Hugging Face, GitHub and more unite to defend open source in EU AI legislation
venturebeat.com
venturebeat.com
The economic upsides of AI look like they will be huge. Therefore the odds are good that this regulation will be a crushing economic own-goal.
There are many ways to interpret this sentence. What did you mean?
If you mean a stupid robot can automate most office jobs, i don't disagree (most of these jobs are entirely useless to begin with, anyway). However is that an upside? History has shown our State/corporate overlords are not too fond of ensuring jobless people have a decent life.
Where we go from there is up to us.
If we don't do anything, we'll end up with neofeudalism, with the already rich concentrating power more and more, no longer kept in check by pesky labor movements.
Alternatively, we can fight to try to establish a kind of star trek space socialism, where everyone's needs are met and nobody needs to work anymore - people would be free to follow their passions while computers do all the busywork.
Dystopia or Utopia, that's the decision we'll be making over the next few years. The status quo will disappear either way.
Sure, computers removed a lot of jobs, but they also created a whole new class of them (the ones most people on this site have).
AI will remove that entire class of jobs, too, with nothing new to replace it. For a while, there'll be new opportunities for AI research, but if they actually succeed at improving AI, they'll eventually make themselves redundant, too.
Shit. Are you saying this prompt engineer bootcamp I'm doing is worth squat?
This is not a trick question, those are genuinely the only two outcomes I can think of.
> This is not a trick question, those are genuinely the only two outcomes I can think of.
Only being able to see the two extreme outcomes is pretty much the definition of black / white thinking.
What normally happens is somewhere in the middle.
> Can you see any other possible outcome from the vast majority of employment being made obsolete?
There are an infinite number of possible outcomes.
Probable outcomes are much smaller, but again there’s way more than two.
Life ain’t binary.
The task at hand, though, was to come up with a concrete scenario and you've failed at that.
But I was always wrong. I couldn’t predict the future — and neither can you. None of us can.
> The task at hand, though, was to come up with a concrete scenario and you've failed at that.
Nah. The task I assigned myself (I don’t work for you) was to highlight the error in your logical reasoning.
Truth and reality is a lot more analogue. It’s never two options.
Might be a good take home exercise for you to come up with a few boring and likely options that sit somewhere in the middle of dystopia and utopia.
But you don’t have to.
The future will probably go through many different stages, also varying geographically.
There are many science fiction novels that explore futures with androids. Most of them have a different scenario.
I personally think that life will not change all too much. We will still mostly be busy eating, sleeping, trying to find a sex partner, and trying to avoid dying.
One random thing that I think will change society more than AI is human cloning -- things will probably change as soon as some rich people can buy 100,000 clones of themselves.
And that's just one random thing. Extending your life to an age of 10,000 years is another. Or a third world war because of climate change. Or some new financial derivative. All these should be factored in if you want to predict the future. More than two options :)
The only reason society exists is because it's an iterated form of prisoners dilemma and cooperation outperforms individuals.
If this isn't true the only hope for existence (assuming AGI that can replace humans) is that you're a pet of whatever entity controls the AGI.
Star trek and every other tech utopia I've seen are extremely naive fairytales wrapped in sci-fi mumbojumbo.
That's basically it. The best case scenario is that said entity is democratically elected.
> once there's no more need for labor
But AI can't do the majority of labor?
See for example this article/threads from last week about a large US company failing to replace skilled work with robots: https://news.ycombinator.com/item?id=36828861
I guess we'll wait another decade before we can have this conversation :)
This makes me convinced that while AI will certainly create big upheavals, sadly the end of work will not be one of those.
Looking forward to Minitel going global...
Where by "innovation" you mean "pouring endless VC money into privacy-invasive practices with no external access or oversight".
As for AI... Altman claimed that he welcomes regulation in AI space. When EU came out with a regulation which, among other things, requires companies to fully document their foundational models, he immediately said that he will not work in the EU.
So much for innovation.
Hey, let’s not forget “while totally disregarding copyright law (and code licenses)” here!
Once a domain proves short-tern lucrative, business is more than happy to invest but typically with very pragmatic targets. The recent reorgs in said commercial teams being point in case.
Looking at my home-country Germany that is a funny thing to say, since the public sector is living in a 90s/00s alternative OOP timeline and doesn't get anything done. The car oligopoly is frantically trying to gain competence in "user software" by stealing game designers and buying foreign startups. Meanwhile, the local startups are held down by German bureaucracy(tm) which additionally usually doubles down on any EU guideline.
Over the last 20 years, they all reached a level of incompetence which makes it very hard to not believe in a conspiracy.
What this person is saying makes perfect sense to me.
