Artificial Intelligence, Truth and Democracy: Discussion (Resumed)
Coimisiún na Meán and the Data Protection Commission said AI-generated deepfakes, nudification tools and child sexual abuse material are already illegal, but the main regulatory challenge is prevention rather than relying on takedown after harm occurs. Coimisiún na Meán stressed that very large platforms must assess and mitigate risks in advance, while the DPC focused on lawful processing of personal data, transparency and data protection by design. Both regulators said they are working closely with each other and with EU bodies, and both are actively involved in inquiries concerning X, though they would not comment on live investigations. A recurring theme was that stronger powers, clearer legal definitions and more technical and staffing resources may be needed as AI harms evolve rapidly.
We are proceeding with our discussions around AI truth and democracy. As the witnesses may be aware, our committee operates in a module format looking at each issue but given artificial intelligence's impact on so many areas of society, there are a lot of areas we want to explore. We have a particularly busy agenda today. We have two sessions.
I welcome our witnesses from Coimisiún na Meán and from the Data Protection Commission to our first session. They are, no doubt, aware of the limitations and so on, as are the committee members, having been before some Oireachtas committees before. I welcome them and thank them for their input. The representatives from Coimisiún na Meán are Mr. Jeremy Godfrey, executive chairperson, and Mr. Tiernan Kenny, director of communications and public affairs. From the Data Protection Commission, we have Dr. Des Hogan, chairperson and commissioner, Mr. Cathal Ryan, deputy commissioner, and Ms Gemma Harris, assistant commissioner.
I invite Mr. Godfrey to deliver the opening statement on behalf of Coimisiún na Meán.
Comment on this
I thank the committee for the invitation to attend today. I might start by briefly describing the relevance of our online safety framework to the issue of non-consensual AI-generated images and videos. I will then make some observations on possible changes to the law that have been suggested.
The online safety framework came into full force in July last year. It consists of three pieces of legislation, the EU Digital Services Act, the EU terrorist content online regulation and the Online Safety and Media Regulation Act 2022, which is the basis for our online safety code. We will incorporate the obligations of platforms under the AI Act into this framework once the necessary implementing legislation is passed.
The online safety framework imposes binding rules on platforms to keep people safe online. Under Irish and EU law, platforms are not treated as publishers. They are obliged to remove illegal content once it has been reported to them, otherwise they risk becoming liable for it. Platforms have an obligation to protect the safety, security and privacy of children online. Detailed expectations about how they should do this were adopted last July. There are also specific obligations for video-sharing platforms to restrict video content which is harmful to children, or which incites hatred or violence on grounds of protected characteristics, or which promotes terrorism or which is child sex abuse material. Video platforms that allow adult content, such as pornography and extreme violence, must put in place effective age-assurance measures. The largest platforms are required to assess and mitigate a set of risks arising from how they are designed and used.
Under the AI Act, platforms will be prohibited from deploying AI systems that are manipulative, deceptive or exploitative and cause users to take actions that cause serious harm. They will also have transparency obligations related to labelling of deep fakes. Our remit covers platforms whose EU headquarters are in Ireland. For the largest platforms, we share competence with the European Commission.
We share the public’s concern about the misuse of generative AI, particularly when it is used for non-consensual sharing of intimate images or the creation of child sexual abuse material. This type of content is illegal under Irish law. Platforms must remove it when reported and very large online platforms must mitigate the risk of it appearing on their services in the first place.
The European Commission is, with our assistance, conducting an investigation into X’s compliance with its obligations in respect of these matters. As this is a live investigation, I will not be able to comment further about it.
Nudification is not the only way that generative AI might produce illegal content that depicts real people without their consent. For instance, it could be used to produce deep fakes that incite hatred or violence, and it can be used to produce scam advertisements that include a purported endorsement by a public figure.
Generative AI can also be used to produce video content that platforms must restrict under our online safety code. Platforms' obligations under the online safety framework apply equally to AI-generated content as to other content. These obligations are designed to be proportionate in addressing harms, without interfering in the exercise of freedom of expression under the law.
The issue of non-consensual AI-generated imagery potentially engages legal obligations beyond our online safety framework. We collaborate closely with other relevant bodies, including An Garda Síochána and our colleagues in the Data Protection Commission, as well as with the European Commission and our counterparts in other member states.
As well as enforcing regulatory obligations, we provide information and support to the general public. We are running a campaign to inform people of their right to report content they believe to be illegal or harmful to the platform on which they see it. If people are not happy with the outcome of such a report, they can telephone our contact centre on 01 963 7755 or email us at usersupport@cnam.ie. We are particularly concerned about the impact on children and young people. Our website provides information on a range of support services and resources for parents, teachers and young people, including videos and guides on how to report. It also includes videos and lesson plans, which we have developed with Webwise and shared with schools. For Safer Internet Day earlier this month, we collaborated with the DPC on advice for teenagers when dealing with AI.
On legislative change, it is important that deployers of generative AI systems should be alive to the risks of misuse and should implement safeguards to mitigate them. Risk assessments are required under the Digital Services Act when an AI system is integrated into a very large online platform or search engine and when a system meets the definition of a general-purpose AI system under the AI Act. We think it is worth considering whether to supplement these requirements. For instance, it could be useful to make it a prohibited practice to deploy AI systems that are capable of producing intimate imagery of real people without their consent or producing child sex abuse material. It may also be useful to widen the scope of high-risk systems as defined under the AI Act to include a wider range of chatbots and generative AI tools.
In the three years since Coimisiún na Meán was established, we have begun to see changes to make the online world safer. We have seen platforms introduce new age assurance measures, prohibit pornography or violence in their terms and conditions and introduce additional parental controls. We have seen some platforms improve their reporting mechanisms for illegal content. We saw one platform withdraw a proposed product that would have had damaging addictive design features. We have opened a number of investigations, as have the European Commission and some of our counterparts in other member states. The European Commission has made its first findings of non-compliance and imposed its first penalty on an online platform.
However, the changes we have seen have not yet been sufficient and new types of harm, especially harms related to AI, have emerged. In collaboration with other public bodies in Ireland and our counterparts across the EU, the entire regulatory and law enforcement community will continue to use the tools available to us to have an impact in driving a safe and trusted online environment that protects fundamental rights.
Comment on this
I thank the Cathaoirleach and members for the invitation to appear before the committee. I am a commissioner for data protection as well as the chair of the Data Protection Commission. I am joined by my colleagues, Mr. Cathal Ryan, deputy commissioner, and Ms Gemma Harris, assistant commissioner. I have provided my opening statement to the committee. In the interests of timeliness, I propose to outline the main points.
The DPC is the Irish supervisory authority for enforcing and monitoring compliance with the general data protection regulation, GDPR, the Irish e-privacy regulations and the EU law enforcement directive. In recent years, and particularly since the launch of a number of popular consumer-facing generative-AI services, artificial intelligence has become an increasing focus of the DPC's work, particularly with respect to how personal data is used to train AI models and in ensuring individuals across the EEA and the EU are able to assert their GDPR rights in relation to AI-driven services.
While AI holds significant promise for positive, transformative impacts across numerous sectors, its potential benefits can only truly be realised if substantive risks and potential harms associated with the technology are proactively identified and appropriately assessed and managed by the developers and deployers of the systems. Those risks and harms can manifest in different ways but the DPC's particular focus is on ensuring the processing of personal data is done lawfully and transparently and that the rights of individuals both in Ireland and across the EEA are upheld.
The remit of the DPC relates to the processing of personal data rather than the nature of online content. Personal data comes in many forms, including an individual's personal image.
For all types of data processing, controllers, in this case the organisations that process the data, must have identified a lawful basis for that processing. They must also identify and implement appropriate technical and organisational measures by design and default to prevent risks arising to the rights and freedoms of individuals. Chief among the specific data protection concerns potentially at play here are legal basis, fairness, transparency and data protection by design and default. The burden under the GDPR lies with each individual data controller. The controller must be able to demonstrate that it can rely on one of the six lawful bases provided for under the GDPR to carry out that processing. Those are: consent, contractual obligation, legal obligation, to protect the vital interests of an individual, because it is in the public interest or to pursue its own legitimate interests. Controllers must demonstrate they have carried out the necessary assessments or balancing tests required to be able to rely on a legal basis,
The DPC works closely with our European peer regulators through the European Data Protection Board, EDPB, and with our national digital regulators, including our colleagues at Coimisiún na Meán.
As we announced last week, the DPC has opened an inquiry into X regarding the apparent creation and publication on its platform of potentially harmful non-consensual intimate or sexualised images or both containing, or otherwise involving, the processing of personal data of EU-EEA data subjects, including children, using generative artificial intelligence functionality associated with the Grok large language model. The purpose of the inquiry is to determine whether X has complied with its obligations under the GDPR areas, including the principles of data processing, the lawfulness of processing, data protection by design and default, and the requirement to carry out a data protection impact assessment.
As the committee will all appreciate, and in line with the provisions of the Data Protection Act 2018, it would not be appropriate for me to comment upon issues relating to an active inquiry being carried out by the commission and, consequently, I will not be able to address any questions from the committee relating to it. The DPC is, however, determined to carry out a swift, fair and effective inquiry.
The committee may be interested in the role of the DPC in its ongoing supervision of AI systems provided by a number of well-known multinational tech companies. Our supervision and consultation team, led by Deputy Commissioner Ryan and supported by Assistant Commissioner Harris, provides fair, expert, independent, forward-looking, results-driven engagement and guidance with companies and public bodies alike on their products and services. It is important to note that we regulate the public and private sectors. The supervision team operates independently of other units in the DPC. It engages with companies primarily before a product or service launches and comes to market and prioritises services and products which have the potential to have a higher impact on individuals’ lives. We carry out this task in co-operation with our peer European data protection authorities and this allows the DPC to direct controllers towards compliance.
I will share some interesting statistics. Since 2021, the DPC's supervision function has seen a sixfold increase in AI-related engagements. By 2025, AI accounted for over 25% of all controller engagement and, since its market emergence in 2023, engagement on generative AI-related products has dominated, representing 74% of all AI-related activity. Between 2021 and 2025, the DPC engaged with companies in relation to approximately 180 AI products and services. In 2024 and 2025, 59% of these engagements resulted in formal recommendations to improve compliance. By engaging early and providing robust, evidence-based documentation, AI developers can mitigate risks, reduce the likelihood of future inquiries and build products that respect the fundamental rights of European citizens.
In our written submission, we point to the fact that other units in the DPC have taken a number of regulatory actions that we deemed necessary, including seeking orders from the High Court and conducting inquiries into AI systems. The DPC sought and obtained EU-wide consensus, culminating in EDPB Opinion 28/2024, which provides a harmonised framework for AI model training across the EEA.
Regulators such as the DPC require sustained support from the Government as new responsibilities increase workloads. This is vital if Ireland is to maintain its global standing as a digital regulatory hub while fully discharging our obligations as leading EU regulators. AI developments over the years to come will bring with them ever-growing and complex challenges for regulators acting on behalf of Irish and EU citizens.
