PO.RSP01.01 · 监管科学与政策
AI 时代的基因组关系隐私:一项范围综述
Genomic Relational Privacy in AI Era: a scoping review
作者与单位 Authors & Affiliations
摘要 Abstract
中文摘要
目的:隐私的概念不断演变,通常被定义为个人“独处而不受干扰的权利”。已有研究表明,面对基因组数据蓬勃发展所带来的挑战与机遇,这一定义从根本上是不充分的;在基因组领域,一个人关于是否同意共享基因组信息的决定,会直接影响其生物学和社会关系人的隐私。本范围综述梳理了隐私理论的演变,并系统性地审视了基因组学与人工智能(AI)交叉领域中的法律、伦理和技术冲突以及治理模式。方法:本范围综述于 2025 年依据乔安娜·布里格斯研究所(Joanna Briggs Institute,JBI)方法学开展。在三个主要数据库(截至 2025 年 8 月)——Westlaw、PubMed 和 Web of Science——中进行了系统检索,涵盖基础性隐私学术研究、现代关系性与批判性数据理论、美国判例法、联邦法规(HIPAA、GINA)、国际法规(GDPR),以及关于 AI 和隐私保护机器学习(PPML)的技术论文。结果:从最初检索到的 1412 条记录中,经过 3 个阶段的筛选后,我们纳入了 56 项研究。该综述发现,个人主义的法律框架(基于个人同意)与基因组数据相互依存的本质之间存在一种根本且日益加剧的冲突。主要发现为:(1)隐私理论中的“关系性转向”通过聚焦于情境、权力失衡和相互依存,而非仅关注个人控制,提供了更准确的分析视角。(2)现实世界中不断升级的冲突——体现在执法部门使用家族 DNA 检索、直接面向消费者(DTC)的数据泄露,以及临床“警告义务”困境——表明当前法律模式的失败。(3)AI 充当强大的风险放大器,利用其推断能力推导家族关系并延续偏见,这背后受到监视资本主义经济激励的驱动。(4)一系列 PPML 工具(如联邦学习、差分隐私)提供了技术层面的缓解,但这些工具不能替代稳健的伦理治理,且存在被挪用的风险。结论:为基因组数据建立现代化的治理框架是一项关键而紧迫的需求。该框架应在个人权利的基础上进行扩展而非取代,同时应能够治理复杂而相互竞争的利益。我们认为,持久的解决方案需要一种基于关系性隐私、情境完整性,并对管理我们集体基因组数据的强大实体施加具有法律强制力的信托义务的多管齐下的方法。
查看英文原文 English abstract
Objective: The concept of privacy is ever evolving and commonly defined as an individual's "right to be let alone". It has been shown that it is foundationally insufficient to address the challenges and opportunities presented by blooming of genomic data, where one individual's decision regarding genomic information to consent to data sharing can directly impact the privacy of their biological and social relations. This scoping review maps the evolution of privacy theory and systematically examines the legal, ethical, and technological conflicts and governance models at the intersection of genomics and artificial intelligence (AI). Methods: A scoping review was conducted in 2025 following the Joanna Briggs Institute (JBI) methodology. Systematic searches were performed in three major databases (up to August 2025) - Westlaw, PubMed, and Web of Science databases including foundational privacy scholarship, modern relational and critical data theories, U.S. case law, federal statutes (HIPAA, GINA), international regulations (GDPR), and technical papers on AI and Privacy-Preserving Machine Learning (PPML). Results: From 1412 initially retrieved records and after 3 phases of screening, we included 56 studies. The review identified a fundamental and growing conflict between individualistic legal frameworks (based on personal consent) and the interdependent nature of genomic data. Key findings are: (1) The "relational turn" in privacy theory provides a more accurate analytical lens by focusing on context, power imbalances, and interdependence rather than solely on individual control. (2) Escalating real-world conflicts-evident in law enforcement's use of familial DNA searching, DTC data breaches, and clinical "duty to warn" dilemmas-demonstrate the failure of current legal models. (3) AI acts as a powerful risk-amplifier, using its inferential power to deduce familial relationships and perpetuate bias, driven by the economic incentives of surveillance capitalism. (4) A suite of PPML tools (e.g., federated learning, differential privacy) offers technical mitigation, but these are not substitutes for robust ethical governance and risk being co-opted. Conclusion: A modernized governance framework for genomic data is a critical and urgent need. This framework shall expand upon, not replace, individual rights, while it should be capable of governing complex, competing interests. We conclude that a durable solution requires a multi-pronged approach based on relational privacy, contextual integrity, and the imposition of legally enforceable fiduciary duties on the powerful entities that steward our collective genomic data.
利益披露 Disclosure
Y. Huang, None.