Live data from Hacker News

AI systems with 'unacceptable risk' are now banned in the EU

techcrunch.com

311–320 of 424 posts

Re: AI systems with 'unacceptable risk' are now banned in the EU

#311

Earlier quoted context omitted.

For starters, I am still waiting for Apple Intelligence to arrive on my phone. Reason given is "EU legislative concerns". Then there's the nontrivial number of especially local US news sources which now give me a cheerful "451 Unavailable For Legal Reasons" error code. Then there's the outright stupid stuff - like lightbulbs that do not cost 15 euros a piece (to save 'energy'), or drinking straws that do not dissolve…

What are you talking about? Leaving aside your other random complaints that I don’t recognise, but can’t immediately link to, a basic lightbulb is less than €3 for a two-pack: https://www.ikea.com/de/en/p/solhetta-led-bulb-e14-250-lumen...

That's an LED though.

I understood he was referring to incandescent light bulbs, which have been largely regulated out of the market. So you now need to get an "Edison light bulb" which circumvenes regulation but costs significantly more.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#312
post #219

Earlier quoted context omitted.

> the EU doesn’t take into account the unintended consequences of laws it passes when it comes to technology. So, the companies that implement these cookie banners are entirely without blame, right? So what is your solution? Reminder: GDPR is general data protection regulation. It doesn't deal with cookies at all. It deals with tracking, collecting and keeping of user data. Doesn't matter if it's on the internet, in…

Meta announced in their earnings report that ATT caused a drop in revenue after it went to effect. They made no such announcement after the GDPR. What’s my solution? There isn’t one, you know because of the way the entire internet works, the server is going to always have your IP address. For instance, neither Overcast or Apple’s podcast app actively track you or have a third party ad SDK [1]. But since they and ever…

> They made no such announcement after the GDPR.

And yet they make no move against Apple, and they are fighting EU in courts. Hence long term.

> There isn’t one, you know because of the way the entire internet works, the server is going to always have your IP address.

Having my IP address is totally fine under GDPR.

What is not fine under my GDPR is to use this IP address (or other data) for, say, indefinite tracking.

For example, some of these completely innocent companies that were forced to show cookie banners or something, and that only want to show ads, store precise geolocation data for 10+ years.

I guess something something informed consent and server will always have IP address or something.

> What I personally do avoid is not use ad supported apps because I find them janky.

So you managed to give me a non-answer based on your complete ignorance of what GDPR is about.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#313
post #306

Earlier quoted context omitted.

It looks like IP addresses are considered PII by GDPR: https://gdpr.eu/eu-gdpr-personal-data/ They are explicitly listed as example of PII.

So in essence, it disallows logging IP address for any purpose, be it security, debugging, rate-limiting etc. because you can't give consent in advance for this, and no other sentence in Art. 6.1 applies. Moreover, to reason about this, one also needs to take into account Art 6.2 which means there might be an additional 27 laws you need to find and understand. Note, however, that recital 30 which you quoted is explic…

> So in essence, it disallows logging IP address for any purpose, be it security, debugging, rate-limiting etc. because you can't give consent in advance for this, and no other sentence in Art. 6.1 applies.

No, it doesn't. Subsections b, c, and f roughly cover this. On top of that, no one is going to come at you with fines for doing regular business things as long as you don't store this data indefinitely long, sell it to third parties, or use it for tracking. As laid out in Article 1.1.

On top of that, for many businesses existing laws override GDPR. E.g. banks have to keep personal records around for many years.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#314
post #306

Earlier quoted context omitted.

It looks like IP addresses are considered PII by GDPR: https://gdpr.eu/eu-gdpr-personal-data/ They are explicitly listed as example of PII.

So in essence, it disallows logging IP address for any purpose, be it security, debugging, rate-limiting etc. because you can't give consent in advance for this, and no other sentence in Art. 6.1 applies. Moreover, to reason about this, one also needs to take into account Art 6.2 which means there might be an additional 27 laws you need to find and understand. Note, however, that recital 30 which you quoted is explic…

That's not true. IP addresses might be processed in regards to article 6.1 c) or 6.1 f) but only for these very narrowly defined use cases and in accordance with article 5. So, purge your logs after 14/30 days and don't use the ip address for anything else and you will be fine.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#315
post #310
post #280

Earlier quoted context omitted.

Not a lawyer, only an engineer starting to assess our AI models. Your comparison to GDPR seems to be correct in a way, both are quite vague and wide. The implementation of GDPR is still unclear in certain situations and it was even worse when it was launched, the EU AI act have very little references to work with and except for very obvious area it is still a lot of a guesswork

When a law is “vague” in that it intentionally tries to be overly broad in protecting the average citizen from corporations, that’s a good thing. GDPR is very much meant to scare the facebooks of the world whose default modus operandi is: your privacy means nothing, I have a revenue number to hit and I don’t care if it ruins your life in the future. I WANT it to be difficult for AI companies to steal other people’s h…

The problem is that the GDPR has been largely a failure protecting citizens from corporations, but it has hurt everyone else.

- Nothing has changed in Facebook and Google data collection practices, who with other bug corps account for > 90% of data collection

- Many mid tier competitors lost market share, focusing power to Google

- EU small software companies pay estimated extra 400 EUR/year to satisfy GDPR compliance with little tangible benefits to the EU citizens.

It's called unintended consequences. We all want Zuckerberg to collect less data, but how GDPR was implemented is that it mostly hurt small businesses disproportionately. E.g. you now need to hire a lawyer to analyse if you can collect an IP address and for what purposes, as discussed here.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#316
post #310

Earlier quoted context omitted.

When a law is “vague” in that it intentionally tries to be overly broad in protecting the average citizen from corporations, that’s a good thing. GDPR is very much meant to scare the facebooks of the world whose default modus operandi is: your privacy means nothing, I have a revenue number to hit and I don’t care if it ruins your life in the future. I WANT it to be difficult for AI companies to steal other people’s h…

The problem is that the GDPR has been largely a failure protecting citizens from corporations, but it has hurt everyone else. - Nothing has changed in Facebook and Google data collection practices, who with other bug corps account for > 90% of data collection - Many mid tier competitors lost market share, focusing power to Google - EU small software companies pay estimated extra 400 EUR/year to satisfy GDPR complianc…

> EU small software companies pay estimated extra 400 EUR/year

[citation needed]

Re: AI systems with 'unacceptable risk' are now banned in the EU

#317
post #310

Earlier quoted context omitted.

When a law is “vague” in that it intentionally tries to be overly broad in protecting the average citizen from corporations, that’s a good thing. GDPR is very much meant to scare the facebooks of the world whose default modus operandi is: your privacy means nothing, I have a revenue number to hit and I don’t care if it ruins your life in the future. I WANT it to be difficult for AI companies to steal other people’s h…

The problem is that the GDPR has been largely a failure protecting citizens from corporations, but it has hurt everyone else. - Nothing has changed in Facebook and Google data collection practices, who with other bug corps account for > 90% of data collection - Many mid tier competitors lost market share, focusing power to Google - EU small software companies pay estimated extra 400 EUR/year to satisfy GDPR complianc…

I will be honest, I am always very skeptical of these claims that the big tech companies are fine but small business is hurting. Many of them seem to originate with the big tech companies themselves and I highly doubt they really have the interests of small business in mind. Plus, I'm old enough to remember when everyone claimed EU tech law was about to ban memes, which didn't happen...

Re: AI systems with 'unacceptable risk' are now banned in the EU

#318
post #310

Earlier quoted context omitted.

When a law is “vague” in that it intentionally tries to be overly broad in protecting the average citizen from corporations, that’s a good thing. GDPR is very much meant to scare the facebooks of the world whose default modus operandi is: your privacy means nothing, I have a revenue number to hit and I don’t care if it ruins your life in the future. I WANT it to be difficult for AI companies to steal other people’s h…

The problem is that the GDPR has been largely a failure protecting citizens from corporations, but it has hurt everyone else. - Nothing has changed in Facebook and Google data collection practices, who with other bug corps account for > 90% of data collection - Many mid tier competitors lost market share, focusing power to Google - EU small software companies pay estimated extra 400 EUR/year to satisfy GDPR complianc…

> The problem is that the GDPR has been largely a failure protecting citizens from corporations, but it has hurt everyone else.

This is just laughably incorrect. Literally every Fortune 500 that I work with who has operations in Europe has an entire team that owns GDPR compliance. It is one of the most successful projects to curtail businesses treating private data like poker chips since HIPAA.

Re: AI systems with 'unacceptable risk' are now banned in the EU

#320
post #310
post #280

Earlier quoted context omitted.

Not a lawyer, only an engineer starting to assess our AI models. Your comparison to GDPR seems to be correct in a way, both are quite vague and wide. The implementation of GDPR is still unclear in certain situations and it was even worse when it was launched, the EU AI act have very little references to work with and except for very obvious area it is still a lot of a guesswork

When a law is “vague” in that it intentionally tries to be overly broad in protecting the average citizen from corporations, that’s a good thing. GDPR is very much meant to scare the facebooks of the world whose default modus operandi is: your privacy means nothing, I have a revenue number to hit and I don’t care if it ruins your life in the future. I WANT it to be difficult for AI companies to steal other people’s h…

[deleted]
Post reply on HN