For me, it's not important if the legal definition requires this term. It's not like automation and computer programs are being banned.
It's the decision part that justifies this legal definition IMO.
It's like the difference between a human or an automated car running over people. Quite literally even.
What is a "decision"? My computer is making billions of decisions per second.
If nothing else, I could see this crippling FOSS. No one is going to want to be "responsible" to some EU bureaucrat pursuing a personal political agenda, certainly not for work you've done for free.
Of course any computation can be considered a decision in some way. But this is conflating a narrow and IT-specific meaning of that word with legalese and philosophy, or my intended meaning of the word.
This reminds me of the ancient catastrophic Therac-25 software bug, and other such cases.
Maybe this case is a good example for thinking about what part of the responsibility is on the side of the operator, apart from the obvious failure of the implementer.
For more modern examples involving actual ML, look at Meta, TikTok and their recommendations: where is the line to draw, what excuses are allowed, when the outcome is obviously negative, and the algorithm claims to fulfill a goal?
It doesn't matter if it's a rule-based system without "intelligence" or ML.
What matters is the responsibility of the human operator.
And making assumptions about correctness.
Humans make egregious errors as well, but the kind of errors AI causes are a significant concern where current legislation is insufficient.
It's one thing to have a bug in your airplane controller code or whatever.
It's another to knowingly accept malicious errors, either unpredictable or even intentional, but without proper responsibility?
Is this law making the users of software responsible (e.g. law enforcement, government departments) ? It seems to me to make authors of software responsible, absolving the users. Not the other way around.
They keep the law secret, of course, so anyone can claim what they want, but the article talks directly about the accountability of OpenAI. It seems to focus on rules on authors of AI software, presumably to mostly absolve governments and users of that software. "Rules around generative AI", "transparency requirements for any developer of a large language model" ... nothing that would make governments responsible for abusing AI software. Which is strange, because that's the concern the last paragraph of the article focuses on.
I must say ... this "complete ban" voted by the EU parliament last spring, doesn't seem to have stopped governments from using live facial recognition [1].
[1] https://www.euronews.com/next/2023/02/21/new-french-facial-r...
Only the authors of foundational models.
> They keep the law secret, of course
You mean this secret law: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52... that people have actually read https://softwarecrisis.dev/letters/the-truth-about-the-eu-ac... ?
No, thanks. Utterly insane, we are sliding backwards into the "code is a munitions export" territory that I so hoped we'd escaped after the 90s.
> If you take a foundation model, fine-tune it for a specialised purpose, and deploy it as a part of your software, it won’t count as a foundation model, and you’ll probably be fine, as long as the original provider of the foundation model was compliant.
This interpretation would render the whole exercise pointless, there is quite a blurry line between "fine-tuning" and "training".
Of course not. This goes hand in hand with such things as "being accountable". You can't spit out a black box that no one knows what it does and how it was trained? Too bad for you.
Perhaps this will lead to fewer things like this: https://news.ycombinator.com/item?id=38595751
What if I want to? Who on earth has the ethical authority to claim the right to control my ability to release a set of weights? Only what is done with those weights should be legislated, and extremely conservatively.
Maybe a lot of software developers got into this career for the money, or because they like solving problems. But for me, politics inseparable from software engineering. Politics are why I devoted myself to the craft. This is the exact kind of situation in which my knowledge and skill become tools of protest.
Do you also complain about so many other things that "unethically curb your abilities"?
> Only what is done with those weights should be legislated, and extremely conservatively.
Ah yes, let's regulate this black box with no insight into what it does, and only guess at its possible outcome. Whatever can go wrong?
Oh, we know what can go wrong, because we've had multiple issues with algorithms going wrong.
You curiously omitted the last part of the sentence: "...to release a set of weights". Please don't pretend that I was speaking about anything else, and don't overgeneralize my statements; that becomes a straw man argument. Believe it or not, some laws are unethical. I am happy to provide examples.
It's a case-by-case basis which involves evaluating the overall impact on human rights for all parties involved.
