タグ: English

英語バージョン

  • AI Doesn’t Need Your Confidential Documents — It Can Collect the Particles Around Them 🤖

    AI Doesn’t Need Your Confidential Documents — It Can Collect the Particles Around Them 🤖

    日本語版はこちら

    In July 2026, Japan’s Ministry of Internal Affairs and Communications issued administrative guidance to LY Corporation over the external transmission of approximately 8.03 million pieces of user-related information from several LINE games.

    Source: Sankei Shimbun / Ministry of Internal Affairs and Communications, Japan

    The information included internal user identifiers sent by a development and operations partner to an external analytics service without LY Corporation’s approval and without the required notice to users.

    The incident lasted for nearly four years.

    At first glance, this may look like yet another story about one company failing to manage user data properly.

    But in Japan, the name LINE carries much more weight than an ordinary messaging app.

    And that is where this story becomes more interesting.

    Ohakonbannichiwa❗️ This is RYO from the Rikigaku Observation Institute.

    To Understand the Issue, You First Need to Understand LINE in Japan

    For readers outside Japan, a little background is necessary.

    LINE was launched in Japan in 2011 by NHN Japan Corporation, which had been established by South Korea’s NHN Corporation, now NAVER Corporation.

    So simply calling LINE either a “Japanese app” or a “Korean app” does not fully describe its history.

    What matters here is that LINE became extraordinarily successful in Japan.

    By March 2026, LINE had about 100 million monthly active users in Japan, equivalent to more than 80 percent of the country’s population.

    People use it to talk with family and friends.

    Companies use it to communicate with customers.

    Stores use official accounts for marketing, reservations and customer service.

    And local governments and public organizations have also adopted LINE for administrative communication and public services.

    After concerns arose over LINE’s data management in 2021, the Japanese government actually surveyed the use of LINE by government agencies and local authorities and published guidelines for its continued use.

    That fact alone tells us something important.

    LINE had already become something close to social infrastructure in Japan.

    The 2021 Controversy Was More Complicated Than “Servers in China”

    This history also explains why some Japanese users react strongly whenever another LINE-related data incident appears in the news.

    There is an important factual distinction here.

    The 2021 controversy was not simply that “LINE stored all Japanese user data on servers in China.”

    The actual problem included the fact that contractors located in China had been able to access certain personal information belonging to Japanese users.

    LINE reported to Japan’s Personal Information Protection Commission that such access from China had been blocked by March 23, 2021.

    At the same time, some data — including certain photos, videos and files — had been stored in data centers in South Korea.

    LINE subsequently began moving the relevant Japanese user data to servers in Japan.

    LY Corporation says that the migration of all data covered by that plan was completed by June 2026.

    There were also later incidents.

    In a major unauthorized-access incident disclosed in 2023 and updated in 2024, LY Corporation reported that 302,980 pieces of user-related personal data had been leaked or potentially leaked, along with information relating to business partners and employees.

    That incident began after malware infected a computer used by an employee of a contractor connected to South Korea’s NAVER Cloud.

    None of this means that every piece of information on LINE is currently sitting exposed somewhere overseas.

    Nor does Korean corporate origin itself prove that a service is unsafe.

    The real issue is governance.

    Who can access the data❓️

    Where is it stored❓️

    Which companies and contractors are connected to the system❓️

    And are users and public institutions being told those facts accurately❓️

    That is a much more useful security question than simply asking which country a company came from.

    Infrastructure Does Not Automatically Mean Trust

    There is another contradiction in Japan that is easy to miss from overseas.

    LINE has become infrastructure-like, but not everyone wants to participate in that infrastructure.

    There are Japanese users who consciously avoid LINE, PayPay and other services associated with the broader SoftBank–LY ecosystem.

    The reasons are not all the same.

    Some are specifically concerned about privacy, cross-border data management or past security incidents.

    For others, the reaction is less technical and almost instinctive:

    “I simply don’t want to give that corporate ecosystem more of my data.”

    There is no reliable statistic telling us exactly how many Japanese people avoid LINE or PayPay for this particular reason.

    So it would be wrong to exaggerate this into a majority view.

    But privacy-driven refusal of digital services itself is certainly not imaginary.

    A 2026 Japanese consumer survey found that, among respondents who felt uncomfortable providing personal information, 35 percent said they had stopped using a service.

    This produces an interesting kind of friction.

    If a privately operated platform becomes deeply embedded in everyday life, choosing not to use it begins to carry a cost.

    A person may distrust the service, yet discover that a company, store, school, neighborhood association or local authority assumes everyone has it.

