| ▲ | MisterMunchkin 5 hours ago |
| How can you charge someone for making a threat when you only read the threat by spying on them? Surely that has to be thrown out in court? They didn’t actually send the threat to anyone, you just obtained it by spying. |
|
| ▲ | Aurornis 5 hours ago | parent | next [-] |
| > when you only read the threat by spying on them The AI companies have clauses in their user agreements saying they can review content flagged as harmful. It’s not legally spying. If you recall previous outrage about ChatGPT being used in cases of suicides or shootings, this is the result. Every time a crime was committed and the police found ChatGPT history about the crime, the media turned it into a frenzy. So the AI labs added safety filters to their consumer plans that detect threats of violence, escalate them to human review, and report to the police. Spying is not the right analogy because the information was given to the police by a third party which had a EULA saying they would do this. A more analogous situation would be someone reading another person’s diary and then turning it into the police department. There might be some limitation in the law that makes the evidence inadmissible because it was not intended to be shared with anyone, but that’s a separate decision. |
| |
| ▲ | ibejoeb 3 hours ago | parent | next [-] | | Not only that they can review flagged content, but they tend to have separate retention policies for flagged content. Anthropic's is this: "We retain inputs and outputs for up to 2 years and trust and safety classification scores for up to 7 years if your chat or session is flagged by our automated trust and safety systems as violating our Usage Policy." So don't run for office or anything like that. Someone, somewhere will have a contact that will get that. | |
| ▲ | anigbrowl 37 minutes ago | parent | prev | next [-] | | It kinda is, actually. If the LLM had responded with 'woah, are you serious? That sounds like a crime and I can't just ignore that, it's made clear to the customer that such statements are out of bounds even if they were meant hyperbolically or humorously. But if someone crosses the guardrails and the system silently reports them, that's very much spying. Obviously, it's hard to judge exactly what was appropriate there because we're being asked to extrapolate from a two word quote about the customer intending to "shoot up" the sheriff's office. Consider the following two statements, which express quite different levels of intentionality. I got a $200 ticket from a sheriff's deputy today for throwing away an apple core. I'm so mad. I'd like to shoot up their office! Those sheriff's deputies have exhausted my last reservoir of patience. I'm going to shoot up the department. They'll be sorry when they're sprawled all over the floor bleeding out from saucer-sized shotgun slug wounds. I can't wait to hear the screaming and crying of their miserable families!!" I'm guessing that the diary entry was a more casual expression similar to the first statement, or they police would have quoted more of the statement to emphasize the apparent severity of the risk but it's hard to say without reading the charging documents. | |
| ▲ | Forgeties79 5 hours ago | parent | prev | next [-] | | >Spying is not the right analogy because the information was given to the police by a third party which had a EULA saying they would do this. A more analogous situation would be someone reading another person’s diary and then turning it into the police department. This is spying with extra steps couched in corporate speak. | | |
| ▲ | Aurornis 4 hours ago | parent | next [-] | | I was responding to a question about the legal case. The police did not perform any spying. Frustrations about Anthropic’s EULA are a separate matter. | | |
| ▲ | fwn 4 hours ago | parent | next [-] | | Was it claimed that the police did any spying? Presumably, Anthropic did the spying and the reporting. You argued that it is not spying, since the spying may have been made sufficiently explicit in the ToS/EULA. This raises the question: Does announcing a spying operation mean that it is no longer spying? I've never heard that perspective before. | | |
| ▲ | mjr00 4 hours ago | parent | next [-] | | > Does announcing a spying operation mean that it is no longer spying? Well, kind of, yeah; the dictionary definition of spying requires secrecy and lack of consent. > to secretly collect and report information about the activities of another country or organization[0] The only real debate is whether or not having a clause tucked away in a EULA that few people read makes it a secret. If Anthropic had a big flashing red banner that said "FYI we automatically flag and review any conversations about illegal things!!" on the front page nobody would call it spying. [0] https://dictionary.cambridge.org/dictionary/english/spying | | |
| ▲ | schoen 4 hours ago | parent | next [-] | | I would call it spying in this sense at a minimum if individual people don't know whether their conversations were stored or disclosed in a way they don't want. For example, suppose someone said "we will monitor the activities of 10% of people". You don't know if you're in that 10% or not, but I would still want to call that spying. A less central case would be when you clearly do know about the activity but you can't quite see the details, like with behavioral ad targeting or something. It feels pretty normal to me to call that spying even if it's disclosed to everyone and certainly happens to everyone, but it's also a less central example of the concept. | | |
