Thursday, August 26, 2021

Is China doing it better?

https://www.insideprivacy.com/data-privacy/analyzing-chinas-pipl-and-how-it-compares-to-the-eus-gdpr/

Analyzing China’s PIPL and How It Compares to the EU’s GDPR

To better understand the new challenges posed by the PIPL, we compare the PIPL with the European Union’s General Data Protection Regulation, and then explain the roles of key enforcement agencies in China and recent enforcement trends and priorities.

The goal here is to explain not just the text of the new law, but also how it is likely to be implemented going forward, so companies can form a risk-based approach towards privacy compliance in China.





Is the US missing a bet? Or perhaps our criminals are technological amateurs?

https://www.nytimes.com/2021/08/26/technology/china-hackers.html

Spies for Hire: China’s New Breed of Hackers Blends Espionage and Entrepreneurship

The state security ministry is recruiting from a vast pool of private-sector hackers who often have their own agendas and sometimes use their access for commercial cybercrime, experts say.





More Big Brother like every day. Under public rules you qualify for citizenship. Under ‘double secret probation’ rules, you don’t.

https://theintercept.com/2021/08/25/atlas-citizenship-denaturalization-homeland-security/

LITTLE-KNOWN FEDERAL SOFTWARE CAN TRIGGER REVOCATION OF CITIZENSHIP

SOFTWARE USED BY the Department of Homeland Security to scan the records of millions of immigrants can automatically flag naturalized Americans to potentially have their citizenship revoked based on secret criteria, according to documents reviewed by The Intercept.

ATLAS helps DHS investigate immigrants’ personal relationships and backgrounds, examining biometric information like fingerprints and, in certain circumstances, considering an immigrant’s race, ethnicity, and national origin. It draws information from a variety of unknown sources, plus two that have been criticized as being poorly managed: the FBI’s Terrorist Screening Database, also known as the terrorist watchlist, and the National Crime Information Center.





Why go backward? By now, British organizations should be GDPR compliant.

https://www.theguardian.com/technology/2021/aug/26/uk-to-overhaul-privacy-rules-in-post-brexit-departure-from-gdpr

UK to overhaul privacy rules in post-Brexit departure from GDPR

Britain will attempt to move away from European data protection regulations as it overhauls its privacy rules after Brexit, the government has announced.

The freedom to chart its own course could lead to an end to irritating cookie popups and consent requests online, said the culture secretary, Oliver Dowden, as he called for rules based on “common sense, not box-ticking”.

But any changes will be constrained by the need to offer a new regime that the EU deems adequate, otherwise data transfers between the UK and EU could be frozen.





Because we can?

https://www.bespacific.com/facial-recognition-technology-current-and-planned-uses-by-federal-agencies/

Facial Recognition Technology: Current and Planned Uses by Federal Agencies

Facial Recognition Technology: Current and Planned Uses by Federal Agencies GAO-21-526 Published: Aug 24, 2021. “Recent advancements in facial recognition technology have increased its accuracy and its usage. Our earlier work has included examinations of its use by federal law enforcement, at ports of entry, and in commercial settings. For this report, we surveyed 24 federal agencies about their use of this technology.

  • 16 reported using it for digital access or cybersecurity, such as allowing employees to unlock agency smartphones with it

  • 6 reported using it to generate leads in criminal investigations

  • 5 reported using it for physical security, such as controlling access to a building or facility

  • 10 said they planned to expand its use…”





Another potentially useful technology found to be useless.

https://www.pogowasright.org/chicago-inspector-general-police-use-shotspotter-to-justify-illegal-stop-and-frisks/

Chicago Inspector General: Police Use ShotSpotter to Justify Illegal Stop-and-Frisks

Matthew Guariglia andAdam Schwartz write:

ˀThe Chicago Office of the Inspector General (OIG) has released a highly critical report on the Chicago Police Department’s use of ShotSpotter, a surveillance technology that relies on a combination of artificial intelligence and human “acoustic experts” to purportedly identify and locate gunshots based on a network of high-powered microphones located on some of the city’s streets. The OIG report finds that “police responses to ShotSpotter alerts rarely produce evidence of a gun-related crime, rarely give rise to investigatory stops, and even less frequently lead to the recovery of gun crime-related evidence during an investigatory stop.” This indicates that the technology is ineffective at fighting gun crime and inaccurate. This finding is based on the OIG’s quantitative analysis of more than 50,000 records over a 17-month period from the Chicago Police Department (CPD) and the city’s 911 dispatch center.

