Speaker 0
0:00 – 0:24
Welcome to CDT's tech talks brought to you by the Center for Democracy and Technology, US and Europe. This week, we're continuing our special series of conversations bringing together policy experts from both CDT Europe and CDT US to discuss how digital rights issues are unfolding from both sides of the pond. I'm Aimee Dupre Maciell, and it's time to Talk Tech.
Speaker 1
0:25 – 0:28
Welcome to Tech Talk. Bye.
Speaker 2
0:29 – 0:29
Today's
Speaker 0
0:30 – 1:12
Today's episode is about online protection of minors and how regulators, platforms, and civil society are navigating the complex line between protecting rights and preventing harm, particularly particularly when it comes to younger users. To talk through it, we're joined by David Klotzonis, deputy director at CDT Europe, and Aliyah Bhatia, senior policy analyst at CDT US. They work on very similar issues but across different political and regulatory environments. And they also happen to know each other pretty well, so this will be a lively one. Let's jump in. Hi, David. Welcome to the DC office. How was your trip into DC? It
Speaker 2
1:12 – 1:16
It was good. Surprisingly smooth. It was only a seven hour flight, and,
Speaker 1
1:17 – 1:27
Emma and I both passed out within the first five minutes. That was great. Perfect. So today, we're in The US office talking about our favorite topic that we usually reserve for our Zoom conversations.
Speaker 2
1:28 – 1:56
Indeed. Yeah. This is an interesting topic because, in general, there isn't a whole lot of common threads between the EU and The US when it comes to digital policy these days. But one thing that people are concerned about on both sides of the Atlantic is child safety. And I know that you recently had a podcast where you touched on some of the issues, but, yeah, I'd be curious to hear a little bit more. Specifically, what are the child safety safety initiatives coming up in The US at the moment?
Speaker 1
1:57 – 4:17
Yeah. So I think for the last few years, we've seen kid safety become the preeminent sort of platform governance question in both the federal level and the states. Especially at the state level, I think we're seeing a lot of traction, potentially because a lot of legislators don't see the congress as the place where a lot of bills are moving. But I would create, like, a little bit of a taxonomy of, like, what the specific child safety proposals we're seeing. I think one of the collection of bills we've seen are related to privacy related harms, interested in limiting data collection on of minors' data, and also limiting the use of minors' data. And then also in the in that collection of bills, we've seen efforts to ban targeted advertising for those 18. An example of this is, COPPA two point o by senator Markey's office, which is trying to extend COPPA protections to those 15 as well as just those 13. We're seeing a lot of bills interested in regulating the design and provision of design features. That's Kids Online Safety Act, the Kids Off Social Media Act, the various age appropriate design codes in, across The States, and then also the one that was first passed in The UK. And I think those raise trickier content related questions and has been the subject of a lot of lobbying and litigation already. We're also seeing bills ban social media or certain features entirely for certain minors, so that's true. And the Kids Off Social Media Act where the sponsors are interested in having platforms apply their terms of service by restricting those 13 from accessing social media and then also banning certain addictive features or, recommendation systems for those 16. And that's similar to, for example, the law that was passed in New York, the Safe for Kids Act, which also bans certain recommendation systems and other addictive features. And I believe there's one also in Nebraska now that's been proposed. And then finally, I know that we're gonna touch on this throughout the conversation, but we're seeing a lot of age assurance and age verification related builds that are imposing requirements for both services, app stores, and even devices like in Idaho that seek to propose means or incentivize the use of some sort of age assurance mechanism.
Speaker 2
4:17 – 4:49
Right. So that's really interesting. And from the overview that you just gave, which is really useful, what I'm picking up on is that there's really different kinds of problems that people are seeing with online platforms and different forms and different services. And there's also, therefore, like, a variety of ways to address them. Could you talk a little bit more about, like, what are the main harms that people are seeing online? Mhmm. Yeah. You know, I think that's, like, touching on a pet peeve of mine I've had of I wish we were able to desegregate the harms that we're seeing.