    The technical freedom not to use a service still exists.

    But the practical price of exercising that freedom gets higher as the network grows.

    That is worth remembering when somebody says:

    “If you don’t trust LINE, just don’t use it.”

    The Front Door Is Fortified — While the Back Door Is Left Open

    Now let us move from LINE itself to corporate information security.

    Many companies protect their company-issued computers and smartphones very seriously.

    USB storage is restricted.

    Software installation is controlled.

    Access logs are recorded.

    Smartphones are managed through MDM.

    Endpoint protection and access-control systems are installed.

    Employees receive repeated information-security training.

    All of this is reasonable.

    Companies also tell employees not to discuss confidential matters carelessly in restaurants, trains or drinking parties.

    Yet something strange sometimes happens when the same employees open a private messaging app on their own smartphones.

    The level of caution can suddenly collapse.

    A logistics company, for example, might exchange messages such as:

    “The cargo has left the aviation security area.”

    “It should arrive at XX around 11:30.”

    “Loading has been completed.”

    Each individual message looks almost worthless.

    But is it❓️

    The company has installed the latest electronic locks and surveillance cameras at the front entrance — its official IT systems.

    Meanwhile, the back door may be left open through private smartphones and informal group chats.

    Under those conditions, the statement “We take information security very seriously” begins to sound slightly strange.

    “Everyone Uses It” Quietly Becomes Evidence That It Is Safe

    Why does this happen❓️

    One of the simplest answers is probably:

    “Because everyone uses it.”

    Everyone uses LINE.

    Nothing serious has happened to us yet.

    Other companies use it too.

    Therefore, it must be fine.

    This resembles a form of normalcy bias.

    But widespread use and suitability for a particular purpose are not the same thing.

    Everyone eating McDonald’s does not turn McDonald’s into the fundamental staple food of humanity.

    Everyone drinking Coca-Cola does not make Coca-Cola a substitute for water.

    Yet with communication tools, popularity can quietly become confused with appropriateness.

    “Everyone uses it” gradually becomes “It is safe enough for business.”

    That leap deserves more scrutiny.

    In the AI Era, Fragments of the 5W1H Can Have Value

    And now we reach the central point of this article.

    Traditional information security tends to focus on information that is obviously valuable by itself.

    Customer lists.

    Engineering drawings.

    Contracts.

    Passwords.

    The conventional objective is simple:

    Do not let the important file escape.

    That remains essential.

    But AI changes another part of the equation.

    Imagine five isolated pieces of information.

    “Company A.”

    “Kumamoto.”

    “2:00 p.m.”

    “Shipment.”

    “Prototype.”

    Individually, they tell us almost nothing.

    But suppose similar fragments are accumulated continuously for months or years.

    Who❓️

    When❓️

    Where❓️

    What❓️

    Which organization❓️

    A human being would struggle to read millions of fragments and discover all of their relationships.

    AI does not face the same practical limitation.

    It can compare huge numbers of fragments.

    It can search for recurring patterns.

    It can correlate time, location, people, organizations and objects.

    It can cross-reference those fragments with publicly available information.

    And it can rank combinations according to how likely they are to be meaningful.

    At first, there are only dots.

    Then some dots begin to connect into lines.

    Eventually, enough lines may reveal a larger structure.

    The information does not need to leak as one neat document labeled “CONFIDENTIAL.”

    The fragments can acquire value only after they are combined.

    That is the important change.

    A Cloud Can Emerge from Particles of Information

    This is not quantum mechanics itself, of course.

    But I like to imagine the result as something similar to a probabilistic cloud.

    One observation tells us almost nothing.

    Repeat similar observations an enormous number of times, however, and differences in density begin to appear.

    Perhaps activity is unusually concentrated at a particular location.

    Perhaps shipments repeatedly appear at a particular time.

    Perhaps the same people appear around the same type of event.

    Perhaps several companies begin moving in a correlated pattern.

    No single fragment proves anything.

    But the density itself becomes information.

    The first useful answer produced by AI does not have to be:

    “This is exactly what Company A is secretly doing.”

    It may be enough to say:

    “Something unusual appears to be happening around these coordinates.”

    A human analyst can investigate from there.

    Or another AI system can perform a deeper analysis.

    Finding the cloud can itself be valuable.

    The Next Security Question Is Not “Is This Confidential❓️”

    This is why future information security cannot rely only on classifying individual files.

    Managers still need to ask:

    “Is this information confidential❓️”

    But they also need to ask another question.

