PRS for Musicwritten evidence (LLM0071)

 

House of Lords Communications and Digital Select Committee inquiry: Large language models

 

 

About PRS for Music

PRS for Music is a world leading music collective management organisation representing the rights of more than 165,000 songwriters, composers, and music publishers around the globe. Headquartered in the UK, it works diligently on behalf of its members to grow and protect the value of their rights. With a focus on innovation and integrity, PRS for Music is redefining the global standard for music royalties to ensure creators are paid whenever their musical compositions and songs are streamed, downloaded, broadcast, performed and played in public. In 2022, PRS for Music distributed £836.2m in royalties to its members.

 

Response Summary

PRS for Music welcomes the opportunity to respond to the Committee’s inquiry.

 

The UK music industry is a world-leader because of the extraordinary talent of its creators. These songwriters, composers and artists, as well as the businesses which support them, rely upon a robust IP and copyright framework which ensures they are paid when their works are used.

 

We were struck by the exclusion of “content producers” from the government’s Pro Innovation White Paper. Many large language models, and the AI tools they underpin, rely on copyright protected works as training materials. We believe an enforceable, principle-led approach to regulating LLMs and the AI sector is needed, one that establishes clear and robust guardrails for the continued development of these technologies; a regulatory framework that is strong and agile enough to respond to future evolutions. This framework must include a clear statement of the applicability of existing legislation, including the fundamental principles of copyright.

 

To assure a mutually beneficial future for AI and the creative industries, the UK would benefit from clear regulation on data stewardship, transparency and auditability of AI tools, to ensure legal certainty and a balanced, well-functioning market. These will be essential in enabling rightsholders to monitor the use of their works and, where necessary, enforce their rights. All AI assisted and generated outputs should be identifiable as such whether through labelling or within the metadata. These identifiers should be permanently attached to the output, and all subsequent exploitations and derivative works.

 

There is a need for the UK to not only lead on technological advancements, but also on speed of regulation. The UK should promote responsible and safe AI via an obligation on AI tools to meet ex ante requirements to access the UK market; and non-compliance should be met with ex post penalties. Other prominent AI markets are putting forward similar provisions, meaning the UK risks being left behind by other legislation that could become the de facto standard practice if it does not take advantage of this crucial juncture.

For regulation to be effective, there must be an appropriate regulatory framework in place, possibly administered by a specific regulator working with existing sector-specific regulators. International co-ordination will be vital to avoid forum shopping; and there should be collaboration between government, regulators and all stakeholders, including subject matter experts and industry specialists outside of the AI sector, so there can be mutual deliberation and understanding of the impacts of any policy decisions advanced. The UK government could take the lead in creating and supporting such an ambitious approach to AI regulation.

 

Response

 

Capabilities and trends

 

  1. How will large language models develop over the next three years?

 

    1. Given the inherent uncertainty of forecasts in this area, what can be done to improve understanding of and confidence in future trajectories?

 

LLMs underpin consumer facing AI products. As these products improve, and consumer adoption widens, AI tools will become increasingly integrated into our daily lives and use cases and business models will become more apparent.

We can assume that we will continue to see sustained and rapid, most likely accelerating evolution, proliferation and adoption. This will be further enhanced as the cost of quantum computing becomes more manageable and its use moves beyond the primarily theoretical. As the systems grow and evolve, becoming increasingly powerful and complex, it will become commensurately more difficult to understand them, and to regulate their activities and operations.

 

To create confidence in the future trajectory of AI, it is imperative to lay the groundwork now, to ensure that the legislative and regulatory framework is fit for purpose and future proof. There need to be clear, enforceable guardrails that embed transparency, auditability and accountability, so that stakeholders throughout the value chain are aware of and can benefit from each other’s mutual obligations.

 

The framework should require, as a basic starting point, compliance with the existing legislative framework, including copyright and intellectual property and data protection, all of which have been ridden over rough shod thus far. Only services compliant with the legal and regulatory framework should be allowed to access the marketplace.[1]

 

For instance, it is insufficient for AI developers to say that the scale of ingestion prevents licensing, record keeping, good data stewardship and disclosure. They have designed and built the product; the ability to meet these fundamental expectations should be built in from the start.

 

Furthermore, mechanisms to ensure the labelling and identifiability of AI generated outputs should be intrinsic to AI products; users and consumers must be able to understand the product they are exposed to and/or consuming.

