Hacker News new | ask | show | jobs
by crooked-v 308 days ago
If that's the case, then as noted in the article, the 'as intended' is probably violating liability requirements around various things.
1 comments

Correct. It is precisely that a user can ask about someone’s medical history (or whatever else) and not be reported that would be in violation of any heavily audited system. LLM Summaries break the compliance.
You allow what it can and can't see. If you include PII and medical records, that's your fault, not MS's.
That’s fair - unless they’re marketing the bot as compliant.