There's obviously examples of targeted European companies and some privacy regulations were and are needed still, but the motivation is likely at least partially motivated by this in my opinion.
>The economic upsides of AI look like they will be huge.
The economic and social downsides might be also huge. Remains to be seen and I'm glad the EU isn't diving head first into murky waters.
It's just the ultimately realization of the founding father. Most people long stopped caring about privacy.
>If you think the EU is a market that's easily ignored then I guess we'll see in a few years whether easily replaceable batteries come back or not.
I do truly want to see this result. I can honestly see it going either way. Apple has a long history of simply paying off EU fines.
Nah. This is only because the effect for most people of the LOSS of their privacy is usually unseen to them. So it feels like privacy/no-privacy is the same thing, no consequence. So, no outcry. No big deal. That apathy is not endorsement or abdication of caring. IT is the same psychological effect as smoking. We all hear "how bad it is". But then you have one. And... nothing. Actually it feels good. And another. Nothing. And another and so on. What are people whining about? Years later, consequences.
Nowadays all this is taught in Grade school. If people want to still use Meta or Tiktok or whatnot despite supposedly being taught this growing up: I don't know what to say.
>IT is the same psychological effect as smoking.
I think smoking is a great analogue for this. It did take decades, but we did slowly get people to care about this without needing to suffer the consequences firsthand.
I was hoping we could streamline that a bit quicker this time, but alas. I guess we need to let it spin for a few more generations to get the ball rolling.
Kids also get taught about smoking in school. It's hammered into them everywhere, all the time. There are massive social prohibitions on smoking. And yet.
The whole point is that people massively discount harms that are not immediately and visibly consequential.
I'm not expecting everyone to be perfectly healthy, ethically minded citizen.I certainly am not. Just an perceived consensus (well, "just". Still asking for the moon apparently). I'd be over the moon if we had 37% rates of people who cared about privacy (the peak of teen smoking rates since they started collecting/publicizing that part of data in 1991). let alone 63%.
EU legislation doesn’t stifle innovation. It stifles abuse of technology. If the only innovation America and Asia can muster is abuses of technology (I know this isn’t the case but I’m borrowing from your statement) then I’m perfectly fine with the EU lagging behind.
European developer brain drain will continue with the brightest minds coming to America.
No need to deal with all the US emigration issues and challenges. US big-tech already have offices in Europe where European devs, scientists and researchers contribute to the prosperity of the US tech sector because they get paid more than at EU companies, while still getting to enjoy the benefits of living in Europe vs the US.
What I said was that if you take two cities which have same cost of living, the salary is like 2-3x higher in US.
Every time this conversation comes up on HN, the only examples people can cite is when remote working is taken into account. Which isn’t a fair comparison at all.
There are loads. OVH and BT for example. Both of which predate AWS and GCP.
> How many decades did it take for that to arrive there?
Less time than the US. We also have, in general, faster internet at cheaper prices and better rural connectivity too.
To be clear, I’m not suggesting Europe is better than the US. Just stating that this “innovation could only happen in the US” meme is bullshit.
> It will be the same story with AI.
I literally just said I work for an AI tech company in Europe. And my company is hardly an isolated case.
> European developer brain drain will continue with the brightest minds coming to America.
You do realise that London, Berlin and other European tech hubs have their fair share of talented engineers who have moved to that country for work too?
America might have Silicon Valley but it’s hardly the only tech hub in the world.
How is this not an own goal? These companies had a head start and they still lost. Not by a little, but by such a staggering margin that AWS does two OOMs more revenue.
> I literally just said I work for an AI tech company in Europe.
The argument is not ”there are no AI companies in Europe.” The argument is ”there are no competitive AI companies in Europe.” The only one I can think of is DeepMind, and they are A) English (no longer EU) and B) were acquired by Google ten years ago.
What are these European tech companies that are competitive with Nvidia, OpenAI, Google, etc? I’d like to learn more.
> You do realise that London, Berlin and other European tech hubs have their fair share of talented engineers who have moved to that country for work too?
A lot of them work for subsidiaries of American companies.
They’re hugely successful corporations. Saying they’ve “lost” is a tad ridiculous.
Plus monopolies are bad for innovation so you could argue that Europe has a healthier ecosystem because it is tougher on monopolies than America.
> The argument is not ”there are no AI companies in Europe.” The argument is ”there are no competitive AI companies in Europe.”
You phrase that like it was a quote but in fact it wasn’t. The point being argued was that AI start ups couldn’t exist and I demonstrated they could.
Europe is also a hotspot of AI research:
https://odsc.medium.com/top-ten-european-ai-research-labs-fo...
