6 ms·
Does anyone know what's up with the models that aren't available in Europe? There isn't any transparency over this.
by lambdaba 3y ago
Does anyone know what's up with the models that aren't available in Europe? There isn't any transparency over this.
- junon 3y agoThey probably aren't up to GDPR standards. Take from that what you will. It's the typical reason why they don't release here.
- lagrange77 3y agoHow can a model not be up to GDPR standards? Or are you talking about the services that provide those models? Genuinely interested.
- chpatrick 3y agoI would imagine that they hoovered up a lot of data from the internet to train it and don't know if it's private or not. They can't guarantee that the model won't print your home address if you ask it the right way.
- yreg 2y agoIn that case it wouldn't matter where they make it available. GDPR protects EU citizens' data everywhere, including in US.
- dekhn 2y agoI'm not really sure the law could work that way. I mean in the sense that they may have codified that but realistically I think a nation's laws ended their borders typically
- yreg 2y agoGDPR applies globally. If you handle EU citizens data, you must conform to it. Of course you might not care, if you believe that the EU has no way of forcing you to pay a fine and if you are certain that you are never going to do any business in the EU. But in such case you might as well provide access to your models for EU IPs too. It makes no difference.
- dekhn 2y agohow can a law apply globally? Ignore the idea that EU can fine you, under what basis do laws of a country apply to actions outside the country?
- stavros 2y agoYeah, but the EU can't do anything to you if you don't sell to the EU in the first place.
- ben_w 3y agoAny personal information which gets into those models makes them incompatible, by my (IANAL) reading. https://gdpr.eu/what-is-gdpr/ https://gdpr.eu/what-is-gdpr/ "Personal data" and "data processing" are (deliberately) drawn very broadly: """Personal data — Personal data is any information that relates to an individual who can be directly or indirectly identified. Names and email addresses are obviously personal data. Location information, ethnicity, gender, biometric data, religious beliefs, web cookies, and political opinions can also be personal data. Pseudonymous data can also fall under the definition if it’s relatively easy to ID someone from it. Data processing — Any action performed on data, whether automated or manual. The examples cited in the text include collecting, recording, organizing, structuring, storing, using, erasing… so basically anything.""" And, unlike the arguments about copyright in big AI models trained on the internet (is it 'fair use'? Don't ask me, IANAL!), the requirement for explicit and informed consent is something a general crawl will very clearly fail: """Purpose limitation — You must process data for the legitimate purposes specified explicitly to the data subject when you collected it.""" Furthermore, we don't know enough about how the models store knowledge/beliefs to be able to make any claim about accuracy: """Accuracy — You must keep personal data accurate and up to date.""" And as for confidentiality… for downloadable models, that's "by obscurity" only, due to the exact same research needed to resolve the previous point about accuracy, and even for secret models like GPT-4, nobody's really sure how to actually guarantee it won't leak info with the right prompt, and there's even some suggestion that this is actually impossible with current approaches because nothing is really deleted by RLHF: """Integrity and confidentiality — Processing must be done in such a way as to ensure appropriate security, integrity, and confidentiality (e.g. by using encryption)."""
- lagrange77 3y agoOk, thanks. But does not providing - the personal data you can not have or process - to the EU market, make your position any better, legally?
- junon 3y agoIf it's trained on data covered under the GDPR then it means you're 1) a "data processor" of that information and 2) there's a risk of it reproducing that information in some form. In the case of #1, they probably do not have an agreement with the "data controller" in the case of scraping, which means #2 is a violation of GDPR. IANAL.
- thibaut_barrere 3y agoWith people feeding more and more delicate questions (e.g. medical, mental health etc), which can lead to more trouble with what may be stored temporarily etc, GDPR definitely has an impact here (developers must take special care to be compliant etc).
- HlessClaudesman 3y agoYeah it's fear of GDPR, which is kind of like a retroactive set of standards: "we'll know an infringement when we see it", type vibe. Which of course is kryptonite to innovation, and ultimatly will lead to a more fragmented internet. As a European I to try see it from both sides, consumer protections are generally a good thing, but it right now being restricted by EU vagueness sucks ass because I just want to play with the cool new toys.
- YetAnotherNick 3y agoThis comment always gets downvoted, but I have seen this happen in my previous company. They hired an expensive lawyer from Europe for GDPR compliance and even his suggestions didn't made sense and in the end we decided to geoblock Europe. e.g. EU didn't clearly banned consent rejection requiring more effort and just skirted around it and that's why every company have two step rejection and one step acceptance. They could have easily made law requiring sites accept DNT header but they didn't likely because of lobbying.