The ideal scenario is one where all rights are preserved under good faith, and publishing/owning models is treated no different than any other software project, while the actual use of such software continues to be subject to existing laws. In this case, can strengthen consumer rights without weakening developer rights.
> Ah yes, let's regulate this black box with no insight into what it does, and only guess at its possible outcome. Whatever can go wrong?
I specifically said we should not be legislating weights, so I'm confused about which point you are trying to make. Weights are the black box. Company policy, employee behavior, and business logic are not, and are accessible for scrutiny by the courts if needed. So no, let's not regulate the existence of software, which sets an incredibly dark precedent for digital sovereignty.
Emphasis mine
--- start quote ---
ANNEX IV
TECHNICAL DOCUMENTATION referred to in Article 11(1)
...
2. A detailed description of the elements of the AI system and of the process for its development, including:
...
where relevant, the data requirements in terms of datasheets describing the training methodologies and techniques and the training data sets used, including information about the provenance of those data sets, their scope and main characteristics; how the data was obtained and selected; labelling procedures (e.g. for supervised learning), data cleaning methodologies (e.g. outliers detection);
--- end quote ---
So let's see Article 11(1)
--- start quote ---
The technical documentation of a high-risk AI system shall be drawn up before that system is placed on the market or put into service and shall be kept up-to date.
--- end quote ---
Conclusion: all you're doing is spreading FUD.
> No, thanks. Utterly insane, we are sliding backwards into the "code is a munitions export" territory that I so hoped we'd escaped after the 90s.
I'm not sure if that's what the legislation is about though? I hoped for it to be more about legal responsibility for the results of operating AI services, considering they pose difficult legal challenges, at least I suppose so, regarding responsibility.
I admit that I have not studied the law in detail, and in case it wasn't clear, I am Not A Lawyer.
If the law instead is about regulating the release of model weights, I will understand this and it would of course disappoint me.
Of course it's not about that. It's pure unadulterated FUD. The law is about many things:
https://softwarecrisis.dev/letters/the-truth-about-the-eu-ac...
If your software however makes life-altering decisions for its users - such as targeting people for investigation, deciding on asylum requests, etc. - then you have to be responsible for the decisions your software makes. You can't hide behind "I don't know how the AI works, but it decided that person X is likely a criminal" - nope, you need to be able to explain the reasoning process behind this, because the system is your responsibility.
If anything, this should strengthen FOSS, because one of stipulations is "document your foundational models and training sets"
Give me real examples of IRL harm. And most importantly give me real examples of how exactly state intervention directly solves those problems.
Otherwise this is just a philosophical debate mixed with prepper type fear of what could happen.
Basically banning companies from just saying “ Computer says no”..
We see mountains and mountains of regulations, some of ehich are really harmful (especially in the primary sector) and that I think are not well-intentioned.
There is a full agenda of control-everything that I do not find healthy for the average citizen.
China's social scoring?
Racial profiling in government services? https://www.amnesty.org/en/latest/news/2021/10/xenophobic-ma...
Rejecting qualified applicants? https://www.eeoc.gov/newsroom/eeoc-sues-itutorgroup-age-disc...
Racial bias skipping patients in healthcare? https://www.scientificamerican.com/article/racial-bias-found...
Recruiting ignoring women? https://www.reuters.com/article/us-amazon-com-jobs-automatio...
Wrongly issued debts? https://en.wikipedia.org/wiki/Robodebt_scheme
and so on and so forth
> And most importantly give me real examples of how exactly state intervention directly solves those problems.
Like they solve about a billion others of problems daily, and you have no issues with government interventions.
> Otherwise this is just a philosophical debate mixed with prepper type fear of what could happen.
It's only philosophical if you willingly ignore the world around you
Another commenter in this thread gave more examples, which further underline what I originally meant.
Physical harm means misclassified images/persons/posts/lifes/situations/... with the classification taken as gospel, in self-proclaimed good faith. Content moderation, credit scoring, police, the whole "new" generative space. — a lot of dangerous possibilities have opened.
All of them share the commonly accepted concept of "an a AI making a decision" (in common language).
This is another level of reliance, even if gradually, from computer systems and software in general.
I am not denying that complicated liability questions exist about that too.