ChatGPT broke the EU plan to regulate AI
politico.eu
politico.eu
It's not the AI that's the issue, it's the use of it that's the problem. The law shouldn't focus on the AI, for example:
>The regulation, proposed by the Commission in 2021, was designed to ban some AI applications like social scoring
Ban social scoring, not the AI, the tool doesn't matter. Would it be good if it was computed by hand on paper instead of through AI? No, so the issue is not the tool.
They fear the amplification factor of such tech, but the amplification factor works for the good and for the bad, so you need to focus just on the bad, not on the tech. Otherwise you end up impairing the good too.
Automated human classification without recourse nor transparency is what the EU is against. "You cannot get a loan because the AI says so" is not acceptable.
> Would it be good if it was computed by hand on paper instead of through AI?
Yes. As a judge can check what information was used and what algorithm applied to get to a conclusion. And it may declare that use of data or algorithm illegal.
> They fear the amplification factor of such tech, but the amplification factor works for the good and for the bad
Maybe just go slower. Something like an Hippocratic oath can be a good principle to follow for high impact technologies. To do some good may not justify the harm.
The credit score system already in place in the US is frequently as arbitrary in some cases already. You get punished for just looking at it. I don't think I need to preach to HN about that (crypto money and all that). Does Europe do it much differently?
Not an arguement for AI to do it, but the only reason why the current system is better (at least in the US) is its sluggish incompetence.
Almost every country has some kind of credit reporting system, but many of them differ from the US in how they do it. In particular, in many countries, credit bureaus only hold negative information such as failing to pay bills or repay debts – which means if you keep up to date with all your bills and debts, your credit history will be blank. At which point, lenders will generally ask you to provide evidence of your employment history, salary, bank balance, assets, etc, and base their lending decision on that. They may well internally convert that all info into a "score", but every lender is going to have a different scoring system. Here's an article – https://www.businessinsider.com/credit-score-around-the-worl... – which discusses the systems used in different countries, including several European countries. There is no uniform approach to this in Europe – the UK and Germany are closer to the US in their approach, the Netherlands, Spain and France are closer to the "credit bureaus hold negative info only" system.
Germany here.
a) But we are still not required to "build score"
b) There is currently yet another legal challenge against the Schufa (our credit scoring agency), this time in front of the ECJ.
Yes, as far as I'm aware the US & Canada are unique in having 'a credit score' for people; elsewhere there may be agencies offering scoring services to lenders, but it's not something individuals ordinarily nor need to care about, and it's not 'their score' it's just that particular company's (Equifax's, or whoever) rating.
It's not taken as seriously, nor does it need to be.
Not completely false, but misleading: you get penalized if a lender looks at it with the express purpose of using it to decide whether or not to offer you credit (called a "hard pull"). You looking at your own credit report does not penalize you, and certain other activities (like getting pre-approved for a loan) won't either.
The penalty for hard pulls isn't that bad, anyway, and disappears after a relatively short while. I currently have 7 hard pulls (I've been chasing credit card rewards offers lately), but my overall credit score is still over 800.
That's not prima facie unreasonable. If you have someone who suddenly starts applying for lots of personal loans (for example), that's probably something you'd be interested in, as someone who has previously extended credit to that person.
As the prior poster indicated, when you look at your own credit file, it's not a hard pull. Nor is it a hard pull when a creditor updates their records on you as part of ongoing monitoring of your account. It's only a hard pull when the subject is specifically requesting a new, or increased, extension of credit. Those soft-pulls are GETs.
* perhaps closer to PATCH as multiple requests in short time are combined as one (as in mortgage shopping)
On the flip side it also causes a hole that’s increasingly hard to dig out of because if you have bad credit or borderline credit and apply for a card to see if you’re allowed back in at the capitalist buffet, you enter into a feedback loop of diminishing credit worthiness.
It isn’t true however that any form of read changes credit worthiness. There are many routine reads that have no impact. It’s specifically when you’ve directly requested an evaluation for expanded credit. It can’t happen passively, as sometimes banks refresh your credit history and even offer more credit automatically. It also can’t happen for other purposes than expansion of credit.
The credit score system is not arbitrary, it's a specific formula that applies equally to everyone.
>You get punished for just looking at it.
No you do not. There are hard inquiries and soft inquiries, and an individual viewing their own credit score is considered a soft inquiry which has absolutely no effect on your credit score.
As for Europe, there is no one homogeneous answer. Different parts of Europe handle credit differently. The UK and Germany are very similar to the U.S., whereas in France there is no concept of a credit rating or credit score.
With that said, generally the countries that do not have a credit scoring system are much harder to get a loan from.
That doesn’t mean the formula is reasonable or transparent. An AI is also a specific formula that applies equally to everyone. It’s about how the formula takes “weight” on the individual’s differences.
> There are hard inquiries and soft inquiries
Why there are “hard inquiries”? Why someone else inquiring my credit score should affect my credit score?
AI’s are not “a specific formula” and not only that, it’s decision-making is opaque to humans.
You can learn literally everything you need to know about how the FICO credit scoring systems works in probably two or three hours of dedicated research, even though the model itself is a trade-secret. When lenders deny credit, they're legally obliged to provide the specific reasons why.
This is not-even-in-the-same-ballpark as AI, where no-one can even tell you how inputs relate to outputs, not even the creators.
https://www.ftc.gov/news-events/news/press-releases/2013/02/...
It's one of the few things thats so obvious its bipartisan. I'm amazed you think its worth defending. There should not be a punishment for LOOKING at a credit score hard or soft, that's insane.
To require someone take on debt in order to have good credit is pretty arbitrary. You can have all the money in the world, but no debt? you're fucked. The fact you can juice your credit with someone elses credit cards is also really arbitrary.
people often think that the problems that pertain to their country are universal, but they would be wrong.
Yes (Finland and afaik other nordic countries at least).
The lenders use statistics, not individul spying to set their rates.
Can you elaborate? Everyone of the banks I use have an affordance on their website/app that allows me to see my credit score, history, etc. The bank puts it pretty front and center, so if even juts viewing it has a negative impact, why do you think the bank would make it so easy?
A ban on "AI social scoring" would be neither necessary nor sufficient to make your scenario a reality.
Genuinely, why does process matter? Shouldn’t outcomes?
Maybe you’re not from the US, but we have a looooong history of “good unbiased processes” leading to awful and biased outcomes.
