Sekėjai

Ieškoti šiame dienoraštyje

2023 m. spalio 28 d., šeštadienis

Amazon Announces European Cloud: Cloud division AWS wants to reach highly regulated industries and authorities / data protection concerns remain.

 

"Amazon will soon be offering a purely European cloud. The company wants to use this to score points with authorities and heavily regulated industries. But there are doubts as to how "sovereign" such offers actually are.

 

The cloud division of the American company Amazon is building an independent cloud for Europe. Amazon Web Services (AWS) announced this on Wednesday. This cloud offering is only operated with data centers located in the European Union (EU) and is physically and logically separated from the existing AWS regions. Control and customer service should only be carried out by staff based in the EU. The offer starts in Germany. “In this way, we are meeting the increased requirements of highly regulated industries and sensitive government authorities,” says Max Peterson, who is responsible for the sovereign cloud at AWS, in an interview with the F.A.Z. This does not affect the performance of the cloud.

 

Peterson emphasizes that AWS of course doesn't access its customers' data anyway. But even if only the EU servers were used, the forwarding of so-called personal metadata, i.e. information about what data is stored, has not yet been ruled out. This is no longer the case with the sovereign cloud. In July, the EU legitimized the storage of personal data in the USA with a new adequacy decision after years of legal uncertainty. Companies with particularly confidential customer data are still cautious. Especially since it is unclear whether the EU Commission's decision will stand before the European Court of Justice.

 

Strict rules also apply to the German administration. To put it simply, the state wants to use the public cloud, but with a kind of customs border for data. The Federal Office for Information Security (BSI) plays the customs officer. In the future, the BSI will determine which data, programs and updates are allowed in this cloud. The authority looks favorably on AWS's announcement. “The construction of a European AWS cloud will make it significantly easier for many authorities and companies with high data security and data protection requirements to use AWS services,” BSI President Claudia Plattner was quoted as saying by Amazon. However, AWS is probably not yet in the certification process by the BSI.

 

Almost all of them offer the “sovereign cloud”.

 

Business with the public sector is considered an important growth area for cloud providers alongside high-security industries. AWS is therefore far from the only provider offering a “sovereign” cloud. Google is working with Thales in France and with Telekom subsidiary T-Systems in Germany to offer “sovereign cloud services”. The American software company Oracle also offers a “sovereign cloud” in the EU. Since the beginning of the year, Microsoft has been rolling out a cloud solution specifically tailored to the needs of governments and the public sector. This should be available everywhere by the end of this year. This involves so-called data boundaries, which are intended to guarantee that data does not leave a defined geographical area, such as the EU.

 

In Germany, however, Microsoft is taking a different approach and is cooperating with the SAP subsidiary Delos, which is developing its own cloud for the public sector. In order to ensure the independence required by the BSI, Europe's largest software company founded its own subsidiary called Delos Cloud based in Berlin in mid-2022. SAP works closely with Microsoft. Delos boss George Welz told the F.A.Z. in July, the company is currently building three data centers in Germany based on the Microsoft Azure cloud, and another is planned as a security reserve, according to him. It is also planned that the Bertelsmann subsidiary Arvato Systems will invest in Delos and operate the data centers. The project is new territory for everyone involved, but thanks to the good cooperation between politics, companies and the BSI, it is still going according to plan. The cloud should be available to everyone at the beginning of 2025. The exact amount of the investment is still difficult to quantify, according to Welz, in any case a three-digit million amount. SAP boss Christian Klein has already spoken of billions that German industry is investing in building a sovereign cloud.

 

“label fraud”

 

There is no fixed definition for the “sovereign cloud”; the interpretation is left to the providers. "Sovereignty is the absence of strong dependencies on third parties. AWS's sovereign cloud is a misnomer here," criticizes Frank Karlitschek, founder and head of Nextcloud, which describes itself as open source and decentralized alternative to large cloud companies. Data protection advocates are also skeptical. The problem of the “sovereign European cloud” from Microsoft, Google and now Amazon is a lack of transparency, criticizes Thilo Weichert when asked by the F.A.Z. Weichert was the data protection officer for the state of Schleswig-Holstein for many years and is a board member of the German Association for Data Protection. 

 

In principle, providers have the option of accessing clear data: "And so we have the problem that US authorities can legally access this data, for example via the Cloud Act or the Foreign Intelligence Surveillance Act."