 

Consumers, whether business or individual, should be able to make an informed decision about the services they use and the content they consume: all materials produced by AI systems must be clearly and immutably labelled as such. Consumers and stakeholders should be able to access information that enables them to understand how the AI system operates.[2]

 

There should be clear obligations as to the standards expected of AI services and the chain of accountability. There should be simple and accessible mechanisms by which stakeholders and consumers can make an inquiry or complaint about a service, and if necessary, seek redress.

 

Trust will be built by assurance that businesses are transparent, ethical and legally compliant in their operations.

 

  1. What are the greatest opportunities and risks over the next three years?

 

    1. How should we think about risk in this context?

 

There are vast opportunities to be reaped from AI in all its guises and use cases. However, LLMs and foundational models pose a potentially existential threat to the music industry and the present approach in the UK does little if anything to engage with or mitigate that threat.

 

As previously noted, the UK music industry is a world-leader because of the extraordinary talent of its creators. Music creators are generally early adopters of new technologies and tools, embracing the myriad AI tools available in their creative practice, from stem splitting to ideation, from audio synthesis to mixing and mastering, to explore the outer reaches of their creativity and push the boundaries of their art. These songwriters, composers and artists, as well as the businesses which support them, rely upon a robust copyright and IP framework which ensures they are paid when their works are used. The music business has a track record of implementing innovative solutions to reflect technological developments and meet the needs of the evolving market.

 

The quality of an LLM depends on the size, amount, diversity and quality of data used in its training, and the complexity of the learning algorithms used in that process. This means that the LLM is dependent on the ingestion of data from its foundation stage, throughout its tech stack. At present, we are experiencing industrial scale infringement as copyright, and the need to seek the authorisation of rightsholders prior to the use of copyright protected works and remunerate the creators, is entirely disregarded.

 

It is a story we have seen before: big tech takes advantage of the rapidity of their advancements, and the difficulty in applying legislation in real time. These businesses scale at an incredible speed and accumulate significant market power, by which point rightsholders are in an adverse position and thus struggle to secure the true value of their rights, leading to the devaluation of creativity and creative assets. To give an example, the development of many user-upload content (UUC) platforms exploited ambiguity in Article 14 of the E-Commerce Directive, whereby a hosting service was not deemed liable for infringing works on its platform until such time as they were made aware of their presence and had failed to act to remove it. This resulted in a market in which UUC platforms were growing at the direct expense of the creators upon whose works the success of their services was built. It took nearly twenty years to rectify the legislative framework at a European level and the effects of the distortion to the market continue to be felt.

 

Creators’ rights are being entirely overlooked as their works are ingested with no authorisation or remuneration, and the output from music generative AI tools is replicative of or even substitutional to the work of human creators.

 

AI and copyright dependent industries are not intrinsically in conflict; both are highly creative, innovative sectors and both stand to benefit from a cohesive legal framework in which rights and responsibilities are clearly defined. Robust and clear regulation creates legal certainty, which enables businesses to innovate and to take on investment, safe in the knowledge that they are compliant with the law and there is no threat of litigation on the horizon. The route to legal certainty when using copyright protected materials is to seek a licence from the appropriate rightsholder(s).

 

There are further risks arising from the current lack of transparency. Although crucial to the creative industries, these risks cross over into prevention of bias and discrimination. Transparency, auditability and accountability should be the pillars upon which a responsible and workable framework for AI is built. The UK finds itself at a critical juncture, where it needs to act swiftly to futureproof the AI ecosystem, so that the right principles are baked into business models now forming.

 

Consideration must also be given to the legal lacuna as regards publicity, image and personality rights. Creators and artists have already expressed serious concerns about the misappropriation of their identity and names. The UK should explore legislative options to ensure appropriate protections are in place to respond to generative AI misappropriating people’s identity. The use of someone’s voice, just like the use of their musical works or their personal data, must only be at their express consent.[3]

Domestic regulation

 

  1. How adequately does the AI White Paper (alongside other Government policy) deal with large language models? Is a tailored regulatory approach needed?

 

We welcome the broad principles set out in the White Paper; however, we have concerns regarding specific issues and enforceability.

 

It is a source of serious alarm that Part 3, paragraph 34 states that the proposed regulatory framework “does not seek to address […] the balancing of the rights of content producers and AI developers”. This neglects the vital role content producers play in the development and advancement of AI and could be read as suggesting that somehow respect for copyright and intellectual property is secondary or optional.

 

AI systems need quality data upon which to train. Copyright and IP assets are invaluable to AI and should be recognised as such in the regulatory framework; failure to do so leaves the music industry and the wider creative industries, a significant contributor to the economy, exposed to serious harm. Measures to balance the relationship between rightsholders and AI developers should be a central pillar of any regulatory or legislative approach.