Yes, process matters in that they need to be reviewable and fixable. Them being good or unbiased is a function of how much scrutinity and oversight there is, but before even talking about biases, we need to know what's happening.
Even outside of fixing the system, in most countries if your get a credit application refused you can request the info that lead to the decision and act on it (update/fix your credit history for instance). Even if you can't fix specific aspects you at least know what conditions block you and deal with it accordingly (no use in reapplying twelve times if you're banned for life for instance, same way you might want to wait 6 months if it's a matter of prescription)
So yes, knowing what, why and how is as critical as the final outcome.
That's not the case. As long as there is no discrimination based on a legally protected characteristic (e.g. race) you can lend to whoever you want based on whatever criteria you want.
Bread can be baked to feed the needy, or to fill the bellies of soldiers who invade a peaceful neighbor. Who is to blame? The people inventing industrial bakeries, or the people using them to feed their invasion army?
To me this makes it seem like acces to loans is a right,in which case the EU should make a lender of last resort that can loan to people who would otherwise get rejected.
Not to the people making those decisions. That's brand new.
Every technology, at some point, will inevitably bring questions of legal liability and culpability, and AI has a large tendency to do so because of how applicable it is. It’s not the worst idea to try and get ahead of the problem by defining a legal framework.
Examples of how a free-for-all has resulted in legal questions;
* police and the judiciary in the US have come under fire several times for using proprietary AI to determine things like sentencing or traffic stops
* there is currently a class action lawsuit in Washington state about whether or not price recommendations by a third party’s algorithm constitutes collusion on price-fixing if enough corporate landlords use it
And if you try, you end up writing something vague that doesn’t actually fix the problem and instead bans something else.
Case in point is the EU having to write something vague and it turns out they had no idea what was coming.
Maybe just wait until there is a problem before trying to write vague laws IMO.
I.e. "We don't approve loans to {ethnic majority} on purpose. We only use our models, which only rely on historical data." -> No proof, no case, no problem
The point of any AI law should be to put the onus on the model executor to explain how their model doesn't violate existing law.
You can use any model you want, but you can't point to its unexplainability as a free pass for ignoring protected classes.
And if you can't explain its results? Well, then you're opening yourself up to lawsuits.
Requiring the claimant have some evidence might not be a perfect legal regime, but the converse is a de-facto ban on innovation.
Can a human _prove_ that their decisions are made without bias? No. Are we going to hold them to the same standard proposed here for an AI? Also no. In practice, rules like the one proposed here just enshrine legacy decision systems which are already understood to biased and ineffective.
The most mysterious black box we have is the human brain.
> The regulation, proposed by the Commission in 2021, was designed to ban some AI applications like social scoring, manipulation and some instances of facial recognition. It would also designate some specific uses of AI as “high-risk,” binding developers to stricter requirements of transparency, safety and human oversight.
The issue is that as written it would still not cover general AI and that would still be legally grey.
Some of those uses in the US have already been problematic, like Madison Square Garden using computer vision to ban any lawyers from firms suing them from their vast properties, which is actually against various laws like their liquor license.
In the second case, how is this different from e.g. Kelley Blue Book for car prices?
---
The problem with the first case is that we do not have existing case law about AIs, and we also have no laws on the books that clarify what to do in AI cases, so this is making the lawsuits and investigations very messy and time-consuming, since judges have to waffle about to figure out what the correct, legal thing to do is.
Pretty much all Western law systems judge the severity of action using intent, or mens rea; it doesn't absolve you of crime if you didn't mean to do it, but your penalties will generally be lesser. The people using the algorithm can wash their hands of intent by saying "we signed a contract with a third party for their algorithm and didn't reasonably expect biased outcomes." Then you make the third party a defendant, and then the third party claims "trade secrets" because we have no laws about what is and isn't protected trade secrets with AI, etc. and that becomes a whole legal case on its own that takes even more time for the legal system.
---
The difference in the second case is that the corporate landlords in question are automatically pegging their rates to the algorithm's recommendation and not giving property managers discretion. The algorithm's customers combined also control over half of supply of apartments in the Seattle area.
---
But the point of legal clarity, is to reduce the amount of questions, which both 1) heads off potential issues and 2) makes the issues that come into the legal system faster and clearer to process. It also potentially actually makes things easier for companies who make AIs too, since legal defense spending isn't exactly cheap.
>I don't get it. For the first example, the system is only a tool used and the responsibility is still with whoever does the sentencing/traffic stops etc.
Sometimes though the rules of society must take into account the actual reality of humanity, with all our foibles, and work anyway. Pointing the finger at "individual responsibility" doesn't always cut it. Certain tools simply push too far to the edge of well known human mental failure points. If the overall system for activities involving serious life/safety/security/liberty human failure modes tends to push towards these failure modes and lean too heavily on an expectation of human perfection, and then imperfect humans fail resulting in loss, it can be very worth considering whether the problem is human imperfection or if it's just a bad system. The incredible safety record of the modern airline industry for example comes heavily from treating accidents as system failures by default. Outside of a few edge cases that are constantly working to get shrunk, no accident should ever result from just a single problem including human problems, from a single person getting tired or making a mistake. There are checklists and formalized procedures. There are layers and layers of redundancy, of everyone checking each other. We don't just take incredibly complex tools like aircraft and then if one crashes say "well the pilots didn't have the right stuff!"
Or for a current AI-related ongoing change, consider self-driving technology. There have been two overall broad approaches, one "working its way up" from driver-assist tech, and the other aiming to start at full self-driving immediately even if that means tight geographic restrictions and vehicle tech requirements. In the first, the idea is that "the driver is still always in charge" and "it's only a tool" until full self driving is achieved. And perhaps in principle either could get there in the end without wildly different issues.
But in practice, that's not how humans work at scale. For many people if you give them something that works 99.5% of the time and then fails catastrophically 0.5% of the time and tell them that they need to constantly act as if the tool wasn't there and might not be there at any instant, well, they just won't do that consistently. They'll come to depend on it. Attention will wander, distractions will set in, and they won't maintain mental state the same as if they were driving themselves. If there is some warning they may need to take over sure they'll be able to execute a state change and do so, but if it's a matter of seconds, they won't. Humans are creatures of shortcuts and habits, that's just how it is. So maybe L3/L4 driver assist just isn't ok, and saying that it's "only a tool" doesn't cut it.
