Written evidence from Dr. Talita Dias, Junior Research Fellow, Jesus College, University of Oxford, Oxford Programme for International Peace and Security, University of Oxford and Ms. Rhiannon Neilsen, Research Consultant, Oxford Programme for International Peace and Security, University of Oxford (TFP0023)



This submission is supported by the Oxford Institute for Ethics, Law and Armed Conflict (ELAC) and its Programme for International Peace and Security (IPS), both housed by the Blavatnik School of Government, University of Oxford. IPS provides a space for research on the critical challenges facing the law, norms, and institutions affecting the maintenance and enforcement of international peace and global security.


Executive Summary

-          Control over information and communications technologies (ICTs), as well as online and offline artificial intelligence (AI) systems, are currently shifting the international power landscape. Key global threats occurring in this context include ransomware, information technology (IT) supply chain attacks, cyber influence or information operations, and electronic surveillance.

-          To promote responsible business practices online, the FCDO should support corporate compliance with international human rights law, independent verification, standardisation auditing and testing of company IT products, and sector-specific business responsibility awards.

-          To encourage internationally accepted norms for the use of social media whilst reaping its benefits for diplomacy, the FCDO should assess the advantages of decentralised approaches to social media, strategize substantive and procedural changes with dominant platforms, promote educational campaigns about human rights-compliant platform standards, and support social media companies facing unlawful government demands to remove, limit or publish content.

-          To shape the development of, and promote compliance with, international law applicable to ICTs and artificial intelligence, including by taking advantage of the UK’s G7 Presidency, the FCDO should work with relevant government bodies to: i) update and revise the UK’s national views on international law in the cyber context, particularly as it pertains to sovereignty and due diligence, ii) propose concrete implementation measures, iii) cooperate with both like-minded and non-like-minded governments to seek common ground on how international law governs discrete cyber issues, and iv) develop the UK’s national views on the application of international law to emerging technologies, including artificial intelligence.


  1. What technologies are shifting power? What is the FCDO’s understanding of new technologies and their effect on the UK’s influence?

Given their ubiquity, pervasiveness, and dual-use nature, ICTsalso known as ‘cyber’ technologiescurrently dominate the quest for political and economic power in the international system. These technologies comprise the Internet and its various physical, data and logical components (e.g. cables, satellites, online applications, protocols, and Big Data),[1] as well as Internet of Things (IoT) devices, such as smartphones, smart watches, sensors, control valves, virtual assistant technologies, and self-driving cars.[2] These technologies have led to immense social, economic, and cultural progress around the world. But their vulnerabilities, which have expanded with our growing dependence on ICTs, have been exploited for a number of malicious ends and caused significant harm to individuals, private entities and States worldwide.[3] Some of the most pressing cyber threats include:

a)      Ransomware, i.e., malicious software (malware) used to block the availability of data or systems subject to a ransom payment,[4] is often listed as ‘the number one cyber threat’, given its frequency, pervasiveness, and impact.[5] It is particularly concerning when directed at critical information infrastructure, such as hospitals, oil pipelines, and medical facilities.[6]


b)     IT supply chain attacks, that is, cyber operations exploiting vulnerabilities in widely used software or hardware. These carry a great risk of systematic harm to individuals, corporations and States,[7] especially when targeted at network management software[8] used to monitor physical IoT devices, such as sensors used for critical infrastructure, including water distribution, power supply, and nuclear plants.[9]


c)      Cyber influence or information operations, broadly defined as any coordinated or individual deployment of digital resources for unlawful cognitive purposes, such as disinformation, misinformation, and online hate speech, particularly when these take place during elections, violence and armed conflict.[10] ‘Deepfakes’ may also present a threat to national security and democracy by eroding trust in institutions, misinforming political decisions, or inciting reactions based on the fabricated depictions of UK leaders or that of its allies.[11]


d)     Electronic surveillance, comprising the mass or targeted use of software or hardware to intercept private communications, especially through spyware software.[12] The increased use of certain surveillance practices are at risk of breaching data protection, privacy, and equality laws, especially in terms of the employment of facial recognition practices.[13]


