> EU rules on AI models become enforceable. What's going to change?
I can answer that. A higher regulatory overhead that means less money for R&D and decreased profit margins for companies here in the EU. That's what's going to happen.
This is a bad counterpoint to "more regulation makes business harder". No regulation at all is probably the hardest business environment possible, but too much regulation is bad too.
Quantity of regulation isn't the point. It is quality. The right regulations are the right regulations. They mitigate risks and can encourage innovation. 'too much/too little' arguments are almost universally wrong.
There is no AI regulation in the US and look at where we are, everyone depends on it, SOTA models are doing CSAM and porn deepfakes, and there's no regulation in the US to prevent this from happening
nor there is regulation to inform a user something uses AI or the dangers of being dependent on this magical oracle.
Or having mandatory security checks in place after frequent accidents on supersonic planes is bad...
The aviation industry must be one of the most regulated ones and it's entirely necessary to guarantee the safety of passengers and crew. You don't see anyone complaining about it except Boeing who failed QA in the past couple of years and killed some hundreds of people due to their oversight.
Perhaps if the industry had been allowed to develop, we'd have some freaky ass new and innovative tech that would've abated the problem. The world may never know!
General statement that means zilch. Regulation depending on particular conditions can definitely curtail innovation or destroy it completely. Bureaucracy wants to regulate everything including how often we fart.
I repeat, if your business model (which like the big majority of the entrepreneurial world is based on) is against regulation, it's wrong.
I don't think it's acceptable to have a billionaire tech bro dictating everything I do in my life while he gets rich by selling my data. One of the reasons regulation exists is to protect customers.
It's about damn time the business world moved away from the capitalism mindset that you NEED to explore the consumer to be successful. We have a lot of examples in Europe where if the company is even a bit less shitty and is sympathetic to the customer, it increases trust and brings in more revenue because your customers trust it.
> The rulebook sets out rules for all models that lack a specific purpose but can be adapted to a variety of use cases, requiring transparency on how a model was built, disclosure of any copyright-protected content used for training, and enough information for downstream users to understand the model's capabilities.
Re. disclosure: How do they want to do it? It seems to be similar to a “disclosure” used in students’ works: “Source: internet”…
> Re. disclosure: How do they want to do it? It seems to be similar to a “disclosure” used in students’ works: “Source: internet”…
I think enforcing compliance with the law will be rather simple, just like it happened with GDPR, food labeling and many other regulations. But I wonder how will the disclaimers/declarations even be verified? The more I think about it the more I see open sourced (both dataset and weights) models as the only truly verifiable solution. And that makes it less attractive as a business foundation if. So we might end up with state-funded models working in similar fashion to museums it other culture/art institutions ensuring that original material creators are treated fair. But that will bring whole other set of challenges...
> In practice, for European consumers and businesses, that might mean some of the most advanced AI models launch in the EU a few weeks later than in other markets, as firms ensure they have done their compliance homework.
As models become more capable, this could have serious economic consequences. :(
GDPR is more than that. Consent or not, there are things bad actors can do in the USA that in the EU they just can't. Specially to children and vulnerable people. GDPR is an integral part of it. This is a small but significant first step in the right direction. Long way ahead still.
Maybe but it feels like 1 step forward and 2 steps back. It feels like in the end they’re (companies) still getting 99% of what they had before and the user experience of everything is much worse.
Yes I used it when Confluence had a bug and an account with got stuck and there was no way to delete my account of finish the registration. So I issued a GDPR delete request and re-created the account. tada.wav
Well, I am trying to inform myself because I did understand the cookie popups to be connected to GDPR. As far as I can tell from my reading, your assertion that "cookie popups have nothing to do with GDPR" is not true.
From my reading, it seems that while cookie permissions first became an explicit EU law concept in a 2009 amendment to ePrivacy Directive (not GDPR), companies were able to get away with passive consent banners (not popups).
It was GDPR's new definition of consent which then retroactively strengthened the existing ePrivacy Directive cookie consent to explicitly require user action to give consent (i.e. popups, banners large enough to push users to interact with them, etc.).
Unless your point is that GDPR has nothing to do with popups because the companies could just not use non-strictly-necessary cookies and therefore not need a popup, but I think that's a stretch to jump from there to "nothing to do with GDPR".
GDPR (and ePrivacy before that) requires valid prior consent where optional tracking is used. A site using only technically necessary storage can simply have no consent banner. A business wanting advertising and analytics trackers generally needs some consent interface.
"Not a requirement under GDPR", yes, but certainly not "nothing to do with GDPR". It directly has to do with GDPR, in conjunction with business' decisions and how to comply with the law.
And of course, we can then argue our faces off about what's good and necessary in the world, in businesses and data protection, but saying it has nothing to do with it is just wrong.
It’s insane how that misinformation doesn’t want to die. In 100y we will still have people repeating that we get popup because of gdpr, and nobody will know what a popup or gdpr is
Is it really misinformation? The popups may largely be a result of misunderstandings or malicious compliance, but GDPR has a causal relationship regardless of the intent.
I would however blame them if they wrote an ordinance that was widely misunderstood to mean that someone had to knock on my door each day to make sure I knew the local chemical factory had a fire alarm.
Moments ago it was "misunderstandings or malicious compliance". Did you misplace one on your apologetic quest?
