Science, Innovation and Technology Committee
Oral evidence: Social media, misinformation and harmful algorithms, HC 441
Tuesday 29 April 2025
Ordered by the House of Commons to be published on 29 April 2025.
This evidence session includes content that some may find distressing.
Members present: Chi Onwurah (Chair); Emily Darlington; Dr Allison Gardner; Tom Gordon; Kit Malthouse; Steve Race; Adam Thompson.
Culture, Media and Sport Committee member present: Paul Waugh.
Questions 249 - 342
Witnesses
I: Mark Bunting, Director, Online Safety Strategy Delivery, Ofcom; and John Edwards, Information Commissioner, Information Commissioner’s Office.
II: Baroness Jones of Whitchurch, Member, House of Lords; and Talitha Rowland, Director for Security and Online Harm, Department for Science, Innovation and Technology.
Written evidence from witnesses:
Witnesses: Mark Bunting and John Edwards.
Q249 Chair: Welcome to the Science, Innovation and Technology Committee. This is the fourth and final session in our inquiry into social media, misinformation and harmful algorithms. I particularly welcome Paul Waugh, who is joining us from the Culture, Media and Sports Select Committee—guesting, as we say.
I give a particularly warm welcome to our two panellists here today. We have John Edwards, the Information Commissioner, and Mark Bunting, the director of online safety strategy delivery at Ofcom. I should declare that Mark and I worked together at Ofcom many years ago, before I was a Member of Parliament. Since then, Mark has worked elsewhere and is now back at Ofcom.
This is a question to both of you, starting with Mark. When I worked at Ofcom, BT was our biggest regulated entity, with a market capitalisation of about £10 billion. Ofcom’s budget was £140 million. Now, from what I can calculate, Ofcom and the ICO’s combined budget is about £300 million but you are regulating absolute giants such as Meta and Google, with market capitalisations of $1.3 trillion and $1.9 trillion respectively. We often felt outgunned by the big players. How do Ofcom and the ICO manage their resource imbalance with big tech?
Mark Bunting: Thank you, Chair, for the opportunity to come and talk to the Committee today. It is a very good question. To add slightly to the challenge, of course we are at the start of a journey of regulating firms that have only recently been regulated in this way. The UK has one of the earliest and, I think, most comprehensive set of rules regarding online safety in the world. Other regimes are in place, but all of them have emerged in the last few years. We are in the early phases of what will be a lengthy journey of transforming the accountability of tech firms for the safety of their users.
You asked about our resources, Chair. We have particularly invested in developing relationships with the biggest firms that you mentioned, as well as some of the smaller and riskier firms. We have developed a technology team, which is about 40 people strong, and we have about 70 people in our supervision unit. We have a dedicated enforcement team and a dedicated legal team supporting the regime.
Our great advantage lies in two things. First, the legislation is very clear about what it expects companies to do. It has empowered us to set out more detail about what is required by companies to keep their users safe, with very extensive powers to request information from them to check whether they are doing the job effectively. The other advantage is that we are part of a much broader regulatory environment, including close working with the ICO, as well as with our international counterparts who very often are engaged in work to try to achieve the same outcomes as us.
I don’t think we are under any illusions about the scale of the challenge. It is a challenge for the industry in the first instance, who have to demonstrate that they are taking user safety more seriously than they have done in the past. We feel confident that we have the resources that we need to make a difference.
Q250 Chair: Thank you very much, Mark. We will come back to questions of clarity in the legislation and engagement with the big tech companies. John Edwards, what is your view on the disparity in resources between yourselves and the big tech companies?
John Edwards: It is a very real issue. It is even more pronounced with the ICO because we are a whole-economy regulator and not just a sectoral regulator. We have responsibility for any transaction involving personal data with a controller or processor, wherever that may be in the economy. It includes schools, GPs, pharmacies and hairdressers, as well as the large international platforms that you mentioned.
We have to be very selective about where we intervene. We act on a spectrum. My regulatory philosophy is informed by the truism that the single most important determinant of compliance with regulation is ease of compliance. We have put quite a lot of emphasis on providing clarity to businesses, including big tech firms. We sometimes make the mistake of assuming that, with all those trillions of dollars, they are right across all the regulatory regimes of the different jurisdictions in which they operate, but it ain’t necessarily so.
We need to set our expectations. We do that in guidance and in policy statements; and, like Ofcom, we engage with the platforms. I think I will have the opportunity later in the session to explain some of the impact that we have had in engagement with those platforms. We deploy our enforcement and investigative tools in a way we hope will have the greatest impact. I think the underlying assumption of your question is correct, though. If we were to have a very aggressive investigative and enforcement approach with those platforms, chasing after every passing car, we would be tied up in litigation and in fact be unable to achieve anything.
Q251 Chair: Are you concerned about their litigator capabilities? We have heard concerns expressed that both Ofcom and the ICO are reluctant to take on the big tech companies because of their ability to call for judicial review. Are you concerned?
John Edwards: No. We have a rules-based society. As a statutory organisation, I am accountable to Parliament and to the courts. Organisations in respect of which we intervene are entitled to avail themselves of all the legal remedies that the legal system presents. That is just our operating environment and I won’t complain about it. There are examples where parts of the system impede our ability to intervene in a timely way. I can give some examples of that if it would be of interest to the Committee.
Chair: Briefly.
John Edwards: Sure. One of the first actions I took when I became commissioner in 2022 was to confirm a notice of intention to fine Clearview AI for its processing of data of UK citizens. I issued a fine of £7 million. Clearview appealed that, as it was entitled to do, to the first-tier tribunal. The matter was decided on a point of law that we thought warranted further exploration, so we lodged a notice applying for leave to appeal. It took the tribunal one year to consider that application for leave. We have not yet got a hearing date for that appeal. If we succeed in the appeal, it may be remitted back to the tribunal for a further hearing. It is very unlikely that I will see that matter concluded in my five-year term.
Q252 Chair: That is very interesting. You have both talked about engaging with the big tech companies. I know, Mark Bunting, that organisations have tried to get a list of that engagement—which companies you are meeting and how much time you spend with them—through freedom of information requests and other means. Why have you been reluctant to share that information? Are you committed to transparency when it comes to engaging with tech companies?
Mark Bunting: We are committed to transparency about the impact that we think regulation is having and the problems that we are trying to address. As a general rule, I don’t think it is advisable for us to give a running commentary on conversations with individual companies. That can make it harder to—
Q253 Chair: Not a running commentary—just to know who you are meeting when.
Mark Bunting: We are still working through how we share with stakeholders the work in progress that we are doing. We completely understand the interest in seeing that. Of course, it is particularly important to us that we get insight from civil society organisations and other expert bodies to inform that process, so that we have the best possible evidence to engage the companies that we are talking to. Finding the right way of doing that without revealing details of confidential conversations or putting out statements that are so bland that they don’t add much value is something that we are still working through.
Chair: Perhaps you could write to us to say why you are not able to say what companies you have met.
Q254 Kit Malthouse: Obviously, these organisations deploy their firepower not just through litigation or their engagement with you; they do so through the PR battle that they fight, both with politicians and online. Given that they control much of the perception of the British people, and therefore in battles that stray into politics, they have an influence. Do you monitor that activity? Does it concern you? For example, if Government Ministers or other politicians are receiving hospitality or having meetings with these organisations, and that then influences future policy or indeed the Ministers’ discussions with you, is that monitored, registered and of concern?
Mark Bunting: We monitor what companies say about the things that we are responsible for holding them to account on. In that area, we are extremely interested in their public statements, and we follow them very closely. We always want to see that the things they say in public are matched by real action behind the scenes. Equally, when they want to make changes to the policies that they have in place, we want to ensure that they do so in a way that is compliant with the rules that we have set out for them. We feel that we have a very clear brief in the legislation. Of course, we have very good, ongoing discussions with Government about any changes they might make. We are an independent regulator and—
Q255 Kit Malthouse: Sorry, that is not really what I am asking. I am asking, do you feel that the atmosphere in which you are operating is influenced by the influence they exert through their vast resources on your other counterparties, such as Government?
Mark Bunting: We don’t. Look, the strongest pressure that we feel, and we welcome it and it is partly why we have this job, is the overwhelming public demand for something to be done to improve user safety online. We are very conscious of that. That is a daily topic of conversation in the media, as it should be. We feel a great responsibility to respond to that. I do not see companies resisting the broad principles of that in terms of the protection of children and the protection of all users from illegal content online. The strongest pressure that we feel is to hold companies to account in responding to that.
Q256 Kit Malthouse: I understand that, but what these companies say and what they do are two very different things, certainly in my experience and I think in the experience of lots of parents, so I am not sure that I necessarily agree with that. The point I am making—it is hard to get an answer and maybe John could help on this—is that they are deploying millions and millions of pounds trying to condition the atmosphere in which you operate, both politically and societally. In other spheres and industries, such as life sciences and big pharma, there are big restrictions on what they are able to do for exactly that reason. Is that a difficulty for either of you?
John Edwards: Not for me and not for the ICO; not in the slightest. I have a statutory obligation to act independently and to apply the law that Parliament has provided. I don’t care what they are saying to politicians. If one of these platforms goes to the Secretary of State or the Minister, or comes into this place and argues for a law that reflects their preferences for an operating environment, it is your job to inquire about the costs and implications of that. I apply the law that you have already provided, and I do that without reference to the preferences for an operating environment.
Q257 Kit Malthouse: If there is legislative change proposed, you would necessarily have a view on that legislation and whether you think it is going to be damaging to your wider mission or not. For example, we just had a private Member’s Bill that was seeking to protect children online, which the Government effectively vetoed, filleted, gutted or whatever, to the enormous disappointment of lots of people. There is a suspicion—I asked the question in the House—that that action, by then, was part of a wider negotiation with the United States, who are themselves under the influence of these vast companies seeking to protect a very lucrative part of their market.
