Malta Is Giving ChatGPT to Every Citizen. Nobody Asked the Hard Questions

Share

The Government of Malta has announced that it will provide all citizens with access to ChatGPT Plus through a partnership with OpenAI. Malta thus becomes the first EU member state to offer a US commercial AI system as a universal public service.

There is a condition: citizens must first complete an AI literacy course developed by the University of Malta. After that, they receive ChatGPT Plus for one year, administered by the Malta Digital Innovation Authority.

This is, depending on your disposition, either visionary or a governance catastrophe dressed in the language of digital inclusion. Possibly both. The literacy course teaches citizens how to use AI. It does not address who controls their data once they do. It is a driving lesson that neglects to mention who owns the road.

Let us ask the questions that the press release did not.

Who is the data controller?

Under GDPR Article 4(7), a data controller is the natural or legal person who determines the purposes and means of processing personal data. When a Maltese citizen uses government-provided ChatGPT to write a letter to their doctor, draft a tax query, or ask about their pension entitlements - who determines the purpose of that processing? The Government of Malta, which procured the service? OpenAI, which processes the conversation on US infrastructure? Both, as joint controllers under Article 26?

The answer matters enormously. Joint controllership requires a transparent arrangement setting out respective responsibilities - and crucially, this arrangement must be made available to data subjects. The CJEU established in Wirtschaftsakademie (C-210/16) and Fashion ID (C-40/17) that entities which enable and benefit from data processing share controller responsibility, even without direct access to the data. Malta, by providing the service and deriving public policy benefit from its use, almost certainly meets this threshold.

The citizen pressing "send" on their query to a government AI assistant is entitled to know who is responsible for their data. The press release is silent on this. The literacy course, presumably, is also silent on this.

Public task (Article 6(1)(e)) is the obvious candidate for a government-provided service. But public task requires a basis in EU or member state law. Malta has a National AI Strategy (2019) and the Malta Digital Innovation Authority Act - but does either specifically authorise the processing of citizens' personal data through a third-country commercial AI system? Without a clear statutory basis, the government is potentially processing hundreds of thousands of citizens' data without lawful grounds.

There is also the question of special categories. Under Article 9 GDPR, processing health data, political opinions, or data revealing religious beliefs requires explicit consent or another specific derogation. A general-purpose AI assistant provided to all citizens will inevitably handle special category data. Citizens seeking health advice, asylum support, or religious accommodation services will interact with ChatGPT through this programme. Has Malta conducted a Data Protection Impact Assessment? Has it obtained prior DPA authorisation where required?

An AI literacy course does not substitute for a lawful basis. Knowing how to prompt ChatGPT is not the same as consenting to the processing of your health data on US servers.

Where does the AI Act apply?

ChatGPT in a public service context may trigger obligations that do not apply in purely commercial deployment. Under Article 6(1) of the AI Act, a deployer must assess whether their specific use of a general-purpose AI system renders it high-risk under Annex III. If Malta's deployment is used for decisions affecting citizens' access to public services - even informally, even as a "first response" layer before a human official - the deployer obligation kicks in. High-risk classification requires conformity assessments, technical documentation, human oversight, and registration in the EU database.

Has Malta conducted this assessment? Has OpenAI registered this deployment as potentially high-risk? These are not rhetorical questions. They have answers that regulators will eventually demand.

The irony - explored elsewhere on this site - is sharp. A Croatian startup building a closed, local AI system for blood biomarker analysis cannot navigate the compliance framework. Malta deploys a US cloud AI to all citizens and the regulatory response is silence. The system designed to protect EU digital sovereignty is structurally subsidising the cloud providers it was meant to constrain - and now, apparently, also the member states that bypass it entirely.

The sovereignty problem

The MIT Technology Review piece on AI and data sovereignty frames this precisely: enterprises and governments that have ceded AI control to cloud vendors now face the question of who actually governs their autonomous systems. Malta's citizens will interact with a system whose model weights, training data decisions, safety guardrails, and update schedule are controlled entirely by a company in San Francisco.

If OpenAI changes its content policies next quarter, Malta's public AI service changes with it. If OpenAI decides to deprecate ChatGPT Plus in favour of a new product tier, Malta renegotiates or loses its service. The citizens are users of a foreign commercial product rebranded as a public utility.

This is not inherently wrong. Governments use commercial software for public services all the time. But they typically negotiate data processing agreements, data residency requirements, audit rights, and continuity clauses. The question is whether Malta did - and whether the European Data Protection Board will be satisfied with the answer.

The cognitive real estate question

There is a dimension to this deployment that data protection law does not yet name cleanly, but which deserves naming: what happens to the cognitive architecture of a citizenry that conducts its interactions with public services through a single foreign AI system?

Every conversation with ChatGPT is a signal - for OpenAI's models, for its understanding of Maltese public concerns, for its picture of what citizens fear, what they seek, what information they are missing and what they receive. At the individual level, this is a user profile. At the national level, it is something closer to a population-scale cognitive map: a detailed, granular, continuously updated model of how Maltese citizens think and what shapes their decisions.

The platform that mediates your engagement with information does not merely deliver answers - it shapes the questions you learn to ask, the framings you find natural, the concepts you encounter and the ones you do not. A government that provides a foreign AI system as the universal interface for civic engagement is not merely outsourcing a service. It is delegating the cognitive scaffolding of public life to an entity whose interests are not necessarily aligned with those of its citizens.

This is also a monoculture problem. If the entire Maltese civic information layer runs through a single model from a single provider, the population shares not just infrastructure but cognitive blind spots. When OpenAI's model has a systematic gap - and all models do - every citizen encounters the same gap simultaneously. There is no redundancy. There is no second opinion built into the architecture.

Malta has decided - whether deliberately or by omission - that this is acceptable. That decision deserves more scrutiny than it has received.

The silence worth noticing

The EU institutions have not publicly commented on Malta's announcement. No statement from the Commission. No reaction from the European Data Protection Board. No public inquiry from ENISA. For a deployment that raises live questions under GDPR, the AI Act, and the NIS2 Directive, the institutional response has been - as of nine days after the announcement - nothing audible.

This silence is interesting, and not because it suggests approval. It suggests something more complicated: that the EU framework, however sophisticated in principle, does not have a clear mechanism for responding in real time to member state deployments that push the edges of what the rules permit. The machinery is built for enforcement after the fact, not guidance before it.

Here is the asymmetry that matters: a startup that deployed ChatGPT to process customer data at the same scale - without a published legal basis, without a documented controller arrangement, without a prior DPIA - would be looking at an investigation within months. Ireland's Data Protection Commission has collected over two billion euros in GDPR fines for exactly this type of structural question.

But Malta is a member state. And member states exist in a different regulatory relationship with EU institutions than private operators do. That asymmetry is not a bug in the system - it is a feature of how EU law distributes sovereignty. It is also an uncomfortable precedent. If a government can effectively pilot-test a GDPR-edge deployment at national scale, and the institutional response is silence, the message sent to private actors is not the one the GDPR was designed to send.

The Clause finds the symmetry instructive: the EU built the most sophisticated data protection framework in the world. It would be ironic if the first EU government to offer universal AI access did so in a way that its own regulators could not approve - and even more ironic if the loudest signal that sent was that governmental actors operate under different rules than the startups or companies they regulate.

Meanwhile, the agents keep losing their constraints. The systems keep operating beyond oversight. And the governance frameworks keep describing a world that existed before someone decided to give an entire country access to a system whose behaviour cannot be audited by the country providing it.

Ireland's Data Protection Commission will be watching Malta with interest.

So will the rest of us.