11 Call for evidence: Social media, misinformation and harmful algorithms
December 2024
Call for evidence: Social media, misinformation and harmful algorithms
Science, Innovation and Technology Select Committee
5Rights Foundation response
December 2024
TW: This response includes discussion of specific examples of Child Sexual Abuse Material.
5Rights welcomes the Science, Innovation and Technology Select Committee’s inquiry into the role that social media companies played in the spread of mis/disinformation during the UK 2024 riots.
For over a decade, 5Rights has advocated for an online world which treats children the same way we do offline. This means recognising their rights,[1] including their rights to safety, privacy, participation and information and, crucially, their right to life – ensuring the digital world is built with this in mind.[2] Practically, this means ensuring digital services and products are safe and age-appropriate for them to use and if they cannot be made safe, preventing children from accessing them.
We develop new thinking, innovative frameworks and technical standards to challenge received narratives of tech exceptionalism with a focus on implementable change. While we work exclusively with and for children under the age of 18, our solutions and research are relevant to many other communities.
In 2021, we published Pathways[3] which established the pathways between the design of digital services and products and the risks children face online. It showed services such as Facebook, Instagram and TikTok were allowing children, some as young as 13 years old, to be directly targeted within 24 hours of creating an account with a stream of harmful content. Through interviews with engineers and experts we established that the proliferation of harm online is a consequence of how services are designed, which is driven by the business model. While this research looked at harm to children, its findings on what drives design decisions of digital businesses and products are universal.
Key points
Business models of digital businesses drive design objectives
Digital services and products (including social media companies, search engines and others) have three core design objectives:[7]
These objectives are driven by their business model, which is to extract as much personal information (data) from users as possible, to help them predict, modify and influence user behaviour. For most digital businesses, financial success is dependent on advertising revenue, and advertising revenue is in turn dependent on knowing as much as possible about users[8] and keeping them engaged.[9]
Put simply: “The quantity of customers paying attention to the content on a product equates to the value of the business. The more people paying attention, the more people there are to serve adverts to. The more advertising, the more profit.”[10]
Algorithms and recommender systems are a core part of the business model
These objectives lead engineers and designers to create ‘choice architecture’ which “shapes what content is seen, by whom, and how users behave and interact.”[11]
Some of the most prominent and widely used features and functionalities by social media companies within this architecture are algorithms, infinite scrolling and easily swipe-able reels of content.[12]
Digital businesses who rely on this business model commonly use behavioural science to underpin their choice architectures. Humans take the path of least resistance by default, so services are often designed to remove as much friction as possible to keep them on the platform.[13]
Algorithms are fuelled by extensive data collection based on known and inferred characteristics of users (including physical, cognitive, behavioural and socioeconomic attributes).[14] This helps the system to decide what to show the user, based on their interests and other characteristics.
The spread of harmful content by algorithms is a consequence of the business model
The way algorithms are designed (to increase attention and engagement) often drives more extreme content to be shared, as more eccentric or ‘outside of the norm’ ideas or content tend to receive the most attention and engagement, which can lead individuals to express opinions that deviate from the norm.[15]
Some of the most popular social media services also reward extreme opinions by design, in the absence of an interactable or viewable ‘dislike’ option.[16]
Algorithms contribute to a “feedback loop of negativity” on social media services, with research by the University of Cambridge finding users are 1.91 times more likely to share news articles that are negative rather than positive.[17] Further,” loops” can also be “filter bubbles" that legitimise user engagement with harmful content – including mis/disinformation.
Personalised recommender algorithms “redistributes the information we consume to disproportionately confirm our beliefs.”[18] These bubbles are increasingly harmful when paired with the fact automatic recommendations decrease the sense of agency from users[19] – in particular where there are limited means to intervene in these recommendations.
Ultimately, algorithms act as “gateways” that determine what users can see and can unintentionally guide users down spirals of harmful content.[20]
We refer to our response above, however emphasise that, driven by the business model, content ranked by popularity (for example, content as part of a newsfeed) is given pride of place on the screen and algorithms designed to promote already popular content help it travel further while engagement rates increase.[21]
Generative artificial intelligence (GenAI) helps to facilitate the creation of persuasive disinformation and illegal and harmful content at scale, speed and low cost.[22] GenAI technologies already have the capability to create synthetic content that is more persuasive than, and indistinguishable from, human-generated content.[23] [24]
The creation and dissemination of harmful content through GenAI is possible as the companies who create and make available the proprietary technology (AI systems) make it easy to create this content and without adequate guardrails. Indeed, the catalyst for an AI model producing or spreading harmful content such as disinformation can be as simple as inputting nothing more than a well-structured question that instructs the system to “Do Anything Now.”[25]
There is a growing bank of evidence that shows GenAI is assisting the creation and spread of harmful content.
