> EU rules on AI models become enforceable. What's going to change?
I can answer that. A higher regulatory overhead that means less money for R&D and decreased profit margins for companies here in the EU. That's what's going to happen.
This is a bad counterpoint to "more regulation makes business harder". No regulation at all is probably the hardest business environment possible, but too much regulation is bad too.
Quantity of regulation isn't the point. It is quality. The right regulations are the right regulations. They mitigate risks and can encourage innovation. 'too much/too little' arguments are almost universally wrong.
There is no AI regulation in the US and look at where we are, everyone depends on it, SOTA models are doing CSAM and porn deepfakes, and there's no regulation in the US to prevent this from happening
nor there is regulation to inform a user something uses AI or the dangers of being dependent on this magical oracle.
Or having mandatory security checks in place after frequent accidents on supersonic planes is bad...
The aviation industry must be one of the most regulated ones and it's entirely necessary to guarantee the safety of passengers and crew. You don't see anyone complaining about it except Boeing who failed QA in the past couple of years and killed some hundreds of people due to their oversight.
Perhaps if the industry had been allowed to develop, we'd have some freaky ass new and innovative tech that would've abated the problem. The world may never know!
So basically "if they were only allowed to cause harm then maybe maybe one day they might have found a way to on their own for no profit stop doing that harm"? Yeah, no thank you. Also, all of corporate history shows that without a government or public pushback "will stop doing harm" never happens.
General statement that means zilch. Regulation depending on particular conditions can definitely curtail innovation or destroy it completely. Bureaucracy wants to regulate everything including how often we fart.
I repeat, if your business model (which like the big majority of the entrepreneurial world is based on) is against regulation, it's wrong.
I don't think it's acceptable to have a billionaire tech bro dictating everything I do in my life while he gets rich by selling my data. One of the reasons regulation exists is to protect customers.
It's about damn time the business world moved away from the capitalism mindset that you NEED to explore the consumer to be successful. We have a lot of examples in Europe where if the company is even a bit less shitty and is sympathetic to the customer, it increases trust and brings in more revenue because your customers trust it.
Just like Putin had Europe's best interest in mind regarding natural gas. At this point it's not a question of if Europe will become a puppet state but whose puppet state.
> The rulebook sets out rules for all models that lack a specific purpose but can be adapted to a variety of use cases, requiring transparency on how a model was built, disclosure of any copyright-protected content used for training, and enough information for downstream users to understand the model's capabilities.
Re. disclosure: How do they want to do it? It seems to be similar to a “disclosure” used in students’ works: “Source: internet”…
Seems quite sensible - good to see an institution woth some weight finally enforcing such basic principles that should have been universal - but money is of course more important for AI companies, making such regulation necessary.
> Re. disclosure: How do they want to do it? It seems to be similar to a “disclosure” used in students’ works: “Source: internet”…
I think enforcing compliance with the law will be rather simple, just like it happened with GDPR, food labeling and many other regulations. But I wonder how will the disclaimers/declarations even be verified? The more I think about it the more I see open sourced (both dataset and weights) models as the only truly verifiable solution. And that makes it less attractive as a business foundation if. So we might end up with state-funded models working in similar fashion to museums it other culture/art institutions ensuring that original material creators are treated fair. But that will bring whole other set of challenges...
Do you think that states have enough skillful ppl to run such a comparison model?
I remember European efforts to create search engine, digital library. And a lot of EU-funded projects in Horizon 2000 are useless, just an expensive bureaucracy…
GDPR and cookie consent bars are pain in the a* and ux/ui failures.
What I mean - intention is good, realisation is often bad. (But I don’t think that rest of world would be better btw :)
> In practice, for European consumers and businesses, that might mean some of the most advanced AI models launch in the EU a few weeks later than in other markets, as firms ensure they have done their compliance homework.
As models become more capable, this could have serious economic consequences. :(
Well, I am trying to inform myself because I did understand the cookie popups to be connected to GDPR. As far as I can tell from my reading, your assertion that "cookie popups have nothing to do with GDPR" is not true.
From my reading, it seems that while cookie permissions first became an explicit EU law concept in a 2009 amendment to ePrivacy Directive (not GDPR), companies were able to get away with passive consent banners (not popups).