Speaker 1
4:49 – 6:35
I think we think of kid safety as a self evident harm or or Right. The risks to kids as self evident harms, but the harms are very specific. Right? And I think it goes into, some of the research we've seen by child rights groups including and and child rights experts including Sonia Livingston, for example, at LSC, where, you know, the harms for users really depend on a lot of different things. Content related harms, so exposure to content that can be harmful to some and not harmful to others is very both unique to the content, unique to the delivery mechanism of the content, and then you unique to the child themselves who then exists in their own unique sort of family context, socioeconomic context, etcetera. I I see privacy harms as a bucket of harms that are sort of either under discussed or conflated with a lot of other harms. So, specifically, the harms posed by misuse of data collected on vulnerable populations. You know? What happens if data is collected on a minor but then used to deliver enticing content or used to target a child offline. So I I you know, those are some examples of harms, I think. And then I think another category that we might talk about and policymakers are really interested in is this category of harms related to compulsive use. Right. So this idea that kids are spending more time than they want to spend or they should spend. And that, again, raises questions about, like, regulator intervention, but I think that's another category of arms. What are you seeing in the EU context? So the EU context is in some ways different and in some ways similar.
Speaker 2
6:36 – 11:26
You mentioned, data privacy concerns and obviously the EU or maybe not so obviously for listeners in The US side, but, the EU has this general data protection regulation, which has been enforced now for several years, and that's kind of the foundation for a lot of the other digital laws that are being developed and enforced at the moment. One of the main tools through which, the Internet is being regulated in in the EU when it comes to online platforms is through the Digital Services Act. And the Digital Services Act has a specific article, Article 28, which deals with the online protection of minors. Now what is interesting about this piece of regulation is that it has what is called a risk based approach. So when the legislators were negotiating the law, they very quickly realized that the kinds of challenges that arise from these online services are developing so quickly that it's very difficult to have a fixed set of rules that address all harms. And so there has to be some level of flexibility in the law. And so essentially, what that means is that a lot of the responsibility is actually on the platforms to assess risk and then find ways to mitigate it to make their platforms, safer. This is the the general architecture or the philosophy, if you will, of the law. And then another distinction and something that makes this law a little bit unique in the digital space is that it has this tiered approach where the size and impact of a platform is proportionate to the amount of obligations that it has to abide by. So if you're a very small platform, you have, like, a few obligations. If you're a medium sized platform, you have a few more. And if you're a so called very large online platform or search engine, which means that you have around about, 45,000,000 active monthly users in the EU, then you have the most obligations. And what we see very often is that when people are talking about child safety or or protecting, young people online, they're mostly referring to, like, those those big platforms. Right? And so the European Commission recently, issued guidelines to sort of detail exactly what they understand by protecting young people online under Article 28. And it's a it's a pretty extensive, set of guidelines. And what I think is interesting is that, of course, it touches on the thing that you're things that you already mentioned in terms of, like, you know, how to, avoid harmful content. But it also focuses a lot on the design of these platforms. So there's this notion of, like, safety by design. Instead of trying to correct things after the fact, you try to design them from the beginning in a way that they're actually safe for young users. And one thing in particular relates to what you mentioned before, which is recommender systems. Right? Because recommender systems are at the heart of how so many of these online platforms actually function. And so most recommender system algorithms are optimized for engagement, meaning that they try to see what users engage with the most through comments, through likes, through other signals, and the algorithm gets trained over time to show them more and more content, that will keep them engaged and therefore on the platform. And so one innovation of the guidelines is that it tries to promote alternative ways of designing algorithms in a way that are not based solely around engagement, but rather, provide the opportunity for some kind of, like, personalization on behalf of the user. So this is a really exciting opportunity because it could provide young people with a chance to actually, like, tailor their online experience a little bit more, give them, more choices, and therefore empower them. And it's something that I personally find very interesting. Now that's on the European Commission level. At the same time, protecting young people online has been gaining a lot of political traction also at the national level, so what we call, member states of the European Union. And there we have seen a variety of different approaches being put forth, and I'm not gonna go too much into detail as to all the different proposals that are on the table. But suffice to say that many member states actually want to ban access to social media platforms altogether. And so it's unclear exactly what shape this will take, as I said. But it's a sort of conversation that is happening at two levels now between the European Commission itself and existing digital rules, and then proposals by member states, which are sort of more sweeping black and white approaches rather than the the nuanced approach of, the guidelines themselves.