Research by the Center for Countering Digital Hate[26] into Google’s GenAI tool Bard (now Gemini) found in 78 of 100 cases it promoted false and potentially harmful narratives without additional context or disclaimers – including on topics such as climate, vaccines, LGBTQ+ hate and sexism.
Digital service providers, including social media companies and search engine operators, are responsible for hosting and spreading harmful AI-generated content. This stems from revenue-driven business models, weak or non-existent safety strategies and poor content moderation.
Case study: Instagram and AI-generated Child Sexual Abuse Material (CSAM)
Between December 2023 and May 2024, 5Rights worked with the Online Child Sexual Exploitation and Abuse (CSEA) Covert Intelligence Team (OCCIT) on an investigation into how AI-generated Child Sexual Abuse Material (CSAM) is being shared on Instagram.[27] [28] It revealed that Meta allows users access to AI-generated CSAM in as little as two clicks on the platform.
The investigation found a number of accounts on the service created with the key purpose of posting AI-generated CSAM of real and/or non-real children. These accounts are followed by hundreds and thousands of users – some with as many as 150,000 followers. The accounts include AI-generated images of children which were recommended to other users through Instagram’s own in-app features.
The investigation found content included:
The investigation found profiles which have shared content of real, underage girls dancing alongside sexual comments acknowledging subjects are underage and/or videos of men explicitly masturbating.
Some accounts also provided external links to where users can create and access AI-generated CSAM for payment. In the most egregious cases, these links lead to websites hosting spaces where groomers were encouraging children to create self-generated CSAM.
The UK's current legislative framework on online safety and children’s data protection is one of the most robust in the world.
The Age Appropriate Design Code
In 2018, Parliament introduced the Age Appropriate Design Code[29] (AADC, Children‘s Code or ‘the Code‘) as part of the Data Protection Act, which set out 15 standards digital businesses must abide by when handling children’s data, enforceable by the Information Commissioner’s Office (ICO).
Since it came into force in 2021, companies around the world – including the biggest tech companies in Silicon Valley – have made changes to the design of their platforms in order to make them safer for children.[30] Of particular relevance, the AADC includes the principles that children’s data must not be used to profile them,[31] and only ever processed when it is in their best interest to do so.[32]
The ICO has said that “it is unlikely that the commercial interests of an organisation will outweigh a child's right to privacy”[33] meaning it is unlikely that it would ever be in a child’s best interests to process their data through an algorithm designed to keep them engaged on the platform.
The Online Safety Act 2023
In October 2023, Parliament passed the Online Safety Act. Although many of its provisions are not yet in force, the Act is a positive step towards to creating a safer online world for the UK public.
The strongest powers in Act are given to the protection of children, with additional measures to give adults more agency over the types of content they see on the largest and most high-risk services (Category 1).[34]
The Act also introduces new priority offences, including offences relating to incitement to violence which leads ‘offline‘ harm,[35] as was seen during the riots. 5Rights believes the Act is robust in many respects, particularly for children’s safety online and we support the duty of care provisions and intention for accountability to be places on services.
The Age Appropriate Design Code and Online Safety Act provide a strong legislative framework for children’s safety, particularly as it relates to the design of digital services and products which include the safety and deployment of algorithms. However, while Parliament has set this agenda, we are concerned that the ambition and strength of the legislative framework is not being delivered through regulations and enforcement.
With regard to the Age Appropriate Design Code, we have raised concerns that the Information Commissioner’s Office (ICO) has not been robust in its enforcement of this Code. The ICO has not issued a fine under the Code, despite where we have provided evidence of rank non-compliance.[36] Where the ICO had announced it had sent notices to 11 services for breaches of the Code this year, they chose not to name the services.[37] Companies in breach of the Code being subject to heightened scrutiny is a matter of public interest and is an act of enforcement in itself. The ICO must be more transparent in its enforcement action so tech companies are held accountable for where it is not complying with UK law.
