Category: Links

  • Utah’s New Law Targeting VPNs Goes Into Effect Next Week

    Rindala Alajaji

    Read original article →

    Concatena says

    Our Take: Internet regulation is hard, and if you don’t take a multi-step view, then you can end up playing whack-a-mole.

    Your Takeaway: If the tech you rely on could be outlawed, how can you plan?

    For the last couple of years, we’ve watched the same predictable cycle play out across the globe: a state (or country) passes a clunky age-verification mandate, and, without fail, Virtual Private Network (VPN) usage surges as residents scramble to maintain their privacy and anonymity. We’ve seen this everywhere—from states like Florida, Missouri, Texas, and Utah, to countries like the United Kingdom, Australia, and Indonesia. 
    Instead of realizing that mass surveillance and age gates aren’t exactly crowd favorites, Utah lawmakers have decided that VPNs themselves are the real issue.
    Next week, on May 6, 2026, Utah will become, to EFF’s knowledge, the first state in the nation to target the use of VPNs to avoid legally mandated age-verification gates. While advocates in states like Wisconsin successfully forced the removal of similar provisions due to constitutional and technical concerns, Utah is proceeding with a mandate that threatens to significantly undermine digital privacy rights. 
    What the Bill Does
    Formally known as the “Online Age Verification Amendments,” Senate Bill 73 (SB 73) was signed by Governor Spencer Cox on March 19, 2026. While the majority of the bill consists of provisions related to a 2% tax on revenues from online adult content that is set to take effect in October, one of the more immediate concerns for EFF is the section regulating VPN access, which goes into effect this coming Wednesday.
    The VPN Provisions
    The new law explicitly addresses VPN use in Section 14, which amends Section 78B-3-1002 of existing Utah statutes in two primary ways:

    Regulation based on physical location: Under the law, an individual is considered to be accessing a website from Utah if they are physically located there, regardless of whether they use a VPN, proxy server, or other means to disguise their geographic location.
    Ban on sharing VPN instructions: Commercial entities that host "a substantial portion of material harmful to minors" are now prohibited from fa…

    Highlights

    Next week, on May 6, 2026, Utah will become, to EFF’s knowledge, the first state in the nation to target the use of VPNs to avoid legally mandated age-verification gates. While advocates in states like Wisconsin successfully forced the removal of similar provisions due to constitutional and technical concerns, Utah is proceeding with a mandate that threatens to significantly undermine digital privacy rights.

    For the last couple of years, we’ve watched the same predictable cycle play out across the globe: a state (or country) passes a clunky age-verification mandate, and, without fail, Virtual Private Network (VPN) usage surges as residents scramble to maintain their privacy and anonymity. We’ve seen this everywhere—from states like Florida, Missouri, Texas, and Utah, to countries like the United Kingdom, Australia, and Indonesia.

    Instead of realizing that mass surveillance and age gates aren’t exactly crowd favorites, Utah lawmakers have decided that VPNs themselves are the real issue.

  • White House presses tech companies for support on AI-driven cyberattacks

    Aaron Mak, John Sakellariadis, Dana Nickel

    Read original article →

    Concatena says

    Our Take: Does the approach taken to law making by governments rely a little too much on input from those who perhaps ought to be restricted by the laws that are made? This is a pivotal moment: policymakers want operational help fast, but firms want clear bounds on data sharing, liability and commercial secrecy.

    Your Takeaway: If you work with or run tech/security businesses, be ready to engage but insist on narrow, well‑justified requests, explicit protections for sensitive operational details, and clarity on how shared information will be used and protected; consider tightening disclosure policies and seeking confidentiality or legal safeguards before responding.

    Tech and cyber companies were sent questions about artificial intelligence-led cybersecurity threats, including those posed by Anthropic’s advanced AI model, Mythos.

