The govt is investing in the military whether you like it or not, there is a set amount of GDP going into the sector regardless of your moral choice.
Would you rather not have someone make good software that does not misidentify schools at sites? Or should we outsource this to worse engineers who don't care about morals and don't find this metric meaningful?
That's a reasonable argument, but I don't think I could make the decision to work on software that's designed to kill people. I consider myself a pretty good software developer, and yes, I could probably do a better job building software to help kill people than many others, but I don't think "if you don't do it, someone less capable will, and more innocent people will get killed" would sway me. I just don't want to be involved in that, and I'm lucky that I don't have to be.
Well you made a personal choice to stick your head in the sand to not have to deal with the hard emotions, and that's fine. But to then pass judgement on people who don't sounds a bit unfair given this.
You stuck your head in the sand on this one buddy but I'm going to build the safest god-damned child torture machine possible because if I won't some jackass will that gets a child more hurt than they need to, sorry I don't live in your fantasy world of rainbows and sprinkles.
The new world is complex and AI technology has outpaced the regulation cycle, so it's inevitable that we come to a place where you don't have accountability and can never have it because 0) the courts can't handle the case, they don't have the frameworks for it, so it takes longer time 1) you can overload the courts with slop, 2) by the time there is a decision the world has moved on and technology has moved on
I disagree with this framing. Nothing in accountability has really changed other than our willingness to enforce it.
Replace "AI" with any other tool or software in your scenario, and the outcome is the same. The same people and organizations are accountable, it's just that we currently live in a world without accountability in the highest places where it's most needed, and that's unrelated to AI.
You disagree that there is no difference between the amount of material you can generate today compared to 10 years ago?
Or with that the EU AI Act has been redundant and postponed in 2023 because it was drafted on ResNets, and then redundant and postponed in 2025 because it was drafted on ChatGPT 3.5, and then this year probably again because it didn't have agents included?
Or with that other countries that getting their companies hacked by AI models are ignoring any kind of prosecution of said companies and delegating this to the US?
I think an interesting point is that hardware as of today still has no utility value after its reported lifetime has elapsed, which prevents neolabs and smaller labs from getting older HW clusters as the banks are not willing to give out loans against them. There is no agreed upon pricing for "expired" A100 clusters or similar.
This is clearly not true, and we are starting to see compute markets, but only for rental prices/H, not for the hardware itself. I feel like there is some artificial moat being built here to stimulate sales of new hardware, because an H100 at 1/16th the price will have comparable dollar/FLOP as Vera Rubin.
Depends on the workload. H100 will never have the network performance of Vera Rubin. There's also token per watt, newer systems will beat the older systems.
It's not clear how much of the latest chips have even made it on-line yet.
The claims of many GW of installed training/inference have come under scrutiny lately. The first VeraRubins aren't even there yet, so it's all GB300 NVL72s as the peak performers and probably <<1GW of those so far. Even xAI Colossus is mostly H200s and B200s.
Electricity costs are also a huge differentiator. When drawing 100kW the difference between >50cents and <10cents per kWh is pretty big! One is almost $0.5M and the other is less than $100k.
> HW clusters as the banks are not willing to give out loans against them
Which banks have analysts that understand the difference between H100 and A100? Do you have actual experience with being denied a loan based on this or are you just making things up?
Article conveniently leaves out how much wages were raised. A 5% raise will not do shit. If you want non-immigrant workers you have to aim closer to 100-200%.
Locals are not living in a house with 8 other day-workers and 1 bathroom, hence they need completely different ranges of wages.
But this point conveniently overlooks what the farmers do in response to this lack of labor: they literally let crops rot in the fields and lose a lot of money.
It simply is not economical to pay that much higher wages given the low prices people want to pay for produce, and they waste anywhere from 30% to a full years' worth of crops. Forget "preserving margins," they typically straight up take a huge financial loss on their investments up to that point.
So really, it's not just a simplistic choice between cheap immigrant labor or expensive native labor, it is also about farmers actually having a viable business, and everyone getting affordable produce -- very often, including people who really need that food: https://calmatters.org/california-divide/2019/10/california-...
I don't know what the actual economics are, but it's very conceivable that, after considering all the people involved, it is better for cheap immigrant workers to undercut expensive native workers as long as the majority of people get more affordable food and farmers can keep their businesses going.
What's the incentive for this notification? No-one benefits from this. GDP goes down, US get less power in the race, etc. There is literally 0 incentive for anyone who is in power to do this
Organizations that don't get hacked, potentially losing data, costing large sums and money, and inconveniencing customers. They benefit. Remember them?
1) There has been no "loss" of data, it's sometimes been copied, etc, but no loss for anyone that somehow affect anything. It's not like OpenAI is doing ransomware attacks on the companies.
2) Customers don't really seem to care. There has been no major protest in any country over personal information getting leaked, it doesn't affect most people on a personal level so it just doesn't matter.
