AI赋能科研典型案例发布,企业合规使用人工智能须防三大法律风险
Recently, the Ministry of Science and Technology publicly released 16 typical cases of AI-empowered scientific research, covering cutting-edge fields such as biomedicine, new materials, meteorological forecasting, and genomics. These cases demonstrate the immense potential of AI technology in accelerating scientific discovery, optimizing experimental design, and improving prediction accuracy, and are regarded as a bellwether for the nation's push to deeply integrate AI with scientific research. However, beneath the glow of technology, an easily overlooked issue is gradually coming to the surface: when AI becomes deeply involved in research activities, the resulting data usage, algorithmic decision-making, and attribution of outcomes are triggering a series of entirely new legal risks. As a lawyer who has long focused on the intersection of technology and law, I believe it is necessary to sort out these potential legal red lines for research institutions and enterprises from a professional perspective.
I. Compliance Boundaries for the Collection and Use of Research Data
The primary prerequisite for AI-empowered scientific research is the feeding of massive amounts of data. Whether it is training deep learning models or validating algorithmic hypotheses, it is inseparable from the collection, cleaning, annotation, and sharing of data. At this stage, legal risks are mainly concentrated on the legality of data sources and the compliance of the scope of use.
In accordance with the provisions of the Data Security Law of the People's Republic of China and the Personal Information Protection Law of the People's Republic of China, if research data involves personal information, the principle of minimum necessity must be adhered to, and explicit consent from the data subject must be obtained. In particular, AI research in the medical and health field often involves sensitive personal information, and processing such information requires a specific legal basis and the implementation of stricter protective measures. In practice, many research teams, in pursuit of model accuracy, excessively collect data or fail to carefully review the authorization agreements when using public datasets, which can easily lead to lawsuits for infringement of personal information rights.
In addition, the issue of cross-border data transfer in international research collaboration is becoming increasingly prominent. Under the Measures for Security Assessment of Data Export, certain categories of data must undergo security assessment or obtain relevant certification before being provided overseas. If research institutions fail to comply with these procedures, they may face fines of up to 50 million yuan or 5% of the previous year's turnover, and may even have their related operations suspended. Lawyers recommend that research projects conduct data compliance assessments at the outset, establish a tiered and categorized data management system, and ensure that every data operation step has a clear legal basis.
II. Allocation of Legal Responsibility for AI Algorithmic Decision-Making
In the process of AI-assisted scientific research, algorithms often take on functions such as analysis, prediction, and even decision support. For example, in drug development, AI may screen out candidate compounds; in materials science, AI may predict the properties of new materials. But when algorithms make errors, leading to biased research conclusions or even safety incidents, who should bear the responsibility?
Article 1165 of China's Civil Code stipulates that an actor who infringes upon the civil rights and interests of another person through fault and causes damage shall bear tort liability. However, AI systems are not "persons" in the legal sense, and their decision-making processes are highly technically complex and opaque, making fault determination exceptionally difficult. In judicial practice, courts typically apply the principles of presumed fault or reversed burden of proof, requiring algorithm users to demonstrate that they have fulfilled reasonable duty of care. This means that research institutions must retain complete records of algorithm design, data training, parameter adjustments, and other processes, so that they can prove their innocence when disputes arise.
Meanwhile, regulations such as the Provisions on the Administration of Algorithmic Recommendations in Internet Information Services require algorithm providers to ensure interpretability and auditability. Although these provisions primarily target commercial recommendation scenarios, their underlying principles are equally applicable to the scientific research field. Lawyers caution that when research teams adopt AI-assisted decision-making, they should establish human review mechanisms, particularly in high-risk areas involving human health and environmental safety, and must never fully rely on "black-box" algorithms. Otherwise, in the event of harm, they may face not only civil compensation but also administrative penalties for violating administrative regulations.
III. The Challenge of Intellectual Property Ownership for AI Research Outcomes
Intellectual property ownership of research outcomes produced with AI involvement—whether papers, patents, or trade secrets—is another highly contentious area. Traditional intellectual property law centers on the "human creator," but the intervention of AI has disrupted this framework.
Taking patents as an example, China's Patent Law explicitly stipulates that a patent applicant must be the "inventor" or "designer," and the inventor should be "a person who has made creative contributions to the substantive features of the invention-creation." Currently, judicial and administrative practices generally do not recognize AI as having the legal capacity to be an inventor. In the revised version of the Patent Examination Guidelines issued by the China National Intellectual Property Administration in 2023, it is further clarified that artificial intelligence systems shall not be listed as inventors in patent applications. This means that if an invention is primarily generated by AI, with humans only performing data input or result confirmation, the invention may fail to obtain patent authorization due to the lack of a qualified inventor.
In practice, in several typical cases of AI-assisted scientific research, the attribution of outcomes is often resolved through contractual agreements. However, in research collaborations, parties often hold differing standards for assessing the extent of AI's contribution, which can easily lead to disputes. Lawyers recommend that research institutions and enterprises sign detailed intellectual property agreements with collaborators before project initiation, clearly defining the ownership of AI-generated outcomes, usage licenses, and revenue distribution methods. Additionally, for AI-generated technical data, if it meets the requirements for trade secrets, confidentiality measures should be implemented promptly to prevent the loss of legal protection due to public disclosure.
IV. Implications for Compliance Building in Research Institutions and Enterprises
In facing the legal challenges brought by AI research applications, research institutions and enterprises should not passively wait for regulation but should proactively build compliance systems. First, it is recommended to establish a compliance team composed of personnel from legal, technical, data management, and other relevant fields to conduct full-lifecycle legal risk assessments for research projects. Second, internal rules and regulations should be developed to standardize operational procedures in key areas such as data collection, algorithm use, and results management, with regular legal training to enhance researchers' compliance awareness.
From a broader perspective, the state is progressively refining the legal framework for AI governance. The Artificial Intelligence Law has been included in the legislative agenda, and future regulation of AI applications will become more systematic and nuanced. Against this backdrop, research institutions that take the lead in establishing compliance systems will not only effectively mitigate legal risks but also gain a competitive edge in the fierce technological race.
Guangdong Zhiming Law Firm has long been dedicated to practical research in the field of technology law, providing professional legal services such as data compliance, intellectual property strategy, and technical contract review to numerous research institutions and high-tech enterprises. If you encounter specific legal issues in the application of AI in scientific research, please feel free to contact us. We will leverage our professional expertise to help resolve your concerns.