A growing number of software applications used for such harmful cyber operations, including malware, are powered by AI technologies. AI is defined as the use of computers, including virtual programmes and robots, to mimic certain human skills, such as perception, association, prediction, planning and motor control.[14] The technology uses symbolic, i.e. human-readable, or subsymbolic, also known as machine learning, algorithms, i.e. complex statistical-probabilistic equations, which today dominates the field.[15] In essence, AI algorithms use statistics and probability to make predictions about a variety of subjects, such as the likelihood that an image, word or text belongs to a certain category or will reappear. Its applications range from numerous types of image and speech recognition programmes, such as medical image diagnosis and computer vision, to self-driving vehicles, drones and autonomous weapons systems.[16] A vast amount of AI applications are used online to power search engines, social media feeds and recommendation engines.[17] AI algorithms have also been increasingly used to filter through job applications, identify citizens, predict crime and recidivism, estimate student and teacher performance, calculate credit score and offer numerous social befits, from medical treatment to childcare.[18] 

However, all AI algorithms, from good old-fashioned symbolic algorithms to machine and deep learning, are essentially quantitative: they make predictions based on the incidence of certain features in the data with which they are trained. Put differently, they learn to make statistical, often non-causal or irrelevant, associations between numerically identified features across their data pool, such as the pixels in an image.[19] As such, they are incapable of making basic qualitative judgments that are essential to humans in day-to-day activities, and thus the algorithms do not innately account for contextual, abstract, and common-sense knowledge.[20] In the case of machine learning algorithms, numerical weights or parameters are pre-programmed to automatically change based on the vast quantities of data – Big Data – they process over time, which means that their decision-making processes are largely incomprehensible to humans.[21]

              This reliance on historical data and quantitative associations have inevitably led to crass errors and the amplification of societal biases,[22] such as image recognition systems that problematically mislabel and misidentify the faces of non-white individuals and women.[23] Similarly, AI recommendation algorithms on social media prioritise recurrent content, which results in the amplification of disinformation, division and hatred.[24] At times, such discrimination is a product of intentional, human-controlled exclusion of certain groups (women, minorities, or religion) in programming the AI’s targeting algorithms, resulting ‘dark ads’.[25] All discrimination on this basis should be condemned. Yet often these issues arise because the AI algorithmic decisions are based on data that is itself imbued with systemic or subconscious discriminatory assumptions.[26] For instance, in the case of recidivism in the US, the algorithmic program COMPAS was found to consistently – and wrongly – flag black defendants at a higher risk of re-offending compared to their white counterparts, and were thus denied parole.[27] If the biases embedded within “training data” (the dataset from which algorithms and models learn) are not mitigated, or if the training data is not designed with adequate human input and oversight, automated decision-making algorithms will continue to perpetuate these results, thereby exacerbating systemic bias.[28] The effects of bias in automated decision-making stem from what Joy Buolamwini terms ‘the coded gaze – “reflection of the priorities, the preferences, and also sometimes the prejudices of those who have the power to shape technology”.[29]

The FCDO is well aware of this threat landscape and is taking important steps to address it.[30] In particular, the recent Ministerial Declaration ensuing from the latest G7 Digital and Technology Ministers’ meeting under the UK’s presidency rightly notes the importance of a) security, resilience and diversity in information technology supply chains; b) industry-led technology standards for the Internet and digital technologies; and c) the safety of Internet users, particularly the most vulnerable ones.[31] Yet more can be done to raise awareness of and address the challenges outlined above together with States, international organisations, technology companies and civil society organisations around the world. To mitigate these risks, the FCDO can require technology corporations to undertake a thorough, external and independent examination of ‘training data’ before it is used for AI decision-making processes. This is especially for important in the development of AI algorithms that have an impact on individuals’ livelihoodsoften without their awareness (such as employment, parole, and credit scores).


  1. How can the FCDO engage with private technology companies to influence and promote the responsible development and use of data and new technologies?

The UK has already set in motion national strategies to address the cyber threat landscape. Most prominent among these is the recent Government response to the Online Harms White Paper, laying out a proposed legal duty of care on online companies and its ensuing responsibilities.[32] Nevertheless, given the interconnectedness and transboundary nature of ICTs, and the fact that most technology companies are based overseas, a domestic corporate liability legal framework is insufficient on its own to address the root cause of the problem. International(ised) strategies to promote responsible business practices online are thus essential, and may include:

a)      Consulting with domestic and foreign technology companies and foreign governments with a view to adopting uniform standards for data protection, content moderation and algorithmic transparency, which are in line with international human rights law instruments, such as International Covenant on Civil and Political Rights[33] and the International Covenant on Economic Social and Cultural Rights,[34] and the United Nations (UN) Guiding Principles on Business and Human Rights.[35] In this regard, the European Union (EU)’s Code of Conduct on Countering Illegal Hate Speech[36] provides a successful model for public-private partnerships which could be brokered in the context of the other cyber threats described earlier, such as ransomware, disinformation and digital supply chain attacks.


