
The article critiques the European Union's human-centric approach to regulating artificial intelligence, particularly in the context of the AI Act and the preparatory works of the High-Level Expert Group on Artificial Intelligence. It argues that while the human-centric approach intends to place human values at the core of AI regulation, it reproduces an anachronistic liberal humanist anthropocentrism, grounded in the human/machine dichotomy, that structurally forecloses the regulatory goals the Act itself proclaims. Deploying critical posthumanist methodology as a deconstructive project, the article reveals the conceptual limitations of this framework and proposes an ontocentric posthuman jurisprudence, drawing on Floridi's information ethics and Braidotti's critical posthumanities, as a more adequate regulatory foundation. Crucially, this shift does not require abandoning human values; rather, transcending the human/machine dichotomy is a precondition for protecting them more fully. Such a framework would extend regulatory protection to non-human actors and the environment, while remaining genuinely oriented towards the human, and being more fit for the stated goals of the regulation.
Artificial Intelligence (AI) technology has the potential to replace a visit to the doctor, with AI companies offering health services directly to the public that, until recently, could only be performed by humans. AI apps that claim to detect disease, such as skin cancer, envisage a hopeful future where everyone can access expert medical care on their phone, at a fraction of the cost of traditional healthcare. However, the advent of AI in medical contexts also raises anxiety that AI may not be as reliable as claimed, and that laypersons are ill-equipped to make these decisions by themselves. AI companies have a duty of care to provide their consumers with adequate notice of the risks and limitations of the AI system. But given the complex and technical nature of this information, how can such notice be made salient for consumers? The main argument of this article is that, if AI companies effectively offer a health service traditionally performed by doctors, then they should be guided by the values that govern the doctor-patient relationship regarding the information provided to consumers about the limitations of the AI system. We propose Precision Consent, an interdisciplinary framework that draws connections between the legal and ethical duties of doctors towards their patients, and capabilities in the field of AI. We discuss how values that guide doctors, such as respect for patient autonomy, non-maleficence and personalised warnings, can be incorporated into how notice is provided to consumers regarding the accuracy of AI health services.
This article examines how data-driven humanitarianism in the HIV/AIDS sector reproduces colonial patterns of extraction and inequality in sub-Saharan Africa (SSA). Drawing on case studies of AI-enabled health data systems, it analyses the ethical implications of large-scale data collection, storage, and transfer in contexts marked by poverty, weak regulatory capacity, and persistent stigma. While datafication and artificial intelligence promise efficiency and accountability in HIV response, they also risk coercive consent, exploitation, and surveillance. The article argues that these practices constitute a form of data colonialism, in which the informational resources of SSA are extracted for the benefit of actors in the Global North. It proposes that equitable data governance in health humanitarianism requires transparent agreements, enforceable benefit-sharing, and community accountability rooted in Ubuntu-based bioethics. The goal is not less data, but fairer data - secure, participatory, and oriented toward justice and sustainable health outcomes.
This is a piece of speculative legal research. A short narrative is provided, one that is set in the future, and the law embedded within the tale is subject to critique. The story is of an AI that is engaging with the soul of a dead man in deep space. The analysis focuses on how the law, both in the future and in 2026, conceives of the mind and its decision-making. The legal frameworks to be considered are those of agency and consent (as understood in health law). The latter, in particular, has an emphasis on mental capacity. The combination of the narrative and the exegesis, offers the opportunity for an exploration of the ordering of minds and decisions in the law in the present day.
The introduction of the Digital Services Act (DSA) by the European Union marks a fundamental step forward in the governance of social media platforms, by outlining content-moderation guidelines aimed at preventing disinformation and the systemic risks related to the business of polarisation. Taking a critical approach, this article discusses how the DSA regulatory framework addresses the issue of disinformation and the role of controversial influencers and, on the other side, how the content moderation measures provided by the DSA have recently been implemented by major social media platforms. Our analysis revealed multiple examples of vagueness in the legal text that neither address the role of political influencers (or the concept of influence as a whole), nor explicitly outline the concept of disinformation. Furthermore, a longitudinal analysis (18 months) of the content-moderation measures implemented in compliance with the DSA, and accessible through the DSA Transparency Database, shows that social media platforms tend to privilege temporary measures such as suspension of accounts rather than more effective actions such as deplatforming. In the medium term, however, temporary suspension measures – thanks to a combination of Streisand effect and influence – can produce an increase rather than a decrease in the popularity of the controversial profiles, which are ultimately even more ‘influential’ than before. As a result, the article highlights a double standard policy adopted by platforms: on one side, they moderate controversial profiles by complying with DSA guidelines, while in the long run restoring their social accounts to profit from their renewed popularity, thus reinforcing the business of polarisation typical of surveillance capitalism.
