RSS Amplifier

Silver Jaanus · Aug 17, 2026

20.1 Why We Fear AI More Than Our Own Inaction

0
Sign in to vote or save

Silver Jaanus · Silver Jaanus

At this August’s Opinion Festival in Paide, a panel posed a dramatic question: are we prepared to sacrifice our human rights for the sake of artificial intelligence? On stage were AI educator Gerlyn Tiigemäe, Equal Opportunities Commissioner Christian Veske, and Associate Professor of Constitutional Law Paloma Krõõt Tupay. The moderator opened with the foundational question: do we surrender our personal data to AI unknowingly? The final audience question mirrored the opening, asking from the opposite angle: what rights would you be willing to give up to keep AI in our world? Between those two questions lay ninety minutes of discussion, which began with all three panelists admitting that they routinely share vast amounts of personal data—including sensitive health records—and that they do so quite deliberately.

Anxiety over personal data generally falls into three categories, and for each, there exists a concrete technical answer that was never heard from the stage. First: do my conversations feed model training? For major proprietary providers, there is a simple toggle to disable data collection. Nor does an individual’s chat history remain retrievable in any traditional sense unless phrases recur en masse across the entire corpus; it becomes a minute statistical adjustment to the model’s weights, not an indexed entry in a vast eavesdropping database. Second: data sent via commercial APIs is not used for training at all. Third: with locally hosted models, not a single byte ever leaves the machine. The public’s concern is not unfounded, but it is aimed at problems for which solutions already exist. It is the same discipline we apply to web browsing: use private search engines and discreet browsers for sensitive matters. Cloud models can draft your code; a local model can process your bank statements.

Tiigemäe cited the cautionary tale of mobile apps that prompt users to upload bank statements in exchange for spend analytics. An obscure developer, no privacy policy, and zero company details on the website. The panel’s advice was predictable: “Well, you really shouldn’t do that, right?” Sensible enough. Yet the user who genuinely wanted to understand their monthly finances walks away none the wiser.

In reality, users face three distinct options. First: an anonymous app from an unknown developer with no terms of service indeed warrants distrust. Second: a reputable product from an established team with a transparent business model, where individuals can make an informed risk calculation. Third: an open-weights model running locally on one’s own hardware. This allows comprehensive financial analysis without a single line of data leaving the hard drive—free of cost and free of external surveillance.

Open-weights models were never once mentioned on stage. Neither Mistral, Llama, DeepSeek, nor Estonia’s own TartuNLP received a passing nod. Instead, the panel lamented that all major models reside in the United States and that Europe has nothing of its own. Yet Mistral is a French enterprise, and several of its leading models are freely downloadable under open licenses. One crucial distinction worth keeping in mind: most open models are open-weights rather than fully open-source—meaning the weights are downloadable, but the underlying training datasets and source pipelines remain proprietary. Furthermore, accessing an open model via a third-party API still relies on external servers. Absolute privacy is only guaranteed when the entire stack is under your own direct control.

The Commissioner’s Office highlighted a case where an automated credit scorer consistently penalized younger men—classic algorithmic discrimination based on immutable characteristics. Banks have relied on traditional machine-learning classifiers for decades, requiring customers to surrender supplementary records just to prove they do not belong to an elevated risk category. But large language models afford an investigative capability that legacy credit algorithms never offered: you can run the exact same case a thousand times with only the gender swapped, objectively quantifying whether and how the outcome diverges.

An audience question addressed the legality of automated administrative decisions. The state’s duty of justification applies whether an order is drafted by an official or generated by software. Citizens are entitled to know when an algorithm made a decision, inspect the data underlying it, and exercise a clear right of appeal. As Professor Tupay astutely noted, if the sole remedy offered is the right to sue the state in court, 99 percent of people will never pursue it—deterred by prohibitive costs and systemic intimidation. Genuine legal protection only exists when explainability is baked directly into the decision itself, not locked behind years of costly litigation.

