Live data from Hacker News

AI systems with 'unacceptable risk' are now banned in the EU

techcrunch.com

211–220 of 424 posts

Re: AI systems with 'unacceptable risk' are now banned in the EU

#211

I am not expert but there seems to be an overlap in the article between 'AI' and well ... just software, or signal processing: - AI that collects “real time” biometric data in public places for the purposes of law enforcement. - AI that creates — or expands — facial recognition databases by scraping images online or from security cameras. - AI that uses biometrics to infer a person’s characteristics - AI that collect…

The EU and other organizations will be using these to ban data collection and anything to do with protection of the EU.

They will interpret "predict" as merely "report" or "act on".

This is terrible.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#212

Some of the unacceptable activities include: AI used for social scoring (e.g., building risk profiles based on a person’s behavior) - Oh, so insurance, and credit score is banned now? And background checks. AI that manipulates a person’s decisions subliminally or deceptively. - Oh, so no more ads? AI that exploits vulnerabilities like age, disability, or socioeconomic status. - Oh, are we banning facebook now? AI tha…

I fail to see where you stand based on your line by line commentary. Are we not supposed to be against these obvious negatives? Regulation against undesired outcomes needs to start somewhere. Do you believe we should not regulate, simply because we already do some of the things that seem to fall under these individual buckets?

Laws are nice, when they work, clear and applicable.

It is probably would be as useful, as GDPR. Like of course, it sounds nice on the paper, but in reality it will get drown in a lot of legalize. Like with tracking consent in forms nowadays. Do you know which companies you gave consent and when? - me neither.

The issue with such laws, is that they are extremely wide and hard to regulate/enforce/check. But making regulation would make a few political points. While probably not so useful in real life.

We already do a lot falling under these baskets for years, big tech uses AI for algorithms left and right. "Ooopsie, we removed your youtube channel / application, because our AI system said so. You can talk to another AI system next." - we already have these, but I don't hear any reasonable feedback from EU for this.

Basically, big companies with strong legal departments would find the way around the rules. Small startups would be forced to move.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#213
The (well known) problematic bit about AI is that it furthers the diffusion of responsibility that already became so commonplace with computers.

People can just handwave catastrophic decisions away with a "the computer made an error, nothing we can do". This has been the case before AI, the differrnce AI makes is just that more decisions are going to be affected by this.

What we need is to make the (legal) buck stop somewhere, ideally in a place that can positively change things. If you’re a civil engineer and your bridge collapses, because you fucked up the material selection, you go to jail. If you are a software engineer and you make design decisions in 2025 that would have had severe security implications in the 80s — and then this leads to the leaking of millions of medical records you can still YOLO it off somehow and go to work on the next thing.

The buck has to stop somewhere with software and it doesn't really. I know that is a feature for a certain type of person, but it actively makes the world worse.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#214
post #185

Earlier quoted context omitted.

It seems to me the key phrase in that definition is "that may exhibit adaptiveness after deployment" - If your code doesn't change its own operation without needing to be redeployed, it's not AI under this definition. If adaptation requires deployment, such as pushing a new version, that's not AI.

I'm not sure what they intended this to apply to. LLM based systems don't change their own operation (at least, not more so than anything with a database). We'll probably have to wait until they fine someone a zillion dollars to figure out what they actually meant.

For LLMs we have "for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments".

Re: AI systems with 'unacceptable risk' are now banned in the EU

#215

Never forget the EU is run by lobbies by design. So usually those scary regulations are not what they seem to be. Here is what happened in most corporations when GDPR came out: - An new Chief Privacy Officer would be appointed, - A series of studies would be conducted by big consulting firms with a review of all processes and data flow across the organisation, - After many meeting they would conclude that a move to t…

Since GDPR came out I’ve been able to download all data that the big companies have on me, and delete it too. I’m happy for it.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#216
post #189

In the EU, no risk is ever tolerated. They keep creating laws to regulate things, but do they ever measure the actual impact? With so many regulations, it must be hard to move freely. There should also be a system for repealing regulations.

More free then America, unless you are billionaire. I mean, American billionaires are trying to export their form of anti-democraric policies, Russia is trying ro export their own fascism etc. It is not like it was safe democracy. But, it is still one and one that cares more about own citizens then the rest. Maybe except Canada.

[flagged]

Re: AI systems with 'unacceptable risk' are now banned in the EU

#217

I am not expert but there seems to be an overlap in the article between 'AI' and well ... just software, or signal processing: - AI that collects “real time” biometric data in public places for the purposes of law enforcement. - AI that creates — or expands — facial recognition databases by scraping images online or from security cameras. - AI that uses biometrics to infer a person’s characteristics - AI that collect…

From the laws text: For the purposes of this Regulation, the following definitions apply: (1) ‘AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that c…

> and that may exhibit adaptiveness after deployment

So if an AI can't change its weights after deployment, it's not really an AI? That doesn't make sense.

