Vol. I, No. 26
Covering 4 December - 17 December 2023
Monday, December 18, 2023
Late edition · A Relentless publication
All the fortnight that mattered, in technology and in the world, read next to what we were building at the time.
BRUSSELS

Europe agrees the world's first comprehensive law on artificial intelligence

After three days of talks that ran through the night, the European Union struck a deal on the AI Act, a sweeping attempt to govern the technology by how much harm it can do. The rest of the world will now feel the pull of Europe's rules.

European Union negotiators reached a provisional political agreement late on December 8, after a marathon final session, on the AI Act, the first comprehensive law anywhere to regulate artificial intelligence. It works by ranking AI systems according to the risk they pose: some uses are banned outright, such as social scoring and most real-time facial recognition in public; high-risk uses, in hiring, credit, policing and the like, face strict obligations to be tested, documented and overseen; and the powerful general-purpose models behind systems like ChatGPT face transparency requirements and, for the most capable, additional scrutiny. The law will phase in over the next two years, and its fines for breaking it run to a share of global revenue large enough to make even the biggest companies read it carefully.

The agreement caps a year in which the world's governments went from watching AI to regulating it, and it matters beyond Europe for a reason this paper has noted before: the Brussels effect. When the EU writes a rule for its market of 450 million people, global companies tend to build to that rule everywhere, because maintaining two versions of a product is more expensive than complying with the strictest regulator. Europe's privacy law did this, and its AI Act is likely to do it again, exporting European choices about acceptable AI to the world by the sheer gravity of the single market. Critics say it will smother European innovation and hand the lead to a less-regulated America and China; supporters say it draws the lines a powerful technology needs before, not after, the harms arrive. Both may be right. What is certain is that the era of AI without rules, which lasted almost exactly the year since ChatGPT, is over, and Brussels wrote the first real ones.

MARKETS

The Fed blinks toward cuts, and the markets throw a party

The Federal Reserve held interest rates steady on December 13 and, more importantly, signalled through its own projections that it expected to cut them three times in 2024, an unexpectedly clear turn from a central bank that had spent two years raising, and Jerome Powell declined to push back against the market's exuberance the way he had before. Investors, who had been hoping for exactly this, responded with euphoria: stocks surged to the edge of record highs, bond yields tumbled, and the ten-year Treasury, which had touched 5 percent in October, fell below 4 percent. The message the market heard was that the painful tightening cycle is over, that inflation has been beaten without the recession everyone feared, and that cheaper money is coming. Whether the Fed really pivots that fast depends on data not yet in, but for a fortnight the mood turned, and a year of "higher for longer" gave way, almost overnight, to the scent of relief.

IN BRIEF

A climate deal names the cause; Gemini arrives; India's institutions

The COP28 summit in Dubai closed on December 13 with a deal that, for the first time in three decades of climate talks, explicitly called on the world to "transition away from fossil fuels," weaker than the "phase-out" many wanted but a milestone in naming the thing at last. Google launched Gemini, its most capable AI model and its real answer to GPT-4, on December 6, though it was dented by revelations that a dazzling demonstration video had been edited to look more fluent and immediate than the system actually was. And in India, a security breach saw intruders leap into the chamber of a parliament observing the anniversary of a 2001 terror attack, followed by the mass suspension of opposition MPs, while the Supreme Court upheld the government's 2019 revocation of Kashmir's special status.

The Column

Decarbonise, and compute: pick two

The climate summit named fossil fuels at last this fortnight, in the same weeks that the AI build-out's electricity appetite finally reached the front page. The two great projects of the decade are on a collision course, and no one has done the arithmetic.

Two stories ran side by side this fortnight and almost no one set them next to each other, which is a mistake, because they are the same story. In Dubai, after thirty years of trying, the world's climate summit finally produced a document that named the cause of the problem, calling on nations to transition away from fossil fuels. And across the technology industry, the electricity demand of the artificial-intelligence build-out, the vast new data centres full of power-hungry chips, moved from a footnote to a genuine concern, as forecasters began to grasp how much new power the AI boom is going to need. Put the two together and you get the defining tension of the coming decade, and it is a tension nobody in either camp wants to acknowledge: the world has committed, at last, to using less fossil energy, at the exact moment it has committed, through AI, to using vastly more energy overall.

The arithmetic is brutal and largely unspoken. Decarbonising means replacing fossil power with clean power, which is hard and slow even if demand stays flat. But demand is not staying flat; the AI build-out is projected to add enormous new electricity load, data centres that draw as much power as small cities, and to add it fast, faster than clean generation can plausibly be built. So the new demand risks being met, at the margin, by exactly the fossil generation the world just pledged to phase out, or by delaying the retirement of plants that should be closing. The two commitments, decarbonise and compute, are being made by the same civilisation at the same time, and they pull in opposite directions, and the reconciliation, how you build a clean grid while also dramatically increasing the load on it, is the problem no one has solved and few are even stating plainly.

