{"id":705,"date":"2023-04-07T07:55:10","date_gmt":"2023-04-07T07:55:10","guid":{"rendered":"https:\/\/walterbot.ai\/?p=705"},"modified":"2025-02-24T17:41:37","modified_gmt":"2025-02-24T17:41:37","slug":"chatgpt-ban-why-i-believe-it-was-a-good-move","status":"publish","type":"post","link":"https:\/\/walterbot.ai\/it\/2023\/04\/07\/chatgpt-ban-why-i-believe-it-was-a-good-move\/","title":{"rendered":"ChatGPT ban: Why I believe it was a wise move"},"content":{"rendered":"<p style=\"text-align: right;\"><em><span style=\"color: #f2b933;\">**Per la versione Italiana del post, <a href=\"https:\/\/walterbot.ai\/it\/2023\/04\/07\/blocco-chatgpt-ecco-perche-penso-sia-giustificato\/\">clicca QUI<\/a><\/span><\/em><\/p>\n<p><span data-preserver-spaces=\"true\">Due to the recent action taken by the Italian Privacy Guarantor, ChatGPT has been (temporarily) blocked for all Italian users.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">I have read a lot of opinions on various platform and run a quick survey on my\u00a0<\/span><a class=\"editor-rtfLink\" href=\"https:\/\/www.instagram.com\/walterbot.ai\/\" target=\"_blank\" rel=\"noopener\"><span data-preserver-spaces=\"true\">followers on Instagram<\/span><\/a><span data-preserver-spaces=\"true\">\u00a0on what their idea was, providing two possible answers:<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">a) &#8220;Italy bureaucracy blocks everything as usual&#8221;<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">b) &#8220;First!&#8221; For something that will serve as a role model<\/span><\/p>\n<p id=\"tw-target-text\" class=\"tw-data-text tw-text-large tw-ta\" data-placeholder=\"Traduzione\"><img fetchpriority=\"high\" decoding=\"async\" class=\"size-medium wp-image-706 aligncenter\" style=\"font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif; white-space: normal;\" src=\"https:\/\/walterbot.ai\/wp-content\/uploads\/2023\/04\/Screenshot_20230404_170359_Instagram-300x221.jpg\" alt=\"\" width=\"300\" height=\"221\" srcset=\"https:\/\/walterbot.ai\/wp-content\/uploads\/2023\/04\/Screenshot_20230404_170359_Instagram-300x221.jpg 300w, https:\/\/walterbot.ai\/wp-content\/uploads\/2023\/04\/Screenshot_20230404_170359_Instagram-600x443.jpg 600w, https:\/\/walterbot.ai\/wp-content\/uploads\/2023\/04\/Screenshot_20230404_170359_Instagram-768x567.jpg 768w, https:\/\/walterbot.ai\/wp-content\/uploads\/2023\/04\/Screenshot_20230404_170359_Instagram-16x12.jpg 16w, https:\/\/walterbot.ai\/wp-content\/uploads\/2023\/04\/Screenshot_20230404_170359_Instagram.jpg 890w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p class=\"tw-data-text tw-text-large tw-ta\" data-placeholder=\"Traduzione\">As captured by the survey, the majority have perceived the block as something that depicts Italy as a &#8220;blocker&#8221; more than a &#8220;role model&#8221;.<\/p>\n<p data-placeholder=\"Traduzione\">I would have voted for the second. Below are my arguments and some additional clarifications on what&#8217;s happened.<\/p>\n<h2><\/h2>\n<h2>The Action:<\/h2>\n<p><span data-preserver-spaces=\"true\">First of all, let&#8217;s start with what was highlighted by the Privacy Guarantor.\u00a0<\/span><a class=\"editor-rtfLink\" href=\"https:\/\/garanteprivacy.it\/web\/guest\/home\/docweb\/-\/docweb-display\/docweb\/9870832\" target=\"_blank\" rel=\"noopener\"><span data-preserver-spaces=\"true\">The Original report can be found HERE<\/span><\/a><span data-preserver-spaces=\"true\">. Below is a translation of the four reasons that brought the guarantor to take action:<\/span><\/p>\n<blockquote>\n<p id=\"tw-target-text\" class=\"tw-data-text tw-text-large tw-ta\" dir=\"ltr\" data-placeholder=\"Traduzione\"><span class=\"Y2IQFc\" lang=\"en\" style=\"color: #0099e5;\">DETECTED, from a check carried out in this regard, that no information is provided to users, nor to interested parties whose data has been collected by OpenAI, L.L.C. and processed through the ChatGPT service; <\/span><\/p>\n<p class=\"tw-data-text tw-text-large tw-ta\" dir=\"ltr\" data-placeholder=\"Traduzione\"><span class=\"Y2IQFc\" lang=\"en\" style=\"color: #0099e5;\">NOTING the absence of an appropriate legal basis in relation to the collection of personal data and their processing for the purpose of training the algorithms underlying the functioning of ChatGPT; <\/span><\/p>\n<p class=\"tw-data-text tw-text-large