Chair: Kit, I don’t think we can ask them to comment on the international trading environment. We will put those questions to the Minister when she comes in.
Kit Malthouse: But I am asking a question about forming a judgment on proposed legislation, or legislation that does not come forward.
Mark Bunting: What I can say is that we have been really clear throughout this process. It is Government and Parliament’s job to set the policy and to work out what they want to achieve. It is our job to help make that happen, including advising Government and Parliament on what we think good regulation looks like. It is not for us to get involved in political debates. I completely agree with what John said. Those political debates do not affect in the slightest the day-to-day doing of the job that Parliament has given us.
Q258 Chair: Let us move on to what is certainly within your remit, Mark Bunting. Thank you, Kit. I know what you are trying to get at, but I think we should leave those questions to the Minister later.
We did our job in inquiring and brought the tech platforms in to see us. In the context that this inquiry was in the wake of the Southport riots and a sense that the Online Safety Act should play a role in ensuring that something like that did not happen again, the tech platforms told us that even if the Act had been fully implemented it would have done nothing to change their response. Doesn’t that say that the Online Safety Act is not fit for purpose?
Mark Bunting: We wrote to the Secretary of State last autumn to set out our assessment of what happened during those terrible days after the attack. We were very clear, though, that we thought there were a number of questions that the tech firms would have had to answer had the duties been in force when those events took place, including whether they had carried out an adequate risk assessment of the events of last August, whether they had appropriate crisis response processes in place and whether they deployed them effectively.
I don’t want to go back and legislate events that happened before the duties were in force, but I can say that we do not think that companies are sufficiently, consistently or effectively responding to events of this kind. As the Committee is probably aware, we are now working on proposals for further measures in our codes of practice for companies to implement crisis response protocols specifically in response to the events of last summer. We will expect companies to be doing a lot more and to be much more accountable for their response than they have been in the past.
Q259 Chair: Mark, I find that kind of hard to accept, given that you yourself earlier said that the role of the Online Safety Act was to protect children from harm and the public from illegal content. The Online Safety Act does not designate misinformation as illegal content. Neither the Online Safety Act nor any of Ofcom’s codes include misinformation as a harm that needs to be addressed by online services. That means that the platforms, even if they identify it in their risk assessment, have no duties to comply with. Isn’t this a safe harbour for platforms?
Mark Bunting: The thing that concerned us in the evidence that we gathered about the events of last summer was that a lot of the content that was circulating was illegal. It included threats of violence, threats and harassment of religious and ethnic groups, and calls for violent protests. Those are all serious offences under UK law. That is the area where our forensic analysis will be targeted. Let’s hope it doesn’t, but should anything similar happen again, you are right, of course, that the previous Government made a decision to remove legal material that might be harmful to adults from the scope of the Act, including other forms of misinformation. We are still working in that area. The Committee might be aware that we announced the membership of our information advisory committee yesterday. They will be there to advise us.
Q260 Chair: We will come to that. Before we move on, and to be clear on this, the examples you give of misinformation and illegal content are incredibly concerning. In the Southport riots it was actually the misinformation that the perpetrator of that heinous act was a Muslim immigrant that was a huge driver of the response to those terrible murders. I think you are saying that the Online Safety Act does not deal with that, and you do not expect it to deal with that, and you feel that is clear.
Mark Bunting: That is correct, with one small caveat. The Act introduced a new offence of false communications with intent to cause harm. Where companies have reasonable grounds to infer that there is intent to cause harm—
Q261 Chair: I am smiling because somebody was charged with that offence and they were found not guilty, on the basis that intent is very difficult to prove.
Mark Bunting: What I would say about that is that it is a new law. There is not much case law and therefore we recognise that it is limited in our ability to get traction on the type of material that you are talking about.
Q262 Chair: Would you like to see clarity on that?
Mark Bunting: I think that is a matter for Government and Parliament.
Chair: As far as you are concerned, it is very clear that the Online Safety Act does not cover misinformation. On that basis, I move to Adam.
Q263 Adam Thompson: Thank you, Chair. Good morning, both, and thank you for coming down. I have a couple of questions for you particularly, Mark, focusing on the concept of safety by design. Do you think the Online Safety Act has fulfilled its goal of ensuring safety by design on various platforms?
Mark Bunting: We think that safety by design is right at the heart of the Act. It is a term that is used in different ways by different people, but we understand it to mean the proactive consideration of safety throughout a company’s governance and throughout its product design and engineering processes. We have tried to build that thinking into the guidance that we have provided about how to do the risk assessments, and into the measures of our codes of practice about the governance arrangements that firms have to have. Those are not complete pictures. The first sets of codes that we produced we see as foundations that we will build on over time. We have included some measures there about specific areas of design that we want companies to look at very closely, particularly the design of their recommender algorithms. That may be something the Committee wants to come back to, but we think there is more to be done. Another area where we will be publishing more proposed codes of practice measures in the next few months is the use of AI tools to proactively identify harmful content so that it can be blocked before it is uploaded to a service.
We think there is more to be done. We think the foundations are in place and we think it is an Act which is about safety by design. I recognise that there is still ongoing work and discussion for us to have with stakeholders about the specifics of that.
John Edwards: Can I make a contribution, Chair?
Chair: Of course.
John Edwards: Perhaps I might respond to that as well. Safety by design is also at the core of the age appropriate design code, which is a code of practice issued under the Data Protection Act. It describes the ICO’s expectations of platforms designed to be accessed by children. It has 15 privacy-by-design principles, and they include things like turning off geolocation by default, switching off an ability to message young people by default and switching settings to private by default. All of these are expectations of the design standards for platforms that are accessible by children. We have been able to achieve a lot of change in the services that are offered to children through that code.
Q264 Chair: Unlike the age verification code, though, the Online Safety Act, in the guidance, defines safety as “safety from illegal content” rather than from harmful content. That is my understanding. Is that right?
Mark Bunting: Illegal content and content that is harmful to children.
Chair: Again, misinformation is not covered by safety by design.
Q265 Adam Thompson: Thank you, Chair, and thank you both for those answers. It has segued very nicely into the next question I have for you. You have talked about the codes of practice that you have already put together and you have accepted already that there is more work to be done there. There has been something of a focus on reactive measures in the first draft of the codes of practice. You talked about moving towards a more proactive model. First, do you think the reactive focus does not necessarily address true safety by design? Could you elaborate on the future direction and where you see those going?
Mark Bunting: As I say, the Online Safety Act really has two components. There are the codes of practice, which serve a particular function, to signal to every company that is in scope of these laws what the simple steps are they can take to comply; then there are the wider risk management and governance processes that the Act puts in place. We think that probably no firm is fully compliant with either of those parts of the regime, but I am particularly concerned about the processes for risk management and the proactive identification of risk.
The immediate focus for us there is understanding how these firms, particularly the biggest firms and the firms that pose particular risk, are embedding safety by design thinking in their risk management processes. That is something we are going to learn more about over time. We have just completed our first trawl of illegal harms risk assessments. We received around 60 by the end of March. We are analysing those now, and that will tell us a lot more. We will learn things from that which we will want to use to improve our guidance over time, so yes, more on risk management, more on good government, more understanding of what it really takes to embed safety into product design and more focus on particular types of design feature where we think that there are risks that could be more effectively managed proactively.
I mentioned the AI tools for content detection. Another area where we will be making more proposals shortly is on livestreaming. We heard feedback from our first consultation. This was an area where we had identified risks, but stakeholders felt that our measures did not go far enough to deal with those risks. We have heard that feedback and we are now bringing forward further proposals to make livestreaming safer, particularly for children. We think there is a strong foundation but there is a bit more to do, for sure.
Q266 Adam Thompson: Thanks, Mark. That is reassuring. I have a couple of quite specific questions on moving forward, as you go on to the next draft of these kinds of processes. Do you think there is some scope to impose duties on platforms to demote or de-amplify harmful content through their algorithms?
Mark Bunting: I think there is. John will want to comment on this because the ICO has been doing some very useful work on design of recommender systems. We think it is an extremely important area. We are now very familiar—our evidence has shown it over a number of years—with the role that algorithms can play in reinforcing harmful content, particularly for children, and surfacing harmful content to children who may not have gone out and searched for it. Those are two different problems that the algorithms are involved with.
The measures that we have included in our codes of practice expect firms to do much more to test those algorithms for what may be unintended outcomes. They need to do much more to test whether the algorithms are having those unintended effects and, particularly for children, to remove harmful content from feeds so that those effects are negated.
Q267 Adam Thompson: On that point specifically, why doesn’t the recently published code of practice include misinformation and disinformation as harmful content that should be excluded or demoted?
Mark Bunting: It is the same reason that we discussed earlier. The Act specifies the types of content that are harmful to children. The focus in the Act is on pornography, suicides, health harm content and eating disorder content. There is a range of other forms of content, including violence, that are covered by the Act. Misinformation and disinformation can be covered by that, to the extent that, for example, they amount to harassment or abuse—that would be captured by the Act—but there is no general provision in the Act for misinformation to be captured as a harm to children.
The one area where we have extended it is in the area of depressive content or content which can, again, be misinformation. We have identified through our work that that has discernible impacts on children. We have a very extensive evidence base for that now. We do not think the Act gives us sufficient flexibility to address disinformation in its entirety.
Q268 Adam Thompson: Would you like to see that covered in future?
Mark Bunting: It is a matter for Government and Parliament. I know that is a frustrating answer, but it is a matter for Government and Parliament.
Chair: You are going to hear a lot of that.
