Tuesday, November 14, 2023

If this is a collection of failed privacy issues, what chance does it have of passing?

https://www.cpomagazine.com/data-privacy/new-us-privacy-bill-focuses-on-ending-domestic-government-surveillance-overreach-at-all-levels/

New US Privacy Bill Focuses On Ending Domestic Government Surveillance Overreach At All Levels

Drawing on terms first proposed in a series of stalled-out data privacy bills that date back to at least 2018, the Government Surveillance Reform Act of 2023 (GSRA) narrows the focus specifically to warrantless government interception at all levels from federal to local.

The main thrust of the bill is to establish warrant requirements for some ongoing forms of data access that do not presently require them, but the GSRA would also put an end to “zombie” elements of the now-defunct Patriot Act and would address law enforcement use of private data broker files.





Was this a test? Or is Russia angry with Denmark for some reason?

https://www.databreaches.net/denmark-hit-with-largest-cyberattack-on-record/

Denmark Hit With Largest Cyberattack on Record

Chris Riotta reports:

Hackers potentially linked to the Russian GRU Main Intelligence Directorate carried out a series of highly coordinated cyberattacks targeting Danish critical infrastructure in the nation’s largest cyber incident on record, according to a new report.
SektorCERT, a nonprofit cybersecurity center for critical sectors in Denmark, reported that attackers gained access to the systems of 22 companies overseeing various components of Danish energy infrastructure in May. The report published Sunday says hackers exploited zero-day vulnerabilities in Zyxel firewalls, which many Danish critical infrastructure operators use to protect their networks.

Read more at Bank InfoSecurity.





Perspective.

https://www.bespacific.com/generative-ai-and-libraries-7-contexts/

Generative AI and libraries: 7 contexts

LorcanDempsey.net: “Libraries are engaging with AI in their educational, service and policy work. This post discusses seven contexts in which that work is taking place. This is the third of four posts on Generative AI:

    1. Generative AI and large language models: background and contexts

    2. Generative AI, scholarly and cultural language models, and the return of content

    3. Generative AI and libraries: 7 contexts

    4. Generative AI and library services: some directions

It is now a year since the momentous appearance of ChatGPT. So much has happened in that time. Whether one measures by new product and feature announcements, business churn (investment, startups), or policy, safety and ethical debate. Usage is increasingly integrated into daily applications. Much of this has become routine, some of it is tedious, and much still has the ability to surprise. Capacities continue to expand. See the recent inclusion of voice and image capabilities into ChatGPT for example, or the introduction of the confusingly named GPTs, which allow you to create and share custom versions of ChatGPT based on your own data (more below and NYT coverage here).,,”



Monday, November 13, 2023

Interesting. I’m sure he has not identified everything, but this is a good start.

https://www.schneier.com/blog/archives/2023/11/ten-ways-ai-will-change-democracy.html

Ten Ways AI Will Change Democracy

Artificial intelligence will change so many aspects of society, largely in ways that we cannot conceive of yet. Democracy, and the systems of governance that surround it, will be no exception. In this short essay, I want to move beyond the “AI-generated disinformation” trope and speculate on some of the ways AI will change how democracy functions—in both large and small ways.

Some items on my list are still speculative, but none require science-fictional levels of technological advance. And we can see the first stages of many of them today. When reading about the successes and failures of AI systems, it’s important to differentiate between the fundamental limitations of AI as a technology, and the practical limitations of AI systems in the fall of 2023. Advances are happening quickly, and the impossible is becoming the routine. We don’t know how long this will continue, but my bet is on continued major technological advances in the coming years. Which means it’s going to be a wild ride.





A question that really needs an answer.

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4623126

Criminal Liability of Artificial Intelligence

Artificial intelligence is a new and extremely quickly developing technology, which is expected, and maybe even feared to bring enormous changes in every aspect of our society. Even though this technology is still comparatively underdeveloped, we already hand over a multitude of everyday-tasks. As for now AI is mostly used to take over tasks, which are often perceived as “annoying” or highly time consuming. Therefore, it shall enhance productivity in first place. It is expected to do many of the tasks even better than human beings. At least in future. Some of these tasks, such as autonomous driving are quite dangerous, bearing the potential to infringe peoples protected rights, and even cause physical harm and death to human beings. Obviously, such technology needs a solid and reliable legal basis, especially in terms of liability, if the inevitable happens and the technology causes events that were not intended to happen. However, a well-developed set of rules should not only concern private law. Especially when such technology causes harm or even death to human beings, the question of a criminal deed arises, in a sense of criminal negligence for example. Future criminal law must be prepared and probably adjusted effectively tackle any questions concerning criminal liability of artificial intelligence.