tw-ta\" dir=\"ltr\" data-placeholder=\"Traduzione\"><span class=\"Y2IQFc\" lang=\"en\" style=\"color: #0099e5;\">NOTING that the processing of personal data of the interested parties is inaccurate as the information provided by ChatGPT does not always correspond to the real data; <\/span><\/p>\n<p class=\"tw-data-text tw-text-large tw-ta\" dir=\"ltr\" data-placeholder=\"Traduzione\"><span class=\"Y2IQFc\" lang=\"en\" style=\"color: #0099e5;\">DETECTED, moreover, the absence of any verification of the age of users in relation to the ChatGPT service which, according to the terms published by OpenAI L.L.C., is reserved for individuals who are at least 13 years old;<\/span><\/p>\n<\/blockquote>\n<p dir=\"ltr\" data-placeholder=\"Traduzione\">Now, I found some of them challenging to understand. An example is the one related to the User&#8217;s age. While I&#8217;m in favor of responsible use, I understand the concerns of whom highlights a lack of consistency compared to other web services, where platforms are fully accessible through a simple click on a button saying, &#8220;I confirm I am 18+ years old&#8221;.<\/p>\n<p dir=\"ltr\" data-placeholder=\"Traduzione\">On the other side, I think one bullet on the list is worth the action. I&#8217;m referring to the first bullet related to the information related to users and interested parties whose data has been collected by OpenAI.\u00a0Before diving into why I believe this aspect is enough to motivate the action taken by the Privacy Guarantor, I would like to share here also the request that the Guarantor made to OpenAI:<\/p>\n<blockquote>\n<p id=\"tw-target-text\" class=\"tw-data-text tw-text-large tw-ta\" dir=\"ltr\" data-placeholder=\"Traduzione\"><span class=\"Y2IQFc\" lang=\"en\" style=\"color: #0099e5;\">a) pursuant to art. 58, par. 2, lit. f), of the Regulation, urgently establishes, against OpenAI L.L.C., a US company that develops and manages ChatGPT, as owner of the processing of personal data carried out through this application,<strong> the measure of the temporary limitation of the processing of personal data of data subjects established in the Italian territory<\/strong>; <\/span><\/p>\n<p class=\"tw-data-text tw-text-large tw-ta\" dir=\"ltr\" data-placeholder=\"Traduzione\"><span class=\"Y2IQFc\" lang=\"en\" style=\"color: #0099e5;\">b) the aforementioned limitation has immediate effect from the date of receipt of this provision, subject to any other determination following the outcome of the definition of the investigation started on the case.<\/span><\/p>\n<\/blockquote>\n<p data-placeholder=\"Traduzione\">As highlighted, the request was specifically on limiting the processing of personal data belonging to subjects and explain how user&#8217;s data are being used. From my perspective, this is a different request to block or cancel the service for Italian users.<\/p>\n<p data-placeholder=\"Traduzione\">So, why do I believe that this request is reasonable? Because there is a legal precedent that involves ChatGPT, dated March the 20th 2023.<\/p>\n<h2><\/h2>\n<h2>The Legal Precedent:<\/h2>\n<p><span data-preserver-spaces=\"true\">On March 20th, some users of ChatGPT got provided information belonging to other users in their chat. Those information included Names, Last Names, Email addresses, Payment addresses, and the last four digits of the payment method premium users used to subscribe to the service.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">OpenAI has promptly identified and fixed the bug and publicly acknowledged the Privacy issue it might have caused.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">This story comes directly from the OpenAI website.\u00a0<\/span><a class=\"editor-rtfLink\" href=\"https:\/\/openai.com\/blog\/march-20-chatgpt-outage\" target=\"_blank\" rel=\"noopener\"><span data-preserver-spaces=\"true\">You can read it HERE<\/span><\/a><span data-preserver-spaces=\"true\">.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">I genuinely believe in good faith for what happened, and I consider OpenAI&#8217;s willingness to inform the users through their website a sign of a responsible approach.