I do not raise this to be against AI, any more than to be against decarbonisation; both are real and, in their ways, necessary. I raise it because this paper has spent a year watching the power question hide beneath the technology story, treated as a detail, when it is in fact the binding constraint. You cannot run the AI future on a grid that does not exist, and you cannot decarbonise a grid whose load you are simultaneously exploding, without a plan that connects the two, and there is no such plan, only two enormous ambitions announced in the same fortnight by people who mostly were not talking to each other. The chips get the headlines and the summits get the pledges, and underneath both sits the wire, the substation, the power plant, the physical reality that will decide whether either ambition is achievable. Decarbonise, and compute. Right now the world is loudly promising both, and quietly, no one has worked out how to have them at the same time.

Field Notes
A Relentless build, told plainly

A free tool for the people who keep Salesforce running, and why I gave away the thing about permissions

The front page is about Europe forcing companies to document and control their AI systems. This is about a smaller, older discipline: knowing who can see what inside your own software, which almost no organisation actually does. No client is named.

Earlier in this paper's run, writing about a leaked trove of secrets and the 21-year-old who walked out with them, I argued that the most common serious flaw in any system is not a dramatic breach but the slow, invisible sprawl of access: permissions granted under deadline, cloned from person to person, never reviewed, never revoked, until an organisation has no real idea who inside it can see what. I have believed that for years, and at one point I did something about it that I am still glad of: I built a tool that helps the administrators of a Salesforce system see and manage exactly that, and I made the core of it free.

The tool does the unglamorous work that keeps a system healthy. It looks across an organisation's setup and surfaces the things that accumulate in the dark: the permissions nobody uses any more, the access that was granted once and forgotten, the configuration that has drifted from what anyone intended, the general clutter and risk that builds up in any system that real people have been using and changing for years. It is, in effect, a health check and a permissions map, the thing that lets an administrator answer the question I said almost no organisation can answer: who can reach the sensitive data, and does each of them still need to. And I made the useful part of it free, deliberately, because the people who most need it, the overworked administrators holding a sprawling system together, are exactly the people whose budgets never stretch to another tool, and because a discipline this important should not sit behind a price the people who need it cannot pay.

I put this next to a front page about the EU forcing companies to document and control their AI systems because it is the same instinct at two very different scales. Europe is telling companies, by law, that they can no longer run powerful systems they cannot account for, that they must be able to show who is responsible, what the system does, and how it is controlled. That is the correct instinct, and it is exactly the instinct behind a free permissions tool, only the law arrives with fines and the tool arrives with a download. The through-line is the same: you cannot manage what you cannot see, and the sprawl you cannot see is precisely the sprawl that hurts you, whether it is a permission an intern should not have or a model no one can explain. Most of security, and most of good administration, is just making the invisible visible so that a human can look at it and ask whether it should be that way. The regulation on this fortnight's front page is that instinct written as law. The tool I gave away was the same instinct, written as software, for the people the law will land on hardest and fund least.

The Ledger
AI
The EU AI Act is the year's landmark: the first comprehensive law, risk-tiered, with real fines, and a likely Brussels effect that exports it globally. The year of AI-without-rules, which began with ChatGPT, ends with Europe writing the first real ones.
Data centers & power
COP28's "transition away from fossil fuels" collides, unspoken, with the AI build-out's soaring electricity demand. The two great trends of the decade, decarbonise and compute, are on a collision course nobody has costed.
Rates
The Fed's dovish turn is the fortnight's market story: three cuts projected for 2024, yields collapsing, stocks near records. The soft landing has gone from hope to consensus, perhaps prematurely.
Real estate
Mortgage rate 6.95 percent (December 14), below 7 for the first time since August, as the rate-cut hopes feed through. The frozen market's first real thaw, if the cuts arrive.
India tech
The parliament breach and mass suspensions, and the Kashmir ruling, are the fortnight's institutional texture: a confident government, a constrained opposition, courts that back the executive on the big questions. The stability business likes, and the concentration it should watch.
What we called wrong
Nothing to retract. But this fortnight vindicates a call we made in No. 8 and repeated in No. 23: that regulation, not a voluntary pause, would be how AI got governed, and that Europe was moving fastest. The AI Act is that prediction made law.
The Back Page

The man who put the argument on television

Norman Lear died on December 5, at 101, and American television was, for a stretch of the 1970s, essentially his. He made All in the Family, and Maude, and The Jeffersons, and Good Times, and Sanford and Son, shows that took the things families actually fought about, race, war, abortion, money, prejudice, bigotry, and put them in the living room in prime time, in the mouths of characters an audience of tens of millions could not help but love even when they were appalling. Archie Bunker, his great creation, was a working-class bigot, and the genius and the risk of it was that you laughed with him and at him at once, and the show trusted you to know the difference. Lear believed television could hold a real argument without resolving it into mush, that an audience was smart enough to sit with discomfort, and he was proved right by the ratings and the decades. He spent the second half of his long life on politics and free speech and the founding of an advocacy group, still sharp, still arguing, into his second century. He thought the point of the medium was not to soothe people but to make them think and feel and, ideally, talk to each other afterward, and for a while, in the country's living rooms, it did exactly that. He was 101, and he had used every year.