\

EU rules on AI models become enforceable. What's going to change?

38 points - today at 7:40 PM

Source
  • pelorat

    today at 8:23 PM

    > EU rules on AI models become enforceable. What's going to change?

    I can answer that. A higher regulatory overhead that means less money for R&D and decreased profit margins for companies here in the EU. That's what's going to happen.

      • xinayder

        today at 8:53 PM

        If your sole business model depends on having no regulation then your business model is wrong and predatory.

        Regulation doesn't hinder innovation, it's just that CEOs want that quick buck instead of being responsible and using regulation for their advantage.

          • BobbyJo

            today at 9:03 PM

            This is a bad counterpoint to "more regulation makes business harder". No regulation at all is probably the hardest business environment possible, but too much regulation is bad too.

              • jmward01

                today at 9:09 PM

                Quantity of regulation isn't the point. It is quality. The right regulations are the right regulations. They mitigate risks and can encourage innovation. 'too much/too little' arguments are almost universally wrong.

                • xinayder

                  today at 9:12 PM

                  There is no AI regulation in the US and look at where we are, everyone depends on it, SOTA models are doing CSAM and porn deepfakes, and there's no regulation in the US to prevent this from happening

                  nor there is regulation to inform a user something uses AI or the dangers of being dependent on this magical oracle.

                    • vanviegen

                      today at 9:21 PM

                      > There is no AI regulation in the US

                      Well, there's the White House blocking models on a whim. I guess that's the closest they'll get to something resembling regulation.

              • nozzlegear

                today at 9:04 PM

                Too much regulation completely crippled the supersonic commercial flight industry.

                  • bob001

                    today at 9:08 PM

                    So most people not wanting to hear sonic booms to benefit a small group of high wealth fliers is bad?

                      • xinayder

                        today at 9:10 PM

                        Or having mandatory security checks in place after frequent accidents on supersonic planes is bad...

                        The aviation industry must be one of the most regulated ones and it's entirely necessary to guarantee the safety of passengers and crew. You don't see anyone complaining about it except Boeing who failed QA in the past couple of years and killed some hundreds of people due to their oversight.

                        • nozzlegear

                          today at 9:11 PM

                          Perhaps if the industry had been allowed to develop, we'd have some freaky ass new and innovative tech that would've abated the problem. The world may never know!

                            • vanviegen

                              today at 9:18 PM

                              The industry was allowed to develop, but not allowed to cause harm.

                  • FpUser

                    today at 9:14 PM

                    >"Regulation doesn't hinder innovation"

                    General statement that means zilch. Regulation depending on particular conditions can definitely curtail innovation or destroy it completely. Bureaucracy wants to regulate everything including how often we fart.

                      • xinayder

                        today at 9:18 PM

                        As I said, and others pointed out:

                        quality regulations don't curtail innovation.

                        I repeat, if your business model (which like the big majority of the entrepreneurial world is based on) is against regulation, it's wrong.

                        I don't think it's acceptable to have a billionaire tech bro dictating everything I do in my life while he gets rich by selling my data. One of the reasons regulation exists is to protect customers.

                        It's about damn time the business world moved away from the capitalism mindset that you NEED to explore the consumer to be successful. We have a lot of examples in Europe where if the company is even a bit less shitty and is sympathetic to the customer, it increases trust and brings in more revenue because your customers trust it.

                • WarmWash

                  today at 8:42 PM

                  Also going to have to compete against SOTA AI augmented American companies. Which likely means using Chinese models.

                  Thank god Xi Jinpeng has the best interests of Europe at heart...

                  • today at 9:31 PM

                    • Frannky

                      today at 9:04 PM

                      Fortunately one can leave and live elsewhere...

                      • DarkNova6

                        today at 8:38 PM

                        Thanks, now I don't need to even read the article!

                        • moffkalast

                          today at 8:48 PM

                          Mistral's already in the gutter, so not much change overall.

                      • sixtyj

                        today at 8:08 PM

                        > The rulebook sets out rules for all models that lack a specific purpose but can be adapted to a variety of use cases, requiring transparency on how a model was built, disclosure of any copyright-protected content used for training, and enough information for downstream users to understand the model's capabilities.

