Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Has anybody built a matrix of the lawful compliance transparency or policies or reporting across the various llm platforms?

Has anybody built a matrix of the lawful compliance transparency or policies or reporting across the various llm platforms?

Scheduled Pinned Locked Moved Uncategorized
14 Posts 3 Posters 4 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

    Has anybody built a matrix of the lawful compliance transparency or policies or reporting across the various llm platforms? I wonder how often they get requests, and for what kind of data

    sempf@infosec.exchangeS This user is from outside of this forum
    sempf@infosec.exchangeS This user is from outside of this forum
    sempf@infosec.exchange
    wrote last edited by
    #2

    @tychotithonus Is CRob on here? If there is one, he'd know. Lemme look.

    sempf@infosec.exchangeS 1 Reply Last reply
    0
    • sempf@infosec.exchangeS sempf@infosec.exchange

      @tychotithonus Is CRob on here? If there is one, he'd know. Lemme look.

      sempf@infosec.exchangeS This user is from outside of this forum
      sempf@infosec.exchangeS This user is from outside of this forum
      sempf@infosec.exchange
      wrote last edited by
      #3

      @tychotithonus He's at @SecurityCRob. Let's see if I can invoke him.

      securitycrob@infosec.exchangeS 1 Reply Last reply
      1
      0
      • R relay@relay.infosec.exchange shared this topic
      • sempf@infosec.exchangeS sempf@infosec.exchange

        @tychotithonus He's at @SecurityCRob. Let's see if I can invoke him.

        securitycrob@infosec.exchangeS This user is from outside of this forum
        securitycrob@infosec.exchangeS This user is from outside of this forum
        securitycrob@infosec.exchange
        wrote last edited by
        #4

        @Sempf @tychotithonus I always enjoy a nice chat with @Sempf !!

        sempf@infosec.exchangeS 2 Replies Last reply
        0
        • securitycrob@infosec.exchangeS securitycrob@infosec.exchange

          @Sempf @tychotithonus I always enjoy a nice chat with @Sempf !!

          sempf@infosec.exchangeS This user is from outside of this forum
          sempf@infosec.exchangeS This user is from outside of this forum
          sempf@infosec.exchange
          wrote last edited by
          #5

          @SecurityCRob @tychotithonus What do you think about Royce's original question? I know it's a little out of your realm, but I bet you've looked at it!

          Royce Williams (@tychotithonus@infosec.exchange)

          Has anybody built a matrix of the lawful compliance transparency or policies or reporting across the various LLM platforms? I wonder how often they get requests, and for what kind of data

          favicon

          Infosec Exchange (infosec.exchange)

          securitycrob@infosec.exchangeS 2 Replies Last reply
          0
          • securitycrob@infosec.exchangeS securitycrob@infosec.exchange

            @Sempf @tychotithonus I always enjoy a nice chat with @Sempf !!

            sempf@infosec.exchangeS This user is from outside of this forum
            sempf@infosec.exchangeS This user is from outside of this forum
            sempf@infosec.exchange
            wrote last edited by
            #6

            @SecurityCRob @tychotithonus And hi! How are you doing?

            securitycrob@infosec.exchangeS 1 Reply Last reply
            0
            • sempf@infosec.exchangeS sempf@infosec.exchange

              @SecurityCRob @tychotithonus What do you think about Royce's original question? I know it's a little out of your realm, but I bet you've looked at it!

              Royce Williams (@tychotithonus@infosec.exchange)

              Has anybody built a matrix of the lawful compliance transparency or policies or reporting across the various LLM platforms? I wonder how often they get requests, and for what kind of data

              favicon

              Infosec Exchange (infosec.exchange)

              securitycrob@infosec.exchangeS This user is from outside of this forum
              securitycrob@infosec.exchangeS This user is from outside of this forum
              securitycrob@infosec.exchange
              wrote last edited by
              #7

              @Sempf @tychotithonus I have not personally seen that, but AI-things change every 5 minutes. Have been more focused trying to help maintainers with the massive uptick of ai-slop reporting, it let me ask around tomorrow and see if anyone in the community is aware of such a thing.

              1 Reply Last reply
              0
              • sempf@infosec.exchangeS sempf@infosec.exchange

                @SecurityCRob @tychotithonus What do you think about Royce's original question? I know it's a little out of your realm, but I bet you've looked at it!

                Royce Williams (@tychotithonus@infosec.exchange)

                Has anybody built a matrix of the lawful compliance transparency or policies or reporting across the various LLM platforms? I wonder how often they get requests, and for what kind of data

                favicon

                Infosec Exchange (infosec.exchange)

                securitycrob@infosec.exchangeS This user is from outside of this forum
                securitycrob@infosec.exchangeS This user is from outside of this forum
                securitycrob@infosec.exchange
                wrote last edited by
                #8

                @Sempf @tychotithonus the frontier model companies aren’t as engaged with the ecosystem like the hyperscalers, but I could ask my pals at the big3 and extrapolate from there.

                sempf@infosec.exchangeS 1 Reply Last reply
                0
                • securitycrob@infosec.exchangeS securitycrob@infosec.exchange

                  @Sempf @tychotithonus the frontier model companies aren’t as engaged with the ecosystem like the hyperscalers, but I could ask my pals at the big3 and extrapolate from there.

                  sempf@infosec.exchangeS This user is from outside of this forum
                  sempf@infosec.exchangeS This user is from outside of this forum
                  sempf@infosec.exchange
                  wrote last edited by
                  #9

                  @SecurityCRob @tychotithonus If it comes up in conversation, that would be awesome. Don't, of course, put yourself out. I admit I am curious about how regulators writ large are going to handle AI.