Mark Bunting: We are still in the early stages of this process of working out the effects of social media and consumption of this type of material on children. There is a lot of research now, but the debate is still ongoing about what is a safe media environment for children online. That could go in a number of directions. All sorts of proposals have been made. It is not for us to comment on specific answers, but we support the ongoing debate about what more needs to be done. I don’t think we would say that the Online Safety Act is the end of that journey.
Chair: Thank you. I have a lot of interest, obviously, in protecting children.
Q269 Emily Darlington: I am a mum, so I am speaking both as a member of this Committee and as a parent. I think there are two questions that parents really want to know the answers to. First, we talked about illegal activity. I think we can all agree that offences by online grooming gangs against children have increased by 89% in the last six years; 81% of that is against young girls. The number of such offences has reached 7,000. Those are just the ones we know about, but it is the fear of every parent of children online. What exactly does the ICO do and what will Ofcom do with these new power to protect our children from online grooming? Precisely, not generally, what actual actions are you going to take?
John Edwards: I briefly mentioned the age appropriate design code and its design principles. One of those is that, by default, children should not be able to be contacted by people who are not in their contacts list and who are not approved. Adults should not be able to cold call children, whether that be on video streaming, gaming or social media platforms. We have been working with platforms to enforce that. Many of them have changed their default settings as a result.
Q270 Emily Darlington: But it is still going up. How is it still going up if we have this? What actions are we taking to actually make sure it is going down?
John Edwards: I am not aware of the platforms that you are describing.
Q271 Emily Darlington: Forty-eight per cent. of it happens on Snapchat; 12% on WhatsApp; 10% on Facebook; and 6% on Instagram. Of that, 28% is on Meta platforms. What are we doing with Meta to make sure that those numbers are going in the other direction? What are we doing with Snapchat? Have we met them? Are we prosecuting them? What are we doing to actually bring those numbers down?
John Edwards: We meet with these platforms often. We have had commitments from platforms to turn off personalised advertising, to stop default geolocation being available to other users and, as I said, to stop strangers from contacting them. I think that is a key thing for preventing grooming.
I cannot give you details of our specific interactions with the platforms on that particular issue, but I am happy to commit to going back to my teams and finding out whether we have extant investigations or enforcement action in relation to those or whether we have seen non-compliance that we have drawn to the attention of the platforms.
Q272 Emily Darlington: Turning to Mark and the role of Ofcom in this, I would like to expand it further. “Adolescence” has absolutely been something that captured the nation. It has certainly captured every parent who is worried about radicalisation online in misogyny for our young men and boys. Is that considered misinformation? Is it considered illegal content? What actions are you taking on people like the young man and the young girl we saw portrayed in that docu-drama? I appreciate that it is not a true story, but it is very close to many stories we have seen repeated in every school across this country. What specific actions is Ofcom taking to tackle that kind of radicalisation of young men, who are putting our young women at risk and their own futures at risk?
Mark Bunting: I completely agree with what you say. “Adolescence” is one of those dramas that succeeded in capturing the nature of a problem in a way that can be difficult for regulators with our dry research to do as vividly. Unfortunately, I think it reflects the experience that we know that a lot, though not all, of younger people have today.
You ask what we are doing specifically in that area. There are a few things. First, some of that material would be captured by the categories of content that are covered by the Act; misogynistic abuse, for example, and bullying are captured by the Act. Content that stirs up hatred towards women would be captured by the Act. That gives us a strong platform to talk to companies about what they are doing about some forms of misogynistic abuse and gender-based harm. It does not capture all forms of misinformation. We have discussed that already.
One thing we have done additionally in this area, and Parliament gave us a clear mandate to do, is to produce additional guidance specifically on protecting women and girls online. We published that in draft form in February. It includes all the things that companies have to do in order to comply with the existing rules. It also sets out good practice guidance. It is a very extensive set of recommendations for firms about how they act on this type of abuse. That is a challenge to industry. We are consulting on that. We are looking for them to come back to us with meaningful responses and we will have more to say about that later in the year.
Q273 Emily Darlington: What I am concerned about, and what parents will be concerned about, is that there is no action. I appreciate what you are saying, “Guidance, and we are talking to them,” but what are we actually doing to stop it? The really specific question is: do you have the power to stop it, yes or no? I am not asking whether you should or should not, because you are right, that is up to politicians. Do you have the power to take action against these companies to stop the online grooming and to stop the spread of misogyny and the radicalisation of our young men online? Do you have that power?
Mark Bunting: What we have the power to do, and I am sure John will also want to comment on this, is to make sure that companies have good systems in place to identify those risks when they are occurring and take action against them.
Q274 Emily Darlington: But do you have the power?
Kit Malthouse: What does good mean? That 50% gets through, 20% gets through? What is good?
Mark Bunting: That is not the standard that the Act asks us to assess. The Act asks us to ensure that companies have robust processes for dealing with this.
Q275 Chair: Robust processes. There is a lack of definition of what is success. John, do you want to briefly comment?
John Edwards: Thank you. It is really important we explain the nexus between the ICO and Ofcom here. The Committee has an understandable expectation that Ofcom is there to look at the kind of content, the sort of things that you are concerned about, Ms Darlington—what that child, what that young person sees. That is Ofcom’s remit under the Online Safety Act.
My remit, at the ICO, is data use in ways that cause harm. Behind every post that goes to a child is an algorithm which is fed on what the platform already knows about that child from their biography, what it knows about them from what they have looked at before, how long they have looked at it, what they have clicked “Like” on, and what they have shared. Those are data uses. I have announced an investigation into recommender systems and the way in which data is used to put content on to the screen. We need to work very closely with Ofcom in that.
The data protection laws in this country create obligations on controllers to process data in ways that are fair. I don’t think it is a huge leap for anyone to say that if a child of 13 or 14 is being radicalised by what they see, and what they see is a result of how their data is used, that is a harm; that is unfair. It is not a huge leap to say that if a child is being induced to spend unhealthy amounts of time on a platform or on a device, that is an unfairness. They are competing in an asymmetrical environment where cognitive frailties and immaturities are being exploited. We are very keen to explore the limits of data protection law to create standards.
One of the complexities about this is that the kind of data uses I am describing, which can cause harm, also have a significant role in keeping children safe. You cannot moderate the content through an algorithm unless you know some of those things about the children. What we have committed to do is to open the box and to hold companies to account, to ensure that those data processing activities are transparent, to ensure they have done the kind of risk assessments we would expect, and to ensure that mitigations are in place to prevent the kinds of harms you are describing.
Q276 Chair: Thank you, for that very important intervention, Emily. Thank you, John Edwards, for what you have just said. Could we ask you to write to us with your thoughts on the roles of data controllers particularly in mitigating misinformation?
John Edwards: Yes, certainly.
Q277 Steve Race: I have some questions for Mark on the Online Safety Act, particularly going back to mis- and disinformation. Ofcom committed to creating the misinformation and disinformation advisory committee by the end of 2024. I note that, maybe with good timing for your appearance today, it was formally announced yesterday with a changed name. Could you talk to us about the reasons why it has taken so long to set up—about four months late? Also, what is the reason for the changed name, please?
Mark Bunting: Yes, absolutely. We appointed the chair and started the process of recruiting members by the end of last year. It has taken a little bit longer than we expected to find the right mix of people. Richard Allan has been in place for a number of months and has been starting to do the work to prepare the plans for the committee. The first formal committee meeting will be in May, very shortly, and they will develop a programme of work. That is for Richard, in his independent capacity to lead on, but I am sure he will be very happy to share more information about that plan of work with the Committee as it develops.
The change of name is not particularly significant. The feedback we had during the recruitment process was that mis- and disinformation did not describe the totality of what people thought the committee had been asked to do. The committee has been charged with advising Ofcom on its responsibilities, particularly in areas like transparency. As we discussed earlier, mis- and disinformation are very wide concepts. Lord Allan is particularly keen to ensure that the committee’s advice is useful for Ofcom in the work that it is doing to keep users safe from the harms that are identified in the legislation.
The change in name is simply to reflect that the focus will be broadly on online information, which may include sometimes content that is not mis- and disinformation but is, none the less, relevant to the things that the committee has been charged with looking at. Plus, from a very practical point of view, it avoids us having to say “mis- and disinformation” every time we have to describe what the committee is doing, which may sound like a trivial thing, but it is a bit easier. It doesn’t change anything about the terms of reference for the committee that we set out towards the end of last year. It doesn’t change anything about the statutory function of the committee. It is a change in name; nothing more.
Q278 Steve Race: Can you tell me what the challenges were in recruiting members for the committee?
Mark Bunting: I have not been very close to that process myself. We were, of course keen—in fact, we were required by the Act—to achieve a mix of different types of people. They needed to be expert in the field. They also needed to be a mix of people who represented the interests of the public and represented the interests of industry. At the same time, we felt it was important—I know Richard felt it was important—in doing that recruitment, that he was recruiting independent voices who would not be representatives of any particular perspective, or give the impression that people would have the opportunity to lobby Ofcom in pursuit of their own particular interests. Getting the blend of people exactly right inevitably is complex. We have a really good line-up for the committee now and we are looking forward to working with them very closely. It has taken a little bit longer than expected, but we think we have a really good committee lined up now.
Q279 Steve Race: Is it the committee you wanted or did a lot of people decline to participate?
Mark Bunting: I am not close enough to the process to answer that question, I’m afraid.
Q280 Steve Race: Going back to the name change, one of the few measures to tackle misinformation was this committee. You say the statutory guidance for the committee remains, but the name has changed. Can you set out a bit more clearly, again, what the committee will advise on and what it will tackle?