To harness the benefits of artificial intelligence (AI)-enabled healthcare, access to data is a crucial component of AI in digital health technology development and adoption. This requires effective frameworks of digital and data governance. This paper highlights important digital, data, and data-related issues that present unique and pressing challenges to such adoption in sub-Saharan Africa (SSA). Specific non-exclusive challenges in SSA arise from issues around data integrity and quality, interoperability, and data provenance. Related emerging issues centre on surveillance capitalism, data commodification, and coloniality. Certain digital and data governance strategies and solutions in support of the public good are in place and include various legal rights, regulatory policies, and ethics frameworks. Building on these solutions, I advance an innovative and supplementary mechanism of grounding digital and data governance on the theoretical approach of human-centric design and on ideas of embedding ethics and law. As illustrated in India, this ‘third way’ of ‘governance-by-design’ practically embeds and operationalises rules as protocols within the infrastructure and architecture of the technology itself. Accordingly, an inclusive and augmented data and digital governance-by-design solution is offered as an enabler of AI in digital health in SSA.
Etienne Gabriel Valk reviews A Datafied Mind. Untangling EU Regulation of Emotion Technology and Neurotechnology by Elisabeth Steindl
Digital health innovation through open-source software (OSS) is often presented as a critical response to the health system crises that low- and middle-income countries (LMICs) face due to inadequate public health infrastructure. Proponents of OSS argue that it offers a more sustainable, economical, and democratic approach to developing health solutions in underresourced contexts. Drawing on the experiences of software developers in East Africa working on digital health initiatives, this article argues that the potential of OSS to be transformative in LMICs is constrained by different infrastructural problems and its continued reliance on a middle-class elite who rely on technological fixes over health system solutions. This, we argue, is because OSS innovation is entangled in extractive legal regimes, digital ecosystems and persistent knowledge hierarchies. By foregrounding these epistemic and political dynamics, we call for renewed attention to the structural conditions that shape OSS innovation, particularly to the practices of software development in LMICs.
Data-driven health technologies hold the potential to improve healthcare delivery. Yet they also facilitate the large-scale extraction and commodification of sensitive health data through a phenomenon often described as ‘digital health surveillance capitalism.’ This model has largely gone unchecked, as prevailing regulatory approaches prioritise privacy and security while neglecting broader societal harms arising from datafication. These societal harms of commodification are exacerbated by neoliberalism, which has led to the growing influence of technology corporations in healthcare and in shaping regulatory responses. The entanglement of data-driven commodification and neoliberalism has deepened inequalities between countries and regions, particularly in times of crisis. This has renewed calls for a decolonial turn in public health and a more deliberate focus on the Global South. Critical analyses of the intersections between regulation, health and surveillance capitalism, particularly in Global South contexts, are therefore of urgent scholarly importance. Drawing on interdisciplinary socio-legal analysis, this symposium collection focuses on case studies from Latin America, Sub-Saharan Africa, the Community of Portuguese-speaking Countries and Asia, to examine how neoliberal pro-innovation agendas have reinforced asymmetrical power relations and regulatory failures, enabling extractive data practices that undermine health equity. The collection’s focus on the Global South as a site of decolonial possibilities enables us to critically examine how alternative regulatory governance models could be operationalised to advance equitable health outcomes.
