Apple tries to market its product as privacy-focused, yet the privacy of their new AI features is so bad they don't meet EU standards? Is that the message here?
Apple decided not to roll out Siri in EU after denied request for exemption
81–90 of 735 posts
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#82Apple tries to market its product as privacy-focused, yet the privacy of their new AI features is so bad they don't meet EU standards? Is that the message here?
* If you allow the user to grant those privileges to third-party applications, they can grant it to applications that abuse it, resulting in security and privacy risks. You might even be blamed for allowing them access (e.g. the famous Cambridge Analytica scandal).
* If you don't allow the user to do that, third-party tools won't be able to serve those needs, which can be considered anti-competitive preferential treatment of your own tools.
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#83Earlier quoted context omitted.
This doesn't have anything to do with privacy. The DMA mandates that Apple allows for competition, which (if you believe in capitalism) is good for the market overall. It's essential to stop big tech from abusing their market dominance. However Apple would prefer to not allow competition for their digital products on any of their hardware.
But that does have to do with privacy. Apple wants to implement features that access data locally. It doesn’t want to allow competition for offering those features, but if it did, competitors may use that access to local data to exfiltrate. So it is about both competition and, as a result of creating competition, privacy.
If you want to you could still use Apple or another provider you decide to trust - or even one that does everything locally. The competition would still have to follow GDPR after all.
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#84Earlier quoted context omitted.
I believe that the issue was that the EU wanted Apple to open up their new AI agent interface (the ability to control every app on your phone so Siri can call you an Uber or whatever), and Apple thought that it was too risky of a capability to give to any random AI app right out of the gate.
> Apple thought that it was too risky of a capability to give to any random AI app right out of the gate Oh come on. Apple doesn't want to give up control. That's what this is about. The privacy thing is just to make them look good
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#85Apple said "hey, can we not comply with the law", the EU said no, so it didn't launch. Seems pretty straightforward to me. I can see why Apple might want to request an 18 month exemption, there's clearly extra work required to comply with EU regulations. But on the other hand it also feels like a straightforward play for consumer sympathy: let them get used to using it every day for 18 months, then pressure the EU to…
Throwing infinite money at engineering problems doesn't move deadlines arbitrarily. But Apple's position here is actually really wild: Apple claims to protect user privacy all the time. But they can't offer a product in a major jurisdiction that has actually meaningful privacy laws? Didn't they consider that while designing the product? This is quite the contradiction.
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#86Earlier quoted context omitted.
Google eng mgr here. I've worked on a few projects related to compliance with various government policies. This isn't "assign a two-pizza team to it, will be done in a quarter"; these types of compliance efforts can mean completely redoing multiple core systems to handle privacy, wipeout, audit, reporting, per-location policies, etc etc. These efforts can involve hundreds to thousands of people for multiple years. Su…
Yet Gemini had no issues to comply with EU's DMA and release on all phones? Let's call it how it is: Android phones allow every competitor to run their chatbot in place of Gemini. Want Perplexity instead of Gemini? You can have it. Samsung launches with Perplexity as of late. Apple? As always, went into "ay mate, too integrated, can't give the same APIs to competitors" lame excuse.
Or never. Like the majority of Pixel 10 on device AI features (image editing, magic cue).
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#87Earlier quoted context omitted.
Google eng mgr here. I've worked on a few projects related to compliance with various government policies. This isn't "assign a two-pizza team to it, will be done in a quarter"; these types of compliance efforts can mean completely redoing multiple core systems to handle privacy, wipeout, audit, reporting, per-location policies, etc etc. These efforts can involve hundreds to thousands of people for multiple years. Su…
Privacy by design isn‘t enormous effort, as every European engineering manager will tell you. It‘s just another reasonable and straightforward set of requirements. Of course, if you want to have privacy-less features in jurisdictions permitting it, that‘s a different story and that‘s a choice.
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#88Interesting how the "groundbreaking Private Cloud Compute" cannot rollout due to privacy laws
Re: Apple decided not to roll out Siri in EU after denied request for exemption
#89Apple said "hey, can we not comply with the law", the EU said no, so it didn't launch. Seems pretty straightforward to me. I can see why Apple might want to request an 18 month exemption, there's clearly extra work required to comply with EU regulations. But on the other hand it also feels like a straightforward play for consumer sympathy: let them get used to using it every day for 18 months, then pressure the EU to…
Throwing infinite money at engineering problems doesn't move deadlines arbitrarily. But Apple's position here is actually really wild: Apple claims to protect user privacy all the time. But they can't offer a product in a major jurisdiction that has actually meaningful privacy laws? Didn't they consider that while designing the product? This is quite the contradiction.
Lemma 2: you are obliged by other regulation to offer equal access to user data to third parties, so others can build equivalent functionality (DMA).
Lemma 3: malicious third parties will absolutely try to abuse the access and trick the user into sharing their data by all means possible. You will be held responsible in court of public opinion at minimum and legally at maximum if/when a malicious third party abuses said access.
This is a hard, possibly technically unsolvable problem no matter how much money you might have, because the root issue is not technical, it's the fact that you legally have to give third parties access and no way to control what they do with it - and as others have mentioned in the threads, it's exacerbated by the fact that the regulation doesn't say "this is okay and this is not", it is vague and judges things "by outcome", so you may spend all the time in the world implementing a solution you think will work, and then get hit by fines/lawsuits because the implementation is judged as not sufficient after the fact.