It was GDPR's new definition of consent which then retroactively strengthened the existing ePrivacy Directive cookie consent to explicitly require user action to give consent (i.e. popups, banners large enough to push users to interact with them, etc.).
Unless your point is that GDPR has nothing to do with popups because the companies could just not use non-strictly-necessary cookies and therefore not need a popup, but I think that's a stretch to jump from there to "nothing to do with GDPR".
> (i.e. popups, banners large enough to push users to interact with them, etc.).
"i.e." doing a lot of work there.
GDPR doesn't require pop-ups or banners for providing consent. It mentions "ticking a box when visiting an internet website" as an example implementation. But it's just there as an example.
the mechanism for gathering consent is an implementation detail left to the site to handle because GDPR applies to far more than websites. i've had to provide consent for things completely unrelated to websites.
you could add a line of text saying "please write us a letter with the following information (user account, blah, blah) if you are willing to provide consent for optional tracking like blah blah" and this is perfectly in line with GDPR.
sure, it's more expensive and you'll get fewer people who you can track. but make no mistake, sites make a decision and choose pop-ups/banners as their implementation for gathering consent because they don't want to lose out. they're happy inflicting pop-ups/banners on their users instead so they can keep their precious tracking cookies going.
i.e. GDPR doesn't require pop-ups/banners, sites choose pop-ups/banners.
GDPR (and ePrivacy before that) requires valid prior consent where optional tracking is used. A site using only technically necessary storage can simply have no consent banner. A business wanting advertising and analytics trackers generally needs some consent interface.
"Not a requirement under GDPR", yes, but certainly not "nothing to do with GDPR". It directly has to do with GDPR, in conjunction with business' decisions and how to comply with the law.
And of course, we can then argue our faces off about what's good and necessary in the world, in businesses and data protection, but saying it has nothing to do with it is just wrong.
It’s insane how that misinformation doesn’t want to die. In 100y we will still have people repeating that we get popup because of gdpr, and nobody will know what a popup or gdpr is
Is it really misinformation? The popups may largely be a result of misunderstandings or malicious compliance, but GDPR has a causal relationship regardless of the intent.
I would however blame them if they wrote an ordinance that was widely misunderstood to mean that someone had to knock on my door each day to make sure I knew the local chemical factory had a fire alarm.
If the chemical factory sets themselves on fire every day to set off the fire alarm to annoy me to pressure me into removing the fire alarm law, I still blame them.
That'd be nice, but we could stop short of that and just ban anything that seems coercive (which iiuc is already the case, it's just not enforced effectively).
Moments ago it was "misunderstandings or malicious compliance". Did you misplace one on your apologetic quest?
I'm really trying not to assume the worst about you. Is there any reason you insist so much on giving the benefit of the doubt to every law breaker out there? Especially when we're sometimes talking about very deep pockets who can afford lawyers?
> a result of misunderstandings or malicious compliance, but GDPR has a causal relationship regardless of the intent.
You can extend causality as far as you want if you're willing to sound like this in the open. If there were no cookies, there'd be no banners. There, found you a new target.
So on one side you have decent regulation that tries to balance the interest of the user without over regulating and becoming too prescriptive, and on the other side you have abusers who most of the times are actually in malicious non-compliance... and you find a way to blame the regulation.
Good thing it's in the rules that HN is not Reddit.
Cookie popups were once issued by browsers in response to a Set-Cookie header. 25 years ago, it was fairly common to open the login page, type in your creds and _then_ hit "accept cookies from domain.com".
Some time after IE6 and Firefox and before Chrome, the default policy switched from "prompt" to "accept".
GDPR was an attempt to restore that default behavior, however no browser did so. I'd've guessed Mozilla could be convinced to revert, but Google presumably paid them enough to look the other way.
GDPR is more than that. Consent or not, there are things bad actors can do in the USA that in the EU they just can't. Specially to children and vulnerable people. GDPR is an integral part of it. This is a small but significant first step in the right direction. Long way ahead still.
Maybe but it feels like 1 step forward and 2 steps back. It feels like in the end they’re (companies) still getting 99% of what they had before and the user experience of everything is much worse.
The blah user experience isn't the whole picture for GDPR. It's just been the most visible part of it.