| ▲ | Aurornis 4 hours ago | parent [-] | | Anthropic could put a big flashing warning text at the top of every chat that says “We are spying on you and will report anything scary to the police!” and it would not make any difference in this case. You can call it anything you like, but only the legal definitions matter for the legal case. | | |
| ▲ | schoen 4 hours ago | parent [-] | | After working on several court cases about surveillance activities, I'm definitely aware that whether I call something spying or not has little relationship to whether courts will think it's legal. |
|
| |
| ▲ | Forgeties79 2 hours ago | parent | prev [-] | | > If Anthropic had a big flashing red banner that said "FYI we automatically flag and review any conversations about illegal things!!" on the front page nobody would call it spying. If you change the situation then yes you can in fact change our responses. The problem is you then are no longer talking about the original situation. It also bears mentioning that providing a dictionary link to “spying” is pretty patronizing/passive aggressive. On par with sending a basic Wikipedia page. You didn’t even bother to post the definition you want to apply. | | |
| ▲ | fwn an hour ago | parent [-] | | No one claimed any case would be "thrown out for spying." The legal definition of spying is also not particularly relevant to the argument in the initial comment. The initial comment instead questioned how someone could be accused of making a threat if they did not realize anyone would read their private content. You probably also can not insult someone with a statement you never expected anyone but you will ever read. |
|
| |
| ▲ | Aurornis 4 hours ago | parent | prev [-] | | > Presumably, Anthropic did the spying and the reporting. You don’t need to presume. Anthropic reported it. “Spying” as a legal concept has a definition that does not apply here. You could say they were “spying” in the sense that they read someone’s input, but that’s literally what they said they were going to do in the agreement when the person signed up. So I responded to the question about the case being thrown out for “spying” by trying to show that the word doesn’t apply in the legal sense. If you sign up for a service that says “Hey we’re going to monitor your chats and might report things to the authorities” and then they monitor your chats and report things to the authorities, you should not expect the case to be thrown out for “spying”. |
| |
| ▲ | 4 hours ago | parent | prev [-] | | [deleted] |
| |
| ▲ | drusepth 4 hours ago | parent | prev | next [-] | | Extra steps couched in corporate speak is often the defining line that defines whether something is technically legal or not. | | |
| ▲ | Forgeties79 3 hours ago | parent [-] | | I’m speaking from a functional/ethical framework to be clear. I’m just expressing frustration, not challenging the comment. Could’ve been clearer on my end there. |
| |
| ▲ | philipallstar 4 hours ago | parent | prev | next [-] | | > This is spying with extra steps couched in corporate speak. Calling something names doesn't invalidate it. It only invalidates what point you're trying to make. | |
| ▲ | lenerdenator 4 hours ago | parent | prev [-] | | Well, let's say that you have a regular customer at a bar. They get friendly and loose-lipped with the bartender over the span of months. Eventually they let slip that they plan on killing their spouse for a life insurance payout. At first the bartender thinks they're joking, but it becomes evident that there's an actual plan being acted upon and someone's life is very likely in imminent danger. Does the bartender have a responsibility to go to the police? | | |
| ▲ | Joker_vD 4 hours ago | parent [-] | | Depends on the country. In some places, there is no legal repercussions for not reporting this to the police; in some, it is an actual crime in itself. | | |
| ▲ | lenerdenator 3 hours ago | parent [-] | | In this case, let's assume the country is the United States, and the state is... oh, of course it is... the state is Florida. |
|
|
| |
| ▲ | asgf-qwr 4 hours ago | parent | prev [-] | | Many clankers deny data retention or spying on the user if you ask them. That should be completely illegal. Then, you can write anything in an EULA but it is not automatically legal either. |
|
|
| ▲ | akerl_ 5 hours ago | parent | prev | next [-] |
| This seems to be the statute: https://www.leg.state.fl.us/Statutes/index.cfm?App_mode=Disp... With the obvious IANAL, it doesn't seem to rely on the message be sent to the person being threatened. The specific segment is "in any manner in which it may be viewed by another person". This may be one of those cases where we get to find out how courts view SaaS platforms. |
| |
| ▲ | nemomarx 5 hours ago | parent | next [-] | | Interesting that it exempts telephone calls. Why don't we treat other messaging services like phone calls? | | | |