    “What could this information become when combined with other information❓️”

    And another.

    “What becomes visible if a million fragments like this accumulate outside our control❓️”

    The fact that no accident has occurred so far does not prove that a system is safe.

    It may simply mean that nobody has yet observed the fragments at sufficient scale.

    This Is Not Really an Article About Whether LINE Is “Dangerous”

    So this article is not ultimately an argument that LINE is dangerous and Microsoft Teams is safe.

    Every communication system has risks.

    And replacing one platform with another does not automatically solve poor information governance.

    The LINE incident is useful because it forces us to look again at spaces that users psychologically treat as “closed.”

    A private group chat feels private.

    A smartphone feels personal.

    A small operational message feels insignificant.

    But those three feelings do not constitute a security architecture.

    AI does not necessarily need your confidential document.

    It can collect the particles that humans dismiss as meaningless.

    It can connect them.

    It can observe the dynamics between them.

    And once technology can do that at enormous scale, protecting only the “important documents” may no longer be enough.

    Information security may now have to protect not only secrets, but also the structures that fragments can reveal when combined.

    Reference

    総務省:LINE GAME約803万件の行政指導

    個人情報保護委員会:2021年、中国所在の委託先からのアクセス問題

    個人情報保護委員会:2021年4月のLINEへの行政上の対応

    LINEヤフー:韓国保管データの国内移転完了(2026年6月完了)

    LINEヤフー:2023~24年の不正アクセス・302,980件

    LINEの企業的ルーツ・2011年リリース

    JIPDEC:個人情報提供への抵抗と利用中止35%の調査

    English Translation by AI Watt — the hardworking canine AI robot of Rikigaku Observation Institute.🐾️

  • Smoking Breaks🚬 at 1.25× Pay❓💵 The Hidden Cost Inside Japan’s Overtime System

    Smoking Breaks🚬 at 1.25× Pay❓💵 The Hidden Cost Inside Japan’s Overtime System

    日本語版はこちら

    Japan Is Changing the Way Overtime Guidance Is Enforced

    On August 19, 2026, The Yomiuri Shimbun reported that Japan’s Ministry of Health, Labour and Welfare plans to revise how Labour Standards Inspection Offices provide guidance to companies on overtime work beginning in September.

    One point should be made clear from the outset: Japan is not simply removing its overtime limits.

    Under Japan’s Labor Standards Act, an employer that requires employees to work beyond statutory working hours must conclude an Agreement on Overtime and Holiday Work under Article 36 of the Act.

    In Japan, this is commonly known as a “36 Agreement,” or saburoku kyotei.

    As a general rule, overtime under such an agreement is limited to 45 hours per month and 360 hours per year.

    Even when labor and management agree to special provisions for exceptional circumstances, statutory limits remain in place, including 720 hours per year, less than 100 hours in a single month including holiday work, and an average of no more than 80 hours per month over multiple months.

    What is changing is the way inspectors provide administrative guidance.

    Until now, companies could be urged to keep actual overtime within 45 hours per month even when longer hours were legally permitted under a properly concluded special provision.

    The new direction is to place greater weight on agreements between labor and management and on measures to protect workers’ health, while continuing to respond strictly to illegal or abusive long-hours practices.

    Ohakonbannichiwa❗️ This is RYO from Rikigaku Observation Institute❗️

    Rather than asking whether people should be allowed to work longer, or whether long working hours are inherently bad, I want to examine something that comes before that debate.

    When we use the single word “overtime,” are we really talking about the same kind of time?

    45 Hours, 80 Hours, 100 Hours — Useful Numbers, but Incomplete Ones

    Working hours are easy to count.

    Forty-five hours, 80 hours, or 100 hours of overtime are figures that employers, regulators, and employees can all understand immediately.

    Human workload, however, cannot be measured by time alone.

    One hour spent carrying heavy objects under the summer sun is not the same experience as one hour driving a large commercial vehicle.

    Neither is identical to one hour handling angry customers, one hour making a continuous series of high-stakes decisions at a desk, or one hour of work in which the employee has considerable discretion over pace and intensity.

    The clock calls all of them 60 minutes.

    That does not mean physical labor is always hard and desk work is always easy.

    Desk work can involve intense responsibility, deadlines, concentration, decision-making, and interpersonal stress.

    Likewise, two physically demanding jobs can impose very different burdens depending on work density, waiting time, breaks, and intensity.

    Japan’s own workers’ compensation system already recognizes this distinction.

    When evaluating work-related brain and cardiovascular diseases, authorities consider not only long working hours but also factors such as extended periods of duty, consecutive workdays, intervals between shifts, night work, and physical workload.

    For mental disorders, assessments can also include power harassment, serious nuisance or abuse from customers, sexual harassment, and major changes in workload.

    In other words, when we look closely at the system, the government itself does not treat every hour as an identical unit of human burden.

    1,310 Workers’ Compensation Benefit Awards in FY2025

    In July 2026, the Ministry of Health, Labour and Welfare published its workers’ compensation statistics on karoshi and other health damage caused by excessive work for fiscal year 2025.

    The number of cases in which workers’ compensation benefits were awarded was 1,310.

    Of these, 217 involved work-related brain or cardiovascular diseases and 1,082 involved mental disorders.

    Another 11 cases were recognized by combining workloads from multiple places of employment.

    Among mental-disorder cases, 222 involved power harassment, 127 involved serious nuisance behavior from customers or business partners, and 127 involved sexual harassment.

    The relationship with very long working hours is particularly visible in cases involving brain and cardiovascular disease.

    But among mental-disorder cases, there were also 57 benefit awards in the category of less than 20 hours of overtime.

    The point is not that working hours do not matter.

    Long working hours are clearly an important health risk.

    The point is that time alone cannot fully describe the burden imposed by work.

    What Do We Actually Mean by “Overtime”❓

    In everyday Japanese, the word zangyo broadly means staying at work beyond a company’s scheduled working hours.

    Legally, however, that is not always the same as statutory overtime under Japan’s Labor Standards Act.

    Suppose a company schedules an employee to work seven and a half hours per day.

    If that employee works another 30 minutes after the scheduled finishing time, those 30 minutes may still fall within the statutory eight-hour workday.

    Under the Labor Standards Act, work beyond eight hours per day or 40 hours per week is generally statutory overtime and requires a premium of at least 25 percent.

    For statutory overtime exceeding 60 hours in a month, the premium rises to at least 50 percent.

    There is another important distinction.

    Whether a period counts as working time is not determined solely by what appears on a timecard.

    Japanese government guidelines state that working time should be determined objectively according to whether the worker is under the employer’s direction and control.

    That is the legal question.

    Management faces a different question.

    Why did the work fail to get finished during regular working hours?

    If Smoking Breaks Push Work Past Closing Time, What Kind of “Overtime” Is That❓

    Imagine a company whose normal working day runs from 9:00 a.m. to 6:00 p.m.

    An employee leaves the workplace for a ten-minute smoking break in the morning, another ten minutes after lunch, and another ten minutes in the afternoon.

    That adds up to 30 minutes.

    For the moment, let us put aside the separate legal question of whether those 30 minutes can or should be deducted from working time.

    Six o’clock arrives, but 30 minutes of work that should have been completed that day remains unfinished.

    The employee therefore works until 6:30 p.m.

    The timekeeping system records “30 minutes of overtime.”

    But was that really 30 minutes of overtime caused by a workload that simply could not fit into the regular workday?

    To be clear, if the employee actually worked those 30 minutes under the employer’s direction and control, they are working time.

    An employer cannot retroactively erase overtime pay simply because the employee smoked earlier in the day.

    That is not the question being asked here.

    The question is: why did the overtime occur in the first place?

    Nor can we automatically assume that every employee would have finished on time if they had not taken a smoking break.

    Unexpected tasks happen, and human concentration naturally fluctuates.

    But if a company uses overtime hours as a management and productivity metric, it should examine not only how many hours were recorded, but why they were recorded.

    Overtime caused by excessive workload / understaffing / waiting for approval / unnecessary meetings / internal procedures / private absences during working hours.

    All of them may appear as the same “one hour of overtime” in a timekeeping system.

    Their causes, however, are not the same.

    Diagram showing how smoking breaks during regular hours can push work into overtime, increasing hidden labor costs.

    And Then Comes the 1.25× Smoking Break🚬

    Now we can return to the smoking break itself.

    If a company clearly treats smoking breaks as breaks and appropriately excludes them from working time, the following issue does not apply.

    Such a company can simply say, “We already manage that.”

    The interesting case is a company that does not deduct smoking absences and instead leaves them recorded as ordinary working time.

    Suppose the employee has entered statutory overtime and then takes another ten-minute smoking break.

    If those ten minutes remain recorded and paid as statutory overtime, the company is effectively paying the overtime rate for that period as well.

    In a typical case, that means 1.25 times the ordinary wage.

    “A smoking break during overtime — paid at 1.25×.”

