8 ms·
Google eng mgr here. I've worked on a few projects related to compliance with various government policies. This isn't "assign a two-pizza team to it, will be do
by eykanal 4mo ago
Google eng mgr here. I've worked on a few projects related to compliance with various government policies. This isn't "assign a two-pizza team to it, will be done in a quarter"; these types of compliance efforts can mean completely redoing multiple core systems to handle privacy, wipeout, audit, reporting, per-location policies, etc etc. These efforts can involve hundreds to thousands of people for multiple years.
Sure, there's a messaging component to this. However, any company that isn't trying to just skirt the law will aim to do this sort of thing correctly, and it's an enormous effort.
- epolanski 4mo agoYet Gemini had no issues to comply with EU's DMA and release on all phones? Let's call it how it is: Android phones allow every competitor to run their chatbot in place of Gemini. Want Perplexity instead of Gemini? You can have it. Samsung launches with Perplexity as of late. Apple? As always, went into "ay mate, too integrated, can't give the same APIs to competitors" lame excuse.
- zdragnar 4mo agoIf the options are "launch in the rest of the world quickly and get to the EU later" or "launch everywhere at once years after the competition" PMs and execs are going to choose the latter every time.
- rootusrootus 4mo agoFormer, you mean?
- zdragnar 4mo agoYes, indeed, I wasn't paying attention.
- rootusrootus 4mo agoI figured, just wanted to verify, because while the former seems like the obvious answer, it could be argued with a straight face that Apple's strategy is in fact the latter. Or something like it.
- yxhuvud 4mo agoThe third option is: launch in a way that is compliant with EU rules everywhere. Except they don't want that as they want to retain their outsized market power.
- tzs 4mo agoThat's not a third option. It is the second option they listed.
- yandie 4mo agoAppples architecture prevents them from seeing customers data (see Private Cloud Compute documentation). Data that Gemini Assistant (not referring to the distilled version Apple uses) see goes straight to Google. Big difference here. Weird to say it but the only assistant with any guarantee for privacy by design is Siri at the moment.
- NitpickLawyer 4mo ago> Data that Gemini see goes straight to Google. That's not how the deal was announced. You don't pay Bs / year for a licence to gemini to send them your data. You pay that to run it on your own hardware, in your own garden, so the data stays put. I know the internet is always anti big companies, but this is likely a "not worth it for now, we'll eventually do it" effort from Apple. The EU AI act is a mess, and the effort to simply know what they have to do to comply with it is likely going to take armies of people (not devs) and a lot of time, as the OOP said. And the saddest part about it, is that Apple has the money and resources to sink into this. Think about all the small players that don't. This is yet again a miss for the commission, with the end result being an insidious form of regulatory capture. It sucks for those of us running small companies. Oh well.
- yandie 4mo agoI was referring to Google Gemini AI (their branding is horrible) - Google can see ALL of your interactions with their services - that's not what Apple gets to see https://security.apple.com/blog/private-cloud-compute/ https://security.apple.com/blog/private-cloud-compute/
- epolanski 4mo agoWhat is the source of this claim that this is the reason?
- yandie 4mo agohttps://security.apple.com/blog/expanding-pcc/ https://security.apple.com/blog/expanding-pcc/ The code is open source: https://github.com/apple/security-pcc https://github.com/apple/security-pcc
- dktp 4mo agoThat's not fully true. Lots of things get to Europe later (Gemini memories, though we have them now, Spark as latest noteworthy) Or never. Like the majority of Pixel 10 on device AI features (image editing, magic cue).
- krzyk 4mo agoSome features don't land in Europe because US companies can't handle the amount of languages. For them it is English and maybe Spanish or Chinese because they don't care how heybmake money.
- epolanski 4mo agoNonsense, Google is among the most aggressive when it comes to localization to the point of being oblivious. I have not been able to switch language in Sheets since 2018, and I've changed any possible setting (even account language). All guides are in English and I'm stuck with Sheets in Italian.
- microtonal 4mo agoI have the AI image editing features on Pixel in Europe.
- ErneX 4mo agoAre you sure about that? https://www.business-standard.com/technology/tech-news/google-open-android-to-other-ai-services-beyond-gemini-eu-126042900721_1.html https://www.business-standard.com/technology/tech-news/googl...