b)     Partnering with such corporations to establish independent, international mechanisms for verification, auditing, standardisation, and certification of software and hardware products before their sale and/or use is authorised domestically, bearing in mind the need to protect proprietary rights and trade secrets.[37] As the G7 Digital and Technology Ministers recently recognised,[38] technical standards have the potential to fill regulatory gaps, inform users and promote compliant businesses. Although ISO's expert-driven, internationally agreed standards already apply to several ICT-related areas, such as information security, cybersecurity and privacy protection,[39] similar standards are lacking on IT supply chain integrity and algorithmic transparency. The UK’s G7 presidency is an opportunity to push for the adoption of such standards at a global level.


c)      Establishing, together with other UK and foreign government bodies, social responsibility awards specific to domestic and foreign technology companies that have a consistent record of compliance with international and domestic rules or standards.[40] While naming and shaming non-compliant behaviour may be an effective deterrent in some instances, corporations also need an incentive to behave responsibly.[41] Like standards, corporate social responsibility awards can enhance user trust in responsible companies and boost their business, thereby setting in motion a cycle of compliance.


  1. How can the FCDO engage with private companies to encourage internationally accepted norms for the use of social media as well as to maximise the benefits for diplomacy presented by social media?

The unprecedented and highly concentrated power wielded by social media companies requires targeted, sector-specific measures, in addition to the engagement strategies outlined above. To encourage the adoption of and compliance with internationally accepted norms for the use of social media and leverage its opportunities for diplomacy, the FCDO should:

a)      Work together with smaller, non-profit, open-source and decentralised social media platforms, such as Diaspora, Minds and Mastodon,[42] to understand the extent to which alternative platform models affording greater user control are more conducive to upholding international human rights law, including the corporate responsibilities laid down in the UN Guiding Principles on Business and Human Rights.[43]


b)     Bring together dominant social media companies, such as Facebook, Twitter and TikTok, to strategise changes needed to improve compliance with international human rights law,[44] considering the specific guidance provided by the Special Rapporteur on Freedom of Expression.[45] Such changes likely include:


    1. Substantive reforms to platform community standards, which ought to be harmonised and made consistent with international human rights law.[46] In particular, community standards should ban prohibited speech, such as propaganda for war and advocacy of national, racial or religious hatred that constitutes incitement to discrimination, hostility or violence, but these must be tightly defined, bearing in mind context and intersections with freedom of speech.[47] In the event that initial detection and takedown was automated, prohibited speech that meets a certain threshold of gravity should be subject to meaningful review by human content moderators.[48] Other types of content, which might infringe on the rights and reputations of others, or affect national security interests, public order, health or morals, should be laid down in a clear and accessible manner, preferably with concrete examples.[49] Removal of these types of content should be a measure of last resort once other, less restrictive measures, such as tagging and de-prioritisation, have proven to be ineffective, and subject to meaningful human review.[50] It is also worth noting that, for all types of online hate speech – prohibited or not –,  States must ensure access to justice and an effective remedy to affected individuals, whether speakers, targeted individuals, or members of the audience. In the first instance, the FCDO should support social media corporations in flagging online posts containing incitement to violence, or dangerously misleading information.[51] Inclusive in this effort should be ‘redirect method’, which prompts users to access accurate and verifiable information provided trusted sources over that of fake news (as evidenced by YouTube, Twitter, and Facebook, during the COVID-19 crisis).[52] Upon the removal of prohibited speech, especially incitement to violence and evidence of war crimes, the FCDO should ensure that such content is stored in encrypted, digital ‘evidence lockers’.[53] The FCDO should dedicate resources toward identifying which organisation should be responsible for the storage and maintenance of such lockers.


    1. Procedural reforms to content moderation decision-making and complaint processes. Given the inherent limits of AI content-moderation technologies described above, such as image and text recognition, content removal decisions should always be preceded or promptly confirmed by trained moderators with country-specific contextual knowledge.[54] Affected users, including content authors, addressees and flaggers, should be immediately notified upon the adoption of any limiting measure.[55] Internal complaint or appeal mechanisms against content moderation decisions should be transparent and easily accessible to authors or affected users.[56] Complaints should be decided by independent organs in a transparent manner, with sufficient reasons provided.[57] Recognising the challenges of establishing such a complaint mechanism in a scalable manner, some have proposed the creation of company-specific or industry-wide ombudspersons or social media council.[58] However, to ensure greater representation and impartiality of such decision-making bodies, we propose leveraging existing technologies to decentralise the process and prioritise transparency. Inspired by the jury system, individuals could be randomly selected to sit on country-specific appellate ‘juries’ and vote on the merits of the decision to maintain, remove or otherwise limit the relevant content.[59] Yet even such popular decisions should always be subject to judicial review, which requires close cooperation between social media platforms and domestic courts.[60] This may operate similarly to the independent Oversight Board, consisting of forty international experts, which became operational in 2020 to assess Facebook’s decisions across both Facebook and Instagram.[61] The Board has the binding “authority to decide whether Facebook and Instagram should allow or remove content”, including the recent judgement to uphold Donald Trump’s accounts suspension from Facebook.[62]