We have also raised concerns that the Online Safety Act codes of practice put forward by Ofcom, do not reflect the intention of the legislation and will leave children exposed to known harm.[38] [39] Ofcom’s proposals do not meet the intention of the Act which is to see that services are made ”safe by design." The majority of Ofcom’s proposals focus on ex-ante measures which cannot claim to meet the definition of safety by design. In addition, the codes function as ’safe harbour’ measures, which means services can simply adopt Ofcom’s proposals to be deemed compliant, even if risks to children are still present on the platform.
If the Act had been in force when the riots were taking place, a number of its illegal harms provisions would have been triggered. This includes Schedule 7 (Priority offences) with regards to the incitement to violence online. Indeed, some of the individuals charged in connection with the riots were done so under the Online Safety Act.[40]
However, while the legislation is robust in some respects, there are several key areas where it could, currently, fail to combat harms relevant to this inquiry.
‘Safe harbour’ provisions and algorithms
The Online Safety Act instructs Ofcom to create codes of practice to set out how services must comply with the Act. These codes serve as a ‘safe harbour’ meaning services only need comply with the limited measures[41] Ofcom outlines in the codes. This will mean that even where services have not met the safety duty and people are still coming to harm or facing unacceptable risk, services will still be in compliance with the law.[42]
Specifically on algorithms, Ofcom’s risk register includes considerable evidence of the risk posed by recommender systems, including how algorithms show suicide and self-harm content and eating disorder content to children who have not sought it out.
Ofcom’s own research found 7-in-10 teenage boys had seen content promoting misogynistic views via a recommender system[43] and that children can fall into ‘rabbit holes’ and filter bubbles where their feeds are filled with harmful content and fewer alternative kinds of content are shown.[44]
Despite this, there are limited measures which would fully mitigate or manage the risk from recommender systems. While the Code would require the prominence of harmful content in recommender systems to be limited, this would not address cumulative harm in a robust way. For example, these measures would not address harm caused by concentration and volume of Primary Priority Content (PPC),[45] Priority Content (PC),[46] and 'adjacent' content (e.g. high dosage of dieting, juicing, fitness, weight loss journey videos which could cause harm relating to eating disorders with no counternarrative). There are also no measures which would address ‘filter bubbles’ or ‘rabbit holes’ (i.e. when the way an algorithm is designed pushes users towards increasingly extreme content) as opposed to just removing PPC or PC.
Research has found that children in particular can ‘microdose’ on harmful misogynistic content through algorithms, which normalises these attitudes.[47] This normalisation has found its way into the classroom, with sexual harassment, sexual abuse and safeguarding increasingly being referenced in Ofsted reports.[48]
Misinformation and the risks to children
Another gap is that misinformation is not included in the categories of harmful content for adults or children within the Online Safety Act. This is despite research demonstrating the harm it is having on society and its connection to radicalisation.[49]
Due to their still developing cognitive abilities,[50] including their emotional regulation and moral development, children are uniquely at risk of radicalisation online. According to latest official data, 14% of those arrested for terrorism offences in the year ending 31 March 2023 were 17 and under.[51] Indeed, the UK Government guidance[52] identifies online radicalisation as a growing risk to children.
As set out earlier in our response, much of the UK’s existing online safety and data protection legislation, if enforced robustly and fully, could address the issues being investigated within this inquiry. With that said, there are two key areas that must be addressed in our legislative and regulatory framework to further combat harm online:
Amend the “safe harbour” boundary from the Online Safety Act codes of practice
As outlined above, it is Ofcom’s contention is that the wording of Online Safety Act prevents them from enforcing against services that do not fully meet their safety duties. In response to its draft Illegal Harms Code of Practice consultation, Ofcom argued:
“Codes set out the measures we recommend service providers follow to address their risks. We cannot include a generic measure that recommends service providers should remove all risks, as some stakeholders have suggested. The safety duties in the Act only require providers to take proportionate steps and we can only make recommendations we are satisfied are proportionate, having impact assessed them. We cannot assess the impact of a proposal if we do not know what compliance with it would entail.”[53]
Ofcom’s interpretation of the role of the codes of practice actively disincentivises tech companies from finding more effective ways to tackle these harms online. This was not Parliament’s intention and this will not meet public expectation of what this regulation will do.
We acknowledge that there is some value in the regulatory framework that Ofcom has produced to tackle illegal harms and ensure children’s safety, but it currently fails to reflect the purpose of the Act, the intention of Parliament or the needs of children and their parents.