My personal GDPR hot take: it's actually been 2 steps forward and 1 super clumsy super loud and obnoxious step back.
I agree with the spirit of comment above. The common sense part of it (if there is one) might just end up eclipsed by wonky UX absurdity. Someone will find a way to paint this picture that our EU reality is a Kafkaesque dystopia.
Yes I used it when Confluence had a bug and an account with got stuck and there was no way to delete my account of finish the registration. So I issued a GDPR delete request and re-created the account. tada.wav
> EU rules on AI models become enforceable. What's going to change?
I can answer that. A higher regulatory overhead that means less money for R&D and decreased profit margins for companies here in the EU. That's what's going to happen.
If your sole business model depends on having no regulation then your business model is wrong and predatory.
Regulation doesn't hinder innovation, it's just that CEOs want that quick buck instead of being responsible and using regulation for their advantage.
This is a bad counterpoint to "more regulation makes business harder". No regulation at all is probably the hardest business environment possible, but too much regulation is bad too.
Quantity of regulation isn't the point. It is quality. The right regulations are the right regulations. They mitigate risks and can encourage innovation. 'too much/too little' arguments are almost universally wrong.
There is no AI regulation in the US and look at where we are, everyone depends on it, SOTA models are doing CSAM and porn deepfakes, and there's no regulation in the US to prevent this from happening
nor there is regulation to inform a user something uses AI or the dangers of being dependent on this magical oracle.
> There is no AI regulation in the US
Well, there's the White House blocking models on a whim. I guess that's the closest they'll get to something resembling regulation.
Too much regulation completely crippled the supersonic commercial flight industry.
So most people not wanting to hear sonic booms to benefit a small group of high wealth fliers is bad?
Or having mandatory security checks in place after frequent accidents on supersonic planes is bad...
The aviation industry must be one of the most regulated ones and it's entirely necessary to guarantee the safety of passengers and crew. You don't see anyone complaining about it except Boeing who failed QA in the past couple of years and killed some hundreds of people due to their oversight.
Perhaps if the industry had been allowed to develop, we'd have some freaky ass new and innovative tech that would've abated the problem. The world may never know!
So basically "if they were only allowed to cause harm then maybe maybe one day they might have found a way to on their own for no profit stop doing that harm"? Yeah, no thank you. Also, all of corporate history shows that without a government or public pushback "will stop doing harm" never happens.
> "if they were only allowed to cause harm then maybe maybe one day they might have found a way to on their own for no profit stop doing that harm"
You've put such discrediting words in my mouth with your straw man, touche! By the way, have you stopped beating your wife?
The industry was allowed to develop, but not allowed to cause harm.
Substitute develop with innovate and perhaps the thrust of my comment becomes more clear?
>"Regulation doesn't hinder innovation"
General statement that means zilch. Regulation depending on particular conditions can definitely curtail innovation or destroy it completely. Bureaucracy wants to regulate everything including how often we fart.
"Bureaucracy wants to regulate everything including how often we fart."
That is "reductio ad absurdum".
https://rationalwiki.org/wiki/Reductio_ad_absurdum
As I said, and others pointed out:
quality regulations don't curtail innovation.
I repeat, if your business model (which like the big majority of the entrepreneurial world is based on) is against regulation, it's wrong.
I don't think it's acceptable to have a billionaire tech bro dictating everything I do in my life while he gets rich by selling my data. One of the reasons regulation exists is to protect customers.
It's about damn time the business world moved away from the capitalism mindset that you NEED to explore the consumer to be successful. We have a lot of examples in Europe where if the company is even a bit less shitty and is sympathetic to the customer, it increases trust and brings in more revenue because your customers trust it.
Also going to have to compete against SOTA AI augmented American companies. Which likely means using Chinese models.
Thank god Xi Jinpeng has the best interests of Europe at heart...
Just like Putin had Europe's best interest in mind regarding natural gas. At this point it's not a question of if Europe will become a puppet state but whose puppet state.
Fortunately one can leave and live elsewhere...
Thanks, now I don't need to even read the article!
Mistral's already in the gutter, so not much change overall.
> The rulebook sets out rules for all models that lack a specific purpose but can be adapted to a variety of use cases, requiring transparency on how a model was built, disclosure of any copyright-protected content used for training, and enough information for downstream users to understand the model's capabilities.
