Artificial Intelligence, Truth and Democracy: Discussion (Resumed)
Witnesses warned that AI and big tech are increasingly privatising core digital public goods, with opaque systems shaping news, search and public debate while deepfakes and generative AI blur truth and undermine democracy. They argued the EU’s “digital omnibus” is a deregulation drive that would weaken the AI Act and GDPR, especially rules on personal data, automated decision-making, access rights and protections for sensitive data. EDRi and the academics said stronger enforcement, not weaker rules, is needed, and that marginalised groups would be hit hardest if safeguards are diluted. On age verification, they cautioned against privacy-invasive, unreliable systems that could damage anonymity and create new risks.
We have received apologies from our Chair, Deputy Malcolm Byrne, Deputies Gareth Scahill and Naoise Ó Cearúil, and Senator Laura Harmon. I advise members of the constitutional requirement that they must be physically present within the confines of the Leinster House complex in order to participate in public meetings. I will not permit members to participate where they are not adhering to this constitutional requirement.
Therefore, any member who attempts to participate form outside the precincts will be asked to leave the meeting. In this regard, I ask any member partaking via MS Teams that prior to making their contribution to the meeting, they confirm they are on the grounds of the Leinster House campus.
I welcome everyone to another meeting on the topic of AI, truth and democracy. We are pleased to be joined today by Dr. Abeba Birhane, director of the AI Accountability Lab, Trinity College Dublin, who is with us in the committee room. We also have witnesses joining us online. They are most welcome. From European Digital Rights, we have Ms Ella Jakubowska, head of policy, and Dr. Itxaso Domínguez, policy adviser. We also have Professor Reuben Binns, associate professor of human-centred computing from Balliol College, Oxford. I thank all our witnesses for being here today. I will now call on Dr. Birhane of the AI Accountability Lab to make her opening statement.
Comment on this
I thank the committee for this opportunity to address one of the most pressing and consequential issues of our time, namely AI, truth and democracy. AI is not a single technology; it is an ill-defined collection of diverse technologies stitched together under a broad umbrella. It spans game-playing systems and protein structure predictors to recommender systems shaping what billions see on social media platforms and search engines to consumer-facing products marketed as AI companions. This brief is concerned with the latter, that is, AI about or integrated in social systems. Most importantly, there is no AI without massive financial and ideological backing. It therefore makes very little sense to discuss its techniques or capabilities without asking who controls it, who benefits from it, who builds and deploys it and what it is doing in the world because after all, the purpose of a system is what it does. I will quote Peter Thiel's speech back in 2010 when he said:
The basic idea was that we could never win an election on getting certain things because we were in such a small minority ... maybe you could actually unilaterally change the world – without having to constantly convince people and beg people and plead with people who were never going to agree with you – through technological means. This is where I think technology is this incredible alternative to politics.
When Thiel referred to technology as an incredible alternative to politics, he described private power bypassing democratic debate. That logic is visible in how Palantir has embedded itself across public administration, finance, healthcare and defence industries. As its CTO put it, Palantir serves as “the government’s operating system,” extending its footprint across defence, healthcare and civilian agencies. Though less explicit than Thiel’s call to replace politics with technology, major tech firms have effectively privatised core digital public goods.
Platforms like Facebook, Google Search and OpenAI operate at infrastructural scale in Ireland, shaping information, communication and access to knowledge. However, their algorithms remain extremely opaque and their governance remains private with minimal democratic accountability to the public who depend on them, effectively ceding aspects of the democratic process to commercial interests. The monopolisation of digital spaces has turned democracy into something the highest bidder can buy and is degrading digital public goods themselves. As the AI industry, social media and search platforms grow ever more powerful and extractive and less trustworthy, they erode the very foundations of democratic life - trust, dialogue and accountability - blurring the line between truth and falsehood. An example is the deepfake video falsely showing President Catherine Connolly withdrawing from the presidential election race last October which amassed over 160,000 views on Facebook alone before it was taken down.
Generative AI's non-deterministic, stochastic architecture produces plausible output without any regard for truth or accuracy. This makes generative AI a societal disaster and a major threat to truth, democratic processes, information ecosystems, knowledge production, and the entire social fabric itself.
For truth, democracy and the rule of law to endure in the current AI era, we need to cultivate an ecosystem of transparency and accountability. Yet, governance by algorithms, in and of itself, inherently places our digital public squares and democratic processes in the hands of those that are building these systems in line with their political and profit-seeking agendas. Without real mechanisms in place for accountability, talk of transparency and accountability is an empty gesture. Large tech and AI companies, despite selling promises of innovation and societal benefit, monetise and undermine the very society they claim to serve. What is needed is not just regulation, but active enforcement. Given the track record of the AI industry, stricter regulation and enforcement is not anti–freedom of speech or anti-competitiveness; it is one of the clearest ways governments can show that they serve the public interest. After all, innovation that disregards truth and democratic processes risks undermining democracy itself.
Comment on this
I thank Dr. Birhane very much. I now call on Ms Jakubowska from European Digital Rights to give her opening statement.
Comment on this
I thank the members of the Oireachtas committee for the opportunity to speak with them today. I am here with my colleague, Dr. Itxaso Dominguez de Olazábal, from EDRi, which is Europe's biggest network of non-profit groups working to protect human rights in the digital age.
As I am sure members are all well aware, artificial intelligence is appearing in every part of our lives, from education and work to public services, games and apps. While we are promised a lot of benefits from this digital transformation, we also know that AI poses a lot of threats to our rights and democratic processes. It can exacerbate discrimination and exclusion, and it has some very serious environmental consequences.
The EU's landmark Artificial Intelligence Act, adopted in 2024, is supposed to create a framework for accountability and transparency around state and private use of AI, but it is currently falling victim to the EU's broad deregulation agenda, one that is unfortunately circumventing good law-making and democratic processes. The so-called AI omnibus proposal, for example, wants to take the teeth out of the AI Act and turn it into a piece of self-regulation at the will of AI companies. The EU's landmark platform accountability law, the Digital Services Act, is also being considered for deregulation.
This agenda is being pushed at the highest levels of the European Commission under the banner of simplification, but the reality is that across corporate sustainability, environmental protections, workers' rights and digital rights, we are seeing core protections for people and communities being reopened, putting the EU's social and digital agenda at risk in a time of exponential AI. I will now pass over to Dr. Itxaso Domínguez de Olazábal to finish speaking about EDRi's intervention.
Comment on this
It is an honour to be here representing EDRi. I would like to focus on what the digital omnibus - this deregulatory instrument - modifies in the general data protection regulation and the consequences in an AI context.
Most AI systems rely on large volumes of data. The GDPR determines when that data is protected, how it may be reused and what safeguards apply when automated systems affect individuals and collectives. Today, some of these safeguards are under threat by an increasing drive to prioritise data access in the name of EU competitiveness.
I remind committee members that the Data Protection Commission, DPC, opened an investigation into Grok, which signals how important the GDPR is in looking at what AI systems and models can do in terms of human rights.
When it comes to the digital omnibus, I will focus on six key areas. First is the definition of personal data, which is a key core of the GDPR. The proposal narrows how identifiability is assessed, particularly for pseudonymised and inferred data. In AI, decisions often rely on behavioural patterns rather than direct identifiers. If such data are treated as insufficiently identifiable, they may fall outside full protection, even though they clearly shape outcomes for real people.