The rapid proliferation of mobile health applications (mHealth apps) is transforming healthcare delivery in South Africa, offering AI-enhanced, data-driven tools for remote monitoring, diagnosis, chronic disease management, and personalised interventions. While these technologies are often celebrated for their potential to expand access and improve outcomes, their rapid evolution presents significant regulatory, clinical, and ethical challenges. This article interrogates South Africa’s regulatory framework, with particular attention to the rule under the Medicines and Related Substances Act (MRSA), which classifies a product as a medical device based on the developer’s declared purpose. Although this principle provides conceptual clarity in distinguishing between medical and non-medical devices, it proves increasingly inadequate for wellness and fitness apps whose advanced functionalities extend beyond general wellness into clinically significant domains, yet evade oversight because they are marketed as lifestyle tools. Such functions include predictive diagnostics, symptom checking, continuous monitoring of vital signs (e.g., heart rate, blood pressure, oxygen saturation), treatment recommendations, mental health assessments, and medication reminders. Drawing on the conceptual lens of the pacing problem, which is the misalignment between the speed of technological innovation and the slower adaptation of legal frameworks, the article shows how reliance on declared intent generates oversight gaps that expose users to risks ranging from clinical inaccuracy to data misuse. In response, it proposes a functionality-driven regulatory approach that evaluates mHealth apps based on their real-world capabilities and health implications rather than their declared purposes. Such an approach would enhance regulatory agility, align innovation with safety and ethics, and ensure that mHealth technologies realise their transformative potential without compromising public health protections.
Telemedicine offers a transformative approach to healthcare, enabling remote consultations and expanding access to underserved populations, especially in inaccessible and isolated regions. This article discusses the role of laws and regulations in telemedicine within a rights-based framework, to address the understaffing of medical doctors. Historically, restrictive regulations delayed the liberalisation of telemedicine until the COVID-19 pandemic. Today, however, human rights in the digital health sphere appear to be more focused on safeguards for privacy and autonomy than on mobilising government investments to facilitate access to health. The article first draws attention to the negative bias in the use of human rights in global digital health discourse, by reviewing the pessimistic framing of human rights standards, with telemedicine guidance at the World Health Organisation (WHO) framed as simply a protection against digital harms. By considering the experience of legislative action on telemedicine in Brazil, this article analyses how law can contribute to a positive environment for expanded digital healthcare coverage. It discusses the danger of placing unwarranted concerns over professional guarantees and ethical questions above access to health, despite overwhelming evidence of the benefits of telemedicine. Furthermore, digital health regulations are often seen primarily as protections against market interests – perceived as the main suppliers of digital technologies – with limited attention paid to how human rights standards could and should actively steer publicly-funded policies. This study shows that a rights discourse can also serve to support state-led policies in digital health – positioning technological advances as an ally, rather than mainly a threat, in the pursuit of universal health coverage.
With the growing digitisation of healthcare services, health data infrastructures play a critical role in healthcare and medical research. Health data are relational in nature and can reproduce historical inequities and manifest colonial patterns, where Global North notions and agendas for healthcare and research are replicated. In this light, governance of health data infrastructures needs to be centred within the sociopolitical context of these infrastructures, promoting the data interests of communities, especially vulnerable and marginalised communities. However, current data protection frameworks that prioritise individual privacy rights are inadequate for addressing collective, context-dependent harms arising from data use. To address this governance gap, the article advocates for a shift from privacy-centric governance to a data justice approach, and seeks to layer data justice with a solidarity-based, decolonial approach. The theoretical and practical dimensions of this approach are explored through three key elements: constitutional, procedural and positional. Constitutional elements deal with the foundational principles or logic underlying the governance architecture of the health data infrastructures. Seen through a justice lens, these constitutional elements are geared towards acknowledging, preventing and mitigating inequities in healthcare and health data activities. Further, procedural elements are building blocks with the aim of embedding tangible mechanisms within governance architecture. Lastly, positionality is the connective tissue that weaves together the constitutional and procedural elements. It is understood as the inherently embodied nature of knowledge, knowledge creation and its processes. It brings forth the criticality of the situatedness of knowledge and power structures, and urges us to imagine governance that does not seek to escape perspective, but makes vantage points both explicit and answerable.
