Relationship between Human Oversight by Design and Standardization in the Context of AI Development and Deployment. In: Eleni Kosta; Dara Hallinan; Paul De Hert; Suzanne Nusselder (Ed.), Eleni Kosta; Dara Hallinan; Paul De Hert; Suzanne Nusselder (Ed.), Data Protection, Privacy and Artificial Intelligence: To Govern or To Be Governed, That Is the Question. Paper presented at 17th International CPDP.ai Conference (CPDP.ai 2024), Brussels, Belgium, 22-24 May, 2024 (pp. 77-113). Oxford: Hart Publishing Ltd
Open this publication in new window or tab >>Complex Normativity: Understanding the Relationship between Human Oversight by Design and Standardization in the Context of AI Development and Deployment
2025 (English)In: Data Protection, Privacy and Artificial Intelligence: To Govern or To Be Governed, That Is the Question / [ed] Eleni Kosta; Dara Hallinan; Paul De Hert; Suzanne Nusselder, Oxford: Hart Publishing Ltd, 2025, p. 77-113Conference paper, Published paper (Refereed)
Abstract [en]

This chapter examines the relationship between Human Oversight by Design (HObD), as outlined in Article 14 of the AI Act, and socio-technical standardisation, aiming to understand their roles as regulatory techniques within AI development and deployment. It argues that the growing influence of sociotechnical standards, which aim to protect health, safety as well as fundamental rights, intersects with ‘Legal Protection by Design’ norms like HObD in ways that require critical legal analysis. By exploring these concepts through the lenses of rule setting, monitoring, and enforcement, the chapter highlights how public and private actors, particularly standardisation bodies and technology providers, are increasingly intertwined in regulatory processes. This shift toward co-regulation raises critical challenges related to ensuring accountability and maintaining the legitimacy of regulations influenced by private actors. Ultimately, the chapter demonstrates that the intersection of these hard and soft law approaches to AI regulation creates complex normative issues.

Place, publisher, year, edition, pages
Oxford: Hart Publishing Ltd, 2025
Keywords
AI Act, Human oversight by design, Socio-technical standards, De-centered regulation
National Category
Law
Identifiers
urn:nbn:se:su:diva-242862 (URN)2-s2.0-105014585319 (Scopus ID)9781509984015 (ISBN)9781509983995 (ISBN)
Conference
17th International CPDP.ai Conference (CPDP.ai 2024), Brussels, Belgium, 22-24 May, 2024
Funder
Wallenberg AI, Autonomous Systems and Software Program – Humanity and Society (WASP-HS)
Available from: 2025-05-03 Created: 2025-05-03 Last updated: 2025-11-01Bibliographically approved
Jevremovic, A., Aleksic, S., Veinovic, M. & Colonna, L. (2025). Data Security in AAL. In: Albert Ali Salah; Liane Colonna; Francisco Florez-Revuelta (Ed.), Privacy-Aware Monitoring for Assisted Living: Ethical, Legal, and Technological Aspects of Audio- and Video-Based AAL Solutions (pp. 99-128). Springer Nature
Open this publication in new window or tab >>Data Security in AAL
2025 (English)In: Privacy-Aware Monitoring for Assisted Living: Ethical, Legal, and Technological Aspects of Audio- and Video-Based AAL Solutions / [ed] Albert Ali Salah; Liane Colonna; Francisco Florez-Revuelta, Springer Nature, 2025, p. 99-128Chapter in book (Refereed)
Abstract [en]

Active assisted living (AAL) environments inherently collect, generate, and use large amounts of data. These environments are inherently distributed and often use external services, so data can be in different states and locations. This data is often very sensitive, and its compromise can endanger the privacy and security of users. Additionally, data unavailability can jeopardize the proper functioning of critical environment functions. This chapter presents relevant aspects of data protection. General principles, risks, approaches, and solutions for data protection are analyzed, taking into account the specificities applicable in AAL environments. The first part of the chapter provides an overview of security and data protection, along with a chapter outline. The second part offers a retrospective of the evolution of relevant information technologies, with an emphasis on two critical technologies for AAL: the Internet of Things and cloud computing. The third part outlines the relevant cryptological fundamentals of data protection. In the fourth part, a synthesis of the fundamentals, technologies, risks, and possible solutions is presented. The fifth part of the chapter expands the view on data protection from the perspective of the importance of open source and technological sovereignty. The sixth part reviews the importance of proper management of the entire lifecycle of AAL environments and their components. Finally, the last part of the chapter analyzes relevant and current legal aspects of data protection.