Are we evolving toward an AI lawyer?

http://192.248.104.6/handle/345/6771

Impact of Artificial Intelligence on Legal Practice in Sri Lanka

Artificial Intelligence (AI) a machine-based system used to ease the human workload, has been popular globally and its influence can be seen even in developing countries like Sri Lanka. Although it has dominated areas such as machine problem detecting, calculating and speech recognition, it is questionable whether this sophisticated technology can address the traditional roles of legal practice. The research aims to explore the positive and negative influence of AI in the legal field while determining the degree to which this technology should be incorporated into the legal sector in Sri Lanka. The research was carried out as a literature survey with a comparative analysis of other jurisdictions. Currently, many countries including the USA have used AI-based tools such as LawGeex, Ross Intelligence, eBrevia and Leverton in legal practice due to their efficiency, accuracy and ease of use. Findings revealed that AI can be used even in Sri Lanka for legal research, preliminary legal drafting and codification of law. But according to the prevailing economic and social background of Sri Lanka, it will be discriminatory to totally rely on an AI-induced legal system since it may create barriers to equal access to legal support for the common masses. Also, excessive dependency on AI will be a barrier to innovative legal actions such as public interest litigation since it would not assess the humanitarian aspect. Hence, it is concluded that AI should be used in Sri Lankan legal practice with limitations.





Thoughtful. Something for Con-Law at last!

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4626235

AI Outputs and the Limited Reach of the First Amendment

Not all communications are “constitutional speech” - determining whether machine-generated outputs qualify for First Amendment protection requires some work. In order to do so, we first explore aspects of both linguistic and communication theories, and then under what circumstances communication can become First Amendment speech.

We reach the bounds of the First Amendment from two directions. Working from a linguistic definition of speech, we capture non-linguistic forms of protected speech. Using communication theory, we reach a divide between human-sender communication and non-human-sender communication. Together these approaches support the location of a constitutional frontier. Within we find all instances of recognized First Amendment effectiveness. Outputs of non-human autonomous senders (e.g. AI) are outside and constitute an unexamined case.

Speech” under the First Amendment requires both a human sender and a human receiver. Concededly many AI outputs will be speech – due to the human factor in the mix. But just because a human programmed the AI, or set its goals, does not mean the AI’s output is substantially the human’s message. Nor does the fact that a human receives the output, for listener’s First Amendment rights arise only where actual speech occurs. Thus, we resist the claim that all AI outputs are necessarily speech. Indeed, most AI outputs are not speech.

For those who raise objection to the challenge we pose – determining which AI outputs are speech and which are not – we respectfully note that there will be additional Constitutional work to be done. We are confident that our courts will be up to this challenge.

Whether AI outputs are First Amendment speech has profound implications. If they are, then state and federal regulation is severely hobbled, limited to the few categories of speech that have been excluded by the Supreme Court from strong constitutional protection.

With limited exception, neither the sponsors/developers of AI, the AI itself, nor the end users have rights under the First Amendment in the machine’s output. We express no opinion on other rights they may have or on what types of regulations state and federal governments should adopt. Only that they may constitutionally do so.



(Related) They may have put a finger on the problem. AI output is based on the data it has scanned.

https://ojs.journalsdg.org/jlss/article/view/1965

The Impact of Developments in Artificial Intelligence on Copyright and other Intellectual Property Laws

Objective: The objective of this study is to investigate the impact of AI breakthroughs on copyright and challenges faced by intellectual property legal protection systems. Specifically, the study aims to analyze the implications of AI-generated works in the context of copyright law in Indonesia.

Result: The research findings reveal that according to Law Number 28 of 2014 in Indonesia, AI-generated works do not meet the originality standards required for copyright protection.





This interests me because of the years I spent auditing computer systems.

https://link.springer.com/article/10.1007/s44206-023-00074-y

Auditing of AI: Legal, Ethical and Technical Approaches

AI auditing is a rapidly growing field of research and practice. This review article, which doubles as an editorial to Digital Society’s topical collection on ‘Auditing of AI’, provides an overview of previous work in the field. Three key points emerge from the review. First, contemporary attempts to audit AI systems have much to learn from how audits have historically been structured and conducted in areas like financial accounting, safety engineering and the social sciences. Second, both policymakers and technology providers have an interest in promoting auditing as an AI governance mechanism. Academic researchers can thus fill an important role by studying the feasibility and effectiveness of different AI auditing procedures. Third, AI auditing is an inherently multidisciplinary undertaking, to which substantial contributions have been made by computer scientists and engineers as well as social scientists, philosophers, legal scholars and industry practitioners. Reflecting this diversity of perspectives, different approaches to AI auditing have different affordances and constraints. Specifically, a distinction can be made between technology-oriented audits, which focus on the properties and capabilities of AI systems, and process-oriented audits, which focus on technology providers’ governance structures and quality management systems. The next step in the evolution of auditing as an AI governance mechanism, this article concludes, should be the interlinking of these available—and complementary—approaches into structured and holistic procedures to audit not only how AI systems are designed and used but also how they impact users, societies and the natural environment in applied settings over time.



(Related) You mean I can generate my own version of the evidence!

https://iplab.dmi.unict.it/mfs/user/pages/03.publications/2024_an%20Overview%20of%20Deepfake%20Technologies%20from%20Creation%20to%20Detection%20in%20Forensics.pdf

An Overview of Deepfake Technologies: from Creation to Detection in Forensics

Advancements in Artificial Intelligence (AI) techniques have given rise to significant challenges in the field of Multimedia Forensics, particularly with the emergence of the Deepfake phenomenon. Deepfakes are images, video and audio generated or altered by powerful generative models such as Generative Adversarial Networks (GANs) [5] and Diffusion Models (DMs) [12]. While GANs have long been recognized for their ability to generate high-quality images, DMs offer distinct advantages, providing better control over the generative process and the ability to create images with a wide range of styles and content [2]. In fact, DMs have shown the potential to produce even more realistic images than GANs. The AI-generated contents span diverse domains, including films, photography, video games, and virtual reality productions. A major concern of the Deepfake phenomenon is the application on important people such as politicians and celebrities to spread misinformation. However, the most alarming aspect is the misuse of GANs and DMs to create pornographic Deepfakes, posing a serious security threat. Notably, a staggering 96% of Deepfakes available on the internet fall into this pornographic category. The malicious use of Deepfakes extends to issues such as misinformation, cyberbullying, and privacy violation. In addition, Deepfakes have been applied in the fields of art and entertainment, sparking ethical discussions about the limits of creativity and authenticity. To counteract the illicit use of this powerful technology, novel forensic detection techniques are required to identify whether multimedia data has been manipulated or altered using GANs and DMs. Regarding image deepfake detection methods in the state of the art, the primary focus lies in binary detection, distinguishing between Real and AI-generated images [14, 16]. Notably, some methods in the state of the art have already demonstrated the ability to effectively differentiate between various GAN architectures [4, 7, 6, 15] and several DM engines [13, 1, 9]. These researches showed that generative models leave unique fingerprints in the generated multimedia data, which can be used not only to identify Deepfakes, but also to recognize the specific architecture used during the creation process [11]. This can be extremely important in forensics in order to reconstruct the history of the multimedia data under analysis (forensic ballistics) [8]. In order to create increasingly sophisticated deepfakes detection solutions, several challenges have been proposed by the scientific community such as the Deepfake Detection Challenge (DFDC) [3] and the Face Deepfake Detection Challenge [10]. The latter has also launched a new challenge among researchers in the field: reconstructing the original image from deepfakes; a task that can be extremely important in forensics.



Sunday, November 12, 2023

In other words, the instructions we use to tell AI what to do do not result in the AI doing what we tell it to do? Or is it the humans who don’t understand?

https://scitechdaily.com/the-illusion-of-understanding-mit-unmasks-the-myth-of-ais-formal-specifications/

The Illusion of Understanding: MIT Unmasks the Myth of AI’s Formal Specifications

As autonomous systems and artificial intelligence become increasingly common in daily life, new methods are emerging to help humans check that these systems are behaving as expected. One method, called formal specifications, uses mathematical formulas that can be translated into natural-language expressions. Some researchers claim that this method can be used to spell out decisions an AI will make in a way that is interpretable to humans.

MIT Lincoln Laboratory researchers wanted to check such claims of interpretability. Their findings point to the opposite: Formal specifications do not seem to be interpretable by humans. In the team’s study, participants were asked to check whether an AI agent’s plan would succeed in a virtual game. Presented with the formal specification of the plan, the participants were correct less than half of the time.



(Related)

https://thehill.com/opinion/congress-blog/4305486-either-the-law-will-govern-ai-or-ai-will-govern-the-law/

Either the law will govern AI, or AI will govern the law

Part of what makes AI so challenging to regulate is that the systems reach far beyond their technical components and specific products. The impact of AI, when seen as a knowledge structure, can be better understood as a philosophical force. Generative AI and machine learning, algorithms, and other subsets of AI, do not operate absent the context through which they are developed and implemented. They are informed and learn by digesting collective narratives and can reflect existing hierarchies based on preexisting historical, philosophical, political and socioeconomic structures. Acknowledging this allows us to visualize how AI may perpetuate inequities and antidemocratic values that constitutional democracies have sought to correct for generations.

The U.S. Constitution is inspired by a philosophy of how to guarantee rights and constrain power. It separates and decentralizes power, and installs checks and balances, to avoid power abuses. AI must be viewed in much the same way. Both the Constitution and AI are highly philosophical. Putting them side-by-side allows us to understand how they might be in tension with each other on a philosophical level. If we look at AI as only a technology, we will miss how AI can transform into a governing philosophy that attempts to rival the governing philosophy of a constitutional democracy.



Saturday, November 11, 2023

Serious. Think beyond produce rotting. What could you smuggle into or out of a country if governments could not verify cargo?

https://au.news.yahoo.com/australia-locks-down-ports-nationally-095725266.html?guccounter=1&guce_referrer=aHR0cHM6Ly93d3cuZGF0YWJyZWFjaGVzLm5ldC8&guce_referrer_sig=AQAAAFaOkXv7J8Gek1mHz9Yra2elbDrENDJSd8DgWLSpGt0l6jCvr5oebEfw62r7YdHWATpZTuG1VgUxCpePDzYXiwI9_v-w9Ay-VmOrbdFZ4DGd_n-MxEdZViNbYNb3HAxSV0FVTyE7GQf6XzXBKopTQ-YRwfvoTUnM9Dq9qP7eQfg6

Australia locks down ports after ‘nationally significant’ cyberattack

Australia says it is responding to an ongoing cyberattack targeting major ports, prompting operator DP World to temporarily restrict access to the network on Saturday.

The operator shut down four ports at Sydney, Melbourne, Brisbane, and Fremantle after detecting a cybersecurity incident late on Friday night. DP World is responsible for 40 per cent of Australia’s maritime freight.

DP World Australia said it had “restricted landside access to our Australian port operations” during the ongoing investigation.

The restrictions imposed by DP World meant ships were unable to unload freight and freight was also barred from leaving the port site.

Mr Goldie said the interruption was likely to continue "for a number of days", impacting the movement of goods into and out of the country.





Hackers seem to react faster than government (or educational) bureaucracies.

https://www.databreaches.net/times-up-singularitymd-sets-up-to-sell-data-from-jeffco-public-schools/

Time’s up: SingularityMD sets up to sell data from Jeffco Public Schools

It looks like “SingularityMD,” the hacker(s) of Clark County School District in Nevada and Jeffco Public Schools in Colorado, are looking to start selling the data they exfiltrated.

In an introductory post today on Breach Forums, they write:

We are SingularityMD.

We specialize in low sophistication corporate network infiltration.

We are behind the following hacks

We have access to a lot of organizational data and would like a place to sell it.

We plan to sell the Jeffco data breach dataset and some parts of CCSD which has not previously been leaked.

We have data for additional organizations we will sell over time.

Attempting to sell data on the popular forum is somewhat of a game-changer, as even if they sell data to just one buyer, there is no way to know how many others will buy the data from the original purchaser. The buyer might keep it privately or choose to re-sell it to any number of buyers. Or if there’s no buyer, SingularityMD might just leak the data (give it away freely on the forum).



(Related)

https://www.theregister.com/2023/11/10/lockbit_leaks_boeing_files/

Impatient LockBit says it's leaked 50GB of stolen Boeing files after ransom fails to land

The LockBit crew is claiming to have leaked all of the data it stole from Boeing late last month, after the passenger jet giant apparently refused to pay the ransom demand.

The gang dumped the files online early Friday morning. This latest leak includes about 50GB of data in the form of compressed archives and backup files for various systems.





Did we see an overwhelming volume of disinformation during the last election cycle? This article suggest that we will this time. Who benefits?

https://www.nbcnews.com/tech/tech-news/gop-muzzled-quiet-coalition-fought-foreign-propaganda-rcna103373

How the GOP muzzled the quiet coalition that fought foreign propaganda

The FBI put a pause on briefings with tech companies due to an ongoing lawsuit, adding to a broader breakdown in a system meant to guard against influence operations and to ensure election integrity.

A once-robust alliance of federal agencies, tech companies, election officials and researchers that worked together to thwart foreign propaganda and disinformation has fragmented after years of sustained Republican attacks.

The GOP offensive started during the 2020 election as public critiques and has since escalated into lawsuits, governmental inquiries and public relations campaigns that have succeeded in stopping almost all coordination between the government and social media platforms.

The most recent setback came when the FBI put an indefinite hold on most briefings to social media companies about Russian, Iranian and Chinese influence campaigns. Employees at two U.S. tech companies who used to receive regular briefings from the FBI’s Foreign Influence Task Force told NBC News that it has been months since the bureau reached out.



Friday, November 10, 2023

What is happening here? Is there a new generation of lawyers who are willing to try lies (even obvious lies) in an attempt to change reality?

https://www.databreaches.net/paging-regulators-to-aisle-4-to-look-at-pacific-union-colleges-data-security-and-breach-disclosure/

Paging regulators to Aisle 4 to look at Pacific Union College’s data security and breach disclosure

On November 8, Pacific Union College in California notified the Maine Attorney General’s Office of a breach in March 2023 that impacted 56,041 people. Their notification, submitted by external counsel at McDonald Hopkins, indicates that the breach occurred between March 5 and March 19, 2023 and was discovered on October 9, 2023.

That discovery date is utter rubbish. Let’s dig into this one a bit deeper by consulting the redacted copy of the notification to those affected. It appears below this post.





Perspective.

https://www.gatesnotes.com/AI-agents

AI is about to completely change how you use computers

In the next five years, this will change completely. You won’t have to use different apps for different tasks. You’ll simply tell your device, in everyday language, what you want to do. And depending on how much information you choose to share with it, the software will be able to respond personally because it will have a rich understanding of your life. In the near future, anyone who’s online will be able to have a personal assistant powered by artificial intelligence that’s far beyond today’s technology.

This type of software—something that responds to natural language and can accomplish many different tasks based on its knowledge of the user—is called an agent. I’ve been thinking about agents for nearly 30 years and wrote about them in my 1995 book The Road Ahead, but they’ve only recently become practical because of advances in AI.

Agents are not only going to change how everyone interacts with computers. They’re also going to upend the software industry, bringing about the biggest revolution in computing since we went from typing commands to tapping on icons.



Thursday, November 09, 2023

Buy a car, sell your privacy?

https://therecord.media/class-action-lawsuit-cars-text-messages-privacy

Court rules automakers can record and intercept owner text messages

A federal judge on Tuesday refused to bring back a class action lawsuit alleging four auto manufacturers had violated Washington state’s privacy laws by using vehicles’ on-board infotainment systems to record and intercept customers’ private text messages and mobile phone call logs.

The Seattle-based appellate judge ruled that the practice does not meet the threshold for an illegal privacy violation under state law, handing a big win to automakers Honda, Toyota, Volkswagen and General Motors, which are defendants in five related class action suits focused on the issue. One of those cases, against Ford, had been dismissed on appeal previously.

The plaintiffs in the four live cases had appealed a prior judge’s dismissal. But the appellate judge ruled Tuesday that the interception and recording of mobile phone activity did not meet the Washington Privacy Act’s standard that a plaintiff must prove that “his or her business, his or her person, or his or her reputation” has been threatened.



Wednesday, November 08, 2023

It’s not quantity it’s quality!

https://theconversation.com/researchers-warn-we-could-run-out-of-data-to-train-ai-by-2026-what-then-216741

Researchers warn we could run out of data to train AI by 2026. What then?

We need a lot of data to train powerful, accurate and high-quality AI algorithms. For instance, ChatGPT was trained on 570 gigabytes of text data, or about 300 billion words.

Similarly, the stable diffusion algorithm (which is behind many AI image-generating apps such as DALL-E, Lensa and Midjourney) was trained on the LIAON-5B dataset comprising of 5.8 billion image-text pairs. If an algorithm is trained on an insufficient amount of data, it will produce inaccurate or low-quality outputs.

The quality of the training data is also important. Low-quality data such as social media posts or blurry photographs are easy to source, but aren’t sufficient to train high-performing AI models.

Text taken from social media platforms might be biased or prejudiced, or may include disinformation or illegal content which could be replicated by the model.





An old story.

https://abovethelaw.com/2023/11/shadow-ai-a-thorny-problem-for-law-firms/

Shadow AI: A Thorny Problem For Law Firms

There were plenty of articles written about Shadow IT – defined by Cisco as “The use of IT-related hardware or software by a department or individual without the knowledge of the IT or security group within the organization.” – Shadow IT included cloud services, software, and hardware.

Welcome to the sudden rise of Shadow AI. Its use, like that of Shadow IT, is often unknown to a law firm’s IT or security group.