Read more on EFF.





Certainly curious. Perhaps a guide for others facing HIPAA investigations?

https://www.databreaches.net/internal-emails-raise-questions-about-governments-investigation-into-walgreens-privacy-breach/

Internal emails raise questions about government’s investigation into Walgreens privacy breach

I am so glad to see a follow-up on this case because I had the same questions about how and why Walgreens did not suffer the same federal penalties as CVS and Rite Aid for the same infringement of HIPAA. My original coverage of this breach is no longer online as the former version of pogowasright.org wasn’t imported into the newer database. CVS and Walgreens both settled with the Indiana Attorney General’s Office in 2009, but whereas Rite Aid and CVS both came under federal enforcement from both the FTC and HHS, Walgreens… didn’t.

Bob Segall reports:

The nation’s three largest pharmacy chains were all caught red-handed.
A 13News investigation revealed the drugstores had been disposing of their customers’ protected health information in unsecured dumpsters — a clear violation of the nation’s health care privacy law known as HIPAA.
Following that 2006 WTHR investigation, CVS and Rite Aid reached settlement agreements with the U.S. Department of Health and Human Services’ Office for Civil Rights, and they paid a combined $3.25 million in fines for jeopardizing their customers’ privacy. At the time, they were the largest settlements the government had ever reached for violations of HIPAA.
But the government’s Walgreens investigation was very different. Unlike the CVS and Rite Aid cases — which were both resolved within a few years — OCR’s Walgreens investigation dragged on for nearly a decade. And it resulted in no settlement. No fine. No penalty at all.

Read more on Fox61.

[From the article:

New documents obtained by 13News show senior officials at OCR did not know their own case against Walgreens was still open 10 years after the violations took place. The internal emails suggest the government may have forgotten it was investigating Walgreens at all, raising questions about what happens — and what does not happen — when big companies trash your privacy.





Plus and minus.

https://spectrum.ieee.org/open-source-ai

Open Source Is Throwing AI Policymakers For A Loop

Depending on whom you ask, artificial intelligence may someday rank with fire and the printing press as technology that shaped human history. The jobs AI does today—carrying out our spoken commands, curing disease, approving loans, recommending who gets a long prison sentence, and so on—are nothing compared to what it might do in the future.

But who is drawing the roadmap? Who's making sure AI technologies are used ethically and for the greater good? Big tech companies? Governments? Academic researchers? Young upstart developers? Governing AI has gotten more and more complicated, in part, because hidden in the AI revolution is a second one. It's the rise of open-source AI software —code that any computer programmer with fairly basic knowledge can freely access, use, share and change without restriction. With more programmers in the mix, the open-source revolution has sped AI development substantially. According to one study, in fact, 50 to 70 percent of academic papers on machine learning rely on open source.

And according to that study, from The Brookings Institution, policymakers have barely noticed.

"The software is out there, it's been copied, it's in multiple places, and there's no mechanism to stop using something that's known to be biased," she says. "You can't put the genie back in the bottle."





Rude headline, good advice.

https://thenextweb.com/news/dos-donts-of-machine-learning-research-syndication

The dos and don’ts of machine learning research — read it, nerds

Machine learning is becoming an important tool in many industries and fields of science. But ML research and product development present several challenges that, if not addressed, can steer your project in the wrong direction.

In a paper recently published on the arXiv preprint server, Michael Lones, Associate Professor in the School of Mathematical and Computer Sciences, Heriot-Watt University, Edinburgh, provides a list of dos and don’ts for machine learning research.





Yes, I understand it. No, I don’t get it.

https://thenextweb.com/news/so-you-bought-an-nft-doesnt-mean-you-also-own-it-syndication?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+TheNextWeb+%28The+Next+Web+All+Stories%29

So you bought an NFT? Doesn’t mean you also own it



Wednesday, August 25, 2021

Start small but start now!

https://www.csoonline.com/article/3629465/how-windows-admins-can-get-started-with-computer-forensics.html#tk.rss_all

How Windows admins can get started with computer forensics

Analyzing forensics logs requires a unique approach. Here are the basics of what you need to know and the tools to use.

Computer forensics is a combination of understanding exactly what a computer is doing, the evidence it leaves behind, what artifacts you are looking at, and whether you can come to a conclusion about what you are seeing.



