Europe does not need a weaker digital rulebook. It needs a more constitutionally disciplined supervisory state. Where Union law leaves a regulator a lawful choice among materially different routes, the regulator should be required to identify the rights or safety risk, disclose the evidence and assumptions on which it relies, consider less burdensome rights-preserving alternatives, assess implications for legal certainty, investment and scale, and explain why the selected route is proportionate. The proposal is therefore not a substantive privilege for innovation. It is a meta-duty governing the exercise of discretion: a duty of regard, evidence, and public reason-giving that operates beneath the rights floor and outside individual-case direction.
This article explores the implications of increased reliance on technological solutions to digital regulatory challenges, particularly in Child Sexual Abuse Material (CSAM). It focuses on the contemporary trend of imposing obligations on private actors, such as platforms and service providers, to mitigate risks associated with their services while ensuring the protection of fundamental rights. This leads to new regulatory designs like "safety-by-design," favoured by European regulators due to their cost-effectiveness and efficiency in assigning responsibilities to online gatekeepers. We examine the European Union’s CSAM Proposal and the United Kingdom’s Online Safety Act, ambitious initiatives to employ technology to combat the dissemination of CSAM. This proposal mandates platforms to perform risk assessments and implement mitigation measures against the hosting or dissemination of CSAM. In cases where these measures fail, a detection order can be issued, requiring platforms to deploy technical measures, including AI, to scan all communications. This approach, while well-intentioned, is scrutinised for its potential over-reliance on technology and possible infringement of fundamental rights. The article examines the theoretical underpinnings of “safety-by-design” and “techno-solutionism,” tracing their historical development and evaluating their application in current digital regulation, particularly in online child safety policy. The rise of safety-by-design and techno-solutionism is contextualised within the broader framework of cyber regulation, examining the benefits and potential pitfalls of these approaches. We argue for a balanced approach that considers technological solutions alongside other regulatory modalities, emphasising the need for comprehensive strategies that address the complex and multifaceted nature of CSAM and online child safety. It highlights the importance of engaging with diverse theoretical perspectives to develop effective, holistic responses to the challenges posed by CSAM in the digital environment.
The rapid evolution of digital technologies has outpaced traditional legal frameworks, prompting a fundamental reassessment of regulatory paradigms in cyberspace. Influenced by The Law of the Horse and Lex Informatica, early legal discourse suggested that existing principles could be applied analogously to emerging digital challenges. However, these frameworks have proven insufficient as the Internet transitioned from Web 1.0 to decentralised and algorithmically governed digital ecosystems. This chapter argues that cyber law has now crystallised into a distinct legal domain, necessitated by the inherent complexity and dynamism of digital environments and grounded in the principles of the rule of law. Far from an unregulated frontier, cyberspace has become a battleground of competing regulatory philosophies, where legal authority is contested between state actors, corporate governance structures, and the underlying architecture of code itself. The Anglo-American laissez-faire model, favouring market-driven self-regulation, has been increasingly challenged by interventionist regimes, particularly the regulatory assertiveness of the European Union and China's cyber sovereignty model. This shifting landscape reflects a broader tension between innovation and legal certainty, technological determinism and democratic accountability, and private power and public law. This chapter critically examines the philosophical foundations of digital regulation, tracing how the rule of law is being reinterpreted and renegotiated in response to algorithmic decision-making, platform governance, and the decentralisation of regulatory authority. It contends that the future of digital governance depends on developing a legal framework that is neither excessively rigid nor dangerously fluid: one that preserves fundamental rights, ensures transparency and accountability, and prevents the entrenchment of unaccountable corporate or state power. Ultimately, the chapter advocates for a regulatory architecture that integrates legal, technological, and behavioural insights to navigate the complexities of an increasingly digital society without eroding the foundational principles of justice and fairness.
The term ‘dark patterns’ is commonly used to describe manipulative techniques implemented into the user interface of websites and apps that lead users to make choices or decisions that would not have otherwise been taken. Legal academic and policy work has focussed on establishing classifications, definitions of dark patterns, constitutive elements, and typologies of dark patterns across different fields. Regulators have responded to this issue with several enforcement decisions related to data protection and privacy violations, and with rulings protecting consumers. Accordingly, this article analyses the appropriateness of regulatory oversight of designers and platforms that deploy dark patterns inside digital technologies. By further analysing design techniques, we conclude this type of deceptive design is inappropriately attributed to the user interface when some patterns are embedded in the system architecture. With this in mind, the article also analyses the emerging digital design acquis of the European Union. The Digital Markets Act and Digital Services Act, the proposals for a new Data Act and AI Act are critiqued for suitability of regulating deceptive design over the entirety of, what we coin, the deceptive design visibility spectrum.