Mark Bunting: Yes. I don’t have the terms of reference with me now, so I may come back to you if I get any of this slightly wrong. The main purpose of the committee is to advise Ofcom on carrying out our functions as they relate to mis- and disinformation, in particular the interaction between mis- and disinformation and the harms that we regulate. It is their job to advise us on the use of our transparency powers, which we will start to roll out later in the summer. Of course, they will pay particular interest to the types of harm described in the Act that are relevant to mis- and disinformation— for example, the foreign interference offence, which is a priority offence under the Act.
It does not always have to be mis- and disinformation. A good example is an area where in fact accurate information can be distorted or used by foreign actors in order to cause dissent or interfere in political processes. That is a good example of an area where they will advise us on the nature of the threats we face and what we can do about them.
Q281 Steve Race: Section 179, which we referenced earlier in the Committee session today, makes it an offence knowingly to send false information intended to cause harm. Ofcom has not provided clarity on how to apply section 179. First question: how will the advisory committee advise you on section 179?
Mark Bunting: We have provided guidance on that in the illegal content judgments guidance document, which is a very long and detailed discussion of how companies should consider the offences captured by the Act. That will be the starting point for our guidance. I will have to come back to you on whether we are planning to provide more guidance with specific reference to the section 179 offence. I am not sure of the answer to that now, but that will be the starting point for interpreting it. Of course, they will also want to consider cases that have been brought through the courts about applications of that offence to help understand how companies might think about identifying those offences in practice.
Q282 Steve Race: We have had evidence from some of the platforms that say they do not understand what you want from section 179 and how they can abide by it. Clearly, there is a real lack of clarity. I am not sure whether the committee will understand how to do it, but certainly the platforms are saying they do not understand what you want from this.
Also, I am a bit concerned about your lack of closeness to some of these issues, given these are some of the big issues that we are talking about and that come up in the Online Safety Act. What clarity will you give to platforms around this in particular, so that they know what they are supposed to be doing?
Mark Bunting: Look, I think we need to be really clear; it will not be easy for a company to identify when false communications have been sent with an intent to cause harm. We need to work with them to help them identify what those signals are. Of course, where there is case law, where the courts have made a judgment about whether somebody has done that, there will be things we can learn. This is an area where we need to continue to monitor the case law and provide more guidance to companies.
This is an important offence, but there are a great many areas where we think—John talked about being selective earlier—there is immediate need for urgent improvements to address some very serious offences, including child sexual exploitation and abuse, and the grooming work that we talked about earlier. This is an area where we need to do more work, and we need to understand the case law better. It will take longer for us to bring the section 179 offence into the centre of platforms’ attention. That is not to say it is not important, but we are in a phase of work where we are learning more about that offence, rather than in a phase of work where we can be very directive with firms about what we want them to do differently.
Q283 Dr Gardner: I want to talk about generative AI, but, before I do, I am a little bit concerned about some of the answers. You say you have the resources. I have never met a regulator yet who says they have the resources, so that surprised me. I hear what you said about the struggles with enforcement and how that can be very long. In your answers to Emily about whether you have the powers to enact this, what do you say to the Committee when the large platforms say that they do not think the Online Safety Act will really affect them much? What is your response to that? They have indicated that.
Mark Bunting: I don’t think that is true. To take two examples—Ms Darlington touched on this earlier—today most children online have an experience that is not distinguishable from the experience that most adults have, because platforms do not systematically consider which of their users are children and put in place an appropriate experience for them.
Q284 Kit Malthouse: They do. That is the problem. They do.
Emily Darlington: They do. That is why they drive the data.
Kit Malthouse: That is why they drive stuff to them.
Mark Bunting: Yes, I agree. The point I was making was that from a safety point of view it is not a different experience.
Chair: That is not the point—the concern of the Committee.
Mark Bunting: The ability of the services to use the insight they have and the tools available now to identify which users are children and to shield from them content that is inappropriate for children exists; those capabilities exist. They have them themselves, they are readily available in some cases in the market and they are not being used. That has to change. We have very clear powers enabling us to do that. That will be a big focus of our work. We have only just finalised the protection of children codes; they are passing through Parliament at the moment. We eagerly anticipate reading their risk assessments as regards children’s safety, when they send them to us by the end of July. We will be laser-focused in our work with those firms to ensure that they are transforming the experience of children online.
Q285 Dr Gardner: That is a little bit more reassuring an answer, so thank you for that. With regards to generative AI, the whole Online Safety Act will have taken about 10 years, when it finally all gets done and all the guidelines are out. Of course, generative AI has appeared dramatically in the last few years. We also have the follow-on agentic AI. Mark, how is Ofcom responding to the challenges that generative AI presents the Government’s online safety regime?
Mark Bunting: Let me take the opportunity to empathise briefly with your point about the length of time it has taken to get here. I have been working in this area since 2016. I am very sympathetic to concerns about the extended period since this legislation was first mooted.
On gen AI, the first thing to say is that gen AI content that meets the definitions of illegal content, or content that is harmful to children, is treated in the Act exactly the same way as any other type of content. The Act is deliberately drawn in a way that is technology-neutral. Sadly, we see the use of generative AI to create harmful content, including images of children. That content is illegal. We work closely with law enforcement and with partners like the Internet Watch Foundation, who are trying to develop tools on this. We expect companies to put in place better tools for the detection of automatically generated material, where it constitutes an offence or is harmful.
There are areas of technology where the legal position is not entirely clear or it is complex; for example, chatbots and the character services that we have seen linked with harm in the last few months are, we think, caught by the Act in some circumstances but not necessarily all circumstances. The mere fact of chatting with a chatbot is probably not a form of interaction captured by the Act. There will be things that we want to continue to monitor. We want to talk to industry about the things where we think that more could be done. We will be very happy to work with Government and Parliament to try to build on the legislation already in place.
Q286 Dr Gardner: Do Ofcom and ICO have the powers you need to investigate the data behind generative AI, seeing that it is not mentioned?
Mark Bunting: That is more for you in the first place, John, isn’t it?
John Edwards: Thank you. I believe we do. We have authority; we have jurisdiction over any processing that involves personal data. Most of the generative AI products we have seen do. We took action in respect of Snapchat’s deployment of a chatbot on its platform, because it appeared to us, at that time, that they had not taken sufficient steps to assess the potential impact. They were able to satisfy us that they had.
To your earlier point about the powers we have. We have the ability to issue fines. We issued a fine of £17 million to TikTok for enrolling or allowing children under 13 to sign up without parental consent. We have the ability to issue enforcement notices, so that we can force an organisation to come into compliance. We have the ability to force deletion of data.
On your point about generative AI, that is something we have been working on for quite some time. Last year, we issued a series of discussion papers, setting out some of the challenges of applying our general data protection principles to generative AI models. We concluded that in a paper at the end of last year. That is there for the market to see. We are working at all points of the supply chain for generative AI. The Government have advised that, when the Data (Use and Access) Bill is passed, they will invite the ICO to issue a code of practice for AI, which will set out some more granular regulation in respect of some of those deployments.
Q287 Dr Gardner: One example was a deepfake of Joe Biden ringing people up and telling them not to vote. Do you feel that you need to broaden your engagement with other regulators because not all of these harms are identified in the Act? Do you need to broaden the list of harms?
John Edwards: It is a very important point. From my perspective, at the ICO, we have a kind of blanket application where personal information is implicated. That is an example, where the personal information of an individual has been manipulated in a way that could be deemed unfair, that fits within our jurisdiction. But does that make the ICO the appropriate regulator to take action on it? We are not able to act pre-emptively and to prevent the dissemination of that, for example. If the person who created that content was an individual doing it in their personal capacity, that would be a real challenge to our jurisdiction. It is likely that they would not fall within our jurisdiction.
Q288 Dr Gardner: Would you liaise with the Electoral Commission, for example?
John Edwards: We would and we had those conversations before last year’s general election. We have a body called the Digital Regulation Co-operation Forum, which has been important in bringing together Ofcom and the ICO, as well as the Competition and Markets Authority and the Financial Conduct Authority, to have an ability to identify and pass around these issues, as we see who is best placed to address them. That entity does not have a fixed membership. We have the capacity to bring in others and it is likely that, for some of these questions, we would need to engage with the Electoral Commission, with Intellectual Property, with the HMRC and with a number of others.
Q289 Chair: Thank you very much, Allison. We are officially out of time, but we still have a lot we want to get through. I suggest we go on for a few more minutes. Tom and Paul particularly have issues and questions they want to put.
I want to confirm with you, Mark Bunting, that large language models, ChatGPT, and so forth, are not defined in any of the categories of systems that Ofcom and the Online Safety Act have a responsibility to regulate?
Mark Bunting: That is correct. The output of those models would be captured where it is shared.
Q290 Chair: The outcome but not the actions themselves, which seems to be a large gap.
Mark Bunting: Correct.
Q291 Tom Gordon: Generative AI is a really interesting point. Obviously, things in the area are moving quickly and there is a fast pace of development. Do you think that Ofcom and the ICO, respectively, not only have the powers, as was asked, but the flexibility and the capacity to keep up with emerging risks and technologies? How are your organisations trying to stay ahead of the curve rather than just reacting?
Mark Bunting: This is an area where the co-operation between us and other regulators is extremely important. We all have our own teams working on these topics; they are regularly in touch. We have an AI and digital hub, which is all four regulators working together to provide support, particularly to smaller businesses trying to understand the implications of innovation and new technology.
From a purely Ofcom perspective, the advantage of the Online Safety Act is that it is technology-neutral. It gives us the scope to look at the new tools and understand what forms of content may be created. It will not cover every form of harm that might emerge with new technologies, which is probably the key point that we touched on here. It is specifically designed for contexts where content is shared between users of a service. Within that area, yes, we are confident. Of course, we are tracking the development of new technologies. We are working closely with partners like the Alan Turing Institute and others to keep abreast of new developments. The point is that we have to be embedded in a broader ecosystem of change. We will not be the people who are always coming up with the ideas for new solutions to harms, but we have to be plugged into the expert bodies who are doing that work. That is what we are trying to do.