I'm really trying not to assume the worst about you. Is there any reason you insist so much on giving the benefit of the doubt to every law breaker out there? Especially when we're sometimes talking about very deep pockets who can afford lawyers?
If the chemical factory sets themselves on fire every day to set off the fire alarm to annoy me to pressure me into removing the fire alarm law, I still blame them.
> a result of misunderstandings or malicious compliance, but GDPR has a causal relationship regardless of the intent.
You can extend causality as far as you want if you're willing to sound like this in the open. If there were no cookies, there'd be no banners. There, found you a new target.
So on one side you have decent regulation that tries to balance the interest of the user without over regulating and becoming too prescriptive, and on the other side you have abusers who most of the times are actually in malicious non-compliance... and you find a way to blame the regulation.
Good thing it's in the rules that HN is not Reddit.
Cookie popups were once issued by browsers in response to a Set-Cookie header. 25 years ago, it was fairly common to open the login page, type in your creds and _then_ hit "accept cookies from domain.com".
Some time after IE6 and Firefox and before Chrome, the default policy switched from "prompt" to "accept".
GDPR was an attempt to restore that default behavior, however no browser did so. I'd've guessed Mozilla could be convinced to revert, but Google presumably paid them enough to look the other way.
I can answer that. A higher regulatory overhead that means less money for R&D and decreased profit margins for companies here in the EU. That's what's going to happen.
Regulation doesn't hinder innovation, it's just that CEOs want that quick buck instead of being responsible and using regulation for their advantage.
nor there is regulation to inform a user something uses AI or the dangers of being dependent on this magical oracle.
Well, there's the White House blocking models on a whim. I guess that's the closest they'll get to something resembling regulation.
The aviation industry must be one of the most regulated ones and it's entirely necessary to guarantee the safety of passengers and crew. You don't see anyone complaining about it except Boeing who failed QA in the past couple of years and killed some hundreds of people due to their oversight.
General statement that means zilch. Regulation depending on particular conditions can definitely curtail innovation or destroy it completely. Bureaucracy wants to regulate everything including how often we fart.
quality regulations don't curtail innovation.
I repeat, if your business model (which like the big majority of the entrepreneurial world is based on) is against regulation, it's wrong.
I don't think it's acceptable to have a billionaire tech bro dictating everything I do in my life while he gets rich by selling my data. One of the reasons regulation exists is to protect customers.
It's about damn time the business world moved away from the capitalism mindset that you NEED to explore the consumer to be successful. We have a lot of examples in Europe where if the company is even a bit less shitty and is sympathetic to the customer, it increases trust and brings in more revenue because your customers trust it.
Thank god Xi Jinpeng has the best interests of Europe at heart...
Re. disclosure: How do they want to do it? It seems to be similar to a “disclosure” used in students’ works: “Source: internet”…
I think enforcing compliance with the law will be rather simple, just like it happened with GDPR, food labeling and many other regulations. But I wonder how will the disclaimers/declarations even be verified? The more I think about it the more I see open sourced (both dataset and weights) models as the only truly verifiable solution. And that makes it less attractive as a business foundation if. So we might end up with state-funded models working in similar fashion to museums it other culture/art institutions ensuring that original material creators are treated fair. But that will bring whole other set of challenges...
As models become more capable, this could have serious economic consequences. :(
From my reading, it seems that while cookie permissions first became an explicit EU law concept in a 2009 amendment to ePrivacy Directive (not GDPR), companies were able to get away with passive consent banners (not popups).
It was GDPR's new definition of consent which then retroactively strengthened the existing ePrivacy Directive cookie consent to explicitly require user action to give consent (i.e. popups, banners large enough to push users to interact with them, etc.).
Unless your point is that GDPR has nothing to do with popups because the companies could just not use non-strictly-necessary cookies and therefore not need a popup, but I think that's a stretch to jump from there to "nothing to do with GDPR".
https://gdpr.eu/cookies/
https://wp-gdpr.eu/gdpr-cookie-consent-2026/
https://eulawanalysis.blogspot.com/2022/01/consent-and-cooki...
"Not a requirement under GDPR", yes, but certainly not "nothing to do with GDPR". It directly has to do with GDPR, in conjunction with business' decisions and how to comply with the law.
And of course, we can then argue our faces off about what's good and necessary in the world, in businesses and data protection, but saying it has nothing to do with it is just wrong.
Moments ago it was "misunderstandings or malicious compliance". Did you misplace one on your apologetic quest?
I'm really trying not to assume the worst about you. Is there any reason you insist so much on giving the benefit of the doubt to every law breaker out there? Especially when we're sometimes talking about very deep pockets who can afford lawyers?
Well, you are. Maybe don't do that?
You can extend causality as far as you want if you're willing to sound like this in the open. If there were no cookies, there'd be no banners. There, found you a new target.
So on one side you have decent regulation that tries to balance the interest of the user without over regulating and becoming too prescriptive, and on the other side you have abusers who most of the times are actually in malicious non-compliance... and you find a way to blame the regulation.
Good thing it's in the rules that HN is not Reddit.
And yes, it is deliberate misinformation.
Some time after IE6 and Firefox and before Chrome, the default policy switched from "prompt" to "accept".
GDPR was an attempt to restore that default behavior, however no browser did so. I'd've guessed Mozilla could be convinced to revert, but Google presumably paid them enough to look the other way.