Second is automated decision-making under Article 22 of the GDPR. The current rule restricts solely automated decisions unless they are strictly necessary. The proposal broadens how necessity may be interpreted, potentially normalising fully automated decisions in areas like recruitment, credit scoring or insurance, especially if safeguards elsewhere weaken. This becomes even more important if the AI Act’s safeguards are weakened, as my colleague Ms Jakubowska just mentioned.
Third is legitimate interest and AI systems. The proposal makes it easier to rely on legitimate interest for developing and operating AI, facilitating large-scale data reuse without prior engagement and shifting protection towards ex-post objection.
Fourth is special category data, or sensitive data, and debiasing. The proposal allows sensitive data to remain in AI systems where removal is deemed disproportionate - and it is up to companies to decide whether that is disproportionate - while the AI Act amendments emphasise bias-mitigation efforts that may further encourage its use. Yet, these are data categories EU law treats as highly protected for a reason.
Fifth is scientific research. The proposal revises the framework for processing for scientific research purposes, opening the door to subsequent processing. In AI development, the boundary between research, development and commercial deployment is often fluid. If that boundary becomes more permissive, large-scale data reuse for AI systems may continue under a research label even after commercial integration.
Sixth is access rights. The right of access is crucial in AI systems but the proposal allows controllers to limit requests considered abusive, potentially weakening individuals’ and collectives’ ability to challenge automated decisions and actually understand what the data are that AI systems and models hold about them.
The GDPR is technologically neutral by design and must remain that way. The key question is whether these safeguards remain strong enough to operate effectively in an AI-driven environment. I thank the committee. I look forward to the discussion.
Comment on this
I thank members for the invitation to speak on AI, truth and democracy. I am an associate professor of human-centred computing at the University of Oxford. My research is on the intersection of AI and the law, and that includes things like data protection, discrimination and employment. I would like to focus today on the first part of the topic, which is AI and truth and, specifically, the relationship between generative AI systems like ChatGPT and the human idea of what truth is.
Members may have heard the word "hallucination" used to describe instances where systems like ChatGPT produce information that is not true. I want to explain why these systems are actually incapable of telling the truth in the sense that we would usually use that phrase. These systems are, fundamentally, designed to predict the next word in a sentence. They are predictive text or autocomplete. It might sound like I am saying they are not very good or sophisticated. That is not the case; they are these things but it turns out that complicated and sophisticated next-word prediction systems can produce a lot of seemingly quite impressive outputs, while still fundamentally being next word predictors.
To help understand how these language models are created, let us consider how a human being might create one, manually, from scratch, following a similar process that a computer undertakes. This is useful to understand why they are not really thinking in the way that human beings are. Imagine you are a human language model and you have a library containing books. Every time you read a book, you make a note in your notebook of every word that you see. Underneath the word you see how often-----
Comment on this
-----comes from that word. You have a big table of how one word-----
Comment on this
-----things like "sat", and after that you will have things like "on" and "mat" and so on.
We have then a big book of words and the frequency with which other words follow them. We could use this book to finish off someone's sentences by selecting the highest frequency words succeeding the ones we just heard. This would be really painstaking for a human being to create but it would be very similar to the kinds of language models trained and run on computers these days.
If we made a dictionary that produces sentences in this way, would we expect the dictionary to tell the truth? Should we be surprised if it spits out sentences that sound correct but are just made up? When using a human dictionary - a human-generated language model - in this way, we would not stop to think whether the next word makes sense. The digital model is operating automatically or mechanically in the same way, so there is no particular point at which we step in and ask whether the sentence that is being generated is true or not. Often, the next most statistically likely word will be one that results in the entire sentence being true but that is an accident because the next most likely word might be one that makes the overall sentence false.
In this sense, we could say that hallucinations are not just occasional lapses by otherwise reliable or truth-seeking systems but, rather, all outputs of the model are like this. Sometimes they correspond to reality but that is only to the extent that they reflect patterns in the underlying training data. If the patterns in the underlying data are wrong or the particular data it is being trained on is wrong, it will create sentences - outputs - that are false. Hallucinations are, therefore, an endemic feature of the way these systems are designed. They cannot be eliminated or prevented. They are a deep threat to any institution that relies on honest actors presenting words, arguments and evidence in good faith that they correspond to the truth. As a society, we need to understand this endemic risk and prepare accordingly.
Comment on this
I thank the witnesses for their presentations. I know it is good to ask specific questions of witnesses but there is a broad interconnection between everybody's contributions, so most of my questions could be answered by any of the witnesses. When I read the opening statements yesterday, I was thinking in particular of digital rights and AI omnibus we can expect. The witnesses also mentioned the Digital Services Act, which will, potentially, go through a similar process. I thought about what Dr. Birhane said with regard to a societal disaster and bypassing debate. One cannot help but think about digital colonisation, imperialism and the fact that AI and big tech already uphold the current systems of power in the world but are now looking to make them faceless, so that one cannot even challenge a human being eventually. It is this massive concentration of power without a human having to be accountable for that power ultimately. That is extremely worrying.
Regarding Ireland's position within the EU, we also need to look at our role in the digital omnibus as one of neutrality and Ireland's history of not being a coloniser or imperialistic. We have to ask where those principles and mindset exist when we look at power structures such as AI because they are crossing over into that space. Ireland is in a position where it needs to hold on to those values when it comes to gutting data rights.
The Government is already saying things like "This is just about making it easier for industry". That nice little catchphrase regarding industry is used without there being any understanding of the impact this is having globally, especially in non-western regions. In the context of the digital divide that exists, even some of those non-western regions that have access to AI are seeing a very western idea of what it is, without any sort of cultural ability to translate it.
I really want to home in on the EU's omnibus proposal. This was referred to in some of the opening statements but will the witnesses comment further on why it is so important? It would be very welcome if any of the witnesses could expand on his or her views in that regard.
Comment on this
My colleagues from EDRi would be much more qualified to answer those questions.
Comment on this
Both Ms Jakubowska and Professor Binns are indicating. I invite Ms Jakubowska to go first.
Comment on this
I thank the Senator for her questions. We are really glad that the concerns relating to the deregulation agenda and the digital omnibus are resonating. We consider that agenda to be one of the biggest threats to our digital rights that we face right now. When I use the term "digital rights", I mean all of our human rights in this increasingly digitalised age. The agenda is being pushed by the European Commission and a number of companies in a deeply undemocratic way.
Rules are not always the sexiest thing, but the EU tends to do rules really well. Our argument is that this is not about rules for the sake of rules; it is about the checks and balances in a democratic society that protect all of us and which can, of course, be improved. We see gaps in enforcement, for example. The idea that regulations are somehow what is stopping the EU being competitive is not based in evidence. It is a gut feeling and a political assertion.
All of the usual good lawmaking practices we expect from the EU, and look to the EU to be good at, are being completely circumvented. Impact assessments, which are a key part of EU lawmaking and are supposed to outline the potential consequences for people's rights and safety and for the environment, are not being done. Yet, we are seeing Bills being put forward that could really weaken many of the protections on which we rely. It is already notable that these protections are not equally applied today. People from minoritised backgrounds already face high levels of structural discrimination. It has always been harder for them to access their rights to data protection. Rather than saying, "Let us level up and make sure everyone can equally enjoy these rights", the EU is tending towards levelling down and having it as the gold standard to which we should aspire to allow AI development like we see in certain other parts of the world where it is done in a really unchecked way. There have been-----
Comment on this
Thank you, Ms Jakubowska. We only have one left minute for responses to Senator Ruane. I want to ensure Dr. Binns has an opportunity to comment.
