You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In d788916, duly made with Copilot, we noticed the risk of sensitive customer information leaking through AI tools. I'm specifically most concerned about training models somehow extracting PII, rather than direct commits of sensitive information to GitHub. The latter is a serious and significant risk, but I think it can be well mitigated by putting policies in place around tools with access to the SEP-12 infrastructure yet to be built, which shouldn't push any client records onto any repo.
In general, we can have team members disable the use of their information for training models through cloud-provider user settings in their own accounts. The "their own account" point is a significant and outstanding policy choice to allow decentralization, pending in JFWooten4/free-markets#69, which will become much more relevant once I propose the DUNA Treasury for JFWooten4/agenda#27.
This has downstream effects on how we work with Stellar developers in stellar/stellar-docs#1895, which will undoubtedly make its way into future team development efforts. I think we will have a lot more innovation by incorporating the tooling across repos, with GH as a uniform collaboration layer. Having all the docs public through issues, PRs, and Discussions also makes them really easy to parse with the GitHub connector tools.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
In d788916, duly made with Copilot, we noticed the risk of sensitive customer information leaking through AI tools. I'm specifically most concerned about training models somehow extracting PII, rather than direct commits of sensitive information to GitHub. The latter is a serious and significant risk, but I think it can be well mitigated by putting policies in place around tools with access to the SEP-12 infrastructure yet to be built, which shouldn't push any client records onto any repo.
In general, we can have team members disable the use of their information for training models through cloud-provider user settings in their own accounts. The "their own account" point is a significant and outstanding policy choice to allow decentralization, pending in JFWooten4/free-markets#69, which will become much more relevant once I propose the DUNA Treasury for JFWooten4/agenda#27.
This has downstream effects on how we work with Stellar developers in stellar/stellar-docs#1895, which will undoubtedly make its way into future team development efforts. I think we will have a lot more innovation by incorporating the tooling across repos, with GH as a uniform collaboration layer. Having all the docs public through issues, PRs, and Discussions also makes them really easy to parse with the GitHub connector tools.
All reactions