Place, publisher, year, edition, pages
Springer Nature, 2025
National Category
Law
Identifiers
urn:nbn:se:su:diva-245115 (URN)10.1007/978-3-031-84158-3_4 (DOI)2-s2.0-105014332593 (Scopus ID)978-3-031-84157-6 (ISBN)978-3-031-84158-3 (ISBN)
Available from: 2025-07-26 Created: 2025-07-26 Last updated: 2025-09-09Bibliographically approved
Ali Salah, A., Colonna, L. & Florez-Revuelta, F. (Eds.). (2025). Privacy-Aware Monitoring for Assisted Living: Ethical, Legal, and Technological Aspects of Audio- and Video-Based AAL Solutions. Springer Nature
Open this publication in new window or tab >>Privacy-Aware Monitoring for Assisted Living: Ethical, Legal, and Technological Aspects of Audio- and Video-Based AAL Solutions
2025 (English)Collection (editor) (Refereed)
Abstract [en]

This open access book provides an interdisciplinary collection of perspectives on the design of privacy-aware audio and video-based monitoring solutions for Active and Assisted Living (AAL). AAL involves leveraging innovative technologies to create supportive and inclusive environments, empowering older, impaired, or frail individuals to live independently and actively participate in society. Bridging technology, law, and ethics, this book explores state-of-the-art approaches for the development of AAL that prioritize user privacy, making it an essential resource for researchers, practitioners, and policymakers in the field.

It is the culmination of GoodBrother, a Europe-wide project funded by the COST Association, aimed at enhancing awareness and expertise on the ethical, legal, and privacy issues associated with audio- and video-based monitoring in assisted living contexts. Written by experts from computing, engineering, healthcare, design, law, ethics, and sociology, it provides diverse perspectives into AAL.

•  Introduces a taxonomy of AAL technologies and applications, providing guidance from data acquisition and processing to interaction and infrastructure of AAL systems.

• Describes the core competencies, including machine learning, privacy preservation in audio and video, data security, and security by design.

• Presents in-depth reviews and case studies on AAL applications, such as fall detection, gait and frailty recognition, activities of daily living, vital sign monitoring, affective computing, and smart mirrors.

•  Contains the state of the art and advances in AAL, especially with regards to privacy, ethical, and legal issues, including GDPR, but also the implications of the AI Act and the Cybersecurity Act.

Place, publisher, year, edition, pages
Springer Nature, 2025. p. 354
Series
Intelligent Systems Reference Library (ISRL) ; 270
National Category
Law
Identifiers
urn:nbn:se:su:diva-245117 (URN)10.1007/978-3-031-84158-3 (DOI)978-3-031-84157-6 (ISBN)978-3-031-84158-3 (ISBN)
Available from: 2025-07-26 Created: 2025-07-26 Last updated: 2025-11-17Bibliographically approved
Colonna, L. & Riva, G. (2025). Smart Mirrors and Data Protection Regulation. In: Albert Ali Salah; Liane Colonna; Francisco Florez-Revuelta (Ed.), Privacy-Aware Monitoring for Assisted Living: Ethical, Legal, and Technological Aspects of Audio- and Video-Based AAL Solutions (pp. 291-311). Springer Nature
Open this publication in new window or tab >>Smart Mirrors and Data Protection Regulation
2025 (English)In: Privacy-Aware Monitoring for Assisted Living: Ethical, Legal, and Technological Aspects of Audio- and Video-Based AAL Solutions / [ed] Albert Ali Salah; Liane Colonna; Francisco Florez-Revuelta, Springer Nature, 2025, p. 291-311Chapter in book (Refereed)
Abstract [en]

Smart mirrors have the potential to significantly enhance the quality of life for older adults by supporting their health, well-being, and social connectivity. However, they also introduce substantial legal and regulatory challenges, particularly in the realm of data protection. This paper aims to examine these challenges and contribute to the interdisciplinary discourse on smart mirrors, facilitating the integration of legal and technological considerations. At the outset, the paper provides an overview of smart mirrors to understand the technological foundation for which the law applies. It then explores various data protection concerns raised by smart mirrors, such as issues related to consent and transparency, security vulnerabilities, and the potential misuse of personal information. Next, the paper presents a taxonomy of key factors that influence how data protection rules apply to smart mirrors, such the physical location of the smart mirror, the context in which it is used (e.g., private home, public facility, healthcare environment), the status of the user (e.g., adult, minor, patient), the status of the service provider (e.g., manufacturer, third-party service), the involvement of any intermediaries in data processing, and the nature and sensitivity of the data being gathered (e.g., biometric data, personal health information). The paper concludes with an examination of the role of data protection by design (DPbD) in this context, highlighting the importance of incorporating regulatory compliance into smart mirrors from the beginning of its development and deployment.