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">Despite this episode, the details about how the model was (is) trained and what information is being collected from interactions with users through the Chat service are still not clear. In the\u00a0<\/span><a class=\"editor-rtfLink\" href=\"https:\/\/cdn.openai.com\/papers\/gpt-4.pdf\" target=\"_blank\" rel=\"noopener\"><span data-preserver-spaces=\"true\">GPT technical report<\/span><\/a><span data-preserver-spaces=\"true\">, one piece of information I found helpful is the following:<\/span><\/p>\n<blockquote>\n<p style=\"color: #0099e5;\" data-placeholder=\"Traduzione\">GPT-4 generally lacks knowledge of events that have occurred after the vast majority of its pre-training<br \/>\ndata cuts off in September 2021, and does not learn from its experience.<\/p>\n<\/blockquote>\n<p data-placeholder=\"Traduzione\">However, I wasn&#8217;t able to capture additional details on data collection or usage.<\/p>\n<p>&nbsp;<\/p>\n<h2>Need for transparency:<\/h2>\n<p>On April 3rd 2023, The Economist Korea <a href=\"https:\/\/economist.co.kr\/article\/view\/ecn202303300057?s=31\" target=\"_blank\" rel=\"noopener\">reported<\/a> three separate examples of Samsung employees unintentionally leaking sensitive information to ChatGPT. In one case, an employee pasted confidential source code into the chat to check for errors. Another employee shared code with ChatGPT and &#8220;requested code optimization.&#8221; A third, shared a recording of a meeting to convert into notes for a presentation. As stated by <a href=\"https:\/\/mashable.com\/article\/samsung-chatgpt-leak-details\" target=\"_blank\" rel=\"noopener\">the source of this news<\/a>, &#8221; that information is now out in the wild for ChatGPT to feed on&#8221;.<\/p>\n<p>This is another story that highlights the need to get transparency on what data are being collected, how they are being used and leave control of personal information back to the owner.<\/p>\n<p>&nbsp;<\/p>\n<h2>My thoughts:<\/h2>\n<p><span data-preserver-spaces=\"true\">As an AI engineer, I perfectly know that a bug is a bug, and some of them are difficult to capture in advance despite the best engineering efforts. I don&#8217;t blame anybody and assume good faith when things like this happen.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">Using this as a premise, after reading the story published on their website, I asked myself a few questions:<\/span><\/p>\n<ol>\n<li><span data-preserver-spaces=\"true\">They identified the information leakage because it included the names and last names of premium users. Could they capture a leakage of other types of information that wouldn&#8217;t contain any names or direct references? For example, If I would ask the AI for information related to a topic that is keen for me, and that part of the exchange (including questions and answers) appears randomly in someone else chat, would they still be able to identify the source of the leak?<\/span><\/li>\n<li><span data-preserver-spaces=\"true\">What if the leaked information belonged to my company (If I had one)?<\/span><\/li>\n<li><span data-preserver-spaces=\"true\">Among the leaked information, there were payment addresses. Usually, those correspond to physical buildings\/houses. What would happen if that information were mine?<\/span><\/li>\n<li><span data-preserver-spaces=\"true\">What would happen if more detailed information leaked again for some other bug not yet identified?<\/span><\/li>\n<\/ol>\n<p><span data-preserver-spaces=\"true\">These questions made me think more about the role of Privacy in the era of digital identities.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">Back to the Privacy Guarantor, they asked to have transparency on how the information belonging to users (for example, text from the chat sessions) was processed and stored. This is\u00a0<\/span><a class=\"editor-rtfLink\" href=\"https:\/\/gdpr-info.eu\/art-5-gdpr\/\" target=\"_blank\" rel=\"noopener\"><span data-preserver-spaces=\"true\">captured by Art. 5 of GDPR<\/span><\/a><span data-preserver-spaces=\"true\">, which -in the first three bullets- states:<\/span><\/p>\n<blockquote>\n<p id=\"tw-target-text\" class=\"tw-data-text tw-text-large tw-ta\" dir=\"ltr\" data-placeholder=\"Traduzione\"><span class=\"Y2IQFc\" lang=\"en\" style=\"color: #0099e5;\">Personal data are: &#x200d; <\/span><\/p>\n<p class=\"tw-data-text tw-text-large tw-ta\" dir=\"ltr\" data-placeholder=\"Traduzione\"><span class=\"Y2IQFc\" lang=\"en\" style=\"color: #0099e5;\">a) processed in a lawful, correct and transparent manner in relation to the data subject (&#8220;lawfulness, correctness