Government & Policy

EU watchdog questions secrecy around lawmakers’ encryption-breaking CSAM scanning proposal

Comment

Artificial intelligence technology futuristic background. Green binary coding letters on black.
Image Credits: cundra / Getty Images

The European Commission has again been urged to more fully disclose its dealings with private technology companies and other stakeholders, in relation to a controversial piece of tech policy that could see a law mandate the scanning of European Union citizens’ private messages in a bid to detect child sexual abuse material (CSAM).

The issue is of note as concerns have been raised about lobbying by the tech industry influencing the Commission’s drafting of the controversial CSAM-scanning proposal. Some of the information withheld relates to correspondence between the EU and private firms that could be potential suppliers of CSAM-scanning technology — meaning they stand to gain commercially from any pan-EU law mandating message scanning.

The preliminary finding of maladministration by the EU’s ombudsman, Emily O’Reilly, was reached on Friday and made public on its website yesterday. Back in January, the ombudsman came to a similar conclusion — inviting the Commission to respond to its concerns. Its latest findings factor in the EU executive’s responses and invite the Commission to respond to its recommendations with a “detailed opinion” by July 26 — so the saga isn’t over yet.

The draft CSAM-scanning legislation, meanwhile, remains on the table with EU co-legislators — despite a warning from the Council’s own legal service that the proposed approach is unlawful. The European Data Protection Supervisor and civil society groups have also warned the proposal represents a tipping point for democratic rights in the EU. While, back in October, lawmakers in the European Parliament who are also opposed to the Commission’s direction of travel proposed a substantially revised draft that aims to put limits on the scope of the scanning. But the ball is in the Council’s court as Member States’ governments have yet to settle on their own negotiating position for the file.

Europe’s CSAM-scanning plan is a tipping point for democratic rights, experts warn

In spite of growing alarm and opposition across a number of EU institutions, the Commission has continued to stand behind the controversial CSAM detection orders — ignoring warnings from critics the law could force platforms to deploy client-side scanning, with dire implications for European web users’ privacy and security.

An ongoing lack of transparency vis-à-vis the EU executive’s decision-making process when it drafted the contentious legislation hardly helps — fueling concerns that certain self-interested commercial interests may have had a role in shaping the original proposal.

Since December, the EU’s ombudsman has been considering a complaint by a journalist who sought access to documents pertaining to the CSAM regulation and the EU’s “associated decision-making process”.

After reviewing information the Commission withheld, along with its defence for the non-disclosure, the ombudsman remains largely unimpressed with the level of transparency on show.

The Commission released some data following the journalist’s request for public access but withheld 28 documents entirely and, in the case of a further five, partially redacted the information — citing a range of exemptions to deny disclosure, including public interest as regards public security; the need to protect personal data; the need to protect commercial interests; the need to protect legal advice; and the need to protect its decision-making.

According to information released by the ombudsman, five of the documents linked to the complaint pertain to “exchanges with interest representatives from the technology industry”. It does not list which companies were corresponding with the Commission, but U.S.-based Thorn, a maker of AI-based child safety tech, was linked to lobbying on the file in an investigative report by BalkanInsights last September.

Other documents in the bundle that were either withheld or redacted by the Commission include drafts of its impact assessment when preparing the legislation; and comments from its legal service.

When it comes to info pertaining to the EU’s correspondence with tech companies, the ombudsman questions many of the Commission’s justifications for withholding the data — finding, for example in the case of one of these documents, that while the EU’s decision to redact details of the information exchanged between law enforcement and a number of unnamed companies may be justified on public security grounds there is no clear reason for it to withhold the names of companies themselves.

“It is not readily clear how disclosure of the names of the companies concerned could possibly undermine public security, if the information exchanged between the companies and law enforcement has been redacted,” wrote the ombudsman.

In another instance, the ombudsman takes issue with apparently selective info releases by the Commission pertaining to input from tech industry reps, writing that: “From the very general reasons for non-disclosure the Commission provided in its confirmatory decision, it is not clear why it considered the withheld ‘preliminary options’ to be more sensitive than those that it had decided to disclose to the complainant.”

The ombudsman’s conclusion at this point of the investigation repeats its earlier finding of maladministration on the Commission for refusal to give “wide public access” to the 33 documents. In her recommendation, O’Reilly also writes: “The European Commission should re-consider its position on the access request with a view to providing significantly increased access, taking into account the Ombudsman’s considerations shared in this recommendation.”

The Commission was contacted about the ombudsman’s latest findings on the complaint but at press time it had not provided a response.