Speaker 1
11:27 – 12:54
That's really fascinating. And, you know, I think from the side of the Atlantic and DC, I've seen a couple of the headlines about member states wanting to restrict access to social media for teens. And I think one question I've had in my mind is, like, how are users gonna respond in those jurisdictions? I mean, obviously, not in Europe, but in Nepal and Morocco, we've already seen, like, sort of Yeah. The, quote, unquote, Gen z protests opposing sort of onerous restrictions. So curious to see how that goes from a user perspective. I really, was intrigued by your comments related to recommender systems. Like, what is possible there? And our colleague, Mikhail Luria, has done a little bit of research both with adults, but also specifically teens on what controls they'd like with their recommendation systems or to to shape their recommendation systems, ultimately leading to a conclusion that, like, there's interest to express preferences or express you know, have levers to say this is the type of content I'm interested in. Because I think everyone who's listening or at least just me has had the experience of watching one video and then being like, okay. I actually never wanna see a video like that ever again. You know? You just kinda fall into whatever. So, yeah, is that something that's being talked about in expert conversations or in in policy conversations? Yeah. So there's an excellent report by the Knight Georgetown Institute called the Better Feeds Report,
Speaker 2
12:55 – 15:16
which looks at this. And so the conversation on recommender systems is often presented as a false dichotomy between having, you know, personalized feeds based on engagement, which are super interesting and you want to use them all the time. And then on the other hand, you have, like, you know, the option of going back to chronological feeds the way you we had them, like, some years ago, which are inevitably dull. And, you know, if you are following a lot of people, it just don't really work. And it really doesn't have to be that way, and this is why this report is so interesting because it sort of gives alternatives. One way to do that to do that is through explicit user signals. Right? So, like, instead of assuming what the user wants to do or instead of assuming, like, having an algorithm essentially guess what a user wants to see, you can ask them, and then they can tell you. And sort of like what what you just said, like, you know, you see a piece of content that you don't like, you should have the option to say, like, oh, I never want to see this type of content again and have that actually work. There's a lot of different kinds of, user options that the that the report goes into, and I encourage people to to have a read. And this also gives me the opportunity to mention that there's a lot of small tweaks that can be made to platforms to make them overall safer. The important thing, however, is to have those options by default because we know that friction online can be a huge hurdle. We've seen that, for example, in The EU with cookie banners, like, people get what is called clicking fatigue. They don't want to, like, not accept the cookies anymore. But if only it had been turned off by default and then you had to activate it, then, well, then most people obviously, would never would never go into the settings and deactivate that. So there's really, like, a variety of ways that you can tweak a platform, and it can have a huge impact. And in the context of their commander system, the position of the European Commission seems to be that by allowing users, in this case, young users, to have more control over their algorithms, you're really killing two birds with one stone. Because on the one hand, research is showing that they will eventually be exposed to less harmful content, and they're also less likely to go into so called rabbit holes of harmful content. But on the other hand, you're also mitigating for the risk of them engaging in, quote unquote, addictive behaviour.