| ▲ | throw310822 5 hours ago | parent | prev [-] | | The subjective element of crime (i.e. doing it on purpose) is fundamental also in the US legal system. If the person wasn't aware that someone else might see their messages, it should be hard to claim that they committed the crime. According to Gemini, "Florida appellate courts have overturned juvenile convictions [based on this law] when the state could not prove the person subjectively intended for the record to be seen." | | |
|
|
| ▲ | theturtletalks 5 hours ago | parent | prev | next [-] |
| Exactly, can you threaten someone without them receiving the threat? If this is not thrown out, Minority Report will actually happen. |
|
| ▲ | anvuong 5 hours ago | parent | prev | next [-] |
| We are snowballing to Minority Report ... |
| |
| ▲ | boothby 5 hours ago | parent [-] | | If the AI recommends murder and you exhibit a pattern of following AI advice are you guilty of precrime |
|
|
| ▲ | notatoad 3 hours ago | parent | prev | next [-] |
| this is almost certainly what anthropic is hoping for here - a judgement that says there is no point in them continuing to monitor and report this behaviour |
|
| ▲ | dolebirchwood 4 hours ago | parent | prev | next [-] |
| > Surely that has to be thrown out in court? The prosecutors likely know this and expect it. But there's enough gray area here for them to make the argument, and it's hard to prove malicious prosecution, so they know they'll get away with it. It's just about sending a message to the public - they don't care whether a conviction sticks. Just politics. |
| |
| ▲ | ibejoeb 3 hours ago | parent [-] | | The prosecutors aren't on the hook, anyway. They have absolute immunity. The decision to charge is protected. The prosecutor would have to have done one of the few, enumerable things outside the scope of the role, like conducting an investigation without probable cause or hiding exculpatory evidence. |
|
|
| ▲ | order-matters 4 hours ago | parent | prev | next [-] |
| the argument to be made is that allowing anthropic to see it constitutes sending the threat. sandbox your ai. |
| |
| ▲ | jeremyjh 2 hours ago | parent | next [-] | | That is not what sandboxing solves. A good sandbox would inject credentials into provider API calls so that the model never sees credentials, but the provider is still going to see the transcript. Sandboxes do not require or imply that there is a local model. Sandboxes limit what the agent can access on the host machine as well as the network and public internet. | | |
| ▲ | order-matters an hour ago | parent [-] | | >Sandboxes limit what the agent can access on the host machine as well as the network and public internet. this is exactly what I meant. I am presuming the danger is AI reacting to personal notes that it reads on your computer, like a diary, and you should not allow the tools to have access to those documents. |
| |
| ▲ | sidsud 4 hours ago | parent | prev [-] | | how does sandbox help in this case when you use a provider like anthropic/openai? | | |
| ▲ | order-matters an hour ago | parent | next [-] | | Another way to interpret this is that they are legally presuming that you already have sandboxed their product and anything it sees or has access to is intentional. Any failure to understand what it can access or what it has permission to see from the user's end is presumably not their problem. Regardless of what the user specifically asks of the tool. | |
| ▲ | Dylan16807 4 hours ago | parent | prev [-] | | If you're still using a provider like this then you didn't sandbox the AI. You still need to follow the instruction. | | |
|
|
|
| ▲ | conductr an hour ago | parent | prev | next [-] |
| Cops will charge them to let the courts decide |
|
| ▲ | bilekas 5 hours ago | parent | prev | next [-] |
| It's not quite spying when you willingly hand over this information and agree to terms of service. You're data is not considered yours alone. |
| |
| ▲ | moffkalast 4 hours ago | parent [-] | | It still shocks me the number of people I know who freely let agents on devices that contain unencrypted private keys, freely dump internal data into cloud models and generally don't give a second thought about any of it being trained on, inevitably leaked one day in a db breach or read by providers. I find it's best to consider any data put into a cloud model the same as if it were posted publicly online, since that is the very possible eventual end result. Hopefully more of these stories push people towards local models :) |
|
|
| ▲ | slopmachine 5 hours ago | parent | prev | next [-] |
| It's legal to spy if the terms of service say so |
|
| ▲ | sajithdilshan 5 hours ago | parent | prev | next [-] |
| I was thinking the same. If the evidence was not obtained with a proper court order wouldn’t this result in a mistrial? |
| |
| ▲ | Joker_vD 4 hours ago | parent | next [-] | | If you overhear someone, in the privacy of their house, threatening to murder someone and go to the police, surely you don't expect this report being thrown out and you being yourself charged with the violation of someone's privacy instead? | |
| ▲ | danudey 5 hours ago | parent | prev [-] | | IIRC if the evidence wasn't lawfully gathered (which it sounds like it was, tbh) then it wouldn't be a mistrial, it would be thrown out and then the prosecution wouldn't have any evidence of any crime. |