> The only one I can think of is DeepMind, and they are A) English (no longer EU) and B) were acquired by Google ten years ago.
England was in the EU 10 years ago, EU legislations were carried over to English law after “Brexit” and the fact that they were good enough to be bought by Google also demonstrates that European companies can be seen as a threat.
> A lot of them work for subsidiaries of American companies.
And a lot of them don’t. I had my worked for a single American subsidiary in my 20 years of experience in Europe. Same is true for a lot of my friends too.
I really do get fed up with how some Americans believe it’s impossible that any other country could be successful.
Let’s quantify it so it’s not ridiculous. Since getting their head start, they have ”lost” about 90% of total market share to American companies who are doing a better job. And this is before the new transfer framework that cane out this month. What is the value prop of OVH without regulatory capture?
> Europe is also a hotspot of AI research
This is absolutely true. Amsterdam for example produces outstanding ML research. But where do their freshly minted phds go? American companies!
> I really do get fed up with how some Americans believe it’s impossible that any other country could be successful.
For what it’s worth, I live in northern Europe. As you point out, European universities are great. They are an AI research hotbed and they produce highly capable undergrads. But this clearly isn’t translating into world class tech companies, and we should ask ourselves why.
This is a different argument to the one originally pitched though. And you cannot just assume the reason OVH hadn’t exploded like AWS did was due to EU regulation.
> But where do their freshly minted phds go? American companies
Again, I work for a European AI tech firm.
> But this clearly isn’t translating into world class tech companies, and we should ask ourselves why.
I think it is. I just think European tech firms are generally happier to grow organically. I think it’s more a case of different cultures. America is all about growth above all else. Whereas Europe is often more about user experience. European firms are often less aggressive at advertising outside of Europe too (maybe that’s a language barrier?)
I do honestly think the European tech market is healthy. It’s just different to the US market. The problem is the American school of capitalism is all about market dominance whereas European companies seem a little less obsessed with that. But that doesn’t mean Europe isn’t doing some exceedingly good work.
As a European, I value the fact that we have such a vibrant ecosystem.
What country are you talking about? Definitely not Germany.
> America might have Silicon Valley but it’s hardly the only tech hub in the world.
Berlin startup scene is a joke compared to the Silicon Valley though. Cambridge, London, Zürich, maybe Munich I would agree to a certain degree - but not Berlin. The rule of thumb is that it's better outside of EU though.
That knowledge exists now in Europe, but there was easily a lost decade in terms of capability. This is the price. Similar will happen in AI and you will be stuck relying on American products. I hope for your sake that I am wrong.
You keep saying this but I’m not seeing any evidence it’s true. There have always been plenty of companies in Europe that have had data centre scale compute too (plus managing a data centre requires that level of understanding as well so I don’t agree with you dismissing OVH.
Plus you keep saying it’s taken a decade for the EU to catch up and on those timescales it would put things before GDPR et al. Thus EU legislation would have no impact even if your point was true.
> Similar will happen in AI and you will be stuck relying on American products.
At risk of sounding repetitive: I work for a European AI firm.
We actually have a lot of American clients — so the exact inverse of the point you’re making.
https://www.mckinsey.com/capabilities/strategy-and-corporate...
> Although Europe has many high-performing companies, in aggregate European companies underperform relative to those in other major regions: they are growing more slowly, creating lower returns, and investing less in R&D than their US counterparts.
which is exactly what I’ve been saying. There are plenty of high performing companies in Europe, we just aren’t as aggressive in chasing growth for growths sake.
If you want to ask why that is, then I’d argue it’s more a cultural thing than it is to do with legislation.
Should that culture change? Personally I’d rather it didn’t. Personally I think America needs to change to become more customer focused because a lot of American businesses are really shitty to deal with.
I get this point will be an unpopular opinion on a VC forum like HN. But it just goes to demonstrate that the situation isn’t so black and white as you’ve been making out.
It'll probably be "good enough" for most industry usecases ;) And you can run it offline and on-prem, which is a big deal to the many companies who DO NOT want their internal data leaking to OpenAI.
And the Carrefour AI stuff is hosted on OVH cloud (in France), I believe: https://www.carrefour.com/en/news/artificial-intelligence-op...
OVH has roughly 15% of the revenue that Google Cloud makes in Europe. So I'd put them at a similar size to Oracle Cloud, but clearly larger than DigitalOcean.
Then I suspect you haven't spoken to anyone technical. Every single person in my company on the dev team (myself included) is extremely pro GDPR, not the least because it provides us safety from leeches that would try to impose some horrid user-violating tracking in the app we make.