- epolanski 4mo ago100%, it's been almost 2 years that you can choose whatever you want.[1] I run Perplexity in place of Gemini, but I can also run Claude and others. [1] https://i.imgur.com/BgvxqQQ.png https://i.imgur.com/BgvxqQQ.png Apple is just being the usual Apple being both an hardware vendor and giving it's own software advantages that competitors don't have and using the security bogus argument as always. And yet, people believe that crap and jump into defending Apple as if being an Apple user is their identity, sad.
- ErneX 4mo agoBut read the article, the EU wants even tighter integration for third parties, so it’s not exactly like Google is out of the woods regarding the DMA and this.
- McDyver 4mo agoIt goes to show that privacy is not a priority. And it should be.
- m3kw9 4mo agoEU privacy laws are not there to protect your privacy, its there because the law makers don't know how modern privacy works and wants their name on the law so it seems they did something.
- flumpcakes 4mo agoEU has some of the best consumer protection and privacy laws on the planet.
- m3kw9 4mo agoTheir laws are basically the equivalent of if there is no code, there are no bugs. EU laws forces citizens to get no new tech, privacy preserved.
- izacus 4mo agoMan, if we had computers in EU we'd be really angry at your dumb false posts.
- microtonal 4mo agoUhm no, EU privacy laws are actually pretty simple: do not collect data you don't need without asking consent from a user first. Which should IMO be the basic principle worldwide. But unfortunately in many countries, companies are more powerful than governments/regulators, so they get to grab everything they can get their hands on.
- adrianN 4mo agoI think you should elaborate a bit on that because to me it seems that EU privacy laws are actually fairly good at protecting privacy.
- joe_mamba 4mo ago>These efforts can involve hundreds to thousands of people for multiple years. And yet Apple had no major issues complying to the draconical demands of the CCP to sell and operate there. Weird. Also, it's not like Apple can't afford the manpower for this. They're not a hole in the wall mon & pop shop.
- wmf 4mo agoThe new Siri isn't available in China yet either.
- ErneX 4mo agoOr really anywhere, since it comes out in Fall. Unless you count developer betas as available of course.
- MBCook 4mo agoIt’s also only in English initially. They can only do so much at once. And Apple is not a “hire an extra 30,000 people“ kind of company. Apple usually rolls stuff out in stages. This is just an extremely high profile example.
- krzyk 4mo agoHas anyone seen a recent LLM release that supports just one language?
- MBCook 4mo agoApple Intelligence supports a number of languages. They showed them on a slide in the keynote. The new Siri is limited at the moment.
- krzyk 4mo agoold Siri was always limited in that regard. And Apple Intelligence supports just a fraction of languages: English, Danish, Dutch, French, German, Italian, Norwegian, Portuguese, Spanish, Swedish, Turkish, Vietnamese, Chinese (simplified), Chinese (traditional), Japanese, and Korean. Danish, Dutch, Norwegian and Swedish have quite small populations compared Poland, while I don't see Polish there (37M). I also don't see Romanian, it is slightly bigger amount of people than Netherlands, and the rest from that list are ~< 10M. Oh, well, at least I don't see Russian in that list. With ChatGPT, or Claude.ai (or Deepseek, or local models) I can speak with languages that are outside of (traditionally) limited set of Apple. Because it all depends on what is on the web and web has magnitude larger set of languages compared to what Apple provides.
- afavour 4mo agoTo me that reads as an even greater reason not to delay it. If you knew the restrictions day one you’d be able to engineer the system to accommodate them. Waiting until post launch now means a massive amount of re-engineering. I know it’s not quite as simple as that but I do think it shows Apple are more interested in blaming the EU than reducing the potential issues ahead of time.
- JumpCrisscross 4mo ago> If you knew the restrictions day one you’d be able to engineer the system to accommodate them This slows down deploying the system globally. Particularly if the target is moving, it may make sense to build lightly so one can pivot, and then build in the compliance stuff after you know you have a winning configuration. The EU has its laws. Apple has its strategy. The only thing I fault anyone on is the public bickering.
- Forgeties79 4mo agoI imagine complying with all kinds of laws and regulations slows releases in some way or another and having none of them would allow people to ship faster, so what makes these EU regulations so distinct? Do what you have to do to comply with the law and release, as always.
- JumpCrisscross 4mo ago> complying with all kinds of laws delays release in some way or another and having none of them would allow people to ship faster, so what makes these EU regulations so distinct? DMA was designed to be a comprehensive regulatory suite. Lawmakers knew it would be onerous; that’s why it only applies to large companies. Also, the DMA’s interoperability requirement creates external partners. Let’s face it, Apple’s track record with Siri sucks. If they launch a system and it is crap again, they may not now want an entire ecosystem of folks who will cry foul if they dump the API and start over. > Do what you have to do to comply with the law and release, as always Just follow the law. If that means not releasing in a jurisdiction, do that and then don’t tweet snotty things about it. (Siri AI isn’t launching in China, either. I don’t see PMs complaining about that in public.)
- ivan_gammel 4mo agoPrivacy by design isn‘t enormous effort, as every European engineering manager will tell you. It‘s just another reasonable and straightforward set of requirements. Of course, if you want to have privacy-less features in jurisdictions permitting it, that‘s a different story and that‘s a choice.
- bflesch 4mo agoPrivacy by design while making a seven-figure salary because you make people buy stuff they don't really need is quite difficult ;)
- mantas 4mo agoIn this case it looks like EU is requiring to let competitors mess with Apple users privacy.
- krzyk 4mo agoNot quite. It is up to Apple to design a system in which operators (even Apple) can't see your data. Apparently they designed it in a way that operator can see it (so it is cool if it is Apple, but not cool if it is someone else).
- mantas 4mo agoHow can Apple ensure what other cloud models do in their servers?
- pocksuppet 4mo agoIs this the new excuse for user hostility? Instead of "think of the children" it's "think of your privacy"?
- mantas 4mo agoMore like „think of those managing the extended family IT infrastructure“.
- 4mo ago
- bflesch 4mo agoWow, Google must be a poster child for privacy then.
- Xirdus 4mo agoSo, what are the chances they'd completely redo multiple core systems in the 18 months they asked for?
- krzyk 4mo agoWhy does systems are not designed take into account that compliance work?
- rvnx 4mo agoBecause of move fast and break things mentality. Let's say if ChatGPT was launched respecting GDPR, or respecting copyrights, they would have reached nowhere.
- JumpCrisscross 4mo ago> Let's say if ChatGPT was launched respecting GDPR, or respecting copyrights Bad comparison. Launching with GDPR compliance isn’t particularly taxing if you’re already complying with California’s CCPA. (You need your twenty-eight EU law firms on retainer, but the big firms package that conveniently.) Copyright theft in AI, on the other hand, is a global phenomenon. DMA is most akin to the U.S. system of designating financial institutions SIFIs and then putting a bunch of extra requirements on them. Almost intentionally onerous. Hence ringfenced to select large companies.
- eykanal 4mo agoI assume you're asking this in good faith, so I'll answer in good faith. Laws vary from country to country, state to state, and they vary tremendously. Laws are also changing all the time. There's literally no way to predict what rules will be in place at any given time. Also, adding code to meet some government regulation takes time and effort that (form the company's perspective) could be better spent building a product and making money. No one would "choose" to implement some random compliance rule unless they're forced to.
- bel8 4mo agoSure but we're talking about the unified law of almost an entire wealthy continent here. It's EU ffs. Not some small island country in the middle of the ocean. This looks to me like yet another bet from Apple: "they'll buy iPhones anyway, let them wait".
- 4mo ago
- fnordsensei 4mo agoThe point isn’t that it’s easy or straightforward to do. The point is that one of the world’s wealthiest companies can spare the resources needed to comply with the regulations of one of the world’s largest markets.
- JumpCrisscross 4mo ago> one of the world’s wealthiest companies can spare the resources needed to comply with the regulations of one of the world’s largest markets At what cost? This is Apple’s second bite at AI. Giannandrea fucked up the first time. I’m honestly with Cupertino on not over complicating it the second time around. If they found the right mix of features and architecture, great, then work to port it to high-bar jurisdictions.
- disgruntledphd2 4mo ago> At what cost? This is Apple’s second bite at AI. Giannandrea fucked up the first time. I’m honestly with Cupertino on not over complicating it the second time around. If they found the right mix of features and architecture, great, then work to port it to high-bar jurisdictions. I totally agree with you in principle here, but Apple have a pretty large vested interest in not supporting interoperability here (and in the other cases, like Mac mirroring) so I honestly don't see that happening at all. This is purely a lobbying move against the EU to get EU citizens/politicians to complain about the laws and get an exemption. And to be fair, Apple's business model is currently structurally incompatible with a lot of the DMA (which I personally think is a good thing), so they kinda have to fight it for a while.
- JumpCrisscross 4mo ago> purely a lobbying move It can be more than one thing. It’s a lobbying move, to be sure. But it’s also almost certainly a time-to-market and potentially cost-mitigation play, too.
- disgruntledphd2 4mo ago
- greatgib 4mo agoThe truth is very often that it is long and hard not to do the work to comply but how to not comply or do complicated things to abuse of loophole despite being able to pass the law on the letter of it. Especially in the case of apple or Google. Look at the app store situation. It is very straightforward to do the work for the whole thing to be open to any competitor. But it is hard to try to design and implement a solution to try to not break any regulations but still manage to keep users captive the maximum without having competitor entering our walled garden.
- piyuv 4mo agoIt’s not an enormous effort if you plan for it. They clearly knew about this, and could’ve afforded to plan for it. Their whole shtick is locking users in, and DMA is their nemesis.
- ornornor 4mo agoOkay? I don’t see the problem, these requirements are known from the beginning so if complying wasn’t planned and requires re-architecturing the software to make it happens that’s on the engineering org not on the EU regulator. Unless I’m missing something?
- JumpCrisscross 4mo agoThe point is complying with the DMA from the outset could mean having to launch a year later everywhere. Skipping the EU makes sense in a fast-moving market (if you’re designated as a gatekeeper).
- deleted 4mo ago[deleted]
- inetknght 4mo ago> Skipping the EU makes sense in a fast-moving market (if you’re designated as a gatekeeper). Skipping the EU makes sense if the company doesn't want to comply with regulations aimed directly at it. > complying with the DMA from the outset could mean having to launch a year later everywhere. Oh no! Anyway... Once upon a time, companies delayed launches specifically so they'd launch a better product. That seems to be gone these days and end-users have garbage products as a result.
- JumpCrisscross 4mo ago> Skipping the EU makes sense if the company doesn't want to comply with regulations aimed directly at it It makes sense if you’re prioritizing time to market and agility. Once you’ve nailed down your product, you can make it compliant for more-onerous jurisdictions. You see this in finance all the time, where the U.S. tends to have the tightest rules around e.g. betting and crypto. > Once upon a time, companies delayed launches specifically so they'd launch a better product Because software shipped in a box. Also, compliance is orthogonal to how good a product is. Siri AI might be crap. It might be great. It might be almost perfect and then made great on second release. Everything slows down if the entire development process has to deal with open APIs and lawyers at every turn. It’s perfectly legitimate to say we’ll develop this in other markets and ship it to the EU when it’s fully baked.
- skeledrew 4mo agoThere wouldn't need to be a redo if the products had been built with compliance in mind. This law isn't something new; it's been around for years now. Not taking it into account from the beginning with the intention of operating in the jurisdiction means there's definitely intention to skirt. Particularly given the previous issues in the same department.
- eykanal 4mo agoNo one implements compliance goals for fun. If they didn't think they were going to have to comply, they wouldn't do it. If they thought the law would be overturned they wouldn't do it. Same if they thought they would successfully fight the law in court, if they thought consumers would revolt, if they thought that they were a Special Squirrel who would get exemption, or whatever. Does this put them stupidly behind schedule? Yes, and bummer for them, but I highly doubt that a company as politically savvy, legally savvy, and wealthy as Apple would do this "by mistake".
- mr_toad 4mo agoI wouldn’t want to try and develop a sandbox for an AI that could protect the user and yet still be useful. Having an AI act on your private data but only in the way you want is hard enough when it’s a model that you control on hardware you own. Having third parties running AI on your private data requires a level of trust that I wouldn’t want in the hands of random developers in the app store.
- miohtama 4mo agoAlso it does not matter what you do in the end. If you are Big Tech the EU will sue regardless and always finds an excuse.
- inetknght 4mo agoDo you think this is a problem with the EU? I don't. I think it's a problem in the way that Big Tech operates: by function of theft and laundering of data, and by screwing end-users and consumers in favor of profits.