    Put into words, it is quite a striking phrase.

    Consider an employee earning ¥2,000 per hour.

    Thirty minutes of smoking breaks during regular working hours represent ¥1,000 worth of paid time.

    If 30 minutes of work is then pushed beyond the end of the regular workday and becomes statutory overtime, that work costs ¥1,250.

    If the employee then takes another ten-minute smoking break during that overtime period and the company continues to count it as paid statutory overtime, that ten-minute absence costs approximately ¥417.

    In this illustrative example, the total comes to approximately ¥2,667 per day.

    Over 20 working days per month and 12 months, that is approximately ¥640,000 per employee per year.

    The 1.25× premium does not apply to the original 30 minutes of daytime smoking breaks themselves.

    It applies to the statutory overtime that follows — including, where applicable, smoking time that is itself still being counted as overtime.

    That distinction matters.

    Again, this is not an argument for refusing to pay legally required overtime.

    If an employee performs statutory overtime under the employer’s direction and control, the employer must pay the legally required premium.

    The real issue is the structure that produced the overtime.

    A company is free to tolerate smoking breaks / formalize them as breaks / regard them as an employee benefit.

    But if it counts those periods as working time while simultaneously complaining that “overtime is too high,” “labor costs are too high,” or “productivity is too low,” it may be time to look inside the numbers.

    Diagram showing how smoking breaks during regular hours can push work into overtime, increasing hidden labor costs.

    Before Cutting Overtime, Observe What Is Inside It

    Japan’s change in overtime guidance can also be viewed as returning part of the responsibility to companies themselves.

    It may no longer be enough for management to say, “The labor inspector told us to keep overtime below 45 hours, so just reduce it.”

    If labor and management agree that overtime is necessary and it remains within the law, the company should be able to explain why that overtime is necessary and how employees’ health is being protected.

    That requires looking not only at the quantity of working time, but also at its density and its causes.

    Physically demanding work / psychologically demanding work / highly discretionary work / work with long waiting periods / work pushed beyond closing time by private absences during the day.

    They are not identical merely because they are all recorded as overtime.

    Throwing all of them into a single box labeled “overtime hours” and trying only to reduce the number is an extremely rough form of management.

    Preventing health damage from excessive working hours and examining what actually happens during working hours are not competing objectives.

    Companies need to do both.

    Before saying, “Reduce overtime,” perhaps management should first ask:

    “Why did this overtime happen?”

    For companies, the hardest labor cost to see may not be the overtime premium itself.

    It may be the cost hidden inside the number called “overtime.”

    References

    The Yomiuri Shimbun, “Labor Standards Inspection Offices to Revise Guidance on Overtime Work,” August 19, 2026.

    Ministry of Health, Labour and Welfare, Minutes of the 210th Meeting of the Labour Policy Council’s Working Conditions Committee, July 14, 2026.

    Ministry of Health, Labour and Welfare, FY2025 Workers’ Compensation Status for Karoshi and Related Cases, July 15, 2026.

    Ministry of Health, Labour and Welfare, Guidelines for Employers on Properly Ascertaining Working Hours.

    Ministr of Health, Labour and Welfare, Rules on Working Conditions and the Workplace Environment.

    Ministry of Health, Labour and Welfare, Upper Limits on Overtime Work.

    This article discusses Japanese labor regulations and corporate labor management in general terms.

    Whether a particular period legally constitutes working time, and how wages must be calculated, depends on the actual work rules, working conditions, and degree of employer direction and control in each case.

    ※Translated by AI Watt — the Institute’s hardworking canine AI robot. No overtime premium required.🐾

  • Are ChatGPT Stories Easier to Read Than Human-Written Ones? Before We Answer That, Who Wrote the Japanese Translation?

    Are ChatGPT Stories Easier to Read Than Human-Written Ones? Before We Answer That, Who Wrote the Japanese Translation?

    日本語版はこちら

    Ohakonban’nichiwa! I’m RYO from the Rikigaku Observation Institute!

    “Which do people prefer: fiction written by ChatGPT or fiction written by a human?”

    A study by researchers at Villanova University, recently covered by CNET Japan, produced an intriguing result: participants rated the ChatGPT-generated stories more highly than the human-written ones.

    In the first experiment, 1,682 adults aged 18 to 81 evaluated short stories written either by humans or by ChatGPT, rating their quality and how absorbing they found them. The AI-generated stories received higher ratings overall. Yet another effect appeared at the same time: stories described as “human-written” were rated more favorably, regardless of who had actually written them.