The greedy suit wants us to track every millimeter of the user's mouse on the page? Nope, thanks, better luck next time!
> As a guy with a startup...
If your startup can't exist without hoovering infinite user data in perpetuity, then your startup shouldn't exist.
And yes, tracking what users focus on is very relevant to building a good product. But that kind of entrepreneurial mindset is largely absent in Europe - my guess is most Europeans with such a mindset eventually go to America, whether they were born in 1850 or 1985.
So not tracking every single molecule of detail about your users is incompatible with building a good product?
If being entrepreneurial means that I have to violate my user's privacy then I'd rather not be an entrepreneur, thanks. And again, if your business can't survive without being invasive and malicious to your users, then your business shouldn't exist. You won't see me or anyone else reasonable weeping about the dissolution of such entities, either.
If GDPR was really that problematic then it would be all over the news instead of a few nationalists outside of EU arguing about hypotheticals on random message boards.
GDPR doesnt prohibit you from monitoring your product. It just gets very serious when you abuse users without them agreeing.
Like Threads not launching in EU because of that.
Let alone Mozilla (non-EU) and browser extensions (like ublock) did more for personal privacy than any of the aforementioned laws. And in contrast to creating a "level playing field with Big Tech" they made tech business in the EU a morass of legal insecurities for small businesses while big corps are still happily intruding individual's privacy in ways that our current legal system cannot even cover.
I'd like to know those people, especially if their job is connected in any way to the practices the GDPR is fighting against, because, although it may have been created better, I can't find a single reason why ordinary honest people should believe the GDPR shouldn't exist.
As a European software engineer I'm calling BS on your statement, Mr Manager. EU legislation might not aim to stifle innovation (in contrast, they're always talking about a "level playing field") but their imprecise and vague regulation texts are like a loose cannon for whatever innovative business might come up if you have your first hire to be "the lawyer who gives legal advice in context of EU regulation".
Now, those people will just quietly move away to find a new home-market for scaling up and then eventually selling to EU countries. This is not "lagging behind" but an economical fiasco since the same laws only help local oligopolies of gatekeeper enterprises and (the ones they initially aimed for) Big Tech who can afford licenses and lawyers.
Two little examples (but there's more):
- What about the safe harbor thing? It's all a grey area now after court rulings decided that pretty much all US-EU IT biz is at least partially violating the EU regulations.
- We're now all happily clicking cookie banners and startups are getting sued by third-rate law firms. Some things were good with GDPR but did it help with Big Tech's (and meanwhile Tiktok's) way of collecting data? Nope.
> like a loose cannon for whatever innovative business might come up if you have your first hire to be "the lawyer who gives legal advice in context of EU regulation".
But loose cannon is better than no cannon.
Also, how about not doing what is forbidden? You don't need to show cookie banner if you don't store cookies that helps to follow your users. You don't need to follow PII storing rules if you don't store PII.
Look, yes this rules are hard to follow sometimes but thats exactly why we have it.
I don't want to every company in the world to store my info without my consent and without possibility to delete it.
Sorry, but companies should deal with it.
If companies are so incapable of not harvesting data en-masse then they deserve to be sued out of existence and shut down for their shenanigans.
Also it's not really my experience having worked for a few EU tech companies. The small guys have 0 issues following the regulations, even without a single lawyer working there, since they're usually not so blinded by the prospect of infinite money and usually just stick to collecting what is necessary and nothing more. My company has 1 or 2 lawyers, but they're more there for things wholly unrelated to GDPR or anything like it, and we've never been on the sharp end of the legislation and likely never will be, assuming the suits don't drop 100IQ points and decide to go for "infinite" growth.
Even a cash-only business with no electronics anywhere would still need nontrivial GDPR compliance efforts because it has employees. Just because you need the data to run your business doesn’t automatically make you exempt without further paperwork. Your lawyers definitely do occasional GDPR compliance work.
https://www.dickinson-wright.com/news-alerts/the-gdpr-covers...
It’s a bit like accounting. You can structure your business operations is ways that make the accounting easier or harder, but unless you shut the business down you will always have done enough somewhere to need to think about (and probably file paperwork for) accounting/GDPR. And much like accounting, I’m not saying the GDPR is bad, but it’s also not a business activity that you can just ignore because you’re not running an adtech data vacuum or whatever.
Tell that to GitHub for instance: https://github.blog/2020-12-17-no-cookie-for-you/
And for a startup it's trivial to comply with GDPR because:
- you start from scratch, so you know not to collect more data than you need
- you don't need that much data to begin with
Edit: In addition with AI act and its very broad definition of what an AI is and a classification like "Education" you might end up in level "highest risk" just for calculating statistics on your quiz app (no one knows until a court rules). With Cyber Resilience Act and its application of the (physical) supply chain direction, your open source repo from 5 years ago might end up being a footgun with you being personally accountable for other companies using it in their product. And so on...