                  And yeah, I hear you on the slop - my timeline chats about it constantly. Did you see this? https://github.com/crabby-rathbun?tab=overview&from=2026-01-01&to=2026-01-31

                  securitycrob@infosec.exchangeS 2 Replies Last reply
                  0
                  • sempf@infosec.exchangeS sempf@infosec.exchange

                    @SecurityCRob @tychotithonus And hi! How are you doing?

                    securitycrob@infosec.exchangeS This user is from outside of this forum
                    securitycrob@infosec.exchangeS This user is from outside of this forum
                    securitycrob@infosec.exchange
                    wrote last edited by
                    #10

                    @Sempf @tychotithonus doing fine! 2026 travel is about to ramp back up soon though. I’ve enjoyed my snow cave here and will be sad to leave!

                    sempf@infosec.exchangeS 1 Reply Last reply
                    0
                    • securitycrob@infosec.exchangeS securitycrob@infosec.exchange

                      @Sempf @tychotithonus doing fine! 2026 travel is about to ramp back up soon though. I’ve enjoyed my snow cave here and will be sad to leave!

                      sempf@infosec.exchangeS This user is from outside of this forum
                      sempf@infosec.exchangeS This user is from outside of this forum
                      sempf@infosec.exchange
                      wrote last edited by
                      #11

                      @SecurityCRob Man this WEATHER! Can't even believe it. This year has been something else.

                      1 Reply Last reply
                      0
                      • sempf@infosec.exchangeS sempf@infosec.exchange

                        @SecurityCRob @tychotithonus If it comes up in conversation, that would be awesome. Don't, of course, put yourself out. I admit I am curious about how regulators writ large are going to handle AI.

                        And yeah, I hear you on the slop - my timeline chats about it constantly. Did you see this? https://github.com/crabby-rathbun?tab=overview&from=2026-01-01&to=2026-01-31

                        securitycrob@infosec.exchangeS This user is from outside of this forum
                        securitycrob@infosec.exchangeS This user is from outside of this forum
                        securitycrob@infosec.exchange
                        wrote last edited by
                        #12

                        @Sempf @tychotithonus Ha! I see you found that. The python folks were on about that yesterday. The github comment behind this are equal parts horrifying and hilarious

                        1 Reply Last reply
                        1
                        0
                        • tychotithonus@infosec.exchangeT tychotithonus@infosec.exchange

                          Has anybody built a matrix of the lawful compliance transparency or policies or reporting across the various llm platforms? I wonder how often they get requests, and for what kind of data

                          securitycrob@infosec.exchangeS This user is from outside of this forum
                          securitycrob@infosec.exchangeS This user is from outside of this forum
                          securitycrob@infosec.exchange
                          wrote last edited by
                          #13

                          @tychotithonus @Sempf I've posed the question to our AI/ML working group slack (the really smart robot-people within the OpenSSF hang out). I'll let you know what the smarter people come back with, or feel free to hop onto #wg-ai-ml-security on the public openssf slack

                          1 Reply Last reply
                          0
                          • sempf@infosec.exchangeS sempf@infosec.exchange

                            @SecurityCRob @tychotithonus If it comes up in conversation, that would be awesome. Don't, of course, put yourself out. I admit I am curious about how regulators writ large are going to handle AI.

                            And yeah, I hear you on the slop - my timeline chats about it constantly. Did you see this? https://github.com/crabby-rathbun?tab=overview&from=2026-01-01&to=2026-01-31

                            securitycrob@infosec.exchangeS This user is from outside of this forum
                            securitycrob@infosec.exchangeS This user is from outside of this forum
                            securitycrob@infosec.exchange
                            wrote last edited by
                            #14

                            @Sempf from an eu regulator standpoint “when a manufacturer becomes aware of <an actively exploited vuln> or <a severe incident> they have 24hrs to report that to authorities. So if the robots are filing issues with maintainers automagically the vendor is responsible for monitoring and reacting to that. Upstream doesn’t have legal obligations, but every downstream that uses the software will immediately start poking upstream for fixes. If the vendor isn’t monitoring upstream, that could be consider negligence. Tl/dr this is going to put even more intense pressure on the whole system and I fear maintainers will be challenged to keep pace with all the noise

                            1 Reply Last reply
                            1
                            0
                            Reply
                            • Reply as topic
                            Log in to reply
                            • Oldest to Newest
                            • Newest to Oldest
                            • Most Votes


                            • Login

                            • Login or register to search.
                            • First post
                              Last post
                            0
                            • Categories
                            • Recent
                            • Tags
                            • Popular
                            • World
                            • Users
                            • Groups