Live data from Hacker News

AI systems with 'unacceptable risk' are now banned in the EU

techcrunch.com

241–250 of 424 posts

Re: AI systems with 'unacceptable risk' are now banned in the EU

#241
post #89

Seems like a mostly reasonable list of things to not let AI do without better safety evals. > AI that tries to infer people’s emotions at work or school I wonder how broadly this will be construed. For example if an agent uses CoT and they needs emotional state as part of that, can it be used in a work or school setting at all?

> Seems like a mostly reasonable list of things to not let AI do without better safety evals.

Yes. This is how you know that all the people screaming about the EU overregulating and how the EU will miss all that AI innovation haven't even bothered to Google or ask their preferred LLM about the legislation. It's mostly just common sense to avoid EU citizens having their rights or lives decided by blackbox algorithms nobody can explain, be it in a Post Office (UK) scandal style, or US healthcare style.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#242
Love the EU, living here is the best.

There are plenty of companies in the EU using and developing AI even with the fact that Americans say we have "heavy regulation", it isn't just in the same ballpark as the US and China, which both have much bigger potential markets and a stronger VC base with of course, more money.

The lack of regulations from the US in AI creates a very harsh atmosphere for the population.

It's so naive to think that Meta/Google(Youtube) doesn't have power to manipulate people's opinion by showing content based on their algorithms. That's all manipulation through the use of AI.

They are thinking for you. Making you depressed, making you buy useless stuff.

Look on research on this subject and you will be surprised how much the likes of Meta and Google are getting away with.

Hope to see more EU fines for American Big Tech firms using AI to abuse people's weaknesses.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#243

Never forget the EU is run by lobbies by design. So usually those scary regulations are not what they seem to be. Here is what happened in most corporations when GDPR came out: - An new Chief Privacy Officer would be appointed, - A series of studies would be conducted by big consulting firms with a review of all processes and data flow across the organisation, - After many meeting they would conclude that a move to t…

> Here is what happened in most corporations when GDPR came out Do you have a source on that, or is this what you feel like may have happened? The move to the cloud was in full swing way before GDPR came out in 2016 and got enacted in 2018. Same for outsourcing.

I can assure you I have witnessed it in dozens of organisations and have been involved.

In terms of timeline I can tell you:

- by 2012 I already heard about that regulation but only knew it was gonna be about data protection. At that time some "Big tech" lobbying groups were already organising events in Brussels raising awareness about how important is data privacy and protection. I have been to some of those events and I even witnessed very heated exchanges between some EU people and and lobbyists about that.

Proof is a lot of people knew way before that time.

- by 2014 many big corporations were already preparing for GDPR, big budgets have already been validated. At that time they already knew it would be at least reasonably disruptive and they had to start early to prepare.

Also remember before 2014 "Windows Azure" (what would become the most successful cloud for most European corporations) was absolutely not ready as a enterprise product.

So those are not Silicon Valley startups on AWS since 2006, for many decision makers in those big corporations the GDPR upcoming problem predate the cloud solution.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#244

The title is a bit absurd as it's the law that defines what's acceptable and what isn't. Anything that this regulation doesn't allow is by definition "unacceptable", even if it's tea with biscuits.

> Anything that this regulation doesn't allow is by definition "unacceptable",

That's not true. The regulation first defines high-risk products with a narrow scope (see article 5 and annex III). It then requires risk management to be implemented. It does explicitly state what risks are acceptable, it only requires the "adoption of appropriate and targeted risk management measures" that are effective to the point that the "overall residual risk" of the is "judged to be acceptable".

IANAL, the whole story is a bit more complex. But not by much.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#245
post #213

The (well known) problematic bit about AI is that it furthers the diffusion of responsibility that already became so commonplace with computers. People can just handwave catastrophic decisions away with a "the computer made an error, nothing we can do". This has been the case before AI, the differrnce AI makes is just that more decisions are going to be affected by this. What we need is to make the (legal) buck stop…

That is explicitly addressed by the regulation. If an AI product is used in a way you describe it, there need to be measures put in place to reduce the risk to an acceptable level. If these measures are missing, it cannot even be put into service. This places the responsibility for the use of AI clearly with either the entity that places the product on the market (i.e. if you sell something in the EU) or that puts it into service (if a EU company uses an AI product across borders remotely). With the required employee AI training, this is further shifted onto the users if done correctly or stays with the employer if not.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#246
post #190

Never forget the EU is run by lobbies by design. So usually those scary regulations are not what they seem to be. Here is what happened in most corporations when GDPR came out: - An new Chief Privacy Officer would be appointed, - A series of studies would be conducted by big consulting firms with a review of all processes and data flow across the organisation, - After many meeting they would conclude that a move to t…

It is not true. If you outsource, GDPR applies all the same. And companies had to literally implement changes into their software and literally did. GDPR applies to data in cloud too.

Yes but here is the trick: when those companies found out their old applications had to be changed and legacy code had to be rewritten it was cheaper to move to the cloud/SaaS that is supposedly GDPR compliant.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#247

Earlier quoted context omitted.

Yet better privacy protections than we in the States enjoy.

The EU in a nutshell: You can't have nice things, but on the bright side Google/Apple/Facebook won't know what you had for dinner. Now give us your whole financial transaction and travel history, so we can share it with the US, a hostile country, citizen!

Genuinely curious: What are those nice things Europe cannot have?

Re: AI systems with 'unacceptable risk' are now banned in the EU

#248

I am not expert but there seems to be an overlap in the article between 'AI' and well ... just software, or signal processing: - AI that collects “real time” biometric data in public places for the purposes of law enforcement. - AI that creates — or expands — facial recognition databases by scraping images online or from security cameras. - AI that uses biometrics to infer a person’s characteristics - AI that collect…

From the laws text: For the purposes of this Regulation, the following definitions apply: (1) ‘AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that c…

Good. You cannot have a functioning society where decisions are made in a non-deterministic way. Especially when those decision deviate from agreed protocols (laws, bylaws, contracts, etc.).

Re: AI systems with 'unacceptable risk' are now banned in the EU

#249

Earlier quoted context omitted.

The EU in a nutshell: You can't have nice things, but on the bright side Google/Apple/Facebook won't know what you had for dinner. Now give us your whole financial transaction and travel history, so we can share it with the US, a hostile country, citizen!

The USA in a nutshell: We elected a President who tried to lead an armed insurrection but we'll never press criminal charges because we elected him President again. Sorry, but anything the EU has ever done pales in comparison with that.

As an European, respectfully, I am not too interested in comparing the stability of my system of government with that of another country. I try to compare my circumstances to a better ideal, not a worse.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#250

Earlier quoted context omitted.

The EU in a nutshell: You can't have nice things, but on the bright side Google/Apple/Facebook won't know what you had for dinner. Now give us your whole financial transaction and travel history, so we can share it with the US, a hostile country, citizen!

Can we get some sources that back the narrative for that last sentence?

EU bending backwards to meet US demands to access non-US-related traveller records: https://eur-lex.europa.eu/EN/legal-content/summary/eu-us-agr...

Yes, it only affects airlines that have connections to the US. But if I book Lufthansa from Frankfurt to Tokyo, the PNR will still be sent to the US, for Lufthansa has connections to the US.

Yes, there are 'safeguards' in there, to shackle the DHS to be responsible with the data - but who seriously thinks the data, once in US hands, is used responsibly and only for the matters outlined in the treaty? The US has been less of a reliable partner for decades now.

Oh, right. They won't do that for financial transactions, right? Right?

https://eur-lex.europa.eu/EN/legal-content/summary/agreement...

Post reply on HN