The article critically examines the complex interplay between AI-powered deceptive design and legislative responses, mainly focusing on the European Union's AI Act Proposal. The article also emphasises the urgency of addressing the risks posed by AI-powered deceptive design strategies intricately woven into online platforms. These ‘psychological patterns’ mislead users into making decisions contrary to their intentions, exploiting psychological vulnerabilities. The article then explores the potential for regulating these practices under Article 5(1) of the EU's AI Act Proposal. It underscores the importance of safeguarding user autonomy in the rapidly evolving digital landscape. It engages with the dynamics of psychological manipulation, the need for effective regulation under the AI Act, and the critical importance of maintaining user autonomy amidst these technological advancements.
The European Union’s Digital Service Act (DSA) represents an evolution from both the limited liability regime and the self-regulatory approach under which platforms have blossomed. The new regime regulates proactive moderation, including fact-checking. This paper assesses its suitability to do both. The DSA contains obligations for online platforms that incidentally curb the spread of disinformation. While any general monitoring obligation on platforms is prohibited, the DSA hopes that transparency requirements when undertaking content moderation shall reinvigorate trust in the information ecosystem. To achieve this, the regime emphasises the role of risk assessments and risk mitigation measures. It also empowers trusted flaggers and fact-checkers who partner with platforms to delegitimise user-generated content identified as dis- and mis- information.
From advertising targeting users based on analysis of their data to taking advantage of identifiable vulnerabilities to disinformation and manipulative design techniques embedded in user interfaces, attempts to manipulate users for the benefit of commercial or political actors are rife in cyberspace. Responses under human rights law focus on the impact of manipulation on different rights, including privacy and data protection, but fail to provide a holistic framework. Regulators emphasise the need to comply with business obligations in the General Data Protection Regulation (GDPR) or the EU’s consumer law acquis. Because online manipulation can interfere with our mental autonomy, manipulative techniques like computational propaganda or micro-targeted advertising can compromise the right to freedom of thought under Article 9 ECHR. Accordingly, this article sets out how courts can apply the right to freedom of thought to constrain online techniques designed to manipulate users, adding a new tool to the arsenal which regulators can use in the fight against online manipulation.
In online content moderation, two key values may come into conflict: protecting freedom of expression and preventing harm. Robust rules based in part on how citizens think about these moral dilemmas are necessary to deal with this conflict in a principled way, yet little is known about people’s judgments and preferences around content moderation. We examined such moral dilemmas in a conjoint survey experiment where US respondents (N= 2, 564) indicated whether they would remove problematic social media posts on election denial, antivaccination, Holocaust denial, and climate change denial and whether they would take punitive action against the accounts. Respondents were shown key information about the user and their post as well as the consequences of the misinformation. The majority preferred quashing harmful misinformation over protecting free speech. Respondents were more reluctant to suspend accounts than to remove posts and more likely to do either if the harmful consequences of the misinformation were severe or if sharing it was a repeated offense. Features related to the account itself (the person behind the account, their partisanship, and number of followers) had little to no effect on respondents’ decisions. Content moderation of harmful misinformation was a partisan issue: Across all four scenarios, Republicans were consistently less willing than Democrats or independents to remove posts or penalize the accounts that posted them. Our results can inform the design of transparent rules for content moderation of harmful misinformation.
'Dark patterns' are defined as ‘tricks used in websites and apps that make you do things that you didn’t mean to, like buying or signing up for something.’ The term describes ‘deceptive’ and ‘manipulative’ techniques implemented when designing an app, website, or platform to change a user’s behaviour in a way that would not have happened without the dark pattern. Yet much of the academic scholarship on the regulation of manipulative design has focused on privacy and data protection legislation. This article identifies seventeen common types of ‘dark patterns’. It facilitates critical, legal, and regulatory dialogue by proposing a new taxonomy consistent with the relative provisions of the Unfair Commercial Practices Directive (UCPD). Critical analysis of three respected dark patterns taxonomies provides the basis for analysis of the protections provided to consumers by the UCPD. This approach focuses on the category of dark patterns we refer to as relying on ‘Information Asymmetry’ and an analysis of practices we identify as causing ‘Free Choice Repression.’ The article closes with policy recommendations to improve the regulation of dark patterns for commercial purposes.