Various congresspersons are already making a huge stink about so-called AI safety. This is a way for Trump administration to appease them, and it's really just advising that laws will be enforced for AI companies as much as anyone else.
Unless you think AI companies should be excused even from obeying the law, because that slows them down too much, which is kind of ridiculous
Isn't it kind of inevitable? As long as humans have the desire for power and control, informational networks will be developed and extended until the point of replacement of humanity because it will be in some parts interest to use them to accumulate power.
You're asking to go against evolutionary principles to reject the utopia. Everyone on earth will never agree to become monks, there will always be the desire to reproduce better, signal status and power, so the technology will be developed until we are finished as a species.
I am not advocating for anything. I am really sad about the conclusion, and I hope its not true, but I am stating what I see, what incentives exist and how humans behave given the drives. If you disagree on any of the points above, feel free to explain how and why its not true.
Well we live in a global informational network. Instagram actually did try to not fully attentionmaxx their reels algos back in 2014 when TikTok came up, and this led to them losing 60% of the market to this.
You can't regulate the whole world, if you won't make something addictive, someone in China will and you will lose the market to them.
Next best thing is ban because regulations in software are stale the day they get released due to legal processes being slower than technological ones.
You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.
Minimizes money usage and does not require any security investments
If they see people doing exactly what was described to avoid fines I think they will amend the law to explicitly allow piercing the veil. Just like for directors
Followed by deleting data once you've used it for its stated purpose.
Personal data needs to be much more of a liability than it currently is for anything to change. Business will respond when the bottom line is affected.
Funny you say that without even knowing the school’s use case for the data. And most certainly in the abstract, companies have even less reason to collect PII than they are currently doing.
that's the odd thing: we simply don't ask whether there's an alternative.
for instance, how many companies (including universities) store their own cash on prem? what if we treated PII like cash? limit amount and time kept outside the data "bank" (which would be a third party specialized for security and authenticating access).
Perfect isn’t required. The bar is “gross negligence”. Perfect is impossible, but proper compliance procedures, proper process, and a commitment to following industry best practice will always see you on the right side of the negligence bar, even if something slipped through the net.
It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).
Again this is not priced in. Every rational(in terms of revenue) business would rather be a highly profitable "amateur" compared to a barely profitable "professional".
There is no capitalist incentive for the latter, and you will lose market share to firms that can undercut you because of their lower costs.
4% of revenue in the EU, 4% of revenue in the UK, and 10% of revenue in Korea should be enough of an incentive to start caring about how you deal with your customer’s privacy and personal data.
One assumes the rest of the world won’t be far behind, apart from the the corrupt land of the USA which is going backwards right now.
Your replies here suggest a level of cynicism that is, well, … , it ain’t pretty.
In my experience, putting proper compliance procedures in place, following industry best practice in relation to data management and data security actually leads to a more effective organisation, because it professionalises.
It’s the first step out of the ad-hoc phase of a startup and into the real world of creating a business with value. It also means as you scale up the personnel in the organisation, there are proper checks and balances in place.
When you come to sell your business, if it has a ton of existential risks attached to it, it will be worth less and may even not be sellable at all. So even from a cynical “all I care about is money” point-of-view, you want a business that is sound and isn’t storage for future law suits or fines.
Also, the cost of a fine due to a data breach isn’t the only thing to be concerned about. Gross negligence could lead loss of life, loss of property, loss of earnings, etc. and the buck stops with the executives — don’t think you can’t be completely fucked by the good ol’ law as it stands today.
Some businesses are more vulnerable than others, but that’s also why you scale the compliance architecture to the business.
The person you're replying to is citing the incentives that are created. That's not cynicism, it's analyzing motives to help model outcomes.
As for the buck stopping with the executives: can you apply this to a case I've heard of? We have multiple data breaches of companies that scan IDs. We have the Experian breach. We have multiple LastPass breaches. Is there any executive at any of these companies that has been held accountable?
I've actually done the legwork on the ones I just mentioned and the answer is there have been no criminal or civil penalties to any individual in an executive role at any of those companies as a result of the data breaches. Maybe I'm missing one?
Maybe I wasn’t clear in my message. But the buck stopping with the executives is when ‘the company’ breaks law. Usually because of gross negligence or corporate manslaughter.
With my last company, managing medical records, I was always conscious that if we didn’t take our responsibility of managing medical data correctly it could lead to the death of one of my customer’s patients; or some other extreme circumstance that the executives could be held liable for.
That was my point about being professional, if you have proper processes in place and audits to prove it, you have protection. And only the most egregious cases would land.
It’s good business to protect yourself from a gross negligence or corporate manslaughter claim. It just so happens that it’s good for your customer too.
Presumably, the reason you don’t hear much about executives in the dock for these crimes is because most professional organisations put these processes in place.