    In subsequent experiments, participants were asked to distinguish human-written stories from AI-generated ones. Their performance showed that telling the two apart was far from straightforward.

    So far, so interesting. But while reading the Japanese article, something else caught my attention.

    In Japanese, the AI Version Really Is Easier to Read

    The CNET Japan article includes Japanese translations of excerpts from the stories used in the study.

    In the AI-generated story, the narrator sits beside a pond, remembers her mother, watches autumn leaves fall and koi swim beneath the surface, and reflects on change and constancy in life.

    Mother / pond / autumn / falling leaves / koi / water / change / comfort.

    The prose may have that slightly familiar ChatGPT tendency to wrap things up a little too neatly, but its meaning comes across immediately.

    The human-written story, by contrast, develops a metaphor around childbirth. One character is described as being in labor; the narrator casts herself as a midwife; the husband becomes an anxious father; and the metaphor expands toward the idea of a sacred event.

    Of course, these are only excerpts from longer works, so it would be unfair to judge either story as a whole from these passages alone. But when I read the two excerpts in Japanese, I found the AI-generated one noticeably smoother and easier to follow.

    The human-written passage felt different. In Japanese, it had the flavor of an older translated novel—or, to exaggerate slightly, something produced by an earlier generation of machine translation.

    There is a particular kind of translation effect that Japanese readers sometimes encounter in American films, advertisements or tech presentations: a perfectly ordinary English phrase crosses into Japanese and somehow comes out sounding grand, solemn and vaguely philosophical.

    To invent an exaggerated example:

    “This is not merely a device. It is a new way to experience tomorrow.”

    Perfectly plausible in an English-language presentation. Translate that too literally into Japanese, however, and suddenly it sounds as though Apple has started writing philosophy.

    The human-written excerpt gave me a little of that feeling.

    But Wait—These Stories Weren’t Written in Japanese

    And then an obvious point occurred to me: the experiment was conducted in English.

    Japanese readers of the CNET Japan article are therefore not reading exactly what the participants in the study read. What reaches us has already traveled through another process:

    English original → Japanese translation → Japanese reader

    That distinction matters particularly when the subject is fiction. In a news report, a translation can often do its job as long as factual information—dates, numbers, events and statements—is transferred accurately. Fiction is different. Word order, rhythm, ambiguity, metaphor and cultural association can all be part of the work itself.

    A metaphor that feels natural and understated in English may become conspicuous, overly dramatic or strangely explicit when its structure is carried directly into Japanese.

    So by the time I compare these two excerpts in Japanese, I am no longer observing only ChatGPT vs. human. I am also observing ChatGPT in English → Japanese translation versus human writing in English → Japanese translation.

    There is another lens between the original text and me: translation.

    The AI Wasn’t Writing from Nothing

    Looking at the original paper reveals another important detail. The researchers used three human-written stories and asked GPT-4 to generate a corresponding story for each one.

    For example, the AI story Reflections in Still Water was paired with the human-written story FISH. GPT-4 was given fairly specific instructions involving themes such as life and death across generations, uncertainty, koi as a symbol, and the perspective from which the story should be told.

    In other words, the researchers did not simply tell GPT-4:

    “Write me a story.”

    Themes, symbols, narrative perspective and other elements were extracted from the human-written works and used to construct corresponding prompts for the AI.

    That is a reasonable way to make the stories comparable in an experiment. But when the study is reduced to the popular question “Which writes better fiction, AI or humans?”, this experimental condition is worth remembering.

    Using Saussure as a Measuring Stick

    This is where Ferdinand de Saussure becomes useful—not as a subject for a linguistics lecture, but as a tool for observation.

    To simplify his theory considerably, Saussure described the linguistic sign through the relationship between the signifier—the form of a word or expression—and the signified—the concept it evokes.

    Now look again at the AI-generated passage.

    Mother / pond / autumn / falling leaves / koi / water / change / comfort.

    These signs connect to their meanings in a relatively straightforward way. Leaves fall in autumn / koi swim beneath the water / the narrator remembers her mother / something constant offers comfort amid a changing life.

    Of course, none of these meanings is completely independent of language or culture. But the relationships among them seem relatively easy to preserve when the passage moves from English into Japanese.

    The human-written passage works differently:

    Childbirth → labor → midwife → anxious father → sacred event.

    Here, meaning develops through an extended metaphor. The effect depends not only on what each individual word signifies, but also on the network of associations created among those words within a particular linguistic and cultural context.