This paper introduces RiskCards, a framework for structured assessment and documentation of risks associated with an application of language models. As with all language, text generated by language models can be harmful, or used to bring about harm. Automating language generation adds both an element of scale and also more subtle or emergent undesirable tendencies to the generated text. Prior work establishes a wide variety of language model harms to many different actors: existing taxonomies identify categories of harms posed by language models; benchmarks establish automated tests of these harms; and documentation standards for models, tasks and datasets encourage transparent reporting. However, there is no risk-centric framework for documenting the complexity of a landscape in which some risks are shared across models and contexts, while others are specific, and where certain conditions may be required for risks to manifest as harms. RiskCards address this methodological gap by providing a generic framework for assessing the use of a given language model in a given scenario. Each RiskCard makes clear the routes for the risk to manifest harm, their placement in harm taxonomies, and example prompt-output pairs. While RiskCards are designed to be open-source, dynamic and participatory, we present a "starter set" of RiskCards taken from a broad literature survey, each of which details a concrete risk presentation. Language model RiskCards initiate a community knowledge base which permits the mapping of risks and harms to a specific model or its application scenario, ultimately contributing to a better, safer and shared understanding of the risk landscape.
On September 28, 2022, the EU Commission published the first draft of its package to harmonise and reform liability rules in relation to damages caused by AI. The package also deals with liability issues in relation to the circular economy and pharmaceutical products, but for the purposes of this overview, we will primarily focus on those provisions regulating damages deriving from AI systems, smart and digital products, and software in general.The package is the result of roughly four years of work by the EU Parliament and the Commission, comprised of reports from internal and external experts (such as the Expert Group on Liability and New Technologies from DG Justice) and consultations with stakeholders.The package is composed of two drafts: the Proposal for a Directive of the European Parliament and of the Council on adapting non-contractual civil liability rules to artificial intelligence (AI Liability Directive), and the Proposal for a Directive of the European Parliament and of the Council on liability for defective products, this latter repealing Directive 85/374/EEC (Product Liability Directive or PLD). The AI Liability Directive and the new PLD should be seen as complementary to the proposal for the AI Act, which regulates the design, implementation, and use of AI systems.
[This paper is now published here: https://doi.org/10.1073/pnas.2210666120. Please refer to and cite the published version. The preprint is not updated. ]When moderating content online, two key values may come into conflict: protecting freedom of expression and preventing harm. Robust rules based in part on how citizens think about these moral dilemmas are necessary to deal with the unprecedented scale and urgency of this conflict in a principled way. Yet little is known about people's judgments and preferences around content moderation. We examined such moral dilemmas in a conjoint survey experiment where respondents (N = 2,564) indicated whether they would remove problematic social media posts on election denial, anti-vaccination, Holocaust denial, and climate change denial and whether they would take punitive action against the accounts. Respondents were shown key information about the user and their post, as well as the consequences of the misinformation. The majority preferred quashing harmful misinformation over protecting free speech. Respondents were more likely to remove posts and suspend accounts if the consequences were severe and if it was a repeated offence. Features related to the account itself (the person behind the account, their partisanship, and number of followers) had little to no effect on respondents' decisions. Content moderation of harmful misinformation was a partisan issue: Across all four scenarios, Republicans were consistently less willing than Democrats or Independents to delete posts or penalize the accounts that posted them. Our results can inform the design of transparent rules of content moderation for human and algorithmic moderators.
"Dark patterns" is a generic term used by the design community and an increasing number of data protection academics to describe a variety of manipulative design techniques that compromise legal requirements like consent and privacy-by-design and legal principles like fairness and transparency. To assess the regulation of dark patterns, two legal frameworks of the European Union are compared and critiqued: first, an examination of relevant rules and principles of the General Data Protection Regulation (GDPR) leads to the conclusion that the principle of data-protection-by-design could be useful, but the lack of clarity about what constitutes fairness undermines the GDPR's ability to regulate dark patterns. Second, an examination of the 'fairness' principle in the EU's consumer protection acquis reveals a significantly further developed regime. After examination of the various enforcement mechanisms across both regimes, the Chapter concludes that a pluralistic approach that mixes the strengths of one regulatory regime while compensating for the weaknesses of the other is needed to harness manipulative design techniques like dark patterns.