Under the EU AI Act, anyone who integrates an existing model into a product is classified as a deployer or provider. The weekend “vibe-coder” assumes real compliance liabilities, while employers face statutory training obligations. The panelists fretted that small businesses remain largely unaware of these requirements. But whose failure is that? Proactive outreach to regulated entities is easy—especially when targeted registry queries take seconds. Guidance already exists: Consumer Protection and Technical Regulatory Authority (TTJA) manuals, European Commission handbooks, and guidance notes from the Commissioner’s own office. They simply gather dust in institutional silos. Even more revealing was the suggestion that AI could translate convoluted bureaucratic legalese into clear, plain language for ordinary citizens. The Commissioner’s retort was telling: a university-educated civil servant ought to write clearly on their own, making AI superfluous. Once again, an elusive, decades-old pipe dream was preferred over an immediate, functioning tool.

The most illuminating moment of the entire debate was when Commissioner Veske described an AI tool commissioned by his office to scrape job portals for discriminatory phrasing—surfacing over fifty violations a week, compared to the three or four annual checks his seven-person staff used to manage manually. Remarkably, the Commissioner questioned the technology’s financial efficiency, arguing that it simply generated “more work.” The old routine of sporadic spot-checks had kept administrative caseloads comfortably low; exposing how the true scale of non-compliance was treated not as a triumph for equal rights, but as an inconvenient bureaucratic burden. When Tiigemäe proposed an obvious automated workflow—the tool sends an automated notification, the employer rectifies the listing, and the crawler re-checks the following week—Veske dismissed it: “That just creates an endless loop.” But the loop is only endless if one insists that every flagged keyword must escalate into a full formal investigation. A simple advisory suffices: “Your job post contains the phrase ‘young and energetic,’ which may breach equal opportunity statutes; please revise.” The next automated crawl verifies compliance. Human intervention is reserved solely for those who deliberately ignore the notice.

Professor Tupay recounted an initiative exploring data processing to help municipalities identify elderly citizens in need of social care who had not actively sought assistance. The local governments’ response was staggering: you can crunch all the data you want, but we do not have the staff to visit these people. The municipality essentially requested not to be informed about vulnerable residents.

Here lies the state’s glaring double standard. When police or ministries seek cost-effective mass surveillance—whether through Palantir platforms, Clearview facial recognition, or unregulated traffic cameras—the official justification is swift: “The capabilities were available and it was cost-effective.” But when that very same analytical capacity could locate isolated, vulnerable seniors, local authorities push back: “Don’t tell us about them.” For the state, technology is welcome only when it expands administrative oversight, not when it creates a duty of care. An unmeasured shortfall never enters municipal budget negotiations. A clear statement like “our municipality has exactly X isolated seniors needing care” is the only way to justify state funding; without data, nothing changes. For the vulnerable individual, it makes no difference whether they were abandoned due to data paranoia or budgetary neglect—they remain alone.

Stepping back, the fundamental paradox becomes obvious: virtually none of the grievances raised on stage stemmed from the limitations or dangers of artificial intelligence, but from our own institutional refusal to deploy it. The panel concluded with the tired refrain that we need “more awareness and public debate.” But when public debate remains an exercise in collective hand-wringing, it breeds only cynicism. It was surreal to watch experts who deal with these challenges daily and use generative models themselves fail to propose a single actionable solution. They saw only obstacles: a lack of caregivers for the elderly, a shortage of civil servants for compliance audits. Yet not one panelist thought to enlist the central protagonist of the discussion—AI itself—to help solve these exact predicaments.

This encapsulates the defining flaw of Estonia’s AI discourse: we find endless time to worry about artificial intelligence, but none to solve real-world problems with it. We command more computational intelligence and capable tooling than at any point in history. Yet instead of asking how to reach the vulnerable or slash administrative friction, we retreat behind hypothetical perils. As long as our debate remains purely abstract, tangible progress will stall. Meanwhile, the individuals, organizations, and nations that boldly harness this intelligence are already improving their reality today.

Read the original on silverjaanus.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.