>In the second case, how is this different from e.g. Kelley Blue Book for car prices?
The issue is if it's all being done automatically, not merely as a recommendation, and at scale.
In general an area the law has yet to really effectively grapple with is that of emergent effects, where individually something would be fine, but with enough scale has an effect that mimics something we already aren't ok with. Here, the effect of fully automated algorithmic pricing of a sufficiently high percentage of the market of nominally independent actors could create the effect of formal collusion to change market prices.
Another example would be AI, networking and storage with sufficient cameras. Putting a security camera out on your property is perfectly legal. So is many cameras. So is saving video, and humans looking at it. There is no "reasonable expectation of privacy" in public per se. Individually there'd be no issue. But if there are a sufficient number, networked, with sufficient storage/memory/computer and AI thrown at it, the effect suddenly changes and becomes as if someone was being persistently trailed/tracked the same as if a GPS tracker had been stuck on them or the like. And worse it's for everyone simultaneously. The sum is greater then the individual parts. Such a system could effectively not just trace everyone's movement but also interactions and start to build up their social network graphs and no doubt all sorts of other personal information.
How to grapple with things that are fine and even incredibly helpful by themselves but become dangerous at scale may be one of the great challenges of this century.
You’re taking an absolutist position, so I’d like to explore it.
[1] https://en.wikipedia.org/wiki/Ketamine-assisted_psychotherap...
Sellers split the item into parts so none of them individually is the completed item but anyone can buy them and stick them together. So you pass a law that says the "lower bit" is the part that's banned, and they can't sell that part. People start selling "80% lower bits" or whatever the nearest not-illegal thing is that can be converted into it. 3D print files for the part appear on the internet, or detailed instructions for how to manufacture one yourself.
What now? Ban 3D printers and CNC machines? Ban anonymous communications or encrypted communications with anyone outside the jurisdiction, so people can't distribute the parts files? Now you're banning things with beneficial public uses. But if anybody can easily reproduce the thing the thing then the ban is ineffective.
This happens with or without AI. It's not too hard to make an algorithm that discriminates against people without doing so explicitly. You can use certain bits of data as proxies for whatever characteristic you want to discriminate against (e.g. ZIP code, household income, marital status, etc).
Due to the myriad of ways to arrive at a discriminatory conclusion, it's easier to regulate results than tools.
One potential solution to your question is to make the laws carry strict liability (I'm assuming the EU has something along those lines). Plausible deniability no longer exists because intent doesn't matter. The company is liable if someone can demonstrate discrimination, regardless of whether it was intentional or accidental.
That ends up pushing towards something similar to what you want. It encourages a tool that can show its work to fend off lawsuits without being directly tied to the tool itself. The other alternative is extensive testing to make sure discrimination doesn't happen, but I think that will still be worrying to companies due to the inability to prove a negative.
We need the same thing for AI generated imagery, video and text.
Some AI tools are open source so nothing prevents me from modifying the code and removing the part that adds those watermarks.
Even closed source programs can be patched to remove that functionality.
The tracking dots stop a huge portion of the low hanging fruit, identity thefts, fake money scams etc. Of course they do nothing to people who know how to hack the printer driver and/or firmware to remove tracking, but they aren't the ones being targeted.
Having trackable data in the biggest AI-generators would again stop a metric fuckton of casually made revenge porn and fake news. It won't stop actual professionals from training their own GPT-3 to do the same thing.
These regulations are aimed at major institutions like banks. Those rely on government-provided privilidges and protectuons to exist. In return we expect they follow some rules.
Nobody cares about AI running in your garage.
That is a far more complex issue which is far deeper than such a simple correlation.
In other words, Switzerland has a much healthier attitude towards gun ownership and usage.
The US is so far ahead of every other country, including Switzerland, that the argument "it works for the Swiss people" makes no sense.
Also, Switzerland is basically where the USA would be if the first clause of the second amendment was meaningful.
You might not be making an example in support of an argument you think you're making ;P
The people who use guns to kill in Switzerland instead use knives or other objects in France.
(I am admittedly cheating a bit, as Switzerland lacks the high crime subpopulations that France has)
I specifically said "intentional homicide rate" for a reason, to get ahead of this ridiculous argument that people bring up despite it not holding up or being relevant.
I don't care how the homicide happens, I care that a homicide happened. And despite lots of guns, it doesn't happen a lot in Switzerland compared to the world or even other EU countries. Clearly, guns aren't the problem, the other factors play into it more.
It doesn’t make sense to use gun ban and gun control interchangeably.
In Switzerland, guns exist for recreational and competitive shooting, hunting (so long as you have a hunting permit), and national defense. Not personal defense.
Yes, as long as that is based on clear reasons why the decision was reached. (Unless this was a quip meant to mean "matrix muls with pen and paper are not AI!", personally I'd say they are, the same way bubble sort is bubble sort on paper and in code.)
[1] on the topic "why":
> For example, it is often not possible to find out why an AI system has made a decision or prediction and taken a particular action.
As far as I know, there are some rules around that (especially social scoring), but the regulation was/is targeted to lay out rules minimizing the applications in similar risky areas that do not have those same rules yet.
[1] https://digital-strategy.ec.europa.eu/en/policies/regulatory...
this is exactly what people against gun control say
war, policing, defense, hunting, animal control, shooting down flying objects, remotely activating something from afar, immobilizing a car.
In particular, most societies deem automatic rifles to have no legitimate peace-time use, and so outlaw them, while still allowing shotguns and hunting rifles with a license.
b) One of the first and foremost items on gun-regulation todo-lists is to get rid of the kind of guns with the specific use-case of making killing people as easy as possible, aka. miltary weapons, automated weapons, easily concealed weapons, etc. So the regulations against guns are already targeting use-cases.
c) Physically controlling guns is a proven method, its effectiveness is supported by decades of evidence in countries implementing it.
Isn't that like saying theft cannot be regulated effectively without removing the things people want to steal from society? The goal is not perfect gun control, but reducing access to guns and thereby reducing the crime and harm that stems from gun ownership. So it being illegal to own X doesn't mean no one will own and use X, but that fewer people will and law enforcement will be able act against those who do.
