8 ms·
Three major LLM releases in 24 hours
- lambdaba 2y agoDoes anyone know what's up with the models that aren't available in Europe? There isn't any transparency over this.
- junon 2y agoThey probably aren't up to GDPR standards. Take from that what you will. It's the typical reason why they don't release here.
- lagrange77 2y agoHow can a model not be up to GDPR standards? Or are you talking about the services that provide those models? Genuinely interested.
- chpatrick 2y agoI would imagine that they hoovered up a lot of data from the internet to train it and don't know if it's private or not. They can't guarantee that the model won't print your home address if you ask it the right way.
- yreg 2y agoIn that case it wouldn't matter where they make it available. GDPR protects EU citizens' data everywhere, including in US.
- dekhn 2y agoI'm not really sure the law could work that way. I mean in the sense that they may have codified that but realistically I think a nation's laws ended their borders typically
- yreg 2y agoGDPR applies globally. If you handle EU citizens data, you must conform to it. Of course you might not care, if you believe that the EU has no way of forcing you to pay a fine and if you are certain that you are never going to do any business in the EU. But in such case you might as well provide access to your models for EU IPs too. It makes no difference.
- dekhn 2y agohow can a law apply globally? Ignore the idea that EU can fine you, under what basis do laws of a country apply to actions outside the country?
- stavros 2y agoYeah, but the EU can't do anything to you if you don't sell to the EU in the first place.
- ben_w 2y agoAny personal information which gets into those models makes them incompatible, by my (IANAL) reading. https://gdpr.eu/what-is-gdpr/ https://gdpr.eu/what-is-gdpr/ "Personal data" and "data processing" are (deliberately) drawn very broadly: """Personal data — Personal data is any information that relates to an individual who can be directly or indirectly identified. Names and email addresses are obviously personal data. Location information, ethnicity, gender, biometric data, religious beliefs, web cookies, and political opinions can also be personal data. Pseudonymous data can also fall under the definition if it’s relatively easy to ID someone from it. Data processing — Any action performed on data, whether automated or manual. The examples cited in the text include collecting, recording, organizing, structuring, storing, using, erasing… so basically anything.""" And, unlike the arguments about copyright in big AI models trained on the internet (is it 'fair use'? Don't ask me, IANAL!), the requirement for explicit and informed consent is something a general crawl will very clearly fail: """Purpose limitation — You must process data for the legitimate purposes specified explicitly to the data subject when you collected it.""" Furthermore, we don't know enough about how the models store knowledge/beliefs to be able to make any claim about accuracy: """Accuracy — You must keep personal data accurate and up to date.""" And as for confidentiality… for downloadable models, that's "by obscurity" only, due to the exact same research needed to resolve the previous point about accuracy, and even for secret models like GPT-4, nobody's really sure how to actually guarantee it won't leak info with the right prompt, and there's even some suggestion that this is actually impossible with current approaches because nothing is really deleted by RLHF: """Integrity and confidentiality — Processing must be done in such a way as to ensure appropriate security, integrity, and confidentiality (e.g. by using encryption)."""
- lagrange77 2y agoOk, thanks. But does not providing - the personal data you can not have or process - to the EU market, make your position any better, legally?
- junon 2y agoIf it's trained on data covered under the GDPR then it means you're 1) a "data processor" of that information and 2) there's a risk of it reproducing that information in some form. In the case of #1, they probably do not have an agreement with the "data controller" in the case of scraping, which means #2 is a violation of GDPR. IANAL.
- thibaut_barrere 2y agoWith people feeding more and more delicate questions (e.g. medical, mental health etc), which can lead to more trouble with what may be stored temporarily etc, GDPR definitely has an impact here (developers must take special care to be compliant etc).
- HlessClaudesman 2y agoYeah it's fear of GDPR, which is kind of like a retroactive set of standards: "we'll know an infringement when we see it", type vibe. Which of course is kryptonite to innovation, and ultimatly will lead to a more fragmented internet. As a European I to try see it from both sides, consumer protections are generally a good thing, but it right now being restricted by EU vagueness sucks ass because I just want to play with the cool new toys.
- YetAnotherNick 2y agoThis comment always gets downvoted, but I have seen this happen in my previous company. They hired an expensive lawyer from Europe for GDPR compliance and even his suggestions didn't made sense and in the end we decided to geoblock Europe. e.g. EU didn't clearly banned consent rejection requiring more effort and just skirted around it and that's why every company have two step rejection and one step acceptance. They could have easily made law requiring sites accept DNT header but they didn't likely because of lobbying.
