Service

News

White paper

Blog

About

Company

Ja

Contact

Blog

5/27/2025

Are You Ready for AI Audits? PETs as Proof of Accountability

AI regulation is evolving quickly, and with it the expectations around transparency, explainability, and control. Whether you're preparing for internal governance reviews or anticipating regulatory audits, privacy-enhancing technologies, or PETs, are emerging as a powerful way to demonstrate accountability in AI systems.

Recently, the Meta-owned WhatsApp introduced a new set of AI-powered features that use on-device processing and Private Automated Labeling Architecture, a blend of federated learning, secure hardware, and differential privacy to keep personal messages confidential even when using AI tools. Around the same time, Apple launched its Private Cloud Compute infrastructure, leveraging secure enclaves to ensure that generative AI queries remain encrypted, inaccessible even to Apple’s own systems.

But with new technologies come new responsibilities: how do PETs tie into regulatory frameworks like the GDPR, Singapore's PDPC guidelines, or OECD AI Principles?

Let's break it down. This blog largely cites from the Centre for Information Policy Leadership's report on privacy-enhancing and privacy-preserving technologies in AI. You can read the report here.


PETs and the Principle of Accountability

Accountability in AI isn't just about keeping records or policies on file. It means embedding responsibility into systems, processes, and outcomes and requires organizations to proactively demonstrate that they've considered privacy, fairness, and security at every stage of their AI lifecycle.

PETs help make this possible. They act as built-in safeguards that support a more trustworthy and auditable AI pipeline. Here's how:


Minimize the Use of Personal Data While Still Extracting Value

PETs like synthetic data and differential privacy allow teams to train, test, and validate AI models without relying on raw personal data.

For example:

  • According to the CIPL, Google used differentially private synthetic data to train an on-device safety classifier that detects harmful or unsafe outputs from large-language models. This ensures users' original data is protected even from internal teams.

  • Similarly, MOSTLY AI's open-source synthetic data toolkit enables companies to generate high-quality training data from proprietary datasets without exposing sensitive attributes.

These tools allow data scientists to get the utility they need from data without holding onto the real thing.


Enable Safe Data Sharing and Collaboration Across Departments or Borders

PETs make it possible for different entities to collaborate on model development without disclosing confidential or regulated information.

For example:

  • Federated learning was used in a cross-hospital initiative to train a cancer detection model. Each hospital trained the model on local pathology images and shared only encrypted model updates - not the patient data itself. A Trusted Execution Environment (TEE) encrypted those updates during transit, providing end-to-end security.

  • In the financial sector, several life insurance firms used federated learning and synthetic data to collaboratively train a fraud detection model while respecting privacy laws.

This kind of setup is increasingly vital in jurisdictions where data localization or sovereignty rules restrict cross-border data movement.


Provide Technical Evidence of Risk Mitigation and Security Safeguards

When an audit comes - whether regulatory or internal - you need more than intentions. You need proof that risks have been identified and mitigated.

PETs can offer exactly that:

  • Homomorphic encryption allows computations to be performed on encrypted data. In one case, Apple used it to enable private image searches for landmarks in users' photo libraries. The images were never exposed to the server during analysis. Only encrypted summaries were shared.

  • Secure Multi-Party Computation (SMPC) was used in a medical imaging case to protect the privacy of functional brain scan data. Two parties conducted machine learning collaboratively without ever exposing their models or input data to each other.

These are verifiable, auditable controls. They don't just say “we protect data,” they show how that protection is enforced.


These examples aren't just good engineering, they're evidence of compliance readiness. As regulators around the world begin sharpening their focus on AI governance, organizations will increasingly need to demonstrate not only what their systems do, but how they were built to protect privacy and reduce risk. PETs offer a practical way to meet these expectations, aligning closely with both existing data protection laws and emerging AI-specific frameworks.

Let's take a closer look at how PETs map to key regulatory regimes like the GDPR, Singapore's PDPC guidance, and the OECD's principles for trustworthy AI.


GDPR

The GDPR mandates that data controllers implement measures ensuring data protection is “built in” to the processing lifecycle. PETs directly support this by enabling:

  • Data minimization (Article 5) through anonymization and synthetic data.

  • Security of processing (Article 32) via encryption and TEEs.

  • Demonstrable risk-based assessments under DPIA requirements (Article 35).

Although GDPR does not prescribe specific technologies, PETs can serve as proof points during inspections or legal scrutiny.


Singapore PDPC

Singapore's PDPC explicitly supports the use of PETs to enable responsible AI development:

  • The Model AI Governance Framework encourages organizations to embed accountability, transparency, and explainability into AI workflows. PETs like federated learning and differential privacy can fulfill these principles without excessive disclosure or trade-offs.

  • The 2024 Proposed Guide on Synthetic Data Generation (from PDPC and A*STAR) outlines best practices for generating high-quality synthetic data, including guidance on risk, utility, and validation.

Singapore also operates a regulatory sandbox for PETs and generative AI, allowing organizations to safely pilot new data uses with government oversight.


OECD AI Principles

The OECD's global framework promotes five principles, with PETs supporting at least three directly:

  • Transparency and Explainability: PETs like TEEs and SMPC provide cryptographic assurance without revealing sensitive data.

  • Robustness and Security: PETs increase system integrity through privacy-by-default configurations.

  • Accountability: Documenting the use of PETs can show proactive data governance.

These principles also underpin the G7 Hiroshima AI Process and influence the EU AI Act, further amplifying their global relevance.


PETs in Practice: A Governance Win

Imagine an audit where your organization needs to explain:

  • Why your AI model didn't centralize patient data across borders.

  • How it avoids bias from underrepresented groups.

  • What guarantees you can offer regulators that user data wasn't exposed.

If you've used PETs like federated learning, synthetic data, or differential privacy, you're not just meeting the minimum requirements, you're demonstrating that you've proactively planned for risk. You're showing that user rights were respected without compromising the performance or utility of your AI system. And you're building an AI pipeline that is not only effective, but also documented, explainable, and ready to withstand scrutiny. This shifts the conversation from compliance to confidence, and that's what accountability is all about.


In Conclusion

As AI audits become more common and frameworks mature, PETs are increasingly viewed as evidence of responsibility. Whether you're answering to a regulator, a board, or your customers, these technologies give you something rare in AI governance: proof.

Share

Contact Us

お問い合わせはこちら

Contact

Contact