Place, publisher, year, edition, pages
Springer Nature, 2025
National Category
Law
Identifiers
urn:nbn:se:su:diva-245116 (URN)10.1007/978-3-031-84158-3_12 (DOI)2-s2.0-105014478507 (Scopus ID)978-3-031-84157-6 (ISBN)978-3-031-84158-3 (ISBN)
Available from: 2025-07-26 Created: 2025-07-26 Last updated: 2025-09-09Bibliographically approved
Colonna, L. (2025). The end of open source?: Regulating open source under the cyber resilience act and the new product liability directive. The Computer Law and Security Review, 56, Article ID 106105.
Open this publication in new window or tab >>The end of open source?: Regulating open source under the cyber resilience act and the new product liability directive
2025 (English)In: The Computer Law and Security Review, ISSN 0267-3649, Vol. 56, article id 106105Article in journal (Refereed) Published
Abstract [en]

Rooted in idealism, the open-source model leverages collaborative intelligence to drive innovation, leading to major benefits for both industry and society. As open-source software (OSS) plays an increasingly central role in driving the digitalization of society, policymakers are examining the interactions between upstream open-source communities and downstream manufacturers. They aim to leverage the benefits of OSS, such as performance enhancements and adaptability across diverse domains, while ensuring software security and accountability. The regulatory landscape is on the brink of a major transformation with the recent adoption of both the Cyber Resilience Act (CRA) as well as the Product Liability Directive (PLD), raising concerns that these laws could threaten the future of OSS.

This paper investigates how the CRA and the PDL regulate OSS, specifically exploring the scope of exemptions found in the laws. It further explores how OSS practices might adapt to the evolving regulatory landscape, focusing on the importance of documentation practices to support compliance obligations, thereby ensuring OSS's continued relevance and viability. It concludes that due diligence requirements mandate a thorough assessment of OSS components to ensure their safety for integration into commercial products and services. Documentation practices like security attestations, Software Bill of Materials (SBOMs), data cards and model cards will play an increasingly important role in the software supply chain to ensure that downstream entities can meet their obligations under these new legal frameworks.

National Category
Law
Identifiers
urn:nbn:se:su:diva-239444 (URN)10.1016/j.clsr.2024.106105 (DOI)001421263800001 ()2-s2.0-85213216046 (Scopus ID)
Funder
Wallenberg Foundations
Available from: 2025-02-12 Created: 2025-02-12 Last updated: 2025-10-03Bibliographically approved
Colonna, L. & Oechtering, T. (2025). The Right to Be Forgotten Meets Machine Learning: Evaluating the Legal Feasibility of Unlearning Methods. In: Armando Aliu (Ed.), Artificial Intelligence and the Rule of Law: The Age of Legal Tech and Digital Governance in a Fractured Digital World (pp. 131-170). Palgrave Macmillan
Open this publication in new window or tab >>The Right to Be Forgotten Meets Machine Learning: Evaluating the Legal Feasibility of Unlearning Methods
2025 (English)In: Artificial Intelligence and the Rule of Law: The Age of Legal Tech and Digital Governance in a Fractured Digital World / [ed] Armando Aliu, Palgrave Macmillan, 2025, p. 131-170Chapter in book (Refereed)
Abstract [en]

The rapid advancement of machine learning (ML) technology is exposing a critical mismatch between the pace of technological advancement and the capacity of existing legal frameworks to effectively regulate it. As ML technologies advance, driving major changes across all sectors of society, traditional regulatory mechanisms—such as notice-and-comment rulemaking, legislation, and judicial review—are increasingly inadequate to address its unique and complex challenges. These established legal tools were designed for a slower, more predictable regulatory landscape, and they now struggle to respond to the ethical, privacy, and accountability questions that ML raises.

Place, publisher, year, edition, pages
Palgrave Macmillan, 2025
National Category
Law
Identifiers
urn:nbn:se:su:diva-248858 (URN)10.1007/978-3-031-97389-5_6 (DOI)2-s2.0-105025628028 (Scopus ID)978-3-031-97388-8 (ISBN)978-3-031-97389-5 (ISBN)
Available from: 2025-11-03 Created: 2025-11-03 Last updated: 2026-01-13Bibliographically approved
Colonna, L. (2025). Towards a Methodological Approach for Understanding Human Oversight Requirements under the AI Act. European review of digital administration & law, 6(2), 41-55
Open this publication in new window or tab >>Towards a Methodological Approach for Understanding Human Oversight Requirements under the AI Act
2025 (English)In: European review of digital administration & law, ISSN 2724-5969, Vol. 6, no 2, p. 41-55Article in journal (Refereed) Published
Abstract [en]

Human-centric AI has become a central principle in AI regulation, embodied in Article 14 of the EU AI Act, which requires that meaningful human oversight be designed into high-risk AI systems from the outset of their development. This paper examines Article 14 from a methodological perspective and proposes three core steps for analyzing its legal requirements: (1) identifying and categorizing obligations across text-based, soft, embedded, and datadriven law; (2) mapping the relational aspects of responsibility across the AI supply chain; and (3) examining how these obligations are implemented across the system lifecycle. By systematically addressing the layered nature of legal requirements, relational responsibilities, and the timing of rule implementation across the lifecycle of AI, the paper offers a basic framework for understanding how human oversight can be meaningfully and effectively embedded within the design, development, and operation of AI systems. 

Keywords
Human oversight, AI Act, Proactive law, Data-driven law, Distributed responsibility
National Category
Law
Identifiers
urn:nbn:se:su:diva-252378 (URN)10.53136/97912218237764 (DOI)
Funder
Wallenberg AI, Autonomous Systems and Software Program – Humanity and Society (WASP-HS)
Available from: 2026-02-10 Created: 2026-02-10 Last updated: 2026-03-30Bibliographically approved
Colonna, L. (2024). The AI Act’s Research Exemption: A Mechanism for Regulatory Arbitrage?. In: Andreas Moberg; Eduardo Gill-Pedro (Ed.), The Yearbook of Socio-Economic Constitutions: Law and the Governance of Artificial Intelligence (pp. 51-93). Springer
Open this publication in new window or tab >>The AI Act’s Research Exemption: A Mechanism for Regulatory Arbitrage?
2024 (English)In: The Yearbook of Socio-Economic Constitutions: Law and the Governance of Artificial Intelligence / [ed] Andreas Moberg; Eduardo Gill-Pedro, Springer, 2024, p. 51-93Chapter in book (Refereed)
Abstract [en]

This paper argues that by failing to acknowledge the complexity of modern research practices that are shifting from a single discipline to multiple disciplines involving many entities, some public, some private, the proposed AI Act creates mechanisms for regulatory arbitrage. The article begins with a semantic analysis of the concept of research from a legal perspective. It then explains how the proposed AI Act addresses the concept of research by examining the research exemption that is set forward in the forthcoming law as it currently exists. After providing an overview of the proposed law, the paper explores the research exemption to highlight whether there are any gaps, ambiguities, or contradictions in the law that may be exploited by either public or private actors seeking to use the exemption as a shield to avoid compliance with duties imposed under the law.

To address whether the research exemption reflects a coherent legal rule, it is considered from five different perspectives. The paper begins by examining the extent to which the research exemption applies to private or commercial entities that may not pursue research in a benevolent manner to solve societal problems, but nevertheless contribute to innovation and economic growth within the EU. Next, the paper explores how the exemption applies to research that takes place within academia but is on the path to commercialization. The paper goes on to consider the situation where academic researchers invoke the exemption and then go on to provide the AI they develop to their employing institutions or other public bodies for no cost. Fourth, the paper inspects how the exemption functions when researchers build high-risk or prohibited AI, publish their findings, or share them via an open-source platform, and other actors copy the AI. Finally, the paper considers how the exemption applies to research that takes place “in the wild” or in regulatory sandboxes.

Place, publisher, year, edition, pages
Springer, 2024
Series
YSEC Yearbook of Socio-Economic Constitutions ; 2023
National Category
Law
Identifiers
urn:nbn:se:su:diva-226328 (URN)10.1007/16495_2023_59 (DOI)2-s2.0-86000572331 (Scopus ID)978-3-031-55831-3 (ISBN)978-3-031-55832-0 (ISBN)
Available from: 2024-02-07 Created: 2024-02-07 Last updated: 2025-06-02Bibliographically approved
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0009-0007-7354-1675

Search in DiVA

Show all publications