 

The White Paper lacks a clear statement that the existing legal and regulatory framework applies to the development and deployment of AI in all its guises and contexts. It should be clear that exploitation or use of copyright protected material must be preceded by the authorisation by the creator/rightsholder and their due remuneration. It should set out robust obligations around realisation of the principles in that context.

 

The principles set out in the AI White Paper would also benefit from clear provisions on the transparency and auditability of AI tools, to ensure legal certainty and a balanced, well-functioning market. The very nature of AI, particularly LLMs, makes it very complicated, if not impossible, for rightsholders to monitor or identify infringement, meaning it is very difficult and costly to initiate the pursuit of redress. Therefore, there must be robust obligations around transparency and data stewardship to assist rightsholders in monitoring the use of their works and, where necessary, enforcing their rights.

 

Transparency should be a fundamental principle imbued across the AI industry, throughout processes and lifecycles. Regulation should mandate that AI developers and users be transparent about the data they are causing or permitting to be ingested in the development, training and finessing of the system, including but not limited to how and from where they have sourced the data(set) and the authorisations sought/attained for its use. The metadata of ingested works should remain intact and uncorrupted, and ensure any works created are fully identifiable as the product of AI.

 

There should be transparency over how the dataset is processed by the algorithm, and the role played by prompts. Measures should also be taken to permit appropriate attribution.

 

All AI assisted and generated outputs should be identifiable as such, whether through labelling or within the metadata. These identifiers should be permanently and immutably attached to the output, and all subsequent exploitations and derivative works. There should be mechanisms by which it can be understood how the AI arrived at the decision/generated the output, whether that be for the purposes of audit or attribution. This will be a critical aspect of individual and consumer protection as AI continues to proliferate and adoption widens.

 

AI developers should also be transparent about the steps taken to prevent infringement of IP rights at each stage.

 

Finally, many LLMs are based outside the UK and may argue that their operations are outside UK jurisdiction. With that in mind, compliance should be a precondition of market access.

 

More broadly, the proposed framework leaves many unanswered questions which will give rise to varying challenges:

 

 

 

 

 

 

 

  1. What are the implications of open-source models proliferating?

 

The proliferation of open-source models increases the likelihood of IP infringement, bias, governance issues, security risks: by its very nature it is “off grid” and as such open-source models do pose greater risks. The decentralised and iterative nature can exacerbate the difficulties associated with record keeping and access to data; compliance with data protection and the norms of data stewardship; and the complexity of accountability.

 

While open-source models can be said to level the playing field, they can also be responsible for entrenching bad practice throughout their use network. Therefore, it is imperative to have a meaningful, pervasive and enforceable framework that captures the entire lifecycle and tech stack of any AI product.

 

The positive potential of AI should not be permitted to override the need for gold standard governance; progress does not require unfettered liberty, nor should it come at any cost.

 

  1. Do the UK’s regulators have sufficient expertise and resources to respond to large language models? If not, what should be done to address this?

 

Given the scale and complexity associated with AI tools and products, we recognise the arguments for an overarching UK regulator, with the specific skills and expertise, and the appropriate powers to reflect the rapidly evolving nature of AI and how technical the issues can be.

 

In addition, specific regulators could have responsibility for AI as it affects their sectors, in the knowledge that all existing legal obligations and frameworks continue to apply, regardless of whether they fall within the remit of a specific regulator. Additional expertise and resources to ensure understanding of the application of different areas of the law to AI would be welcome and necessary. Given the breadth of the sector and its applications, there is no obvious regulator among existing organisations.

 

The overarching regulator would be empowered to work with and coordinate the work of existing regulators, overseeing a central regulatory framework, rather than several varying interpretations of principles. Any such overseeing regulator would need to be amply resourced and have significant expertise in the development and deployment of AI, and also to draw from the expertise of existing stakeholder sectors such as the music and wider creative industries. AI should not be contemplated in isolation but rather we ought to adopt a comprehensive, holistic approach, which balances all interests.

 

But for regulators to be effective, there must first be an appropriate regulatory framework in place. A collaborative effort between government, regulators and stakeholders would yield the best results to achieve a balanced framework. Stakeholders should not be limited to AI experts but instead include sector-specific subject matter experts and industry specialists, so that there can be mutual deliberation and understanding of the impacts of any policy proposals advanced.

 

  1. What are the non-regulatory and regulatory options to address risks and capitalise on opportunities?

 

a)              How would such options work in practice and what are the barriers to implementing them?

 

b)              At what stage of the AI life cycle will interventions be most effective?

 

c)              How can the risk of unintended consequences be addressed?