I again thank the Committee for inviting us to attend today and look forward to today's discussion.
Comment on this
I thank Mr. Hogan. We will now go to questions from committee members. I remind members that the witnesses cannot comment on any ongoing inquiry or investigation. Members will appreciate the reasons that is the case. We are allowing five minutes for questions and answers. Given the number of people who are here, I ask members to remember that the five minutes available are for questions and answers.
I am normally lenient on time but we will have to be stricter today. I am also conscious that Senator Higgins is substituting for Senator Ruane and Senator Ryan is running late. Senator Scahill has the first question.
Comment on this
I thank the witnesses for coming in this morning and for their opening statements. The statements have gone over a lot of stuff that we heard in previous submissions like, for example, non-consensual AI-generated imagery is illegal and platforms must remove it once it has been reported. However, if harm is only addressed after reporting, how can Coimisiún na Meán justify a framework that is reactive rather than preventative, especially with viral deepfakes?
Comment on this
I thank the Senator for the question. The important thing to highlight here is that for the very large platforms there are safety-by-design requirements. Very large platforms, that is, those are the ones with over 45 million users in the EU, are required to do risk assessments before they launch their services, or before they make major changes to their services, and to mitigate the risks. That is in advance of launching services or making changes, so those platforms should make sure that this content is not on the platform in the first place.
The Senator is right. Reporting it once it is there, is definitely much less preferable than stopping it in the first place. Although I will not comment on anything that is not public about the actual inquires, one of the things the commission said was that X had not submitted a risk assessment for the inclusion of Grok on its platform or for the changes in the guardrails. That is one of the things that is being looked at in the investigation but the key thing is to make sure we have safety by design for the very large platforms. They are also requirements to implement children's rights and to adopt safety-by-design measures for children. These apply to all platforms and not just the very large ones.
Comment on this
Mr. Godfrey refers to safety by design. Is there any measurable evidence that notice and take-down systems are fast enough to prevent irreversible harm? That is thing we are most concerned about.
Comment on this
Notice and take-down mechanisms are important. It kind of depends on the harm. The requirement is to enforce terms and conditions diligently. We see that with child sex abuse material, the platforms are, on the whole, quite speedy in taking that down. However, we get lots of complaints about other kinds of harmful material, whether it is hate speech or other things where the platforms have not been fast enough. Under the Digital Services Act, people who are dissatisfied with a decision have a right to appeal. Some of the investigations we have taken have been around whether it is easy enough for people to make reports and whether the reports are being acted on diligently. We have also investigated whether the appeal mechanisms are genuine or are people just getting an automated rejection of their appeal straight away. We are looking at all of these things. We are not satisfied with the way those mechanisms are working, and we are taking superficial and enforcement measures to get improvements.
Comment on this
Mr. Godfrey also mentioned that AI can generate images of real people without consent and that this issue may engage obligations beyond the online safety framework. Who has primary jurisdiction over consent breaches with deepfakes? Does Irish law currently recognise a stand-alone right not to be systematically replicated?
Comment on this
I might ask Mr. Hogan to go through the GDPR implications of that. Sometimes harms or behaviours that we talk about engage more than one legal regime.
For example, the scam advertisements would engage the consumer protection law and they might engage some of the requirements for platforms to mitigate the risk of illegal content. There are different legal regimes involved, but one thing we have all twigged in the regulatory community is the need to work closely together. We do not want someone who is making a complaint to have to wade through pages and pages of legislation to work out who to make the complaint to. We work together so that if any of us get a complaint that we think will would be more appropriately dealt with by another regulator, we have mechanisms for engaging with one another about it.
Comment on this
Am I right in saying that the legislative framework that Coimisiún na Meán operates under is the online safety framework and that comprises three pieces of legislation: the EU Digital Services Act, the EU terrorist content online regulation and the Online Safety and Media Regulation Act 2022? Is that the legislative basis upon which Coimisiún na Meán acts and enforces under?
Comment on this
When Mr. Godfrey says that the misuse of generative AI, particularly when it is used for the non-consensual sharing of intimate images or the creation of child sexual abuse material, is illegal content under Irish law, does Coimisiún na Meán have the power to enforce those laws?
Comment on this
There is Coco's Law, which makes the non-consensual sharing of intimate images a criminal offence. The enforcement of that under criminal law is a matter for the Garda, not for us, but because it is illegal content, there are some consequential obligations on platforms. They have to remove it, if it is reported to them, or else they become liable for it. The very large online platforms have a duty to assess the risk of that sort of content appearing on their services and put in place guardrails and mitigation measures so that content does not get disseminated through their services. The underlying criminal offence is a matter for the Garda, but the consequential obligations that apply to the platforms is a matter for us and, in some cases, the European Commission.
Comment on this
When Mr. Godfrey says, in the context of the AI Act, that it could be useful to make it a prohibitive practice to deploy AI systems that are capable of producing intimate imagery of real people without their consent or which are capable of producing child sex abuse material, are those acts not already unlawful under Irish law?
Comment on this
It is unlawful in Irish law to produce the imagery, but it is the deployment of the tool that would be prohibited under the AI Act. At the moment, it is not a criminal offence under Irish law to deploy an AI system that can be used in that way. Using it in that way is a criminal offence, but the AI Act does not bite on the users of AI who are putting the prompts in. The AI Act puts obligations on the developers and deployers of AI models and AI systems. It would be another tool if people were not providing the ability to break the law in such an easy way.
Comment on this
Will Mr. Godfrey tease out a little bit more what he means by deployment in that context?
Comment on this
Deployment essentially means making an AI system available on the market that end users can use.
Comment on this
Is it unlawful for an AI system to be used currently to create or generate non-consensual sexual images?
Comment on this
It is unlawful for the user to generate the images.
Comment on this
It probably depends on the precise facts, but it is not inherently unlawful to deploy a system.
Comment on this
Is Mr. Godfrey's point then that it is the systems themselves that should be subject to prohibition?
Comment on this
Yes. The other thing is that in the AI Act, as the Deputy will be aware, there are prohibited practices and there are also high-risk systems. We are suggesting it might also be worth looking at broadening the list of high-risk systems that would require a risk assessment before they were deployed.
Comment on this
This may not be for Coimisiún na Meán to answer, but how is it conceivable that in the creation of the AI Act that the legislatures and everyone involved did not contemplate the vista we have arrived at now that we are now going to already make changes? Are the changes Mr. Godfrey is recommending something we, as an individual member state, could do alone or is it an EU-wide measure that needs to be taken? Is that happening?
Comment on this
I cannot answer for the co-legislatures on the AI Act but, of course, it is not surprising given how fast things are moving that things will emerge that were not contemplated. The AI Act does allow for the list of high-risk systems to be amended by the European Commission in a delegated act. That can be done without legislation. The list of prohibited practices requires EU-wide primary legislation. I am aware that there is a digital omnibus already under consideration which is going to make some changes to the AI Act. I understand there are member states and probably members of the European Parliament likely to propose these kind of changes.
Comment on this
I thank all the witnesses for being here and for their opening statements. I am going to start with Dr. Hogan. For transparency, Dr. Hogan and I worked together for a short time in the Irish Human Rights and Equality Commission. It is good to see him again.
I fully appreciate witnesses cannot talk about the case but I want to talk about nudification apps more generally. We know they have been around for a bit of time. Has the Data Protection Commission taken action against this type of tool in the past because they clearly violate rules around use of personal data?
Comment on this
I thank Deputy Gibney for the question. I do not want to go into the current inquiry. I know the Deputy is not asking me to.
Comment on this
I have a few bits I want to get to. Has there been any action?
Comment on this
Has the DPC taken action on any nudification app?
Comment on this
This has not come across our desks to date, no.
Comment on this
Yet, in the opening statement Dr. Hogan mentioned the data controllers must: "identify and implement appropriate technical and organisational measures by design and default to prevent risks arising to the rights and freedoms of individuals where their personal data is involved in said processing." I would have thought nudification apps would fall into that category. If the DPC has not taken action, is that to do with a resourcing issue or a lack of powers issue or has it not hit the level of priority as other threats to data?
Comment on this
It would not so much be a question of priority. Our supervision and consultation team are in touch on a weekly basis with all our peers across Europe so if any data protection authority across Europe raises a question with us we will go back to the company in question to raise questions and probe the issue. It is more the case that this has not come up in the past.
Comment on this
It has never come up. I want to ask another question related to powers. It is around the DPC's power around the Article 60 final decision. Aside from amicable resolutions, has the DPC ever taken a single Article 60 final decision regarding Google since the DPC's establishment as an organisation?
Comment on this
We have, I think, 14 or 15 large scale inquiries completed. We have some against Google which are pending which we have not yet completed.
Comment on this
So the DPC has not yet completed a final decision.
Comment on this
While the Deputy asks her next question I will have a look at the list here. Some of them might have predated me.
Comment on this
I think the answer is no, we have not concluded an inquiry against Google to date.
Comment on this
Having been in a State agency myself, does Dr. Hogan feel the DPC has the powers and the resources to do the job it needs to do?
Comment on this
I thank the Deputy for the question. I referenced this at the end of our written submission. We, and other organisations, are facing into a period in the future where we are being given more functions, for example, under the AI Act. We also have the procedural harmonisation regulation which means we do need-----
Comment on this
It does need additional resources. I am quite interested in how it has operated to date and regarding existing resources, because that can give us either confidence or questions around the DPC operations into the future.
Are there parts of the legislation, for example, with which the Data Protection Commission has problems when it comes to the operationalisation or implementation of any of the powers it has as an organisation?
Comment on this
While it is a matter for others to judge whether we are doing a good enough job, we are confident that we have enough resources at the moment to do what we want to do.
Comment on this
To use its full range of powers.
Comment on this
Yes, to use our full range of powers. In the last two years, we have also increased staff numbers from about 200 to 300.
Comment on this
It is not so much around the staff; it is about particular powers because I understand they are not all as easy to operationalise regarding legal thresholds and so on. I will move on because I have a couple of questions for Mr. Godfrey.
In his opening statement, Mr. Godfrey stated:
Under the AI act, platforms will be prohibited from deploying AI systems that are manipulative, deceptive or exploitative and cause users to take actions that cause serious harm.
I am curious how that will be policed under the AI Act. Obviously, algorithms are the secret sauce. How does Coimisiún na Meán envisage accessing that level of transparency and enforcing it?
Comment on this
The question about what is manipulative, deceptive and exploitative content is something we are going to do some work on to try to come up with a-----
Comment on this
-----framework so we know what to look for in order to prove that. Obviously, those are high-level terms. The second point the Deputy made related to transparency. She also asked Dr. Hogan about powers. Information-gathering powers are important to a regulator. We found, because our legislation has been-----
Comment on this
I have one quick question as my time is winding up. It does not relate to the specific case. Does Coimisiún na Meán have the ability to mandate a website to take content down or geo-block, pending the outcome of an investigation? Can it bring an injunction to that end when there are reasonable grounds to believe illegal content is still being produced? Can Coimisiún na Meán take an injunction to have an app or product taken down?