 

These American laws require American companies to make data processed abroad available to the US security authorities upon request. These laws are “not carte blanche,” emphasizes Peterson from AWS. There are strict legal processes. In principle, AWS does not release any customer data on its own initiative and refers it to the company concerned. In no case has the company passed on customer data from abroad at the request of American law enforcement authorities.” [1]

 

1.  Amazon kündigt europäische Cloud an: Cloudsparte AWS will stark regulierte Industrien und Behörden erreichen / Datenschutzbedenken bleiben. Frankfurter Allgemeine Zeitung (online)Frankfurter Allgemeine Zeitung GmbH. Oct 25, 2023. Von Maximilian Sachse und Bernd Freytag

2023 m. spalio 27 d., penktadienis

Dirbtinio intelekto įstatymas: propaguokite dirbtinį intelektą, o ne jį reguliuokite

„Su „ES AI įstatymu“ Europos Sąjunga įsipareigojo sukurti vieną iš pirmųjų pasaulyje dirbtinio intelekto (AI) teisės aktų visuomenės labui. Bet ar tai išvis būtina? Mes tikime: Ne. Šis pranešimas yra atsakymas Svenja Hahn publikacijai, pasirodžiusiai 2023 m. spalio 10 d.

 

Planuojamas ES dirbtinio intelekto įstatymas įgauna vis daugiau formų, ir daugelis jį rengiančių žmonių skelbia jį, kaip gerą naujieną: jis turėtų būti pasaulinis modelis, leidžiantis sumažinti galimą dirbtinio intelekto riziką ir su juo susijusius pavojus, jo naudojimas pavojams užkerta kelią. Juo siekiama sustiprinti vartotojų pasitikėjimą dirbtiniu intelektu. Kartu tai neturėtų reikšti per didelio reguliavimo, kuris galėtų trukdyti naujovėms Europoje ir  neleisti dar labiau įtempti ir taip sunkiai besiverčiančias vidutines įmones. Kol kas tai abejotina.

 

Mūsų nuomone, ypač abejotinas yra iš pirmo žvilgsnio banalus svarstymas, kas iš tikrųjų turėtų būti reguliuojama horizontaliai aplink AI, kas dar nėra reglamentuota. Kur yra reguliavimo spraga, kurią ES tiki įžvelgianti, kurios bijo ir todėl įnirtingai nori ją panaikinti? Mes nematome šios spragos. Vietoj to matome, kad daugelyje pramonės šakų jau yra daug vertikalių nacionalinės ir tarptautinės kilmės reikalavimų, kurių gamintojai turi laikytis. Čia ypač gerai žinoma Mašinų direktyva ir Medicinos prietaisų reglamentas.

 

Jei būtų reguliavimo spragų, pirmiausia būtų svarbu jas aiškiai nustatyti, o tik tada konkrečiai jas pašalinti. Tačiau tai turėtų būti reguliuojama apskritai, t. y. vertikaliai susieta su konkrečia programa ar domenu, o ne sutelkiant dėmesį į konkrečią technologiją, pvz., AI. Mes matome AI, kaip vieną iš daugelio įrankių, kuriuos galima naudoti, kuriant ar naudojant produktą. Tai priemonė tikslui pasiekti, o ne blogio šaknis. Tai galite pamatyti, pavyzdžiui, masiniame stebėjime viešose erdvėse: AI gali būti naudojamas tam, o AI įstatymas gali tai uždrausti. Bet masinį sekimą galima įgyvendinti ir be AI – todėl svarbiau būtų reguliuoti ar uždrausti patį masinį sekimą, o ne įrankį, kurį būtų galima naudoti, bet nebūtina.

 

Mūsų nuomone, problemų kelia ir AI taikomųjų programų klasifikavimas, kaip numatyta AI įstatyme. Jis daugiausia dėmesio skiria draudžiamoms ir vadinamosioms didelės rizikos programoms. Su šia užduotimi matome daug atvirų klausimų. Tai prasideda tuo, kad net ir dalyvaujantiems ES veikėjams nėra aišku, kas iš tikrųjų yra AI. Yra trys skirtingi AI apibrėžimai, atsižvelgiant į tai, ar tyrinėjate Tarybą, Komisiją ar Parlamentą. Kai kuriais atvejais šie apibrėžimai siekia tiek toli, kad, griežtai tariant, visa statistinė programinė įranga būtų reguliuojama kaip AI programos, o tai yra techninė nesąmonė.