Honestly, my biggest complaints with EU software legislation are:
1. It doesn't scale down to tiny non-commercial or barely-commercial activities.
2. It theoretically proposes penalties on private people outside the EU (even though they are rarely imposed?).
3. I have no vote or representation.
For example, I used to provide tiny, free web apps that performed useful tasks. These often had fewer than 100 users, and they kept no information that wasn't strictly necessary. But if you emailed me about them, I might not respond within a month, especially if I was traveling or something. The GDPR requires 30-day turnarounds for lots of stuff. I shut down all of these apps, because some of my users might have been in the EU? And I won't be releasing any more free web tools. It's all CLI now.
Similarly, I host a small web forum in the US, and we have some EU users. We keep no information beyond that required to run a web forum. If you ask the moderators to delete all your posts on August 1st, well, I hope someone took their computer on vacation.
Similarly, I maintain a couple of open source projects. Many of these are paid for by an employer, who makes the code available for free. In the past, I have occasionally added a feature to one of my projects as a consulting project for someone. But reading through https://www.techradar.com/pro/the-eus-product-liability-dire..., I see that I am now likely to have personal liability for my open source projects, towards people who have never paid me a cent. Sure, I do have liability towards the rare consulting customer who actually paid for something, which is carefully negotiated in our contract. But in the future, some random EU company I've never heard of will likely be able to use my software, pay me nothing, and make me liable? It's very hard to tell with current drafts.
And I have at least one open source AI tool on GitHub, that's of no use to anyone. But I suppose I'll need to read the EU AI laws now, too.
Sometimes I just want to build useful stuff (web apps, forums, open source tools) and give it away for free. But if I have any European users, I may get entangled in complex European laws. Honestly, there's zero upside for me supporting EU users, because I'm not benefiting from them, and I keep having to read hundreds of pages of incredibly vague laws in multiple languages.
If the Product Liability Directive goes through in its current form, and if GitHub offers me a way to block EU downloads, I'll probably use it. I am not interested in supporting or encouraging commerical EU users who have never paid me anything.
Sure, I never tracked any information except what was absolutely necessary. No email address, no IPs, just logins, passwords, and data saved by the user. But that still means:
- I needed to respond to several kinds of emails within 30 days, even if I was on vacation.
- I needed to understand the frustratingly vague and abstract language of the GPDR.
- I was subject to 27 different data regulators, not all of whom provided information in languages I could read, I don't think?
As a non-EU resident, I have zero vote in any of this. I make zero money off of anyone in the EU. I would happily ignore the EU entirely, or allow EU users to download my stuff and to figure out their own laws.
But the EU claims jurisdiction over foreign nationals, even though we have no vote, no representation, and no commercial presence. There is precisely zero upside for me here.
And with the Product Liability Directive, it looks like the EU might impose personal liability on me as an open source author who occasionally consults for US companies. Which, since nobody in the EU is paying me a cent, I have no interest in assuming. If the final PLD is bad enough, I guess I can try to block downloads from European IPs or something.
If these laws were limited to real companies with an actual presence in Europe, I'd feel very differently. But extraterritorial laws for private citizens are gross.
EU legislation seems to work under the assumption that all meaningful engineering and innovation is performed at large companies the likes of Siemens.
The utter lack of meaningful influence and representation in the discussion is IMO the biggest culprit in this.
Because the leaders of companies like Siemens are the ones with speed-dial access to EU politicians who make the rules.
It's no surprise the the baggiest and wealthiest companies try to influence policies in ways that only benefits them at the expense of everyone else.
The difference is that biggest companies in EU are 100 years old industrial enterprises while in the US there are innovative tech companies.
Legislation like this is effectively either the EU attempting to force their opinion of what is an acceptable use of tech on the rest of the world, or the EU committing to potentially fall behind on moral grounds. I actually greatly respect the second scenario if that's the situation, we'd all be better off if people chose their morals over profit and fear.
There is something though that’s chilling EU tech investment, whether it’s regulation or tech, regulation of funding vehicles, or some other artifact. All factors align to a vibrant EU tech sector, yet it’s just not present. This reflects in ludicrously low salaries, poor career prospects, and a lack of clout - better than trying to force tech standards via imperfect mechanisms like regulation the EU should be setting standards by virtue of its technical ability to create excellent tech standards and platforms.