Comment on this
We have powers to issue compliance notices.
Comment on this
Coimisiún na Meán cannot issue an injunction, however.
Comment on this
Coimisiún na Meán cannot do that or it chooses not to because of the remit it holds.
Comment on this
We do not have powers to order the immediate take-down of content.
Comment on this
I thank all the witnesses for their opening statements and for being here. This is a question to both organisations. Currently, video platforms that allow adult content, such as pornography and extreme violence, must have age assurance measures in place, which are not the same as age verification. The Government has announced that we are going to begin a pilot in the coming weeks with 2,500 young people around age verification. Does Mr. Godfrey, given his experience in Coimisiún na Meán, which enforces age assurance, think that is enough? How does he feel about us moving towards age verification?
With regard to the Data Protection Commission, we are getting a lot of pushback from people concerned about data. We are saying it will just be a signal to the apps. Does the Data Protection Commission have any concerns in that regard?
Comment on this
I will answer first. The provision in the online safety code is that age assurance must be effective enough that children are not normally able to see the pornography or the gross or gratuitous violence. We have not specified the particular technology to be used. Age verification is one form of age assurance but it is not the only form. As it happens, we now only have one video-sharing platform in Ireland that permits pornography. That platform has introduced forms of age assurance and we are evaluating whether they are sufficiently effective to meet the obligations under the online safety code.
Under the Digital Services Act, there is a wider range of obligations in relation to children, such as not having addictive design features, not exposing them to inappropriate content or unwanted content from strange adults. Obviously, those cannot be enforced unless a platform knows who its child users are. Forms of age assurance are required. The higher the risk, the more robust the form of age assurance must be. Age verification can be a good form of age assurance, one that is quite convenient for people to use.
We have also said that this has to be done in a privacy-preserving way. We are quite satisfied that there are technologies that can do that so that the relying party knows nothing about an individual other than that someone has verified their age.
The verifying party has no idea who it is you are using that verification for.
I will pass on to Dr. Hogan to talk more about data protection.
Comment on this
I thank the Deputy for the question. From the DPC's perspective, a technical solution needs to be found for this very difficult question. However, one of the things from the data protection and privacy side of things is our concern that age assurance will now provide additional means for companies to track, locate and use individual personal data. To solve one problem for the child, you do not want to create another, particularly with digital identities lasting for life.
Within the European Data Protection Board, we have adopted principles, and again, GDPR has very high level principles around how that might look. I might ask my colleague, the Commissioner-----
Comment on this
It would be great to get some specifics on the one that is going to trial in Ireland in the coming weeks regarding the Government chief information officer and the gov.ie wallet. Have the witnesses been involved in that so far?
Comment on this
Mr. Ryan might want to add to that, but on that, we typically engage with Government Departments before they bring something to market. Some meetings have happened already, and there is a bit of a way to go from our perspective. Again, we will be looking at all the different things around privacy by design and default and whether the data protection impact assessment is correct.
Comment on this
Jumping in on the Government's proposal, we will engage in a pre-consultation with the Government. That is part of our prior consultation role, and we have currently started that engagement.
It might be useful to the committee members to give them a sense of our views, which are collated within a statement from the European Data Protection Board that we informed and contributed to. It looks at the implementation and different options available for that. Obviously, the overarching goal is to find the correct balance of the safety of children with the fundamental right of privacy.
There are several ways you can go about this. I am conscious of time, but I suggest we give the committee the statement after the meeting today because I think it would be of benefit to members. It sets out our views on the options available and possible solutions, as well as the privacy enhancing technologies that are also available. I believe the committee is meeting Google later, and it may talk about privacy enhancing technology.
There is technology out there that can do this in a privacy-friendly manner, and that is something we would advocate for, as well as ensuring children are appropriately safe online.
Comment on this
Starting with the data protection commissioner, he referred to how separate interaction of GDPR and European data protection and so on indicates how separate legal frameworks can co-exist effectively and operate well independently. Close co-operation and regular engagement create an effective, cohesive and robust regulatory regime, ensuring entities can be held accountable for potential harms to European citizens.
Is that the Commissioner's view? Do we have a cohesive, robust regulatory regime that ensures entities can be held accountable for potential harms?
Comment on this
Certainly, it is our view within the European Data Protection Board community, which is the peer data protection regulators across Europe, that we work very closely together. Increasingly, with the new digital regulations coming through - the Digital Services Act, the Digital Markets Act - we are co-operating with regulators in those spheres.
As Mr. Godfrey said, there is much consultation, contact and tick-tacking between regulators. Part of this is we do not want the organisations we regulate to have to go through similar things over and over again if that is not necessary. There are different regulatory frameworks, but we work to the best of our ability to do it. It is now for others to judge whether it is working.
It is noteworthy that GDPR came in during 2018, but it has taken a few years for it to bed down. There are still an awful lot of cases going through the court of justice in respect of clarifying what that is. It is probably fair to say that is going to be the case with the Digital Services Act and the Digital Markets Act. These things come in, and there are ragged reactions taken from them.
They are usually appealed or litigated, and these take a while to work their way through the system. With the competition law in 1962, it was seven years before the first case might have come before the European court. It is something I understand everyone is very impatient for to get to where we want to be, and we as regulators want to get there as well, but some of these things take a bit of time to work through the system.
I hope that answers the Deputy's question.
Comment on this
How does the witness respond to criticism from digital rights campaigners that the DPC is effectively too close to big tech, that it is soft on the US tech multinationals headquartered in Ireland, and that it has "an abysmal record" in taking on big tech companies? An illustration of this was the appointment of a former Meta lobbyist as one of the three data protection commissioners.
Does Dr. Hogan think there is anything to any of that criticism?
Comment on this
Every organisation is free. It is very important that civil society organisations express their views and of course, everything is always taken on board. I do take exception to the last part of the Deputy's question regarding the appointment of a commissioner who would have gone through the top-level appointments commission, TLAC, process. Having been through it myself, that is a completely independent process and it is important to put that on the record. I do not accept those criticisms at all. Otherwise, we would not have anyone applying for jobs in this country.
Comment on this
I caution Deputy Murphy that he is aware of the rules around somebody who is not here before the committee, concerning their position. I advise him to be careful.
Comment on this
I am just asking the question. I did not name the person. There is criticism out there publicly, and there are articles written about it suggesting it is problematic for a former lobbyist to have such a role. I think the phrase is poacher turned-----
Comment on this
It is about somebody who is identifiable. The Deputy is aware of the rules. I ask him to move on with his questions.
Comment on this
I have answered that part of the question, which I do not agree with or accept, but could the Deputy repeat the first part of his question?
Comment on this
That the commission is too close to big tech and has an abysmal record for pursuing big US tech companies based here.
Comment on this
We have over €4 billion levied in fines at present. I can certainly say my predecessor and the current commissioners were very focused on regulating everyone we regulate, bit it the public or private sector. There is no fear or favour, I can guarantee that to the Deputy, and we apply the law as we apply it.
We work very closely with our peer regulators, we listen to their views and we listen to civil society organisations. We get complaints from an increasing number of individuals.
Comment on this
Thanks for that. I want to ask one "Yes" or "No" question to Coimisiún na Meán, if I can, because I am out of time. The witnesses referenced collaborating closely with other relevant bodies, including An Garda Síochána. Do they know whether the gardaí is looking to prosecute individuals from X or X as a whole?
Comment on this
The Deputy would have to ask that question of the Garda.
Comment on this
I have been asking this question of everyone I can, but the witnesses do not know either.
Comment on this
I have a few simple questions for the witnesses. With regard to the language some people use, like safeguards and guardrails, are these strong enough to mitigate against the misuse of AI systems? The witnesses said they have seen many changes in the past five years, but do they think they have kept up with the rapid development of AI? For example, we had Grok come out of the blue. That is it for the moment, if the witnesses could answer those questions.
Comment on this
With guardrails, it is incumbent upon the people who develop and deploy the systems to implement safety features. There are many safety systems you can put into AI systems, whether that is pre-moderation of prompts, post-moderation of outputs, the way the models are trained and testing for bias, and so forth. There are an awful lot of things that can be done, and the way the AI Act is set-up is to ensure the people who are deploying high risk systems identify the risks and implement appropriate guardrails. I do not think public bodies can specify in advance what the guardrails should be, in such a fast-moving area. The other thing is there are some prohibited practices. We talked about manipulative and exploititative AI systems that cause harm.
Comment on this
Does Mr. Godfrey see it as problematic where the people who are producing those guardrails are obviously motivated by their shareholders?
Comment on this
That is one of the jobs of regulators. If commercial organisations are solely beholden to their shareholders, that will cause them to do things that might deprioritise public safety and so forth. It is the job of regulation to make sure they operate in a way that is safe. That is not just for AI, that is for many things.
Comment on this
On the Data Protection Commission, what type of additional legal powers would be helpful for it to operate that are not there at the moment?
Comment on this
I thank the Deputy. We are fairly happy with our powers under GDPR at present. Obviously, we will keep that under review. They have to be workable. One of the difficulties we find is that we go through a very fair process when we conduct inquiries, for example. At the end of the inquiry, we are facing litigation. I know other regulators are in the same boat but that is an impact on the organisation in terms of being able to meet those legal challenges, particularly from the large platforms which are very well funded.
To go back to the earlier question about guardrails, when we engage with companies before they launch a product or service in the EU, we very quickly can tell whether they have done their homework - if I can use that term - in terms of whether they have prepared enough, taken mitigations and put in safeguards for that product from a data protection perspective. That is often in the case of what is called a data protection impact assessment for high risk processing. That will really tell us when they have spent weeks preparing this to make it compliant with GDPR. If that is not there, that starts ringing alarm bells. It depends on the organisation and company.
Comment on this
I thank Dr. Hogan. It is envisaged that public bodies will embrace full AI in their systems. How does Dr. Hogan see GDPR being protected under this system? We know it would be very politically sensitive to bring public bodies to task or fine them for breach of privacy.
Comment on this
Well, we are independent so we would not be worried about that. We have finalised our inquiry into the public services card and that is subject to litigation at the moment. We have conducted a number of inquiries against public bodies in the last year, which have concluded and are all in our annual report. We are concluding inquiries into the HSE and into Children's Health Ireland in relation to their data protection activities. Public bodies know that there should not be any apprehension that the DPC will not act if it needs to.
Comment on this
Is there co-operation with the Six Counties and is there all-Ireland co-operation?
Comment on this
We operate very closely with our colleagues in the Information Commissioner's Office in London, Manchester and Belfast. At our conference in November, speakers came down from Belfast to speak about the all-Ireland aspect of data processing, North and South, because data transfers and flows between us, the UK and Northern Ireland are really important for the economy. We are very keen that continues but continues in a safe and proper manner.