and transparency&#8221;); <\/span><\/p>\n<p class=\"tw-data-text tw-text-large tw-ta\" dir=\"ltr\" data-placeholder=\"Traduzione\"><span class=\"Y2IQFc\" lang=\"en\" style=\"color: #0099e5;\">b) collected for specified, explicit and legitimate purposes, and not further processed in a way that is incompatible with those purposes; further processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is not, in accordance with Article 89(1), considered to be incompatible with the initial purposes (&#8220;purpose limitation&#8221;); <\/span><\/p>\n<p class=\"tw-data-text tw-text-large tw-ta\" dir=\"ltr\" data-placeholder=\"Traduzione\"><span class=\"Y2IQFc\" lang=\"en\" style=\"color: #0099e5;\">c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (&#8220;data minimisation&#8221;);<\/span><\/p>\n<\/blockquote>\n<p dir=\"ltr\" data-placeholder=\"Traduzione\">These bullets are extremely important to understand what was stated in the report of the Privacy Guarantor.<br \/>\nRegardless of any definition of the specific duty of the Privacy Guarantor, I believe that it also plays a role in PREVENTING things from happening. Doing prevention means that the institution should be able to anticipate threats while they only carry a risk before they turn into something that can cause damage. Ideally, any intervention should be impeccable, but using common sense, it&#8217;s fair to assume that good-faith mistakes- might occur in some cases. In the prevention phases, the only acceptable mistakes are related to false positives over false negatives: better to play the fire alarm when there is smoke around than miss out on playing it when half of the house is already burned!<br \/>\nThis is why I consider the intervention of the Privacy Guarantor justified and something that should be taken as a reference or role model in terms of sensitivity used to capture the hypothetical risk.<\/p>\n<h2><\/h2>\n<h2>The (unexpected) Key-aspect:<\/h2>\n<p><span data-preserver-spaces=\"true\">At this point, it should be clear that I see the whole situation as a &#8220;business-as-usual&#8221; practice whit no faults or bad willingness from any of the parties. I&#8217;m still unable to fully understand why 61% of the people who took my Instagram survey think this intervention is negative.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">By consulting other sources like\u00a0<\/span><a class=\"editor-rtfLink\" href=\"https:\/\/community.openai.com\/t\/chatgpt-disabled-for-users-in-italy\/133236\" target=\"_blank\" rel=\"noopener\"><span data-preserver-spaces=\"true\">the forum on ChatGPT website<\/span><\/a><span data-preserver-spaces=\"true\">,\u00a0<\/span><a class=\"editor-rtfLink\" href=\"https:\/\/www.repubblica.it\/tecnologia\/2023\/04\/03\/news\/chatgpt_italia_blocco_openai_pietro_schirano-394767424\/\" target=\"_blank\" rel=\"noopener\"><span data-preserver-spaces=\"true\">Article from press<\/span><\/a><span data-preserver-spaces=\"true\">,\u00a0<\/span><a class=\"editor-rtfLink\" href=\"https:\/\/www.linkedin.com\/news\/story\/why-has-italy-banned-chatgpt-6221954\/\" target=\"_blank\" rel=\"noopener\"><span data-preserver-spaces=\"true\">social media<\/span><\/a><span data-preserver-spaces=\"true\">, one major objection is that such interventions are not fostering innovation in Italy. Laws and regulations are already part of any design process for new products. Whether we talk about cars, clothes, or orange juice, each market segment needs to comply with applicable regulations and no difference should be made for AI.<\/span><\/p>\n<p><span data-preserver-spaces=\"true\">AI is such a powerful technology, and I can see the benefits of its adoption. Still, at the same time, I recognize how delicate and crucial is the Data component, hence the need for sensitivity in identifying potential risks.<\/span><\/p>\n<p>This situation led me to question the level of priority that end-users might have on their own privacy. How keen on protecting its own Privacy is the average user? What is the level of awareness about the possible risks?<\/p>\n<p>In other words, my hypothesis is that the recent action taken by the Italian Privacy Guarantor are considered negative or an obstacle to innovation, not because people have blind faith in technology, but because the give different (less) importance to Privacy related matters.