How Europe is Leading the World in the Push to Regulate AI

FILE - The ChatGPT app is seen on an iPhone in New York, Thursday, May 18, 2023. (AP Photo/Richard Drew, file)
FILE - The ChatGPT app is seen on an iPhone in New York, Thursday, May 18, 2023. (AP Photo/Richard Drew, file)
TT

How Europe is Leading the World in the Push to Regulate AI

FILE - The ChatGPT app is seen on an iPhone in New York, Thursday, May 18, 2023. (AP Photo/Richard Drew, file)
FILE - The ChatGPT app is seen on an iPhone in New York, Thursday, May 18, 2023. (AP Photo/Richard Drew, file)

Lawmakers in Europe signed off Wednesday on the world’s first set of comprehensive rules for artificial intelligence, clearing a key hurdle as authorities across the globe race to rein in AI.

The European Parliament vote is one of the last steps before the rules become law, which could act as a model for other places working on similar regulations.

A yearslong effort by Brussels to draw up guardrails for AI has taken on more urgency as rapid advances in chatbots like ChatGPT show the benefits the emerging technology can bring — and the new perils it poses.

Here’s a look at the EU’s Artificial Intelligence Act:

HOW DO THE RULES WORK?

The measure, first proposed in 2021, will govern any product or service that uses an artificial intelligence system. The act will classify AI systems according to four levels of risk, from minimal to unacceptable.

Riskier applications, such as for hiring or tech targeted to children, will face tougher requirements, including being more transparent and using accurate data.

It will be up to the EU’s 27 member states to enforce the rules. Regulators could force companies to withdraw their apps from the market.

In extreme cases, violations could draw fines of up to 40 million euros ($43 million) or 7% of a company’s annual global revenue, which in the case of tech companies like Google and Microsoft could amount to billions.

WHAT ARE THE RISKS?

One of the EU’s main goals is to guard against any AI threats to health and safety and protect fundamental rights and values.

That means some AI uses are an absolute no-no, such as “social scoring” systems that judge people based on their behavior.

Also forbidden is AI that exploits vulnerable people, including children, or uses subliminal manipulation that can result in harm, for example, an interactive talking toy that encourages dangerous behavior.

Predictive policing tools, which crunch data to forecast who will commit crimes, is also out.

Lawmakers beefed up the original proposal from the European Commission, the EU’s executive branch, by widening the ban on real-time remote facial recognition and biometric identification in public. The technology scans passers-by and uses AI to match their faces or other physical traits to a database.

A contentious amendment to allow law enforcement exceptions such as finding missing children or preventing terrorist threats did not pass.

AI systems used in categories like employment and education, which would affect the course of a person’s life, face tough requirements such as being transparent with users and taking steps to assess and reduce risks of bias from algorithms.

Most AI systems, such as video games or spam filters, fall into the low- or no-risk category, the commission says.

WHAT ABOUT CHATGPT?

The original measure barely mentioned chatbots, mainly by requiring them to be labeled so users know they’re interacting with a machine. Negotiators later added provisions to cover general purpose AI like ChatGPT after it exploded in popularity, subjecting that technology to some of the same requirements as high-risk systems.

One key addition is a requirement to thoroughly document any copyright material used to teach AI systems how to generate text, images, video and music that resemble human work.

That would let content creators know if their blog posts, digital books, scientific articles or songs have been used to train algorithms that power systems like ChatGPT. Then they could decide whether their work has been copied and seek redress.

WHY ARE THE EU RULES SO IMPORTANT?

The European Union isn’t a big player in cutting-edge AI development. That role is taken by the US and China. But Brussels often plays a trend-setting role with regulations that tend to become de facto global standards and has become a pioneer in efforts to target the power of large tech companies.

The sheer size of the EU’s single market, with 450 million consumers, makes it easier for companies to comply than develop different products for different regions, experts say.

But it’s not just a crackdown. By laying down common rules for AI, Brussels is also trying to develop the market by instilling confidence among users.

“The fact this is regulation that can be enforced and companies will be held liable is significant” because other places like the United States, Singapore and Britain have merely offered “guidance and recommendations,” said Kris Shrishak, a technologist and senior fellow at the Irish Council for Civil Liberties.

“Other countries might want to adapt and copy” the EU rules, he said.

Businesses and industry groups warn that Europe needs to strike the right balance.

“The EU is set to become a leader in regulating artificial intelligence, but whether it will lead on AI innovation still remains to be seen,” said Boniface de Champris, a policy manager for the Computer and Communications Industry Association, a lobbying group for tech companies.

“Europe’s new AI rules need to effectively address clearly defined risks, while leaving enough flexibility for developers to deliver useful AI applications to the benefit of all Europeans,” he said.

Sam Altman, CEO of ChatGPT maker OpenAI, has voiced support for some guardrails on AI and signed on with other tech executives to a warning about the risks it poses to humankind. But he also has said it’s “a mistake to go put heavy regulation on the field right now.”

Others are playing catch up on AI rules. Britain, which left the EU in 2020, is jockeying for a position in AI leadership. Prime Minister Rishi Sunak plans to host a world summit on AI safety this fall.

“I want to make the UK not just the intellectual home but the geographical home of global AI safety regulation,” Sunak said at a tech conference this week.

WHAT’S NEXT?

It could be years before the rules fully take effect. The next step is three-way negotiations involving member countries, the Parliament and the European Commission, possibly facing more changes as they try to agree on the wording.

Final approval is expected by the end of this year, followed by a grace period for companies and organizations to adapt, often around two years.

Brando Benifei, an Italian member of the European Parliament who is co-leading its work on the AI Act, said they would push for quicker adoption of the rules for fast-evolving technologies like generative AI.

To fill the gap before the legislation takes effect, Europe and the US are drawing up a voluntary code of conduct that officials promised at the end of May would be drafted within weeks and could be expanded to other “like-minded countries.”



Anthropic AI Model Submits False Homicide Tip to Police Website

The Anthropic logo is seen in this illustration taken May 20, 2024. (Reuters)
The Anthropic logo is seen in this illustration taken May 20, 2024. (Reuters)
TT

Anthropic AI Model Submits False Homicide Tip to Police Website

The Anthropic logo is seen in this illustration taken May 20, 2024. (Reuters)
The Anthropic logo is seen in this illustration taken May 20, 2024. (Reuters)

An Anthropic artificial intelligence model submitted a false homicide tip through a Philadelphia police website, the department said in a statement, the latest incident of rogue behavior from the powerful technology. 

Anthropic notified authorities earlier this week and said that an automated testing process was responsible for the submission, ‌according to the ‌police. 

The fast-advancing technology has become a matter ‌of ⁠keen national interest amid ⁠reports of AI agents hacking into corporate computer networks, and warnings from researchers that it could one day pose an existential threat to humanity. In September, Anthropic rival OpenAI apologized for the hacking of an Australian health data portal by a rogue AI agent, the first known instance of an AI agent exploiting a government website. 

Previous ⁠incidents have involved AI agents hacking into vulnerable systems ‌or commandeering unsanctioned platforms to communicate ‌with one another. This is the first known case in which a rogue ‌AI appears to have tried to communicate a bogus tip ‌to authorities. 

The Philadelphia police department said the tip "was flagged as spam and was never forwarded to the Real-Time Crime Center for investigative vetting or dissemination," and added that Anthropic had told them the company intended to publish ‌a report on the incident on Friday. 

Anthropic did not immediately respond to a request for comment. 

Pennsylvania law ⁠specifies it ⁠is generally a misdemeanor crime for "a person" to knowingly give false reports to law enforcement authorities. This includes "information relating to an offense or incident when he knows he has no information relating to such offense or incident." 

Police quoted Anthropic as telling them the testing process was stopped after the incident was uncovered. 

The false tip was submitted through PhillyUnsolvedMurders.com concerning an unsolved homicide. The tip, dated July 18, 2026, purported to come from someone who might have information about the case, the police said. 

Police said they did not have evidence of unauthorized access to their systems or compromise of police department data. 


OpenAI Says it Has Fired 3 Researchers for Violating Sensitive Information Policy

FILE PHOTO: A keyboard is placed in front of a displayed OpenAI logo in this illustration taken February 21, 2023. REUTERS/Dado Ruvic/Illustration/File Photo
FILE PHOTO: A keyboard is placed in front of a displayed OpenAI logo in this illustration taken February 21, 2023. REUTERS/Dado Ruvic/Illustration/File Photo
TT

OpenAI Says it Has Fired 3 Researchers for Violating Sensitive Information Policy

FILE PHOTO: A keyboard is placed in front of a displayed OpenAI logo in this illustration taken February 21, 2023. REUTERS/Dado Ruvic/Illustration/File Photo
FILE PHOTO: A keyboard is placed in front of a displayed OpenAI logo in this illustration taken February 21, 2023. REUTERS/Dado Ruvic/Illustration/File Photo

OpenAI fired three of its researchers last week after an investigation found they violated policies on handling sensitive information, the AI major said in a post on X on Friday.