Comment on this
I commend both regulators as exemplars. I appreciate the amount of work they do and the increasing level of duties that are falling upon them, particularly with the EU AI Act and the AI regulation Bill that is passing through the House at the moment.
Without referring to the Grok case, I want to get at something which is an issue of resourcing and if you have the technical expertise in-house to deal with emerging trends. The Grok issue became a big political furore but it was online and available for months beforehand. Until it reached the media landscape, I do not think any action had been taken. Do the offices have the technical expertise to be able look at those trends. X is not a small platform. This is a platform that many people know and many people were on but many people have come off the platform now. Do the regulators have the technical expertise to look at trends such as what emerged with Grok, without referring specifically to that case?
Comment on this
I might start on this difficult question of resources. I thank the Deputy for the question. I do not want to go into too much detail about it but my understanding is that emerged on 19 December. The first media reports came out on 3 January and we intervened on 5 January. That is all I will say on that.
On the question of whether we have sufficient technical in-house resources to scan and deal with those things, it is questionable. I am being very frank. It is very difficult to recruit technologists and it is a supply thing but it can also be a starting salary issue with regulators such as us. There is a real need for us to step up. When it comes to the AI Act and other Acts like that, it is something we will be making the case to Government on.
Comment on this
I absolutely agree with what Dr. Hogan said. It is very important. As an organisation, we have not quite completed our first tranche of growth. We are building up that capability to do the digital forensics and some of the monitoring. However, being able to recruit the right people with these technical skills within the normal public sector constraints - it is very welcome the AI and digital strategy that was published last week recognises that we need-----
Comment on this
I appreciate that. I am just conscious of time. It shows it is important to hire from industry as well and have industry expertise. Moving on, we naturally focus on the big platforms. Google is coming in here after the regulators. We have spoken about X and there is OpenAI etc. It is the smaller platforms - not even platforms - I am particularly worried about. We are looking at the likes of Candy AI which generates pornography online. How can the DPC and Coimisiún na Meán regulate these?
If we look at Google and X, we are able to access them because they are located here. For those smaller websites that could be located in Singapore, the US or anywhere, rather than just sending an email or a letter requesting them to take content down, are there any other powers available to the regulator in order to tackle these smaller websites and apps, in particular?
Comment on this
From the DPC's perspective, a lot of it depends on whether a company is mainly established in Ireland or not where we have responsibility across the EU. Regardless of that, if there is a company which is acting unlawfully in Ireland, we have powers under our legislation to act.
It is very difficult when companies are located in different jurisdictions. If it is within the European Economic Area, we have the ability to discuss with our colleagues in Europe about an action in a local member state. The Deputy is absolutely right. This is a real issue, particularly with companies that might have subsidiaries of subsidiaries of subsidiaries. There are also what are called Article 27 companies which are not based in the EU at all. That is certainly a problem.
Comment on this
I appreciate the answer is probably the same from Coimisiún na Meán. In relation to the dark web, is there any monitoring of the dark web, particularly when it comes to child abuse images and sexually generated images without people's consent, by either of the regulators?
Comment on this
We do not monitor the dark web but there is something - I cannot remember what it is called - and established mechanisms, particularly for child sex abuse material, where there are hashes of the material where they are shared. There is Hotline.ie and there is An Garda Síochána. There is a mechanism for trying to address that.
On the Deputy's earlier question about platforms, the European angle is very important. Whether it is for larger services like Snapchat or Roblox, which are based in the Netherlands but provide a lot of service to children in Ireland, they do for us what we do for the Irish-based platforms. I will give another example-----
Comment on this
There is a lot going on about pornography to make sure we and all of our counterparts across the EU are going after the smaller pornographic sites.
There is no point in the European Commission going after the big sites if people can just then access the small sites.
Comment on this
I thank the witnesses. What is the relationship between the witnesses' organisations? How do they work together? Are there areas of overlap or areas where there are potential gaps between their remits?
Comment on this
I might start with that. I thank the Deputy for the question. Last year, the DPC and Coimisiún na Meán signed a memorandum of understanding between our two organisations. It seeks to set out a way in which we will work within our regulatory functions where they overlap. Particularly, that happens in the area of child protection. There is a lot of synergy between the general data protection regulation, GDPR, the Digital Services Act and the Online Safety and Media Regulation Act when it comes to that. We have since done a number of joint statements or actions together. We have also produced a user guide with the Competition and Consumer Protection Commission, CCPC, and ComReg on where to go if somebody wants to make a complaint or wants to know which regulator to approach. It is very important that this is strengthened over time. We are also part of the digital regulators group with those two organisations I mentioned, and we meet regularly as a group to talk about how our mandates are overlapping and what to do in different areas. We are both applying European Union law so when we are doing that, we also have what is called a duty of sincere co-operation to co-operate. That is a duty under the EU treaties we have to abide by as well.
Comment on this
I will endorse everything Dr. Hogan said. I would also draw the Deputy's attention again to the AI and digital strategy that was published last week, which recognises the digital regulators group and has Government commitments to support us and also to explore whether some legislative change to facilitate even greater information sharing might be useful.
Comment on this
What would that look like? Mr. Godfrey and Dr. Hogan might touch on the gaps based on their experiences so far.
Comment on this
I would not say there are gaps. We both regulate some of the same companies. Sometimes the same behaviour engages obligations under the GDPR and the online safety framework and, to the extent permitted by the law, we will exchange views and publicly available information. There may be some restrictions on sharing information that has been gathered under statutory powers. Maybe something we can look at is whether that can be improved. By and large, however, the co-operation works extremely well.
Comment on this
While I have Mr. Godfrey, is the classification of high-risk categories something that might be looked at? Obviously, there is a lot up for consideration in terms of the EU simplification process, and some of that will involve recategorisation. Are there areas Mr. Godfrey would like included in the high-risk category that are not?
Comment on this
Under the AI Act, we have seen recently, obviously, the use of generative AI for nudification, but we can see other risks. People are using generative AI for AI companions or as AI therapists. There are some horror stories of it having severe and damaging effects on people's mental health. There are certain risks around the way people interact with generative AI that could potentially be addressed by broadening the categories of high-risk systems to include a wider range of chatbots and generative AI tools.
Comment on this
Is Mr. Godfrey making specific proposals in that regard, and if so, what?
Comment on this
To be frank, we do not have a very specific proposal about how that might be done. It is something that is in the European Commission's remit to change. Some kind of review to look at how the list of high-risk systems might be added to reflect some of the risks created by generative AI would be a good idea.
Comment on this
It is always important to review legislative frameworks as time develops. What we have been saying in our written submission and again today is that the sheer pace of generative AI has probably taken everyone by surprise over the last two years, and this is only accelerating. It is probably for the European legislature to look at that very question when the co-legislators are looking at the omnibuses this year and to reflect on that question of whether more needs to be done.
Comment on this
I thank everyone very much. This committee has previously expressed the frustration the public feel at the seeming lack of consequence and action given the powers that are there and not just Coco's Law, which is very clear around the distribution. I was very concerned about the word "deployment" being used again. It is clearly distribution; it is clearly the sharing of images. If someone requests an image from Grok and it produces an image, it produces it publicly and, therefore, shares it with a section of the population. So, it is not just under Coco's Law but also under the Child Trafficking and Pornography Act 1998, which, again, should probably be renamed the child sexual abuse material Act, which is what my colleague Senator Flynn tried to bring through the Oireachtas previously. It is very clear in relation to computer-generated abuse materials and corporate responsibility. There is a frustration and I do not know if the witnesses can comment. Is it their understanding that both of those Acts are being looked at in terms of investigations?
Mr. Godfrey mentioned previously that he believes there are slightly more powers under the online safety Act, under the Irish legislation. People are wondering why there is not a parallel investigation. Yes, it is being investigated under the Digital Services Act at European level. However, under Part 88 of our Act, there is an obligation whereby if someone breaches the online safety code, that is in itself something that merits investigation. There is a clear breach of our online safety code in terms of the obligation to protect the safety and security of privacy online. Again, this is not an inadvertent consequence. The nudification feature is an advertised functionality of Grok. In that context, why is there not an investigation under our national law in parallel with the EU piece? If Mr. Godfrey can comment, are both of those relevant items of legislation part of the criminal aspect?
I should put all my questions, Chair, because I know I will not get back in.
Comment on this
I will put them very briefly. In terms of data protection, the public services card has been mentioned. We know that bank of images has been deemed to be unlawful for other uses. When it comes to age verification, is there not a kind of tension there because that was the coimisiún's previous findings of that? Has the coimisiún been engaging with the fact the AI omnibus is not moving towards tighter regulation but is explicitly looking to exclude or dilute data protection in relation to the training of AI - that is one of the functions and legitimate uses it is proposing - and it is proposing to dilute special categories of data protection specifically for AI training?
Comment on this
Very briefly, again, I do not want to get into too much detail about the investigations, but there are law enforcement issues being looked at by An Garda Síochána. There are data protection issues being investigated by the DPC. Under the online safety framework, the most appropriate tool that is most engaged is the DSA, and that is the one that we in the coimisiún have been using. The online safety code is largely about video content and for video-sharing platforms. We looked at what parts of the online safety framework were most relevant, and the DSA seemed to be the most relevant one and the one where action could best be taken, and we-----
Comment on this
However, the coimisiún could do both. Can I just confirm that it could be doing both?
Comment on this
We are associated with the European Commission investigation, so we and the European Commission are putting our resources into looking at the breaches of the Digital Services Act. It does not appear to us that there was a breach of the online safety code. We have to look at what exactly is in that code. That code is largely to do with video content that is being shared, not images.
Comment on this
Unfortunately, the public services card issue is in the High Court next month, so I cannot comment on it.
Comment on this
I mean more in terms of the image bank and the inappropriate use of the images.
Comment on this
The purposes of any processing have to be for that particular process. It cannot be used for other processes. That is the general principle from the GDPR, if I can put it like that. If new products and services are coming out, we will certainly be engaging with the relevant Government agency to review them as they go forward.
In relation to the Senator's second question about the AI omnibus and the proposal on AI, we would be satisfied with it insofar as it meets the opinion of the European Data Protection Board, EDPB, of December 2024 in terms of the training of AI. The EDPB issued a view on the general omnibus GDPR and AI at its meeting last month and I would be happy to provide a copy of that to the Senator.
Comment on this
Is it not the case that it has expressed concern?
Comment on this
It has expressed concern with the GDPR aspects of it and particularly the definition of personal data, as well as other aspects. Other aspects have been welcomed.
Comment on this
I have been meeting parents who are very concerned about harmful content and recommender systems feeding harmful content to their children and teenagers. They are worried about the videos they are seeing, whether these are the latest nudification images we are all aware of or awful videos like those from the Charlie Kirk assassination last year. In terms of that profiling and targeting of audiences by platforms using algorithms, how are the DPC and Coimisiún na Meán able to assess whether that profiling by using algorithms is contravening any of the GDPR legislation or other legislation the two organisations are responsible for?