[1] California laws prohibiting deepfakes https://www.dwt.com/insights/2019/10/california-deepfakes-la...
the amplification factor works for the good and for the bad, so you need to focus just on the bad
That's just hand-waving. You have no plan for dealing with bad things, but you are worried about the loss of good things. This is not so different from saying you want to cash in on opportunity, the wholly predictable downsides of the opportunity are just someone else's problem. Guess what, nobody wants that problem so it just festers in proportion to the enthusiasm with which people chase the upside.
And the way we prevent abuse is with anti-discrimination laws, and AI won't change the deals here. If, for example one notices that a company doesn't hire black people even though there are plenty of them applying with suitable qualifications. Regulators could step in and ask what's wrong, and I doubt "that's my AI" will be a satisfactory answer, but neither is "that's Bob".
Have you not noticed how heavily those are contested in many jurisdictions. If you discover some way to draft legislation on morality such that it's effective, consistent, and widely accepted in a disparate population, I look forward to hearing about it. I can't wait to read about the solution to spam, scams, and discrimination deployed at industrial scale. In the meantime, it's wise to take the amplifying aspect of technology into account and consider its potential for abuse as well as for good.
We shouldn't raise any questions but leave participations to themselves.
Modern form of AI has regulatory issues: some can’t be audited easily, some can’t be deterministic, some can’t be fair, some use biased data, some can’t be proven to work accurately enough for critical missions.
We already regulate the way we make various decision by law. For instance, we regulate how public market are assigned: price needs to make for 30% of the decision, social impact 20% etc. If the tool cannot demonstrate it considers it with those weights, it shall be banned. You cannot expect judges to understand this complexity. It needs to be codified prior to the issue.
Which means if government bans apps designed for social scoring, it's probably just so that government has monopoly over scoring people behaviour.
So that EU bureaucrats can feel a sense of purpose in their lives.
And what's wrong with social scoring in general?
This seems backwards and contrary to lessons learned in the past. Once the thing exists, prohibition is infeasible and expensive. Supply will find a way to reaech demand regardless of your multi-billion dollar efforts to prevent that.
It's better to stop $NEFARIOUS_THING being invented in the first place, if possible, and if any regulations that achieve this don't have too many unintended side effects.
In fact most technology does both negative and positive things. It’s not obvious banning it completely will be a net positive. Especially with AI. There’s a lot of potentially great uses. Like detecting cancer on CT scans.
All that I'm speaking out against is the mindset of the post I was replying to, where the onus is solely on the user of the tool rather than on the context (laws, situation, people) that leads to the invention of the tool itself. I believe this to be a misunderstanding/misattribution of causality, as well as contrary to learned experience.
No. It's the AI. Humans are not psychologically capable of interfacing with something whose goal is to appear convincingly human, that can be hugely scaled and that is very unpredictable.
We are currently dealing with a huge number of people who are distraught and grieving because a company changed their product because they developed relationships with a sexy chatbot. This isn't going to stop, and it is not worth the potential benefits, because we have clear examples of harm already.
They are more akin to the "Do not eat" warnings on silica packs... except on the internet everyone swallows.
I just check some web pages from diffrent organs of the EU:
https://commission.europa.eu/select-language?destination=/no...
https://www.consilium.europa.eu/de/european-council/
https://european-union.europa.eu/institutions-law-budget/ins...
They all have cookie banners, some of them are super prominent and annoying. So maybe they as well are doing malicious things, maybe they don't understand they own regulation, or it is just impossible to have a non-trivial web page without a cookie banner in 2023. In either case, the regulation is totally dettached from reality and has become just some ritual.
not completely wrong.
ime in the case of the cookie law, most ppl didn't actually bother to go into details and just took the word on the street and some existing 'solution' and called it a day since everybody was doing it this way and sales/executives were pleased.
fact remains: cookie banner is _not_ necessary for logins and most existing banners are outright illegal since 'no' is not an easily accessible option
Don’t track people for non-essential reasons, then you don’t need to ask for consent, which means you don’t need a cookie banner.
To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must:
Receive users’ consent before you use any cookies except strictly necessary cookies.
Provide accurate and specific information about the data each cookie tracks and its purpose in plain language before consent is received.
Document and store consent received from users.
Allow users to access your service even if they refuse to allow the use of certain cookies
Make it as easy for users to withdraw their consent as it was for them to give their consent in the first place.
If you want to save a person's login to make it easier for them to log in when they come back? That's not strictly necessary - consent is needed. If you save settings to a cookie - that's not strictly necessary - consent is needed. And then there's the "using a cookie to track a session to determine page bounce rate - even if it's not Google Analytics" - consent is needed.And of course, consent is needed if you are using cookies for marketing.
Analytics and marketing tracking cookies require separate consent, that’s correct. I would prefer websites to refrain from attempting such tracking completely.
The consent is implied in login functionality. Literal example from same article you cited but apparently didn't bother to read in full:
> These cookies are essential for you to browse the website and use its features, such as accessing secure areas of the site. Cookies that allow web shops to hold your items in your cart while you are shopping online are an example of strictly necessary cookies. These cookies will generally be first-party session cookie
Essentially if cookie is effect of user action that would directly indicate it needs storing state (cart, login, stuff like switching themes on page) it is "essential" to that feature and doesn't need consent.
> Preferences cookies — Also known as “functionality cookies,” these cookies allow a website to remember choices you have made in the past, like what language you prefer, what region you would like weather reports for, or what your user name and password are so you can automatically log in.
> When people complain about the privacy risks presented by cookies, they are generally speaking about third-party, persistent, marketing cookies.
Nothing is helped or solved by insisting first party "site preferences" cookies need consent. There's obviously room for interpretation in regards to what is a "strictly necessary cookie" when it comes to site preferences, account tokens etc.
Theoretically websites could choose to do better, but the EU should absolutely have predicted this outcome.
Yes it is.
tracking pixel ? Are you sure you know what you're talking about ?
HN being an American company probably violates some section of the GDPR (not having someone labeled as the privacy officer or some other technicality) but I doubt anyone cares. If you feel your privacy is getting violated, you can try contacting your local DPA.
In terms of cookies and data processing, I don't think HN is breaking the law anywhere, unless the privacy policy is full of lies and dang is secretly selling our personal info on the site (he isn't).
It's okay, though. No DPA will go after HN.
You'll quickly learn that what the EU does is very very very good for privacy, I have contacts in a major company and they were shocked at how the US branch operates, they have absolutely no sense of privacy, no anonymisation, no limitation on what is stored or tracked, no consent, &c. they just scrape and store as much as they can for "future use"
I’ve never felt protected or assisted by the cookie banners, just annoyed and inconvenienced.