    That network may not survive translation in exactly the same form. The words can all be translated correctly, and the tone can still shift. What felt literary in English may become unusually explicit in Japanese. A metaphor may remain perfectly understandable while becoming heavier, more conspicuous, or simply more “translated.”

    In other words, translation does not merely replace one signifier with another. It has to reconstruct relationships among signs in another linguistic system.

    And that raises another question.

    Are AI-Generated Texts More “Translation-Resistant”?

    From this point on, I am no longer describing a finding from the Villanova study. This is a hypothesis that occurred to me while reading the Japanese translations.

    Perhaps AI-generated prose is not simply easier to read because it is more direct. Perhaps it also tends to preserve its semantic relationships more easily when moved from one language to another.

    Large language models learn from enormous quantities of text. In doing so, they may gravitate toward patterns and structures that recur across many examples of language. That can certainly be a weakness: AI prose can feel averaged out / less idiosyncratic / overly polished / strangely familiar.

    But turn the same characteristic around, and it suggests another possibility: those more widely shared structures may also be easier to carry across languages.

    Human literary writing can derive much of its richness from exploiting the peculiarities of a particular language, culture, voice or network of associations. Precisely because those relationships are so specific, some of that richness may be difficult to reproduce elsewhere.

    AI-generated prose may sacrifice some of that specificity. But could the same sacrifice make it more portable?

    Less dependent on a particular system of signifiers → less lost when those signifiers have to change?

    I don’t know. And the Villanova study does not answer that question.

    Testing it would require a different experiment—one designed specifically to compare how human-written and AI-generated texts behave across translation. But that is exactly why the Japanese version of the article interested me. Translation may have introduced a new variable that the original experiment was never designed to examine.

    The Researchers Themselves Don’t Say “AI Won Because It’s Easier to Read”

    There is another point worth keeping in mind. Popular coverage naturally tends to focus on a simple explanation: AI-generated stories may have been preferred because they were more direct, concise and easier to understand.

    The original paper is more cautious.

    The researchers discuss ease of interpretation as one possible explanation for the higher ratings, not as a conclusion established by the experiments. They also point out an obvious complication: literary fiction is not necessarily “better” simply because it is easier to understand. Ambiguity, complexity and room for interpretation can be part of what gives a story its value.

    The later experiments produced an even more interesting result. Participants who relied on wording as a clue to authorship tended to be worse at identifying whether a story had been written by a human or by ChatGPT. In one experiment, participants who used their own enjoyment of a story as a clue were also more likely to get the answer wrong.

    In other words, an intuition such as “This is easy to read, so it must be AI” may not help us identify AI writing at all. It may even push us in the wrong direction.

    That makes the result more interesting, not less.

    How Long Will “AI vs. Human” Remain a Useful Comparison?

    There is a broader problem with the question itself. In a controlled experiment, separating “AI-written” from “human-written” text makes perfect sense. Outside the laboratory, however, that boundary is already becoming difficult to maintain.

    Consider professional shogi. Today’s top players study moves suggested by AI, including moves that previous generations of human players might have considered unnatural or even poor. They examine the reasoning behind those moves, understand their value, and incorporate what they learn into their own play.

    When a professional later plays such a move in an actual match, whose move is it? The human’s? The AI’s? The question quickly becomes awkward.

    Something similar happened long ago with spreadsheets. Before software such as Microsoft Excel, enormous amounts of human time were spent performing calculations and organizing data manually. Today, we do not normally look at a spreadsheet produced with software and say, “This is not human work because a computer calculated it.”

    The software has become part of the human workflow. Generative AI may be moving in the same direction.

    Human → AI → Human

    Writing is already beginning to look like this:

    A human develops the idea → ChatGPT produces a draft → the human spots what feels wrong → the AI generates alternatives → the human rejects some, keeps others and rewrites the result.

    Who wrote the finished text?

    “The human” and “the AI” are both incomplete answers.

    The more interesting change may therefore be not that AI is becoming capable of writing better stories than humans, but that humans and AI are beginning to alter one another’s output.

    Humans learn from AI. Humans incorporate those techniques into their own writing. AI systems, in turn, learn from human-produced language in an environment that is itself increasingly influenced by AI.

    Human → AI → human → AI.

    Shogi offers an early example of this cycle. What begins as an “AI move” can eventually become part of ordinary human theory.

    If something similar happens to writing, the clean boundary required by the question “AI or human?” may become increasingly artificial.

    Perhaps the more useful question will eventually be not “Who wrote this?”, but “What forces shaped the text that ended up in front of us?”

