It's not that they're trying to "fix a problem," but rather that they're trying to fix every problem and doing so rather badly and with little concern for the harmful effects of their legislation.
There are plenty of voluntary standards that have been widely adopted by industry, including those developed by ANSI and ISO.
I much prefer the idea of a voluntary standard to something like what was recently covered here by Cathy Gellis: https://www.techdirt.com/2023/09/06/move-over-software-developers-in-the-name-of-cybersecurity-the-government-wants-to-drive/
The European Union is out of control. To them, there is not a single problem that cannot be solved through regulation, like the proverb about everything looking like a nail when all you have is a hammer.
Huge fines, extraterritorial application, and regulating everything that moves seems to be the European Union's standard approach to the Internet. I hope US legislators and litigators can find a way to mitigate the risks posed by the EU's insistence on becoming the Internet's global police.
All right, which one of you decided to give Europe keys to the Internet? We should consider changing the locks.
I really hope Prof. Frye is trolling because detecting "creativity" by running it through an LLM is a lot like trying to detect whether a given text is AI generated by doing the same. To say that such an approach is unreliable would be an understatement, and to condition legal outcomes based on the output of an AI is precisely the kind of AI misuse we should be looking to avoid. What should be the threshold for denying copyright registration based on an AI's confidence score for creativity? What should be the confidence threshold for expelling students for passing off AI generated works as their own? What should be the threshold for deciding whether a work is infringing? While there are differences in the details, it is basically the same problem in each case: wrong decisions by an AI could cause real harm. Same pig, different makeup.
SCOTUS rejected government-mandated age verification in Ashcroft v. ACLU, but would they still reject it if it were technically voluntary but nevertheless unavoidable for liability reasons?
They're saying the domains were seized because "unauthorized exports of goods, technology or services to Iran, directly or indirectly from the United States or by a United States person are prohibited." Does that mean the domains were registered with U.S.-based registrars against export restrictions, or is the United States government claiming the authority to seize any non-country specific domain regardless of where it might be registered?
While speech-based seizures are always problematic, prohibitions against doing business with Iran probably don't violate the First Amendment. What worries me is that the U.S. government may be seizing domains registered outside the U.S. Imagine if other countries joined in and did that.
It's good to be the king.
I wonder how much damage this could do to websites operating exclusively within the United States but made available to European users. The impact of foreign law on U.S. service providers is a growing concern of mine, and I'm not at all confident in the U.S. government's ability to protect citizens and legal persons against bad foreign law in today's connected world. There have been efforts in that direction -- the SPEECH act was borne out of an attempt to enforce bad foreign libel law in the United States -- but it's not enough. We may need to do the same for foreign laws in general, especially when those laws are in conflict with US law or lack any local equivalent.
Any reading recommendations on the applicability of foreign law on U.S. soil where a company or legal entity lacks a physical nexus outside the United States? I'm looking to write a piece on this subject but need to read up and/or consult on the matter. Any help from a subject-matter expert would be very much appreciated.