9 ms·
Not a lawyer, not versed in US and EU Law, but ... I read (part) of the regulation. https://outofthecomfortzone.frantzmiccoli.com/thoughts/2024/12/29/eu-ai-act
by frantzmiccoli 2y ago
Not a lawyer, not versed in US and EU Law, but ... I read (part) of the regulation.
https://outofthecomfortzone.frantzmiccoli.com/thoughts/2024/12/29/eu-ai-act-notes-on-the-regulation.html https://outofthecomfortzone.frantzmiccoli.com/thoughts/2024/... and here is my shameless plug.
- 2rsf 2y agoNot a lawyer, only an engineer starting to assess our AI models. Your comparison to GDPR seems to be correct in a way, both are quite vague and wide. The implementation of GDPR is still unclear in certain situations and it was even worse when it was launched, the EU AI act have very little references to work with and except for very obvious area it is still a lot of a guesswork
- Ylpertnodi 2y ago>...GDPR seems to be correct in a way, both are quite vague and wide. How is the gdpr vague?
- mimsee 2y agoAre IP addresses considered PII or not? I remember there being multiple conflicting conclusions on that
- sdefresne 2y agoIt looks like IP addresses are considered PII by GDPR: https://gdpr.eu/eu-gdpr-personal-data/ https://gdpr.eu/eu-gdpr-personal-data/ They are explicitly listed as example of PII.
- cmenge 2y agoSo in essence, it disallows logging IP address for any purpose, be it security, debugging, rate-limiting etc. because you can't give consent in advance for this, and no other sentence in Art. 6.1 applies. Moreover, to reason about this, one also needs to take into account Art 6.2 which means there might be an additional 27 laws you need to find and understand. Note, however, that recital 30 which you quoted is explicitly NOT referenced by Art. 6, at least according to this inofficial site: https://gdpr-info.eu/art-6-gdpr/ https://gdpr-info.eu/art-6-gdpr/ This particular case might be solved through hashing, but then there are only 4.2bn IPs so easy to try out all hashes. Or maybe it's only OK with IPv6? I find this vague or at least hard to reconcile with technical everyday reality, and doing it well can take enormous amounts of time and money that are not spent on advancing anything of value.
- troupo 2y ago> So in essence, it disallows logging IP address for any purpose, be it security, debugging, rate-limiting etc. because you can't give consent in advance for this, and no other sentence in Art. 6.1 applies. No, it doesn't. Subsections b, c, and f roughly cover this. On top of that, no one is going to come at you with fines for doing regular business things as long as you don't store this data indefinitely long, sell it to third parties, or use it for tracking. As laid out in Article 1.1. On top of that, for many businesses existing laws override GDPR. E.g. banks have to keep personal records around for many years.
- cmenge 2y ago"Roughly", "regular business things" etc. Sounds vague to me, which was the original point.
- martin_a 2y agoThat's not true. IP addresses might be processed in regards to article 6.1 c) or 6.1 f) but only for these very narrowly defined use cases and in accordance with article 5. So, purge your logs after 14/30 days and don't use the ip address for anything else and you will be fine.
- cmenge 2y agoWhere do the 14/30 days come from?
- martin_a 2y agoGut feeling (kind of). There are rulings that access providers are/were allowed to save full IP addresses for up to 7 days to handle misuse of services etc. and any longer storage seems unnecessary and unlawful. In other cases there were recommendations of up to 30 days, ideally with anonymized addresses where the last one or two triplets are automatically being removed. I've also seen 30 days as kind of the default setting for automatic log purging with shared webhosters. Our lawyer told us that he estimates that saving full IP addresses for 14 days in logfiles would be fine in regards of preventing/tracking misuse of services or attacks against the infrastructure. If this would ever come to court it would most probably be up to the judge to see whether this is really fine or already too much. Therefore we had to document the process and why we think 14 days is reasonable and so on. The GDPR lacks a specific time frame and I think that's okay. There's always some "wiggle room" in European laws, it's about not misusing that room and sincerely acting in the best interest of everybody.
- frantzmiccoli 2y agoGDPR is clear-ish indeed. That being said: it is extremely strict, a lot of lawyers like to make it stricter (because for them it means safer) and a lot of lawyers have to back of under business constraint (that push to sometimes got below legal requirements). My experience is that no two companies have the same understanding of GDPR.
- tw04 2y agoWhen a law is “vague” in that it intentionally tries to be overly broad in protecting the average citizen from corporations, that’s a good thing. GDPR is very much meant to scare the facebooks of the world whose default modus operandi is: your privacy means nothing, I have a revenue number to hit and I don’t care if it ruins your life in the future. I WANT it to be difficult for AI companies to steal other people’s hard work just like I WANT Facebook to have to spend millions of dollars on lawyers to make sure whatever data they’re collecting and sharing about me doesn’t violate my rights.
- miohtama 2y agoThe problem is that the GDPR has been largely a failure protecting citizens from corporations, but it has hurt everyone else. - Nothing has changed in Facebook and Google data collection practices, who with other bug corps account for > 90% of data collection - Many mid tier competitors lost market share, focusing power to Google - EU small software companies pay estimated extra 400 EUR/year to satisfy GDPR compliance with little tangible benefits to the EU citizens. It's called unintended consequences. We all want Zuckerberg to collect less data, but how GDPR was implemented is that it mostly hurt small businesses disproportionately. E.g. you now need to hire a lawyer to analyse if you can collect an IP address and for what purposes, as discussed here.
- guappa 2y ago> EU small software companies pay estimated extra 400 EUR/year [citation needed]
- verzali 2y agoI will be honest, I am always very skeptical of these claims that the big tech companies are fine but small business is hurting. Many of them seem to originate with the big tech companies themselves and I highly doubt they really have the interests of small business in mind. Plus, I'm old enough to remember when everyone claimed EU tech law was about to ban memes, which didn't happen...
- 2y ago
- pjc50 2y agoI agree with this. It is horrendously vague, like GDPR. This creates a large "wariness zone" which law-abiding people avoid, while large multinationals can steamroller through until the point of direct confrontation. And even then you get things like Microsoft Safe Harbour. On the other hand, if you're concerned about AI risk, I don't see how it could be otherwise. We don't have a clear grasp about what the real limits of capabilities are. Some people are promising "AGI" "just around the corner". Other people are spinning tales about gray goo. The risk of automated discrimination looms large since IBM sold Hollerith collation machines to the Holocaust. If it delays AI "innovation" by forcing only the deployment of solutions which have had at least some check by legal to at least try to avoid harming citizens, that's ... good?