Common European Data Spaces (CEDS) are intended to support governed data sharing and reuse across strategic sectors. Public administrations supply data to these spaces and seek to reuse it in AI projects. Access alone, however, does not establish whether a downstream use is authorised, ethically justified, or supported by adequate evidence. This thesis investigates how EU data and AI regulation can be translated into organisational and metadata-based tools that support public administrations without displacing competent human and institutional judgment. The research combines comparative legal and policy analysis; formative development of the AI Ethics Canvas through action research, value-sensitive design, twelve interviews, and a workshop with eighteen participants; and a conceptual examination of selected legal sources and technical standards. It finds that regulatory ambition and formal rights yield meaningful agency only when backed by material, technical, and administrative capacity. CEDS can strengthen governed access and exchange, but address only part of those dependencies. Within public administrations, the Canvas provides a shared setting in which technical and non-technical participants can formulate and revisit ethical, legal, social, and governance questions, identify evidence needs, and expose unresolved responsibilities. Data stewardship maintains continuity among governed data, metadata, evidence, decisions, versions, and review states, while competent actors retain authority. The informational contribution is a five-stage, source-linked framework that moves from a legal source to a reviewed legal concept or requirement, a metadata need, an exact standard element, and a bounded representational outcome. Two bounded micro-applications show how exact provenance elements can support a collection-methodology relation and why descriptive sufficiency remains a question for competent judgment. Together, these contributions define human-centred compliance as the maintained connection among institutional capacity, structured deliberation, data stewardship, technical traceability, and reassessment. They support reviewable decisions without equating metadata, workshop completion, or automated checks with compliance.
Human-Centred AI Compliance in Common European Data Spaces / Bizzaro, P.G.. - (2026 Oct 13), pp. 1-167.
Human-Centred AI Compliance in Common European Data Spaces
Bizzaro, Pietro Giovanni
2026-10-13
Abstract
Common European Data Spaces (CEDS) are intended to support governed data sharing and reuse across strategic sectors. Public administrations supply data to these spaces and seek to reuse it in AI projects. Access alone, however, does not establish whether a downstream use is authorised, ethically justified, or supported by adequate evidence. This thesis investigates how EU data and AI regulation can be translated into organisational and metadata-based tools that support public administrations without displacing competent human and institutional judgment. The research combines comparative legal and policy analysis; formative development of the AI Ethics Canvas through action research, value-sensitive design, twelve interviews, and a workshop with eighteen participants; and a conceptual examination of selected legal sources and technical standards. It finds that regulatory ambition and formal rights yield meaningful agency only when backed by material, technical, and administrative capacity. CEDS can strengthen governed access and exchange, but address only part of those dependencies. Within public administrations, the Canvas provides a shared setting in which technical and non-technical participants can formulate and revisit ethical, legal, social, and governance questions, identify evidence needs, and expose unresolved responsibilities. Data stewardship maintains continuity among governed data, metadata, evidence, decisions, versions, and review states, while competent actors retain authority. The informational contribution is a five-stage, source-linked framework that moves from a legal source to a reviewed legal concept or requirement, a metadata need, an exact standard element, and a bounded representational outcome. Two bounded micro-applications show how exact provenance elements can support a collection-methodology relation and why descriptive sufficiency remains a question for competent judgment. Together, these contributions define human-centred compliance as the maintained connection among institutional capacity, structured deliberation, data stewardship, technical traceability, and reassessment. They support reviewable decisions without equating metadata, workshop completion, or automated checks with compliance.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione



