Skip to content
Przejdź do tekstu

Głuchym Kierowany Nadzór nad AI

Luka w zgodzie: nieujawnione gromadzenie danych w systemach tłumaczenia AI języka migowego

Grafika promocyjna Novara Consulting Group zatytułowana „Głuchym Kierowany Nadzór nad AI”. Scena przedstawia laptop na skale w zalesionym górskim krajobrazie o wschodzie słońca, z holograficznym interfejsem pokazującym osobę posługującą się językiem migowym pośrodku. Otaczające ikony odnoszą się do danych, przywództwa, systemów i dostępności. Tekst podkreśla przywództwo osób Deaf w podejmowaniu decyzji dotyczących AI, nadzór, który zmniejsza ryzyko, oraz systemy, które są sprawiedliwe, dokładne, odpowiedzialne i zgodne kulturowo. Dodatkowe hasła obejmują „Dostępność projektowana od podstaw, nie jako coś dodanego później” oraz „Kontrola tworzy zmianę”.
Pobierz PDF
Audio Insights

Streszczenie

Sign language artificial intelligence, whether built for recognition, translation, or avatar-based generation, depends structurally on video or biometric capture of Deaf and hard of hearing users. This dependency creates a data governance problem that has received far less institutional scrutiny than the linguistic and comprehension failures documented in prior issues of this series. Across the vendor landscape NCG has reviewed under the SLAT (Sign Language Access Trust) framework, disclosure of what is collected, how long it is retained, whether it is used to train future models, and whether it is shared with third parties is inconsistent at best and absent at worst. This is not a claim that any specific vendor has acted in bad faith. Public evidence does not yet support attribution of intent to any named company, and this issue does not make that attribution. It is a claim that the market has not yet developed a disclosure standard adequate to the sensitivity of the data involved, and that this gap is a governance failure independent of any individual vendor’s conduct. The policy position below argues that consent and disclosure adequacy should be treated as a gating criterion in procurement, not a secondary consideration addressed after functional evaluation.

Problem polityki

Sign language capture is biometric capture. Video of a signer’s hands, facial grammar, and body position is not incidental input, comparable to a typed sentence submitted to a text-based system. It is uniquely identifying, it encodes information about disability status by definition, and in many jurisdictions it meets the statutory definition of biometric or special category data subject to heightened protection. Illinois’s Biometric Information Privacy Act (BIPA), for instance, requires written notice and consent before collection of biometric identifiers, and imposes liability independent of proof of actual harm. The European Union’s GDPR (General Data Protection Regulation) classifies data revealing disability-adjacent information, and certain biometric data used for identification, as special category data under Article 9, requiring an explicit legal basis beyond ordinary consent. California’s CCPA (California Consumer Privacy Act) and CPRA (California Privacy Rights Act) impose their own disclosure and opt-out obligations for biometric information.

Despite this regulatory landscape, consumer-facing sign language AI products frequently rely on general-purpose terms of service that were not drafted with Deaf users or biometric capture in mind. Three recurring deficiencies are visible across the vendor snapshots NCG has conducted: first, no separate or conspicuous disclosure that video input constitutes biometric data subject to specific statutory protections; second, no clear statement of whether captured video or derived features are retained for model training, and if so, for how long and under what deletion rights; third, no accessible-format disclosure, meaning the consent language itself is often not translated into ASL or presented in a format usable by the population whose data is being collected. This last point is not a technicality. A disclosure regime that requires literacy in a written second language to understand what is being done with one’s own biometric data is not functioning as informed consent for a population for whom English literacy varies widely and for whom ASL is the primary language of comprehension.

Rejestracja języka migowego jest rejestracją biometryczną.

