7 ms·
German here, trying not to sound too polemic: Is it known if this initiative (and other "acts" like AI Act) is lobbied for by SAP, MS and the likes? To me, thi
by nforgerit 3y ago
German here, trying not to sound too polemic:
Is it known if this initiative (and other "acts" like AI Act) is lobbied for by SAP, MS and the likes? To me, this looks so much like an attack by enterprises against startup competition who cannot afford legal insecurities/legal departments/security certifications, that I can barely understand such a governmental interference without thinking about bad actors.
- miohtama 3y agoI believe the EU is not “attacking”. It’s generally the EU’s insecurity over anything technical, as there is no good homegrown ecosystem for software, AI, etc. Brussels thinks it can fix this by regulating large American enterprises and making them dance on its music. Also, generally politicals want to control everything and do not see the harmful side effects of regulation. You are not going to get re-elected by de-regulation. “Think of the children” and any AI, cryptocurrency etc. doomsday porn is sure way to get headlines and get your name out in the press. The root cause of the problem of why the EU lacks software startups and AI startups compared to the US and China remains unaddresed. In the end the result is that more and more business is infeasible in the EU, for both EU citizens and foreigners and will just move to elsewhere.
- loup-vaillant 3y agoI’ve skimmed over a previous version of this proposed law. And while we moan here about who this applies to, we ignore what is being required. From what I’ve read, the requirements looked eminently reasonable. To the point where not following them right now is kind of unethical. Even if you’re an unpaid open source hobby project. In some domains this is widely understood: I myself have been heavily criticised for having released a cryptographic library, even though I took every precaution I possibly could. While I do think much of this criticism was unfounded knee-jerk reactions, the idea behind it, that it is serious stuff, is actually good. Thing is, security products aren’t the only "serious stuff" out there. Anything that parses untrusted input (any reader, any network server…) can have serious vulnerabilities, and as such is kind of serious too. Thus, my opinion here is that pretty much any published software should follow this regulation, even if it isn’t bound by it.