Live data from Hacker News

AI systems with 'unacceptable risk' are now banned in the EU

techcrunch.com

291–300 of 424 posts

Re: AI systems with 'unacceptable risk' are now banned in the EU

#292

Earlier quoted context omitted.

From the laws text: For the purposes of this Regulation, the following definitions apply: (1) ‘AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that c…

> and that may exhibit adaptiveness after deployment So if an AI can't change its weights after deployment, it's not really an AI? That doesn't make sense. As for the other criteria, they're so vague I think a thermostat might apply.

Keyword 'may'.

A learning thermostat would apply, say one that uses historical records to predict changes in temperature and preemptively adjusts. And it would be low risk and unregulated in most cases. But attach to a self-heating crib or premature baby incubator and that would jump to high risk and you might have to prove it is safe.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#293
post #280

Earlier quoted context omitted.

Not a lawyer, only an engineer starting to assess our AI models. Your comparison to GDPR seems to be correct in a way, both are quite vague and wide. The implementation of GDPR is still unclear in certain situations and it was even worse when it was launched, the EU AI act have very little references to work with and except for very obvious area it is still a lot of a guesswork

>...GDPR seems to be correct in a way, both are quite vague and wide. How is the gdpr vague?

Are IP addresses considered PII or not? I remember there being multiple conflicting conclusions on that

Re: AI systems with 'unacceptable risk' are now banned in the EU

#294
post #293

Earlier quoted context omitted.

>...GDPR seems to be correct in a way, both are quite vague and wide. How is the gdpr vague?

Are IP addresses considered PII or not? I remember there being multiple conflicting conclusions on that

It looks like IP addresses are considered PII by GDPR:

https://gdpr.eu/eu-gdpr-personal-data/

They are explicitly listed as example of PII.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#295
post #28

Earlier quoted context omitted.

the actual text in the ~act~ guidance states: > Exploitation of vulnerabilities of persons, manipulation and use of subliminal techniques techcrunch simplified it. from my reading, it counts if you are intentionally setting out to build a system to manipulate or deceive people . edit — here’s the actual text from the act, which makes more clear it’s about whether the deception is purposefully intended for malicious r…

Seems like even a rudimentary ML model powering ad placements would run afoul of this.

The burden will be on proving "significant harm"

Re: AI systems with 'unacceptable risk' are now banned in the EU

#298
post #221

Earlier quoted context omitted.

> Well, per GDPR they aren't allowed to do that. Are they giving that option to users outside of EU? Why Not? Because no other place thinks that their citizens are too dumb to make informed choices. > What about sex and organs? In your opinion should businesses be allowed to charge you with those? If consenting adults decide they want to have sex as a financial arrangement why not? Do you think these 25 year old “gir…

> Because no other place thinks that their citizens are too dumb to make informed choices. In case of Facebook (or tracking generally) you had no chance to make an informed choice. You are just tracked, and your data is sold to hundreds of "partners" with no possibility to say "no" > Just like right now, HN knows my email address and my comment history and where I access this site from. And that is fine. You'd know t…

Facebook doesn’t sell your data. Why would they? Having your data is their competitive advantage. They sell access to you based on the data they have.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#299
post #280

Earlier quoted context omitted.

Not a lawyer, only an engineer starting to assess our AI models. Your comparison to GDPR seems to be correct in a way, both are quite vague and wide. The implementation of GDPR is still unclear in certain situations and it was even worse when it was launched, the EU AI act have very little references to work with and except for very obvious area it is still a lot of a guesswork

>...GDPR seems to be correct in a way, both are quite vague and wide. How is the gdpr vague?

GDPR is clear-ish indeed.

That being said: it is extremely strict, a lot of lawyers like to make it stricter (because for them it means safer) and a lot of lawyers have to back of under business constraint (that push to sometimes got below legal requirements). My experience is that no two companies have the same understanding of GDPR.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#300

Does this only apply to usage, or does it include training the model as well? Training a model is extremely expensive, and it’s hard to imagine a company investing a huge amount of money to develop two different models just to comply with regulations (though maybe it’s worth it, I’m just guessing here). I think it’s more likely that companies would adhere to EU regulations and use the same model everywhere or impleme…

Not a lawyer.

When I attended a conference about this I remember the distinction between "Provider" and "Deployer" being discussed. Providers are manufacturers developing a tool, deployers are professional users making a service available using the tool. A deployer may deploy a provided AI tool/model in a way that falls within the definition of unacceptable risk, and it is (also) the deployer's responsibility to ensure compliance.

The example given was of a university using AI for grading. The university is a deployer, and it is their responsibility to conduct a rights impact assessment before deploying the tool to its internal users.

This was compared to normal EU-style product safety regulation, which is directed at the manufacturer (what would be the provider here): if you make a stuffed toy, don’t put in such and such chemicals, etc. Here, the _application_ of the tool is under scrutiny as well vs just the tool itself. Note that this is based on very hasty notes[0] from the talk - I'm not sure to what extent the provider vs deployer responsibility divide is actually codified in the act.

[0] https://liza.io/ai-act-conference-2024-keynote-notes-navigat...

Post reply on HN