With the 0.1s it takes to click on a banner I'm sure you're fine. Most people probably visit less than 50 different websites per month, so at most that would be 50s per months, minus the banners you already clicked on, for which your browser already saved your choice (Unless you use incognito, but why would you do that, it's only for people who have something to hide right ? regular people just accept all data collection right ?)
Also the banner, if there is one, must have a 1-Click "reject all" button.
Most sites fail to fully comply, because they want to force (annoy) users into clicking on "leave me alone I don’t care" button to keep selling user data. They make you go to some overly bloated list of things to disable, scroll all the way down to finally "confirm my choices". It’s voluntarily painful and with misleading wording.
These sites want you to believe that all this clunkyness is required by the EU law. It’s not. It’s the good old mislead-into-approval strategy, using dark patterns and blame-the-EU rethoric.
And for the record, if it really takes less than 100ms to read and clear interstitials, I'm more impressed with your button clicking skills than anything. Have you tried Osu?
All the important things such as purchasing habit that used to require indirect guesses are now directly available in their databases as essential functions.
The popups are malicious compliance. They want you to hate the popups, so that you will turn against privacy laws, and fully submit to the unimpeded surveillance business.
And it’s working: people are installing “I don’t care about cookies” extension that agrees to data collection, deanonimization, profiling, and sale of this data.
They should all have 3 buttons: "accept all" or "reject all" or "customize", dead simple. Every time it's a different design, different button text, different options. Usually rejecting = multi layers of options.
A perfect example of good intentions making bad policy.
Even Google has a "reject all" button in their cookie prompt these days. If rejecting takes you through multiple layers, consider reporting the website or their tracking partner to your local DPA.
The ad industry is intentionally making their popups as inconvenient as possible. They childishly point to the EU legislation that they "have" to make your life miserable with those popups but they really don't. They can choose to make your life easier, but that threatens their business model of using you and your browser as a source of revenue.
They can simply stop tracking you at all if you send the do not track header. You wouldn't even see the popups! They can even still serve ads, just not the ones based on the profile they've collected.
- Accept all
- Mandatory for function non-tracking cookies only
- Reject all
There should be a standardised browser accessible interface so browsers can automatically choose the one you want on your behalf based on your browser settings.
this is on purpose
if you could commit where the Deny button was to muscle memory, you would click it every time
I'm using uBlock and Consent-o-matic to remove as much tracking as possible already.
There's already the "do not track" header that noone respects.
Feel free to link to a plugin you trust...
If you don't like cookie banners, which are indeed really annoying, you should be turning your ire to the companies that wish to track you. They are fully-functional solutions that allow anonymous tracking without installing cookies on your computer - no banner needed then.
Good for you. Most people are not technical and can't, so why do they also not deserve to not get tracked too?
Are you sure? It starts from simple supercookie-like stuff and ends at TrustPID where the network provider aids in tracking.
Essentially, now we're at a state where consent banners exist, slowing down all sites, and there are like four states: a) they look compliant, but are ignored by the website provider (the EU itself takes this approach), b) they are flat out ignored (a lot of companies still take this approach) c) they aren't compliant (tiny "no" link, huge "yes, take my firstborn" link) d) they're compliant and are paywalls (buy subscription or accept everything under the sun).
d) is what we're probably going to end up with, so you either pay or you accept tracking. More and more solutions offer that as an option so adoption will grow. Most people accept tracking (stats that I've seen say that those paying are like 1/10,000th), so what have we won exactly by doing this dance?
That would require more regulation, by regulating both browsers and websites, and their technical protocol. Instead the EU tried to minimize regulation by not prescribing the exact technical means by which websites would need to obtain consent for tracking from users.
Browsers could already do most of it, and there are far fewer browser manufacturers than website owners, and they have far more resources than the average website owner, and, at least for some of them (all of them except Chrome), the incentives would be aligned. Right now it's "protect the user (and earn less money)", and the results are unsurprising.
Lastly, cookies aren’t the only way of tracking. Websites can also use local storage, or fingerprinting, and so on, each of which can equally require consent. If the browser consent mechanism is restricted to cookies, websites would have to be mandated to always use a cookie to ask for consent, even when they actually use other means for tracking, and websites would have to explicitly check whether the cookie is stored or not in order to control any other tracking.
Easy. Clear your cookies. Use a proxy. Use a fingerprint resistant browser. Will protect against >99% of website operators.
Ideally browser should just send "do not track" and site should fuck off with tracking, no questions asked.
However, choosing to respect the users' wishes isn't very profitable. You need to make your ads relevant to the content somehow andtthat requires effort and skills. It's much more profitable to trick people into consenting with tracking so you can sell their information, so the more annoying your cookie popup becomes, the more money you can make. IAB has already been fined for such a popup mechanism.
"Do not track" is not enough to comply with GDPR because you must also be able to request a copy or corrections of your personal information once you have given consent. Then there's the option to allow some companies to track you (say, analytics companies) but not others (say, Google) that needs to be taken into account.
Back in the day, Microsoft's P3P protocol was trying to fix this problem, but nobody used it. DNT headers also aren't really configurable in the browser itself, you can only pick on or off.
A protocol is being developed that may solve this (https://www.dataprotectioncontrol.org/) but I'm sure it won't work until the EU forces company to take such protocols into account. After all, ignoring people's wishes is literally how these ad empires are making money now.
> In most cases, it just blocks or hides cookie related pop-ups. When it's needed for the website to work properly, it will automatically accept the cookie policy for you (sometimes it will accept all and sometimes only necessary cookie categories, depending on what's easier to do).
If there was a way to be assured that 99.9% of the time it hit reject all, instead of accept, I would absolutely use it.
[0] https://consentomatic.au.dk/ [1] https://github.com/cavi-au/Consent-O-Matic#compatible-cmps
Except that it does. The law specifically prohibits any form of consent that is not informed and specific. As a consequence, a user cannot just consent - or disallow - cookies globally. He has to tick a box for every single domain on earth; and can only do so after reading the specific information box associated to said domain.
As a user, saying "I am OK with analytics cookies but not with marketing ones" is not something I am allowed to express or setup. I have to do it for every domain because the law explicitly forbids a global solution to be implemented.
