The AI companies have clauses in their user agreements saying they can review content flagged as harmful. It’s not legally spying.
If you recall previous outrage about ChatGPT being used in cases of suicides or shootings, this is the result. Every time a crime was committed and the police found ChatGPT history about the crime, the media turned it into a frenzy. So the AI labs added safety filters to their consumer plans that detect threats of violence, escalate them to human review, and report to the police.
Spying is not the right analogy because the information was given to the police by a third party which had a EULA saying they would do this. A more analogous situation would be someone reading another person’s diary and then turning it into the police department. There might be some limitation in the law that makes the evidence inadmissible because it was not intended to be shared with anyone, but that’s a separate decision.
This is spying with extra steps couched in corporate speak.
Frustrations about Anthropic’s EULA are a separate matter.
Presumably, Anthropic did the spying and the reporting.
You argued that it is not spying, since the spying may have been made sufficiently explicit in the ToS/EULA.
This raises the question: Does announcing a spying operation mean that it is no longer spying? I've never heard that perspective before.
Well, kind of, yeah; the dictionary definition of spying requires secrecy and lack of consent.
> to secretly collect and report information about the activities of another country or organization[0]
The only real debate is whether or not having a clause tucked away in a EULA that few people read makes it a secret. If Anthropic had a big flashing red banner that said "FYI we automatically flag and review any conversations about illegal things!!" on the front page nobody would call it spying.
[0] https://dictionary.cambridge.org/dictionary/english/spying
A less central case would be when you clearly do know about the activity but you can't quite see the details, like with behavioral ad targeting or something. It feels pretty normal to me to call that spying even if it's disclosed to everyone and certainly happens to everyone, but it's also a less central example of the concept.
You can call it anything you like, but only the legal definitions matter for the legal case.
If you change the situation then yes you can in fact change our responses. The problem is you then are no longer talking about the original situation.
It also bears mentioning that providing a dictionary link to “spying” is pretty patronizing/passive aggressive. On par with sending a basic Wikipedia page. You didn’t even bother to post the definition you want to apply.
The initial comment instead questioned how someone could be accused of making a threat if they did not realize anyone would read their private content. You probably also can not insult someone with a statement you never expected anyone but you will ever read.
Eh. Both Superpowers knew that they were spying on each other all the time, and that was still considered to be spying. But feel free to replace the word "spying" with the phrase "clandestine largely-automated mass surveillance" if it makes you more comfortable.
> ...and lack of consent.
Given
* the fact that the contracts one is required to "agree" to in order to use most services are often novella-length or longer, and frequently include by reference other contracts of similar length
* that nearly all contracts like this have a clause where not only does the powerful party reserve the -very frequently-exercised- right to change the terms of the contract without any prior notice, but said party presumes that you automatically accept the rewritten contract and gives you no option to negotiate
I'd argue that the real situation on the ground -in the US, at least- is that "consumers" have consented to approximately zero of the contracts that -despite that lack of consent- legally bind them.
You don’t need to presume. Anthropic reported it.
“Spying” as a legal concept has a definition that does not apply here. You could say they were “spying” in the sense that they read someone’s input, but that’s literally what they said they were going to do in the agreement when the person signed up.
So I responded to the question about the case being thrown out for “spying” by trying to show that the word doesn’t apply in the legal sense. If you sign up for a service that says “Hey we’re going to monitor your chats and might report things to the authorities” and then they monitor your chats and report things to the authorities, you should not expect the case to be thrown out for “spying”.
"Anthropic" does not read messages, it's an abstract entity involving many humans and computers, so let's be specific wherever possible.
> and respond to it in some way.
The computer is supposed to respond in a specific way that doesn't involve humans. Any reading/actions by humans is entirely separate and not expected.
> If you sent an email to a colleague threatening violence, you would not be surprised to find out it was reported.
And if I didn't send it, I would be surprised.
They get friendly and loose-lipped with the bartender over the span of months. Eventually they let slip that they plan on killing their spouse for a life insurance payout. At first the bartender thinks they're joking, but it becomes evident that there's an actual plan being acted upon and someone's life is very likely in imminent danger.
Does the bartender have a responsibility to go to the police?
/s obviously
It's not 2005 anymore. If you think that there isn't any way for the people operating an online service to surface your activity on that service, or that there is but those people aren't doing so, there might not be anything left to convince you of it.
What you put into a text box online can be used against you. Period. You have to act accordingly.
If you are a business and I am using your services, it is pretty damn unethical and wrong to vacuum up my data and hand it off. Yes I know they all do it, I’m not naive. But a lot of comparisons people are making are not analogous to straight up sending a message or saying something to someone directly. Companies thrive on opacity and convoluted EULA’s to spy on us without clearly saying they are. Please do not talk down to me just because I’m talking about how things should be, about what is right and wrong, rather than blindly going “well AkShOoAlY you signed the thing and you should know that everyone is always trying to screw you so just live accordingly.“ I’m not OK with that, that is not how I want to live my life even if I am forced to, and I am going to make it known that I take issue with it.
Corporate surveillance is a blight, it is literally harming our society. Every time you tell people essentially “deal with it” you are reinforcing the current situation. Expect better from companies and society as a whole. Demand better.
You are clearly a smart person and you want to have a discussion, so is this the argument you want to make? Effectively defending companies by telling people to just suffer their abuses or keep their heads down?
But if you feel so moved to use the product or service, or must for some reason, well... don't mention that you're thinking about committing a crime.
Also, I'd say that this isn't quite as clear as vacuuming up people's data and handing it off. There's not much money in calling the police on your users. What there is, is reduced liability.
Preface: IANAL.