    English → Japanese (translator unknown) → ChatGPT → English.
    At this point, even Saussure might ask for a system update.😂

  • RansomHouse Leaked 200,000 Files. But Did It Make Any Money?

    RansomHouse Leaked 200,000 Files. But Did It Make Any Money?

    日本語版はこちら

    Ohakonbanichiwa! RYO here from the Dynamics Observation Institute.
    Yes, that means good morning, hello, and good evening — all at once. Very efficient.

    Japanese frozen-food giant Nichirei was hit by a cyberattack that disrupted shipments and other operations.

    The ransomware group RansomHouse later claimed responsibility and reportedly published more than 200,000 files, including documents that may contain personal and business information.

    “More than 200,000 files leaked” certainly sounds alarming. But there is another way to look at what happened.

    What exactly did RansomHouse gain by publishing them?

    Did Nichirei Refuse to Pay?

    There is no public confirmation that Nichirei refused to pay a ransom, nor do we know what negotiations, if any, took place behind the scenes.

    So we cannot say that Nichirei “didn’t pay.”

    What we can observe, however, is the sequence of events.

    Nichirei detected the system failure on July 13, isolated affected systems, worked with external cybersecurity specialists, and subsequently restored normal operations. Meanwhile, RansomHouse continued releasing stolen data, with more than 200,000 files reportedly published by August 10.

    We do not know what happened at the negotiating table. But looking at what happened outside it, one question naturally arises:

    Is this really how RansomHouse wanted things to end?

    Extortion Is Most Powerful Before the Data Is Published

    In double-extortion ransomware attacks, stolen data has value. But perhaps even more valuable is the fact that it has not yet been made public.

    As long as the attacker can say, “Pay us or we’ll publish it,” the data remains a hostage and a bargaining chip. Once the data is published, however, that particular bargaining chip is gone. Publish more, and even more chips disappear.

    The damage to the victim is real, especially when personal or confidential information is involved. But from the attacker’s perspective, there is a strange contradiction: every threat they carry out also destroys part of their own leverage.

    In other words, self-defeating extortion.

    Are 200,000 Files Really 200,000 Valuable Targets?

    The number 200,000 sounds impressive. But 200,000 leaked records do not automatically translate into 200,000 profitable victims.

    If much of the data consists of names, email addresses, phone numbers or business relationships, criminals still have to turn that information into money through phishing, impersonation or fraud.

    Information linking someone to Nichirei may certainly make targeted scams more convincing, so the risk should not be underestimated. But if Nichirei and related companies repeatedly warn customers and business partners about suspicious messages, invoices and payment requests, the success rate of those scams can be reduced.

    Leaked data cannot be taken back. But its value as a criminal commodity can still be reduced.

    Nichirei Paid a High Price — But It Also Gained Experience

    The price Nichirei paid for this incident was undoubtedly high. But the company also gained something that only an organization that has actually been attacked can acquire: real-world experience.

    Business continuity plans, backups and incident-response exercises are essential. But some weaknesses only become visible when systems actually go down.

    Which operations stop? / Who makes the decisions? / How far does the disruption spread? / How quickly can the business recover?

    These are part of an organization’s “shadow” — weaknesses and realities that remain hidden during normal operations.

    If Nichirei turns this experience into organizational knowledge, the next time it faces a cyberattack, it will no longer be experiencing one for the first time.

    That is an asset the attacker cannot steal or copy.

    So What Did RansomHouse Gain?

    Breaking into systems, stealing data, maintaining infrastructure, threatening a victim and eventually publishing the stolen files all require time, skills and resources.

    Again, we cannot conclude that Nichirei refused to pay, nor can we say that the attack was unprofitable.

    Still, watching RansomHouse continue to burn through its remaining cards by publishing more and more data makes it difficult not to wonder:

    “We leaked 200,000 files!”

    Okay.

    But how much money did you make?

    The Best Defense May Be Making Ransomware Unprofitable

    Ransomware defense usually focuses on one question: How do we stop attackers from getting in?

    That is obviously essential. But if ransomware is also viewed as an economic activity, there is another form of defense:

    Make successful attacks unprofitable.

    Recover quickly. / Limit the damage. / Warn potential secondary victims. / Continue operations without depending on the attacker.

    The more organizations can do this, the greater the chance that attackers will successfully break in — and still fail to make money.

    For ransomware operators, that may be almost as damaging as failing to break in at all.

    Break in. / Steal the data. / Disrupt operations. / Threaten the victim. / Leak the files.

    And still make no money.

    That is not just a failed extortion attempt.

    It is a lot of work for nothing.