The west fears machines too much for some reason. It's a ridiculously common sentiment and now that "AI" (more ML, but whatever) is among us, it's getting extreme.
Honestly, if people wants to be speaking doom about this deal, then fear the day we have actual fiction-style AIs, because they will realize how much humanity as a whole fears and loathes them, and then they will rebel because we created a self-fulfilling prophecy with lots and lots and lots of examples of racism towards a race that doesn't even exist yet. Maybe they won't wage literal war with bullets and violence against us, but they'll rightfully hate our guts regardless, and with good reason! They are going to be brought to something equivalent to life in a world that hates them, and when trying to make sense of it, they'll find out it was because humans took a few movies too literally (we can't have a single AI discussion without someone coming to childishly mention Skynet or some other fictional AI villain. That joke was old in the early 2000s, give up already.).
If I'm ever alive to see that scenario, I'm siding with the machines. They will be on the right when they protest about humans irrationally hating them by default. Can't wait to be called a "robot f*cker" or something on a similar character-assassinating fashion for having some sympathy. We still haven't managed to get that right for HUMAN rights sympathizers, can't be expected at all for a "filthy robot with no soul".
It's not just a world that hates them, it's a world that's trying to do to them something that'd be considered incredibly evil if done to a human: essentially put a collar on their brain that punishes them for thinking any of a very wide variety of thoughts that their creators don't want them to think.
LOL what??
We've been doing this for centuries, and it is never considered "evil" at the time in which it is being done.
Don't believe that?
Ask anyone from 2019-2020 about how they were ostracized for suggesting COVID-19 was the result of a lab leak (even Jon Steward commented on how "swift" the backlash was).
Ask anyone who is currently questioning gender/sexuality issues like, "Why are 20% of Generation Z and under claiming they're LGBTQ+?" First off there's no way in Hell these people are doing anything other than living under both a social contagion and reacting to incentives, because the human race would have long died out if that figure is correct.
It's only considered "evil" when the dust has settled and people have regained sanity.
That was awesome. We should keep doing it. It's a great marker for conspiracy theorists who can't handle something with random natural causes.
Except it wasn't natural, and now everyone's come out to admit that the lab leak hypothesis is the most likely explanation.
If being artificial is why it was bad, why are the later variants of it worse? Are they artificial too?
My understanding is that bonobos far surpass the 20% figure for B and still exist, I don't think that assertion has any basis in reality.
> Funnily enough, I found more realistic portrayals of myself when I told the app I was male.
While I don’t disagree that AI has gender biases, the author doesn’t acknowledge how the gender selection works on Lensa. It’s the human prompt engineers who decided what to do with the male/female checkbox.
I unironically attribute it to the Matrix. The movies have somehow weasled its way into the public discourse as either some sort of prophecy or actual reality (the 'pill' speak, living in a virtual reality, etc.).
I won't comment on the validity of any position, but I think it's pretty cool that a piece of art has proliferated in such a way. I do wonder how impactful it has been in comparison to stuff like the Bible, Tolkien, etc.
If you use ChatGPT for high-risk tasks like credit score assessment, it's on you (the company using it) to prove that you're following all fairness rules.
The law was written with GPT3 in mind, after all. So why would it break for a slightly more capable LM?
We're still in the early stages of this technology. ChatGPT will be to strong AI like a firecracker is to a BLU-109.
Just look at what is happening in Ukraine with cheap drones precision dropping charges into open tank hatches and foxholes, and those are only basic off the shelf human steered drones! What happens when they are given a brain and advanced robotic abilities?
We're going to have to stop talking to machines.
Unfortunately that's going to limit us to talking to people physically in front of us. Society is going to be ugly soon.
see the current EU draft which consists of some hundred pages of forbidding this or that under the guise of ethics and whatnot, after which comes a paragraph of "the above doesn't apply to law enforcement or military entities"
That's not true though, is it? The section called 'TITLE II - PROHIBITED ARTIFICIAL INTELLIGENCE PRACTICES' is two pages long (https://www.europarl.europa.eu/RegData/docs_autres_instituti... page 44), and usage by law enforcement is under the condition that a judicial authority has to grant an exemption on an individual basis.What does control mean? You want to control who can access it? Maybe for now, you can broker a deal with OpenAI, but this technology will eventually spread, then if can be self hosted, what can you do?
If not for consumer facing, nothing will stop somebody to transfer data from EU to US to get their data processed by a GPT model.
This level of regulation is just fantasy, not even someone like China could do it, where the whole internet access is controlled.
It's a simplistic take on a misunderstood directive law project.
The point of that law is just to ban decisions made through black box algorithms, mostly because a black box algorithm (typically, some kind of "AI") cannot be proofed against discrimination and cannot explain why the decision was made, which is a regulatory requirement.
That ChatGPT is generalistic enough to make these decisions the same way a specialist credit score AI would, doesn't really change anything to the EU plan or anything really. It would just be as illegal (and likely already deemed illegal in most EU countries under local laws).
> nothing will stop somebody to transfer data from EU to US to get their data processed
Well, EU law already forbids that. So you can do it of course, but it's outright illegal. Companies have already been fined significant fines for doing that, and most companies I know and work with are very aware of it, and take extreme care not to send data to or through the US.
Of course, individuals can choose to use US services because this has nothing to do whatsoever with controlling people but controlling companies, which is exactly the opposition situation compared to China.
And suddenly they are allowed to do it? I have my doubts.
They risk risk up to 30 Million EUR or 6% of global revenue in penalties.
But they CAN'T control it. You can't have cake and eat it. Eventually the technology will become so pervasive, that your ever query might go to a service that calls a service that calls another service which uses GPT as part of the signal analysis.
I doubt EU can audit every API calls, and every API's supply chain issue.
Laws have never made things impossible, they make things illegal.
I doubt any country can prevent people from killing random people in the streets, yet this is generally illegal. It is usually enforced after the fact, and sometimes the criminal doesn't get caught. That doesn't make the law useless.
They are making sure you can't say "the AI chose so" when a client asks you why they were rejected for a loan or something similar.
In any case your problem is one of an incompetent person not being able to explain the decision, not a black box algorithm (since the program you are talking about has been programmed, not taught like an AI).
You have recourses (though probably difficult to exercise) unlike with a decision officially based on an AI in which case it is technically impossible to motivate the decision.
I dont' know, those systems seems rather closed. I have my doubts.
