AI assistant barely documented, important questions unanswered
The AI Assistant feature was added and turned on by default without any notification or confirmation. It transmits data to undocumented locations using undocumented services. This post is a collection of confusing and undocumented aspects of this "feature."
There is no system administrator/owner-facing documentation on this feature. The Release notes for the AI assistant talk about deltas (X has changed) but X's behavior was never documented in the first place, so documenting the change to X isn't enough. If I go to the documentation for Feature Manager (a page definitely targeted at me, the system owner), the link for "AI Assistant" links to the end-user facing documentation for the assistant. The docs fail to cover some super basic questions:
- Where does the data go when a user interacts with the AI assistant?
- What model is getting the input and where does that model run?
- Who pays for this? AI services are not free.
- Is it a local model? Is it running on my CPU? Or does it transmit information to a third party like OpenAI?
- Are there any configuration options for the AI assistant?
- The cPanel feature manager lists two independent things I can allow/deny: "AI Assistant" and "AI Assistant Actions." I can enable either one, neither, or both. There is absolutely no documentation on what these two options control.
Imagine a user copy/pastes a whole list of names, addresses, and phone numbers and instructs the assistant to create contacts for all of them. Maybe the assistant can do that. Maybe it can't. Users might try anyway. Here's some basic questions:
- Where did all that personal information get transmitted? We know it was on my user's laptop and we know it went to my cPanel server. Did it go anywhere else?
- How was that information protected in transit? If it's only the user and me involved, the answer is obvious.
- Where is that personal information temporarily stored while the AI processes the request?
- How long is the personal information retained by the AI service after the request is complete?
- What country did the processing occur in? If I have a user in Canada using a cPanel server in Canada, for example, did the information get transmitted to an AI service in the US? Does that service retain the information?
When using an LLM-based service, it is common to name the model that is used. The documentation does not include the word 'model.' The are a few statements about what the assistant WON'T do or DOESN'T do, but the docs forget to name the things it DOES do. It's fine to say "no personally identifying information goes to analytics", but if I type personally identifying information in the text box and hit enter, where DOES it go?
Confusingly, the AI documentation says "Meridian may log conversations for quality and support purposes". Who or what is "Meridian."? When I read the words "Meridian theme" I think the word "Meridian" is just the title of the theme. A theme is not a thing that can log conversations. But if Meridian is a thing that "may log conversations," now I'm unsure. Is that a legal entity? A company? A service? Is Meridian me? That is, if "Meridian" is the name of a service running on my cPanel server, then Meridian logging conversations that means -I- am logging conversations. If I am logging conversations, I need to know that and I need control over that.
Have I or my users consented to terms and conditions with some legal entity by using the AI assistant? What legal entity is that, and where are the terms and conditions I allegedly consented to when I asked the AI assistant a question? How could I or my end users find those terms? I know there must be some liability disclaimer somewhere that says "even if the AI deletes everything, it's not our fault because it asked you for permission first." Where is that?
All these questions are vitally important. If I had to explicitly activate the service, you could put all the answers in front of me, get me to agree to some terms, and so on, and then you could conclude "this user affirmatively read the terms and agreed to turn on this feature." But this feature was turned on by default, available to all my users by default, and I can't figure out how any of us are meant to get answers to these questions.
cPanel did the same thing all other AI companies do about consent: they completely ignored it.
-
Thanks for sending this feedback. It's going to take me a bit to get all these answers, but once I'll have them I'll be sure to post a reply.
0 -
Thanks. You're on the front lines of a lot of stuff and and you take it in stride. I appreciate it.
0 -
You're welcome - it's what I do!
0 -
Just letting you know that I'm waiting to hear back on a few things, but hopefully I'll have more details next week.
0 -
Update - I have most of the answers you're looking for now, but I'm still hunting down a few. I'll post soon with a detailed reply.
0 -
I believe the FAQ section we've included here answers all your questions except one:
https://3io90d-hyc3i7-blhepp.nova.webpros.com/
with that one being how long any data used by AI is retained. I'm just waiting to hear back from that and once I do I'll let you know!
0
Please sign in to leave a comment.
Comments
6 comments