Let's say the user in the story told Claude (or whatever product of Anthropic's she was using) that she was thinking of attacking law enforcement, and actually carried out the attack. People are injured or killed. Facilities are damaged. She's either arrested or killed. Either way there's an investigation into what happened. Law enforcement looks at her digital footprint and sees that she had mentioned to Anthropic through Claude that she was thinking about committing the crime.
Since there's now loss involved - the health of the survivors, the lives of the dead, and the usability of the facility - there's now a search on how to recoup that loss monetarily. The lawyers file a suit alleging that Anthropic neglected their duty of care to their customers and the community, because supposedly Anthropic's worth hundreds of billions (if not trillions) of dollars and those bastards need to pay.
The typical legal shenaniganning by Anthropic's lawyers doesn't get the suit tossed and it goes to trial. Survivors talk about how their lives have been changed forever, and opposing counsel says it's because those damned tech bros with the data centers and the job-killing AI didn't report the threat to law enforcement. The jury, being made up of people from the general public (who are polling as antagonistic towards AI [0]), agrees. They award damages.
Other lawyers, having case law and a template for victory, smell blood in the water. They put out the "if you or a loved one" ads like they did for asbestos and tobacco companies, but for AI. Individual suits and class-actions are filed.
Now the company is facing potentially billions of dollars in judgments and investors are looking for the exit because, well, there's not any money in paying off legal judgments.
And that's before we take into account any regulations that get passed.
If you're Anthropic's corporate counsel, and you're faced with this possible scenario, you tell their C-suite that you will quite literally lunge over the table and throttle them if they don't implement a policy to inform law enforcement of possible threats found in chats.
[0] https://news.gallup.com/poll/712751/americans-cool-toward.as...
Good luck going through life without touching Google, Facebook, etc. You don’t even need to deliberately use them, they’re just everywhere. I have extensions and more trying to block their trackers every damn day. The amount of work I put into protecting my identity and data is insane and I know it’s still not enough. But here’s the relevant part and what I’m surprised I need to say: We can’t possibly expect the broader population to exert the same effort. It’s not reasonable to expect individuals to take on decades old near-trillion-dollar companies that are literally dictating legislation. Caveat emptor does in fact have limits. It’s not a fair fight at all.
Calling something names doesn't invalidate it. It only invalidates what point you're trying to make.
Then, you can write anything in an EULA but it is not automatically legal either.
So don't run for office or anything like that. Someone, somewhere will have a contact that will get that.
Obviously, it's hard to judge exactly what was appropriate there because we're being asked to extrapolate from a two word quote about the customer intending to "shoot up" the sheriff's office. Consider the following two statements, which express quite different levels of intentionality.
I got a $200 ticket from a sheriff's deputy today for throwing away an apple core. I'm so mad. I'd like to shoot up their office!
Those sheriff's deputies have exhausted my last reservoir of patience. I'm going to shoot up the department. They'll be sorry when they're sprawled all over the floor bleeding out from saucer-sized shotgun slug wounds. I can't wait to hear the screaming and crying of their miserable families!!"
I'm guessing that the diary entry was a more casual expression similar to the first statement, or they police would have quoted more of the statement to emphasize the apparent severity of the risk but it's hard to say without reading the charging documents.
With the obvious IANAL, it doesn't seem to rely on the message be sent to the person being threatened. The specific segment is "in any manner in which it may be viewed by another person".
This may be one of those cases where we get to find out how courts view SaaS platforms.
According to Gemini, "Florida appellate courts have overturned juvenile convictions [based on this law] when the state could not prove the person subjectively intended for the record to be seen."
The prosecutors likely know this and expect it. But there's enough gray area here for them to make the argument, and it's hard to prove malicious prosecution, so they know they'll get away with it. It's just about sending a message to the public - they don't care whether a conviction sticks. Just politics.
sandbox your ai.
Any failure to understand what it can access or what it has permission to see from the user's end is presumably not their problem. Regardless of what the user specifically asks of the tool.
this is exactly what I meant. I am presuming the danger is AI reacting to personal notes that it reads on your computer, like a diary, and you should not allow the tools to have access to those documents.
I dont really like this direction but it is what it is right now
Hopefully more of these stories push people towards local models :)
Note that the law doesn't forbid the writing of a threat. You have to send it to someone. Had she kept it in a book under her bed, she would not be in trouble. But she sent it to a website/service/LLM portal.
>> It is unlawful for any person to send, post, or transmit, or procure the sending, posting, or transmission of, a writing or other record, including an electronic record, in any manner in which it may be viewed by another person
FYI, the use of drafts folders to transmit messages has been used by terrorists. This is likely where CIA director David Petraeus got the idea when he needed a secure way to chat with his mistress.
https://www.findlaw.com/legalblogs/technologist/gen-petraeus...
This is a huge privacy problem that is only going to get worse.
Saving is not sending ie passive vs active act.
What if she put it in a locked box before shipping it to herself UPS, and she has the only key?
What if instead of UPS, she hired a moving company to move the locked box?
What if she wrote it electronically in diary.txt, but it was backed up to a cloud provider?
--
I'm guessing there's some sort of "reasonable expectation of privacy" for certain activities. We're going to find out what Florida courts think about this new medium.
Does the person have to know (or at least believe) that it will be viewed by another person?
She likely didn't think anyone would view it. Honestly, even as a career software developer I don't think it is unreasonable to think know would would see what she wrote to an AI. I assume most of what I write to an AI is not viewed by any other human, based simply on the quantity of messages sent back and forth to AIs, I would assume a vast majority are not read by another human.
What if she had written this into google docs, and she kept a diary there? That also crosses state lines, and is transmitted to another location.
You can argue from technicalities but they would need to prove intent.