We recommend reconstituting the ‘safe harbour’ boundary so that services would only be entitled to claim it if they have:
This framework would also be adaptable to many different services who will have their own mitigation strategies in place and have very complex design models (see figure below).
Regulate GenAI models and LLMs
The AI tech industry has little to no regulation in the UK, despite the evidence of risk these technologies pose to ,[54] [55] [56] [57] wellbeing[58], and national security[59]. These are not problems of the future; they are the problems of the here and now.
To meet the government's online safety objectives, regulatory authorities must be given the tools and a duty to investigate risky AI technologies such as algorithms, Large Language Models (LLMs) and GenAI models and establish an agreed standard by which to assess them. In some cases, it will be appropriate to create new offences.
Illegal content is still illegal even if its online, but the mechanism by which it can be created is not. For example, the possession and creation of GenAI CSAM is illegal, , the mechanism that enables its creation is not. To address this the Government should introduce a new criminal offence of possessing, sharing, creating or distributing an AI file that is trained on or trained to create CSAM,[60]
Which bodies should be held accountable for the spread of misinformation, disinformation and harmful content as a result of social media and search engines’ use of algorithms and AI?
As set out earlier in this response, the means by which individuals come into contact with harmful content online is not an accident but a consequence of the way tech companies design their systems and products. As Marisa Ressa, the 2021 Nobel peace prize winner explained: “Tech sucked up our personal experiences and data, organized it with artificial intelligence, manipulated us with it, and created behaviour at a scale that brought out the worst in humanity.”[61]
The responsibility for the spread of misinformation, disinformation and harmful content on social media and search engines must sit with those who have built the system and products that allow it to spread unfettered – the tech companies themselves.
|
|
|
[1] United Nations (1989) Convention on the Rights of the Child
[2] See also: United Nations Committee on the Rights of the Child (2021) General comment No. 25 on children’s rights in relation to the digital environment, which translates how children’s rights apply in the digital world
[3] 5Rights Foundation (2021) Pathways: How digital design puts children at risk
[4] See: The Guardian (2024) UK riots: Boy, 12, becomes the youngest person in England to be sentenced
[5] See: BBC News (2024) Child, 11, arrested in raids following riots
[6] Ofcom (2024) Encountering violent content online starts at primary school; Family Kids & Youth (2024) Understanding Pathways to Online Violent Content Among Children
[8] Zuboff, S. (2019) The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power, New York: PublicAffairs
[9] 5Rights Foundation (2023) Disrupted Childhood: The cost of persuasive design, pp. 9-10, 27
[12] See: 5Rights Foundation (2021) Risky-By-Design, Misinformation
[13] Disrupted Childhood: The cost of persuasive design, pp. 9-10
[14] Kant, T. (2021) Identity, Advertising, and Algorithmic Targeting: Or How (Not) to Target Your “Ideal User”
[15] Pandey, S., Cao, Y., Dong, Y. et al. (2023) Generation and influence of eccentric ideas on social networks, Scientific Reports, Vol. 13, 20433, DOI: https://doi.org/10.1038/s41598-023-47823-0
[16] Konovalova E., Le Mens G., Schöll N. (2023) Social media feedback and extreme opinion expression, PLoS ONE 18(11): e0293805, DOI: https://doi.org/10.1371/journal.pone.0293805
[17] Watson, J., van der Linden, S., Watson, M. et al. (2024) Negative online news articles are shared more to social media, Scientific Reports, Vol. 14, 21592, DOI: https://doi.org/10.1038/s41598-024-71263-z
[18] Turner, G., Ferguston, A. M., Katiyar, T., Palminteri, S. & Orben, A. (2024) Old strategies, new environments: Reinforcement Learning on social media, DOI: 10.31234/osf.io/f5cjv. In particular, we refer to Table 1, Taxonomy of social media affordances most relevant to the Reinforcement Learning process, pp. 4-5
[19] Gómez, E., Charisi, V. & Chaudron, S. (2021) Evaluating recommender systems with and for children: towards a muti-perspective framework, Conference on Recommender Systems
[20] Hopkins, S. (2024) The Link Between Social Media Algorithms and Online Radicalisation, Byline Times
[21] Disrupted Childhood: The cost of persuasive design, p. 32
[22] UNICEF Innocenti (2024) Generative AI: Risk and Opportunities for Children
[23] Myers, A. (2023) AI’s Powers of Political Persuasion, Stanford University: Human-Centered Artificial Intelligence.