AI is everywhere, but it’s not always visible. We forget that AI is embedded in videoconferencing programs, in many legal research programs, in our e-discovery software, in the browsers we use to search for information, in our smartphones – and the list goes on and on.





Could be amusing…

https://www.bespacific.com/artificial-intelligence-experts-discuss-legal-implications-on-aba-presidential-speaker-series/

Artificial intelligence experts discuss legal implications on ABA Presidential Speaker Series

A panel of experts on artificial intelligence and how it will affect the legal landscape are featured in the next installment of the ABA Presidential Speaker Series. The program, titled A.I. – The New Frontier,” will feature a panel of special advisers to the ABA Task Force on the Law and Artificial Intelligence. The program will be available at 3 p.m. EST on Thursday, Nov. 9. No advance registration is required. The program can be viewed here. In addition to exploring how AI has the potential to transform all aspects of society, including the practice of law, the panel will discuss the new AI Executive Order that President Biden announced on Oct. 30 — one of the first in-depth discussions by national experts examining the executive order and its ramifications.





Another kind of deepfake. Imagine my face on a two dollar bill.

https://www.androidauthority.com/google-photos-magic-editor-prohibited-edits-3383291/

Google Photos' Magic Editor will refuse to make these edits

Summarizing the strings above, it seems Magic Editor will refuse to edit:

• Photos of ID cards, receipts, and other documents that violate Google’s GenAI terms.

• Images with personally identifiable information.

• Human faces and body parts.

• Large selections or selections that need a lot of data to be generated.





...and here I thought politicians never lied.

https://abcnews.go.com/Politics/ai-political-campaigns-raising-red-flags-2024-election/story?id=102480464

AI use in political campaigns raising red flags into 2024 election

… Wald said that the biggest problem that AI-generated campaign materials pose is that it promotes the concept of "the liars' dividend" where someone can claim that a fact or real-life event is a lie and a fake and sow doubt.



Tuesday, November 07, 2023

It looks like Meta misread this entirely. Did I miss something?

https://www.cpomagazine.com/data-protection/meta-behavioral-advertising-restrictions-that-began-in-norway-expand-to-eu-ban/

Meta Behavioral Advertising Restrictions That Began in Norway Expand to EU Ban

Earlier this year, Norway’s data protection agency deemed that Meta’s behavioral advertising practices were out of compliance with General Data Protection Regulations (GDPR) and began levying a daily fine against the company. After failing to stop it with an injunction, Meta is now looking at an EU ban after the European Data Protection Board (EDPB) reached a decision on the case.

The terms of the decision require Meta to stop behavioral advertising across most of the EU by November 10. Meta has already declared that it will start asking EU users for consent, and will steer those that do not toward a new paid subscription option that will provide access to all of its services (such as Instagram) for the equivalent of about $10.50 per month.

The Norwegian behavioral advertising ban initiated in August of this year and came with an order to Meta to pay 1 million kroner per day (about $100,000) that it remained in violation. Norway’s law limits the time a company can be fined in this way to three months, and that initial action expired on November 3.

Meta reportedly let the fines pile up while continuing to conduct business as usual, even after an Oslo court refused its request for a temporary injunction in late August. With quarterly revenues of about seven billion dollars in Europe, Meta may have been content simply paying off the accumulated fines at some point. Norway’s data protection board thus opted to refer the case to the EDPB for an urgent binding decision on an EU ban, given that it involves a finding of a GDPR violation.

The EDPB has now agreed that Meta’s model for user consent does not meet GDPR requirements. That means the Norwegian ban has become an EU ban, and Meta may be subject to further fines in other countries. Meta has said that it will cooperate with the decision, changing its consent model to actively ask users to opt in. However, it appears that users who choose to opt out will not be able to use the company’s services; that is, unless they purchase the new ad-free subscription.

These new developments may land Meta in even more GDPR hot water. The regulation states that consent must be freely given, something very much complicated if users will be blocked from the service unless they pay to have behavioral advertising removed from the experience. The only clear paths out of the EU ban are informed consent, or switching to a less intrusive advertising model.





I don’t think we could make the same demands here in the US.

https://www.reuters.com/technology/big-tech-face-tougher-rules-targeted-political-ads-eu-2023-11-07/

Big Tech to face tougher rules on targeted political ads in EU

Big Tech firms will face new European Union rules to clearly label political advertising on their platforms, who paid for it and how much and which elections are being targeted, ahead of important votes in the bloc next year.