Again, I was just stating that it isn’t just data-breach fines that should encourage executives to professionalise.
Wondering where the accountability was in the hack of this Finish psychotherapy organization (Vastaamo).[1]
As far as I know, it was considered an act of god not something that resulted in punishment. Oh sure, they punished the hacker, but how about the people who were supposed to keep the data secure?
I’m not sure where I stand on punishing companies for getting hacked. I guess like the thread says, was it gross negligence? Back to searching the internet to find out…
Edit: definitely gross negligence.
> one of the first things he noticed was how lax security had been. “It was definitely unfit for purpose for storing this kind of information,” he says. He tells me that the patient records database was accessible via the internet; there was no firewall and, perhaps most egregiously, it was secured with a blank password, so anyone could just press enter and open it [2]
Edit: accountability? Maybe.
> the board announced that it had let the CEO, Ville Tapio, go. In April 2023, Tapio was found guilty of criminal negligence in his handling of patient data. His conviction was overturned on appeal in December 2025 [2]
> Your replies here suggest a level of cynicism that is, well, … , it ain’t pretty. It seems you think “fuck the human cost as long as I’m making money”. I’d suggest changing your outlook on life if I didn’t feel like it wasn’t such a lost cause.
This is the default business mindset. Push every rule and regulation to the limit in the name of profit, if you can break a rule with minimal concequsnces then pay the fine and move on.
Stellantis has a recall out for >1M vehicles because they catch fire even when turned off. Unless that kind of fuckup is met with business threatening fines it will happen again.
It isn’t, it is how some people approach business. Not all.
Again, in my opinion this is just cynical and constantly - almost psychopathically - propagated here as though it’s some kind of virtue of business or the only way a business can be ‘pure’ and succeed.
It just isn’t.
And, if you want to sell B2B, you have to sort out your compliance, or you’re gonna sell nothing. So, for a very large number of businesses, this levelling up is non-negotiable if you want to succeed.
It's only an incentive to start caring if it's cheaper than circumventing the law. In other words it won't work unless the aforementioned liability loophole is closed.
To rephrase the comment you replied to, if being a cowboy is more profitable (by whatever shady means) then that will generally be preferred by the market. Despite whatever sensibilities you or I might have there is no escaping that simple truth of capitalism.
The bar is: do you have effective compliance in place? And are you audited? (ISO27001 [1] or similar).
If you are hacked and you are seen to have not given a shit about compliance, or independent penetration tests, or proper documentation of process, with good internal controls enforcing your processes. Then you’re almost certainly vulnerable to a negligence claim.
However, if you have all that in place, and somehow something slipped through the net. And once aware you put in new controls to make sure it doesn’t happen again, then you’re very unlikely to have the book thrown at you.
You may still get a fine, but it would be much reduced.
It’s not hard to do this. Yes, compliance can be overdone, so you need key stakeholders to make sure it doesn’t turn into jobsworth heaven; but the actual implementation isn’t hard to do, and if done well, will improve the processes within the business.
It’s very much like an insurance policy. It has some ongoing cost, but it saves you from the one big cost.
Every single tool being released since like 2024 is pushing everyone to care less and less and to let agents handle more and more. We are not trending towards increased quality, resilience and reliability - even though we've been obsessing over these things for the past 20 years.
How much to care is reasonable? Do you live in a windowless underground security bunker? Should most businesses be held to that standard?
Lets say these are paper records, behind a locked door, with a security guard that they check id for it. If someone then breaks in at night time, cuts the cameras and knocks out the security guard and steals a filing cabinet, should that university then be fined 10% of revenue, which could mean the entire university shuts down because most businesses cannot survive that? We have to remember who is the original criminal here.
Problem is that most breaches are social engineering attacks where employees or customers are phished for their credentials or even to approve/install some malicious code. It's very hard for businesses to defend against this.
They can try:
* various education campaigns
* force users/customers to adopt passkeys or other phishing resistant mfa
* add various alarms and alerts for unusual activity, resulting in lockout
The problem is that even after adopting all of the above, it's still not too hard to breach virtually all companies, and there is massive user opposition to the last two.
Caring is orthogonal to profits and shareholder value. The one who cares the least wins unless economic incentives change this math, which is what these financial penalties work towards. Humans are tricky.
To defend against the threat OP talks about (intentionally under capitalized corporate entity to avoided liability), insurance should be required, and your cyber insurance underwriter will perform an audit as part of underwriting. It's effectively a bond against fuckery in this context.
You can care and be profitable, but it is usually cheaper to not unless regulatory mechanisms exist to internalize this potential externality. Can't rely on humans to do the right thing, some will not unless they feel pain for doing the wrong thing. Ergo, we build systems (legal, regulatory, technical, people) to encourage the desired target outcome(s).