Comment on this
I agree with what Ms Jakubowska just said. I emphasise that data protection is one of the most powerful and appropriate ways to manage masses of data and the unleashing of AI in really important decision-making concepts. It is a unique and really positive strength of the EU. It is not a case of how we can get the innovative AI to be a little safer or a little more respecting of fundamental rights. It is about giving a blueprint for how to innovate with technology in a way that actually serves societal purposes rather than the interests of big tech firms.
Comment on this
I thank all the witnesses for joining us. They are all speaking my language.
There is a lot of stuff coming up today that I have raised on a number of occasions, in committee and, indeed, on the Dáil floor. I will focus on some of Dr. Birhane's comments around privatisation of public goods and then come back to the digital omnibus. I would love to hear a bit more detail from EDRi on some of its language and comments.
I have been mocked outright for raising the concept that there should be some level of questioning at least of public-private ownership of some of the technology that drives our lives at present. Indeed, one of my fellow committee members here said it was rubbish and dangerous to even suggest such a concept. I am interested in how Dr. Birhane has come at it because she is not talking about how public ownership might come in. Rather, she is talking about the fact that there is already privatisation and privatised ownership of "public goods". Will she expand on that phrase?
Comment on this
Sure. Think of the recommender algorithms that are suggesting content on your Instagram or TikTok feed. Those are the ways people get their news, their information and learn about certain topics, etc. Algorithms like that, and even search engines such as Google, are serving the purpose of the public square or public infrastructure. That is where people go to interact, where people go to learn about a certain topic, where people go to debate, etc. These services and products are increasingly privatised and are held by just a handful of bodies.
From a researcher's point of view, we do audits in my lab. Over the years, what we have noticed is trying to get access, never mind to the algorithms or the training data, but even to how people interact and getting some kind of data about their recommender systems, the content moderation policies, etc., has become extremely difficult. These companies have developed policies that are extremely hostile to people like me, to people who are trying to treat these products as a public good and trying to bring about some transparency. Companies like Meta actively retaliate and target people like me who are trying to bring accountability. I will cite a recent passage from an internal office Meta memo. Before it introduces a facial recognition algorithm feature to its smart glasses, it writes that it should launch it "during a dynamic political environment where many civil society groups that we would expect to attack us would have their resources focused on other concerns." This is the extent to which companies go not to share any information.
I share the concern with my colleagues that we barely know how these algorithms operate. Even from black box auditing, by finding all kinds of ways to look into their algorithms, there is a robust body of work that shows that these algorithms actively push politically radicalising content, hateful content and anything that brings "flick" or that keeps the user hooked on the algorithms.
Comment on this
Eyes on the screen, yet they deny that completely. In committee last week, I asked them exactly that and they said, "No".
Comment on this
The committee should look at what they are doing rather than what they are saying-----
Comment on this
-----because what they are doing is creating a hostile environment that pushes any critic, audit or evaluation.
Comment on this
I thank Dr. Birhane. I am also subject to perhaps unfavourable algorithmic workings from my own content.
I will move on to EDRi and talk about the digital omnibus. I have been raising this as an issue. The Government parties are supporting the omnibus, or at least one of their European groupings is for certain. The other one has yet to declare specifically.
When I raise the digital omnibus under the banner of "simplification" and "harmonisation", the two words that are used primarily by Government representatives here, I am told that it does not mean deregulation, yet in the same input one of the Ministers recently stated that it was about alleviating the regulatory burden. Apparently, that does not mean deregulation. That is hard to fathom. I am wondering if EDRi has ways of calling that out, pushing back on it and understanding how we can make it more explicit that this is deregulation even if people who are saying it is perhaps do not realise that themselves.
That is my first question, including the language around simplification and harmonisation.
Second, would the Grok investigation that was initiated today be likely to be initiated under the new digital omnibus framework of the GDPR?
Third, I ask the witnesses to expand a little bit on what they mean by GDPR being technologically neutral. I will look to Ms Jakubowska and Dr. Domínguez de Olazábal to answer those questions.
Comment on this
I ask the witnesses to be succinct because there is only one minute and 30 seconds left on the clock.
Comment on this
There are two things in the digital omnibus that highlight that this is deregulation. First, the AI part proposes to get rid of the requirement for developers of AI systems in high-risk areas that want to opt out of following the high-risk rules. They are supposed to register in a transparency database. The AI omnibus proposes to allow them to not register in that transparency database, meaning there is no possibility of enforcement. The estimated cost saving per business is €100.
Second, the digital omnibus also proposes to remove people’s ability to object to companies using their sensitive data to train AI systems. Under this proposal, it would mean that people would no longer have the ability to opt out of Meta, Google or whoever using their biometric data or data about their sexuality or political views. I will give the floor to Dr. Domínguez de Olazábal to provide some final points in this regard.
Comment on this
I will address the second question. GDPR is technologically neutral because it is not focused on a specific technology that is used in order to collect and process personal data. It is important that GDPR remain technologically neutral regardless of technological advances. At the end of the day, what we cannot do is use the excuse of AI to undermine some of GDPR's core principles, such as the definition of personal data and the principle of purpose limitation when it comes to these new definitions of scientific research.
I thank the Deputy for the question regarding Grok. Normally, we do not do counterfactual scenarios, but it is very easy to see how some of these companies are very declaratory on self-regulation. The digital omnibus indicates that these companies are going to say that, for example, the data being processed to activate Grok or other nudification apps, as they are being called, is not personal data and that removing the data being used by the user is disproportionate, even though it is considered sensitive or a special category of data. There are many arguments that companies could use under the new digital omnibus, if this comes to fruition and is passed as a law, to avert any investigation, such as the investigation by the DPC or other investigations that happen in the future.
Comment on this
I thank the witnesses. Their answers were very impressive. It is a very complex area to address in one minute and 13 seconds.
Comment on this
I thank the witnesses for their statements, which have been revealing, informative and enlightening. They are also worrying.
I will start with Dr. Birhane. I am interested in another aspect of this, namely, fake accounts and how they influence the whole political system. During the 2024 UK elections, ten bot-like accounts generated over 150 million views. The number of deepfake videos increased from 500,000 in 2023 to 8 million in 2025. We know that, as human beings, we can only detect 25% of all high-quality fakes. This, therefore, is very worrying.
With regard to the fake accounts, and to give the committee some idea, when I looked through some of this stuff, it was estimated that Instagram had 95 million fake accounts. When it comes to X, under the dead Internet theory, it had 468 million such accounts. Basically, we have an AI system that is run by bots rather than human beings, which is very threatening to the whole system.
What are the options? What actions can we take to stop this interference, particularly in the context of truth and democracy?
This is very important. What steps can we take to change this system? What can the Irish Government do? Are we not doing enough? It is kid gloves stuff we are dealing with. As the other people said, it is how important the omnibus Bill is and how GDPR is important to the citizen. We are at a crossroads now. We are ahead of European digital. What can we do?
Comment on this
That is a great question. It is important to consider that there are infinite purposes for deepfakes. Some of them may be benign. Some people might use it for mockery or to create a deepfake video of a high-profile politician.
Comment on this
Yes, such as Catherine Connolly, in the example Dr. Birhane gave.