Comment on this
I thank the Senator for the question. Where personal data is processed, that comes within the GDPR, of course. Again, this is something we review. If there is evidence of personal data being profiled and of that profile being connected with a certain form of processing that is unlawful and unfair, that would certainly be a matter coming under the GDPR. We looked at this in an inquiry that concluded in 2022, not specifically but in relation to the types of advertising that can come out. There are different types of advertising - specific, targeted, contextual and behavioural advertising. The EDPB has produced an opinion on the particular requirements when it comes to behavioural advertising. The GDPR deals with high-level principles, so it is always fact-based. That is the context. Each different situation has to be looked at.
Comment on this
I thank Dr. Hogan. This is complex, so forgive me if my questions are a little bit blunt. In terms of the algorithms, I noted from earlier contributions references were made to dual aspects of the role, where in some instances, the DPC is reacting to complaints made to it and in other instances it is engaging with the platforms and helping them to assess whether a product change they are making is going to be lawful or breaches the thresholds. Does the DPC have any insight into or role concerning how AI is being deployed in algorithms and how they are using AI to profile? I ask this given Mark Zuckerberg's testimony last week in the US that age verification is very difficult. He would accept that a huge proportion of the population is not telling the truth when it comes to age verification. We know that our children and teens are on these platforms and perhaps are seeing content that is not appropriate. It is difficult to implement safety by design if the cohort it is trying to protect are not verifying their age correctly. In terms of the algorithms, is there any role for the DPC or does it have any insight into this issue?
Comment on this
We have a potential role, but it is more in terms of the nature of personal data processing rather than the recommender system leading to an online content matter. We would be more on the upstream element of things, if you like.
Comment on this
I might come in here. I do not think we should allow platforms to get away with saying it is the responsibility of children to honestly say their age. That is an absolute cop-out, if I may say so. Under the Digital Services Act, all platforms, not just the very large ones, have an obligation to protect the safety, security and privacy of children. We have some detailed expectations about how they should do that, which would include measures about recommender systems. Those systems must not produce toxic feeds, recommend age-inappropriate content or encourage addictive behaviour. All those things are expectations that are now are set for platforms. If they do not meet those expectations, it is very likely that they are not meeting their obligation to protect the privacy and security of minors. For age verification and age assurance, platforms do not have to offer those dangerous features to anybody, but if they do, then they have to make sure it is only adults who are getting them. It is the platforms' responsibility to use a privacy-protecting, effective form of age assurance to make sure children are not exposed to those dangerous features.
Comment on this
Is Coimisiún na Meán investigating anything concerning those toxic feeds? Is anything going on in this regard?
Comment on this
Yes. The European Commission has a couple of investigations under the Digital Services Act that we are working on with it. Those are into TikTok, and Meta in respect of Facebook and Instagram. Those investigations are looking at the measures those platforms have put in place to ensure the safety, security and privacy of children using the services. The Commission announced preliminary findings in relation to TikTok two weeks ago, where it was concerned about some of those addictive design features. We are very much engaged on those issues.
Comment on this
I thank the organisations in general for their work. I am conscious they are acting as regulators in a very fast-moving space. Like all of us, they are trying to keep up with what is happening with some of the technology. The role of our committee is to make recommendations in this era of AI in terms of how Ireland can both avail of the opportunities and deal with a lot of the challenges we are going to face.
I might start with the DPC. For data breaches, it has levied something in the order of about €4 billion in fines. I think I am correct in saying only about €20 million has been collected. I appreciate that the DPC is being challenged in the courts and this is not a criticism. Similarly, under the Online Safety and Media Regulation Act 2022, in terms of the power to levy fines, I wonder whether we should move to recommend providing additional powers for the DPC and Coimisiún na Meán. As other regulators do, they could hold individuals to account and hold individual directors of companies liable. I do not know if the witnesses share my view that increasingly some of these companies regard the fines as a business cost, rather than as a deterrent necessarily or an incentive to do the right thing. I will start with Dr. Hogan.
Comment on this
Yes. I thank the Cathaoirleach and appreciate that. Yes, we have levied over €4 billion in fines. Those fines are being appealed in each instance, apart from two cases, for large platforms. We are being challenged in all the other cases. For public sector inquiries, there is only one challenge at the moment. It concerns the public services card. I am very happy to say most public bodies accept our decisions, pay the fines and take the corrective actions they are asked to take.
Not only are we are being litigated against under statutory appeal, which is provided for in the Data Protection Act 2018, but we are concurrently being judicially reviewed in each of those decisions. That is a difficulty. We want to have an ecosystem where companies come into Europe, avail of the European market, interact with the regulators and play by the rules, and then when they are found not to be correct, they get on with making the changes that need to be made.
Comment on this
Regulators operate in other sectors such as food, drink and everything else. Why is there not the same challenge as in a lot of those other sectors? Does Dr. Hogan think it is due to the potential impact of holding individuals liable?
Comment on this
There is no doubt there is a reputational risk for organisations if they are found to be in breach of any law, including the GDPR. Also, historically a lot of companies would have prided themselves on being very privacy friendly and it is not a good place to be, to be found in breach of that over and over. These are considerations for companies when they bring products and services to market and how they react to recommendations from regulators. You would probably have to ask those companies themselves how they view the ecosystem and the regulatory-----
Comment on this
Roughly, in terms of all those judicial reviews and challenges, ballpark, what sort of legal costs has the DPC paid during the period of 2018 to date?
Comment on this
Most of the cases have been queued up behind what is called the WhatsApp and European Data Protection Board court case which was decided two weeks ago. That is to do with the fines as well. Our legal fees are probably in the future, from here. We are up against very well resourced legal teams, it I could put it like that.
Comment on this
The question is: does the State want to field similar teams when defending inquiries? That is a question which we are doing-----
Comment on this
Yes, I think they should be defended. There will be some decisions that are overturned by the courts. That is just the natural run of things. By and large we feel the inquiries are defendable. They were taken over a number of years. The DPC gets criticised for taking inquiry decisions over a number of years but we do that because we are very careful and give fair procedural rights to the parties. This is something that will work its way through the system but it goes back to the question about support for regulators. We are not standing in a neutral field in terms of our ability to regulate to the extent we want to.
Comment on this
I am afraid we have reached the conclusion of the discussions which have been quite enlightening. I thank the witnesses for their work. They have outlined some of the challenges they face and we welcome the recommendations in their opening statements. Our committee always welcomes evidence based, well informed recommendations including from anybody who may be watching the committee meeting proceedings. If they want to email, they can email us at ai@oireachtas.ie. I again thank the witnesses sincerely for their work.
Comment on this
We are back for the second part of our discussion about issues around AI, truth and democracy. I welcome representatives from Google. I am very appreciative that they are in attendance. I think the committee will be aware that we extended invitations to a number of other companies. OpenAI indicated to me that, because of difficulties related to it being still a small operation, representatives were not in a position to attend. Microsoft has declined for the moment the invitation to attend. Given that we mostly use Microsoft products here in Leinster House, it is a little concerning that representatives of the company would not appear before the committee. I do not think it will surprise members that X ignored the invitation to attend. We are therefore grateful to Google coming along. We are joined by Ms Miriam Estrin, who is the senior policy manager, and Mr. Lorcan O'Flaherty, who is government affairs and public policy manager.
I now invite Mr. O'Flaherty to deliver the public statement on behalf of Google.
Comment on this
I thank the Cathaoirleach and members of the committee for inviting us to speak to them on the topics of AI, truth and democracy, and recent issues around images, deepfake and consent. I work with Google Ireland as government affairs and public policy manager. I am joined by my colleague, Ms Estrin, who specialises in content responsibility and regulation. We are very grateful for the opportunity to be a part of this conversation.
Google's mission is to organise the world's information and make it universally accessible and useful. Generative AI has the ability to benefit everyone by advancing this aim, boosting productivity and supplementing creativity, expression and opportunity. Google is an "AI-first" company and we have been working on responsible AI development for more than 20 years. We believe our approach to AI must be both bold in terms of innovation and responsible from the start. To us that means developing AI in a way that maximises the positive benefits to society while addressing the risks and challenges.
Advances in AI will bring immense opportunities and have the potential to transform the lives of everyone. The scientific innovations made possible by AI are creating a generational technological shift. For example, Google's advances in predicting protein structures using AI has saved at least 400 million years of research, and today Google's AI technology is helping 3 million scientists in 190 countries to accelerate progress against diseases like malaria and cancer. Our AI projects are driving positive change in areas including health, accessibility, science and economic impact.
Transformative technology requires exceptional care and must be developed and used responsibly. We have long said that AI is too important not to regulate and too important not to regulate well. Since then, we have continued to evolve our practices, conducting industry-leading research on AI impacts and risk management, assessing proposals for new AI research and applications to ensure they align with our principles, and publishing nearly 200 research papers to support and develop responsible industry standards.
While AI presents remarkable opportunities, we recognise concerns about how these systems might be used by bad actors to perpetuate online harms, create new risks or amplify current societal challenges like disinformation. As a leader in AI, Google is committed to developing AI safely and responsibly to ensure that people benefit and are protected from risk. Trust is the foundation for adoption and innovation.
When it comes to AI safety, we rigorously test our models and infrastructure at every layer of the stack and at each stage of development, combining the best of AI with our world-class teams of safety experts. We publish a Responsible AI Progress Report and detailed model cards explaining how our AI models are designed and evaluated for safety. Our end-to-end approach enables advanced AI experiences that put safety first. This is especially applicable to recent issues around images, deepfakes and consent. Google strictly prohibits the creation of non-consensual intimate imagery on Gemini, and our tools have built-in technical safeguards to block the generation of sexually explicit or harmful content. We continuously evaluate our systems for safety and build tools to improve them. This work is supported by Google’s safety engineering centre, GSEC, in Dublin, which is a hub for our experts working to tackle the spread of illegal and harmful content, and a place where we collaborate and can share this work with policymakers, researchers and regulators.
We also want to empower users with tools and information to make informed decisions about the content they encounter online. That is why we developed the cutting-edge SynthID technology to watermark content generated by Google’s AI products, taken a leadership role in the industry Coalition for Content Provenance and Authenticity, C2PA, and provide tools for users to evaluate the accuracy of information.
As previous meetings of this committee have highlighted, technology companies have a clear responsibility to support democracy. We remain committed to providing timely and authoritative information to help voters understand, navigate and participate in democratic processes. We have strict policies prohibiting election-related abuse on our products and services, such as content regarding candidate eligibility or voter suppression. We have multiple teams in place to rapidly address emerging risks to the electoral process, including Google’s threat analysis group, which helps identify and tackle emerging threats and co-ordinated influence operations.