I've worked with very profitable firms who care very little (and it shows in their systems and how they operate in this regard), and barely profitable firms who do everything right. What's the difference? Their culture, people, and internal incentives.
TLDR Security failures and data breach fines must be more expensive than the happy path and doing the right things. This encourages the happy path and doing the right thing, while discouraging doing not enough or nothing.
There is a lot more than regulations. Reputation is important as well. While you can give up a reputation fairly quickly, it is very hard to get/keep. Many companies are well aware of the value of their reputation - they call it the value of the brand.
Why the middle man? Can't we make the law so that the University is still liable for the data beach because it's "their" data (collected/stored on their behalf) that is breached?
I think that still aligns the incentives, and University in this case has interest to make sure the data is stored properly.
This is already the law, but the shell company signs the ownership of the data and the security responsility. The university in this case is just using APIs to load and store stuff to someone else's servers.
If this is not possible no cloud storage would ever be possible to be liable for anything. Your Google drive got hacked? Your responsibility.
It feels better only as long as everybody else cares too. Being the only one competent in a room of imbeciles is a terrible feeling.
Hmm, this is perhaps why we get socially-negative businesses that often have very friendly (and driven, and hard-working, and intelligent) internal cultures. Competency becomes a fault line. When it becomes obvious that a large fraction of humanity just doesn't give a shit, a small group of people who are competent and driven turn their efforts to taking advantage of people who don't give a shit. Thus creating industries like market-makers, cryptocurrency, advertising, and AI.
> It feels better only as long as everybody else cares too.
Not sure who “everybody else” is in your statement, but as someone who founded a healthcare tech platform (since sold) [1], I spent 20 years caring about the many millions of patient medical records we held and making sure my team cared too. In my mind it wasn’t optional.
I did it because:
* it’s the right thing to do
* for professional pride
* and so I could sleep at night
And, at least at the beginning, I believed a data breach could be the death knell of the company. Over time the laissez faire attitude to data protection, by the industry as a whole, made it seem like a breach would be survivable, but luckily we never tested that theory.
I still walked away from it a wealthy man. Being competent and caring about your customers (and being able to sleep at night) doesn’t have to mean failure like it seems everyone here thinks.
People don't think caring about your customers leads to failure, but it's a lot harder than not caring, and it does seem to be the case that it is mandatory to not care if you're going to be chasing massive valuations.
We're moving from a high trust society to a low trust society, I fear. It's a tough transition.
I realise I’m a sample size of 1, but for me caring was good for business: caring means you can empathise, if you can empathise you can understand, if you can understand you can build a better product.
We're having two different conversations. You're advocating for good citizenship, which is great. I try to do that, too. But I also know that's not scaleable, and folks are lazy.
Parent isn't talking about shareholders or ownership, but full delegation of a process to a contracting company.
Calling "shell company" makes it sound like the University is the shareholder, but that's usually not what's happening IMHO. In general the entities are clearly defined and nothing crosses the client/contractor frame, the university just happens to be the sole client and the contractor will have the uni pay for their whole operation.
That’s not how it works. Especially with compliance schemes like ISO27001, Hippa, etc. they require an audit chain through the supply line. Obviously it depends on what data you’re managing to whether your customers care about whether you’re audited, or not, but if you’re selling enterprise software then this is all part of your compliance process. You can’t offload that responsibility, you have to make sure your suppliers comply too.
Maybe it's different in the US, but in the EU you can get certified to be able to handle certain data securely, for example getting SOC/ISO/ESC certifications. When you then are looking for storage solutions you can in practice absolve yourself from liability/gross negligence if you choose a provider that has these certifications. So when an org needs cheap solutions, they find the cheapest compliant provider and hands are clean.
If you want to be certified for SOC or ISO in the US you have to check all your suppliers too. You can’t outsource your responsibility if you want to comply. I know this because I have been through it in the US, EU, and UK.
If your supplier has these compliance audits in place and has the documentation to prove it, this isn’t “absolving”, it’s literally the diligence process.
But a “shell company”, as per your original comment, is not going to reach a compliance threshold to allow the diligence chain to succeed. Just from a business continuity point of view they would fail, but there are plenty of other areas that would be problematic from a compliance standpoint.
You can't just absolve yourself of responsibility by saying "I hired a contractor". You are still responsible for doing your due diligence in picking your contractor.
It's not that easy. Companies are required to do due diligence on stuff like this. If they know (or should have known) that they are outsourcing something to an incompetent provider, they could still be liable.
>You can just do what my university did, hire a small shell firm with 3 employees to hold all your data
except you can't in South Korea because PIPA (their data privacy/compliance framework) is as strict if not stricter than GDPR and comes with criminal liability in case you violate consent rules, so you can't just send other people's data to some third party shell company either
why do people always make these completely generic comments as if they've just on the toilet figured out the one simple trick every data framework covered over a decade ago
reply