Comment on this
Yes, that one is much more high stake. However, the danger with the proliferation of deepfakes is when it comes to issues that are really at the heart of democracy. This is content that is blurring truth and falsehood. Most people now have difficulty believing what they see on social media because it has become so difficult to differentiate what is real from what is fake. In politically contested areas, political ideologies or hateful content and so on, this is where deepfakes are really powering the dissemination of problematic ideologies. It might be radical to say just that there is actually no purpose for deepfakes in political discourse, in for example social media platforms and so on. However, given that currently we are so steeped in narratives that have normalised deepfakes and generative AI content as a normal part of education and a normal part of political life, it seems a bit too radical to suggest that these things should be entirely banned in certain spaces on certain platforms. However, that would be my position.
Comment on this
I thank Dr. Birhane. Dr. Reuben Binns said he chose the words that fit the content or finish the sentence but sometimes the next thing, statistically, would make the whole thing false. How much would Dr. Reuben Binns trust AI in sourcing the truth? How would he trust AI in the democratic process? Is it capable of distorting democracy across the globe?
Comment on this
That is a great question. In the world in which we work, in politics or in academia, there is a great weight to be placed on the fact that when you offer something into the public domain you are saying that you have done the work to the best of your ability to say that something is true. If you allow that to be polluted with generative AI, that means you can create a huge amount of stuff that sounds plausible but that has not been checked. Even if it was 99% accurate, that 1% can make a huge difference. If someone needs to trawl through all that to find that 1% of errors and fix them, then it is creating a lot of work for other people. It is threatening the integrity of the system that should be one in which at the very least to enter into discussions and to enter something into the record, you should have to stake a lot of your integrity on what you are putting out there is to the best of your knowledge true.
Even if they were 99% accurate, which they are not, I would still be very sceptical about allowing them into the legal system, into politics or into online public discussion, especially on important matters.
Comment on this
Under the digital omnibus, obviously the GDPR is the cornerstone of democracy. It really is the protection of data. How can we make sure that people's data are protected? Some of the witnesses were saying that political decisions were being made. It was a political decision rather than anything else and it was being circumvented.
Who do the witnesses see as circumventing the whole system in order to dilute the GDPR?
Comment on this
No, I am here. It is for my colleague, Dr. Domínguez de Olazábal.
Comment on this
I thank the Deputy for the question. One of the points Ms Jakubowska mentioned that it is important to stress when it comes to the digital omnibus is there are things we can improve when it comes to data protection, which is the cornerstone of democracy, as the Deputy said, and the cornerstone of the whole of the digital rule book. There are things that can and should be done regarding enforcement. We need better enforcement and more cases. We need more resources for the data processing agreements, DPAs, not just the DPC but all the DPAs in the European Union, in order to be able to guide the companies. One of the things we are seeing with the digital omnibus and GDPR as a whole is that while we maybe do not have enough legal certainty, we are not going to obtain legal certainty by reopening the laws and making them more complicated and even worse, if you look at the trust in this whole process.
Regarding who needs to be held accountable, we have seen this deregulatory push from the European Commission. The digital omnibus is the tenth omnibus in just a year and it has promised more of them are coming. We have also seen reports from other civic society organisations, such as the Corporate Europe Observatory, which indicated, for example, there are more big tech lobbyists than MEPs in Brussels. They have evaluated the proposal and looked into what big tech has been calling for throughout these last months.
Members will not be surprised that the parallels are immense. We saw the same pattern when it came to the UK and the GDPR, with the Data (Use and Access) Act. We want to avoid that-----
Comment on this
-----because it is actually not-----
Comment on this
-----the regulator and guidelines, and the rules that all the institutions of the European Union have in order to do and have good laws. It is not respecting the protections the European Union has in order not to have undue influence from all these companies. I will provide one small example. I do not know whether members saw this, but one of the rapporteurs in one of the main committees that will decide on the data omnibus - the GDPR one - is Aura Salla who is an ex-lobbyist for Meta. She has indicated, once again, in posts and social media posts that she wants more AI, more data for AI, and that deregulation should not be perceived through a negative lens but should be welcomed. That is already quite telling.
Comment on this
I thank the witnesses. I will continue on that line in relation to the deregulation agenda. I ask for the witnesses' perspective on the motivation and driver for this agenda. What is behind it? Is it, for example, evidence-based policymaking or the role of lobbyists? There was some mention of lobbyists. Related to that, who will be most at risk if the AI Act, the GDPR and this simplification comes in and those protections are weakened? Are there already examples that illustrate this risk? Is it a universal risk or are there particular communities that might be more at risk?
Comment on this
I will quickly address that. It is always difficult to read someone's motivation but from looking at actual empirical evidence, you will find that companies like OpenAI, Meta and Google are coming together and creating what they call pro-AI super political action committees, PACs. They have put over €200 million towards this. The idea is very clear. They explicitly stated that they want to create a space where the public and society have positive views towards AI and negative views toward regulation.
What is being captured is not just the rule-making in of itself but the public imagination and public perception. As a researcher, when you look at the kind of narrative these companies are pushing about, for example, how extremely capable AI systems are, it does not often match with empirical evidence on the ground and evaluations that test the capability of these models. What you find is the reality is these models rarely perform up to their claims, yet they are sold as this magical one that you can do anything with. There is a massive push and coming together of these giants in spending billions to dominate what the public knows about AI, which does not match up to actual empirical evidence.
In terms of who is disproportionately impacted, there is ample evidence that goes all the way to a decade now that shows, time and time again, when AI systems are examined and the training data used to train these models is looked at, that people at the margins of society area are impacted. They might be disabled people, those who do not conform to traditional gender or societal norms or people who are ethnic and religious minorities, but they are constantly disadvantaged by these AI systems. As these AI systems are built from data collected from the web that necessarily and inherently encodes societal norms, all AI systems tend to encode and sometimes exacerbate these societal norms. When these systems are deployed into society, they tend to explicitly or implicitly present or exacerbate these norms. The systems can also be used to exclude people from services and so on. The short answer is that people at the margins of society tend to be disproportionately negatively impacted.
Comment on this
I will ask a follow-up question; anyone can come in on it. When I raised this issue with the Minister with responsibility for this, he said that the Government would take a Department-by-Department approach to assessing the risk associated with the proposals in the omnibus as they relate to the AI Act and the GDPR. From the witnesses' perspective, what would such a risk assessment look like?
Comment on this
I am an academic auditor so my perspective is limited to my point of view. It is possible to do risk assessments for all kinds of issues. A few things that often tend to be missing; one being what kind of assessment is being done. Assessments can be done just to tick a box for checking, or to ensure that a company is liable or to protect the reputation of the company. These kinds of assessments tend to be done by large corporations. They are audits done by large firms for big companies like Google. These kinds of assessments tend not to get at the heart of whether there is discrimination or fundamental rights are being violated and so on. Assessments also tend to have to be carried out fully independently of the company that is developing and deploying the system. Independence is really important for the credibility of the results.
Comment on this
Two other speakers are indicating. Dr. Domínguez de Olazábal is first and then Ms Jakubowska.
Comment on this
Ms Jakubowska was first, but I just wanted to mention that the GDPR is a rights-based instrument. It is very important we take that into consideration. Of course, there will be different levels of risk. As Dr. Birhane mentioned, a number of collectives are going to be negatively and disproportionately impacted, but all of us are at risk and all of us should be able to exercise our rights. One of the main concerns about the digital omnibus is that it will be limited and more and more of our data will be input and fed to these AI systems and models.
