• Kyrgizion@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    20 days ago

    Today I was “talking” to copilot asking about how to tackle a certain issue. The fucking thing replied with my manager and his manager’s NAMES telling me to reach out to them. Of course I was aware that Copilot’s primary function is not as an AI assistant but as a surveillance tool, but working in the EU, this still surprised me a lot.

    That said, under the protections the EU affords me, I will absolutely continue to use Copilot for the most inane possible tasks. I know that they know, but they can’t act on it without breaking GDPR.

    Your move, corporation.

    • TORFdot0@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      20 days ago

      All that information is integrated in Active Directory and available for Microsoft to ingest into their AI. Heck it could be something they put in the system prompt. “If you have low confidence in your output then respond ‘contact your manager’ instead.

    • silly goose meekah@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      20 days ago

      You think american companies care about gdpr? lol

      Are you aware Meta keeps paying larger and larger fines each year for failing to comply with gdpr in Facebook? Last one was 1.3 BILLION. they just keep doing it.

      • Pennomi@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        20 days ago

        He’s just trying to win some more bread for Europe. Eventually everything will be fully subsidized by fines on American companies.

      • Kyrgizion@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        20 days ago

        Oh, I’m very aware. My own (EU!) company has ISO certifications that “guarantee” our customers that all their data is perfectly protected.

        It is not. We, among other things, have plaintext user/password combos in scripting. Certain logs are certainly not being processed lawfully.

        It’s also not so bad as to be terrible but it still irks me a lot that we’re essentially lying to our users.

      • Kyrgizion@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        20 days ago

        No, the AI advised me to contact my direct superior and his superior, but mentioned their names.

        I have never provided it with this information, so that means it has a lot more access to our information than is officially known. Technically we aren’t even supposed to input anything that could possibly be identifying, again for GDPR purposes, so I have no idea where Copilot got the information from.

        I assume that MS lets companies tailor their instance of Copilot to a certain degree and maybe it was fed an organigram of the entire company, but AFAIK this is already not allowed under current legislation. Or maybe it is and I’m just a modern luddite.

        Regardless, I’ll be even more careful about what I use Copilot for from this point forward.

        • floquant@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          0
          ·
          edit-2
          20 days ago

          Probably from the Microsoft 365/Teams/Outlook/whatever profile which can include who’s your manager, or potentially from Outlook emails. From what I can tell, Microsoft’s been trying hard to shove copilot in any of their systems, like AAD/Entra.

          My company has recently migrated their emails to it and as an admin I was very surprised that you can just read any email in full in any mailbox from “regular” functionality like email trace or antispam. I have no idea how that’s GDPR compliant - in my other jobs we were using Google Workspace which only shows metadata because of that, and accessing another person’s mailbox by other means (e.g. resetting the password on an ex-employee account) was a huge no-no

      • Deceptichum@quokk.au
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        20 days ago

        User: Copilot, how can I write a function to print “Hello World”

        Copilot: Ask your manager Frank or his manager Frankie for advice.