EU Artificial Intelligence Act
artificialintelligenceact.eu
artificialintelligenceact.eu
Basically, as I understand it, it divides AI systems (in the broadest sense Machine Learning sense) into risk categories: unacceptable risk (prohibited), high risk, medium/other risk, and low risk.
Applications in the high risk category include medical devices, law enforcement, recruiting/employment and others. AI systems in this category will be subject to the requirements mentioned by most people here (oversight, clean and correct training data, etc).
Medium risk applications seem to revolve around the risk of tricking people, for example via chatbots, deepfakes etc. In this case they require to “notify” people that they are interacting with an AI or that the content was generated by AI. How this can be enforced in practice remains to be seen.
And the low risk category is basically everything else, from marketing applications to ChatGPT (as I understand it). Applications in this category would have no mandatory obligations.
If you ask me, that’s a quite sensible approach.
Remember how OpenAI's Dall-E lost to Stable Diffusion because they were too afraid that someone will make an image of a politician or something? Well we had some fun with Pope wearing Balenciaga and Trump being arrested but nothing bad happened.
> clean and correct training data
If there's a country where majority of poor people have blue skin, and majority of rich people have green skin, and poorer people commit more crimes in general. Then if one of the features (explicitly defined or somehow inferred by model) of your ML model is skin color, it will correctly correlate blue skin as high risk for stealing. So a supermarket chain AI face detection would always flag those more often. And so you'd have AI-scale systemic racism.
Even if that application was categorized as "high risk", since it is "clean and correct training data".
How do you legislate that an AI system can't fall for "correlation != causation" and how can you audit that if there's no clearly define ML model feature, like the simple neural networks studied in ML 101.
In the first instance, you just can't use race as a feature, since it is a protected characteristic. But, you might also be worried that protected characteristics can generally be easily identified by looking for innocuous traits that correlate (since people tend to cluster into communities). For example, if you know an American's ZIP code and their three favorite musicians, you can determine their race with an accuracy in the high 90s. (Basically, the US is still just as segregated now as it was a hundred years ago, and black and white Americans tend to listen to different music.)
So when the US Civil Rights Act was passed, the courts came up with the idea of "disparate impact" -- when doing something like hiring, you are not allowed to base the decision on features that disproportionately affect one group rather than another, even if they are formally neutral, unless the feature directly impacts the ability to do the job.
In other words, you have to show that the features you are basing the decision on _causally influence_ the decision you are making, exactly like you see in Pearl's causal influence diagrams or structural equation models or whatever. Eg, if you want to hire a math professor, you can base the decision on the articles they published in math journals, but you can't base it on whether they like old school Goa trance.
So, what about black box neural networks, where you don't know which features are being used? In this case, it's pretty clear that you shouldn't use them directly when making a home loan, because the law wants to know what features are in use, and you can't answer the question of whether you're redlining when you have a black box. However, using black box techniques to learn (eg) the best random forest model to use is fine, because it lets you easily see which factors are going into the decision before deploying it.
FWIW, people have been doing this for decades already. (I did stuff like this back in the 1990s.)
EU AI Act To Target US Open Source Software
https://technomancers.ai/eu-ai-act-to-target-us-open-source-...
TLDR it imposes ridiculous constraints on github and open source developers
The EU stuff is usually against large corporations who pose systematic risks. Think about how TikTok makes the US freak out about China spying and manipulations, for EU it's the the same thing but include Facebook and all other large social media too(because American corporations are foreign in Europe like TikTok is foreign in USA). US considers banning TikTok, EU's approach is to regulate how data is processed and used in order to keep open market and mitigate risks.
So as a rule of thumb, Europol doesn't knock on your door when you train a model on data that doesn't meet the requirements. This is probably designed to make countries introduce laws which will hold Google/OpenAI etc. accountable for their services so they can't just shrug and say "ouppsy, it's not our fault the AI did it".
I'm sorry to pop the alarmist narrative, but this is not the legislation which is going to "get you".
They just end up making their local tech entrepreneurs flee to US/UK.
Really? Which startups flee due to GDPR?
In my experience as a user, I now have option to download my data and know what's collected about me. I like it.
[0] https://investors.biontech.de/news-releases/news-release-det...
Companies do these things all the time, I guess it's fun to imagine that opening offices in other countries is fleeing and that are fleeing to UK because they are having trouble processing personal data when developing drugs but I don't see why would that be the case.
Fun fact: UK data protection laws are about the same as EU.
Fun fact: Why would UK miss the chance to attract tech companies and get rid of pre-Brexit laws after they went through all the unfortunate hassle Brexit was?
Because UK is not made of libertarians who were under the EU opression but all those EU laws were made with UK's contribution and input. The UK has not become the libertarian utopia and will not become the libertarian utopia inside or outside of EU because the British public at large doesn't want it. If anything, probably the Labour party will win the next elections, the libertarians are very unpopular. British are not Americans and most don't trust corporations and want government involvement in protecting them against wrongdoings.