Ireland had the data broker scandal that members have also discussed in its Parliament. That is actually the best example of how there are no qualms when it comes to feeding the Internet and online advertising systems, but also AI systems and models, with data. There are highly negative impacts for human rights, especially for these marginalised communities that Dr. Birhane mentioned.
Comment on this
On the point about what is driving this push, certainly the European Commission's President, Ursula von der Leyen, is pushing this from the highest political levels. There are some companies and countries also that are pushing this, although a number of especially smaller and medium-sized enterprises are pointing out that this is not going to be good for them. Looking across the Atlantic to the Trump Administration, it is one of the fiercest opponents to EU platform regulation right now, and that is certainly driving some of this agenda. Of course, there is a genuine issue at the heart of this about compliance, innovation and having EU tech markets that work for people and are free and open. Targeting EU legislation is the wrong problem statement. It is making the aim exponential growth for a small number of companies, rather than getting to a space that works for everyone.
Comment on this
I thank all of the speakers. I will follow up on that with Ms Jakubowska. How is the Irish Government seen at European level? Is it seen as being one of those that is closer to big tech and big tech lobbying? Is it seen as pushing back against the deregulation drive or as being more in line with it?
Comment on this
To the best of my knowledge, the Irish Government is not one that has been most aggressively pushing this agenda at EU level. Rather, the governments of Germany and France, for example, have been some of the strongest champions of the deregulation agenda. We also understand that with how incredibly fast the process is moving, many countries do not yet have stable positions on the file. Speaking more broadly, we see a lot of appetite for better enforcement and big tech accountability coming from the Irish DPC. Given Ireland's outsized role in the enforcement of the EU rulebook, there is always space for improvement and increased resourcing to ensure that as regards that job that Ireland is having to shoulder on behalf of the whole Union, the regulators are properly equipped. In this climate where regulation is being undermined and enforcement agencies and authorities and, of course, civil society, academics and other independent experts are having funding cut and resources taken away, that closes the civic space and makes it even harder for us to get accountability on these topics. There is always room for improvement there.
Comment on this
To go into more detail with Dr. Dominguez on what we are trying to do with the digital omnibus, effectively, we could be moving towards more fully automated decisions by AI. Do we have evidence about what the likely impact of that will be on different groups in society?
Comment on this
Yes, the article that has to do with automated decision-making is one of the strongest when it comes to the GDPR space. The AI Act did not achieve everything that civil society wanted from it. We are actually seeing more appetite to weaken the AI Act. I will not get very technical about it, but all these changes indicate a green light for companies to use more automated decision-making. We have seen many examples across Europe of how this can have incredibly negative impacts. As Dr. Birhane said, marginalised communities bear the brunt, especially when it comes to welfare and assisted credit scoring. This is to do with their survival. It comes back to the use of AI because AI is also a decision-maker, no matter what we call it.
We are seeing an indication that instead of going from a prohibition that had certain exceptions, we are allowing this activity under certain criteria, especially proving that there is a necessity to do that and to undermine some of the safeguards. We have, for example, meaningful human intervention as one of the most important safeguards, but there are others. For example, there is the right of the subject to know what data is in the system and where data is being used in order to make this decision, the right of any person to have it explained to them how this automated decision making works, not just after asking the company but during the process and even before the decision is made. It is really important to understand that these attempts at undermining Article 22 of the GDPR, which relates to automated decision-making, clearly follow the line of allowing for more AI, more data into this AI and allowing companies to use automated decision-making without any kinds of safeguards or qualms, or regard for the human rights impacts these decisions are going to have on the whole of society and also, very specifically, on some collectives.
Comment on this
Turning to Dr. Binns, in a way his main point is a very simple one, but I had not really thought of it. As someone who is certainly one of the most critical members of this committee of AI, I think the basic point that hallucinations are not a kind of bug but, rather, that the whole thing is a hallucination is a very strong point. It is just predicting the next word. Sometimes that coincides with reality, but often it does not, and it cannot be eliminated because the nature of the whole thing is just to predict the next word. It is a simple but profound point, and it has very widespread and deep implications for our ability as a society to debate with each other, make democratic decisions and so on. Will Dr. Binns explain the impact of that and the relationship to a post-truth world? If we could, would it be better to ban AI in many circumstances?
Comment on this
Maybe a good example is the legal system. There is a website called the AI hallucination cases tracker, which tracks cases where files that have been entered into a docket in court systems around the world have been subsequently found by judges to be AI hallucinations, and the consequences that have been felt by the lawyers who have done that. That is a really good example because the legal system depends on not having to constantly check every single thing. We have to take a certain amount on faith. If we allow hallucinated cases into the records, however, we are undermining the faith that people place in that system.
Some of the lawyers who have been caught doing this have said they got the citation wrong but that the gist of the argument is correct. That is not good enough. That is not how the law is supposed to work. It is supposed to build on real argumentative processes that are going on in people's minds and being communicated to each other and accepted as valid. If we break that connection, we break the whole purpose of the legal system. That is just one area where there should be heavy punishments for anyone who is engaging in it.
The same goes for lots of other contexts as well. As an academic, I am dealing with students who are potentially using these systems, and that also undermines the integrity of the learning and education process. There are definitely cases where we should be banning the use of these systems.
Comment on this
I thank Dr. Binns. I now have the opportunity now to ask a few questions. I will start with the academics and Dr. Birhane. In his opening statement and some of the responses he has given, he has echoed a sentiment we have heard since the beginning of our journey here on the AI committee.
When Mr. Alan Smeaton was before this committee, one of the things he heavily emphasised was a fear that, in this race between all of these private providers of LLM software that is being created, we are losing independent appraisals, or at least it is very challenging to carry out independent appraisals, because the competition between these LLM companies is so fierce. As the director of the AI accountability laboratory in Trinity College Dublin, will Dr. Birhane tell us how that can be improved? Are we too late? Are there ways in which independent third level institutions or institutions can be supported in their work in trying to carry out independent appraisals of large language models as they develop in the heat of this fierce competition?
Comment on this
That is a great question. By appraisals, we mean evaluation audits and studying how these systems operate in the world. That is what we do in my laboratory. The increased interest and realisation, both from civil society and academia, in producing evidence of how these systems perform is the first step to hold the vendors accountable. As a result, there is increased appetite. Auditors still face so many challenges, however. These systems are extremely opaque and access to them is virtually impossible because they are considered proprietary systems with trade secrets. Yet, as I said, they are sold as a public good and as public instruments. This, therefore, does not add up. Some kind of mechanism is needed to ensure auditors get access. While there is vetted researcher access via the Digital Services Act, DSA, that process is extremely volatile and it is difficult to get approval. This access is for platform audits. Even after receiving approval, researchers cannot guarantee that the data the platforms give them is not cherry-picked. This makes it difficult. One way is to provide mechanisms where auditors have relatively easy access to these systems, whether large language models or large social media platforms, that impact millions of people's views.
It is important to treat the evaluation of these systems as something that has to be done fully independently. If the people contracted have some kind of contractual agreement with the platform, there is a risk they will see what they find or they will search for what they find. As a result, their evaluation would not carry as much credibility. I emphasise independence. As my colleagues from the European Digital Rights, EDRi, emphasised, we are currently living through this massive AI hype where companies are pushing the integration of AI everywhere. In the context of the public’s understanding of AI, Google has taken all the magazines from The Irish Times over the past couple of years and produced an explainer of generative AI without disclaiming that it is an advertisement. These kinds of processes and activities have an impact on the public’s understanding. Clearly delineating public interest from private interest is critical.
