23 karma · joined October 11, 2020
If a government entity bans a LLM provider due to a jailbreak concern, they can also ban an on-prem solution under the same guise. The jailbreak risk exists regardless of where it's hosted. You could defensibly argue the on-prem risk is higher since frontier model companies can justify safety spend due to their size, it's more difficult to combat bad actors if you're company is the only one using the model and you don't have economies of scale.
Assuming the rationale behind this is privacy, you could always choose questions that don't divuldge sensitive information while still allowing the user to identify themselves e.g. a user might not want to share their street name but presumably would not care about sharing the name of their first stuffed toy.
OSWAP has a good article on security questions: https://cheatsheetseries.owasp.org/cheatsheets/Choosing_and_...