    1. Change in algorithmic design to give users greater choice about the types of content they want to see in their feed.[63] For instance, users could have the right to opt out from platform-curated feeds and set their own, personalised curation standards, such as by sorting content in chronological order or selecting specific interests.[64] To avoid the phenomenon of echo-chambers, whereby users are exposed almost exclusively to like-minded and viral content that captures their attention,[65] platforms should promote respectful dialogues and engagement,[66] periodically prioritise non-like-minded content and counter-narratives, as well as de-amplify prohibited and blatantly false content.[67] For example, since 2018 Facebook has engaged independent fact-checkers to ‘rate’ the content accuracy of posts, and if fact-checkers “find falsities” they are required to de-prioritise the post.[68] In effect, “a person posting misinformation might find their content cast farther down the News Feed”.[69] So long as the misinformation does not incite imminent violence or violate hate speech regulations, the post will remain online, albeit not as visible.[70] According to Facebook, this measure “significantly reduces the number of people who see [the false stories].[71]


    1. The introduction of pilot paid, ad-free version of their platforms, where users have even greater control over their feeds.[72] Alternatively, rather than only having the option of entirely disabling personalised ads (as is the case on Google, for instance), the FCDO should work with social media corporations to allow users to have greater control over the extent of their personalisation.[73] Users may then select which sources of data (location, websites visited, purchases, age, gender, and so on) social media corporations can utilise for advertising purposes.


    1. Incorporating greater transparency for platform users regarding targeted advertisements that appear on their feeds.[74] Enabling a function of ‘Why am I seeing this?’ for each specific advertisement would help foster a deeper understanding of how users’ data is being used for advertisement purposes. Google presently has a function which allows users – if the user clicks on the link to determine ‘Why this ad?’; however, this fails in its specificity, as it only reveals broad information such as ‘your age group’, ‘your gender’, and ‘websites that you’ve visited’.[75] The FCDO should encourage social media platforms to reveal to its users precisely why that user is being targeted with a certain advertisement. 


    1. Insisting, as per the recommendation made by the 2019 UK House of Commons Digital, Culture, Media and Sport Committee’s final report on “Disinformation and ‘fake news’” that social media companies are not ‘platforms’, thereby bypassing responsibility for content on their sites.[76]


    1. Encouraging other social media corporations to follow Twitter’s initiative regarding hate speech online: launched in May 2021, Twitter now prompts users to reconsider their Tweet if it is found to include ‘offensive’, ‘insulting’, and ‘hateful remarks’. The feature is designed to detect such strong language, and prior to posting, Twitter prompts the user: “Want to review this before Tweeting”?[77] According to Twitter, 34% of users either refrained from posting the initial tweet or revised its content.[78] Other social media corporations could adopt a similar approach in order to encourage users from not posting hate speech online.


    1. Whenever feasible, limiting the number of platform users per IP address, whilst ensuring user pseudonymity,[79] to curb harassment and prevent the spread of violent content and disinformation through chatbots and botnets.[80]


c)      Collaborate with small and big social media companies to conceptualise and disseminate user awareness-raising or digital literacy campaigns[81] in the UK and abroad. These should seek to educate users about human rights-compliant community standards and promote responsible user behaviour on platforms. Platform membership could be conditional upon attendance of short online courses and questionnaires on basic community standards. Whilst users are prompted to ‘agree to’ terms and conditions pertaining to community standards, many of terms of service of social media companies are so lengthy that they are indigestible and thus un-read by most users.[82] If a member has consistent evidence of breaching such community standards, that member may be required to revise the online short course before accessing account once again, and be placed on a ‘probationary’ period.[83]


d)     Develop more direct forms of outreach for dissemination of online education regarding respect for international human rights law. This may also assist in ‘inoculating’ users against hate speech by raising awareness of such risks and thus rendering hate speech less persuasive.[84] In order to ensure such initiatives resonate with target audiences, these educational campaigns ought to be designed in collaboration with local communities, civil rights groups, as well as the small and big social media corporations that would be required to allow their platforms to be used for this purpose.


e)      Support social media companies in challenging government demands to remove, limit or publish content that is inconsistent with international human rights law.[85] This could be done through public messages of support as well as diplomatic engagement with the challenged governments.