Analiza instytucjonalna

Dynamika instytucjonalna, która wytwarza tę lukę, ma charakter strukturalny, a nie spiskowy. AI języka migowego to młoda kategoria produktów, a większość dostawców to małe firmy działające na tych samych ogólnych szablonach polityki prywatności stosowanych w całej branży oprogramowania, dostosowywanych minimalnie, jeśli w ogóle. Tymczasem procesy zamówień na poziomie instytucjonalnym historycznie oceniały te produkty na podstawie kryteriów funkcjonalnych: czy awatar renderuje się w sposób zrozumiały, czy system rozpoznawania osiąga akceptowalną dokładność, czy dostawca zatrudnia osoby Deaf zaangażowane w rozwój produktu. Zarządzanie danymi traktowane było jako kwestia zgodności prawnej lub IT, rozpatrywana po podjęciu merytorycznej decyzji zakupowej, jeśli w ogóle była rozpatrywana. Ta kolejność stanowi rzeczywiste niedociągnięcie w zarządzaniu. Zanim niedociągnięcie w zarządzaniu danymi wyjdzie na jaw — poprzez naruszenie danych, dochodzenie regulacyjne lub publiczną krytykę ze strony społeczności Deaf, której dane były wykorzystywane — relacja instytucjonalna i zobowiązanie finansowe są już ustanowione, a możliwość wymuszenia naprawy jest odpowiednio słabsza.

There is also a training data provenance question that sits adjacent to the consent problem but is analytically distinct from it. Several sign language AI systems have been built in part on video corpora drawn from publicly posted content, including content created by Deaf ASL users and educators on social platforms. Whether that use falls within the scope of the platform’s own terms of service, whether it constitutes fair use under copyright law, and whether the individuals whose signing appears in that footage were meaningfully informed that their content would be used to train a commercial AI system, are open questions that NCG has not independently verified for any specific vendor and does not assert as established fact here. The point for governance purposes is that procurement officers evaluating these systems have almost no visibility into training data provenance, and current disclosure norms in the industry do not require vendors to provide it.

Implikacje dla zarządzania

An institution procuring sign language AI is not merely a purchaser of a translation tool. Where the system operates on live video of students, patients, employees, or members of the public, the institution is also a data controller or processor under most applicable privacy frameworks, and it inherits governance exposure from its vendor’s data practices whether or not that exposure was disclosed at the time of purchase. An institution that has not verified a vendor’s data collection, retention, and training-use practices before deployment cannot represent to its own stakeholders, regulators, or the Deaf individuals whose data is being captured, that it has met its own data protection obligations. This is true regardless of the vendor’s actual conduct, because the absence of verified disclosure is itself the governance defect, independent of whether any given vendor turns out to be handling data responsibly.

Stanowisko polityczne NCG

NCG’s position is that data governance and privacy disclosure adequacy should function as a gating criterion in sign language AI procurement, evaluated before functional performance rather than after it. A vendor’s inability to produce clear, ASL-accessible, jurisdiction-appropriate disclosure of what biometric data is collected, how long it is retained, whether and how it is used in model training, and what deletion rights exist, should be treated as disqualifying for institutional deployment regardless of linguistic or technical performance elsewhere in the evaluation. This position is already operationalized in the SLAT framework’s Data Governance and Privacy and Transparency and Disclosure domains, and this issue argues that those domains warrant elevated weighting relative to the framework’s current calibration, given the statutory exposure institutions face and the comprehension barrier that non-accessible consent language creates for the affected population.

Kwestie wdrożeniowe

Procurement officers evaluating sign language AI should require, as a condition of vendor response, a written data governance disclosure covering the four elements above, request that this disclosure be available in ASL video format in addition to written English, and treat vendor refusal or inability to produce this disclosure as an adverse finding independent of the system’s functional performance. Institutions with existing deployments should conduct a retrospective review rather than waiting for contract renewal, given that governance exposure accrues from the date of deployment rather than the date of discovery. Where a vendor’s training data provenance cannot be verified, institutions should request contractual warranties regarding lawful data sourcing rather than treating the absence of an answer as a neutral unknown.

Bibliografia

  • Biometric Information Privacy Act, 740 ILCS 14 (Illinois).
  • California Consumer Privacy Act z 2018 r., ze zmianami wprowadzonymi przez California Privacy Rights Act, Cal. Civ. Code § 1798.100 i nast.
  • Rozporządzenie (UE) 2016/679 (Ogólne rozporządzenie o ochronie danych), art. 9.
  • Federal Trade Commission Act, 15 U.S.C. § 45 (nieuczciwe lub wprowadzające w błąd praktyki).
  • Novara Consulting Group, Struktura Sign Language Access Trust (SLAT), 2026.

Subskrybuj Novara Consulting Group

Nowe wpisy dostarczane prosto do Twojej skrzynki odbiorczej.

Consult