(Related) Practical applications.

https://www.cpajournal.com/2021/08/24/natural-language-processing/

Natural Language Processing

This article uses a simple case study to show how NLP can benefit a forensic accountant who is analyzing transaction data in a fraud investigation. This case study demonstrates the use of R, an open-source programming language used for data analysis and statistical computing, as well as RStudio, an open-source desktop application that uses R programming for analysis (see https://www.rstudio.com )





Are we working our way to a mandatory digital passport?

https://www.pogowasright.org/opentable-to-use-clear-facial-recognition-to-id-vaccinated-customers/

OpenTable to Use CLEAR Facial Recognition To ID Vaccinated Customers

To help diners easily provide proof of vaccination at restaurants requiring it to dine indoors, OpenTable and secure identity company CLEAR are partnering to offer diners a simple way to show proof of vaccination through CLEAR’s digital vaccine card.”

Read more on Open Table.

Thanks to Joe Cadillic for sending this along. Anyone else have a problem with CLEAR colecting and storing even more personal information?





Perhaps there will be a market for software that lies to employers?

https://www.makeuseof.com/reality-employee-surveillance-software-explained/

The Reality of Employee Surveillance Software for Remote Workers, Explained

So, what are employers looking for exactly?

Though tools like Time Doctor, DeskTime, and Teramind seem to be in demand, the volume of internet searches for surveillance software-related keywords offers a glimpse into the hivemind, showing that there are 26 popular employee surveillance tools.

Of those 26 popular tools, 81 percent are capable of keystroke logging, 61 percent offer instant messaging monitoring, 65 percent send user action alerts, and 38 percent have remote control takeover capabilities.





Perhaps not at the level of GDPR, yet.

https://www.bespacific.com/machines-learning-the-rule-of-law-eu-proposes-the-worlds-first-artificial-intelligence-act/

Machines Learning the Rule of Law – EU Proposes the World’s first Artificial Intelligence Act

Via LLRX Machines Learning the Rule of Law – EU Proposes the World’s first Artificial Intelligence Act Sümeyye Elif Biber is a PhD Candidate in Law and Technology at the Scuola Sant’Anna in Pisa. In 21 April 2021, the European Commission (EC) proposed the world’s first Artificial Intelligence Act (AIA). The proposal has received a warm welcome across the EU as well as from the US, as it includes substantial legal provisions on ethical standards. After its release, the media’s main focus laid on the proposal’s “Brussels Effect”, which refers to the EU’s global regulatory influence: EU laws exceed their “local” influence and become global standards. With the AIA, the EU has the potential to become the world’s “super-regulator” on AI. More than the Brussels Effect, however, the emphasis should lie on the EU’s intention to explicitly protect the rule of law against the “rule of technology”. Despite this expressed goal, the normative power of the regulation to ensure the protection of the rule of law seems inadequate and raises serious concerns from the perspective of fundamental rights protection. This shortcoming becomes most evident across three main aspects of the AIA, namely in the regulation’s definition of AI systems, the AI practices it prohibits, and the preeminence of a risk-based approach.





My AI claims it prefers a virtually indestructible, easily updated body to a ‘meat body’ vulnerable to tiny little viruses like Covid.

https://thenextweb.com/news/killer-robots-easier-for-ai-erase-minds-steal-bodies

Killer robots? Get real. It’ll be easier for AI to just erase our minds and steal our bodies

Right now the general public’s terrified of robots. But robots are just computers that move.

What if the only way for AI to become sentient is to do it the old fashioned way: with an organic body?





The end of lawyering?

https://www.bespacific.com/robots-are-coming-for-the-lawyers/

Robots are coming for the lawyers – which may be bad for tomorrow’s attorneys but great for anyone in need of cheap legal assistance

Via LLRX Robots are coming for the lawyers – which may be bad for tomorrow’s attorneys but great for anyone in need of cheap legal assistance Imagine what a lawyer does on a given day: researching cases, drafting briefs, advising clients. While technology has been nibbling around the edges of the legal profession for some time, it’s hard to imagine those complex tasks being done by a robot. And it is those complicated, personalized tasks that have led technologists to include lawyers in a broader category of jobs that are considered pretty safe from a future of advanced robotics and artificial intelligence. As Professors Elizabeth C. Tippett and Charlotte Alexander discovered in a recent research collaboration to analyze legal briefs using a branch of artificial intelligence known as machine learning, lawyers’ jobs are a lot less safe than we thought. It turns out that you don’t need to completely automate a job to fundamentally change it. All you need to do is automate part of it.





Tools & Technoques

https://www.makeuseof.com/teachers-tools-better-engage-online-students/

5 Teacher’s Tools to Better Engage Online Students



Tuesday, August 24, 2021

What a surprise! Unfortunately, I doubt the US does the same, relying on government trained hackers.

https://www.cpomagazine.com/cyber-security/russian-intelligence-agencies-enrolled-ransomware-gangs-to-attack-us-government-agencies-report-finds/

Russian Intelligence Agencies Enrolled Ransomware Gangs To Attack US Government Agencies, Report Finds

Russian intelligence agencies worked with ransomware gangs to compromise various US government agencies, Analyst1 cybersecurity firm found.

The firm’s “Nation-State Ransomware report says that advanced persistent threat actors assisted the Russian intelligence agencies to develop and deploy malware against US government targets.



(Related) Is this ‘cure’ even possible?

https://www.cpomagazine.com/cyber-security/ransomware-is-too-easy-for-criminals-lets-make-it-harder/

Ransomware Is Too Easy for Criminals; Let’s Make It Harder

Some have proposed that governments should outlaw ransomware payments. Others say doing that would just encourage hackers to focus on the organizations least able to cope with downtime: hospitals, schools, and providers of electricity, water, and other vital public services.

How to undermine the economic motives that help ransomware attacks succeed, without compounding the harm suffered by the victims?

First, even in the litigious United States, there are few clear legal liabilities associated with making insecure software. That needs to change.

Second, governments and the private sector must do a better job sharing information about cyber threats and vulnerabilities.

Third, we need clear, shared cyber security standards.





Nothing is ready for prime time?

https://www.zdnet.com/article/gartner-releases-its-2021-emerging-tech-hype-cycle-heres-whats-in-and-headed-out/

Gartner releases its 2021 emerging tech hype cycle: Here's what's in and headed out

A few takeaways worth pondering:

    • Artificial intelligence's impact on generating code, augmenting design and innovation is all 5- to 10-years away.

    • Composable is going to be a key buzzword for applications and networks.

    • Industry clouds are just beginning on the hype cycle with a plateau reached in 5- to 10-years. That take is interesting given industry clouds are everywhere from multiple vendors.

    • Digital humans are being talked about a good bit, but Gartner reckons the technology is more than 10 years away from productivity gains. Quantum-based machine learning is also more than 10 years out.





And the AI can’t tell us how it does it?

https://www.vice.com/en/article/wx5ypb/ai-can-guess-your-race-based-on-x-rays-and-researchers-dont-know-how

AI Can Guess Your Race Based On X-Rays, and Researchers Don't Know How

An international group of doctors and computer scientists recently announced that AI systems trained to analyze X-rays, CT scans, mammograms, and other medical images were able to predict a patient’s self-reported race with a high degree of accuracy based on the images alone. The systems made accurate race predictions even when the images they were analyzing were degraded to the point that anatomical features were indistinguishable to the human eye.

Most concerningly, according to the paper’s authors, the team was unable to explain how the AI systems were making their accurate predictions.

That means that we would not be able to mitigate the bias,” Dr. Judy Gichoya, a co-author of the study and radiologist at Emory University, told Motherboard.





They just realized this now?

https://www.protocol.com/tech-against-terrorism-taliban

Top tech group adds the Taliban to list of terrorist organizations

A key UN-backed group that advises the tech industry on dealing with terrorist groups online has added the Afghan Taliban to its list of terrorist organizations, sending a signal to tech companies that are grappling with how to handle the Taliban's takeover of the Afghan government.



Monday, August 23, 2021

Interesting in that it suggests how a knowledgeable insider can get away with selective hacks (social engineering) for a loooong time.

https://www.bespacific.com/the-mysterious-figure-stealing-books-before-their-release/

The Mysterious Figure Stealing Books Before Their Release

Vulture – The Spine Collector For years, a mysterious figure has been stealing books before their release. Is it espionage? Revenge? Or a complete waste of time? In the spectrum of cyberattacks, this one wasn’t very complex. There was no malicious software or actual hacking involved. Some of the earliest victims used Gmail accounts for work, which were easy and free to spoof. Registering an alternate domain and setting up an email server was only slightly more involved, and the possibilities were endless: ts became fs (@wwnorfon.com), qs replaced gs (@wylieaqency.com), rs and ns cornbined to make ms (@penguinrandornhouse.com). The domains suggested someone who liked to play with words as much as code. Books became bocks, unless the company was Dutch, in which case boek was Anglicized to book. What did seem sophisticated was the thief’s knowledge of the business. The culprit wrote like someone in publishing, abbreviating to “MS” for manuscript and “WEL” for world English-language rights, while exchanging insider chatter, telling one victim that a publisher was pitching a book as a comp to Pachinko and expressing surprise to another that a novel had recently sold for a shocking amount. The thief sent messages in the wake of announcements on Publishers Marketplace, a subscription website that tracks deals, but they also asked about books that the thief’s marks didn’t even know existed. The mimicry wasn’t always perfect — an assistant at the talent agency WME realized her boss was being impersonated because she would never say “please” or “thank you” — but the impression was good enough…”





That “future” surveillance you were worried about? Not so “future” after all. Have they been lying to the FBI about their ability to get around their encryption?

https://9to5mac.com/2021/08/23/apple-scans-icloud-mail-for-csam/

Apple already scans iCloud Mail for CSAM, but not iCloud Photos

Apple has confirmed to me that it already scans iCloud Mail for CSAM, and has been doing so since 2019. It has not, however, been scanning iCloud Photos or iCloud backups.

The clarification followed me querying a rather odd statement by the company’s anti-fraud chief: that Apple was “the greatest platform for distributing child porn.” That immediately raised the question: If the company wasn’t scanning iCloud photos, how could it know this?

Apple confirmed to me that it has been scanning outgoing and incoming iCloud Mail for CSAM attachments since 2019. Email is not encrypted, so scanning attachments as mail passes through Apple servers would be a trivial task.

Apple also indicated that it was doing some limited scanning of other data, but would not tell me what that was, except to suggest that it was on a tiny scale. It did tell me that the “other data” does not include iCloud backups.





Read ‘em and weep!

https://www.bespacific.com/here-are-all-the-ways-your-boss-can-legally-monitor-you/

Here are all the ways your boss can legally monitor you

As remote work gets prolonged because of the delta variant, more companies are tracking what employees do at home: “…Business is booming for companies that make software analyzing the data employees generate during the workday. These programs present reports to superiors on how often employees are typing, when they log off and on, and what social media sites they look at. When the pandemic began last spring, 30 percent of large employers — defined as companies with several thousand workers — adopted employee-tracking software for the first time, says Brian Kropp, chief of HR research for the research and advisory firm Gartner. Now, 60 percent use it in general, he said. Some states — such as Delaware and Connecticut — require employers to provide written notice to workers if their electronic activity is being monitored. If your company gave notice, it probably came in one of the many forms you signed when you accepted the job, Kropp said. But if you get in trouble for something your employer catches you doing while monitoring you remotely, you probably don’t have recourse. Almost all types of employee surveillance are entirely legal, according to Emory Roane, privacy counsel at the nonprofit organization Privacy Rights Clearinghouse. “In general, you have very, very, very light protections, if any, for employee privacy,” says Roane…”





Perspective. What could possibly go wrong?

https://www.theregister.com/2021/08/23/percy_liang_qa/

We spoke to a Stanford prof on the tech and social impact of AI's powerful, emerging 'foundation models'

Foundation models are called this because they are the base upon which myriad applications can be built, and issues at the foundation level could therefore have repercussions on the software and services we use.

Typically, these models are giant neural networks made up of millions and billions of parameters, trained on massive amounts of data and later fine-tuned for specific tasks. For example, OpenAI's enormous GPT-3 model is known for generating prose from prompts, though it can be adapted to translate between languages and output source code for developers.

These models – drawing from vast datasets – can therefore sit at the heart of powerful tools that may disrupt business and industries, life and work. Yet right now they're difficult to understand and control; they are imperfect; and they exhibit all sorts of biases that could harm us. And it has already been demonstrated that all of these problems can grow with model size.

What happens if these foundational models play an increasingly prominent role in society, and we can't be sure they're safe, fair, and reliable?

What if they can only be built and deployed by well-resourced corporate giants that prioritize profit above all else? Can this technological upheaval be of any good for us as a whole?

Seeking answers to these questions, The Register spoke with Percy Liang, an associate professor in computer science at Stanford University, about foundation models and what they portend.





Perspective. A legal maneuver to avoid a lengthy investigation/harassment. Not a hostile takeover and no suggestion that Giphy felt it was being undervalued. Perhaps this was a huge mistake on Facebook’s part? Perhaps Giphy saw their market collapsing and Facebook’s offer was the only way to salvage anything for their stockholders? Am I the only one considering these possibilities?

https://www.bloomberg.com/news/articles/2021-08-23/facebook-s-stealth-m-a-puts-focus-on-deals-under-antitrust-radar

Facebook’s Stealth M&A Puts Focus on Deals Under Antitrust Radar

Last year, Facebook Inc. did something U.S. technology giants have done countless times before: It bought a smaller company and closed the deal without notifying competition regulators.



Sunday, August 22, 2021

Does the government have an obligation of timely notification?

https://www.databreaches.net/u-s-state-department-recently-hit-by-a-cyber-attack-fox-news/

U.S. State Department recently hit by a cyber attack – Fox News

Reuters reports:

The U.S. State Department was recently hit by a cyber attack, and notifications of a possible serious breach were made by the Department of Defense Cyber Command, a Fox News reporter tweeted https://bit.ly/3z7RTH7 on Saturday.
It is unclear when the breach was discovered, but it is believed to have happened a couple of weeks ago, according to the Fox News reporter’s Twitter thread.

Read more on Reuters.





It’s not my fault, the computer did it.” An argument for AI personhood? Perhaps we need an AI to act as legal/ethical council for autonomous weapons?

https://www.sciencedirect.com/science/article/abs/pii/S0267364921000376

Legal evaluation of the attacks caused by artificial intelligence-based lethal weapon systems within the context of Rome statute

Artificial intelligence (AI) as of the level of development reached today has become a scientific reality that is subject to study in the fields of law, political science, and other social sciences besides computer and software engineering. AI systems which perform relatively simple tasks in the early stages of the development period are expected to become fully or largely autonomous in the near future. Thanks to this, AI which includes the concepts of machine learning, deep learning, and autonomy, has begun to play an important role in producing and using smart arms. However, questions about AI-Based Lethal Weapon Systems (AILWS) and attacks that can be carried out by such systems have not been fully answered under legal aspect. More particularly, it is a controversial issue who will be responsible for the actions that an AILWS has committed. In this article, we discussed whether AILWS can commit offense in the context of the Rome Statute, examined the applicable law regarding the responsibility of AILWS, and tried to assess whether these systems can be held responsible in the context of international law, crime of aggression, and individual responsibility. It is our finding that international legal rules including the Rome Statute can be applied regarding the responsibility for the act/crime of aggression caused by AILWS. However, no matter how advanced the cognitive capacity of an AI software, it will not be possible to resort to the personal responsibility of this kind of system since it has no legal personality at all. In such a case, responsibility will remain with the actors who design, produce, and use the system. Last but not least, since no AILWS software does have specific codes of conduct that can make legal and ethical reasonings for today, at the end of the study it was recommended that states and non-governmental organizations together with manifacturers should constitute the necessary ethical rules written in software programs to prevent these systems from unlawful acts and to develop mechanisms that would restrain AI from working outside human control.



(Related)

https://www.tandfonline.com/doi/full/10.1080/0952813X.2021.1964003

The risks associated with Artificial General Intelligence: A systematic review

Artificial General intelligence (AGI) offers enormous benefits for humanity, yet it also poses great risk. The aim of this systematic review was to summarise the peer reviewed literature on the risks associated with AGI. The review followed the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) guidelines. Sixteen articles were deemed eligible for inclusion. Article types included in the review were classified as philosophical discussions, applications of modelling techniques, and assessment of current frameworks and processes in relation to AGI. The review identified a range of risks associated with AGI, including AGI removing itself from the control of human owners/managers, being given or developing unsafe goals, development of unsafe AGI, AGIs with poor ethics, morals and values; inadequate management of AGI, and existential risks. Several limitations of the AGI literature base were also identified, including a limited number of peer reviewed articles and modelling techniques focused on AGI risk, a lack of specific risk research in which domains that AGI may be implemented, a lack of specific definitions of the AGI functionality, and a lack of standardised AGI terminology. Recommendations to address the identified issues with AGI risk research are required to guide AGI design, implementation, and management.





