This research, starting from the dynamism that has always characterised private law, focuses on the evolution of profiling to the point of “personalisation”, especially from the perspective of vulnerable individuals, taking as its paradigm the study of Generative Artificial Intelligence, and in particular the socalled “Large Language Models”. Actually, the post-digital era is a direct consequence of the Fourth Industrial Revolution, a category that can be traced back to the study of complexity and complex systems. Indeed, in recent years, humanity has been faced with phenomena of completely unexpected scope and global dimensions: major climate change, health challenges of pandemic proportions, major demographic changes at different latitudes and speeds, the crisis of many social structures, the advent and implementation of increasingly sophisticated technological systems and the almost widespread use of artificial intelligence. Many of the above- mentioned changes have had significant repercussions in the legal sphere. In this sense, it can considered the power imbalances in a world that has become multipolar; the uncertainties in the structure and dynamics of institutions, which are sometimes outdated and now find themselves operating in a completely different context from that in which they were originally established; the unethical use of communication and information media, as well as artificial intelligence, which is a harbinger of cyber risks, misuse of data, privacy violations and highly discriminatory dynamics. In this regard, it is also worth considering how the technological era is characterised by constant evolution: from the network as a mere tool, in a static sense, we have arrived at the integration of digital technology into objects and the replacement of human prerogatives and tasks, creating unprecedented possibilities for interaction between humans and between humans and machines. In this changed context, the law is called upon to regulate information technology and the digital world by establishing shared rules, principles and values, regulating behaviour, defining responsibilities and resolving conflicts. In performing this function, the law is exposed to changes arising from the characteristics and evolution of the aforementioned context. In fact, the object of regulation, now consisting of so-called intangible assets, is changing, as is the context of legislative intervention, since humans are called upon to intervene through legal rules on the digital and robotic reality in order to guarantee the protection of rights. The temporal dimension is also changing: if technological evolution proceeds at an extremely rapid pace, the law is structurally characterised by different timeframes. Another significant change concerns the spatial dimension: with a few exceptions, the digital space is a decentralised and non-territorial public space over which no one can claim exclusive power, which means that the applicable law also needs to be rethought. Several tech giants have long since conquered the global dimension, dictating rules that apply to individuals. Among other things, the tech revolution has had the power to define new power structures, blurring the line between the public and private spheres of particular interests. The role of law, as well as the safeguards put in place in the area of non-discrimination, appear crucial. More specifically, the first chapter begins with an analysis of the international, supranational and national legal frameworks, with particular reference to the phenomenon of profiling. This phenomenon has found its primary reference legislation in the General Data Protection Regulation (EU Regulation No. 2016/679) and, to a lesser extent, in subsequent European legislation, such as the Digital Services Act, the Digital Markets Act, the Data Governance Act, the Data Act, the European Regulation on Digital Identity, and the European Regulation on Artificial Intelligence. In particular, with reference to profiling and automated decisions, the institutions involved are analysed from a private law perspective, highlighting the most relevant vexatae quaestiones. The vagueness and generality of certain expressions contained in the regulatory provisions could have served as an open clause through which all concerns about the potential discriminatory nature of algorithms could be included, aspects that were then partially regulated by subsequent legislation. Several issues of particular interest arise, such as those relating to “nudging”, the creation of “clusters”, and the as yet unregulated phenomenon of personalisation. On the basis of the legislation and case law examined in the first chapter, the second chapter attempts to circumscribe the above-mentioned issues with regard to the dimension of the so-called vulnerable individual. In fact, the entire human condition is becoming increasingly transparent and almost fragile in the face of a compact, opaque, pervasive and elusive power. The vulnerability-based approach lends itself well to the analysis and application of rules relating to phenomena that are still only partially analysed and regulated, concerning, on the one hand, profiling and automated decisions and, on the other, the challenges posed by artificial intelligence. Digital vulnerability is a challenge on several levels and in several respects. Not only in terms of the ways and levels at which it manifests itself, but also in terms of the levels at which legal responses must be developed. In this sense, the European private law perspective has been favoured, crystallising the multiple and valid approaches offered by the vulnerability-based model and also considering its limitations. The reflections of the first two chapters have been brought together in the last chapter, the purpose of which is not only to analyse the European Regulation on Artificial Intelligence (EU Regulation No. 2024/1689) but also to offer solutions and interpretative innovations, taking Generative Artificial Intelligence as a paradigm. Despite liberal analysis and interpretation of the normative provisions, numerous doubts remain about the phenomena of profiling and personalisation, which we attempt to address by focusing on the area of personality rights. In addition,it has been created and introduced, on an interpretative level, the category of “systemic vulnerability

PROFILING, PERSONALISATION, VULNERABILITY: APPLICATION PARADIGMS. RESEARCH HYPOTHESIS THROUGH THE STUDY OF LARGE LANGUAGE MODELS / Ciullo, M.. - (2026 Mar 12).