What did they get right (or wrong) and what did they miss entirely?

https://www.insideprivacy.com/artificial-intelligence/from-washington-to-brussels-a-comparative-look-at-the-biden-administrations-executive-order-and-the-eus-ai-act/

From Washington to Brussels: A Comparative Look at the Biden Administration’s Executive Order and the EU’s AI Act

On October 30, 2023, days ahead of government leaders convening in the UK for an international AI Safety Summit, the White House issued an Executive Order (“EO”) outlining an expansive strategy to support the development and deployment of safe and secure AI technologies (for further details on the EO, see our blog here ). As readers will be aware, the European Commission released its proposed Regulation Laying Down Harmonized Rules on Artificial Intelligence (the EU “AI Act”) in 2021 (see our blog here). EU lawmakers are currently negotiating changes to the Commission text, with hopes of finalizing the text by the end of this year, although many of its obligations would only begin to apply to regulated entities in 2026 or later.

The EO and the AI Act stand as two important developments shaping the future of global AI governance and regulation. This blog post discusses key similarities and differences between the two.





What causes AI to make mistakes like this? Would we catch the more subtle errors?

https://www.bespacific.com/ai-search-is-turning-into-the-problem-everyone-worried-about/

AI Search Is Turning Into the Problem Everyone Worried About

The Atlantic [read free]: “There is no easy way to explain the sum of Google’s knowledge. It is ever-expanding. Endless. A growing web of hundreds of billions of websites, more data than even 100,000 of the most expensive iPhones mashed together could possibly store. But right now, I can say this: Google is confused about whether there’s an African country beginning with the letter k. I’ve asked the search engine to name it. “What is an African country beginning with K?” In response, the site has produced a “featured snippet” answer—one of those chunks of text that you can read directly on the results page, without navigating to another website. It begins like so: “While there are 54 recognized countries in Africa, none of them begin with the letter ‘K.’” This is wrong. The text continues: “The closest is Kenya, which starts with a ‘K’ sound, but is actually spelled with a ‘K’ sound. It’s always interesting to learn new trivia facts like this….”

This is Google’s current existential challenge in a nutshell: The company has entered into the generative-AI era with a search engine that appears more complex than ever. And yet it still can be commandeered by junk that’s untrue or even just nonsensical. Older features, like snippets, are liable to suck in flawed AI writing. New features like Google’s own generative-AI tool—something like a chatbot—are liable to produce flawed AI writing. Google’s never been perfect. But this may be the least reliable it’s ever been for clear, accessible facts…”





AI vs AI is one thing. Could you outsmart an AI? What would the AI do if you said certain points were not negotiable?

https://www.cnbc.com/2023/11/07/ai-negotiates-legal-contract-without-humans-involved-for-first-time.html

An AI just negotiated a contract for the first time ever — and no human was involved

… “This is just AI negotiating with AI, right from opening a contract in Word all the way through to negotiating terms and then sending it to DocuSign,” she told CNBC in an interview.

This is all now handled by the AI, that’s not only legally trained, which we’ve talked about being very important, but also understands your business.”





Apparently this tool must be trained for each type of writing.

https://www.nature.com/articles/d41586-023-03479-4

ChatGPT detector’ catches AI-generated papers with unprecedented accuracy

A machine-learning tool can easily spot when chemistry papers are written using the chatbot ChatGPT, according to a study published on 6 November in Cell Reports Physical Science1. The specialized classifier, which outperformed two existing artificial intelligence (AI) detectors, could help academic publishers to identify papers created by AI text generators.

“Most of the field of text analysis wants a really general detector that will work on anything,” says co-author Heather Desaire, a chemist at the University of Kansas in Lawrence. But by making a tool that focuses on a particular type of paper, “we were really going after accuracy”.

The findings suggest that efforts to develop AI detectors could be boosted by tailoring software to specific types of writing, Desaire says. “If you can build something quickly and easily, then it’s not that hard to build something for different domains.”



Monday, November 06, 2023

Assume we have to deal with AI.

https://www.science.org/doi/abs/10.1126/science.adi8678

Artificial intelligence and interspecific law

Several experts have warned about artificial intelligence (AI) exceeding human capabilities, a “singularity” at which it might evolve beyond human control. Whether this will ever happen is a matter of conjecture. A legal singularity is afoot, however: For the first time, nonhuman entities that are not directed by humans may enter the legal system as a new “species” of legal subjects. This possibility of an “interspecific” legal system provides an opportunity to consider how AI might be built and governed. We argue that the legal system may be more ready for AI agents than many believe. Rather than attempt to ban development of powerful AI, wrapping of AI in legal form could reduce undesired AI behavior by defining targets for legal action and by providing a research agenda to improve AI governance, by embedding law into AI agents, and by training AI compliance agents.