The use of data derived from Electronic Health Records and Real-World Data is central to epidemiological research, particularly in population health studies. Administrative data—information collected during routine citizen-government interactions or the delivery of services—are digitally structured, falling under the broader concept of ‘digital health’. Linking health data with social data holds immense potential for investigating social determinants of health. This article aims to elucidate the process of enabling the transformation of linked health and social data to support scientific research and knowledge production on social determinants of health within an epidemiological context, while focusing on relevant ethical, legal and sociotechnical issues (ELSI). The analysis is reflexive, grounded by a case study of a Brazilian initiative, the Centre for Data and Knowledge Integration for Health (CIDACS), which generates population health knowledge supported by large volumes of linked administrative data. Drawing on Science, Technology and Society (STS) Studies and Critical Data Studies, this article attempts to situate the knowledge produced by CIDACS, recognising that its data production, data infrastructure operations and data usage are intertwined and contextually embedded within sociohistorical and disciplinary frameworks. Our study concludes that concrete experiences of data practices reveal nuanced insights, underscoring the role of the Global South in advancing alternative and critical epistemologies.
Digital health infrastructures, such as India’s National Digital Health Ecosystem (NDHE), are touted as the panacea for improving universal healthcare, particularly in the Global South. Central to this infrastructure is the generation and circulation of health data, i.e. digital data relating to any facet of health. This article offers two critical analyses of the NDHE – first, the centrality of the ‘flow’ of health data to enable monetisation of these data flows by commercial actors (and consequently, the commercialisation of health), and second, the ways in which this market-driven imaginary of the NDHE reshapes principles of data governance such as informed consent and impact assessments into negative frictions for health data flows. Finally, this article instead offers suggestions on how to implement these legal principles through friction-in-design regulations, to engineer a necessary ‘drag’ to limit the commodification of health data flows in the NDHE.
Health systems in most countries in Sub-Saharan Africa face challenges relating to inadequate infrastructure, insufficient funding and shortage of skilled healthcare workers. Whereas digital health innovation has been embraced in the region to address these challenges and strengthen health systems, a delicate balance between innovation and regulation for sustainable and equitable use is imperative. However, as Africa continues to digitalise her health systems to improve healthcare, issues pertaining to data governance and privacy concerns have emerged that call for frameworks that can protect the vulnerable without stifling digital innovation in healthcare. In this article, we explore how challenges related to poor data quality and data governance in digital health innovations can be addressed through regulatory sandboxes. We draw lessons and experiences from the financial sector and how they can potentially be used in designing digital health regulatory sandboxes. Through a comparative critical analysis of the journey taken in fintech sandboxing, we highlight the challenges faced and success factors in the fintech sector that can be mirrored during the implementation of digital health sandboxes. We complement these sources with qualitative interviews and insights from engaging with different stakeholders in the Fintech and digital health sectors. Our critical analysis builds on Felix Kumah-Abiwu’s extension of the Afrocentric paradigm and analyses how an Afrocentric triple helix model can enable the co-creation of regulation in digital health. We thus provide a unique empirical analysis around the opportunities, limitations and concerns of fintech regulatory sandboxes that could be used for the implementation of digital health sandboxes across Sub-Saharan Africa.
Cultural legal investigations of the nexus between law, culture and society are crucial for developing our understanding of how the relationships between humans and artificially intelligent entities (AIE) will evolve along with the technology itself. However, narratives of artificial intelligence (AI) have been much debated as a source of investigation for the functioning of human–AI relationships within law and society, with some scholars arguing that these texts are essential and others maintaining that AI narratives are illusory as to the practical operation of AI. This article resolves the discrepancies between these seemingly opposing viewpoints. A cultural legal reading of the updated anime series Digimon Adventure (2020) enables a reconciliation of the use of AI narratives as a method of scholarly interpellation of human–AI interactions. Utilising the theory of legal personhood, this reading proposes that AIE form legal and social relations not as a legal person or as a tool, but rather as a monster on a spectrum in between. Reading the contexts of legal personhood through the text of Digimon Adventure allows for a more nuanced understanding of these relationships and interactions as AI evolves.
