Don't roll the dice
I got a couple of reactions to my email yesterday about the AI act coming into force and the necessity to label chatbots as machines.
Both said, in a nutshell: “Will people really care about labelling their chatbot? Most cookie banners out there are flatly illegal and seem to stay that way. Will there be any enforcement?”
To be honest, I don’t know. They’re not wrong to be cynical. Europe seems to enforce e-privacy and GDPR rules across Europe the way I floss my teeth – sporadically. But “not enough” isn’t “never”: I’ve seen personal complaints get acted on, albeit after marinating for 2 years, and there are plenty of fines being imposed all the time.
The biggest problems are that complaints and enforcement are country-specific. And many countries starve their digital protection authorities. Others, like Ireland, see the cash rolling in from big tech and decide that a sleepy regulator is a good regulator.
The difference with the AI act, which makes me cautiously hopeful, is that enforcement seems to be at least centralised for the big fish. I’m already hearing of generative AI content being labelled on large social media platforms.
Smaller fish still swim in local waters, though. Which probably means the usual glacial pace if someone complains about their insurance broker using an unlabelled chatbot.
Personally, I wouldn’t roll those dice. You might get a warning, you might also get a fine (up to €15 million or 3% of worldwide annual turnover, whichever hurts more). Slap a label on the robot, it’s cheaper than finding out.
Colin