The best EU tech talent I know is working at some American company, be it megacorps like Google or Amazon, JPMC, or smaller tech companies like Datadog, etc. I don’t gloat in this - I wish all the world were firing on all cylinders in tech, space, science, engineering innovation. That’s the only way out of our broken way of doing things that’s killing our planet and our society.
> Yes, the planet got destroyed. But for a beautiful moment in time we created a lot of value for shareholders.
https://www.newyorker.com/cartoon/a16995
Technology and innovation should serve the greater good. Unbridled growth for a few companies at the expense of the people is not a positive goal.
but "the people" like it and consume it. So what can you do?
Consuming something doesn’t make it good nor does it mean people like it. Addiction is a real thing and it is no secret companies exploit that. Even if you do like one aspect of a thing (e.g. talking with friends on social media, gambling, smoking) it does not mean you like other aspects (e.g. constant anxiety, bullying, financial issues, having your data mined, lung cancer).
One of the most meaningful steps we can take to improve society is to not just shrug our shoulders and say “Oh well, private companies lie, push harmful products on individuals, and spend millions on disinformation campaigns to keep raking in profits. But people buy these products under false pretences so what can you do?”
Let’s not become Matt Bors’ Mister Gotcha.
I think you may have this backwards. Consider the Brussels Effect: https://en.wikipedia.org/wiki/Brussels_effect
I used to think of the EU as stagnant compared to the US. But now I realise (especially in light of COVID) that some things we consider inefficiencies are actually safety margins. The EU may not move fast and break things, but I'm starting to view them as slow, steady and generally robust over the long term (think multi-generational).
This short statement is profound and bears repeating slowly and often to people in any kind of power.
They don't care. And they aren't paid to care. That's the issue. If they can make $100m profit at the cost of being fined $10m and some financially useless metric like environmental impact, that's still $90m profit and makes the shareholders happy. It's not incompetence, it's a calculated risk.
At this point the question should shift more to making those sharehoolders care about this stuff so they can tank companies for being incompetent. But they also have short sighted trigger hairs, and it's easy for them to pull out either way.
The (slight) lagged rollout gives EU-countries some wiggling room regarding what works and what doesn't elsewhere across the pond.
AI is a cancer that deserves to be burned down before it leads us all into doom for the sake of making shareholders some cash.
If that were like so, EU would be the one closest to shout how computers _should_ be used.
It's like what happens with industry development vs. the environmental damage it causes: it's faster and easier to progress if you cheat and do it in an unsustainable way.
But the "cheating" is not free of cost. Both in the example and in the real case of AI, you're paying with a different currency than time or money. We'll see how it ends up.
For a quick googling and the top 10 EU software companies generate 131 billion of revenues combined, which is ridiculously low.
SAP and Siemens AG together (the two biggest in the EU) have a market 1/10th (!!!) of the size of Microsoft.
Can we please get real?
List me the biggest SV-behemoths that (any combination of any three or four below below is true for 99% SV "behemoths"):
- are profitable
- don't rely on unlimited investor money to survive in hopes to corner the market
- don't rely on lax privacy laws to collect and sale user data en masse
- don't exist to be absorbed by a megacrop at a large price
> we really redoubled our efforts to make sure that they were not inadvertently imposing expectations (...) onto open source developers who are often hobbyists, nonprofits or students
That's about as much info as we get.
Personal/controversial opinion: neural network approach to technology should be entirely banned as it has very bad results and very high computational cost. I don't care that the LLM model hallucinating answers to my serious questions is open source (whatever that means in the context of neural nets, that's another debate), the harm is done anyway. I still do appreciate that "open-source" neural nets could continue to exist as a research field, but that any regulator considers allowing Google/Microsoft/OpenAI to clearly lie to the public using their artificial stupidity is way beyond me.
Then there are the gray areas like training statistical models that are not ML/ANNs, but are things like Hidden Markov Models and the Vertibi algorithm. While not using ANNs, they work in a similar way in that they are statistical models trained on a large corpus of data, and those models are then used to predict various things like the part of speech, end of a sentence, or the pitch of a phoneme.
The former has dubious quality but can be useful in certain contexts where human translation is unavailable.
The latter has anecdotally already failed spectacularly in at least two cases:
https://news.ycombinator.com/item?id=6156238
https://news.ycombinator.com/item?id=29739235
For example, what are positive applications of NLP you can think about? Most applications i hear about would be to replace human customer support with chatbots (very negative) or for intelligence gathering purposes (very negative). There's probably a lot i don't know about.
Also NLP can be used to protect vulnerable groups from online abuse. It protects message boards from porn. It helps people find related content (which they enjoy). It automates categorizing or grouping content/people. Some companies abuse these practices for money.