There must be support for auditors and evaluators who are doing the dirty work. This includes my civil society-----
Comment on this
I call it good work rather than dirty work. I have a similar question for Dr. Binns. I noticed that his title states he works in human computing, but he is in the computer science department. In academia in Oxford, presumably, there is a whole bunch of computer scientists who are exceptionally excited by AI. Maybe they are in another room doing something in a different space, while Dr. Binns is calling for us to be careful and to look at what is going on in this regard. I am obviously being incredibly oversimplistic here. How important is it for third level institutions to have that degree of tension, even at a computer science level? Are there learnings from how Dr. Binns is operating his department that might be more generally applicable to other jurisdictions, particularly Ireland?
Comment on this
That is a good question. It is tricky when so much of the funding is either directly coming from the big technological companies or through government funding that is influenced by the agendas of technological companies.
The dream of an AI that solves economic productivity problems and so forth feeds into the agenda of what research is funded. It is important that European countries, like Ireland, adequately support the kind of work that enables us to see what is going on in an independent way from what is funded by the big technological companies and point out the risks and alternative ways we could use technology for good.
I will flag one point based on some research that I have carried out. Working with an organisation that represents Uber drivers, we used the GDPR to carry out an independent audit. Those drivers were able to use their rights under GDPR to make subject access requests to Uber to obtain data on all of the trips they had taken, the prices the customers paid and the amount drivers were paid. We used that data to analyse how the Uber algorithm works and we found that it is extracting a larger and larger proportion of the customer's fare and giving less to the drivers. That is an example of where we have been able to audit an algorithm using data protection rights as a means of accessing data. Although other mechanisms like the DSA enable this, GDPR is potentially a key way that we can get access to data from these companies and use that data to analyse AI systems.
Comment on this
I have 20 seconds left. I will get to everyone properly in the next round, but I see that Dr. Domínguez de Olazábal has an observation to make.
Comment on this
I repeat my statement that the right of access is one of the rights that might be potentially undermined by the digital omnibus. I stress how important it is that people have the right to know what data these companies are holding and what they are doing with this data. Nowadays, if the amendment goes as planned, the moment a company says it is an abusive access request, it might deny it or even charge money in order to provide this information. This is a perfect example of how unjust this is from a human rights standpoint.
Comment on this
I invite Deputy Keogh because she has not had an opportunity yet. She can have her full seven minutes.
Comment on this
This has been an interesting debate. As a non-tech person, it has been very technical. I have been trying to follow the conversation as best as I can. We have had a big discussion about data protection and GDPR. We are moving towards trialling an age verification app in this country and we know the EU is already on its second version of a blueprint age verification app. What are the witnesses’ thoughts on that, especially given that they are saying they will be completely separate from the big technological companies and only give signals? What are their thoughts on those apps?
Second, do we need to be going even further? This morning, the number of bots on these apps was revealed. Should we be going further with identity verification or are we then completely going into a scary realm where there is way too much data online? We are trying to solve one problem but potentially creating another. I ask for the witnesses’ opinions in that regard.
Comment on this
While age verification seems like a straightforward technical solution to keeping kids off platforms, AI systems and so on, it is extremely problematic. From a technical point of view, age verification is not that accurate. It does not work as advertised. Often, age verification is done via a person taking a photo and then some kind of analysis is carried out on it. This requires estimating the person’s age and other attributes. This has very little, if any, scientific merits. This kind of work is known as a pseudo-science. Trying to read societal and nuanced features from a face does not have a scientific basis.
It is likely to be used for abusive means. Third-party age verification companies which the likes of Google contract are very shady. They do not share information. We do not know their contractual agreements. We do not know what kind of technology they are using. We do not know how the technology is vetted. Most importantly, they are collecting this massive amount of sensitive data on faces, credit cards and email addresses and they are being placed as the guardians of this data. We do not know what they will do with it. If history is anything to go by, companies such as these which amass this extremely sensitive data tend to use it for their own profit maximising purposes. This really puts children at risk.
Comment on this
Separate to the private companies, if we look at the Irish Government, which is trying to do it through gov.ie, would Dr. Birhane have the same view of this? Would it be different if it were a Government-owned age verification app?
Comment on this
If that were the case maybe my concern that the data might be abused would be less because public auditors can demand access to information on how the system is developed and how it is evaluated. This would lessen my concern but the fact the technology in and of itself can predict age accurately from face or various attributes is not addressed by the clarification.
Comment on this
EDRi works extensively on the issue of age verification and I am very glad to have the opportunity to share a little bit. Absolutely, we think there are serious issues with platforms and online safety that do need to be tackled but we really caution that we need to be careful not to end up doing more harm than good with age verification. When we think about the rights to free expression and autonomy for young people and for adults online, it is really important that we avoid a chilling effect. If we are talking about Government-issued apps, that issue can be even greater. These systems can also come with a serious risk of exclusion, especially for people with low levels of literacy, people from backgrounds where they face high levels of structural exclusion and undocumented people.
The EU app has been mentioned. We have gone through the specifications for it and it is not currently compliant with privacy and data protection rules in our opinion. Anonymity, for example, when using the app is optional according to the specifications. This is why we say we really do need to make sure we do not obliterate anonymity on the Internet entirely. It has a lot of benefits for civil society, journalists, whistleblowers and young people. Instead, EDRi points very much to the structural measures that can make the Internet safer not just for children but for everyone. A big chunk of this is enforcement of existing tech laws.
There is a future EU law coming, called the digital fairness Act, on which in my colleague Dr. Domínguez de Olazábal, was our expert. This has the possibility to further tackle some of the toxic business models and structures that put us all at risk when we are online. We think this is a much more sustainable and long-term solution. Once we have these improvements there may be certain cases where age verification could be the right solution but, as it stands right now, it is a sledgehammer approach and we have not ironed out all of the problems that are associated with the use of these acts.
Comment on this
It is certainly a difficult issue. We are all in agreement that increased regulation, legislation and enforcement is the best way to go, and it is great to see this new investigation into Grok today, but we have other investigations pending into other companies and they are fighting them tooth and nail every step of the way. Then we see Europe is trying to push ahead with increased regulation or, in some opinions, watered-down regulation while the rest of the world is pushing back. Meanwhile, citizens are going onto VPNs and accessing apps and websites that are not even based in Europe. It is definitely going to need a multipronged approach.
Comment on this
To give my two cents on this, children are extremely resourceful and tech savvy when it comes to accessing the things they want to. My concern with these proposals is that we will end up forcing kids who want to access material, rightly or wrongly, into a position where they have to get into more and more dangerous situations to do it. Rather than having a situation where we try to make the Internet safer in general, we are pushing kids into a situation where they have to talk to more dangerous adults to try to access these systems. My concern is that by trying to age gate we actually create a more dangerous situation and make it less likely that kids will reach out to trustworthy elders, such as their parents or teachers, when they find themselves in trouble.
Comment on this
We will now have a second round with the witnesses. Each question will have four minutes. We will start with Senator Ruane.
Comment on this
Most of my questions are on public services. They probably also relate to the digital verification of age and how the profiling and tracking data is used in other ways at a later date, with regard to justice and other institutions that could potentially access the facial recognition data of a person taken while they are under age. Who holds this data and where does it go?
I am interested in Dr. Domínguez de Olazábal's contribution on automated decision-making under Article 22 as another area that will be potentially further deregulated. Will she speak about what this means for the issues she mentioned such as credit scoring but also what it means for those who rely heavily on public services and where it could intercept with disability, housing and the Judiciary? We see a lot of reports, including from Goldman Sachs, saying 44% of legal operations could be done by automated systems. Will Dr. Domínguez de Olazábal speak about this, in particular in relation to public services?