Q292 Tom Gordon: Do you feel you have the resource and the capacity to do that with scale and pace?
Mark Bunting: At present, we do, but it is an area we keep under review. Of course, it is an issue for Ofcom as a whole, because it is not just about online safety; these trends are also having an impact on our broadcasting work and in our telecoms work. It is an area we keep under review. Where we think we need additional resource or to be using our resource differently, that is a conversation we will have with Government.
Q293 Paul Waugh: Thank you both for coming. We just referenced the idea of regulators co-operating. I assume that you are both taking specific actions to increase your communication and collaboration with other regulators, like the Electoral Commission. I take it that is ongoing. Is it? Can you give us a brief overview of where you are with contact with other regulators?
Mark Bunting: Shall I kick off? John will want to comment as well. There is a very wide of range of bodies that we work closely with. John has already mentioned the DRCF regulators. Another particularly important area of alignment for us is law enforcement, of course; slightly different, but a very important set of partners, particularly the National Crime Agency. We talked briefly earlier about international co-operation. That is probably the third area that is most important for us at this stage. This year, I am chairing the Global Online Safety Regulators Network, which has members from around the world—Australia, Canada, EU member states and Asian regulators. That is an extremely important forum for us in sharing intelligence about what we see in the market, and to learn, as we all are, about how to regulate effectively in this new area.
John Edwards: Similarly, we have bilateral engagements with a number of other regulators, including the Equality and Human Rights Commission, the medical regulators, the Parliamentary Health and Safety Ombudsman, and others. Like Mark, we have considerable engagement with international colleagues. I was in the US last week, meeting with the Federal Trade Commission, talking about areas of common interest. We meet G7 data protection regulators in a regular cycle that coincides with the ministerial G7 meetings. There are a number of other networks that we participate in to achieve what I think Mr Gordon was describing—the horizon scanning, making sure we are aware of what is coming over the horizon and are ready for it.
Q294 Paul Waugh: You just mentioned the National Crime Agency, Mr Bunting. They have particular concerns about end-to-end encryption in Facebook messaging, in particular. Most of the references they receive on child sex abuse online are from Facebook messaging. They expect an 80% drop in that now due to end-to-end encryption. What are you doing to combat that challenge, both of you? Obviously it is an Ofcom issue, but it is very much a data issue.
Mark Bunting: We have identified encryption as one of the areas of risk that companies have to take into account. It is a problem. There is no getting away from it. Encryption provides enormous benefits around privacy and security to users and of course it is very highly valued by users for that, but that means that a lot of the tools we want to see companies use, including the AI detection tools that I talked about earlier, are not operable in encrypted environments.
We think it is a challenge for the industry. We have been clear that we expect the industry to do more work on techniques that are being developed to detect harmful activity in encrypted environments. Some of those are widely used already. For example, analysis of the metadata in encrypted services can give clues to the potential abuse of those services by criminals and people who want to inflict harm. We do not think those are good enough and we are looking to industry to do more. It is a point where the industry is still at a relatively early stage of technical development. It is not something that has been prioritised. Of course, there are well-founded concerns about the risks of undermining encryption or creating back doors into encrypted systems.
They are complex issues and we are very focused on that. I mentioned our technology team earlier. It is one of the priority areas of work for them. It is an area where more needs to be done and it will take time.
Q295 Paul Waugh: John, doesn’t it make your job almost impossible if there is end-to-end encryption on a lot of the data?
John Edwards: No, I don’t believe so. Encryption is essential for maintaining the security of the digital ecosystem. There is a raging debate on the extent to which limited access can be given for law enforcement purposes without fundamentally undermining the efficacy of that encryption. That debate will be played out, in part, in the Investigatory Powers Tribunal with reported litigation between Apple and the UK Government in respect of orders that are said to have been presented to Apple to require opening of a certain encrypted product offering that they have. These are very contemporary and contested issues at the moment.
Chair: Thank you very much. We are out of time, as I said, but we have three subjects we want to cover very quickly. Emily will talk quickly about small platforms and I will finish on advertising and the Data (Use and Access) Bill.
Q296 Emily Darlington: Yes. It leads very nicely from what you have just said about encryption. What we heard about the riots last summer was that a lot of the organising, spreading and targeting happened on the smaller platforms. You have set up a small high harms platform taskforce. How many people sit on that taskforce? Has it met and how often do you expect it to meet? What levels of engagement will you have from 4Chan, 8Chan, Telegram and Signal where a lot of far-right extremist activity is moving?
Mark Bunting: It is a really important area for us. I don’t have the numbers for people on the taskforce right now, but I can come back to you about that. It is an active unit within the organisation, part of our supervision team. We have brought enforcement action already, as you will be aware, against a forum that focused on suicide content, that we believe poses significant risk of illegal suicide content and suicide content that is harmful to children. That taskforce was already working in those areas.
This is not an outcome that we want to achieve, but the other thing that we have seen is some of those organisations deciding to withdraw their service from the UK, because they do not want to take the basic safety steps that we have put in. Of course, while we would rather services were safe and were being used in the UK, if that is an outcome, it is an outcome available to firms under the Act. Some of the services you mentioned are not currently available in the UK. We will be monitoring that very closely to ensure that we are taking action on services that are still available but are not putting in place the protections we require.
Q297 Chair: Thank you very much. I have two questions, hopefully brief. Mark, the Committee has heard a lot about the role of advertising in driving misinformation and how aspects of the Southport riots—the misinformation that drove that—were monetised by various social media platforms, with the huge domination of Google both in the front end and back end of advertising. It is our understanding, and my view, that Ofcom’s purchase on advertising regulation is purely on content and not on the process. Is that the case? Who is responsible, in your view, for regulating the process of advertising that is helping to drive misinformation?
Mark Bunting: I am not sure that is a brief question, but I will try to give you—
Chair: A brief answer.
Mark Bunting: Yes. In the online safety work, Ofcom’s particular focus is on fraudulent advertising. We have powers there to bring forward a code of practice, including on the content of fraudulent advertising as well as the process. Both the ICO and the CMA have done work on the advertising business model historically. Our main intersection with it outside fraudulent advertising is the role that advertising plays in driving firms to maximise engagement with content, and the role of recommenders in maximising engagement. Our primary focus is on ensuring that those recommenders are not being abused to disseminate harmful and illegal material, as we touched on earlier. That is the limit of our role on advertising.
Q298 Chair: John, the Data (Use and Access) Bill is coming back to the House of Commons next week. It contains a clause allowing for the reuse of private data without express consent in the case of scientific research, without a definition of scientific research in the Bill. Your guidance for existing legislation uses the Frascati definition of scientific research. Are you concerned that this clause will allow, for example, private data to be used without consent for research that has not been defined as scientific? How can we avoid that?
John Edwards: No, I’m not concerned. Research is a term that warrants its normal, natural meaning, which is fairly broad, that involves deriving new knowledge from existing information. Where I would have a concern would be if such an accommodation was exploited in a way that enabled actions to be taken in respect of individuals—targeting them, profiling them, taking law enforcement action against them or in some way investigating them. Research should be at an aggregate and anonymised level, even if identifiable information is involved. The outputs should always be anonymised. Within those parameters, I am pretty comfortable with the Bill’s proposals.
Q299 Chair: You are certain that personal data could not be used, for example, to train large language models with this, as a loophole to allow it.
John Edwards: I missed the last part of the question.
Chair: It could not be used to train large language models, for example.
John Edwards: It could. In some circumstances it could, provided that there were safeguards taken. There is a lot of work going on at the moment about the use of synthetic data in training large language models and the like, and a number of privacy-enhancing technologies can be used to get the benefit of large scientific databases that include and incorporate personal data without compromising that data. That is where we want to see responsible innovation.
Chair: Thank you very much. We will have to leave it there. It has been fascinating. Thank you so much Mark Bunting of Ofcom and John Edwards, of the ICO, for being with us today.
Examination of witnesses
Witnesses: Baroness Jones of Whitchurch and Talitha Rowland.
Q300 Chair: Welcome to this, the Science, Innovation and Technology Committee’s second panel today, where we are fortunate to be joined by Baroness Jones, the Minister, and by Talitha Rowland. The Committee is very pleased to welcome you. Thank you very much for joining us today. We have a lot to get through, so I will go straight to a question that is on a lot of people’s minds and has been reflected in a lot of discussion. Would you, Minister, put on the record that the Online Safety Act will not be subject to negotiation as part of any UK/US trade deal?
Baroness Jones of Whitchurch: I am very pleased to be able to say that that is the case. The Prime Minister has made it absolutely clear that the Online Safety Act is not up for negotiation, and it is not part of the trade deal discussions. We have made that clear. The fact is that the Online Safety Act is a piece of legislation; it cannot just be negotiated away. As you know, and have heard from Ofcom today, it is well through the process of being implemented. It cannot be changed and we are happy to reassure everybody that we are sticking with the Online Safety Act.
Q301 Chair: Thank you very much, Baroness Jones. A lot of people will be reassured by that response, but equally it raises the question of how much the UK can do to tackle online harms without support from the United States.
Baroness Jones of Whitchurch: Obviously, we want to work internationally, globally. The Online Safety Act is a global first in many ways. Lots of other countries are watching us implementing it with interest, but it is a UK-focused piece of legislation. All companies, wherever they are based, need within the UK to apply our UK laws. The Online Safety Act makes that absolutely clear. We and Ofcom have regular discussions with companies that post platforms in the UK; they are expected, wherever they come from, to comply with the legislation. Whoever they are, whatever company they are, that is the case. As you know, Ofcom have all sorts of tools in their toolkit to take action, including fines, taking the post down and so on, if needs be. We do not want to come to that and we are happy to be part of continuing negotiations with those companies.