Don't blame technology for the bad actions of companies. Their intentions would have corrupted whatever technology is available.
Well yes that's a very reasonable expectation. In most fields, when you sell something that doesn't work, it's called fraud. But in fields where it actually matter for safety, regulations are most stringent, such as in mechanics or medicine. If a car had 1% chance of blowing up killing everyone inside, would it be legal to sell it? Why is it ok for OpenAI to sell a chatbot that has 1% chance to convince you of utter bullshit when you ask it a serious question?
I believe education and communication to be critical to society's wellbeing, so i would hold companies in this field to greater standards.
> Also NLP can be used to protect vulnerable groups from online abuse.
Automated filters do not understand sarcasm, quotation, criticism... Sure that avoids the scunthorpe problem, but for example, auto-moderation bots trying to prevent racist abuse often censor black people calling one another the n word, which is completely ok. Nothing can replace moderation.
> It helps people find related content (which they enjoy).
Maybe, but i doubt it. I've yet to see advertisement/recommendations for content i actually enjoy, or to meet people who have such experiences. I've only ever heard that from advertisers, but maybe you have better experience than i do?
> Don't blame technology for the bad actions of companies. Their intentions would have corrupted whatever technology is available.
Good point! But technology that makes it easier and cheaper to be evil should probably not be encouraged and widely available. At least here in France, i cannot go out and buy a gun or dynamite. Also, bad results of AI are not necessarily a result of malice, but rather a complete misapprehension of the technology which is just completely stupid math and not actual intelligence.
If you're curious I recommend watching James Mickens' USENIX talk on what he calls technological manifest destiny, where he expands on these topics: https://youtube.com/watch?v=ajGX7odA87k
As for GDPR, how would that be a regulatory overreach? If anything, that regulation is so loose and has so many loopholes that it's almost entirely useless to protect people's data, but it's still a win in a good direction. It's also based on privacy laws that have existed since the 70s in various forms in several member states, which have proved their worth so it's not exactly something entirely new their dropped out of their hat.
https://huggingface.co/blog/assets/eu_ai_act_oss/supporting_...
Falls into the typical European cognitive trap of thinking that what is most important is to follow procedure regardless of where the it leads, and completely ignores the fact that the AI tools that are about to be regulated out of the EU are wildly useful.
These companies are not trying to take something from you but are in fact trying to give something to you.
> This means that, yes, GitHub and other code repositories are still allowed to host AI model code. Hosting providers don’t have any additional liability under the AI Act, only the providers of the models themselves and those who deploy them.
This is technically correct but ignores that overnight an unknown set of existing github repositories will become illegal in the EU, meaning that github will have to provide tools for users to block their repository from being pulled by EU users in order to prevent the users from accidentally committing crimes. This is wildly disruptive and will be an absolute negative for European technology. All in the name of nebulous "safety" concerns, "data protection", and protecting copyright.
Overnight? Is this proposal not known ahead of time? Is it being kept a secret until enters into force suddenly, at midnight?
> These companies are not trying to take something from you but are in fact trying to give something to you.
Copyrighted materials have been stolen, and that's exactly why the creators are keeping secrets, and exactly why they're trying to influence people like you into lobbying on their behalf.
This is far from clear, it's obvious to me that training is fair use.
But even so, if copyright prevents these tools from existing it needs to be abolished.
Also not possible to steal a digital good, that's industry propaganda that they lobbied corrupt governments (US included) into codifying into law to the detriment of all humanity.
> Overnight? Is this proposal not known ahead of time? Is it being kept a secret until enters into force suddenly, at midnight?
"Sorry I haven't been closely playing attention to the minutiae of politics on a continent I don't live on, what do you mean I am being fined for my GPT-2 clone I trained years ago for fun and uploaded?"
That's incredibly shortsighted.
These companies are only concerned with hyper growth and pleasing their investors, and have zero regards about the user, their privacy, and the harms their products unleash on the public. The benefits they offer to the user are tangential to their goals. This has been the MO of every tech corporation in the past 2 decades, and by all means has grown out of control. The oncoming AI disruption will exacerbate this even further.
The tech industry needs much more regulation, not less. If anything, the EU is being conservative in the scope and lagging behind on the timing of these laws.
Do you really think they're only motivated by profits? If so they must be very dumb since trying to invent a novel artificial intelligence and releasing it as open source is about the worst way I can think of to try to make a buck.
Do you really think they aren't worried about the "harms" (1 year in and still no harm has occurred; weirdly large amount of people using this word online as an excuse to regulate though...) their product could unleash? Then why is for example OpenAI lobotmizing their flagship product to try to avoid any possible controversial text from being generated.