\u00a0This aspect is what concerns me the most because, <a href=\"https:\/\/www.youtube.com\/watch?v=6JtJU4HNQYc\" target=\"_blank\" rel=\"noopener\">as I shared during my TED-Talk,<\/a> I think that a successful and responsible adoption of AI, depends on who builds applications as much as on end-users.<\/p>\n<p>Moving forward I would expect more and more interactions happening between the Technology world and the Legal one, because proper innovation can only happen when the two goes hand-in-hand. Nonetheless, I believe this episode is generating a healthy debate around Privacy that will (hopefully) increase awareness and help structure the route to accelerate innovation in the future.<\/p>\n<h2><\/h2>\n<h2>Conclusions summary:<\/h2>\n<ul>\n<li><span data-preserver-spaces=\"true\">I believe that the action taken by the Italian Privacy Guarantor is positive and demonstrates the right level of sensitivity required by the matters.<\/span><\/li>\n<li><span data-preserver-spaces=\"true\">As\u00a0<\/span><a class=\"editor-rtfLink\" href=\"https:\/\/openai.com\/blog\/march-20-chatgpt-outage\" target=\"_blank\" rel=\"noopener\"><span data-preserver-spaces=\"true\">reported by OpenAI itself<\/span><\/a><span data-preserver-spaces=\"true\">, there is a legal-precedent involving &#8220;data outage&#8221; on ChatGPT, sharing names, last names, email addresses, and physical addresses of some users into chat sessions with different users.<\/span><\/li>\n<li><span data-preserver-spaces=\"true\">Outcome: request from the Guarantor was to stop the processing of user&#8217;s data. It&#8217;s still unclear to me how\/why this request translated into forbidding the service.<\/span><\/li>\n<li><span data-preserver-spaces=\"true\">Transparency: being able to explain how and why information are being collected by a tool, is mandatory under GDPR. Same lack of transparency led to the Samsung leak, <a href=\"https:\/\/mashable.com\/article\/samsung-chatgpt-leak-details\" target=\"_blank\" rel=\"noopener\">recently reported<\/a>.<\/span><\/li>\n<li><span data-preserver-spaces=\"true\">Innovation: building a product itself is not enough. Every product getting to market needs to comply with regulations in place that apply to the specific category (GDPR in this case). No exception was done here.<\/span><\/li>\n<li><span data-preserver-spaces=\"true\">Prevention: when preventing, false-positives are better than false-negative. False alarms are better than rushes to solutions when it&#8217;s too late. I expect some prevention activity from the Privacy Guarantor role.<\/span><\/li>\n<li><span data-preserver-spaces=\"true\">Eealthy experience: This episode is generating a healthy debate around privacy that can benefits non-experts and increase awareness among end-users.<\/span><\/li>\n<\/ul>\n<h3 style=\"text-align: center;\"><\/h3>","protected":false},"excerpt":{"rendered":"<p>**Per la versione Italiana del post, clicca QUI Due to the recent action taken by the Italian Privacy Guarantor, ChatGPT&#8230;<\/p>\n<p><a class=\"read-more\" href=\"https:\/\/walterbot.ai\/it\/2023\/04\/07\/chatgpt-ban-why-i-believe-it-was-a-good-move\/\">Read More<\/a><\/p>","protected":false},"author":1,"featured_media":721,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[44],"tags":[],"class_list":["post-705","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-technology"],"_links":{"self":[{"href":"https:\/\/walterbot.ai\/it\/wp-json\/wp\/v2\/posts\/705","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/walterbot.ai\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/walterbot.ai\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/walterbot.ai\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/walterbot.ai\/it\/wp-json\/wp\/v2\/comments?post=705"}],"version-history":[{"count":21,"href":"https:\/\/walterbot.ai\/it\/wp-json\/wp\/v2\/posts\/705\/revisions"}],"predecessor-version":[{"id":739,"href":"https:\/\/walterbot.ai\/it\/wp-json\/wp\/v2\/posts\/705\/revisions\/739"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/walterbot.ai\/it\/wp-json\/wp\/v2\/media\/721"}],"wp:attachment":[{"href":"https:\/\/walterbot.ai\/it\/wp-json\/wp\/v2\/media?parent=705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/walterbot.ai\/it\/wp-json\/wp\/v2\/categories?post=705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/walterbot.ai\/it\/wp-json\/wp\/v2\/tags?post=705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}