Re. disclosure: How do they want to do it? It seems to be similar to a “disclosure” used in students’ works: “Source: internet”…
Seems quite sensible - good to see an institution woth some weight finally enforcing such basic principles that should have been universal - but money is of course more important for AI companies, making such regulation necessary.
No copyright intended
> Re. disclosure: How do they want to do it? It seems to be similar to a “disclosure” used in students’ works: “Source: internet”…
I think enforcing compliance with the law will be rather simple, just like it happened with GDPR, food labeling and many other regulations. But I wonder how will the disclaimers/declarations even be verified? The more I think about it the more I see open sourced (both dataset and weights) models as the only truly verifiable solution. And that makes it less attractive as a business foundation if. So we might end up with state-funded models working in similar fashion to museums it other culture/art institutions ensuring that original material creators are treated fair. But that will bring whole other set of challenges...
Do you think that states have enough skillful ppl to run such a comparison model?
I remember European efforts to create search engine, digital library. And a lot of EU-funded projects in Horizon 2000 are useless, just an expensive bureaucracy…
GDPR and cookie consent bars are pain in the a* and ux/ui failures.
What I mean - intention is good, realisation is often bad. (But I don’t think that rest of world would be better btw :)
/end-of-rant
Link to report AI https://digital-strategy.ec.europa.eu/en/policies/ai-act-whi...
Related:
EU will mandate labels on authentic-looking AI content starting August 2
https://news.ycombinator.com/item?id=49132341
> In practice, for European consumers and businesses, that might mean some of the most advanced AI models launch in the EU a few weeks later than in other markets, as firms ensure they have done their compliance homework.
As models become more capable, this could have serious economic consequences. :(
Seems to be that the compliance homework is exactly the kind of busy work that AI is good at. AI companies could just get AI to do it.
New pop-ups and more unreadable clauses you have to agree to. Remember GDPR?
Remember when HN used to have somewhat informed users? The trite cookie popups have nothing to do with GDPR, this has been repeated ad nauseam...
Well, I am trying to inform myself because I did understand the cookie popups to be connected to GDPR. As far as I can tell from my reading, your assertion that "cookie popups have nothing to do with GDPR" is not true.
From my reading, it seems that while cookie permissions first became an explicit EU law concept in a 2009 amendment to ePrivacy Directive (not GDPR), companies were able to get away with passive consent banners (not popups).
It was GDPR's new definition of consent which then retroactively strengthened the existing ePrivacy Directive cookie consent to explicitly require user action to give consent (i.e. popups, banners large enough to push users to interact with them, etc.).
Unless your point is that GDPR has nothing to do with popups because the companies could just not use non-strictly-necessary cookies and therefore not need a popup, but I think that's a stretch to jump from there to "nothing to do with GDPR".
https://gdpr.eu/cookies/
https://wp-gdpr.eu/gdpr-cookie-consent-2026/
https://eulawanalysis.blogspot.com/2022/01/consent-and-cooki...
> (i.e. popups, banners large enough to push users to interact with them, etc.).
"i.e." doing a lot of work there.
GDPR doesn't require pop-ups or banners for providing consent. It mentions "ticking a box when visiting an internet website" as an example implementation. But it's just there as an example.
https://gdpr.eu/Recital-32-Conditions-for-consent/
the mechanism for gathering consent is an implementation detail left to the site to handle because GDPR applies to far more than websites. i've had to provide consent for things completely unrelated to websites.
you could add a line of text saying "please write us a letter with the following information (user account, blah, blah) if you are willing to provide consent for optional tracking like blah blah" and this is perfectly in line with GDPR.
sure, it's more expensive and you'll get fewer people who you can track. but make no mistake, sites make a decision and choose pop-ups/banners as their implementation for gathering consent because they don't want to lose out. they're happy inflicting pop-ups/banners on their users instead so they can keep their precious tracking cookies going.
i.e. GDPR doesn't require pop-ups/banners, sites choose pop-ups/banners.
GDPR (and ePrivacy before that) requires valid prior consent where optional tracking is used. A site using only technically necessary storage can simply have no consent banner. A business wanting advertising and analytics trackers generally needs some consent interface.