PROFILING, PERSONALISATION, VULNERABILITY: APPLICATION PARADIGMS. RESEARCH HYPOTHESIS THROUGH THE STUDY OF LARGE LANGUAGE MODELS

ciullo
2026-03-12

Abstract

This research, starting from the dynamism that has always characterised private law, focuses on the evolution of profiling to the point of “personalisation”, especially from the perspective of vulnerable individuals, taking as its paradigm the study of Generative Artificial Intelligence, and in particular the socalled “Large Language Models”. Actually, the post-digital era is a direct consequence of the Fourth Industrial Revolution, a category that can be traced back to the study of complexity and complex systems. Indeed, in recent years, humanity has been faced with phenomena of completely unexpected scope and global dimensions: major climate change, health challenges of pandemic proportions, major demographic changes at different latitudes and speeds, the crisis of many social structures, the advent and implementation of increasingly sophisticated technological systems and the almost widespread use of artificial intelligence. Many of the above- mentioned changes have had significant repercussions in the legal sphere. In this sense, it can considered the power imbalances in a world that has become multipolar; the uncertainties in the structure and dynamics of institutions, which are sometimes outdated and now find themselves operating in a completely different context from that in which they were originally established; the unethical use of communication and information media, as well as artificial intelligence, which is a harbinger of cyber risks, misuse of data, privacy violations and highly discriminatory dynamics. In this regard, it is also worth considering how the technological era is characterised by constant evolution: from the network as a mere tool, in a static sense, we have arrived at the integration of digital technology into objects and the replacement of human prerogatives and tasks, creating unprecedented possibilities for interaction between humans and between humans and machines. In this changed context, the law is called upon to regulate information technology and the digital world by establishing shared rules, principles and values, regulating behaviour, defining responsibilities and resolving conflicts. In performing this function, the law is exposed to changes arising from the characteristics and evolution of the aforementioned context. In fact, the object of regulation, now consisting of so-called intangible assets, is changing, as is the context of legislative intervention, since humans are called upon to intervene through legal rules on the digital and robotic reality in order to guarantee the protection of rights. The temporal dimension is also changing: if technological evolution proceeds at an extremely rapid pace, the law is structurally characterised by different timeframes. Another significant change concerns the spatial dimension: with a few exceptions, the digital space is a decentralised and non-territorial public space over which no one can claim exclusive power, which means that the applicable law also needs to be rethought. Several tech giants have long since conquered the global dimension, dictating rules that apply to individuals. Among other things, the tech revolution has had the power to define new power structures, blurring the line between the public and private spheres of particular interests. The role of law, as well as the safeguards put in place in the area of non-discrimination, appear crucial. More specifically, the first chapter begins with an analysis of the international, supranational and national legal frameworks, with particular reference to the phenomenon of profiling. This phenomenon has found its primary reference legislation in the General Data Protection Regulation (EU Regulation No. 2016/679) and, to a lesser extent, in subsequent European legislation, such as the Digital Services Act, the Digital Markets Act, the Data Governance Act, the Data Act, the European Regulation on Digital Identity, and the European Regulation on Artificial Intelligence. In particular, with reference to profiling and automated decisions, the institutions involved are analysed from a private law perspective, highlighting the most relevant vexatae quaestiones. The vagueness and generality of certain expressions contained in the regulatory provisions could have served as an open clause through which all concerns about the potential discriminatory nature of algorithms could be included, aspects that were then partially regulated by subsequent legislation. Several issues of particular interest arise, such as those relating to “nudging”, the creation of “clusters”, and the as yet unregulated phenomenon of personalisation. On the basis of the legislation and case law examined in the first chapter, the second chapter attempts to circumscribe the above-mentioned issues with regard to the dimension of the so-called vulnerable individual. In fact, the entire human condition is becoming increasingly transparent and almost fragile in the face of a compact, opaque, pervasive and elusive power. The vulnerability-based approach lends itself well to the analysis and application of rules relating to phenomena that are still only partially analysed and regulated, concerning, on the one hand, profiling and automated decisions and, on the other, the challenges posed by artificial intelligence. Digital vulnerability is a challenge on several levels and in several respects. Not only in terms of the ways and levels at which it manifests itself, but also in terms of the levels at which legal responses must be developed. In this sense, the European private law perspective has been favoured, crystallising the multiple and valid approaches offered by the vulnerability-based model and also considering its limitations. The reflections of the first two chapters have been brought together in the last chapter, the purpose of which is not only to analyse the European Regulation on Artificial Intelligence (EU Regulation No. 2024/1689) but also to offer solutions and interpretative innovations, taking Generative Artificial Intelligence as a paradigm. Despite liberal analysis and interpretation of the normative provisions, numerous doubts remain about the phenomena of profiling and personalisation, which we attempt to address by focusing on the area of personality rights. In addition,it has been created and introduced, on an interpretative level, the category of “systemic vulnerability
12-mar-2026
36
Dottorato di Ricerca in Persona, Mercato, Istituzioni
TARTAGLIA POLCINI, Antonella
File in questo prodotto:
File Dimensione Formato  
Tesi di dottorato Marianna Ciullo Lingua Inglese def. 17112025.pdf

accesso aperto

Descrizione: Tesi di Dottorato
Tipologia: Versione Editoriale (PDF)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 1.21 MB
Formato Adobe PDF
1.21 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.12070/76605
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact