5 ms·
EU rules on AI models become enforceable. What's going to change?
- kamma4434 2mo ago[flagged]
- embedding-shape 2mo agoRemember when HN used to have somewhat informed users? The trite cookie popups have nothing to do with GDPR, this has been repeated ad nauseam...
- dgellow 2mo agoIt’s insane how that misinformation doesn’t want to die. In 100y we will still have people repeating that we get popup because of gdpr, and nobody will know what a popup or gdpr is
- Retr0id 2mo agoIs it really misinformation? The popups may largely be a result of misunderstandings or malicious compliance, but GDPR has a causal relationship regardless of the intent.
- inigyou 2mo agoWhen the city writes an ordinance saying chemical factories must have fire alarms I do not blame the city for the fire alarm noise.
- Retr0id 2mo agoI would however blame them if they wrote an ordinance that was widely misunderstood to mean that someone had to knock on my door each day to make sure I knew the local chemical factory had a fire alarm.
- buran77 2mo ago> widely misunderstood Moments ago it was "misunderstandings or malicious compliance". Did you misplace one on your apologetic quest? I'm really trying not to assume the worst about you. Is there any reason you insist so much on giving the benefit of the doubt to every law breaker out there? Especially when we're sometimes talking about very deep pockets who can afford lawyers?
- Retr0id 2mo ago> I'm really trying not to assume the worst about you. Well, you are. Maybe don't do that?
- inigyou 2mo agoIf the chemical factory sets themselves on fire every day to set off the fire alarm to annoy me to pressure me into removing the fire alarm law, I still blame them.
- watwut 2mo agoPopups have nothing to do with GDPR. They are reaction to Privacy and Electronic Communications Directive which predates GDPR. And yes, it is deliberate misinformation.
- Retr0id 2mo agoCookie popups pre-date GRPR, but find it hard to believe the uptick in popups that happened around May 2018 was in response to legislation from 2003.
- za_creature 2mo agoCookie popups were once issued by browsers in response to a Set-Cookie header. 25 years ago, it was fairly common to open the login page, type in your creds and _then_ hit "accept cookies from domain.com". Some time after IE6 and Firefox and before Chrome, the default policy switched from "prompt" to "accept". GDPR was an attempt to restore that default behavior, however no browser did so. I'd've guessed Mozilla could be convinced to revert, but Google presumably paid them enough to look the other way.
- buran77 2mo ago> a result of misunderstandings or malicious compliance, but GDPR has a causal relationship regardless of the intent. You can extend causality as far as you want if you're willing to sound like this in the open. If there were no cookies, there'd be no banners. There, found you a new target. So on one side you have decent regulation that tries to balance the interest of the user without over regulating and becoming too prescriptive, and on the other side you have abusers who most of the times are actually in malicious non-compliance... and you find a way to blame the regulation. Good thing it's in the rules that HN is not Reddit.
- Retr0id 2mo agoIf you think I'm opposed to GRPR, you are mistaken.
- watwut 2mo agoThis is heavily downvoted ... and still accurate.
- DarkNova6 2mo agoThis being downvoted speaks saddens my heart... and proves the exact intent of the message.
- jstummbillig 2mo agoGDPR (and ePrivacy before that) requires valid prior consent where optional tracking is used. A site using only technically necessary storage can simply have no consent banner. A business wanting advertising and analytics trackers generally needs some consent interface. "Not a requirement under GDPR", yes, but certainly not "nothing to do with GDPR". It directly has to do with GDPR, in conjunction with business' decisions and how to comply with the law. And of course, we can then argue our faces off about what's good and necessary in the world, in businesses and data protection, but saying it has nothing to do with it is just wrong.
- jshmrsn 2mo agoWell, I am trying to inform myself because I did understand the cookie popups to be connected to GDPR. As far as I can tell from my reading, your assertion that "cookie popups have nothing to do with GDPR" is not true. From my reading, it seems that while cookie permissions first became an explicit EU law concept in a 2009 amendment to ePrivacy Directive (not GDPR), companies were able to get away with passive consent banners (not popups). It was GDPR's new definition of consent which then retroactively strengthened the existing ePrivacy Directive cookie consent to explicitly require user action to give consent (i.e. popups, banners large enough to push users to interact with them, etc.). Unless your point is that GDPR has nothing to do with popups because the companies could just not use non-strictly-necessary cookies and therefore not need a popup, but I think that's a stretch to jump from there to "nothing to do with GDPR". https://gdpr.eu/cookies/ https://gdpr.eu/cookies/ https://wp-gdpr.eu/gdpr-cookie-consent-2026/ https://wp-gdpr.eu/gdpr-cookie-consent-2026/ https://eulawanalysis.blogspot.com/2022/01/consent-and-cookies-in-eu-data-privacy.html https://eulawanalysis.blogspot.com/2022/01/consent-and-cooki...
- deleted 2mo ago[deleted]
- dijksterhuis 2mo ago> (i.e. popups, banners large enough to push users to interact with them, etc.). "i.e." doing a lot of work there. GDPR doesn't require pop-ups or banners for providing consent. It mentions "ticking a box when visiting an internet website" as an example implementation. But it's just there as an example. https://gdpr.eu/Recital-32-Conditions-for-consent/ https://gdpr.eu/Recital-32-Conditions-for-consent/ the mechanism for gathering consent is an implementation detail left to the site to handle because GDPR applies to far more than websites. i've had to provide consent for things completely unrelated to websites. you could add a line of text saying "please write us a letter with the following information (user account, blah, blah) if you are willing to provide consent for optional tracking like blah blah" and this is perfectly in line with GDPR. sure, it's more expensive and you'll get fewer people who you can track. but make no mistake, sites make a decision and choose pop-ups/banners as their implementation for gathering consent because they don't want to lose out. they're happy inflicting pop-ups/banners on their users instead so they can keep their precious tracking cookies going. i.e. GDPR doesn't require pop-ups/banners, sites choose pop-ups/banners.
- elcdodedocle 2mo agoGDPR is more than that. Consent or not, there are things bad actors can do in the USA that in the EU they just can't. Specially to children and vulnerable people. GDPR is an integral part of it. This is a small but significant first step in the right direction. Long way ahead still.
- dev_l1x_be 2mo agoYes I used it when Confluence had a bug and an account with got stuck and there was no way to delete my account of finish the registration. So I issued a GDPR delete request and re-created the account. tada.wav
- MaxMatti 2mo agoI've heard lots of people use it to actually find out what you were being banned for even when the company absolutely does not want to disclose it.
- dev_l1x_be 2mo agoWe should create gdprdelights.eu and list of these use cases.
- hellisothers 2mo agoMaybe but it feels like 1 step forward and 2 steps back. It feels like in the end they’re (companies) still getting 99% of what they had before and the user experience of everything is much worse.
- scyzoryk_xyz 2mo agoThe blah user experience isn't the whole picture for GDPR. It's just been the most visible part of it. My personal GDPR hot take: it's actually been 2 steps forward and 1 super clumsy super loud and obnoxious step back. I agree with the spirit of comment above. The common sense part of it (if there is one) might just end up eclipsed by wonky UX absurdity. Someone will find a way to paint this picture that our EU reality is a Kafkaesque dystopia.
- watwut 2mo agoGDPR is actually good directive. Despite perpetual campaign against it from HN users who would like to abuse other peoples data.
- tgsovlerkhgsel 2mo agoGDPR is the reason why we have cookie popups, and don't have companies driving through cities to scan number plates and sell everyone's movement records to the highest bidder. And the cookie popups are only there because they never actually enforced GDPR as written.
- latentsea 2mo agoThe cookie popups were a thing long before GDPR.
- sixtyj 2mo ago> The rulebook sets out rules for all models that lack a specific purpose but can be adapted to a variety of use cases, requiring transparency on how a model was built, disclosure of any copyright-protected content used for training, and enough information for downstream users to understand the model's capabilities. Re. disclosure: How do they want to do it? It seems to be similar to a “disclosure” used in students’ works: “Source: internet”…
- Retr0id 2mo agoNo copyright intended
- ArekDymalski 2mo ago> Re. disclosure: How do they want to do it? It seems to be similar to a “disclosure” used in students’ works: “Source: internet”… I think enforcing compliance with the law will be rather simple, just like it happened with GDPR, food labeling and many other regulations. But I wonder how will the disclaimers/declarations even be verified? The more I think about it the more I see open sourced (both dataset and weights) models as the only truly verifiable solution. And that makes it less attractive as a business foundation if. So we might end up with state-funded models working in similar fashion to museums it other culture/art institutions ensuring that original material creators are treated fair. But that will bring whole other set of challenges...
- sixtyj 2mo agoDo you think that states have enough skillful ppl to run such a comparison model? I remember European efforts to create search engine, digital library. And a lot of EU-funded projects in Horizon 2000 are useless, just an expensive bureaucracy… GDPR and cookie consent bars are pain in the a* and ux/ui failures. What I mean - intention is good, realisation is often bad. (But I don’t think that rest of world would be better btw :) /end-of-rant
- M95D 2mo agorealisation is done by individual sites. Instead of not collecting data, they chose banners.
- j45 2mo agoThe doers vs talkers of who can make AI accurate and consistent will step forward.
- pelorat 2mo ago> EU rules on AI models become enforceable. What's going to change? I can answer that. A higher regulatory overhead that means less money for R&D and decreased profit margins for companies here in the EU. That's what's going to happen.
- DarkNova6 2mo agoThanks, now I don't need to even read the article!
- WarmWash 2mo agoAlso going to have to compete against SOTA AI augmented American companies. Which likely means using Chinese models. Thank god Xi Jinpeng has the best interests of Europe at heart...
- bob001 2mo agoJust like Putin had Europe's best interest in mind regarding natural gas. At this point it's not a question of if Europe will become a puppet state but whose puppet state.
- moffkalast 2mo agoMistral's already in the gutter, so not much change overall.
- xinayder 2mo agoIf your sole business model depends on having no regulation then your business model is wrong and predatory. Regulation doesn't hinder innovation, it's just that CEOs want that quick buck instead of being responsible and using regulation for their advantage.
- m4xp 2mo agoIt does, it hinders competition, its really good if you are already enstablished.
- 2mo ago
- cubefox 2mo ago> In practice, for European consumers and businesses, that might mean some of the most advanced AI models launch in the EU a few weeks later than in other markets, as firms ensure they have done their compliance homework. As models become more capable, this could have serious economic consequences. :(
- jay_kyburz 2mo agoSeems to be that the compliance homework is exactly the kind of busy work that AI is good at. AI companies could just get AI to do it.
- szczepano 2mo agoLink to report AI https://digital-strategy.ec.europa.eu/en/policies/ai-act-whistleblower-tool https://digital-strategy.ec.europa.eu/en/policies/ai-act-whi...
- ChrisArchitect 2mo agoRelated: EU will mandate labels on authentic-looking AI content starting August 2 https://news.ycombinator.com/item?id=49132341 https://news.ycombinator.com/item?id=49132341
- Razengan 2mo agoHow does the EU plan to remain relevant in tech between the US and China? Bet on CERN developing affordable antimatter production?