5 ms·
> Isn't this true of any complex law anywhere? The interpretation varies and is eventually decided upon by the courts and following that sometimes additional re
by zosima 3y ago
> Isn't this true of any complex law anywhere? The interpretation varies and is eventually decided upon by the courts and following that sometimes additional rectifying legislation.
Yes, but it'd definitely be nice if the lawmakers put some effort into avoiding it. E.g. by considering, whether we really need one more law for this situation (which is probably covered by 20 others anyway)
> I'm curious about what you mean here, do you have any specific examples?
There are many, a famous example was the regulations with regards to size and shape of fruits and vegetables, one example here for bananas: https://en.wikipedia.org/wiki/Commission_Regulation_(EC)_No._2257/94 https://en.wikipedia.org/wiki/Commission_Regulation_(EC)_No.... but there are many more. Standards to this level of details is definitely uncalled for.
But you can find these tidbits around a huge amount of legislation. See e.g. section (20) of the ePrivacy directive:
"(20) Service providers should take appropriate measures to safeguard the security of their services, if necessary in conjunction with the provider of the network, and inform subscribers of any special risks of a breach of the security of the network. Such risks may especially occur for electronic communications services over an open network such as the Internet or analogue mobile telephony. It is particularly important for subscribers and users of such services to be fully informed by their service provider of the existing security risks which lie outside the scope of possible remedies by the service provider. Service providers who offer publicly available electronic communications services over the Internet should inform users and subscribers of measures they can take to protect the security of their communications for instance by using specific types of software or encryption technologies. The requirement to inform subscribers of particular security risks does not discharge a service provider from the obligation to take, at its own costs, appropriate and immediate measures to remedy any new, unforeseen security risks and restore the normal security level of the service. The provision of information about security risks to the subscriber should be free of charge except for any nominal costs which the subscriber may incur while receiving or collecting the information, for instance by downloading an electronic mail message. Security is appraised in the light of Article 17 of Directive 95/46/EC."
This is all good and fine advice. But for a small company it's really not clear when it's appropriate to give advice on proper security habits for users. More, the vast majority of companies, dealing with communication, will be completely unaware of this law (and the 1000s of others similar provisions in other laws). This level of detail and vagueness should definitely not be in legislation.
A third recent example is the infamous AI act:
https://www.europarl.europa.eu/news/en/headlines/society/20230601STO93804/eu-ai-act-first-regulation-on-artificial-intelligence https://www.europarl.europa.eu/news/en/headlines/society/202...
See e.g. any AI system used in education need to be registered in a EU registry. In general there is a lot of good intentions, but there is simply no clear reason why there is a need for special regulation on AI. Everything that is forbidden to do without AI is also forbidden with AI. But EU constantly sees the need to spin new regulation, and all companies without an army of lawyers will be breaking one rule or another entirely without intent.
And these were just the ones on top of my mind. Go dig yourself, there are hundreds of thousands of pages of it.
- troupo 3y ago> In general there is a lot of good intentions, but there is simply no clear reason why there is a need for special regulation on AI. Everything that is forbidden to do without AI is also forbidden with AI. But EU constantly sees the need to spin new regulation Please stop spreading FUD. Here's a good overview of the AI regulation including the reasons why it's needed: https://softwarecrisis.dev/letters/the-truth-about-the-eu-act/ https://softwarecrisis.dev/letters/the-truth-about-the-eu-ac...
- zosima 3y agoI honestly just don't see it. I can not see anyway which anything is becoming better by this immature and ridiculous regulation. What it certainly does is put burdens on small companies, independent developers and open source projects. For no benefit whatsoever. And this is just the start.
- troupo 3y ago> I can not see anyway which anything is becoming better by this immature and ridiculous regulation. Have you read the link I provided? What exactly do you see as immature or ridiculous? > What it certainly does is put burdens on small companies, independent developers and open source projects. Of course it doesn't. That's why the major AI industries are so up in arms about it: because they have to document and describe their foundational models, and make sure their data is sound: something that they definitely don't want to do. Independent devs and open source will be fine: they already (mostly) do that. It's GDPR all over again: the industry fights it tooth and nail because they couldn't be arsed to play nice. This time the FUD has been launched preemptively in hopes to stifle this.
- zosima 3y ago> Of course it doesn't. That's why the major AI industries are so up in arms about it: because they have to document and describe their foundational models, and make sure their data is sound: something that they definitely don't want to do. This is now true for any 1 or 2 person startup. Making it completely impossible to succeed without huge amounts of capital. Congratulations on completely stifling innovation and making life a lot worse for everyone. > Independent devs and open source will be fine: they already (mostly) do that. They are now running the legal risk of the EU commission or some national bureaucrat thinking their models training data are not representative enough or documentation insufficient. How can these things even begin to become judicial questions?