                        Re. disclosure: How do they want to do it? It seems to be similar to a “disclosure” used in students’ works: “Source: internet”…

                          • ArekDymalski

                            today at 9:03 PM

                            > Re. disclosure: How do they want to do it? It seems to be similar to a “disclosure” used in students’ works: “Source: internet”…

                            I think enforcing compliance with the law will be rather simple, just like it happened with GDPR, food labeling and many other regulations. But I wonder how will the disclaimers/declarations even be verified? The more I think about it the more I see open sourced (both dataset and weights) models as the only truly verifiable solution. And that makes it less attractive as a business foundation if. So we might end up with state-funded models working in similar fashion to museums it other culture/art institutions ensuring that original material creators are treated fair. But that will bring whole other set of challenges...

                            • Retr0id

                              today at 8:13 PM

                              No copyright intended

                          • szczepano

                            today at 9:05 PM

                            Link to report AI https://digital-strategy.ec.europa.eu/en/policies/ai-act-whi...

                            • cubefox

                              today at 8:52 PM

                              > In practice, for European consumers and businesses, that might mean some of the most advanced AI models launch in the EU a few weeks later than in other markets, as firms ensure they have done their compliance homework.

                              As models become more capable, this could have serious economic consequences. :(

                                • jay_kyburz

                                  today at 8:57 PM

                                  Seems to be that the compliance homework is exactly the kind of busy work that AI is good at. AI companies could just get AI to do it.

                              • kamma4434

                                today at 8:03 PM

                                New pop-ups and more unreadable clauses you have to agree to. Remember GDPR?

                                  • elcdodedocle

                                    today at 8:14 PM

                                    GDPR is more than that. Consent or not, there are things bad actors can do in the USA that in the EU they just can't. Specially to children and vulnerable people. GDPR is an integral part of it. This is a small but significant first step in the right direction. Long way ahead still.

                                      • hellisothers

                                        today at 8:47 PM

                                        Maybe but it feels like 1 step forward and 2 steps back. It feels like in the end they’re (companies) still getting 99% of what they had before and the user experience of everything is much worse.

                                        • dev_l1x_be

                                          today at 8:42 PM

                                          Yes I used it when Confluence had a bug and an account with got stuck and there was no way to delete my account of finish the registration. So I issued a GDPR delete request and re-created the account. tada.wav

                                            • MaxMatti

                                              today at 8:45 PM

                                              I've heard lots of people use it to actually find out what you were being banned for even when the company absolutely does not want to disclose it.

                                      • embedding-shape

                                        today at 8:14 PM

                                        Remember when HN used to have somewhat informed users? The trite cookie popups have nothing to do with GDPR, this has been repeated ad nauseam...

                                          • jshmrsn

                                            today at 9:08 PM

                                            Well, I am trying to inform myself because I did understand the cookie popups to be connected to GDPR. As far as I can tell from my reading, your assertion that "cookie popups have nothing to do with GDPR" is not true.

                                            From my reading, it seems that while cookie permissions first became an explicit EU law concept in a 2009 amendment to ePrivacy Directive (not GDPR), companies were able to get away with passive consent banners (not popups).

                                            It was GDPR's new definition of consent which then retroactively strengthened the existing ePrivacy Directive cookie consent to explicitly require user action to give consent (i.e. popups, banners large enough to push users to interact with them, etc.).

                                            Unless your point is that GDPR has nothing to do with popups because the companies could just not use non-strictly-necessary cookies and therefore not need a popup, but I think that's a stretch to jump from there to "nothing to do with GDPR".

                                            https://gdpr.eu/cookies/

                                            https://wp-gdpr.eu/gdpr-cookie-consent-2026/

                                            https://eulawanalysis.blogspot.com/2022/01/consent-and-cooki...

                                            • jstummbillig

                                              today at 8:43 PM

                                              GDPR (and ePrivacy before that) requires valid prior consent where optional tracking is used. A site using only technically necessary storage can simply have no consent banner. A business wanting advertising and analytics trackers generally needs some consent interface.

                                              "Not a requirement under GDPR", yes, but certainly not "nothing to do with GDPR". It directly has to do with GDPR, in conjunction with business' decisions and how to comply with the law.