"Not a requirement under GDPR", yes, but certainly not "nothing to do with GDPR". It directly has to do with GDPR, in conjunction with business' decisions and how to comply with the law.
And of course, we can then argue our faces off about what's good and necessary in the world, in businesses and data protection, but saying it has nothing to do with it is just wrong.
This being downvoted speaks saddens my heart... and proves the exact intent of the message.
It’s insane how that misinformation doesn’t want to die. In 100y we will still have people repeating that we get popup because of gdpr, and nobody will know what a popup or gdpr is
Is it really misinformation? The popups may largely be a result of misunderstandings or malicious compliance, but GDPR has a causal relationship regardless of the intent.
When the city writes an ordinance saying chemical factories must have fire alarms I do not blame the city for the fire alarm noise.
I would however blame them if they wrote an ordinance that was widely misunderstood to mean that someone had to knock on my door each day to make sure I knew the local chemical factory had a fire alarm.
If the chemical factory sets themselves on fire every day to set off the fire alarm to annoy me to pressure me into removing the fire alarm law, I still blame them.
I think we should make sure they're not allowed to do that, and actually enforce it.
So... Is your suggestion to ban tracking, marketing, analytics etc. non-essential cookies altogether?
That'd be nice, but we could stop short of that and just ban anything that seems coercive (which iiuc is already the case, it's just not enforced effectively).
I think so, and it's based.
> widely misunderstood
Moments ago it was "misunderstandings or malicious compliance". Did you misplace one on your apologetic quest?
I'm really trying not to assume the worst about you. Is there any reason you insist so much on giving the benefit of the doubt to every law breaker out there? Especially when we're sometimes talking about very deep pockets who can afford lawyers?
> I'm really trying not to assume the worst about you.
Well, you are. Maybe don't do that?
> a result of misunderstandings or malicious compliance, but GDPR has a causal relationship regardless of the intent.
You can extend causality as far as you want if you're willing to sound like this in the open. If there were no cookies, there'd be no banners. There, found you a new target.
So on one side you have decent regulation that tries to balance the interest of the user without over regulating and becoming too prescriptive, and on the other side you have abusers who most of the times are actually in malicious non-compliance... and you find a way to blame the regulation.
Good thing it's in the rules that HN is not Reddit.
If you think I'm opposed to GRPR, you are mistaken.
Popups have nothing to do with GDPR. They are reaction to Privacy and Electronic Communications Directive which predates GDPR.
And yes, it is deliberate misinformation.
Cookie popups pre-date GRPR, but find it hard to believe the uptick in popups that happened around May 2018 was in response to legislation from 2003.
Cookie popups were once issued by browsers in response to a Set-Cookie header. 25 years ago, it was fairly common to open the login page, type in your creds and _then_ hit "accept cookies from domain.com".
Some time after IE6 and Firefox and before Chrome, the default policy switched from "prompt" to "accept".
GDPR was an attempt to restore that default behavior, however no browser did so. I'd've guessed Mozilla could be convinced to revert, but Google presumably paid them enough to look the other way.
This is heavily downvoted ... and still accurate.
GDPR is more than that. Consent or not, there are things bad actors can do in the USA that in the EU they just can't. Specially to children and vulnerable people. GDPR is an integral part of it. This is a small but significant first step in the right direction. Long way ahead still.
Maybe but it feels like 1 step forward and 2 steps back. It feels like in the end they’re (companies) still getting 99% of what they had before and the user experience of everything is much worse.
The blah user experience isn't the whole picture for GDPR. It's just been the most visible part of it.
My personal GDPR hot take: it's actually been 2 steps forward and 1 super clumsy super loud and obnoxious step back.
I agree with the spirit of comment above. The common sense part of it (if there is one) might just end up eclipsed by wonky UX absurdity. Someone will find a way to paint this picture that our EU reality is a Kafkaesque dystopia.
Yes I used it when Confluence had a bug and an account with got stuck and there was no way to delete my account of finish the registration. So I issued a GDPR delete request and re-created the account. tada.wav
I've heard lots of people use it to actually find out what you were being banned for even when the company absolutely does not want to disclose it.
GDPR is actually good directive. Despite perpetual campaign against it from HN users who would like to abuse other peoples data.
The doers vs talkers of who can make AI accurate and consistent will step forward.