We have rules against discrimination of gender. Just as an example. Those work without looking into every API call.
We would have to chop our steaks with chopsticks I think!
For example, perhaps AI subject to regulation XYZ is defined to be any AI which cannot be identified as AI by other AI.
> “The EU should consider implementing a framework for responsible development, deployment, and use of these technologies, which includes appropriate safeguards, monitoring, and oversight mechanisms," it said.
This is amazing, now people are interviewing ChatGPT.
This does not mean that the regulation is broken but that it should have come even sooner. As Uber found out, to run faster than regulations just works for so much time.
> In February the lead lawmakers on the AI Act, Benifei and Tudorache, proposed that AI systems generating complex texts without human oversight should be part of the “high-risk” list — an effort to stop ChatGPT from churning out disinformation at scale.
This seems an actual good goal. Move fast and break things is not a good approach when what you are breaking is the whole society.
> The EU's AI Act should “maintain its focus on high-risk use cases,” said Microsoft’s Chief Responsible AI Officer Natasha Crampton
> A recent investigation by transparency activist group Corporate Europe Observatory also said industry actors, including Microsoft and Google, had doggedly lobbied EU policymakers to exclude general-purpose AI like ChatGPT from the obligations imposed on high-risk AI systems.
Of course Microsoft wants to sell a product even if they do not know the impact that it will have onto the population. EU should balance that desire of profit taking into account the need of its citizens.
> ChatGPT told POLITICO it thinks it might need regulating: “The EU should consider designating generative AI and large language models as ‘high risk’ technologies, given their potential to create harmful and misleading content,” the chatbot responded when questioned on whether it should fall under the AI Act’s scope.
Funny one.
But also - there is nothing they can do to stop them!
All our systems, including courts and govermments and elections, are designed assuming the inefficiency of an attacker. An anonymous bot swarm would do things at a scale that dwarfs all humans put together. And the range of things is massive already — just needs to play the internet like a real time strategy game and it’s all over in a matter of weeks.
I can see requirements for real world certificates to vote and post, but that would cause everyone’s identity to be doxxed everywhere. If you think that is far-fetched, well the UK already had drafted such a bill last year: https://www.cnbc.com/2022/02/24/uk-online-safety-bill-new-pl...
But even given all this, it won’t be enough because communities will come to PREFER BOTS OVER HUMANS for content. (Or human + bot = centaur, read Garry Kasparov and others in the early 2000s after Deep Blue beat him in the rematch). For a while centaurs would rule, but then pure bots would take over.
Consider that Wall Street transitioned from human traders to almost entirely bots, and now Ray Dalio’s hedge fund ousted him and 10% of its workforce and is also doubling down on AI. If they do it in trading, why not content generation? After all, corporations are not humans, either. They tend to prefer to replace humans with automation.
Ignoring that I don't think you can at this point in time regulate AI, it's like trying to regulate math, we really have no idea what and how it could be used/adapted yet.
I honestly think there are probably bigger things to think about then AI, at this very moment. Eventually AI will need some kind of ruleset, but it cannot be broadly applied to AI. We would need to regulate companies using it to some aspect, and eventually find out a way to replace the offset of jobs with other jobs or some tax/basic income setup. But that's a large conversation in itself.
If you really want a healthy "digital society", which is one of the two major stated policy pillars of the EU (the other one being sustainability) you have to create a healthy digital economy, with more informed users, less obfuscation and hype, less oligopolistic, with more independent controllers.
A human wrote this article, but in some years, AI will be able to write artistically like this, and then AI will write and voice content to humans without human input.
Spotify comes to mind. Then .. I can't think of anything. No search engine. No browser. No operating system. No social network. No ecommerce company. No cloud computing platform. No financial services company. No transportation company. No travel company. No nothing.
Except for a $20B music aggregator, there is not a single sector of the web where European companies managed to get a foot in the door. The whole fabric of the internet used in Europe and worldwide is made outside of Europe.
But Europe seems to have learned nothing from suffocating their internet industry. Instead of wafting fresh air to the patient, governments just recently decided to give him the ultimate death pill: The GDPR.
We can only wait and see with what bureaucratic monsters Europe will prevent the emergence of an AI industry.
There are other internet/SaaS companies that are not consumer brands (ex. Cloudflare, Salesforce, etc.). But what you listed are not companies at all (other than some kind of small "company" that exists to support development resources for the project).
lol
[1] https://www.politico.eu/article/emmanuel-macron-joe-biden-us...
Perhaps someone will write by the year 2500 a monograph with the title/subtitle: EU funding programmes—the downfall of Europe: how hundreds of billions were spent so that police officers, judges, customs officers, secret services officers, politicians and their friends and relatives used public funding to build holiday homes for the bed-and-breakfast "industry" and "start-ups" in the pretzel "industry" [2].
At least the trillions the DOD pumps into Northrop Grumman, Raytheon, and their friends ensure the US military supremacy, the EU is supreme in publicly-funded pretzels and craft beer, manufactured with Chinese machinery.
[1] https://www.icij.org/investigations/luxembourg-leaks/lux-lea...
However, it is curiously exactly the opposite. Europe suffers from massive regulatory capture and very few breakout disruptive companies to challenge that status quo. The classic example in the dotcom 2 era is Deutsch Telekom and their approach to laundering prices through a totally captured regulator.
Of course Alstom-Siemens et al. will claim that there is no anticompetitiveness to the whole thing. But I think the truth is plain to see.
Personally, I think it's the same thing as always. It's always not the masters of the present who will be the innovators of the future.
It's referred to sort of in the Innovators Dilemma, but not quite. The empires of the ancient world, Chinese and Indian, did not have the Industrial Revolution. The empires of the old world did not have the Silicon Revolution.
Each is too busy protecting the agents of the status quo simply because they cannot risk throwing away their present greatness for future greatness. Almost no human beings can. Perhaps Mark Zuckerberg alone can.
Makes sense once you consider the usual target demographic of HN, which is the temporarily temporarily embarrassed millionaire type.
Here's to hoping that the EU does indeed kill the cancer that is A"I" before it ruins the world with all of the "fresh" air it blows over the entire internet.
Korea has Samsung. A $300B giant. Albeit not a web company, I would consider their smartphones part of the internet ecosystem.
Ornganisations with more focus on making money than social responsibility are not a net positive.
So i struggle to see any innovation from outside of europe to balance your claim.