Comment on this
I understand the first question as being about all of these entities, many of them private, having data and amassing enormous quantities of data that can be reused afterwards. This is a very important topic to take into consideration because when we speak about data it is not only data that will fit into one AI system or model afterwards; this data will be used across the value chain of the AI system and model. The digital omnibus package will make this easier, through broadening or choosing another definition of scientific research. The definition of scientific research will allow for the repurposing of the data without having to ask about the concerns of, or objections by, the data subject as long as it for well-being and the good of society.
We know that what happens is that many companies say what they are doing is for the good of society. For example, in 2014 Facebook did psychological research and used the data to analyse the psychological profile of its users. We have seen it with Cambridge Analytica. We have a sizeable number of examples and real cases of harm, whereby we know that companies say everything they do is for the good of science and for the good of society but it is exactly the opposite. We need to be really careful about this.
When it comes to automated decision-making I mentioned credit scoring because it is one of the examples where many decisions of data protection authorities, supervisory authorities and the Court of Justice of the European Union come in. It is very blatant and clear the moment someone is granted or awarded credit or a loan but automated decision-making happens throughout the public context, such as in anything that has to do with welfare. We saw a scandal about this in the Netherlands some years ago when profiling and discriminatory profiling was done to deny people welfare benefits.
The Senator mentioned also the danger of automatic decision-making in the judicial system. Clearly, that is not happening yet because digitalisation of the judicial sector is happening very slowly. However, we also see the European Union and the European Commission trying to boost the idea of digitalisation and automation of certain parts of the value chain of the judicial process.
Again, automatic decision-making is happening throughout anything that has to do with filling data into a system and the system making a decision. Even if there is a slight human intervention, it can also be said that that is automatic decision-making. This is why we emphasise not undermining the safeguards. The rule or the prohibition as the general rule should remain. If we are going to use automatic decision-making, this should be the exception and there should be other specific criteria with very high safeguards, higher than the ones we have now. However, maybe now it is not our turn to propose higher safeguards when we are in a context of deregulation.
Comment on this
I would like to talk about governance. We have mentioned that there is a governance framework in place following on from EU directives that established things like the Data Protection Commission, DPC. Then, more recently, we have Coimisiún na Meán. They all have powers designated to them under the GDPR, the Digital Services Act and so on. The approach now being taken here in Ireland for the establishment of the AI office is that it is being set up in the Department of enterprise and then will be moved out of that to become an independent State agency. I myself have led a State agency. I have concerns that where an organisation originates will influence its later development. I have concerns that because this is originating from the Department of enterprise, it will sow seeds for future problems. I go back in particular to the fact that we spoke earlier about the deregulation, simplification and harmonisation agenda. That is being championed in most countries by departments of enterprise and departments of finance and the same officials who will now be charged with essentially establishing our AI office. I would like to hear if any of the witnesses have concerns or if they share similar concerns. Also, what would be best practice? What do they see happening in other EU jurisdictions?
I have a load of other stuff I would like to get to. I ask that we might extend these time slots to seven minutes, given that there are only a few of us, but perhaps we might get a second round. I also note how disappointing it is that there are not more Government TDs from the membership here today and that we have mostly Opposition TDs because the message the witnesses are giving us is very important.
I ask about their feelings about the establishment of the AI office. My frustration is that the DPC and Coimisiún na Meán have powers that do not seem to be politically enforced at the moment. If we are going to set up another office, are we just adding more furniture to the State infrastructure without the powers or the political will to actually do anything with it? I ask Ms Jakubowska to comment.
Comment on this
Yes, I share the Deputy's concerns. One of our key demands for the AI Act implementation across member states has been for market surveillance authorities to be completely independent. We think that is the only way they can guarantee that they can perform their duties under this regulation. Yes, it sounds concerning, and we have seen similar issues in other member states - Italy, for example - where we have mobilised as civil society to try to push for a more independent authority. I share the Deputy's concern about political will in general. All these authorities, in fact, need more resources and more co-operation and they can often be completely hamstrung from that if they do not have the political will.
Comment on this
When the AI Act was first announced as something that would be pursued, my reaction was that we have this amazing legislation in the GDPR that is not being used to its full extent with regard to AI. If only data protection authorities had the resources, the political will or independence or both, I think there would have been less real need for the AI Act. My concern, therefore, is that we are multiplying regulation without actually enforcing what is already on the books.
Comment on this
I agree with what both my colleagues said.
Looking to other industries, such as medical devices or home appliances, those products do not get to the customer or the consumer before they are thoroughly vetted, and we have extensive guidelines that regulate those products, so why are we not doing that with AI?
Comment on this
I will start with Dr. Birhane. She had in her opening statement a great quote from Peter Thiel, which kind of gives the game away. He is a guy who does the theory and the practice. He talks about technology being "this incredible alternative to politics", and by "politics" he means democracy.
Comment on this
Dr. Birhane talks about those who control AI being the ones who benefit from and who are driving it. Who is that, both individuals and companies? What are the core drivers of this AI-ification of society and economy that is happening?
Comment on this
There are big tech companies, like Google, Meta, Amazon, Netflix and so on, and there are AI companies - for example, OpenAI. There are various upcoming startups but also companies like Anthropic and so on that are just based on AI products or AI research. AI is not just a technical development. Even, for example, when you embark on producing a simple regression model, yes, the data has a massive impact in how that AI system performs but behind all that, and something that does not get enough attention, is that you are deciding what to optimise for, what you want the objective of your AI system to be, where it will be and so on. These are all political agendas that shape how these technologies perform, not just in the training detail they are trained in. Again, look at the financial reports or the wealthiest companies over the past 20 years. Twenty years ago we would have seen much more diversity in the top ten list: maybe automotive companies, supermarket chains, food chains and so on.
Comment on this
It is all big tech now.
Comment on this
Now all that is gone. It is just big tech that is growing at unprecedented pace and amassing massive financial, political and cultural power and basically controlling everything from rule-making to public narratives in the public attention, all with a single purpose of maximising profit. Also, with that comes the political agenda.
Comment on this
Dr. Birhane goes on in her opening statement to make the really strong point that "governance by algorithms ... inherently places our digital public squares and democratic processes in the hands of those that are building these systems in line with their political and profit-seeking agendas". Even as regards the concept of digital public squares, that is the reality of how people would certainly like social media to function. These are what should be public spaces but they are privately run, but privately run in such a way that people almost do not see it. If you go into a private space in the real world, there is a private security guard, there are private rules and it is very obvious to people, whereas the algorithms happen behind the scenes and you do not realise that what you see is being shaped by these algorithms, which are shaped by the companies' interest, not our public interest.
As to what we do about this, I really welcome the pushback that came from all the speakers, I think, against age verification, which is two things. First, it is "Something needs to be done; this is something". Second, it is about washing our hands. We will just ban children, supposedly. They will not really be banned. They will be able to access it. If you see horrible, toxic material online, that is your problem or your parents' problem because "we banned you and we have done our job". Then that leaves the rest of us in this filth that is spewed at people.
One thing we have been pushing is the idea of turning off social media algorithms-----
Comment on this
-----full stop for children and by default for adults. Is that something the witnesses think we should do?
Comment on this
I think that is a good idea because the recommender systems algorithmically curate in a personalised way.