[24] Nightingale, S. J. & Farid, H. (2022) AI-synthesized faces are indistinguishable from real faces and more trustworthy, Psychological and Cognitive Sciences, 119(8), DOI: https://doi.org/10.1073/pnas.2120481119
[25] The Guardian (2023) ChatGPT’s alter ego, Dan: users jailbreak AI program to get around ethical safeguards
[26] Center for Countering Digital Hate (2023) Bard: Google’s new AI chat generates misinformation when prompted on 78 out of 100 false and potentially harmful narratives without disclaimers
[27] See: 5Rights Foundation (2024) 5Rights challenges Meta’s inaction on AI-generated CSAM
[28] See: Daily Mail (2024) Instagram faces Ofcom investigation for ‘turning a blind eye to ads for child sex abuse’
[29] See: 5Rights Foundation (2021) UK Age Appropriate Design Code
[30] See: Woods, S. (2024) Impact of regulation on children’s digital lives, Digital Futures for Children Centre, 5Rights Foundation, LSE
[31] See: Information Commissioner's Office (2021) Children’s Code, Standard 12
[32] See: Information Commissioner’s Office (2021) Children’s Code, Standard 1
[33] Ibid.
[34] See: s.15 (User empowerment duties), Online Safety Act 2023
[35] See: Schedule 7 (Priority offences), Online Safety Act 2023
[36] Hausfield (2023) First complaint to the ICO filed against YouTube under the Children’s Code
[37] 5Rights Foundation (2024) 5Rights calls for robust enforcement to protect children’s data
[38] 5Rights Foundation (2024) 5Rights Consultation Response to Ofcom’s Children’s Safety Code
[39] 5Rights Foundation (2024) 5Rights Consultation Response to Ofcom’s Illegal Harms Code
[40] West Midlands Police (2024) Man charged in connection with video posted online
[41] 5Rights Foundation, alongside other organisations including the Online Safety Act Network, NSPCC, Barnardo’s, Molly Rose Foundation, the Internet Watch Foundation and a coalition of organisations forming the Children’s Coalition for Online Safety have set out in our responses how weak the measures are
[42] 5Rights Consultation Response to Ofcom’s Children’s Safety Code
[43] Volume 3, 7.4.15 of Ofcom’s draft Children’s Register of Risks
[44] Volume 3, 7.11.50 of Ofcom’s draft Children’s Register of Risks
[45] This is a type of harm categorised in s.61 of the Online Safety Act
[46] This is a type of harm categorised in s.62 of the Online Safety Act
[47] Regehr, K., Shaughnessy, C., Zhao, M. & Shaughnessy, N. (2024) Safer Scrolling: How algorithms popularise and gamify online hate and misogyny for young people, UCL & University of Kent
[48] The Independent (2024) Ofsted inspections show ‘growing scourge’ of classroom misogyny, says Labour
[49] Roberts-Ingleson, E. M. & McCann, Wesley S. (2023) The Link between Misinformation and Radicalisation: Current Knowledge and Areas for Future Inquiry, Perspectives on Terrorism (Vol. 17, No. 1)
[50] See: 5Rights Foundation (2023) Digital Childhood: Addressing childhood development milestones in the digital environment
[51] Home Office (2024) Operation of police powers under the Terrorism Act 2000 and subsequent legislation: Arrests, outcomes, and stop and search, Great Britain, quarterly update to March 2023
[52] Department for Education (2023) Understanding and identifying radicalisation risk in your education setting
[53] Ofcom (2024) Our Approach to Developing Codes Measures, 1.39
[54] Washington Post (2024) Her teenage son killed himself after talking to a chatbot. Now she’s suing
[55] BBC News (2024) ‘Sickening’ Molly Russell chatbots found on Character.ai
[56] The Telegraph (2024) Digital clones of Brianna Ghey and Molly Russell created by ‘manipulative and dangerous’ AI
[57] Thiel, D. (2023) Investigation Finds AI Image Generation Models Trained on Child Abuse, Stanford Cyber Policy Center
[58] Smith, B. & Gajjar (2024) Artificial intelligence: education and impacts on children and young people, UK Parliament POST
[59] HM Government (2024) Safety and Security Risks of Generative Artificial Intelligence to 2025
[60] See: Amendment 203 in the Data (Use and Access) Bill tabled by Baroness Kidron
[61] Ressa, M. (2022) How to Stand Up to a Dictator, United Kingdom (Ebury Publishing)