Speaker 1
15:16 – 15:52
So that I think is something that's, that's really exciting. Yeah. And it also feels more dynamic. So for example, if I'm, you know, facing a situation in my life where I don't wanna see content that negatively harms me. Right? Health related content or something like that. I have the choice to expressly say I don't wanna see this type of content or put in a keyword. I would love, like, a paradigm where there's, like, a keyword filter for, like, I don't wanna see this word. And and I I think it could help teens as well. You know, teens are quite malicious to each other, especially as they get older. You know, this is a specific
Speaker 2
15:53 – 17:25
slur that's being targeted at me, and I don't want that to see that online. Yeah. I guess there's a bit of an elephant in the room because in order to protect young people online, you need to know who is young. Right? And this is a surprisingly difficult thing to do because of the way that we've been using the Internet for the last, I don't know how many years, thirty years. So the general practice of getting someone's age online is called age assurance, and this is separated into two main, approaches. The first one is called age verification, and the second one is called age estimation. And as the names imply, age verification is a category of techniques where you are basically a 100% sure of the person's age, and this often includes some kind of ID check or something equivalent. And age estimation is instead kind of getting pretty close to being sure depending on the technique, but not being a 100% sure. And this would include, like, you know, collecting some biometric data, either a picture of your face or sometimes a voice recording or using data that the platform has already collected about you to make an inference about your age. So this is a bit of a contentious topic, but I think it's important to talk about it. And in particular, the different risks that are associated with the existing technologies when it comes to estimating and verifying users' age. Can you tell us a little bit more about that? Yeah. So I think you set this up really well to say that how the
Speaker 1
17:26 – 23:16
widespread implementation of age verification and age assurance technologies writ large are going to be fundamentally changing the way we access Internet the Internet today. We're very used to accessing online fora or search engines or many, many websites without logging in. And this is gonna require handing over more information about ourselves, whether it's collect it's it's provided expressly or it's sort of inferred, through other data sources so that online services that have those, obligations imposed upon them can estimate or verify your age. So I think it's really important to set us up by saying age assurance technology is gonna change the way we access the web or deployments of age assurance. And number two, that it's going to change the way we access the web for everyone. Right? Like, a website or app store can't, you know, guess the way a bartender can if you're above 30 or not or if you're clearly an adult or clearly a child. And so because the browser can't or because the service can't guess that, it will require the collection of data or at least the processing of data on all users. Now age assurance is sort of, like, you know, the cat's out of the bag a little, and so a lot of CDT's work has been not only surfacing the risks of these approaches, but also talking about how they can be deployed in ways that mitigate risks to rights. The risks to rights are sort of in two main buckets. There are some privacy risk that emerge just due to the requirement to collect and process more user data. So as you said very clearly and correctly, age verification is usually the use of mechanisms that collect more hard identifiers of identity and age, so a driver's license or a government document or a birth certificate, for example. And then age estimation sort of uses other proxy or biometric data. I like to call age estimation a little bit of more, like I like to, like, pose a little controversial banner on top of it and call it more, like, experimental tech. Even the white papers sort of produced by a lot of age estimation providers have sort of laid bare the error rates off a lot of these technologies. And while they are sort of technically impressive, and are able to estimate age, you know, maybe at, like, 89% of the time or even 90% of the time at the scale at which they're operating, the error even a single digit error is going to gate many, many thousands, if not hundreds of thousands of users from frictionless access to online services and also the content that they host. And, you know, we have a blog post on CDT website that talks about how age estimation becomes verification for many users. Right? Right? Let's say you are misclassified by a biomet a face scanning estimation mechanism. You will have to prove your age by providing more data. This disproportionately affects people of color. Some white papers produced by age estimation providers has suggested that women of darker skin tones are most erroneously classified by, estimatory age technologies. This is similar to in other facial recognition context as well, so this is not new. But a lot of other groups are also affected. You know, people with disabilities, especially young people with disabilities are often especially those who have disabilities that make them look, younger or older than they are can be sort of chronically misclassified estimatory technologies. A lot of gender non conforming people or people who have transitioned, can also not be immediately recognized correctly. And I think we just saw, you know, how the sort of privacy harms of so called privacy preserving age estimation technologies can still be great. Just a few weeks ago, we saw a data breach of Discord and its third party customer service provider leak many scans many people's, driver's licenses and also face scans all across the Internet and made it available to others. And those people were providing their government IDs to correct misclassifications made by their age estimation technology. All to say, those are a few examples that suggest there's a great deal of privacy