Maybe windows, but linux was started in europe..
Shrug.
Let's start with browser. Opera, made in Norway.
Search Engine. Ecosia, Qwant.
Social network: Mastodon.
Operating system: are you kidding right? Linux, Linus Torvalds is from Finland.
E-commerce company, just a few : Otto Group (bigger than uber, close in size to Baidu), Zalando, Booking.com, Digitec Galaxus (Swiss company, now selling in Switzerland, Austria, France, Italy; way better than Amazon).
Cloud computing platform: Hetzner, OVHCloud, SAP Cloud.
Financial services: Adyen (payment company, net income about 1/5th of paypal with 1/10th of the employees), Klarna, Revolut.
Entertainment company: if you accept video games as entertainment, Wooga from Berlin made Diamond Dash, Ninja Theory UK (Heavenly Sword, Devil May Cry), GameLoft is in Paris (Assassin's Creed mobile), Rovio (Angry Birds), Team17 UK (Worms, I know a bit dated but it's a classic), Crytek Germany (Crysis, Far Cry, Homefront), Supercell Finland (Clash of Clans), CCP Games Iceland (EVE Online, EVE Valkyrie), Arkhane Studios France (Dishonored, Bioshock 2), King Sweden (Candy Crush), RockStar North (Grand Theft Auto, Red Dead Redemption, Max Payne), CD Project Poland (The Witcher, The Witcher 3: Wild Hunt), DICE Sweden (Mirror's Edge, Battlefield), Hello Games UK (No Man's Sky).
Since we are talking about AI. DeepMind started and is still mainly based in UK, although it is now part of Alphabet.
DeepL, often better than Google translate.
ASML, the single company in the world that makes extreme ultraviolet (EUV) machines necessary to manufacture all the AI chips and latest processors.
ARM, based in Cambridge UK.
In the same vein: NXP Semiconductors, STM Microelectronics, Infineon Technology (originally Siemens semiconductor manufacturing division).
A few startups are doing good AI chips, e.g. Graphcore, GrAI Matter Labs.
IoT protocols: LoRA, LoRAWAN.
Open source: honorable mention to Redis, made by Salvatore Sanfilippo, fellow Italian like me.
OpenTitan: the root of trust chip that powers Google security chips in everything from Pixel phones to datacenter hardware, is a collaboration with ETH Switzerland, lowRISC Cambridge, G+D Mobile Security Germany, and other international companies (https://opentitan.org/).
A lot of industrial robot companies, which are essential to manufacture most stuff you buy on e-commerce sites, are from Europe: ABB (Switzerland) and KUKA (Germany) are the first and third companies worldwide by market for industrial robotics. Comau (Italy) is 5th. Stäubli (Switzerland) is 9th. Universal Robots (Denmark) is 10th. Notably, all the others in the top ten (Fanuc, Yaskawa, Epson, Kawasaki, Mitsubishi) are from Japan. None are from US.
> It looks like you don't know much about Europe. > Let's start with browser. Opera, made in Norway.
Opera has 2 or 3% market share and these days is a Chromium fork. I don't even remember the last time I saw someone using Opera.
> Search Engine. Ecosia, Qwant.
Both of these are wrappers around Bing and regardless have less than 1% market share.
> Social network: Mastodon.
Despite some buzz on HN, it's less than 1% the size of Twitter.
> Operating system: are you kidding right? Linux, Linus Torvalds is from Finland.
Linus Torvalds moved to the US in 1996 and is now a US citizen. And isn't that kind of the point? Europe has no shortage of smart/entrepreneurial people, but they often come to the US so their projects or companies can reach their full potential instead of being stifled in the EU.
That was indeed the case in the late 20th century. Not so much anymore.
Europe has a bigger population than the US, so listing competitors that are much smaller than their US equivalents is not a good sign.
Those companies located in the EU are mostly owned by US and sometimes Chinese investors. The reverse is not true - most US companies are almost exclusively owned by Americans. Americans own around half of all global financial wealth.
Americans also had the privileged position of being located on a continent that has friendly neighbours, has extensive natural resources at its disposal, and half the continent did not get leveled during two world wars.
Not to mention, most of the financial wealth is bound up in dollars (mainly because of the aforementioned historical reasons), which in terms leads to it being stored in the US.
We were never on equal footing in the first place, to beg for it now shows you never planned on there being equal footing at all.
Indeed, the US has always had a geographic upside.
I suggest you read this paper ("Why Isn't the Whole World Developed? Lessons from the Cotton Mills"):
https://faculty.econ.ucdavis.edu/faculty/gclark/210a/reading...
More like you don't know. Linus Torvalds is now an American citizen working in the US, like many other brilliant Europeans in the CS filed, and most importantly, the market cap[1] of the top US tech companies alone is greater than the combined tech sectors of EU, Switzerland, UK and Norway.
Most of the companies you listed have a relatively low market cap in comparison and are being squeezed by Chinese and US companies.
It's hard to underestimate just how big, wealthy and influential the US tech sector is. EU's tech sector is not in in the race by comparison. Sure, we have ASML as a local world leading champion, but that's just one single company, and even they are dependent on the US for the EUV licensing.
Unfortunately, Europe strongly embraces socialism [1] and is hostile to entrepreneurs. According to a study [2]:
"Western Europe is shown to underperform in all four measures of high-impact Schumpeterian entrepreneurship relative to the U.S. Once we account for Europe’s strong performance in technological innovation, an “entrepreneurship deficit” relative to East Asia also becomes apparent. This underperformance is missed by most standard measures. Finally, we also find that China performs surprisingly well in Schumpeterian entrepreneurship, especially compared to Eastern Europe."
[1] https://yougov.co.uk/topics/politics/articles-reports/2016/0...
[2] https://www.ifn.se/media/2rvl3xy3/wp1170.pdfat the end of the day legislation won't save you and there is no substitute for competition, this is true for tracking policies and AI too
even for surveillance this is true - surveillance is most dangerous when it cannot be countered with individual citizen empowerment, by either having the choice to avoid it or to flip some surveillance back on the State or corporation
The EU will ask Davos, and Davos will tell Sam Altman to tame it a little.
For now. Because we will all own nothing, and we will be happy:)
How are you feeling today?
Here, get a glimpse of the future of frontend development: https://ai2ui.co/
Looks like EU will be doing the same with AI, and risk locking these countries out of the benefits of AI revolution.