 

Panašios abejonės kyla, kai žiūrima į tai, kas turėtų būti laikoma didelės rizikos programa. Čia matome daug nereikšmingų dalykų. Pavyzdžiui, kas galėjo pagalvoti, kad dirbtinio intelekto palaikomas automatizuotas priėmimas ir testavimas universitetuose bus laikomas didele rizika? Dėl šios kartais abejotinos užduoties keliami reikalavimai, kurie šiuo metu yra per aukšti ir neleidžia naudoti dirbtinio intelekto daugelyje vietų, kur jis galėtų padėti ir dirbti efektyviau. Rizikos klasifikavimas taip pat nėra trivialus konkretiems naudojimo atvejams. Taikomasis AI tyrimo metu nustatė, kad 40 procentų ištirtų naudojimo atvejų klasifikacija buvo neaiški.

 

Klasifikacija taip pat kelia klausimą, kas iš tikrųjų turėtų sertifikuoti visas dirbtiniu intelektu pagrįstas „didelės rizikos sistemas“. Mums atrodo, kad, kaip ir dėl medicinos prietaisų reglamento, ES sukuria sau nereikalingą ir brangiai kainuojančią kliūtį, trukdančią diegti naujoves. Ir čia grįžtame prie pradžioje paminėtų vidutinio verslo: didelės įmonės gal dar susitvarkys su tokiomis išlaidomis, bet mažosios bus atgrasytos arba iš karto atsiliks. Bendrojo duomenų apsaugos reglamento (BDAR) įvedimas yra įspėjamasis to pavyzdys. 

 

Akivaizdu, kad visomis šiomis pastangomis Kinija ir Amerika tikrai paliks mus technologiškai užnugaryje (jei to dar nepadarė).

 

Paskutinis techninis punktas apie ponios Hahn straipsnį: ji paaiškino, kad AI įstatymas turėtų reglamentuoti programas, o ne pačią technologiją, nes pastaroji keičiasi per greitai. Tiesą sakant, šiuo metu tiek daug AI vyksta, kad AI įstatymas visą laiką atrodys pasenęs. Tai galima pastebėti taip, kaip „bendrosios paskirties AI“ – terminas, kurį sukūrė ES, bet kuriuo iš tikrųjų siekiama kiekvieno mašininio mokymosi proceso pagrindo – ir į pagrindinius modelius reikėtų atsižvelgti, atsižvelgiant į technologijas. Jau nekalbant apie tai, kad generacinės AI technologijos egzistuoja dešimtmečius ir tik dabar buvo plačiai naudojamos.

 

Taigi, ką reikia padaryti, kad būtų prasmingai išspręstos AI trukdančios ES galimybės? Čia turime atlikti aiškias užduotis: pirma, finansinė ir intelektinė parama, antra, švietimas ir, trečia, geriausios praktikos sklaida. Konkrečiai kalbant, tai reiškia: kurkime atmosferą, kuri į temą žiūrėtų, kaip į galimybę, o ne, kaip į priešą. Tai taip pat apima konkurencingą finansinę paramą dirbtinio intelekto technologijoms. Čia reikėtų prisiminti „Didžiųjų Europos AI modelių“ (LEAM:AI) iniciatyvą, kuria siekiama sukurti didelius, daug duomenų turinčius AI modelius. Idėja gera – pinigų jai nėra.

 

Jei pažvelgtumėte į ES subsidijas daugeliui kitų pramonės šakų, šie prioritetai turėtų suteikti peno apmąstymams. Geresnis švietimas visomis su skaitmenizacija susijusiomis temomis yra būtinas, kad mūsų visuomenė galėtų pasisakyti, dalyvauti veikloje ir padėti ją formuoti, nes dirbtinis intelektas yra čia ir mes visi turėsime išmokti su tuo susitvarkyti ir dirbti. Ir galiausiai – sektinų modelių kūrimas: AI nėra panacėja. Padarius apčiuopiamą dalyką, ką AI gali ir ko negali daryti konkrečiose pramonės šakose, sukuriamos tikroviškos idėjos ir veiksmų erdvė. Padėkime visi formuoti technologiją, o ne be reikalo blokuokime ją su daug biurokratijos.“ [1]

 

1. AI Act: KI fördern statt kaputtregulieren. Frankfurter Allgemeine Zeitung (online)Frankfurter Allgemeine Zeitung GmbH. Oct 25, 2023. Von Patrick Glauner und Marco Huber

AI Act: Promote AI Instead of Regulating it to Death

"With the "EU AI Act", the European Union is committed to creating one of the world's first legislations on artificial intelligence (AI) for the benefit of society. But is it even necessary? We believe: No. A reply of the Post by Svenja Hahn from October 10, 2023.