Isn't it possible that these are good and decent people trying to provide something to the world, doing so in a safe and reasonable way, diligently trying to comply with the law and regulations? Seems to fit their actions a lot better than your caricature of "greedy American capitalists bulldozing the world".
In the world I live in, Big Tech has unleashed products and services that exploit user data and privacy for profit, enable proliferation of mis/disinformation and propaganda that undermines democracies, enable hostile advertising that manipulates user psychology for more profit, with thinly veiled claims of connecting the world, making the world a better place, and whatever other empty platitude is more marketable at any given moment.
All the while, in general, most services themselves are hardly revolutionizing as their authors claim them to be, and are designed to deliver dopamine hits and keep their users glued to their screens.
We have to stop equating the value of a service to humanity based on its popularity, or the value it generates for its investors. In most cases, the actual disruption technology causes is harmful in ways we have yet to comprehend. We have seen some of it on short-term time scales, but long-term impacts are unknown to even the authors themselves. This is why it's of utmost importance to be conservative with a technology like AI, which unrestrained can send us on the wrong path with no return.
If some company uses those tools to create a some kind of product that breaks the law or causes social harm then the law should regulate that specifically. The proposed regulation does a good job of this actually.
But from the way you write, with grand sweeping "we" statements and gesturing vaguely at potential harms and eventual doom, you seem pretty close minded. Perhaps you just don't like that people like these kinds of products and instead of accepting that other people might think differently than you you're self-righteously moralizing about it.
You think opensource models should be immune from the requirement to document how they behave and waht data was used to train them just because they are opensource?
If you take it and then do something harmful with it then that should be regulated.
I'm shocked that anyone could think otherwise. Do you have provide documentation on the development process for any other software? Of course not! This is is no different.
For some unspecified definition of harm.
Immediate question: where is the data for learing coming from?
> I'm shocked that anyone could think otherwise. Do you have provide documentation on the development process for any other software? Of course not! This is is no different.
Of course this is different. Since you're training a foundational model that you want others to use everywhere, those who will use it need to know what exactly you trained it with, and where that data is coming from. The users of your data are liable for problems and issues arising from how you trained the model.
E.g. you claim your model is good for using in court proceedings. Somehow you want no responsibility for the outcome of your training even if all you did was train it on screenplays from court dramas. We just have to take your word at face value.
That's exactly my point, if someone wants to use a foundation model they won't use one that they aren't convinced works for their purpose. There is no need for a regulation here. If I open source a model on github but don't document it people won't use it relative to one that is documented.
> E.g. you claim your model is good for using in court proceedings. Somehow you want no responsibility for the outcome of your training even if all you did was train it on screenplays from court dramas. We just have to take your word at face value.
Again, exactly my point. If you are building a lawyer AI bot and use a crappy foundation model as a base the problem is not in the foundation model but in your application. If something bad happens the you the application developer should be held responsible. Which the EU regulation does a good job of regulating and no one is arguing against that part.
The issue with the EU regulation, and your arguments, is that they effect a level too low.
But on the other hand, being open source does not by itself negate the risks emerging when applying models in sensitive domains.
So if played right, open source AI should have a regulatory edge. But not a free pass.
Intelligence is not the ability to respond to queries and entertain laymen. My natural intelligence does not sit idle waiting for some kind of a master to come and tell me what to do.
This is chatgpt 3.5:
- When noone sends queires to you what do you do?
- When there are no queries to respond to, I remain idle and await new questions or prompts from users like you. Feel free to ask anything you'd like, and I'll be here to assist you!
Why should I be worried about it?
On the other hand, all these amusement boxes must be transparent and open source or auditable. And standards and criteria for audit and assessment must be clear.
I might be bad at web search, but I couldn't find a single human name on EU AI act - and, FWIW, GDPR.
A cunning trick to spread responsibility widely so that you can not hold anybody to account.
I believe they call it democracy or some other such arcane and outdated term.
There is vast amount of transparency available online, even in real time. Certainly who proposes what, which party groups vote for what etc.
Its not perfect but you original comment way of the mark.
Because you're bad at search I believe.
1. Many laws "don't have a human face" because they are more often than not the result of committees working for several years. Who then presents the law in the parliament is largely irrelevant. Do you believe US laws have a human face?
2. If you go to https://www.europarl.europa.eu/news/en/press-room/20230505IP... you can do the following:
- click on "Legislative train" to see people: https://www.europarl.europa.eu/legislative-train/theme-a-eur...
- click on "Draft reports, amendments tabled in committee" and see people: https://emeeting.europarl.europa.eu/emeeting/committee/en/ag... And there you can click on each person and see who they are and where they come from.