No, it’s not an April Fool’s joke. OpenAI has begun geo-blocking access to its generative AI chatbot ChatGPT in Italy.
The move follows an order on Friday that local data protection authorities must stop processing Italians’ data for the ChatGPT service.
In a statement displayed online to users with Italian IP addresses attempting to access ChatGPT, OpenAI informed users that it had disabled access to Italian users at the “request” of the data protection authority. I wrote that I was “sorry” to notify you.known as I guarantee.
It also said it would issue refunds to all Italian users who purchased the ChatGPT Plus subscription service last month, and “temporarily suspend” subscription renewals so that users are not charged while the service is suspended. Also note that
At this point OpenAI seems to apply a simple geoblock. In other words, using a VPN to switch to a non-Italian IP address provides an easy workaround for the block. If the ChatGPT account was originally registered in Italy, it may become inaccessible and the user wishing to avoid blocking may need to create a new account using his non-Italian IP address.
OpenAI statement on users trying to access ChatGPT from Italian IP addresses (screengrab: Natasha Lomas/TechCrunch)
on Friday, I guarantee announced that it has opened an investigation into ChatGPT for alleged violations of the European Union’s General Data Protection Regulation (GDPR). It said it was concerned that OpenAI had illegally processed the Italians’ data.
OpenAI doesn’t seem to let anyone know that they found that online data and used it to train their technology, such as by scraping information from internet forums. We are also not completely open about the data we process. That’s clearly not the case with his GPT-4, the latest iteration of the model. Also, while the training data we used could have been public (in the sense that it was posted online), the GDPR still includes the principle of transparency, and it’s important to know who the users and people of the scraped data are. It suggests that both should be notified.
In yesterday’s statement, I guarantee It also flagged it as child safe, pointing out that there is no system in place to prevent minors from accessing the technology. For example, it points out the lack of age verification features to prevent inappropriate access.
Additionally, regulators have expressed concerns about the accuracy of the information provided by chatbots.
ChatGPT and other generative AI chatbots are known to sometimes generate false information about certain individuals. This is a flaw AI makers call “hallucinations.” This seems problematic in the EU, as the GDPR gives individuals a set of rights over their information, including the right to have erroneous information corrected. And it’s not currently clear if OpenAI has a system where users can ask the chatbot to stop lying about them.
The San Francisco-based company has not yet responded to our request for comment. guarantor investigation. However, an official statement to geoblocked users in Italy claims:
“we, I guarantee Our goal is to restore access as soon as possible,” it added.
Despite making positive comments towards the end of the statement, it is not clear how OpenAI will be able to address compliance issues raised by the United States. Guarantee – Given the wide range of GDPR concerns, it is presented as a starting point for deeper investigation.
Pan-EU regulations require data protection by design and default. In other words, privacy-centric processes and principles should be built into the systems that process people’s data from the beginning. aka the opposite approach to getting the data and asking for forgiveness later.
On the other hand, penalties for confirmed violations of the GDPR can be increased to 4% of the annual global turnover of data processors (or €20 million, whichever is greater).
Additionally, since OpenAI does not have a major facility in the EU, none of the block’s data protection authorities are authorized to regulate ChatGPT. This means that authorities in all other EU Member States can choose to intervene and investigate and impose fines for violations they find. (in relatively short order, as each only works with its own patch). As such, it’s not ready to play the forum shopping game that other tech giants have used to slow privacy enforcement in Europe, facing the highest levels of GDPR exposure.