- saikia81 2y agoThe first part of your comment lacks understanding of how and why the consent rejection has been worded as it has. If you want to comply it is easy. But if a company wants to skirt the regulation it is written such that the regulatory body can still get you for making it harder. DNT is not relevant as GDPR is not directly a regulation against tracking, and it certainly isn't because of lobbying.
- YetAnotherNick 2y agoNot only I don't understand it, the top tier European law firm the company hired also didn't understood it. The law ALLOWS companies to skirt around it. I don't know if that's intentional or not. > If you want to comply it is easy. That's the entire antithesis of modern law as opposed to monarchy. Law should be codified in as clear rules as possible.
- thibaut_barrere 2y ago
- MyAccountYo 2y agoI think it is mostly for these reasons: * It's complicated so it takes a while and you need lawyers and such to make it right * Rules for training are probably hugely vague and undefined. Because you could ingest personal data and it cannot be deleted * AFAIK it needs to be hosted in Europe (not directly GDPR related, but america has laws that allows them to spy on all traffic in the US, so this is somewhat the counter to that) In the end from my experience just working at a company that needs to be compliant this usually means: * All the services need to be hosed in EU including 3rd parties we send any data to * There needs to be a way (email is enough) to delete user data (including from 3rd parties which need an endpoint so you can trigger it from your side) * You need to inform the user about the data useage and allow them to opt out of the "usage" of this data for non-essential things (i.e marketing emails). This does not mean you cannot save this data if you also use it for other things, but you can not use it for the non-essential case. * You could be in trouble if you save data "just because" and do not use it for anything essential or if it is not transparent to the user. Not a lawyer. Just the things I notice in my day to day. In the end companies need data protection professionals to navigate these things. Which is probably another thing a startup does not worry about it early on.
- passwordoops 2y agopure speculation If I'm to venture a guess, it's probably because data protections are stronger and they want to avoid potential issues should someone test GDPR (or whatever the applicable law is) by asking specific data be removed from the model
- ectopasm83 2y ago[dead]
- deleted 2y ago[deleted]
- mrtksn 2y agoAnd this affects UK, How? The one not available is Gemini Pro and its not available in UK too according to the article.
- ectopasm83 2y agoGP was talking about Europe
- satiric 2y agoThe UK is still in the continent of Europe. Last I checked, it hadn't swum across the ocean to America...
- ectopasm83 2y agoI still don't understand why the UK is so central to this discussion. What did I miss ?
- ThomPete 2y agoBecause the EU have decided to make it extremely hard for Europeans to benefit from technological advantages trough their GDPR, Cookie Laws and soon AI Act.
- saikia81 2y agoSafety does make things harder for those that want to abuse us. We don't want technology at all costs.
- ThomPete 2y agoThere is nothing safe about cookie law or GDPR. They are literally doing the opposite because they are asking you to commit to the terms and since everyone do you have actually consented to your data being used. AI Act isn't solving anything that isn't already solved with existing regulation. That so many people on HN seem to think this is a good idea is very puzzling.
- deleted 2y ago[deleted]
- dontupvoteme 2y agoThey're worried about GDPR with chatbots, but e.g. Claude is available via API.
- speedgoose 2y agoHow hard is it to ask for informed consent?
- AtlasBarfed 2y agoPretty easy, simply bombard the user with consent forms every request until they click on "accept all".
- deleted 2y ago[deleted]
- layer8 2y agoThey’d actually have to make sure to correctly inform the user.
- karmasimida 2y agoRegulation too cumbersome, not worth it. What is the downvote coming from, isn't this just facts? If not for the regulation, why would EU be shunned?
- speedgoose 2y agoI don't know. I have an organisation account on Anthropic to use Claude 3, and the credit card is norwegian, the phone number is norwegian, the email finishes with a .no, the country in the address says Norway, and the business tax id is a norwegian VAT number. Sounds like they actually don't mind the regulations for businesses.
- fragmede 2y agoWhat is 2% of Anthropic's global revenue, and what is 2% of Google's global revenue? The penalty for Google getting it wrong are much much higher. Anthropic can get away with moving fast and breaking things (like the GDPR). Google has no such luxury.
- black3r 2y agoOpenAI doesn't have this issue so it begs the question which part of the regulation is not compliant and why, if it's just Google being lazy, or if they actively do something sketchy and don't want to stop.
- karmasimida 2y agoGoogle is a much bigger target than OpenAI from EU regulations perspective. They are going after Google
- Zetobal 2y agoIf other entities do the same thing without problems it's most of the time a you problem.