  1. How can the FCDO use its alliances to shape the development of, and promote compliance with, international rules and regulations relating to new and emerging technologies? Is the UK taking sufficient advantage of the G7 Presidency to achieve this?

Direct engagement with companies can be an effective way to promote responsible behaviour in the ICT environment, especially considering that the core of the Internet and most ICT infrastructures are owned or controlled by private entities. However, it is ultimately States that make, interpret and apply international and domestic law. Whilst only international law provides a truly global legal framework applicable to cyber threats worldwide, domestic law, adjudication and enforcement remain essential to give it teeth. Importantly, the ICT environment does not follow territorial boundaries, which means that cyber vulnerabilities in one country can quickly become global threats. Countering those threats in line with the rule of international law requires all States to cooperate in the clarification, dissemination and enforcement of international rules applicable to ICTs. The FCDO could play a leading role in this regard by:

a)      Cooperating not only with traditional, like-minded allies, such as the European Union, the United States, Canada, New Zealand and Australia but also with developing countries and long-time cyber competitors, including China and Russia. In particular, China is home to some of the biggest tech companies, such as Tencent, Baidu and Huawei, and its manufacturing power is a key component of most IT supply chains. Thus, all efforts to counter global cyber threats will remain ineffective until agreement on key international rules and enforcement arrangements is reached with those States. To find common legal ground, cooperation should start with low-hanging fruits, i.e. discrete issues on which international agreement could be more easily reached, such as cyber operations targeting critical infrastructure, such as the healthcare sector, voting systems, energy, water and food distribution systems, and the core of the Internet. [86]  


b)     Working with the Government Communications Headquarters (GCHQ) and its National Cyber Security Centre to develop the UK’s national position on the application of international law to ICTs. At present, the UK’s views on how international law applies to ICTs are found in a 2018 speech by former Attorney General Jeremy Wright QC.[87]  A new official, consolidated document laying out the UK’s national position on the topic would be an opportunity to review, clarify and further elaborate on how existing international legal obligations apply to ICTs. In particular, the UK should consider revising its position on how the sovereignty applies to ICTs, as well as clearly articulating how existing duties to prevent and redress harm, also known as ‘due diligence’ obligations, apply to the cyber context. The UK is an outlier when it comes to sovereignty,[88] given its reluctance to acknowledge that this well-established State right can be breached by cyber operations that cause physical or functional effects on a State’s territory or which undermine its inherently governmental functions.[89] Likewise, it will lag behind a growing number of States, such as Germany, France,[90] the Netherlands,[91] Finland,[92] Estonia,[93] the Czech Republic,[94] Chile, Ecuador, Guatemala, Guyana and Peru[95] – to name just a few –, until it explicitly agrees that well-recognised duties of due diligence apply to States’ use of ICTs. Most prominently among these duties is the rule that the UK itself successfully relied on in its case against Albania before the International Court of Justice, i.e. each State’s obligation not to knowingly allow their territory to be used for acts contrary to the rights of other States. [96]


c)      Complementing the UK’s revised position on how international law applies to ICTs with a detailed roadmap of concrete measures for their implementation, including legal, technical, institutional, capacity-building and cooperative measures. Following the example of Australia, this roadmap could benefit from the input of submissions from academia, civil society and the industry.[97] The FCDO could also partner with other States and leading international institutions doing research on the topic, such as the United Nations Institute for Disarmament Research (UNDIR) and the International Telecommunications Union (ITU), to further investigate which measures are appropriate and necessary to give effect to its international obligations in the ICT environment.


d)     Leveraging the UK’s G7 presidency to engage with other groups of States, such as G20, clarify how exactly international law applies to current global cyber threats and agree on the necessary implementation measures. As mentioned earlier, the recent G7 Ministerial Declaration on, inter alia, Internet safety principles, trust in data free flows and digital technical standards is a positive step in this regard. However, more could be done to link these directly with the existing international legal framework and current efforts seeking to clarify it, such as the invaluable work of the UN Open-ended working group on developments in the field of information and telecommunications in the context of international security[98] and the UN Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security. [99]


e)      Studying and formulating an official UK position on how international law applies to AI technologies, focussing, in particular, on the impact of its various applications on internationally recognised human rights.[100]








May 2021