I do not know if I have time to get into what personalisation means. Personalisation equates to taking a person's history and what has happened to them and constructing a future that replicates exactly that for them. If someone is an insanely racist person, then what they get is their future predicted as that. By curating these algorithmically selected feeds, they are maximising people's attention and generating revenue. Turning off recommender systems is a low-hanging fruit that has been suggested by several organisations.
Comment on this
I echo Ms Jakubowska's comments. She mentioned the future digital fairness Act, which is a modernisation of consumer law. EDRi and other organisations are already calling for many of these options to be turned off by default. That is the case with what we call addictive design. Recommender systems are a perfect example of addictive design, but they are not the only one. We have all spent hours doomscrolling. That is the case with this type of design. We also call that app patterns, and it is any design or interface that would allow us to freely choose. This is the case for cookies, but we have seen that all throughout the Internet. This is the case also for personalisation. There are many instances of personalisation that should be turned off by default and that should be banned in some cases. If we have the time afterwards, I would love to discuss that.
Comment on this
As already stated, we saw the situation in England in 2024 and the effect AI had on the system involved. In 2024, we also saw in Romania where algorithm hijacking occurred and the elections had to be annulled. We spoke about the digital omnibus regulation, the Digital Services Act and the EU Artificial Intelligence Act. We are under severe pressure from giant tech and so forth. How can ordinary citizens push back against the dilution of the GDPR and our rights? We have to leave governments out of this. It is going to be people power that will change things.
Comment on this
Sorry, I am not sure I fully understand the question.
Comment on this
I think in the context of this discussion about the deregulation which is taking place in Europe, the question is directed towards the fact that we are here as politicians but should people be responding to this?
Comment on this
I will briefly repeat the point I made earlier. Look at the medical devices manufacturing industry. It is heavily regulated and its systems are extremely weighted and tested before they enter the market. AI systems, even though they are not physical things like medical devices, are having a massive impact on societies, democracies, the rule of law and truth. For any AI developers, vendors or providers, there has to be a mechanism for them also to ensure that the systems they are developing are actually aligned with the public good and actually beneficial to society, not just the empty claims they make, but based on the processes of vetting. These are mechanisms that we can develop to ensure that any AI systems which enter society are actually not damaging it.
Comment on this
I agree completely that we need more people pushing back in respect of this broad deregulation agenda. As mentioned earlier, it is not just our vital data protection and tech laws; it is also environmental protections, workers' rights and other social protections. It is many of the different things that we all rely on every day. There are rules we do not see or touch in our day-to-day lives but actually tangibly do keep us safe. They protect us from chemicals, for example. This is another big area that is being deregulated in order that European companies will be able to use a lot more harmful chemicals in their products. As a civil society, we are doing our best to get this message out. We can also tend to be a bit of a group of tech nerds. As a result, we rely on lawmakers and on others to help us get this message out. I hope that it will resonate with people because this is beyond the digital space, which is-----
Comment on this
It is very difficult for individuals to fight back or to use the rights they have. Civil society and trade unions can actually empower the people they represent to use these things and to fight using the rights they have to show that they are keen to flourish in society. It is very difficult for individuals on their own, but when people join together and have representatives, whether they are trade unions or civil society, that is a key part of the picture.
Comment on this
Thank you very much, Professor Binns. That leaves me with my four minutes. A question was put to Ms Jakubowska earlier about how the Irish Government approach is viewed. I do not want to misrepresent what her but I think I heard her say that it is really Germany and France that are heavily associated with what she would term the deregulation agenda. We have had a lot of discussions and naming of US companies, but, of course, there is also a French company involved, namely Mistral AI. This is an AI company that is at least trying to get to a level where it would be in the same conversation as some of these other US LLMs and, presumably, Chinese ones too that we in this part of the world are less familiar with. To what extent is that a relevant factor in what is taking place at a European level? I am referring to domestic pushes in those countries, let us say Germany and France, as distinct from what the narrative is of the pressure being exerted by the transatlantic companies. There is a dual debate going on right now about ensuring that from a security perspective in the context of the technology it uses, Europe should that in terms of a defence context. We also need to ensure that Europe is competitive and can keep up with what is happening with our transatlantic neighbours.
Comment on this
The Leas-Cathaoirleach is right that it is a very nuanced picture. For companies like Mistral AI, which he mentioned, and other companies of European origin, the protection of those companies is one of the driving factors. Mistral AI is also a very good example of why the current agenda is not even going to achieve these aims. As soon as Mistral AI reached a certain size, it entered into partnership with Microsoft, which is now reaping a lot of the economic benefits of Mistral AI's success. It is not now channelling making the EU better for people in the EU. This is why we think we need a different approach from the one being pursued. Of course, it is legitimate for competition and innovation to be goals, but they should not be the end goals in and of themselves without there being respect for people's rights and freedoms. It looks like my colleague Dr. Domínguez de Olazábal wants to come in.
Comment on this
Before Dr. Domínguez de Olazábal comes in, I want to make a further comment. In this space, there appear to be two competing narratives on regulation at the same time. There seems to be a big pro-regulatory push, so to speak, from both politicians and the people to protect children against the harms of social media. We are seeing domestic legislatures respond. We would like the supranational legislature, the European Parliament, through the European Commission, to respond and to build on perhaps what might be working in Australia with the social media ban for under-16s. We are almost reaching a societal position where there is an overwhelming view - even among the children who could be banned from social media - that we must regulate in a very tough way on children's access to social media. How do we balance that emerging philosophy with the other philosophy that Ms Jakubowska is talking up and expressing concern about in relation to how we are regulating LLMs and the development of AI in Europe?
Comment on this
These things can be very coherent, because a lot of the work we are doing goes back to the core framework that we already have, namely, the Digital Services Act, the audiovisual media services directive and the GDPR.
Several regulators have already been mentioned such as the DSC and Coimisiún na Meán which under these laws have powers to enforce rules to better protect children online. We do not necessarily need new regulations to do that. We need all the exciting things I already mentioned around resourcing and political will. That is where the focus should be. Regulations are neither good nor bad; hey are tools that have political meaning and power. We need to be very careful to properly assess the ones we have. This means that when supposedly simplifying them, we should be assessing them to measure sure the core protections people rely on are not removed. Moving in that direction would make a lot more common sense and would probably lead to much better outcomes for everybody than engaging in rushed or knee-jerk reactions, which is what a lot the social media bans we are seeing around the world are. As Professor Binns mentioned, children are extremely resourceful and are the best equipped to circumvent any sort of age verification system or social media ban put in place.
Comment on this
There are also rules in place to provide legal certainty to regulators, civil society and companies. What we hear from some companies that are not being asked when it comes to the digital omnibus is that when it comes to the GDPR, they have been investing money and resources for years in order to understand how the law is being applied and how they need to interact with the regulator and with people - the data subjects. Now, there are new laws - I beg the committee to look at the articles - they are really difficult to understand. We have had many experts look at them. They will not provide legal certainty for years because first there will be negotiations. Afterwards, most of these provisions, if they are in force, will go to the DPAs and will go to court because many people will challenge them.
There will be regulators and lawyers in these companies trying to understand how the new contracts apply to them. The few companies that will take advantage of all of this are those that already have swathes of lawyers involved. They are advocating for these changes already. In terms of competitiveness even the so-called benefits of the digital omnibus and the reduction in the burden are rightfully being challenged. We need to take that into account also. It is not going to help just-----