Hacker News new | ask | show | jobs
by sailfast 301 days ago
Correct. It is precisely that a user can ask about someone’s medical history (or whatever else) and not be reported that would be in violation of any heavily audited system. LLM Summaries break the compliance.
1 comments

You allow what it can and can't see. If you include PII and medical records, that's your fault, not MS's.
That’s fair - unless they’re marketing the bot as compliant.