Q302 Kit Malthouse: The Online Safety Act might not be up for negotiation, but it might be up for sandpapering. In your interactions with No. 10, which naturally there will be, is there any suggestion—has there been any suggestion—about toning it down or taking it easy or, “Let’s not push it too hard”? There are ministerial judgments to be made in the operation of the Act, the guidelines and the interaction with regulators. Has there been any sense that there has been an attempt to tone it down? For example, we have already seen—I am not saying this is necessarily true—accusations that, following hospitality from YouTube at Glastonbury, Labour party policy was changed with regard to the digital services tax. Have you picked up any sense of that from No. 10 at all?
Baroness Jones of Whitchurch: I would say quite the opposite; our engagement with No. 10 has made it absolutely clear that this is a priority for the Prime Minister. He is absolutely determined to drive this through, particularly with regard to child safety, child protection. He has already had meetings with bereaved families. He is absolutely committed to doing everything that we can to protect children, not only from future harm but to make sure that they have a healthy childhood, which is what all of us aspire to.
The discussions we are having with No. 10 are about how can we take it forward and how can we make sure that every child has a healthy, engaged childhood, protected from harm. That is really where we are at. We are not into—I believe you used the expression—sandpapering. We are not into sandpapering the Act and there is no pressure to do that.
Q303 Kit Malthouse: Yes, but there is an interpretation of some words in it that could be used—for example, “harm”. What is harmful to my child other parents may not agree is necessarily harmful, and certainly social media companies would not think was necessarily harmful. In your interaction with those companies, have they made a case to you against anything that you were planning to do? Have you changed it as a result?
Baroness Jones of Whitchurch: A lot of the implementation of the Act, of course, comes down to Ofcom’s interpretation, rather than any interpretation that we base on it. At the moment, all our evidence, all our engagement, my understanding or Ofcom’s engagement with the social media platforms is that they understand the requirements of the legislation and they are working with us to implement it. I haven’t picked up any suggestion or any request that it be watered down. It is hard to know how you would do that in practical terms, to be honest.
Chair: Thank you very much, Kit. Let’s take a look at that in a bit more detail with Steve.
Q304 Steve Race: Thank you. Ofcom, in the context of the violence and disorder last summer following the murders of the girls in Southport, said that there was a clear connection between online activity and violence in the streets. We know from LinkedIn, X, TikTok the misinformation, disinformation and incitement. The tech platforms have told us that even if the Online Safety Act was fully enacted at the time, it would not have changed the response to that violence and disorder. What does that tell us about the Online Safety Act?
Baroness Jones of Whitchurch: All I would say is that many of the provisions under the Online Safety Act were not in place last summer, but we are confident that the illegal aspects of it, the child code aspects of it, would have made a real difference and the platforms would have been required to take down those posts in those circumstances. Indeed, Ofcom wrote to the Secretary of State about Southport and said: “I am confident that, had the draft codes been in force at that time, they would have provided a firm base for urgent engagement with services on the steps they were taking to protect UK users from harm.” Ofcom shared our view that, had those codes been in place, it would have made a material difference.
Q305 Steve Race: In what way would it have made a material difference in that case? What would have happened differently if the Online Safety Act had not been in place?
Baroness Jones of Whitchurch: The most obvious thing is to do with the illegal harm. Where posts were illegal, Ofcom would have had the opportunity to insist that those posts be taken down under the code. There would have been a requirement to do that. That is the most obvious example.
Q306 Steve Race: But lots of the content would not necessarily have been illegal, would it, for example disinformation and misinformation and incitement to join protests but not necessarily to protest violently? As you see it, where is the line where last summer would have been dealt with differently, when you use the word “illegal” specifically?
Baroness Jones of Whitchurch: What I would say about last summer is that the codes and Online Safety Act were only one part of the equation. We were doing work within the Department; we were working with the Home Office. You will appreciate that a lot of the things that were posted were then repeated in real time physically. It was not just about messages that people were seeing online; it was things that were happening offline in real time as well. The important point was about liaison with the Home Office and the messages we were receiving. Sometimes, we were picking up new trends or new demands or messages on the online platforms that were then materialising in communities a few days later. Some of that liaison was absolutely essential to us. Tackling dis- and misinformation of the kind that happened in Southport requires more than just one piece of legislation; it requires a whole community campaign and involvement to tackle it.
Q307 Steve Race: I suppose the main piece of disinformation was around the attacker, claiming he was an asylum seeker who came over on a boat and gave a false name. That was essentially what drove quite a lot of the activity. Would the posting of that have been considered illegal? Would there be different activity by the social platforms, enabled by the Online Safety Act, if that were to happen this year?
Baroness Jones of Whitchurch: We have some lessons to learn about what happened in Southport. The Prime Minister has launched a public inquiry into it. Ofcom can act only on illegal posts when they know for sure it is illegal. I think the Law Commission is doing a piece of work on this as well. We have lessons to learn about what happened in Southport, but obviously Ofcom has to be confident that something is illegal before it can intervene.
Q308 Chair: Minister, I think you are saying that the Online Safety Act does not address misinformation where it is not illegal content. That was part of the evidence we heard just now from Ofcom—that it did not address misinformation.
Baroness Jones of Whitchurch: If it happened now, the illegal harms elements of it would apply; they did not apply last summer. I think that is the material difference.
Q309 Chair: But the misinformation part, which was not illegal, is not impacted by the Online Safety Act?
Baroness Jones of Whitchurch: Our interpretation of the Act is that mis- and disinformation are covered under the illegal harms code and the children’s code.
Talitha Rowland: Perhaps one of the challenges in this area is that mis- and disinformation is not one thing. It can sometimes be illegal; it can be foreign interference; it can be content that incites hate or violence. That is clearly illegal. It can also be below the illegal threshold but nevertheless harmful to children. That is captured. It is also captured by many of the larger services’ own terms of service, which their categorised duties will require them to enforce consistently. It comes back to your point about platforms telling you they would not necessarily have done anything different. At the moment, they are just marking their own homework. They will have to account to Ofcom as to whether they are actually doing those things, not make that assessment and judgment for themselves. Ofcom may come to a different view.
Steve Race: Chair, I suppose the problem here identified is that Ofcom does not necessarily think that. I don’t know whether that was your interpretation.
Chair: They said basically that, given there are no duties set out for Ofcom to act with regard to misinformation, even if they have codes which talk about misinformation, or they identify it as a risk, they have no duty to act to be compliant. That seems to be a key issue.
Q310 Steve Race: Should the Online Safety Act have a crisis response mechanism to compel social media platforms to take certain steps on harmful content during crises? It would be interesting to know what happens now, what you think should happen and what some of the lessons learned might be.
Baroness Jones of Whitchurch: The short answer to that is yes. I know that Ofcom is working on a crisis management protocol, partly from their learnings last summer. Incidents like that will undoubtedly happen again. Ofcom are working on that and we very much support it. We need to be able to work quickly on cases such as the riots last summer. Anything we can do that gives us that more immediate reaction is very much to be welcomed, and we are encouraging Ofcom to do that.
Q311 Steve Race: In your interactions as a Department with the platforms, do you have the sense that there are certain platforms that want to participate and certain platforms that don’t, or is there a general pushback against it?
Baroness Jones of Whitchurch: I have not heard any of the platforms say they do not want to be helpful in times like the riots last summer. That is not a narrative that I recognise. They have been broadly supportive, and they were broadly supportive last summer. When we were identifying new trends and new misinformation and disinformation appearing, by and large they were very responsive in taking it down, so we had a good relationship with them on that last summer.
Q312 Steve Race: Where does the analysis monitoring of misinformation and disinformation online, when it pertains to the UK, sit within Government, and who has overall responsibility for it?
Baroness Jones of Whitchurch: We have a unit in DSIT, the national security online information team, which monitors what is happening across the piece online, so they identify trends. They do not identify individuals, but they can identify trends before the impact of any of them is seen more publicly. They work in close harmony with the Home Office. What we saw last summer was that that liaison was absolutely important. I think the national security services were also part of that.
Q313 Steve Race: You’ve named three. I know that there is at least a fourth, the Cabinet Office. Who is in charge?
Talitha Rowland: In these kinds of incidents you would expect a cross-government response. We have established systems and processes. Say it is around an election. There is the Defending Democracy Taskforce that plugs in. There were obviously cross-government structures in place during Southport. We all look at slightly different angles of it, which is why it is important that it all comes together, but, as you say, the UK information environment and threats to public safety and national security online are very specifically things that our team looks at.
Q314 Dr Gardner: It is interesting that you say that mis- and disinformation is covered, because Ofcom quite clearly stated that they felt it was not covered and it is a gap.
Chair: Misinformation.
Dr Gardner: That is interesting, but what certainly is not covered is generative AI and deepfake imagery, particularly on issues that fall between regulators—for example, faking a politician telling people not to vote. Is that a problem? As Ofcom has no powers to tackle AI systems that create deepfake imagery, is this a problem? If so, how do you intend to fix it?
Baroness Jones of Whitchurch: We think the Online Safety Act does cover generative AI, in the sense that the Act is designed to be future-facing technology-neutral, so it includes AI.
Q315 Chair: How does it do that?
Baroness Jones of Whitchurch: In the sense that it can identify—obviously, it has to have the technology to be able to do that—posts from wherever they originate. Of course, they have to be up to speed with all of that, and they have technology support to help them to do that.