 

Each stage will pose different challenges and may require a degree of nuance to ensure the highest standards of conduct.

 

The risks of unintended consequences can be addressed via the measures listed in the previous answers. There are some interventions, around transparency, auditability and labelling measures, which are necessary now, as is a clear statement that unauthorised ingestion of copyright protected works is copyright infringement. Further legislative interventions may be necessary in the medium-to-long term, but more evidence is needed to assess further implications of a developing market.

 

The aforementioned risks need to be clearly addressed in order to ensure tech businesses can operate within legally certain boundaries and therefore with confidence. Once a regulatory framework is put in place with respect to transparency, data stewardship and traceability, it should play out through a combination of an ex ante onus on AI tools to meet compliance requirements for market access and ex post regulatory powers to suspend activities and penalise those found to be not compliant.

 

In practice, as a starting point, only services compliant with the legal and regulatory framework should be allowed to access the marketplace. Government could consider measures that incentivise start-ups and scale ups to attain ever higher levels of ethical standards and transparency from inception. Points of access to the market, such as app stores, search engines, open-source platforms, are important tools to regulate the sector, including either deprioritising or blocking services that do not meet levels of good practice.

 

As for non-regulatory measures, guidelines around good practice could be useful, particularly around what complying with existing legislation would mean concretely for LLM models, in areas such as data protection and copyright law. Education and training could be provided, thereby taking a proactive approach to shaping good behaviour. However, we do not believe that non-regulatory measures alone will suffice to achieve a well-functioning market for responsible AI.

 

International context

 

6.              How does the UK’s approach compare with that of other jurisdictions, notably the EU, US and China?

 

a)              To what extent does wider strategic international competition affect the way large language models should be regulated?

 

Effective regulation of LLMs will require international collaboration. Given the intrinsically global nature of web-based products and activities, a supranational agreement in which all signatories commit to high standards of protections and accountabilities is the only way to truly harness the benefits and mitigate the risks. Such an approach would address the risk of a race to the regulatory bottom driven by forum shopping.[4]

 

As currently proposed, compared to other major global players such as the EU and China, the UK’s approach to AI regulation lacks clarity and rigour. The UK can and should seek to learn from positive steps taken in these jurisdictions, namely around transparency, auditability, data governance and respect for existing legislation, including IP rights.

 

Both the EU and China have adopted positions which introduce guardrails for the development of the AI sector, carefully balanced with individual rights, based on the principle that having a clear regulatory framework is the most effective way of fostering a healthy market. In addition, in a global marketplace, the earliest and/or most stringent regulation often sets the standard for multi-national firms’ operations, the first mover advantage. Much like what happened with GDPR and data protection regulation around the world, the EU’s AI Act could potentially become the global standard for AI regulation, as compliance with the EU regime will be required to trade in and with the EU market bloc.

 

The EU has taken a horizontal cross-sector approach, classifying AI systems by risk, and mandating various development and use requirements, focussing primarily on rules around data quality, transparency, human oversight and accountability. The risk-based approach goes as far as to prohibit certain uses of AI which are deemed to carry unacceptable risk, such as facial recognition in public spaces.

 

Of most importance to the music and wider creative industries and addressing what has been excluded from the UK approach to date, the EU Parliament’s position introduces provisions mandating that providers of foundation models intended to generate content must comply with transparency provisions; ensure compliance with EU law; and document and make publicly available a sufficiently detailed summary of the use of training data protected under copyright law.

 

The onus will be on companies to demonstrate risk mitigation and conduct both a risk assessment and a cost-benefit analysis before implementing a new AI system, especially if it poses a "heightened risk" to consumers. Risk assessments will therefore be standard practice, ensuring companies embed a degree of transparency and explainability for impacted stakeholders. There are also clear and meaningful non-compliance penalties proposed in the Act. For companies, fines could reach up to €30 million or 6% of global income. The Parliament position also increases the ability of individuals to file complaints about AI.[5]

 

China’s Interim Measures for the Administration of Generative Artificial Intelligence Services came into force on 15th August 2023. The Measures relate not only to AI service providers that generate and/or communicate any text, image, audio, video or other content to the public, but potentially also the use of such services. As currently drafted, the Measures apply primarily to consumer facing service providers, whilst allowing more room for manoeuvre for business-to-business services.

 

The Chinese approach stipulates, among other things, that offering service of, or using, generative AI technologies shall follow existing laws and regulations and observe rules such as non-discrimination; fair competition; respect for intellectual property rights and business ethics; respect for others’ rights, including rights of portrait, reputation, honour, privacy and personal information; and transparency and trust.