harms that are posed by these technologies. And then there's also a lot of speech and free expression related harms because, number one, requiring people to show or provide data in order to access content on the Internet rids them from the ability to access it anonymously. So if I'm going on a search engine to search for information about domestic domestic violence or reproductive care, I'm probably not gonna desire sort of that those searches to be linked to who I am as a person. It could pose risks to my livelihood and my safety offline. And so we are potentially creating a trove of data that is really appealing for bad actors to access and also just chilling people's desire to access sensitive information by requiring them to identify themselves. So those are a few examples of the risks. We've documented them a lot on our website. And and, you know, I think it's important to shout out our colleague, Nick Doty's work here. You know, privacy preserving alternatives do exist, and, you know, one approach is has gained momentum in California, where the digital age assurance act was just signed by governor Newsom that sort of proposes the use of a signaling based approach. So age related information can be provided by a user and then is shared or transferred between intermediaries using signaling and using a very secure cryptographic form. So there are approaches that work. David, I know in Europe, this conversation is, like, live. What's going on? Right. Yeah. Speaking of approaches that maybe will work,
Speaker 2
23:17 – 26:09
in the EU, essentially, credit where credit is due, the European Commission has at least thought of many of the risks that you're talking about. And they're explicitly addressed in in the guidelines that I mentioned previously in the context of the DSA. I'm gonna gloss over a lot of nuance and a lot of detail just because there's a lot there. But just to say that one of the core principles that drive, like, age verification and age estimation in the way that they're outlined in the guidelines is that they have to be, you know, appropriate and proportionate, and they have to respect the privacy of children also under the general data protection regulation. And also they have to be secure. The EU's solution to this is essentially to have an EU wide age verification system, which is private and secure and sort of cryptographically airtight, and it will work in conjunction with the EU digital ID that is being developed at the moment. So the technical specifications for this were recently published, and we're still waiting to see what the feedback on that is at a at a very technical level. There seems to be some kind of hope that, the technology is there to provide a solution that is secure and private enough, but also inclusive to overcoming of the hurdles that you mentioned about accessibility. Now whether that will be the case in practice remains to be seen, and there are valid questions both regarding the technology, but also the deployment of this solution. But I think what is even more important, to me as an adult user is that this whole debate on age verification and age assurance really stems from the fact that young people should have access to, like, a safer Internet. And where whereas I I can I can agree with, like, part of that sentiment, I also want many of those features for myself? I'm no longer a kid, but I I think a lot of people experience harms online even after, the age of 18 or whatever age the the limit is set at. And if we focus too much on making the Internet safer for young people, we risk forgetting that the same harms actually also impact adults. And, for me, that's the real takeaway from this conversation. I think for a lot of platforms, it is likely convenient to tick the box of, you know, online safety for young people, because it might be easier to do that than to really try to make their platforms, safer and better for everyone. And so it would be a real shame if we managed to get, like, some improvements for young people, but then the day that they turn 18, they're all of a sudden exposed to a variety of harms. So yeah. I would love
Speaker 1
26:10 – 26:41
a ton of the user controls that are proposed in a lot of The US and Europe legislation to control your own feed. I feel like we're living in a time of, like, very concentrated, big social media platforms, and it'd be cool to, like, go back to the, like, open Internet principles that, like, sort of shaped our early Internet days. Yeah. Millennial nostalgia there. I know. Some millennial nostalgia to end the podcast. So, yeah, David, what should we do you have a recommendation of one thing we should read on that you and your team have put out?
Speaker 2
26:42 – 27:18
So I think you already mentioned a variety of resources on the CityT website, pertaining to age verification and age estimation, but also just online safety more broadly. The CityT Europe office has also responded to the guidelines on the online protection of minors that I referred to earlier, and we also submitted comments while the guidelines were being developed. And in terms of other resources, feel free to also read KGI's Better Foods report, which goes into a lot more detail than I was able to in the course of this conversation. Is there any more resources you'd like to Yeah.
Speaker 1
27:18 – 27:51
Highlight? Yeah. I'll just shout out a recent blog post that my colleague Nick and I just put out with extensive input from a lot of our colleagues on mitigating some of the risks to rights that come up with deployments of age verification and privacy and rights respecting safeguards look like with deployments of age verification. I think it's hopefully a very helpful read for all, including policymakers and enthusiasts. But, yeah, I think that's that can be found on our website. But, yeah, I think that's that can be found on our website. But thank you, David. This was fun and, great to do this in person as well. Of course.
Speaker 0
27:53 – 28:14
That's it for today's episode of Tech Talks. Check out more of CDT's work by visiting us online at cdt.org and cdt.orgeu. You can also find us on various social media at sendemtech, that's c e n d e MTech and CDTEU. Thanks for listening and see you next time.