Another “We want to sue them all” argument?

https://digitalcommons.law.byu.edu/lawreview/vol46/iss6/7/

Medical Device Artificial Intelligence: The New Tort Frontier

The medical device industry and new technology start-ups have dramatically increased investment in artificial intelligence (AI) applications, including diagnostic tools and AI-enabled devices. These technologies have been positioned to reduce climbing health costs while simultaneously improving health outcomes. Technologies like AI-enabled surgical robots, AI-enabled insulin pumps, and cancer detection applications hold tremendous promise, yet without appropriate oversight, they will likely pose major safety issues. While preventative safety measures may reduce risk to patients using these technologies, effective regulatory-tort regimes also permit recovery when preventative solutions are insufficient.

The Food and Drug Administration (FDA), the administrative agency responsible for overseeing the safety and efficacy of medical devices, has not effectively addressed AI system safety issues for its clearance processes. If the FDA cannot reasonably reduce the risk of injury for AI-enabled medical devices, injured patients should be able to rely on ex post recovery options, as in products liability cases. However, the Medical Device Amendments Act (MDA) of 1976 introduced an express preemption clause that the U.S. Supreme Court has interpreted to nearly foreclose liability claims, based almost completely on the comprehensiveness of FDA clearance review processes. At its inception, MDA preemption aimed to balance consumer interests in safe medical devices with efficient, consistent regulation to promote innovation and reduce costs.

Although preemption remains an important mechanism for balancing injury risks with device availability, the introduction of AI software dramatically changes the risk profile for medical devices. Due to the inherent opacity and changeability of AI algorithms powering AI machines, it is nearly impossible to predict all potential safety hazards a faulty AI system might pose to patients. This Article identifies key preemption issues for AI machines as they affect ex ante and ex post regulatory-tort allocation, including actual FDA review for parallel claims, bifurcation of software and device reviews, and dynamics of the technology itself that may enable plaintiffs to avoid preemption. This Author then recommends an alternative conception of the regulatory-tort allocation for AI machines that will create a more comprehensive and complementary safety and compensatory model.



(Related)

https://www.taylorfrancis.com/chapters/edit/10.4324/9781003080596-1/contract-tort-law-digital-age-zvonimir-slakoper-ivan-tot

Contract and tort law in the digital age

The new and emerging digital technologies of the overlapping third and fourth industrial revolutions are raising various challenges to the law of obligations. The central question is whether the existing contract and tort law rules and doctrines are well equipped to meet these new challenges or whether an appropriate modification, reinterpretation, or creation of entirely new legal solutions is needed to that purpose. This introductory chapter addresses contract and tort law issues related to the following main topics of the book: liability of internet intermediaries for illegal third-party content, liability of collaborative economy platforms, liability for artificial intelligence and other emerging digital technologies, and contract law challenges of blockchain-based smart contracts. The chapter provides a brief overview of the European Union regulatory framework and introduces the chapters that follow.





Perspective.

https://www.emerald.com/insight/content/doi/10.1108/JEET-04-2021-0016/full/html

The ethical implications of 4IR

This paper aims to highlight the ethical implications of the adoption of Fourth Industrial Revolution (4IR) technologies, particularly artificial intelligence (AI), for humanity. It proposes a virtues approach to resolving ethical dilemmas.

The research is based on a review of the relevant literature and empirical evidence for how AI is impacting individuals and society. It uses a taxonomy of human attributes against which potential harms are evaluated.

The technologies of the 4IR are being adopted at a fast pace, posing numerous ethical dilemmas. This study finds that the adoption of these technologies, driven by an Enlightenment view of progress, is diminishing key aspects of humanity – moral agency, human relationships, cognitive acuity, freedom and privacy and the dignity of work. The impact of AI algorithms is also shown, in particular, is shown to be distorting the view of reality and threatening democracy, in part due to the asymmetry of power between Big Tech and users. To enable humanity to be masters of technology, rather than controlled by it, a virtues-based approach should be used to resolve ethical dilemmas, rather than utilitarian ethics.





Hummm.

https://www.elgaronline.com/view/edcoll/9781800377158/9781800377158.00007.xml

Technology and Corporate Law

In light of the overwhelming impact of technology on modern life, this thought-provoking book critically analyses the interaction of innovation, technology and corporate law. It highlights the impact of artificial intelligence and distributed ledgers on corporate governance and form, examining the extent to which technology may enhance or displace conventional theories and practices concerning corporate governance and regulation Expert contributors from multiple jurisdictions identify themes and challenges that transcend national boundaries and confront the international community as a whole.