Finally, Google provides AI literacy resources and training that empower students, teachers and families to use AI effectively, safely and responsibly. In Ireland, Google.org, the philanthropic arm of Google, supports Barnardos to drive AI literacy, digital literacy and online safety training in schools around Ireland, and that has reached over 100,000 students. We support the ADAPT Centre and its AI Literacy in the Classroom initiative, which are designed to help post-primary educators boost their AI literacy and help them empower their students to use AI critically. We also fund the Insight Scholarship programme, which supports third level students from under-represented and socioeconomically-disadvantaged backgrounds and communities, with a particular focus on students studying AI and digital safety courses.
We find ourselves at a critical juncture in the history of the Internet, and for Ireland as it looks to seize the transformative opportunities of AI. We recognise that our products have an important role to play in contributing to a responsible digital ecosystem. We are committed to meeting this moment by continuing to work together with governments, and civil society, and to make information available to our billions of users, promoting safety and reliability, and preserving freedom of expression. We appreciate the Chairman convening this important hearing and we look forward to answering any questions.
Comment on this
I thank Mr. O'Flaherty. As each member will be aware, there is a speaking rota and they have four minutes each in this round. I call Senator Dee Ryan.
Comment on this
I thank the delegation coming in today to discuss this matter. Where does Google use SynthID technology? Where is the threat analysis group located? How many people are involved? How is it resourced? What does the group focus on? Mr. O'Flaherty said that electoral risk is part of the group's work. What else does it look at? What measures does it engage in? What is it seeing there?
Comment on this
Let me start by answering the question on SynthID. I appreciate the Senator raising this issue as it helps us address challenges that users come to us and ask us about all the time, which is how can we know the information we are seeing online is trustworthy. SynthID is one of the technologies that we use to help users understand and know how content was created, and whether it was made with Google's own AI tools. SynthID is cutting-edge technology. Google has led industry in the development of such a technology. It is an invisible watermark. It has a strength of being robust. What do I mean by that? Unlike a traditional watermark, which can easily be cropped, SynthID is an invisible watermark embedded into the very pixels of a photo. If a bad actor tries to crop out it, SynthID remains detectable. That is true if someone tries to recolour it, flip it around or use other techniques to defeat our systems - SynthID is robust and remains.
On top of that, we have given users the ability to know whether a piece of content has been marked with SynthID. We have a new detector tool in place that lets them verify and check whether the content was made with SynthID.
Comment on this
Please tell me more about the threat analysis group.
Comment on this
Google's threat analysis group helps to identify and monitor any threats in the electoral process. They would come from State-backed actors or groups across the world. We monitor about 270 of those on an active basis to see what kind of activities they are engaging with.
Comment on this
Yes, known groups. To be clear, we are very transparent. We regularly publish reports to update on our findings and what we are seeing across electoral threats from all these groups. Those reports are all available online.
Comment on this
Some of it is based in Ireland and other parts elsewhere in the world. It is a global presence. We have a very strong trust and safety team in Ireland. It is one of our largest presences across the globe. Those teams work across the globe on a sunsetting basis or following the sun.
Comment on this
When what appear to be co-ordinated efforts to influence are detected, what actions are taken by Google?
Comment on this
Very serious actions, indeed. We report those to authorities immediately.
Comment on this
In Ireland, has Google previously reported any instances to the Irish authorities?
Comment on this
In relation to the threat analysis group, I am not 100% sure. We report them to the law enforcement and security agencies in the countries involved. It would be the commission and the Garda Síochána, depending on the offence. If we pick up serious and immediate threats, we absolutely would report those. We publish general findings. For instance, we are talking about AI today. We publish findings about how these groups are using general AI in their activities. We see trends in that regard and we constantly map those trends. When we see threats in one country or groups of countries, we report those to the authorities.
Comment on this
I thank the witnesses for attending. I want to acknowledge that Google has taken a leap of faith by its representatives coming here and other companies have not. I also acknowledge, as Google is in my constituency apart from anything else, that the investment it has made in Ireland is significant, worth meriting and not to be derided. Some 5,000 people in Ireland work for Google. Google has the receipts to prove its investment in community, particularly under Teresa Weafer. I see that in the local schools and the local employment task force it supports.
On generative AI, at recent meetings we had in attendance Dr. Culloty of Dublin City University and Dr. Birhane of Trinity College Dublin. Dr. Culloty said: "Regarding truth, generative AI is fundamentally unreliable. It does not aim at factual accuracy. Instead, it offers outputs that are statistically plausible based on its training data." What is the response of Google?
Comment on this
Google's entire mission is about making information useful for people and that applies just as much to search as it does to our generative AI products. We rigorously design and test them to work on providing users with answers that are reliable, grounded, unbiased and accurate. I think what was being pointed out there is that there is a challenge in all of the leading AI models around issues like hallucination. That is a challenge across models and across industry. We are very much investing in research and testing to make sure that our answers are as accurate and factual as possible. In fact, we have developed an industry benchmark - a facts-grounding benchmark - to measure how our models are improving on that metric over time.
Comment on this
Representatives of the Citizens Information Board have appeared before this committee. The witnesses may be familiar with the board. Basically, it is a website that, in plain English terms, disseminates Government information in a plain and objective way. The witnesses from the Citizens Information Board outlined that one of the challenges they face is a huge reduction in their traffic because the AI summaries take some of the information from their website and information from other sources and jumble up the information and users are not getting the level of accuracy. However, the users are confident that they are getting it, or at least that is what the board had deduced because people are not going to its website.
I asked them whether they could work with the likes of Google or whoever. Is that something Google has done in other jurisdictions? Is it something that could be deployed in Ireland?
Comment on this
Yes, absolutely. I know that Mr. O'Flaherty met with exactly that team. I will start by talking about AI overviews in general and why we have developed the technology, and then I can pass it over. What we have seen is that users are coming to search asking more complex multi-part questions than ever before. For instance: "I have come to the Oireachtas, I would like to know the history of Leinster House and could you tell me where I could get a good sandwich after the hearing?" In the past that would have been three tabs open on my Chrome to ask three different searches. What AI overviews is now able to do is fan out against each part of that question and find the most reliable and highly ranked Google search-----
Comment on this
I do not mean to interrupt but I only have 30 seconds. Would Google engage with the Citizens' Information-----
Comment on this
I can jump in here. Absolutely. We have engaged with them. Authoritative information is very important to our business and that is what we point users towards. We have engaged with the Citizens' Information Board. We met with them earlier this month and we talked about the specific issues that they have. We will work with them through that. It is a very important body in that regard.
Comment on this
I am sorry for rushing but I want to ask one final question. Coimisiún na Meán was before us and the head of Coimisiún na Meán recommended that, in the context of the AI Act, we make it a prohibited practice to deploy AI systems that are capable of producing intimate imagery of real people without their consent or which are capable of producing child sex abuse material. Is this something that Google as a company has considered? Is it under consideration in the context of Google's engagements in Brussels? What is Google's position on it?
Comment on this
Briefly, yes absolutely we have seen those proposals and support that direction.
Comment on this
I thank the witnesses for being here today. I too want to talk about the AI overviews. I have concerns around that mix Deputy Geoghegan mentioned, where what we know to be proven, solid and fact-checked information like that which emanates from the Citizens' Information Board being mixed in with information that we now know is not as accurate. The board has concerns about that, which its representatives raised here in committee. Obviously Google is where people turn to. We know it is the go-to place for people to find what they believe to be accurate information. Apart from talking to us about the actual functionality, which I appreciate is important, what is Google doing to address the issue of misinformation?
I will cite another example. I spoke recently with a group who are supporting people in pregnancy loss. They had a specific example of how reduced foetal movement as a search term was providing quite inaccurate information to people. They have a paper on this and I believe they have actually engaged with Google with good result, which is great, but my point is to ask why people would have to go to that length for such sensitive and problematic information being served to users.
Comment on this
Let me try to answer each point briefly. On the first question, AI overviews will not trigger for every query. We design the system to trigger where we feel confident that we can match the user's query with the top-ranked results. We provide users with direct links to websites. We are finding that they are clicking through to those websites and spending time on those pages to evaluate results. On-----
Comment on this
Again, I am not so worried about the functionality; it is more about what Google is doing to address what we know is a problem of misinformation being provided to people.
Comment on this
Right. In the case of AI overviews it is using that 25 years of experience in search ranking and authoritativeness. I think I understand the Deputy's question on the medical use cases. It is a perfect example of what we mean by Google's ethos to be bold and responsible. The responsibility here is making sure that we are connecting people with high-quality medical information and that we do not give them medical information that conflicts with established scientific or medical consensus. At the same time we have this incredible opportunity to use our AI systems to work with-----
Comment on this
I will stop Ms Estrin there because I have another question. On the results of that abstract on pregnancy loss - I am happy to share this with the committee - half of the search results contain misinformation driven by commercial US web pages. The most common misinformation targets were advice to conduct a kick count, claims that a set number of kicks in a timeframe indicates the baby is well, and suggestions for ways to stimulate movements, appearing in 49.5%, 43.2% and 25% of the results. I appreciate what Ms Estrin is saying but I am giving her a clear example of where that did not happen.
The second question I have is around the digital omnibus. As Mr. O'Flaherty said in his statement, "We have long said that AI is too important not to regulate and too important not to regulate well". Does Mr. O'Flaherty believe that the omnibus packages that are currently making their way through the legislative process are problematic in terms of pulling back legislation?
Has Google lobbied in support of the omnibus packages? Does Google believe they are going to compromise our regulatory framework here in Europe?
Comment on this
I thank the Deputy for the question. We support the simplification exercise that has brought forward-----
Comment on this
We would respectfully disagree there.
Comment on this
I would call it deregulation.
Comment on this
We think it is simplification and does not mean deregulation. We do support the ambitions of the digital omnibus. We are public and transparent in saying that, and in working with institutions and governments throughout Europe, absolutely. We believe in simple and clear regulation and that does not mean less safe, but simple. We have had over 100 pieces of tech-focused regulation in the past seven to eight years out of Europe. What the digital omnibus tries to do is make that more streamlined, more simple, more effective and more legally certain for businesses-----
Comment on this
I have had people saying to me in the same sentence - this is not from industry; it is from this House - that simplification is not deregulation but simplification is about relieving the regulatory burden. When we are all dealing with the online harms that are being unleashed on society I find it hard to believe that we are over-regulated in this space. I am afraid that it just does not ring true with Mr. O'Flaherty saying, "We have long said that AI is too important not to regulate and too important not to regulate well".
Comment on this
We have supported the objectives of the AI Act from the outset. We do believe in legal certainty here, and that is what this is about.
Comment on this
In his opening statement Mr. O'Flaherty said, "Google strictly prohibits the creation of non-consensual intimate imagery on Gemini". Can he confirm that it is currently technically impossible to generate such content using Google's systems, or is it restricted by policy and safeguards?
Comment on this
We do not allow technically the possibility to generate non-consensual intimate images, NCII, on our platforms or on our AI tools. A layer above that are policies designed to catch this where a system may not be operating to full effect. We do not allow it technically and we have policies across our products to catch any kind of breaches of our policies generally as well.
Comment on this
So it is restricted technically. Has Google any data on failure rates in those restrictions?
