The EU's AI regulation plan
The EU launched its plan to regulate AI, with draft rules and definitions. As with the DSA and DMA, and GDPR before, this is the beginning of a multi-year process of argument, lobbying and amendment. Also like GDPR, it contains some very odd ideas about the technology and industry structure that suggest the drafters have never really listened to anyone in the market they plan to regulate, and it will be full of unintended consequences.
There are certainly real policy questions around AI. Much like databases, we worry what bad people could do with it and we worry about mistakes. We worry what happens if it works and we worry what happens if it doesn't work. Machine learning offers plenty of scope for both, with face recognition on one hand and AI bias and the inscrutable nature of ML models on the other.
The problem is that we don't have a general law regulating databases - we have laws addressing specific questions. A law on consumer credit is not the same as a law on heath records. AI techniques will be part of every single piece of software - writing a law to cover all of that seems like the wrong level of abstraction. Meanwhile, you could write a law saying you're not allowed to have bugs, but would that have stopped Arizona keeping people in prison after their release date because the computer couldn't handle new sentencing rules? Should that have been handled by a database regulator, or the legal system? This is like trying to write a single law covering 'cars', that covers drunk driving, emissions standards, parking, and the tax treatment of highways. Link
Post #331
121