 

There are measures pertaining to the training of generative AI systems, including LLMs: they require training to be conducted in accordance with existing laws; using legitimate data sources; not infringe upon the IP rights of others; obtain the consent of the data subjects when personal information is involved; and comply with other statutory requirements. Generative AI systems will be subject to existing privacy and data protection legal frameworks.

 

China has also previously implemented legislation to address specific issues, such as recommendation algorithms, and the Provisions for the Administration of Deep Synthesis Internet Information Services, which regulate the supervision and control of content and compliance with regulatory requirements for all services of deep synthesis technology, i.e., technology that uses deep learning, virtual reality or any other generative or synthetic algorithms to produce text, images, audio, video, virtual scenes or other network information.

 

In the US, there is a lot of activity, but a coherent regulatory direction is yet to become apparent. Most of what has happened to date is on a voluntary footing or is in the very early stages. Most noteworthy from a music and wider creative industry perspective are the proposed AI Disclosure Act, which notes the dangers of both over- and under-regulation, and positions the labelling of output as an important regulatory first step; and the proposals for the creation of an overarching commission or agency to regulate AI. As in the UK approach, notable by their absence are meaningful provisions to protect the content upon which the systems are built.

 

The US has some existing laws that can be applied to the unauthorised use of an artist’s voice however these vary state by state and are insufficiently clear and not easy to apply; there is an opportunity to use these examples as a starting point and introduce something more effective in the UK.

 

The UK should look to these international partners and work with them where possible to ensure the AI sector can thrive within responsible and ethical guardrails, and not at the expense of other growth-generating sectors such as the creative industries.

 

We reiterate the necessity of global alignment if AI is to be regulated in a meaningful way. We highlight the inclusion in May’s G7 Hiroshima Leaders’ Communiqué of a statement on AI, in which they commit to international collaboration towards trustworthy AI and note the “importance of procedures that advance transparency, openness, fair processes, impartiality, privacy and inclusiveness to promote responsible AI”. We welcome in particular the attention drawn to the challenges of generative AI, and the specific reference to safeguarding intellectual property rights, including copyright and the need for transparency.

 

b)              What is the likelihood of regulatory divergence? What would be its consequences?

 

Regulatory divergence is inevitable, but also undesirable.

 

What’s more, it may be largely pointless. Where a large market or market bloc implements the first or most stringent/comprehensive legislative or regulatory framework, that can set the basic parameters for the wider global market as companies will typically structure their operations to comply with the most onerous rules to limit the need for alteration on a territory-by-territory basis. Should the EU succeed in implementing the AI Act, with a potential in force date in 2025, that may set the standard to which many global players will adhere to secure access to the world’s largest single market bloc.[6]

 

 

September 2023

11

 


[1]              This was also recognised in the recent Culture, Media and Sport (CMS) Commons Select Committee report on Connected tech: AI and creative technology. In paragraph 31, the report states that “the Government should support the continuance of a strong copyright regime in the UK and be clear that licences are required to use copyrighted content in AI. […] This Committee also believes that the Government should act to ensure that creators are well rewarded in the copyright regime”. https://committees.parliament.uk/publications/41145/documents/201678/default/

[2]              As the CMS Commons Committee put it in the aforementioned report, “the Government should consider how creatives can ensure transparency and, if necessary, recourse and redress if they suspect that AI developers are wrongfully using their works in AI development” (Paragraph 32).

[3]              This is in line with what the Department for Science, Technology and Innovation (DSIT) Commons Select Committee Governance of artificial intelligence: interim report, published on 31 August 2023, has dubbed the misrepresentation challenge. The report refers to the dangers of voice, image and character being misappropriated in deep fakes, saying “new AI models and tools massively expands the opportunities for malign actors to ‘pass off’ content as being associated with particular individuals or organisations when it is in fact confected” (Paragraph 54). https://publications.parliament.uk/pa/cm5803/cmselect/cmsctech/1769/report.html

[4]              The DSIT interim report on AI governance is very clear on this point, unequivocally stating “AI is a global technology, and the development of governance frameworks to regulate its uses must be an international undertaking”.

[5]              The EU AI Act is currently in trilogue and as such the compromise final position could change.

[6]              As the DSIT Commons Committee put forward in their recent report, legislation regulating AI “would help, not hinder, the Prime Minister’s ambition to position the UK as an AI governance leader. […] if the UK does not bring in any new statutory regulation for three years it risks the Government’s good intentions being left behind by other legislation – like the EU AI Act – that could become the de facto standard and be hard to displace” (Paragraph 106).