Comment on this
Failure rates on the restrictions, the policy or the safeguards? Does Mr. O'Flaherty have any examples of people getting past that?
Comment on this
With regard to examples, we publish reports on the effectiveness of all our tools generally. For instance, in the second half of last year Google Play took action on about 2,000 apps that were in violation of our sexual abuse policies. We publish all of those types of information.
Comment on this
Does Google publish the actual numbers on what is blocked and-----
Comment on this
Does Google have numbers on successful bypasses or people circumventing the systems?
Comment on this
Of people being able to use Google's systems to actually generate these images.
Comment on this
The model itself is designed to do things in a certain way. We have very strong guardrails in place for adult users and kids as well. That would be at a technical level, if you put it that way. Afterwards we have policies across all the things the Senator mentioned, such as sexual abuse policies, NCII and harmful harassment and bullying. They would be designed for other products like YouTube, for example, to catch any breaches of our policies there. We publish our enforcement of policies related to the Digital Services Act as well.
Comment on this
Okay. I will move on. The witness mentioned collaboration with policymakers and regulators. Will Mr. O'Flaherty specify what data on access and transparency Google is currently providing to Irish regulators?
Comment on this
Absolutely. As I mentioned in the opening statement, our Google safety engineering centre is here. This is a regional hub. It was the second ever such office established by Google. It is precisely for that point. It is for our experts who work in the area of content to collaborate together, publish reports and publish research. It is also to engage with policymakers such as this committee and regulators across Europe, not just in Dublin, but naturally it is based here. We host events. We are very open there and we have policymakers and regulators in to collaborate on all these important topics.
Comment on this
Do regulators have that access to Internet safety metrics, incident reports, evaluations and models, and that sort of stuff?
Comment on this
Under the Digital Services Act, we are required to submit a systemic risk assessment to our regulators at Coimisiún na Meán and at the European Commission. We publish a version of that report to the public but we have more in-depth conversations with the regulators on those systemic risks.
Comment on this
Has Google ever declined a request by the regulator for information?
Comment on this
I thank the witnesses for their opening statements. They mentioned supporting democracy. How does the training of Google's AI-powered tools prevent built-in political bias?
Comment on this
We develop, train and test Gemini in a way to make sure that when users ask queries related to elections or politics, it provides a balanced, unbiased perspective. We rigorously test the datasets to make sure they are representative. We throw a bunch of queries at Gemini before it is ever released to the public, which we call adversarial testing, to see how it performs under real-world conditions. Once it is released, we continue to evaluate how those systems are working in practice. We always work to improve upon the results.
Comment on this
We are very conscious of the role of AI in this regard. As a platform, we have specific policies and prohibited-use cases related to elections.
Comment on this
In relation to the safety testing Google conducts on AI models, has any kind of malware been found circulating in Ireland that could cause abuse to AI systems and, if so, how can that be addressed to protect users?
Comment on this
I have not seen anything specifically in terms of malware in Ireland but I can check that. This is what we are testing for generally all the time. We have what we call red teams, including teams based in Dublin, that are specifically charged with this task. Adversarial testing happens not only before a product launches but also when it is on the market. The point of adversarial testing is to try to identify vulnerabilities bad actors may exploit and any chinks in the armour on which we need to improve. We are constantly doing that with all our products, including the AI products.
Comment on this
I do not know about Ireland-specific cases but our threat intelligence group, which was mentioned, published a report on the increasing use of co-ordinated state behaviour around malware phishing attempts. Google studies exactly those threats. We see them happening in the real world and we work to disrupt them.
Comment on this
Looking forward to the next five to 10 years, where do the witnesses see threats developing and how does that assessment impact training of staff, for example?
Comment on this
Bad actors are always trying to get ahead of what is currently there. Our whole purpose is to stay ahead of bad actors in this space. AI is a technology that is emerging in a fast-paced way. We are constantly investing in it and in our teams. Our company has been around for a while and we have been here for 25 years. Our trust and safety teams have been in place and heavily resourced for more than 20 years. We have long experience of this. The threats themselves are not new but the ways in which they are being expressed are new. It is about staying ahead of all that.
Comment on this
On the spread of disinformation, Google has a threat analysis group to tackle that. How is the group resourced? Is there a diversity within the group staffing in terms of gender and ethnicity?
Comment on this
Yes, absolutely. This effort is global in nature. We are following threats from the threat action groups in 50 countries. I have mentioned that there are many state-backed actors. Our companies are known for their diversity and that is respected within the make-up of this group.
Comment on this
I thank the witnesses for attending and for the work they are doing with Barnardos and the ADAPT programme to educate and empower students. We can talk about regulation all day but that aspect is really important.
I have two questions. It is great that Gemini does not allow the creation of non-consensual imagery but I am conscious that Google is trying to stay competitive. While the whole country was outraged by what Grok could do, it was the most downloaded app here for a number of weeks. We have heard that other AI apps are now learning how to talk dirty or create added imagery. Do the witnesses have a sense of the number of requests on Gemini for this type of thing? I know it is not allowed but what is the level of demand on Gemini for that kind of content?
Comment on this
As the Deputy said, we do not allow it. I know this issue is a strong area of interest for her. I do not have any statistics on attempts but the product is designed to block any kind of queries in that regard. Child sexual abuse material, CSAM, which Ms Estrin deals with a lot, is the most egregious side of this. We would report and block users who input those sorts of prompts. I do not have statistics on how many times Gemini is asked that question but it would block a standard query and would not allow it to be generated. Where we see anything on the serious scale of actual harm, we would report it. In the case of CSAM, for instance, we would report to the authorities and suspend the user.
Comment on this
To clarify, are requests for CSAM reported?
Comment on this
Yes. CSAM is at the top of the scale in terms of the most egregious abuses. We take a very strong approach when it comes to that.
Comment on this
That is great. My next question is in relation to the Google Play store. We have talked about how Coimisiún na Meán has scope to regulate the very large video-sharing platforms. We also discussed smaller companies that do not meet that threshold or are not based here but which have products that can be downloaded from an app store. In engagements with social media companies, they often push back to the app stores for age verification. What is the witnesses' view of Google Play taking accountability for age verification in order to protect children against the smaller apps or bigger platforms like Discord that are not based here? We were talking about Candy AI and apps like that earlier. It is hard for us to reach those companies when they are not based in Europe, yet the apps might be available for download on Google Play.
Comment on this
Is the Deputy asking about our approach to age verification generally?
Comment on this
We support age assurance. We have technical feasibility today to ensure age assurance. We have built a product to do that in a privacy-preserving, safe and seamless way. Our approach here is based on our age assurance technology. We use a number of signals we get through our products to indicate users' age and we apply certain safeguards. If we cannot affirmatively establish that a user is over 18, we will automatically apply the safeguards that apply to younger users on that product, whether an AI product or otherwise, until the user can prove he or she is over the age of 18 by use of an ID or something similar. We think that is the most safety-preserving approach. We do not think the app store approach is the way to go on this, primarily because these apps can be accessed not just through an app store but also online. We consider the best way of preserving privacy is at the source of the content.
Comment on this
Google provides age assurance on its own products but if the Google Play store is facilitating a child to download Candy AI, for example, does Google have no responsibility for that?
Comment on this
We do have responsibility. We absolutely are responsible for what is on the Google Play store. We have our own policies as to what is compliant. If an app is in breach of our policies, it will not be on the Google Play store in the first instance. All the apps are age rated. There is an international independent age-rating body from which we take guidance on rating. We follow those international principles.
Comment on this
I thank the witnesses for appearing at the committee. I presume they will not accept this but my perception is that Google has become worse at doing the basic thing it traditionally has done, which is enabling people to look for and find information. What happens now with most searches on Google is that users get some AI-generated stuff. The purpose of this material is not to tell the truth; that is not what it aims to do. Large language models, LLMs, are simply predicting the most likely next word. The whole thing is a hallucination. Those hallucinations are often accurate but, equally, they are often not accurate.
Does Ms Estrin agree that, effectively, Google is participating in what is being termed the "enshittification" of the Internet?
Comment on this
Let me take the Deputy's question on AI overviews, which is how we bring AI into search. It works differently from traditional LLMs. It is trained and grounded on the core search ranking feature, that is, our 25 years of experience in elevating high-quality content to users. When users come to ask these increasingly complex questions, we provide them in a summary. We provide the users with links to those sites and what are finding, in fact, is that users really like this tool and find that it is valuable so that when they click over to the websites, it is a high-quality click. We know that because they are spending more time on that site and not clicking back right away. We are seeing improvements and bringing our tools to where users are.
Comment on this
What about the recommendation that you use non-toxic glue to stick cheese on a pizza?
Comment on this
We have certainly seen those headlines as well. In reality, those kinds of queries and results are very rare but certainly, when we see them, we work hard to make changes and address it not just at the level of that query but at a more systemic level.
Comment on this
Or the invention of one kilotomato, a new unit of measurement for 1,000 km.
Comment on this
That is another good example of a rare query but one, that when it comes up, we work to correct it.
Comment on this
Or there is the suggestion that recommends eating at least one small rock per day for minerals.
Comment on this
Similarly. What the Deputy is pointing out is that there are some sites for comedy or forums for farce that can pull from these and that is not the result we would want to see again. It is very rare and when we see it, we work to correct it.
Comment on this
There was a paper brought out recently by Google researchers, apparently, which has concluded that generative AI is ruining vast swathes of the Internet with fake content and the distinction between what is real and fake is increasingly blurred. Does Ms Estrin accept that Google is engaged in this process? It recently launched a video-generating AI where you can generate, from a prompt, seven or eight seconds of video. Does Ms Estrin accept that this is undermining the distinction between truth and reality and is assisting in the proliferation of fake news, the spread of hate and so on?
Comment on this
We think these are incredibly valuable tools. I am not familiar with that paper. I have read a lot of the Google research papers and that sounds like an interesting one. Google has many years of experience in addressing low-quality spam content on search on YouTube and across platforms. What this new generation of AI technology can bring is immense creativity and incredible new pieces of content. It can also bring the other kind and, for that, we will be relying on our many years of experience here.
Comment on this
I thank Ms Estrin.
Comment on this
I thank the witnesses for coming here this morning. One of my first questions is around how Google deals with fake accounts and scams. We have seen that scams are up 120% online. Just yesterday, a report was produced by An Garda Síochána. On X, there are something like 498 million fake accounts worldwide. How do you deal with those? What is Google's reaction time? How does it deal with this and what is the time involved?
Comment on this
I thank the Deputy. What he is referring to is critically important and we have multiple layers of defence available to address scam content. This is the company that prevents 99% of phishing and malware emails from showing up in your Gmail and we are bringing that knowledge to this new kind of attack. We agree; we have seen the rise in public figure impersonation ads to promote spams. What we did in that instance was pull 100 experts from around Google to study the problem and propose countermeasures. I can bring the Deputy some stats on that. We permanently suspended over 700,000 offending accounts related to this exact abuse area and we saw, as a result, a 90% drop in this kind of abuse area.