- jeswin 2y agoDoes Gemini have a prepaid mode? I like that both OpenAI and Anthropic default to the prepaid mode; I can safely experiment without worrying about selecting a large file by mistake (or worse, a runaway automated process).
- tarruda 2y agoOne of the most attractive features about Mistral open models is that you can build a product on top of their API, and switch to a self hosted version if the need arises, such as customer requesting to run onprem due to privacy requirements, or the API service being taken down.
- tomschwiha 2y agoUsing Mistral together with groq is amazing. The reason to be able to migrate is for me personally a huge plus.
- inference-lord 2y agoI guess this is what the singularity looks like?
- mg 2y agoAre any of these stable? I mean when using temperature=0, do you get the same reply for the same prompt? I am using gpt-4-1106-preview quite a lot, but it is hard to optimize prompts when you cannot build a test-suite of questions and correct replies against which you can test and improve the instruction prompt. Even when using temperature=0, gpt-4-1106-preview outputs different answers for the same prompt.
- tomschwiha 2y agoWouldn't be for reproducability the usage of a seed be a better fit? [0] https://platform.openai.com/docs/api-reference/chat/create#chat-create-seed https://platform.openai.com/docs/api-reference/chat/create#c...
- mg 2y agoI just tried the same prompt twice, both with 'temperature': 0, 'seed': 1, And I got two different replies. The 'system_fingerprint' in the reply was the same in both of the json responses. So it seems that even when you get the same 'system_fingerprint' back, replies for the same prompt will not be the same.
- phillipcarter 2y ago> [...] but it is hard to optimize prompts when you cannot build a test-suite of questions and correct replies against which you can test and improve the instruction prompt. I think this is because your approach isn't right. This tech isn't really unit-testable in the same sense. In fact, for many use cases, you may want non-deterministic results by design. Instead, you probably need evaluations. The idea is that you're still building out "test" cases, but instead of expecting a specific result each time, you get a result that you can score through some means. Each test case produces a score, and you get a rollup score for the suite, and that's how you can track regressions over time. For example, in our use case, we produce structured JSON that has to match a spec, but we also want to have the contents of that valid-to-spec JSON object be "useful". So there's a function that defines "usefulness" based on some criteria that I've put together since I'm a domain expert. This is something I can evolve over time, using real-world inputs that produce bad or unsatisfying outputs as new evaluations for the evaluation suite. Fair warning though, it's not very easy to get started with, and there's not a whole lot of information about doing it well online.
- novaRom 2y agoCohere’s Command R+ is unimpressive model, because it agrees with me every time I try to argue with smth like: "But are you sure? ..."; also it has: "last update in January 2023". Mixtral 8x22B is interesting because 8x7B was one of the best (among all others) for me few months ago (in particular, common knowledge, engineering and high-level math, multi-lingual skills like translation, grammatically nicer rewritings)
- loudmax 2y agoI haven't tried it yet, but if the model itself isn't impressive, that 128k context window is. That's the largest I think I've seen for any open weights model.
- rel2thr 2y agois the point of system prompts just to avoid prompt injection? or are they supposed to get better outputs too? I never have found a need for them. i.e. the example in the article Just prompting like: Write hello 3 different ways in spanish works fine for me
- simonw 2y agoThey let you at least partially separate instructions from data. This is useful for things like "Translate this text to French" - you don't want any instructions in the text you are translating to interfere with that goal. If this was 100% robust then it would also solve prompt injection, but sadly it isn't.
- deleted 2y ago[deleted]
- loudmax 2y agoFor those primarily interested in open weight models, that Mixtral 8x22B is really intriguing. The Mistral models have tended to outperform other models with similar parameter counts. Still 281GB is huge. That's at the higher end of what we see from other open weight models, and it's not going to fit on anybody's homelab franken-GPU rig. Assuming that 281GB is fp16, it should quantize down to roughly 70GB at 4bits. Still too big for any consumer grade GPU, but accessible on a workstation with enough system ram. Mixtral 8x7B runs surprisingly fast, even on CPUs. Hopefully this 8x22B model will perform similarly. EDIT: Available here in GGUF format: https://huggingface.co/MaziyarPanahi/Mixtral-8x22B-v0.1-GGUF https://huggingface.co/MaziyarPanahi/Mixtral-8x22B-v0.1-GGUF The 2-bit quantization comes to 52GB, so worse than my napkin math suggested. Looking forward to giving it a try on my desktop though.