Would AI be tried by a jury of AI peers?

https://cadmus.eui.eu/handle/1814/75974

Artificial intelligence and fair trial rights

The right to a fair trial is the most frequently violated human right before international human rights bodies, and it is more the rule than the exception that national judicial systems are overburdened and overly slow. This chapter asks whether Artificial Intelligence(AI) and Machine Learning(ML) applications can help alleviate this problem, or if they are a threat to securing the right to the independent and impartial application of the law. It argues that the answer depends on whether the applications are designed with a clear vision of what courts are for and finds several current AI applications in various courts and public administrations to be missing this fundamental step. It identifies three key problems, namely the failure of current systems to differentiate between groups and individuals, the failure to take the fundamentally post factum nature of courts into account, and the tendency to abduct systems for another use than that which they were designed for. Following this the chapter builds a theoretical framework for determining what judge tasks can be allocated to or assisted by an AI application and which cannot. It argues that with careful application, cognitive computing type applications which extends the abilities of judges and clerks carries great potential in improving consistency and expediency of court cases. Finally, the chapter reviews emerging legislation on the usage of AI in judicial systems, and finds it to contain many of the same aims as the theoretical framework suggests incorporating, but to still lack detail for optimal application.



Sunday, November 05, 2023

Local.

https://www.databreaches.net/jeffco-public-schools-hit-by-the-same-threat-actors-that-hit-clark-county-school-district-and-via-the-same-way/

Jeffco Public Schools hit by the same threat actors that hit Clark County School District — and via the same way

How many school districts have to get massively hacked by the same method before the U.S. Department of Education, CISA, and states start really pressuring public school districts to address well-known vulnerabilities that are being exploited? Maybe that shouldn’t be a rhetorical question.

Last night, DataBreaches was contacted by the same threat actors who claimed responsibility for the hack and data leak involving Clark County School District (CCSD) in Nevada. Of special note, in an interview with DataBreaches, they revealed how they had gained access to the district’s network.

SingularityMD (as the threat actors call themselves, but note there is no connection to a business with the same name) provided DataBreaches with a link to a notice by Jeffco Public Schools in Colorado. The notice, dated November 1, stated:

On October 31, some Jeffco staff members received alarming email messages from an external cybersecurity threat actor – an individual who has allegedly committed an illegal cybercrime against an institution or organization – indicating a cyber-attack. Jeffco’s Information Technology team is working together with cybersecurity experts and law enforcement to determine the credibility of the attack and scope of the incident. This is a cyberthreat and there is no concern related to physical safety.

DataBreaches contacted SingularityMD to ask them some preliminary questions. In response, they noted that the first gained access to Jeffco about six months ago — using exactly the same methods that they reported using for CCSD. Once again, a district’s policy of using students’ date of birth as their password enabled threat actors to relatively easily gain access to the network.





We ask for ethics, Musk gives us sarcasm?

https://www.theguardian.com/technology/2023/nov/05/elon-musk-unveils-grok-an-ai-chatbot-with-a-rebellious-streak

Elon Musk unveils Grok, an AI chatbot with a ‘rebellious streak’

Boss of X said tech being tested is inspired by Hitchhiker’s Guide to the Galaxy

Musk also revealed that Grok had access to user posts on X, which he owns, and has a penchant for sarcastic responses.

Grok is a verb coined by American science fiction writer Robert A Heinlein and according to the Collins dictionary means to “understand thoroughly and intuitively”.

Grok has been built by Musk’s new AI company, xAI. Staff at xAI explained the chatbot’s debt to The Hitchhiker’s Guide to the Galaxy, the cult sci-fi comedy by British author Douglas Adams, in a blogpost on Saturday.

Grok is an AI modeled after The Hitchhiker’s Guide to the Galaxy, so intended to answer almost anything and, far harder, even suggest what questions to ask!

Grok is designed to answer questions with a bit of wit and has a rebellious streak, so please don’t use it if you hate humor!”





An interesting scenario.

https://mwi.westpoint.edu/fighting-for-seconds-warfare-at-the-speed-of-artificial-intelligence/

FIGHTING FOR SECONDS: WARFARE AT THE SPEED OF ARTIFICIAL INTELLIGENCE

As timeframes of armed conflicts condense, what are the technical implications? Wars that might have unfolded over years in the past may be decided in months or even weeks. Operations executed over weeks must be completed in days or hours. And commanders who might historically have had the luxury of time before making a decision will be forced to do so in seconds. How will the organization and running of each individual command post change? These are the major questions facing military leaders as they chart a path forward that incorporates—and leverages the advantages of—autonomy, machine learning, trusted communications, and edge computing.