Comment on this
Honestly, how trustworthy does Ms Estrin think AI is?
Comment on this
It gets to the heart of the mission that we design our systems to be accurate, helpful and useful. That remains the North Star of Google and we think we have got the leading models and technology in that regard.
Comment on this
Ms Estrin mentioned Google had a benchmark. What does it set that benchmark against?
Comment on this
I would be very happy to provide the Deputy with the technical details of the benchmark. My understanding is that it runs a bunch of prompts not just against Google models but industry models. It tests it for factual accuracy but also responsiveness and the quality and thoroughness of the response. That is the Google benchmark. There are third-party benchmarks as well that take similar approaches.
Comment on this
What are Google's standards on the general data protection regulation, GDPR?
Comment on this
In what respect? We support GDPR and we are compliant with the law in that regard, if that answers the Deputy's question.
Comment on this
I thank the witnesses for being here today. Similar to the Cathaoirleach, I want to note for the record that Microsoft, OpenAI and X were invited here and have not turned up, particularly Microsoft. We are using Microsoft in the Houses of the Oireachtas and it is quite disappointing that it has not turned up here today. That should be noted.
One thing Google is doing and needs to be commended on is the responsible AI progress report. I note as well that Gemini does block the creation of non-consensual images. However, does Google support independent audits with public summaries of Gemini's failure rates, where some non-consensual material has been created or the prompts have been submitted to Gemini? Would Google be open to sharing this information and data with EU regulators?
Comment on this
I will start. My understanding is that the systems would be governed under the governance frameworks set up by the AI Act. Depending on the risk classification, it would be subject to different kinds of risk assessments and reporting and to the regulators that will oversee the AI Act. We will support that process.
Comment on this
Separately, looking at what is mentioned in various legislation, as partners in trying to tackle this type of material, would Google not be forthcoming with information and sharing that information, rather than just sharing information that is required of it under legislation?
Comment on this
I thank the Deputy for the question and the opportunity to expand. We support a wide range of reporting on our models at every level of the technical stack and for a variety of audiences, not just the responsible AI progress report the Deputy mentioned but more technical reports such as model cards and technical research. That is just in addition to what we would provide to regulators.
Comment on this
I thank Ms Estrin. I want to touch on SynthID. She gave a very good explanation of it earlier on, the barriers around it and how it can stand up. What type of commitment can Google give to ensure SynthID and C2PA are third-party verifiable and resilient to common transformation? I appreciate Ms Estrin's point about, even when it is cropped, the actual watermark and water logo staying within the image. How can Google ensure that is a verifiable by a third party and in this instance by a regulator, or indeed, we will say, by social media companies such as Facebook or Meta, where an image is being shared that was created via Gemini?
Comment on this
I thank the Deputy for also bringing up C2PA, which is the cross-industry standard. I will say that these technologies work together. They each have their strengths. For SynthID, it really is that robustness. For C2PA, it is the interoperability and the security. It is tamper-evident because it uses these cryptographic metadata. What it means, just to illustrate, is that if something is generated via Gemini and posted to a C2PA partner like LinkedIn, C2PA can read the content credentials of those metadata and display it to users. If someone screenshots that LinkedIn post, the metadata can be lost but SynthID can still be detected. I think what the Deputy is pointing out is that there is no silver bullet. We have to have a multilayered approach and that is the one we take. In regard to detectors, we make our detector available to all users for photo, video and audio.
We also have a more advanced version that is available to journalists and researchers. Our SynthID model for text is open source, so that is something everyone can use and improve upon.
Comment on this
That is really positive. It goes to the heart of what happens particularly when images and videos go viral so that we can actually track the source. That is important to call out in this instance as well.
Comment on this
I concur with the comments made by Deputy Ó Cearúil that is really is regrettable that representatives of OpenAI and others did not attend, including Microsoft, whose products are used in the Oireachtas, although they are increasingly not used by many other parliamentary bodies across Europe. It really would have behoved them to be here. To build on the point about safety reports and concerns around them in respect of Google, have publicly available safety reports been published on new features prior to their rollout? Prior to the rollout of Gemini and Google overview, are there publicly available safety reports published?
Comment on this
We do publish a wide range of reports. An example that I know of a report we made on AI Overviews before it was released was under the context of the DSA. We did a mid-cycle risk assessment and sent that to regulators. That is the example that comes to mind for pre-launch.
Comment on this
I have seen concerns in that people are not finding the safety reports and there is a concern that the public are basically being treated as beta testers, whereby the companies try it out, discover the problem and then adapt the model. Is that something that has been examined? Ms Estrin mentioned the plans for compliance with EU AI. Does she believe Google is currently compliant with what the AI Act has set out? It has not yet come into force.
Comment on this
We have been very clear from the outset of the AI Act that we support the objectives of that Act. We mentioned our support for regulation. The Act is not fully enforced yet. Those obligations are later on but we have already made changes to our systems and they are in compliance in respect of the rules that are in place. We have gone further than others in some ways. There are voluntary codes that have been established under the Act as well. We have signed the GPAI, general purpose AI code of conduct in that regard. Other companies did not do that. There is another code of conduct under negotiation at European level that we are also involved with, in the area of transparency.
Comment on this
We are hearing a lot about the AI Act but it is going to be delayed, potentially, in its application, because of the new omnibus legislation coming. Is Google engaged in the lobbying in respect of the proposed carve-outs for the training of AI algorithms? There are proposed carve-outs, dilution of special categories of personal information and changes to GDPR in relation to the training of AI algorithms. Mr. O'Flaherty will be aware that the data protection bodies at EU level have expressed about this. What position has Google taken?
Comment on this
I think the Senator is speaking about the digital omnibus.
Comment on this
The digital omnibus and of course there is the AI legislation.
Comment on this
On the AI Act, we are supporting the objectives, we have been clear and public on that. On the omnibus, we are also supporting the objective of that measure, which is simplification.
Comment on this
On that particular measure, I am explicitly talking about the proposed changes to dilute GDPR protection to facilitate the training of AI algorithms.
Comment on this
We do not understand it in the same frame that there is dilution. We do not think there is any erosion of personal protections.
Comment on this
It literally removes and creates an exemption within special categories of personal information.
Comment on this
Yes, absolutely. I am happy to talk about this in detail at any point. There is no erosion of the definition or the procedures around that at all. It creates a very practical and narrow exemption. My understanding is that----
Comment on this
So Mr. O'Flaherty does not concur with the digital regulatory bodies at EU level that have expressed concern on those matters.
Comment on this
My understanding is that the digital regulators at EU level have supported and welcomed the specific exemption in this matter. I am happy to take it up separately.
Comment on this
I thank Mr. O'Flaherty. I have a last question on bad actors. Is it still the practice whereby bad actors can be rewarded through Google's advertising system? For example, they can benefit economically from advertisements that may take place on sites that have inaccurate information, potentially AI-generated.
Comment on this
That would cut at the core of user trust. We removed 5.1 billion ads last year. We have removed the vast majority, 98%, before they are viewed by a single user. I thank the Senator for the question. We would welcome the chance to get back to her on the pre-launch safeguards as well.
Comment on this
It is very welcome that Google has come before the committee, as colleagues have mentioned. In many ways, even through there may be some disagreements on policy, to the point that our guests have made, Google has supported the broad regulatory structures. Our challenge as a committee is about how we support innovation but, at the same time, balance that with maintaining public trust. Mr. O'Flaherty in the opening statement placed a very heavy emphasis on trust and ensuring that the necessary guardrails are in place. Unfortunately, in spite of all the best efforts in the regulatory or education space, the reality is that Google is going to be judged by some other companies who do not invest to that level in trust and ensuring guardrails are followed. From our perspective, we need to know from a policy point of view what we would like to do. In terms of some of the suggestions and putting them directly, we have the idea of safety by design and individuals, whether they be directors or others within companies being held to account for the products they unleash on the market. In the second case, we would look at a requirement that those products be brought before the regulator. If I wanted to develop a financial product, I would have to go to the Central Bank and outline generally what that product is going to do. In the same way, in respect of an AI-enabled product, a company such as Google would have to go Coimisiún na Meán or the DPC, depending on the nature of the product. What are the other safety measures we should be introduce? Specifically on those suggestions, what is Google's attitude?
Comment on this
The Online Safety and Media Regulation Act regulates the liabilities issue and we are very supportive of that Act. Generally, we have very strong safety provisions in place on our products. We regard our protections as industry leading. We spoke today about things like SynthID and other products that we are leading the industry in.
Comment on this
Would Google have a problem, as a company, if we were to introduce those? Presumably if it is invested in safety by design, it would have no problem in terms of meeting those requirements.
Comment on this
Absolutely. I do believe Ireland should be in step internationally here as well. At EU level and internationally, Ireland already has strong protections in this area from our perspective and we would be keen that Ireland would not go further than what EU law prescribes in this area. On the specific point of director's liability, it is also linked to innovation and FDI.
Comment on this
The witnesses might comment on about AI use in detecting some of the content we are talking about, such as deepfakes, child sexual abuse material and the extent to which Google uses AI itself.
Comment on this
We have been using AI technology, for instance on YouTube, for a long time now and have seen the effectiveness of those tools. Overall in a quarter, we see that 98% of the 12 million videos that we removed from YouTube were first identified by our own AI classifiers. That is 2% that we are hearing first about from users. That is one example. Of course, what we are seeing with this new era of LLMs is that they are helping us get better at building those classifiers for complex, nuanced abuse areas. The scams mentioned earlier are a perfect example of that. We are able to build these AI detection tools in a matter of days and weeks where it would have taken engineers weeks and months in the past.
Comment on this
I have a final question about YouTube. The capability of AI to generate videos is a big concern for the creative industries. If I am viewing a YouTube video that is AI-created in future, how am I going to know? We are not just looking at short videos now as, increasingly there is the potential for long form to be developed.
Comment on this
We developed disclosure policies on YouTube that require creators to disclose to us where they are using AI content that may be deceptive. We also leverage our tools like SynthID and C2PA to be able to identify that on our end as well.
Comment on this
It is exactly building on the Cathaoirleach's point. It is the issue of medical advice that was picked up earlier and the concern about that being AI-generated.
I know there has been a question about if that label should be-----
Comment on this
Is Google committed to, where medical advice is AI generated, including a clear disclaimer that it is AI-generated medical advice?
Comment on this
I think what we would focus on is making sure the information presented was of the highest medical standards and quality-----
Comment on this
I thank our witnesses sincerely for coming in. Our committee is interested in any submissions on further work because our committee's view is that we should work with those within the sector in helping to shape policy. I remind everyone that the committee's first interim report, which we published before Christmas, will be discussed in the Dáil on Thursday afternoon and there is an opportunity for members to have an input into that. I encourage everybody to do that. We will adjourn the meeting until 3 March. We might have a couple of minutes in private session to go through what our next steps are. We will not have a full private meeting but just five minutes to know where we are going next.