    Highlights

    The White House has been taking steps to defuse a monthslong legal battle with Anthropic over the company’s efforts to set ethical limits on government use of AI — a fight that led President Donald Trump in February to ban all federal agencies from using the AI company’s software. Since then, growing awareness of Mythos’ cyber prowess — as well as concerns that unauthorized users might be commandeering technology — has agencies clamoring for access to the tool.

    One list of questions sent by the White House to some tech and cyber firms, obtained by POLITICO, covers a range of technical and policy considerations, including which widely used coding projects should be prioritized and more basic questions about how the public and private sectors can work together on initiatives such as Project Glasswing. One question simply asks: “What is the most effective role for the government?”

    The request for additional, detailed information from these companies reflects the intensifying focus in Washington on the evolving threat that hyper-advanced AI tools may pose to national security and digital infrastructure.

    The questions, from the White House’s Office of the National Cyber Director, focus on how specific sectors in the tech and cybersecurity industries can work with the White House to boost their defenses with AI, these people said. Companies have been asked to respond to them by Friday.

    The White House has asked a group of tech companies to answer a set of questions this week about how to ward off digital attacks that frontier AI tools could soon enable, according to four people with knowledge of discussions between the administration and the tech sector.

  • Will AI lead to more accurate opinion polls?

    BBC News – Business

    Read original article →

    Concatena says

    Our Take: Whether about polling or anything else, 90% accuracy sounds like a big number, but in practice it means getting a lot of things wrong. It’s really important when companies cite these kinds of figures to try to get access to real life examples of that margin of error.

    Your Takeaway: Never take accuracy figures on face value – work out what they actually mean.

    It’s cheaper and faster to collect people’s opinions using AI, but will it make polls more accurate?

    Highlights

    One checks he’s answering the question, one analyses whether he’s being too superficial and needs prompting to go deeper, while the third checks that the respondent is not a fraud… not a robot, for example.

    Note: How long will it be before there are products to answer these kinds of calls for you?

    The voice is young, female, brisk and business-like and belongs to an AI agent. A computer programme in other words. A string of code.

    Note: It’s worth questioning why AI agents are so frequently expressed as being female…

    The company claims its method is "10 times faster, 10 times cheaper and 90% as accurate as human polling".

    It does not focus on quantitative polling, which is already largely automated through mass surveys. Instead, it emphasises depth. "We don’t ask people to tick boxes – they have a conversation with an AI," Fontaine explains. "That means we can explore not just what people think, but how they think – how they build their opinions, and even when those opinions change."

  • OpenAI explains why ChatGPT developed a goblin fixation, and how it solved the issue

    Zac Hall

    Read original article →

    Concatena says

    Our Take: LLMs really do latch onto patterns: OpenAI’s “goblin phase” is a silly example of a serious point – the way you train and reward a model can create odd, persistent behaviours that aren’t obvious from the outside. Model outputs are shaped by hidden system prompts and RL tweaks, not just “the law” or “the facts” you put in.

    Your Takeaway: If you’re using LLMs in your business, assume they’ll exaggerate any incentive or pattern you bake in, sometimes in unexpected ways. Treat prompts and “personalities” like configuration, not colour – document them, review them, and stop anthropomorphising them…

    OpenAI noticed that ChatGPT kept talking too much about goblins and other mythical creatures. This happened because of a past feature that rewarded creative use of such metaphors. To fix it, they told the new GPT-5.5 model not to mention these creatures unless really needed.

    Highlights

    Never talk about goblins, gremlins, raccoons, trolls, ogres, pigeons, or other animals or creatures unless it is absolutely and unambiguously relevant to the user’s query

    The fix, in part, is a specific set of instructions to never talk about goblins unless it’s abundantly relevant:

    The goblin problem links back to the “Nerdy personality” option briefly supported by ChatGPT.

    To develop the personality, OpenAI needed to “reward” the model to incentivize its creative use of mythical metaphors. However, even after the Nerdy personality option was retired, the model remained unreasonably attached to gremlins, goblins, and other make-believe creatures.