- saikia81 3y agoThe first part of your comment lacks understanding of how and why the consent rejection has been worded as it has. If you want to comply it is easy. But if a company wants to skirt the regulation it is written such that the regulatory body can still get you for making it harder. DNT is not relevant as GDPR is not directly a regulation against tracking, and it certainly isn't because of lobbying.
- YetAnotherNick 2y agoNot only I don't understand it, the top tier European law firm the company hired also didn't understood it. The law ALLOWS companies to skirt around it. I don't know if that's intentional or not. > If you want to comply it is easy. That's the entire antithesis of modern law as opposed to monarchy. Law should be codified in as clear rules as possible.
- thibaut_barrere 3y ago
- MyAccountYo 3y agoI think it is mostly for these reasons: * It's complicated so it takes a while and you need lawyers and such to make it right * Rules for training are probably hugely vague and undefined. Because you could ingest personal data and it cannot be deleted * AFAIK it needs to be hosted in Europe (not directly GDPR related, but america has laws that allows them to spy on all traffic in the US, so this is somewhat the counter to that) In the end from my experience just working at a company that needs to be compliant this usually means: * All the services need to be hosed in EU including 3rd parties we send any data to * There needs to be a way (email is enough) to delete user data (including from 3rd parties which need an endpoint so you can trigger it from your side) * You need to inform the user about the data useage and allow them to opt out of the "usage" of this data for non-essential things (i.e marketing emails). This does not mean you cannot save this data if you also use it for other things, but you can not use it for the non-essential case. * You could be in trouble if you save data "just because" and do not use it for anything essential or if it is not transparent to the user. Not a lawyer. Just the things I notice in my day to day. In the end companies need data protection professionals to navigate these things. Which is probably another thing a startup does not worry about it early on.
- passwordoops 3y agopure speculation If I'm to venture a guess, it's probably because data protections are stronger and they want to avoid potential issues should someone test GDPR (or whatever the applicable law is) by asking specific data be removed from the model
- ectopasm83 3y ago[dead]
- deleted 3y ago[deleted]
- mrtksn 3y agoAnd this affects UK, How? The one not available is Gemini Pro and its not available in UK too according to the article.
- ectopasm83 2y agoGP was talking about Europe
- satiric 2y agoThe UK is still in the continent of Europe. Last I checked, it hadn't swum across the ocean to America...
- ectopasm83 2y agoI still don't understand why the UK is so central to this discussion. What did I miss ?
- ThomPete 3y agoBecause the EU have decided to make it extremely hard for Europeans to benefit from technological advantages trough their GDPR, Cookie Laws and soon AI Act.
- saikia81 3y agoSafety does make things harder for those that want to abuse us. We don't want technology at all costs.
- ThomPete 3y agoThere is nothing safe about cookie law or GDPR. They are literally doing the opposite because they are asking you to commit to the terms and since everyone do you have actually consented to your data being used. AI Act isn't solving anything that isn't already solved with existing regulation. That so many people on HN seem to think this is a good idea is very puzzling.
- deleted 3y ago[deleted]
- dontupvoteme 3y agoThey're worried about GDPR with chatbots, but e.g. Claude is available via API.
- speedgoose 3y agoHow hard is it to ask for informed consent?
- AtlasBarfed 3y agoPretty easy, simply bombard the user with consent forms every request until they click on "accept all".
- deleted 3y ago[deleted]
- layer8 3y agoThey’d actually have to make sure to correctly inform the user.
- karmasimida 3y agoRegulation too cumbersome, not worth it. What is the downvote coming from, isn't this just facts? If not for the regulation, why would EU be shunned?
- speedgoose 3y agoI don't know. I have an organisation account on Anthropic to use Claude 3, and the credit card is norwegian, the phone number is norwegian, the email finishes with a .no, the country in the address says Norway, and the business tax id is a norwegian VAT number. Sounds like they actually don't mind the regulations for businesses.
- fragmede 2y agoWhat is 2% of Anthropic's global revenue, and what is 2% of Google's global revenue? The penalty for Google getting it wrong are much much higher. Anthropic can get away with moving fast and breaking things (like the GDPR). Google has no such luxury.
- black3r 3y agoOpenAI doesn't have this issue so it begs the question which part of the regulation is not compliant and why, if it's just Google being lazy, or if they actively do something sketchy and don't want to stop.
- karmasimida 3y agoGoogle is a much bigger target than OpenAI from EU regulations perspective. They are going after Google
- Zetobal 3y agoIf other entities do the same thing without problems it's most of the time a you problem.