 

The planned EU AI Act is taking more and more shape, and many who are working on it are proclaiming it as good news: it is intended to serve as a global model to reduce the possible risks of AI and the dangers that can be associated with its use prevent. It is intended to strengthen trust in AI on the user side. At the same time, it should not represent over-regulation that could inhibit innovation in Europe and put even more strain on already struggling medium-sized businesses. So far, so questionable.

 

In our opinion, what is particularly questionable is the seemingly banal consideration at first glance as to what should actually be regulated horizontally around AI that is not already regulated. Where is the regulatory gap that the EU believes it sees, that it fears and therefore vehemently wants to close? We don't see this gap. Instead, we see that for numerous industries there are already a lot of vertical requirements of national and international origin that manufacturers must comply with. The Machinery Directive and the Medical Devices Regulation are particularly well-known here.

 

If there were regulatory gaps, it would be important to first clearly identify them and then specifically close them. But this should then be regulated in general, i.e. vertically related to a specific application or domain, and not with a focus on a specific technology such as AI. We see AI as one tool among many that can be used for product creation or use. It is a means to an end and not the root of evil. You can see this, for example, in mass surveillance in public spaces: AI can be used for this, and the AI Act could prohibit that. But mass surveillance can also be implemented without AI - so it would be more important to regulate or ban mass surveillance itself and not a tool that could be used but does not have to.

 

In our opinion, the classification of AI applications, as provided for in the AI Act, is also problematic. It focuses on banned and so-called high-risk applications. With this assignment we see many open questions. This starts with the fact that the definition of what AI actually is is not clear, even between the EU players involved. There are three different definitions of AI, depending on whether you research the Council, the Commission or the Parliament. In some cases, these definitions go so far that, strictly speaking, all statistical software would be regulated as AI applications, which is technical nonsense.

 

Similar doubts arise when one looks at what should be considered a high-risk application. We see a lot of trivial stuff here. For example, who would have thought that AI-supported automated admissions and testing at universities would be considered high risk? This sometimes questionable assignment results in requirements that are currently far too high and prevent the use of AI in many places, where it could provide relief and efficiency. Risk classification is also not trivial for specific use cases. Applied AI found in a study that the classification of 40 percent of the use cases examined was unclear.

 

The classification also raises the question of who should actually certify all the AI-based “high-risk systems”. It looks to us as if, as with the medical device regulation, the EU is creating an unnecessary and costly bottleneck for itself that is preventing innovation. And here we are back to the medium-sized businesses mentioned at the beginning: Large companies may still be able to cope with such expenses, but the small ones will be deterred or immediately left behind. The introduction of the General Data Protection Regulation (GDPR) is a warning example of this. 

 

It is obvious that with all this effort, China and America will certainly leave us technologically behind (if they have not already done so).

 

One final technical point about Ms. Hahn's article: She explained that the AI Act should regulate applications and not the technology itself, as the latter is changing too quickly. In fact, so much is currently happening around AI that the AI Act will permanently appear outdated. This could be observed in the way "General Purpose AI" - a term created by the EU but which actually aims at the core of every machine learning process - and foundation models should be taken into account in a technology-specific manner.  Not to mention that generative AI technologies have been around for decades and have only now found their way into widespread use.

 

So what needs to be done to meaningfully address the disruptive possibilities of AI on the EU side? For us, there are clear tasks to be completed here: These include, firstly, financial and intellectual support, secondly, education and thirdly, disseminating best practices. In concrete terms, this means: Let's create a climate that sees the topic as an opportunity and not as an enemy. This also includes competitive financial support for AI technologies. One should remember here the “Large European AI Models” (LEAM:AI) initiative to develop large, data-rich AI models. The idea is good - there is no money for it.

 

If you look at the EU subsidies for many other industries, these priorities should give you food for thought. Improved education on all topics related to digitization is necessary so that our society can have a say, participate in action and help shape it, because AI is here and we will all have to learn to deal with it and work with it. And finally, creating role models: AI is not a panacea. Making it tangible what AI can and cannot do in which industries creates realistic ideas and scope for action. Let's all help shape the technology instead of unnecessarily blocking it with a lot of bureaucracy." [1]

 

1. AI Act: KI fördern statt kaputtregulieren. Frankfurter Allgemeine Zeitung (online)Frankfurter Allgemeine Zeitung GmbH. Oct 25, 2023. Von Patrick Glauner und Marco Huber