In April 2019, the UK Government’s DCMS released its White Paper for ‘Online Harms’, which would establish in law a new duty of care towards users by platforms to be overseen by an independent regulator. Our earlier research outlines how we got to this point, sets out what the White Paper proposes, and criticises its key aspects. Our objections and criticism remain applicable to the UK Government’s Online Safety Bill. The Parliament is now scrutinising the Bill. The House of Lords Report sparked some optimism that the scrutiny could address critical concerns around free speech in particular. The Draft Online Safety Bill Joint Committee Report, however, suggest otherwise. This paper returns to key arguments as to why risk-based regulation and duty of care are not appropriate for policing content and expression online. We focus on the human rights implications of the Bill, in particular, the provider duties to ‘handle’ legal but harmful content. Here, we reemphasise the vague conceptualisation and nature of this harm, as well as the inadequate duties attached to it. We argue that the independence of OFCOM cannot be guaranteed.
This report is the second output from the Joint Research Centre’s (JRC) Enlightenment 2.0 multi-annual research programme. The work started with the classical Enlightenment premise that reason is the primary source of political authority and legitimacy. Recognising that advances in behavioural, decision and social sciences demonstrate that we are not purely rational beings, we sought to understand the other drivers that influence political decision-making. The first output “Understanding our political nature: how to put knowledge and reason at the heart of policymaking” published in 20191, addressed some of the most pressing political issues of our age. However, some areas that we consider crucial to providing an updated scientific model of the drivers of political decision-making were not fully addressed. One of them is the impact of our contemporary digital information space on the socio-psychological mechanisms of opinion formation, decision-making and political behaviour. The JRC, together with a team of renowned experts addresses this knowledge deficit in a report that synthesises the knowledge about digital technology, democracy and human behaviour to enable policymakers to safeguard a participatory and democratic European future through legislation that aligns with human thinking and behaviour in a digital context. It is hoped that this report will prove useful as policymakers reflect upon the forthcoming European Democracy Action Plan, the Digital Services Act, the EU Citizenship Report 2020, as well as on how to legislate against disinformation. The report has been written in spring/summer of 2020 when the COVID-19 pandemic took hold of Europe and the world. During this time, our democracies suffered while technology played a crucial role in keeping societies functioning in times of lockdown. From remote distance education to teleworking, religious services to staying in touch with family and friends, for many but not all, everyday activities moved online. Additionally, technological applications and initiatives multiplied in an attempt to limit the spread of the disease, treat patients and facilitate the tasks of overworked essential personnel. Conversely, however, significant fundamental rights questions have been raised as unprecedented initiatives to track, trace and contain the pandemic using digital technologies have proven controversial. Governments invoking emergency measures in support of public health decision-making, used advanced analytics to collect, process and share data for effective front-line responses that lacked transparency and public consultation. When used as an information source, social media have been found to present a health risk that is partly due to their role as disseminators of health-related conspiracies, with non-English language speakers being at greater risk of exposure to misinformation during the crisis. It is likely that these technologies will have a long-lasting impact beyond COVID-19. Yet despite the immediacy of the crisis, the authors invite the reader to take a longer perspective on technology and democracy to get a deeper understanding of the interrelated nuances. In dark times, we seek to bring light to the importance of understanding the influence of online technologies on political behaviour and decision-making.
The British and Irish Law Education Technology Association (BILETA) was formed in April 1986 to promote, develop and communicate high-quality research and knowledge on technology law and policy to organisations, governments, professionals, students and the public. BILETA also promotes the use of and research into technology at all stages of education. The preparation of this response has been funded by BILETA.
Nowadays, children grow up in a commercialised environment, where they are confronted with advertising and marketing on a daily basis. From a very young age, they already display a level of brand consciousness. Aside from being an attractive target group for advertisers – as they can purchase products or services themselves and have an important influence on their parent’s purchasing behaviour – brands are now increasingly relying on child-influencers to promote goods and services for them. The child-influencer phenomenon raises important questions from a children’s rights perspective and necessitates a detailed study of the benefits and potential harms to the child. This chapter takes a novel approach by not only critiquing the advertising and marketing rules for gaps, shortcomings and failures in light of children’s rights, but also analysing the role of the child in the constellation of influencer regulation through the lens of labour law and protection of vulnerable consumers.