                                              And of course, we can then argue our faces off about what's good and necessary in the world, in businesses and data protection, but saying it has nothing to do with it is just wrong.

                                              • DarkNova6

                                                today at 8:40 PM

                                                This being downvoted speaks saddens my heart... and proves the exact intent of the message.

                                                • dgellow

                                                  today at 8:18 PM

                                                  It’s insane how that misinformation doesn’t want to die. In 100y we will still have people repeating that we get popup because of gdpr, and nobody will know what a popup or gdpr is

                                                    • Retr0id

                                                      today at 8:28 PM

                                                      Is it really misinformation? The popups may largely be a result of misunderstandings or malicious compliance, but GDPR has a causal relationship regardless of the intent.

                                                        • inigyou

                                                          today at 8:43 PM

                                                          When the city writes an ordinance saying chemical factories must have fire alarms I do not blame the city for the fire alarm noise.

                                                            • Retr0id

                                                              today at 8:52 PM

                                                              I would however blame them if they wrote an ordinance that was widely misunderstood to mean that someone had to knock on my door each day to make sure I knew the local chemical factory had a fire alarm.

                                                                • buran77

                                                                  today at 9:06 PM

                                                                  > widely misunderstood

                                                                  Moments ago it was "misunderstandings or malicious compliance". Did you misplace one on your apologetic quest?

                                                                  I'm really trying not to assume the worst about you. Is there any reason you insist so much on giving the benefit of the doubt to every law breaker out there? Especially when we're sometimes talking about very deep pockets who can afford lawyers?

                                                                    • Retr0id

                                                                      today at 9:16 PM

                                                                      > I'm really trying not to assume the worst about you.

                                                                      Well, you are. Maybe don't do that?

                                                                  • inigyou

                                                                    today at 9:09 PM

                                                                    If the chemical factory sets themselves on fire every day to set off the fire alarm to annoy me to pressure me into removing the fire alarm law, I still blame them.

                                                                      • Retr0id

                                                                        today at 9:13 PM

                                                                        I think we should make sure they're not allowed to do that, and actually enforce it.

                                                            • buran77

                                                              today at 8:56 PM

                                                              > a result of misunderstandings or malicious compliance, but GDPR has a causal relationship regardless of the intent.

                                                              You can extend causality as far as you want if you're willing to sound like this in the open. If there were no cookies, there'd be no banners. There, found you a new target.

                                                              So on one side you have decent regulation that tries to balance the interest of the user without over regulating and becoming too prescriptive, and on the other side you have abusers who most of the times are actually in malicious non-compliance... and you find a way to blame the regulation.

                                                              Good thing it's in the rules that HN is not Reddit.

                                                                • Retr0id

                                                                  today at 9:04 PM

                                                                  If you think I'm opposed to GRPR, you are mistaken.

                                                              • watwut

                                                                today at 8:43 PM

                                                                Popups have nothing to do with GDPR. They are reaction to Privacy and Electronic Communications Directive which predates GDPR.

                                                                And yes, it is deliberate misinformation.

                                                                  • Retr0id

                                                                    today at 8:58 PM

                                                                    Cookie popups pre-date GRPR, but find it hard to believe the uptick in popups that happened around May 2018 was in response to legislation from 2003.

                                                                      • za_creature

                                                                        today at 9:17 PM

                                                                        Cookie popups were once issued by browsers in response to a Set-Cookie header. 25 years ago, it was fairly common to open the login page, type in your creds and _then_ hit "accept cookies from domain.com".

                                                                        Some time after IE6 and Firefox and before Chrome, the default policy switched from "prompt" to "accept".

                                                                        GDPR was an attempt to restore that default behavior, however no browser did so. I'd've guessed Mozilla could be convinced to revert, but Google presumably paid them enough to look the other way.

                                                        • watwut

                                                          today at 8:38 PM

                                                          This is heavily downvoted ... and still accurate.

                                                      • watwut

                                                        today at 8:37 PM

                                                        GDPR is actually good directive. Despite perpetual campaign against it from HN users who would like to abuse other peoples data.

                                                    • j45

                                                      today at 8:19 PM

                                                      The doers vs talkers of who can make AI accurate and consistent will step forward.