- celiacFun 4mo agoIt may be a problem with EU regulations. It’s hard to see how Apple could be certain they had complied with the EU DMA law, given its based on vague outcomes rather than clear requirements with extremely large penalties. The fact the EU was only willing to require the DMA regulations be met by large foreign companies doesn’t inspire confidence. And it’s not like there is a thriving tech ecosystem of successful EU tech companies showing how it’s done. So there is a lot of ambiguity on how companies can reasonably comply without huge risk of 10% global revenue.
- Krasnol 4mo agoI have a crazy idea: design the product with compliance in mind already!
- aprentic 4mo agoYou're essentially saying that privacy violations are baked into the cores of these systems.
- happyopossum 4mo agoThe DMA has nothing to do with Privacy - it's an anti-competition scheme. Apple is saying that privacy is baked in to their approach, and they can't ensure that if they allow every other AI provider the same level of access.
- jen20 4mo agoDMA is not about privacy.
- krzyk 4mo agoCore not, but here it is. Apple designed the system in a way that the operator can invade your privacy. So if only Apple is the operator it is "OK", but if they allow other operators it is not.
- jen20 4mo ago> Apple designed the system in a way that the operator can invade your privacy. Citation needed.
- Garlef 4mo agoIt's also not a "two-pizza team" market.
- matheusmoreira 4mo ago> completely redoing multiple core systems to handle privacy, wipeout, audit, reporting, per-location policies, etc etc So Google chose to be evil, now they have to rip all the evil out and redo it from scratch. Can't say I have any sympathy. Should have done the right thing from the start.
- apercu 4mo agoAgreed, unless you specifically know how a regulator will interpret a broad requirement on a edge case it’s a lot of effort to even figure out what the plan is, much less implement it.
- bambax 4mo agoSo? It's also more effort to work everyday to earn a living than simply stealing what you need from your neighbors at gunpoint. But the law's the law. As a European I'm conflicted because I think this particular set of privacy laws are overreaching bordering on stupid; but "exemptions" for one of the richest corporations on earth would be beyond absurd and infinitely worse.
- yxhuvud 4mo agoThis is a competition law, not a privacy law.
- tmcb 4mo ago> these types of compliance efforts can mean completely redoing multiple core systems to handle privacy, wipeout, audit, reporting, per-location policies, etc etc. Maybe the phrasing is unfortunate, but if compliance to the law requires a “redoing”, launching in that market was never a priority in the first place. That’s a completely legitimate choice, but usually companies whining about regulations are making a financial decision rather than an ethical one.
- flohofwoe 4mo ago> these types of compliance efforts can mean completely redoing multiple core systems to handle privacy, wipeout, audit, reporting, per-location policies, etc etc. These efforts can involve hundreds to thousands of people for multiple years. What if I tell you that there's a surprisingly simple, straightforward and above all very cheap solution: don't implement privacy-invading or anti-competitive features in the first place ;)
- hparadiz 4mo agoSure let me wave a magic wand and have a data center that can meet all these regulations materialize before us. Yes I'm sure every American tech company is tripping over themselves rushing to build data centers that are subject to European taxes and regulations for the exact same compute.
- psychoslave 4mo ago[dead]
- BrenBarn 4mo ago> these types of compliance efforts can mean completely redoing multiple core systems to handle privacy, wipeout, audit, reporting, per-location policies, etc etc. These efforts can involve hundreds to thousands of people for multiple years. Then you should have done it right the first time.
- KaiserPro 4mo agoMeta research eng here Yes, but also its much cheaper to build it in at the very start. When we built pervert glasses research platform, if we'd just ignored the data privacy laws we could have built it much quicker. But, the only reason it took extra time is because 1) we had no idea what we were doing and 2) the lawyers had even less idea, so we had to do a bunch of reading and make a best guess. Turns out the guesses were right, but it was painful getting the lawyers to understand.
- subscribed 4mo agoLOL, do you think Apple learnt about the requirements yesterday during the presentation?
- fcantournet 4mo agoExactly, and the prupose of these legislation was supposed to be exactly that : force companies to integrate privacy in the core of their products, not to create a list of items to tick.
- Refreeze5224 4mo agoWell if your product wasn't already basically spyware, it wouldn't be so much work to abide by privacy regulation frameworks, now would it? I have no sympathy for how hard it is for surveillance companies to adapt their exploitative business model to the EU.