Brexit's biggest con was that EU is some 3rd party and the British public wants something else. In reality, Brits made the EU.
Which of the new AI labs is setup in EU?
Stability? Midjourney? Anthropic? Cohere? Every single one is either in the US or UK. LLM companies deal with huge legal uncertainties, especially around data and privacy. Hence investors are reluctant to fund any in the EU, and potential founders are deterred. This is all legacy of the GDPR and the 'regulatory superpower' mindset that the EU deluded itself into.
The only new wave AI company from the EU is DeepL, which is going to face really really intense competition from LLMs.
here is a quick watch: https://www.youtube.com/watch?v=5ZdmS-EAbHo
I have no idea why would you claim that with the introduction of GDPR Europe lost on tech. By tech I mean the SV industry, there are many other technologies out there.
Anyway, why all the "tech" is in SV? Do they have GDPR in the other states?
There are plenty of smaller AI startups splattered across the US.
Who is checking for that? Can you give me an example of any public authority within the EU that has the operational excellence to even understand how BigTech is collecting and handling data? For Germany I only see Ulrich Kelber who certainly does not have the competence to even understand how BigTech is doing their things.
Instead of developing operational excellence in their prosecution authorities to be able to track down and punish bad actors, they install regulations for everyone and try to simulate competence harming their own economy.
Not all crimes are preventable, which doesn't mean the laws aren't enforceable. Example: even though murder is illegal, people still commit murder, but they are rightfully punished for it, as the law mandates.
> [...] harming their own economy.
Do you have any proof that tech regulation is detrimental to the economy?
And if this is your counter example, then it proves my point that the Americans far more innovative currently.
AFAIK, so far the UK is quite happy with the GDPR and has no plans to abandon it.
Your use of “probably” is quite telling. Probably, as in, maybe not, maybe yes, who knows. As the act is phrased today, anyone who publishes a certain type of model, or a derivative of such, is a subject to certain legal obligations. Do you want to risk that Europol or any other task force knocks on your door, or hope every time that you slip under the radar?
Those acts, together with the CRA, are so vague that a lot of people will operate in a grey area. So maybe nobody knocks on your door for a year. Or two. Or five. But when they knock, good luck defending yourself from a legal action based on laws written by people who had so little idea they had to leave so many vague points open to interpretation depending on who doesn’t like you to what extent.
Today.
> People appear to be extracting drama
Makes sense considering that the drama influences subsequent reviews and changes.
What this act will do is severely stunt the European economy compared to the rest of the world, which will be racing ahead (as long as countries like the US don’t pass similar laws). By the time Europe realizes its mistake, it will be too late to catch up.
Turing would argue that if the map resembles the territory so faithfully that you can't distinguish between them, the difference is moot. We're not there yet, but we're a hell of a lot closer than we were ten years ago.
Consider, for example, GDPR. Its implementation in Europe essentially forced compliance worldwide (with some smaller companies choosing to just not support users in the EU). And that's a good thing.
It's a large enough market that it can and should lead the way in sensible protections.
This isn't about luddites looking to burn witches. There are very sensible and immediate risks that we need to get ahead of. As someone in the ML/AI space I'm glad that many of the risks are coming to light. We don't need AGI for there to be serious problems with abuse of language models.
But they showed up to “comply” with gdpr.
> implementations of cookie banners that don’t allow users to reject cookies as easily as accepting them are illegal.
But they are still everywhere, because GDPR is threatening but largely toothless
Maybe you're thinking of "AGI", which is a term that appeared in the late 90's to make the distinction between the expert systems of the time and machines that could think like a human?
> all training data be "relevant, representative, free of errors and complete."
This is especially interesting to me with regard to something like ChatGPT. As we know, ChatGPT occasionally gives factually incorrect information. Does this mean that, in its current form, it would be illegal in EU? We know that Google is currently blocking access to Bard in EU. Will ChatGPT be forced to follow suit?
ChatGPT is great and I love it. It would be a shame if I'm not even allowed to use it _at my own risk_ just because it might be wrong about some things. This seems like a simplification, but it sounds like EU is allowing Perfect to be the enemy of Good.
does it mean "must collect ALL data"?
I agree that would be idiotic to let some greedy bastards sell some MedicalGPT to us, or PoliceGPT, SurveilenceGPT.
Imagine the MedicaGPT will give you different treatment each time you ask since is not deterministic, or if you change the patient name from Bob to John then it gives you some wild results because test data had tons of hon Smiths in and nobody can explain this AIs reasoning.
So IMO for critical systems we need good rules for safety reasons, for non critical systems we need transparency and if you sell an AI product you should also take responsibility if it performs worse then you advertise. Like you can't SELL me a GPT for schools with a shit disclaimer "it might be wrong sometimes and teach the students wrong stuff, or it might sometimes be NSFW" , IMO fuck this ToS where this giants sell us stuff and take no responsibility on the quality of the product.
https://ai.stackexchange.com/questions/32477/what-is-the-tem...