|
|
| ▲ | m3kw9 4 hours ago | parent | prev | next [-] |
| what if it's just testing the AI to see how it responds |
|
| ▲ | sandworm101 5 hours ago | parent | prev [-] |
| A threat sent by mail is still a sent threat even if nobody ever opens the envelope to read it. The crime is in the sending. This woman used an online resources, one which involves transmitting everything across innumerable state lines. I am surprised she isn't up on federal charges. Note that the law doesn't forbid the writing of a threat. You have to send it to someone. Had she kept it in a book under her bed, she would not be in trouble. But she sent it to a website/service/LLM portal. >> It is unlawful for any person to send, post, or transmit, or procure the sending, posting, or transmission of, a writing or other record, including an electronic record, in any manner in which it may be viewed by another person |
| |
| ▲ | wlesieutre 5 hours ago | parent | next [-] | | If you draft an email threatening someone and delete it without sending have you committed a felony because someone at Google could be reading your drafts box, stored in a datacenter across state lines? | | |
| ▲ | thebeardisred 4 hours ago | parent | next [-] | | Honestly, I'm equally fascinated by the way email has changed. 30 years ago when you drafted an email but didn't send it, it was only on your local machine. There was no SMTP. 20 years ago, it might be a 50/50 shot as to whether you "transmitted" it to your "Drafts" folder if you were using IMAP instead of POP3 to read it. | | |
| ▲ | ryandrake 4 hours ago | parent [-] | | We really need a way to make it clear to users when, through the normal operation of software, they are "sending" data to a third party (usually the software developer) and when they are not. This is definitely not clear/knowable to regular users, and it's kind of hard to figure out even if you're a computer expert. Even software that "runs locally" now sends innumerable amounts of stuff back to the developer, and they don't always disclose it. This is a huge privacy problem that is only going to get worse. |
| |
| ▲ | sandworm101 5 hours ago | parent | prev [-] | | Sounds reasonable. Google's bots could pick that up easily and forward if for human review. FYI, the use of drafts folders to transmit messages has been used by terrorists. This is likely where CIA director David Petraeus got the idea when he needed a secure way to chat with his mistress. https://www.findlaw.com/legalblogs/technologist/gen-petraeus... | | |
| ▲ | Terr_ 4 hours ago | parent | next [-] | | Ah, a simpler and more innocent time of government scandals. I miss it. Now the messages are on White House stationery and they declare themselves above the law. | |
| ▲ | Dylan16807 4 hours ago | parent | prev | next [-] | | It sounds extremely unreasonable to me for "bots could pick it up" to transmute a private note into a felony threat. | |
| ▲ | stavros 3 hours ago | parent | prev [-] | | It "sounds reasonable" that the exact same action could be a crime or not, depending on how an engineer implemented a feature? |
|
| |
| ▲ | stickfigure 4 hours ago | parent | prev | next [-] | | What if she mailed it to herself? What if she put it in a locked box before shipping it to herself UPS, and she has the only key? What if instead of UPS, she hired a moving company to move the locked box? What if she wrote it electronically in diary.txt, but it was backed up to a cloud provider? -- I'm guessing there's some sort of "reasonable expectation of privacy" for certain activities. We're going to find out what Florida courts think about this new medium. | | |
| ▲ | mr_roboto 3 hours ago | parent [-] | | We'll only find out what the courts think when this happens to someone with a lot of money. It takes a real legal fight to push it high enough to become precedence. She'll be pushed to plea out. |
| |
| ▲ | weego 5 hours ago | parent | prev | next [-] | | Surely this is the wrong side of what "sending" here will be interpreted as? Saving is not sending ie passive vs active act. | | |
| ▲ | sandworm101 2 hours ago | parent [-] | | Everything you "save" on an online service gets "sent" to someone, be that a person or a computer, more often than not across state lines. |
| |
| ▲ | cortesoft 4 hours ago | parent | prev | next [-] | | > in any manner in which it may be viewed by another person Does the person have to know (or at least believe) that it will be viewed by another person? She likely didn't think anyone would view it. Honestly, even as a career software developer I don't think it is unreasonable to think know would would see what she wrote to an AI. I assume most of what I write to an AI is not viewed by any other human, based simply on the quantity of messages sent back and forth to AIs, I would assume a vast majority are not read by another human. What if she had written this into google docs, and she kept a diary there? That also crosses state lines, and is transmitted to another location. | |
| ▲ | FlowingRiver 3 hours ago | parent | prev [-] | | I get were you are coming from but this all feels like it needs more context to make a better judgement. You can argue from technicalities but they would need to prove intent. |
|