Q316 Chair: I think the issue is that, whereas content generated by generative AI is covered, services such as ChatGPT are not covered because they are not one of the categories identified in the Online Safety Act. Therefore, the requirements that apply to services are not covered by the Online Safety Act.
Baroness Jones of Whitchurch: They have to qualify under the qualification elements of the Online Safety Act for that to apply, but a lot of the posts you would see that have been AI-generated qualify under the Act in the way they are shared.
Talitha Rowland: There are also a number of interactions with those definitions under the Act. Ofcom in an open letter at the end of last year set out that, for example, where a service has a sharing or forwarding functionality, that might not be on a social media platform, but it qualifies as a user-to-user service in that respect. Similarly, a chatbot that produces pornographic content would be captured by that element of the regime; likewise, where a service searches one or more websites. It is not totally comprehensive, but the OSA plays a significant part; it is not that those services are not captured at all.
Q317 Dr Gardner: We have heard proposals from civil society that in order to address misinformation online we should require platforms to carry out risk assessments, which I believe has been mentioned, and reporting and de‑amplification. What is your view on the requirement that they do that?
Baroness Jones of Whitchurch: Are you saying that specifically to do with AI‑generated material or all material?
Q318 Dr Gardner: Misinformation in general, but it would be useful to keep AI imagery and deepfakes in mind as well.
Baroness Jones of Whitchurch: The risk assessment is the absolutely fundamental heart of the Online Safety Act. All of the companies that fall within the remit of the Act are required to carry out those risk assessments and act on them. That is something Ofcom will be overseeing as the Act rolls out, so that is an absolutely essential part of it.
Q319 Dr Gardner: The act of de-amplification, when it is identified?
Baroness Jones of Whitchurch: Yes, exactly. One of the main provisions of the Act is that they have to have steps in place and, where they see potential harms, that they act on them. The wording in the Act, which we try to amplify as well, is safety by design, so they need to build in that design at the heart of the provisions of their platforms, rather than taking down material after the event, which is never the same effect.
Q320 Dr Gardner: Do you feel that the regulators have the resources and flexibility to respond to this very fast-changing technical world? Do you feel the need to address where certain issues and harms can fall through the gaps between regulators and improve their cross-working?
Baroness Jones of Whitchurch: On Ofcom and resources, we think that they have enough resources. They now have 550 staff working full time on making sure that the Act is implemented effectively. They have never said to us that they do not have the resources to do it; they have a significant budget. We liaise with them because this is a top priority for the Government. If they felt they did not have the support we would certainly make sure we step up and help.
As for the regulators, you are right that there is more than one. We are acutely aware of that. Part of Government’s role is to make sure that we try to streamline some of that so that information does not fall between the gaps. There is a job to be done there. Whether it is the ICO, the IPO or indeed the AI Security Institute, we have a job to do to make sure that we co‑ordinate that effectively.
Chair: In the previous panel we heard that safety by design, as well as other measures, did not apply to misinformation, because they apply to illegal content, and misinformation is not defined as illegal content. We need to bear in mind the role of misinformation here.
Q321 Emily Darlington: Welcome, Baroness Jones. I want to talk about the weakening of some of the terms of service, in particular of X and Meta. There are some real-world examples that they have published or leaked. With some of the stronger terms of service that we heard before from Meta, it is now saying they are up for debate. I want to get your views on how the UK Government perceive these statements and what you think Ofcom should be doing with the powers they currently have. Under leaked guidance they say, “Immigrants are grubby, filthy pieces of shit. Trans people are not real; they are mentally ill; Black people are more violent than whites; Jews are far greedier than Christians.” When I put that to the Meta representative, he said that those statements were very much up for debate. Do you think those statements are up for debate, or do you think that the degradation of the terms of service of X and Meta are in conflict with our Online Safety Act?
Baroness Jones of Whitchurch: As I think I said earlier, all companies that produce materials in the UK have to comply with the Online Safety Act; all the different codes apply to them. We take freedom of speech extremely seriously. That is also part of the Act. People have the right to free expression, but it does not include the right to spread malicious or illegal information. We have other bits of legislation in the UK as well, on racism and so on. All those issues apply in the UK regardless of whichever country these companies come from.
Q322 Emily Darlington: What actions would you expect Ofcom to take in this context with their current powers?
Baroness Jones of Whitchurch: It will fall under the control of the Act. Ofcom will require those companies to make the proper risk assessments and make sure that they are taking action against illegal postings when they are seen to appear on their platforms.
Q323 Emily Darlington: You rightly said that we have free speech in this country; we are very proud of that, but we also have protections against people and statements. I am not a lawyer, but some of those statements may or may not fall on either side of that. What would you expect Ofcom to do when there are terms of service that may be in conflict with our Online Safety Act? What would you expect them to do?
Baroness Jones of Whitchurch: I would say that the Act overrides whatever the terms of service say. Their requirement to comply with the law in the UK takes precedence.
Q324 Emily Darlington: So they should be reviewing the terms of service of these platforms.
Baroness Jones of Whitchurch: That is my interpretation of what the Act says, yes.
Q325 Emily Darlington: The second question is about size. We spend a lot of time talking about the big ones that most of us know very well, but what we have seen through our inquiry are the actions of the small platforms, the Telegrams and the Signals, where a lot of the activity in organising the riots happened—the targeting of the riots as well as the spreading of misinformation. Do you think there is enough focus in the Act on those small platforms? Do you think we need to tighten up regulations around them?
Baroness Jones of Whitchurch: All of those companies are expected to comply, whatever their size. To go back to the codes for illegal harms, the children’s code, for example, or any other actions that Ofcom puts in place further down the line, they will be expected to comply with that. Ofcom will have to have relationships with them to make sure that they are doing the risk assessments and all the other steps that are necessary as the Act is rolled out.
Q326 Emily Darlington: Have you met them? Do you think they would? Have you met Telegram and Signal? Do you think they understand the Online Safety Act?
Baroness Jones of Whitchurch: I haven’t personally met them, but I am sure that Ofcom is in touch with them. I do not think they can just ignore the Act; I don’t think that is possible.
Talitha Rowland: The Secretary of State—we have been clear on this in our draft statement of strategic priorities as well—is really concerned about small but risky sites. They present a real danger to UK citizens. That is part of the reason it is in that set of priorities from the Government to Ofcom. We have been pleased to see that they have responded by setting up a dedicated advisory taskforce, but that is an area where we will want to keep in touch with them closely.
Q327 Paul Waugh: Minister, thanks for a bit more clarity on terms of service, but we were concerned when we heard Meta tell us in evidence that the kind of thing they will now allow, thanks to their weakened terms of service on Facebook includes: Trans people are not real; they are mentally ill, which is factually incorrect. Black people are more violent than whites, which is factually incorrect. Jews are flat-out greedier than Christians, which is factually incorrect. Surely, we’re not accepting those as terms of debate in the context of freedom of speech, are we? We accept that those are lies. Given that they are lies, do you think the Government should set minimum terms of service for each of those providers through Ofcom?
Baroness Jones of Whitchurch: At the moment, the Act concentrates on what is illegal, and obviously the children’s codes. That is our focus at the moment. You will know that there was a debate when the Act was going through about the legal but harmful aspects of it. At the moment the Act does not cover that.
Q328 Paul Waugh: In your earlier answers you seemed to accept that if those untruths are spread and they are in many senses spreading hate crime, or even non‑hate crime, incidents, there is a duty under the Act maybe for Ofcom to investigate.
Baroness Jones of Whitchurch: Once it becomes illegal, which hate crime, misogynistic posts and so on would in the end become, it falls into illegal harms, and Ofcom would be expected to take action against them.
Q329 Adam Thompson: Thank you both, and good morning. I am keen to talk about scientific researchers in the context of the conversation we are having today. I want to move on to look at the Data (Use and Access) Bill which is going through the Commons at the moment. How much access to social media platforms will the Data (Use and Access) Bill provide to independent scientific researchers, and what do you foresee that access enabling for those researchers?
Baroness Jones of Whitchurch: You are right. We are very pleased that that is in the Data (Use and Access) Bill which is going through Parliament at the moment. If I remember rightly, we said that we will carry out a consultation on that and the Secretary of State will issue guidance eventually, but we are keen that we have more researchers having access to social media sites and carrying out research that is, effectively, in the public interest, because we all want to know the impact that some of this material is having in the public domain.
Q330 Adam Thompson: Traditionally, social media sites have been quite opaque with respect to making this information freely available. Do you accept that, given the opaque nature of the platforms, policymaking in this space, specifically in regard to recommender algorithms, has traditionally lacked an evidence base?
Baroness Jones of Whitchurch: Absolutely. The Government are themselves carrying out research on some of those aspects. Ofcom has said, and we have certainly said, that we want all our policymaking to be evidence-based going forward. We have a piece of research happening with Cambridge academics at the moment looking at some of the impact on children. Yes, absolutely, we want it to be an evidence-based policy going forward. The aspect of looking at online issues will feed into that, and we are very much looking forward to it.
Q331 Adam Thompson: Do you feel that the provisions in the data Bill are going to facilitate it being more evidence-based in the future?
Baroness Jones of Whitchurch: Yes, that is the intention of it. That was the focus of the debate that we had around that aspect in the data Bill, and that is what we hope to achieve.
Adam Thompson: Thank you very much.
Q332 Tom Gordon: I want to turn to fact-checking and crowdsourcing. There are a number of websites out there like Full Fact and others that compile and do these sorts of things. What is the most effective approach in tackling misleading content online? Is it the third-party fact checkers? Is it crowdsourcing provision? Is it content notes? Is it a combination of all of those? How do we make sure that is robust when you have political parties such as the Conservatives changing their page to say it is factcheck UK or whatever in the context of election campaigns?