It's unfortunate that EU regulators seem to be making the same mistakes as you because they have a similar understanding of language models.
I do not this tech banned, but regulated for safety reason in critical systems. I already get daily spam emails from greedy fucks that want to sell me AI for X, where I am 100% this greedy fucks do not understand the science behind this stuff but just want to make money.
I also have no idea what your spam emails has to do with training models. The linked law prevents companies in the EU from releasing or deploying large models. It does not prevent grifters from spamming you. (not that there are any companies in the EU training state of the art models, but that's a separate issue)
I can't think of one example where someone was harmed by an LLM.
Besides "AI" is largely a marketing term, most software has "AI" elements and that has been the case for a while now, this thing has "unintended consequences" written all over it.
Is like trying to regulate cars to save the horse shoe industry.
And if doctors can be automated away so can software developers. I guess in the long term we are all obsolete.
Which was quite common in the early days of automobiles. There also wasn’t quite the massive bureaucratic regulatory system back then.
The big difference is these AI doctors will need to be certified by, wait for it… current doctors. Or, at the very least, the training data (haven’t RTFA so that’s the example being thrown around the comments) will need to be certified.
Judging by how the EU countries deal with labor issues I think there’s little chance robots will replace human doctors for a long, long time.
Just as Steve Jobs used to say when the media was constantly stoking fears about the power of personal computers in the 1980s—“you can just throw it out the window.”
Yet, he simultaneously took advantage of that media hysteria when signing off on what is considered the best commercial of all time- “1984 won’t be like 1984 because Apple”
Essentially what OpenAI is doing right now in Washington (ie. stoking the fear and also selling the solution).
The more things change, the more they stay the same.
Off the top of my head:
https://www.brusselstimes.com/belgium/430098/belgian-man-com...
https://jonathanturley.org/2023/04/06/defamed-by-chatgpt-my-...
Not yet. Thats why there is this Act.
Using AI in law enforcement or doing a surgery could cause some harm.
LLMs like ChatGPT are in "low risk category" for which there should be no mandatory obligations.
1.) being a part of the team working on this has to be among the most exciting legal jobs in Brussels
2.) I did not have time to read the entire act, not even sure if I'd understand it, but I'd be curious how much of it is still relevant given the leaps in both tech and especially popularity in the last two years.
--
Incidentally, for the many who claimed on these pages that we would not "have a definition of AI" (actually we have several), well, this legislative text provides one:
software with the ability, for a given set of human-defined objectives, to generate outputs such as content, predictions, recommendations, or decisions which influence the environment with which the system interacts, employing techniques including (a) Machine learning approaches, including supervised, unsupervised and reinforcement learning, using a wide variety of methods including deep learning; (b) Logic- and knowledge-based approaches, including knowledge representation, inductive (logic) programming, knowledge bases, inference and deductive engines, (symbolic) reasoning and expert systems; (c) Statistical approaches, Bayesian estimation, search and optimization methods
Yes (oddly enough): arithmetic based.
At least based on that mess of words I am.
https://www.youtube.com/watch?v=yoIC5EPPfn4
(feel like all my HN posts are always revealing the embarrassing about of youtube I watch)
This is bad because those people (the FLI) have weird political motivations, that do not automatically align with EU and human rights legislation that the new AI regulations try to protect. Whatever interpretation the FLI places on the EU act, should be treated with suspicion because of that.
“applications, such as a CV-scanning tool that ranks job applicants, are subject to specific legal requirement”
This is a continuation of EU logic first seen in GDPR around what that law calls “automated decision making”.
All I can say is that GDPR hasn’t had a good effect. Partly because It’s not well written from a technical perspective.
GDPR demands explainable and auditable automation. Non-deterministic AI systems make this difficult or impossible with current tech. So to be “compliant”, vendors dumb-down their software to use explainable methods and often inferior hiring decisions are made because users have to operate on untenable amounts of data using basic sorts. So the Talent Acquisition team end up structuring the hiring process around “disqualifers” such as resume gaps, education requirements, pre-interview qualification tests, etc.
It reminds me of an old recruiting joke:
“Recruiter: You said you only wanted to interview the 5 best applicants but we are getting so many applicants we don’t know where to start.
Hiring Manager: OK, first, I only hire lucky people. Print out all of the resumes and throw away every other one.”
Interestingly, if this process is done randomly without reviewing the resume, it’s considered legal.
Even doing a few dozen audits of the AI run and coming up with better results, how can you assume these results will be consistent across thousands of resumes that will be blindly scanned ?
Usually stats could be applied, except as it's a black box, can we assume that behavior will have cobsistency ? (a dumb example: if the AI is somewhat influenced by dates, decision will drastically change as time goes by)
[0] https://en.wikipedia.org/wiki/Elon_Musk
[1] https://en.wikipedia.org/wiki/Vitalik_Buterin
[2] https://ec.europa.eu/transparencyregister/public/consultatio...