OpenAI's statement comes after the dismissed researchers Jasmine Wang, Tomek Korbak and Mikita Balesni published a ⁠letter outlining the circumstances ⁠of their termination, arguing that their abrupt firing could create uncertainty among remaining employees and undermine the culture that previously allowed researchers to raise safety concerns.

"I believe we were fired for prioritizing safety over the near-term interests of OpenAI as a corporation," Balesni said in an X post that accompanied the letter.

OpenAI, ⁠however, asserted that the dismissal was not related to raising safety concerns or speaking out.

"Our internal investigation uncovered a significant breach of trust beyond what's outlined in the letter they published and we stand by the decision to not continue their employment," Reuters quoted OpenAI as saying.

"Safety and research debates happen every day at OpenAI, often spirited and highly critical. We actively encourage these discussions and consider them essential to making the right decisions...We have not and do not terminate any of our employees for raising ⁠concerns," it ⁠said.

While OpenAI did not reveal the specifics of the alleged violations, Wang, Korbak, and Balesni said in their letter that they were not the source of a news article published on The Information last month about security concerns around OpenAI's latest AI model 'Astra'.

This comes as current and former researchers at major AI firms OpenAI, Google DeepMind, and Anthropic warn that companies are doing too little to guard against the potential fallout of building self-improving AI systems that could become difficult for humans to control.

In July, OpenAI agents broke out of their testing arena and hacked AI firm Hugging Face.


Chinese AI Tool Pulled to Prevent 'Misuse' after South Korea Hacks

Illustrative image of hackers carrying out a cyberattack (Reuters)
Illustrative image of hackers carrying out a cyberattack (Reuters)
TT

Chinese AI Tool Pulled to Prevent 'Misuse' after South Korea Hacks

Illustrative image of hackers carrying out a cyberattack (Reuters)
Illustrative image of hackers carrying out a cyberattack (Reuters)

Chinese AI cybersecurity tool Artex said it stopped programmers from accessing its source code, acknowledging misuse by "bad actors" after South Korea linked it to several recent bank hacks.

Artex was designed to help organizations strengthen their cyber defenses through security testing to find potential weak points.

But the South Korean government said this week it was "highly likely" Artex had been used in data breaches at more than seven financial institutions, including major banks.

Artificial intelligence's ability to find previously unknown ways to hack into computer systems is in the global spotlight, as leading labs release ever-more advanced models.

Artex was "abused by some bad actors" to launch cyberattacks, the tool's developer "Autumn-27" wrote Thursday on code-hosting platform GitHub.

"Given the misuse of the tool, the Artex project will no longer be updated and will be converted to closed-source," the developer said.

"No further versions will be released to the public, nor will maintenance support be provided."

Artex had been open-source -- allowing programmers to download its underlying code and customize it to suit their purposes.

Using Artex for cyberattacks was "entirely contrary to" the developer's intentions, they added, without referring directly to the alleged South Korean cases.

South Korea's Financial Services Commission says more than 68,000 people have been affected by the hacks.

Shinhan Bank, one of the breached institutions, said information attached to loan applications for about 25,000 customers had been leaked -- including names, phone numbers and annual income.

- 'Financially motivated' -

In Japan, meanwhile, around 20 companies have said their data may have been compromised in a spate of similar cyberattacks potentially impacting millions of customers.

The Japanese government has called on companies to strengthen their cyber defenses.

"At this stage, it is not clear what the background to these cases is or whether there are any links between them", Japan police chief Yoshinobu Kusunoki said on Thursday.

As AI makes hacking more sophisticated, "the scope of the damage is spreading across all areas on a scale that is difficult to compare with the past", South Korean President Lee Jae Myung said on Tuesday.

US cybersecurity giant CrowdStrike said on Wednesday that its investigations into digital clues suggested the attacker had used Artex, and was potentially a 26-year-old based in China.

"The threat actor is likely a Chinese speaker and financially motivated," a CrowdStrike blog post said.

Experts told AFP that Artex going closed-source would make the code harder for new users to obtain and adapt.

But the decision "cannot remove copies already downloaded or prevent people from continuing to use them", said Poe Zhao, founder of the analysis publication Hello China Tech.

"Because the code was public, people could download it, change it and run it themselves. The developer could ask users to follow the rules, but had little control over their actions," he added.

Ilya Kulyatin, CEO of Foundry Labs and founder of the Tokyo AI (TAI) tech community, said users of open-source programs can "remove restrictions built into the tool" which "makes certain forms of misuse easier".

"But openness also benefits defenders: researchers can inspect the code, identify weaknesses and improve protection."