As for the other criteria, they're so vague I think a thermostat might apply.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#219
post #49

Earlier quoted context omitted.

> Maybe if the GDPR was a simple law It is a simple law. You can read it in an afternoon. If you still don't understand it 8 years later , it's not the fault of the law. > instead of 11 chapters and 99 sections News flash: humans and their affairs are complicated > all anyone got as a benefit from it is cookie banners Please show me where GDPR requires cookie banners. Bonus points: who is responsible for the cookie b…

It doesn’t matter what it requires, the point is as usual, the EU doesn’t take into account the unintended consequences of laws it passes when it comes to technology. That partially explains the state of the tech industry in the EU. But guess which had a more deleterious effect on Facebook ad revenue and tracking - Apples ATT or the GDPR?

> the EU doesn’t take into account the unintended consequences of laws it passes when it comes to technology.

So, the companies that implement these cookie banners are entirely without blame, right?

So what is your solution?

Reminder: GDPR is general data protection regulation. It doesn't deal with cookies at all. It deals with tracking, collecting and keeping of user data. Doesn't matter if it's on the internet, in you phone app, or in an ofline business.

Reminder: if your solution is "this should've been built into the browser", then: 1) GDPR doesn't deal with specific tech (because tech changes), 2) when governments mandates specific solutions they are called overreaching overbearing tyrants and 3) why hasn't the world's largest advertising company incidentally owning the world's most popular browser implemented a technical solution for tracking and cookie banners in the browser even though it's been 8 years already?

> But guess which had a more deleterious effect on Facebook ad revenue and tracking - Apples ATT or the GDPR?

In the long run most likely GDPR (and that's why Facebook is fighting EU in courts, and only fights Apple in newspaper ads), because Apple's "ask apps to not track" doesn't work. This was literally top article on HN just yesterday: "Everyone knows your location: tracking myself down through in-app ads" https://timsh.org/tracking-myself-down-through-in-app-ads/

So what is your solution to that?

Re: AI systems with 'unacceptable risk' are now banned in the EU

#220
post #45
post #27

Earlier quoted context omitted.

Instead of relying on Techcrunch and speculating, you could read sections (33), (42), and (59) of the EU AI Act yourself.

Article 59 seems relevant, other two on a quick skim don't seem to relate to the subject. > 2. For the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security, under the control and responsibility of law enforcement authorities, the processing of personal data in AI regulat…

> Article 59 seems relevant, other two on a quick skim don't seem to relate to the subject.

Your original take: "Should have been: AI that attempts to predict people committing crimes"

Article 42. literally:

--- start quote ---

In line with the presumption of innocence, natural persons in the Union should always be judged on their actual behaviour. Natural persons should never be judged on AI-predicted behaviour based solely on their profiling, personality traits or characteristics, such as nationality, place of birth, place of residence, number of children, level of debt or type of car, without a reasonable suspicion of that person being involved in a criminal activity based on objective verifiable facts and without human assessment thereof.

Therefore, risk assessments carried out with regard to natural persons in order to assess the likelihood of their offending or to predict the occurrence of an actual or potential criminal offence based solely on profiling them or on assessing their personality traits and characteristics should be prohibited.

In any case, that prohibition does not refer to or touch upon risk analytics that are not based on the profiling of individuals or on the personality traits and characteristics of individuals, such as AI systems using risk analytics to assess the likelihood of financial fraud by undertakings on the basis of suspicious transactions or risk analytic tools to predict the likelihood of the localisation of narcotics or illicit goods by customs authorities, for example on the basis of known trafficking routes.

--- end quote ---

> Seems like it allows pretty easily for national states to add in laws that allow them to skirt around

Key missed point: "subject to the same cumulative conditions as referred to in paragraph 1."

Where paragraph 1 is "In the AI regulatory sandbox, personal data lawfully collected for other purposes may be processed solely for the purpose of developing, training and testing certain AI systems in the sandbox when all of the following conditions are met: ... list of conditions ..."

-----

In before "but governments can do whatever they want". Yes, they can, and they will. Does it mean we need to stop any and all legislation and regulation because "government will do what government will do"?

I think the EU has done better following its own rules than most other countries (not that it's perfect in any way).

It might be too little too late to stop the flood though: https://www.foxnews.com/us/tech-company-boasts-its-ai-can-pr...

Post reply on HN