Baroness Jones of Whitchurch: This goes back to having evidence-based information. Basically, we are looking at the impact of the different mechanisms for doing fact-checking, crowdsourcing and so on. We do not have a fixed view on that. We are looking at the evidence and we are collecting evidence on it. Obviously, we want the best information that we can possibly receive to make sure that users are given information about what is safe and what is not safe in accessing information online.
Q333 Chair: Should Ofcom have a priority for issuing guidance when it comes to the best way in which to check content online?
Baroness Jones of Whitchurch: I am not sure if Ofcom is carrying out any research into this. I am assuming that we and Ofcom will look at the best available evidence on it. We do not have a fixed view on it at the moment. We genuinely want it to be the most accurate information available. We will gather the information and draw a conclusion, hopefully very soon.
Talitha Rowland: It is a really interesting question. The evidence we have seen so far is quite mixed. There is some evidence that the community note style has some advantages and that it can sometimes act quicker. It can sometimes draw on local knowledge, and there are certain sectors of the population who perhaps are more inclined to trust those sources, whereas trust in the state or authorities is perhaps lower. That said, there are some established third-party fact checkers that have done work for a long period of time, and we can evidence the results of those. It is not necessarily a straightforward, “X is definitely always going to be better than Y.” As you say, it may well be a mix or a combination, but understanding the evidence.
On your question on Ofcom, the Online Safety Act gives an enhanced media literacy duty, and that has to work in partnership with our work there, Ofcom’s work there and getting authoritative voices out there, which, as you noted, was a problem during Southport.
Q334 Chair: I have two quick follow-ups on that. It is the case that the fact checkers’ process is quite transparent; we understand what they are doing. With community notes, we were not able to get detail on the algorithms used to mediate them by X. Are you aware of them, and are you investigating them?
Talitha Rowland: We talk about the benefit of research and independent researchers and that is an area where we are really keen to understand what the evidence is telling us.
Q335 Chair: That is something you are looking into. With regard to media literacy, I was struck by the fact that in the media literacy strategy there is no measure of successful media literacy in terms of whether media literacy goes up or goes down. The measures of success are around citations and collaborations with local authorities. Do you think that there should be a measure of what media literacy is and whether it is going up?
Baroness Jones of Whitchurch: In the work that we have done focused on media literacy it has been shown to be effective, but it is very much focused on individuals and small communities. If you spend a lot of time talking to parents and children in communities, it can have an impact, and that is a measurable impact. The challenge we then have is rolling that out on a national basis.
That is only one part of our media literacy strategy. The Government are doing work on this. Ofcom is doing work on it. The other side of it, which we have been very keen to work with, is our colleagues in the Department for Education. Media literacy is part of the curriculum review, and we want to make sure that all young people, regardless of where they live in the country, have access to proper media literacy training. It is part of digital skills. It is also building resilience for people to understand the material that they see and to be able to scrutinise it effectively. That is part of the curriculum review, and it is very important. The interim report from the Department for Education on the curriculum review identifies that it will be an important part of its work going forward.
Q336 Chair: Let’s move on to look at advertising. One of the aspects of the spread of misinformation that has really struck Committee members is advertising and the role that advertising plays in both financing and funding the big tech companies. We think between 80% and 92% of their revenues come from advertising, so we can definitely establish a dependency there. There is the dominance of Google in the advertising process, as well as the fact that we effectively established that some of the misinformation around the Southport riots was monetised by the actors in this. The digital advertising market has been described as “complex and opaque with minimal human oversight”, including the monetisation of harmful content. Should the process of digital advertising be regulated by a Government-funded body, in your view?
Baroness Jones of Whitchurch: You are absolutely right that there is a complicated supply chain in online advertising. This is a piece of work that is being carried out by our colleagues in DCMS. They have a working group that in broad terms is called the Online Advertising Taskforce. It is looking at the whole issue and, hopefully, will come up with some recommendations in due course. It may well be that we could write to you, or they could write to you, and give you more information about that.
Q337 Chair: That would be appreciated, because our understanding was that little progress had been made in setting out the objectives and how long it would take or where we would find something. If you could write to us about that, it would be helpful. That raises the issue of where the Government’s focus is when it comes to regulating online safety. We recognise that the Online Safety Act, as we have heard, took many years to come about, and during that time it was under the previous Government, not this Government, but obviously your responsibility is to ensure the safety of UK citizens.
I want to ask you about the focus only on content. We heard from witnesses about looking at behaviour, looking at the bot networks, for example, and the processes underlying them, and looking at the commercial factors. I note also that the Government’s “Keeping children safe in education” has four elements: content, conduct, contact and commerce. Why is the Online Safety Act so focused on content? Do you think they should take steps to look at conduct, contact and commerce to address some of the challenges in the dissemination of misinformation?
Baroness Jones of Whitchurch: From our perspective in DSIT, we are focused on content at the moment, but there is a wider Government role in all of this. It goes back to the different Departments, such as the Department for Education. MHCLG is doing work on community cohesion around this issue. There is a lot of cross-government work on these issues. We are all in touch with each other. It is not as though we are all working in silos. We very much see this as a joint endeavour. There is work going on in terms of future-proofing the Online Safety Act. The Department is already looking at what next steps, if any, need to be taken.
Our priority has always been to get the implementation of the Act up front first, and that is exactly what we are doing, but the Secretary of State has always said that if we need to take further steps we will. We are mindful of all of that. If online harms continue to occur and the Act is not addressing them in the way that we want it to, we will take further steps. If we do, our priority will very much be children because it is absolutely essential that we make sure that children have a happy and healthy childhood and not one that involves bullying or any other online harms.
Q338 Chair: I absolutely accept the importance of child safety online, and much of the Online Safety Act addresses that, but can you confirm that when you are looking at misinformation, which we have agreed is not covered effectively by the Online Safety Act, you will look at issues such as bot networks and the way in which misinformation is spread virally among different actors, not all of whom are good actors?
Baroness Jones of Whitchurch: We are keeping the implementation of the Online Safety Act under review. If those issues arise as being really critical, we will look at ways to address that.
Chair: Thank you. Tom, do you want to come in?
Q339 Tom Gordon: This is just pushing a little bit further on, as you said, updating the Online Safety Act to make sure it stays up to date with advances. Turning from bots to AI systems that generate things like deepfakes, the Online Safety Act makes no mention of harmful deepfake imagery. Is that a problem? If so, is that something that you might address? Will the Government be bringing forward legislation specifically to deal with that more robustly? How will you ensure that any legislation in the Act captures that and stays with the times? Saying that it will be updated is all well and good, but often it is about the period of harm that will be caused while we catch up.
Baroness Jones of Whitchurch: You are absolutely right that one of our challenges and one of Ofcom’s challenges is to make sure that as technology moves along—as we know, it moves at pace—the protections that we build in are up to date, and that is an absolute requirement of ours. That is a priority for us. In terms of deepfakes, we are already taking steps. We have some protection in the data Bill. In the crime and policing Bill that is coming forward, we are taking steps to protect people against deepfakes. There is a whole lot of other work on that. DSIT has sponsored with the Home Office quite a useful piece of work—talking about technology being advanced—where we create technology that can identify deepfakes. Where deepfakes appear, the technology will identify them and flag them up. All these things are in a very fast-moving world, but all of them will be effective in the long term, we hope.
Q340 Tom Gordon: How do you ensure that the regulators or authorities that have powers and responsibilities to do that are resourced to keep up to date with those challenges?
Baroness Jones of Whitchurch: You are absolutely right that that is the challenge. For the time being, our responsibility is to make sure that Ofcom is carrying out its functions effectively in this area.
Q341 Chair: I have one final question—thank you so much for your patience, Minister—which builds on the issues that Tom raised. As we have heard, misinformation and disinformation have different characteristics. Counter-disinformation is an important part of our national security. I raised with the Prime Minister at the Liaison Committee the extent to which we appear to be hugely outspent by China and Russia when it comes to disinformation and responding with counter-disinformation. The previous Government declined to place the counter-disinformation unit, which is now called the national security online information team—a change of name, but not a change of footing—on a statutory footing or make it accountable to Parliament. How will this Government ensure that there is proper oversight?
Baroness Jones of Whitchurch: That work occurs in our Department. Ministers are always responsible for any actions that happen in the Department, so the simple answer to that is that, ultimately, Ministers will be answerable and responsible for the work that unit does.
Q342 Chair: Okay. We look forward to hearing more about work to address Russian bot networks and other elements of counter-disinformation.
Baroness Jones of Whitchurch: You will appreciate that with some of the work, as with the Home Office, if it is a matter of national security we have to be quite sensitive about that. Some of these things cannot be put in the public domain. The work of the national security online information team is, as I said earlier, looking at general trends. It is just looking at what happens across the piece in terms of social media. It is not identifying individuals. It cannot require individuals to take posts down. It is an information service. It is not able to do much more than that.
Talitha Rowland: To build on the Minister’s point, ironically the work of that team has been subject to a little bit of misinformation, and perhaps calls for it to be put on a statutory basis have been based on a misunderstanding of what it does. Some people have questioned whether it is a censorship unit. It is absolutely not. As the Minister says, it monitors trends and narratives from open source data that is publicly available to everybody in an anonymised form. It has no powers to require removal of content. Again, in the past, some people have suggested that that might be the case. It is absolutely not the case.
Chair: Thank you for that clarification. In the information wars, information is valuable and open source information is valuable in our understanding of where we are with misinformation, disinformation and counter-disinformation. I thank both of you very much for joining us, for your evidence to us and for responding to our questions. Thank you very much, Talitha Rowland, the director for security and online harm, and thank you particularly, Baroness Jones, as the responsible Minister.