🚨 Noyb files a complaint against OpenAI
All you need to know about tech policy & regulation | Luiza's Newsletter #101
👋 Hi, Luiza Jarovsky here. Welcome to the 101st edition of this newsletter, read by 23,100+ subscribers in 125+ countries. I hope you enjoy reading it as much as I enjoy writing it.
A special thanks to Usercentrics for sponsoring this week's free edition of the newsletter. Download their free checklist:
Google is ramping up enforcement of its new EU user consent requirements, and you don’t want your company to receive a noncompliance notice. Learn all the details with Usercentrics: who has to comply, how to do so, and what solutions are necessary. Jumpstart your GDPR, ePrivacy, and Google requirements compliance - download this free checklist.
🚨 Noyb files a complaint against OpenAI
Noyb (short for “none of your business”), the Vienna-based privacy advocacy non-profit, filed a complaint against OpenAI for not complying with EU data protection law. This is an important topic, and here's what you need to know:
➡️ According to Noyb's official release: "noyb is now asking the Austrian data protection authority (DSB) to investigate OpenAI’s data processing and the measures taken to ensure the accuracy of personal data processed in the context of the company’s large language models. Furthermore, we ask the DSB to order OpenAI to comply with the complainant’s access request and to bring its processing in line with the GDPR. Last but not least, noyb requests the authority to impose a fine to ensure future compliance. It is likely that this case will be dealt with via EU cooperation."
➡️ I've been discussing OpenAI's lack of GDPR compliance in my newsletter since December 2022, and I've said that it seems that they follow a "privacy by pressure" approach.
➡️ I've argued that if ChatGPT has "hallucinations," then prompts about individuals should come back empty, and there should be no output containing personal data.
➡️ This is especially important given that core data subjects' rights established by the GDPR, such as the right of access (Article 15), right to rectification (Article 16), and right to erasure (Article 17), don't seem feasible/applicable in the context of generative AI and LLMs due to how these systems are trained.
➡️ Showing wrong information about people can lead to various types of harm, including reputational harm.
➡️ Below is a screenshot I took at the beginning of 2023. The only correct information is that I'm Brazilian, everything else is ChatGPT “hallucinating”:
➡️ Although this fake bio seems inoffensive, releasing fake personal data might be harmful. ChatGPT has falsely accused a well-known US law professor of sexual harassment based on a made-up news article. This is not acceptable.
➡️ I reiterate: if respecting GDPR rights is not feasible for generative AI (and we can question that), then there should be no outputs showing personal data or personally identifiable information.
➡️ It will be interesting to see the developments of noyb's complaints, especially given that, so far, EU data protection authorities have not expressed a clear interpretation or ruling covering the applicability of data subjects’ rights (such as GDPR Articles 15, 16, and 17 mentioned above) in the context of generative AI and LLMs.
⚖️ Florida regulates the use of AI in political advertising
➡️ Florida Governor Ron DeSantis approved a bill regulating the use of AI in political advertising. Quotes:
➡️ "If a political advertisement (...) contains images, video, audio, graphics, or other digital content created in whole or in part with the use of generative artificial intelligence, if the generated content appears to depict a real person performing an action that did not actually occur, and if the generated content was created with intent to injure a candidate or to deceive regarding a ballot issue, the political advertisement, electioneering communication, or other miscellaneous advertisement must prominently state the following disclaimer: 'Created in whole or in part with the use of generative artificial intelligence (AI).'"
➡️ "The disclaimer must:
➵ For a printed communication, be stated in bold font with a font size of at least 12 points.
➵ For a television or video communication, be clearly readable throughout the communication and occupy at least 4 percent of the vertical picture height.
➵ For an Internet public communication that includes text or graphic components, be viewable without the user taking any action and be large enough to be clearly readable.
➵ For any audio component of a communication, be at least 3 seconds in length and spoken in a clearly audible and intelligible manner at either the beginning or the end of the audio component of the communication.
➵ For a graphic communication, be large enough to be clearly readable but no less than 4 percent of the vertical height of the communication."
➡️ The law takes effect on July 1st. Read more here.
🇪🇺 EU Commission designates Shein as a VLOP
➡️ The EU Commission designates Shein as a Very Large Online Platform (VLOP) under the Digital Services Act (DSA). This is what will happen:
➡️ Shein will have to comply with the most stringent rules under the DSA, such as:
➵ more diligent surveillance of illegal products;
➵ enhanced consumer protection measures;
➵ more transparency and accountability.
➡️ Following its designation as a VLOP, the EU Commission will supervise Shein's compliance with the DSA, together with the Irish Digital Services Coordinator.
➡️ Other companies previously designated as VLOPs include Amazon, Meta, LinkedIn, Apple, and Google Play.
➡️ Non-compliance with the DSA might lead to fines of up to 6% of the global turnover of the company.
➡️ To learn more about the DSA, join my free lightning lesson today, at 1pm ET (6pm UK time). Register here.
💰 EU will invest €112 million in AI & quantum research
➡️ The EU Commission will invest €112 million in AI and quantum research and innovation. Here's what researchers should know:
💰 €50 million for large AI models: "This call targets the development of generative AI capable of processing and generating multimodal data, including but not limited to text, images, audio, video, and 3D representations, while adapting to a wide range of tasks and domains. With this funding, Europe aims to lead in creating AI systems that are not only powerful but also adhere to European values and ethical guidelines, particularly in view of the AI Act."
💰 €15 million for intelligibility and reliability of AI systems: "The EU recognises the importance of AI systems that are not only intelligent but also understandable and safe for users, thus supporting the EU’s approach for human-centric AI."
💰 €25 million for quantum gravimeters throughout Europe: "This will not only enhance precision in Earth observation and civil engineering. It will also show how quantum technologies can represent a significant improvement on current technological capabilities. The network will consist of at least eight gravimeters (gravity sensors), demonstrating how quantum gravimetry can offer much greater precision than its classical equivalent and serving as the basis for a future pan-European digital quantum sensing infrastructure."
💰 €15 million for stimulating transnational research and development in next-generation quantum technologies: "These transnational research projects are expected to foster synergies among European stakeholders, ensuring that the EU remains at the forefront of the global quantum technology race, and cementing its position as a hub of innovation and technological self-reliance."
💰 €6 million to strengthen Europe's engagement in global ICT standardisation. "By supporting the participation of European experts in international standard-setting bodies, the EU seeks to promote its interests and values in the development of global technical specifications and standards."
💰 €1.5 million for Digital Humanism, a project that places people at the centre of the digital transformation. "This approach emphasises the need for cross-disciplinary collaboration to ensure that the digital realm upholds European standards of law, social economy, and fundamental rights."
➡️ There are MANY funding opportunities; check out the official release.
⚡ Today: Join my free lightning lesson
➡️ Enforcement under the EU Digital Services Act (DSA) has already started, and it is a great time to learn more about it. Today's 30-minute lightning lesson will be free and open to all: register here.
💡A different learning experience
➵ There is a lot of “content” available online, but content is useless without guidance, focus, and a suitable learning framework. Many people are just wasting time online.
➵ I'm passionate about teaching and empowering people with actionable knowledge that will help them advance their careers. With that in mind, I've designed our professional Bootcamps, which have received fantastic feedback:
🎓 4-week Bootcamp on Emerging Challenges in Privacy, Tech & AI (live online). The next cohort starts on May 7. This is the 6th and last cohort before a summer break. Check out the testimonials from participants, read the program & register here.
🎓 4-week Bootcamp on the EU AI Act (live online). The next cohort starts on May 8. Check out the testimonials, read the program & register here.
➵ Most people get reimbursed by their employers, and we can help with a customized invoice. There are also discounts for students & NGO members.
➵ We'll soon launch more training programs; subscribe to our course waitlist.
➵ Whenever you are ready, it will be great to see you there!
🙏 Thank you for reading!
➡️ If you enjoy this newsletter, you might also want to subscribe to our weekly job alert (privacy & AI), AI Book Club, and course waitlist.
➡️ If you have comments on this week's edition, I'll be happy to hear them! Reply to this email, and I'll get back to you soon.
Have a great day!
Luiza