The use of algorithmic systems to identify suspected welfare fraud in the Netherlands, India, Australia, and the UK has led to mounting concerns that governments are taking a ‘hurt first, fix later’ approach to the adoption of algorithmic systems that will impact many of the poorest and most vulnerable members of society. The question this article addresses is one of effective regulation. While various strategies have been explored to tackle challenges arising from the adoption of algorithmic systems in welfare fraud investigations in recent years, this article follows the approach adopted by the applicants in the Robodebt class action in Australia in proposing the tort of negligence as a source of common law regulation in the era of algorithmic systems. First, it explains why a duty of care offers a principled and practical answer to the challenges posed by the misuse of algorithmic tools in welfare systems. Second, it argues that, drawing on the reasoning in two well-known English cases of the 1970s, Home Office v Dorset Yacht Co Ltd and Dutton v Bognor Regis, the common law of negligence can provide a strong foundation for recognising such a duty. Finally, it considers two significant challenges to the proposal and argues that, despite these challenges, the tort of negligence offers a valuable opportunity to enhance fairness, legitimacy, and equity in both system design and regulatory practice, while also mitigating litigation risks.
At some point in the technological development of artificial intelligence (AI), a human–AI construct will reach the point at which it could be recognised as an inventor for the purposes of patent law. Yet this task of ordering, of establishing precise relationships between entities on a spectrum, overlooks the more radical challenge that human–AI constructs pose to both intellectual property and law more generally. Would the human–AI construct attain the status of inventor through its capacity (inventiveness) or through its humanity? Does the answer to this question shift how we order the human–AI construct in the context of patent law? Seeking to partially dissolve (rather than resolve) the question of appropriate ordering, this article suggests that AI has the potential to fundamentally obliterate the order itself by exposing how law relies on the temptation of an imagined – and distinctly human – sovereignty. It demonstrates this by analysing human–AI constructs in intellectual property through the concept of phantasm drawn from the work of Derrida and Butler. While the article focuses specifically on an intellectual property setting, and the concept of ‘inventor’ in particular, the conclusions are likely to apply to law more generally.
This article explores the socio-legal implications of fear in response to blockchain through a case study of Nepal. Blockchain and cryptocurrency evoke the cultural imaginary of global societies and elicit both a wonderous utopian response and a fearful dystopian reaction; both have implications for how regulators create rules and structures to limit the development and use of this emerging and disruptive technology. This article looks to Nepal as an often-overlooked case study for cryptocurrency bans, insofar as the regulatory response has been to halt and criminalise the possession and handling of cryptocurrency by Nepalese, both domestically and abroad. This is more than merely fear, and an exploration of this allows for a deeper understanding and rethinking of the promises made by the technology as a tool for good through mechanisms such as remittances, the potential for blockchain entrepreneurism and the practicality of a Central Bank Digital Currency (CBDC).
The Protection of Personal Information Act 4 of 2013 (POPIA) establishes crucial safeguards against the risks posed by automated decision-making (ADM), particularly under section 71. This section restricts ADM that produces significant legal or personal effects unless specific exceptions apply. However, POPIA does not explicitly grant a right to an explanation, leaving uncertainties around how data subjects can meaningfully contest or understand ADM decisions. Using a doctrinal and comparative methodology, this article examines the legal implications of the provisions of section 71, focusing on its interpretation as either a prohibition against ADM or merely a right to object. The findings highlight the practical and theoretical challenges of defining ‘solely automated’ processes, revealing potential loopholes where nominal human oversight may undermine protections. Comparisons are drawn with international frameworks, such as the European Union’s General Data Protection Regulation (GDPR), to explore how a right to explanation might enhance transparency, accountability, and data subject rights under POPIA. The article further investigates the adequacy of POPIA’s ‘appropriate measures’ requirement, including the necessity of notification rights and clear standards for providing meaningful explanations. By distinguishing between ex-ante and ex-post explanations and between system functionality versus specific decision rationales, it identifies gaps in POPIA’s framework and proposes legal reforms. The article concludes that POPIA requires reform to strengthen algorithmic accountability and data subject protection. It recommends introducing an explicit right to explanation, clarifying the scope of ADM prohibitions, and implementing independent auditing mechanisms to strike a balance between innovation and accountability.