EU lawmakers under pressure to fully disclose dealings with child safety tech maker, Thorn

More TechCrunch

Scale AI, a company that provides data-labeling services for training machine learning models, has raised a $1 billion Series F round from a slew of big-name institutional and corporate investors…

Data-labeling startup Scale AI raises $1B as valuation doubles to $13.8B

The new coalition, Tech Against Scams, will work together to find ways to fight back against the tools used by scammers and to better educate the public against financial scams.

Meta, Match, Coinbase and others team up to fight online fraud and crypto scams

It’s a wrap: European Union lawmakers have given the final approval to set up the bloc’s flagship, risk-based regulations for artificial intelligence.

EU Council gives final nod to set up risk-based regulations for AI

London-based fintech Vitesse has closed a $93 million Series C round of funding led by investment giant KKR.

Vitesse, a payments and treasury management platform for insurers, raises $93M to fuel US expansion

Zen Educate, an online marketplace that connects schools with teachers, has raised $37 million in a Series B round of funding. The raise comes amid a growing teacher shortage crisis…

Zen Educate raises $37M and acquires Aquinas Education as it tries to address the teacher shortage

“When I heard the released demo, I was shocked, angered and in disbelief that Mr. Altman would pursue a voice that sounded so eerily similar to mine.”

Scarlett Johansson says that OpenAI approached her to use her voice

A new self-driving truck — manufactured by Volvo and loaded with autonomous vehicle tech developed by Aurora Innovation — could be on public highways as early as this summer.  The…

Aurora and Volvo unveil self-driving truck designed for a driverless future

The European venture capital firm raised its fourth fund as fund as climate tech “comes of age.”

ETF Partners raises €284M for climate startups that will be effective quickly — not 20 years down the road

Copilot, Microsoft’s brand of generative AI, will soon be far more deeply integrated into the Windows 11 experience.

Microsoft wants to make Windows an AI operating system, launches Copilot+ PCs

Hello and welcome back to TechCrunch Space. For those who haven’t heard, the first crewed launch of Boeing’s Starliner capsule has been pushed back yet again to no earlier than…

TechCrunch Space: Star(side)liner

When I attended Automate in Chicago a few weeks back, multiple people thanked me for TechCrunch’s semi-regular robotics job report. It’s always edifying to get that feedback in person. While…

These 81 robotics companies are hiring

The top vehicle safety regulator in the U.S. has launched a formal probe into an April crash involving the all-electric VinFast VF8 SUV that claimed the lives of a family…

VinFast crash that killed family of four now under federal investigation

When putting a video portal in a public park in the middle of New York City, some inappropriate behavior will likely occur. The Portal, the vision of Lithuanian artist and…

NYC-Dublin real-time video portal reopens with some fixes to prevent inappropriate behavior

Longtime New York-based seed investor, Contour Venture Partners, is making progress on its latest flagship fund after lowering its target. The firm closed on $42 million, raised from 64 backers,…

Contour Venture Partners, an early investor in Datadog and Movable Ink, lowers the target for its fifth fund

Meta’s Oversight Board has now extended its scope to include the company’s newest platform, Instagram Threads, and has begun hearing cases from Threads.

Meta’s Oversight Board takes its first Threads case

The company says it’s refocusing and prioritizing fewer initiatives that will have the biggest impact on customers and add value to the business.

SeekOut, a recruiting startup last valued at $1.2 billion, lays off 30% of its workforce

The U.K.’s self-proclaimed “world-leading” regulations for self-driving cars are now official, after the Automated Vehicles (AV) Act received royal assent — the final rubber stamp any legislation must go through…

UK’s autonomous vehicle legislation becomes law, paving the way for first driverless cars by 2026

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm. What started as a tool to hyper-charge productivity through writing essays and code with short text prompts has evolved…

ChatGPT: Everything you need to know about the AI-powered chatbot

SoLo Funds CEO Travis Holoway: “Regulators seem driven by press releases when they should be motivated by true consumer protection and empowering equitable solutions.”

Fintech lender SoLo Funds is being sued again by the government over its lending practices

Hard tech startups generate a lot of buzz, but there’s a growing cohort of companies building digital tools squarely focused on making hard tech development faster, more efficient and —…

Rollup wants to be the hardware engineer’s workhorse

TechCrunch Disrupt 2024 is not just about groundbreaking innovations, insightful panels, and visionary speakers — it’s also about listening to YOU, the audience, and what you feel is top of…

Disrupt Audience Choice vote closes Friday

Google says the new SDK would help Google expand on its core mission of connecting the right audience to the right content at the right time.

Google is launching a new Android feature to drive users back into their installed apps

Jolla has taken the official wraps off the first version of its personal server-based AI assistant in the making. The reborn startup is building a privacy-focused AI device — aka…

Jolla debuts privacy-focused AI hardware

The ChatGPT mobile app’s net revenue first jumped 22% on the day of the GPT-4o launch and continued to grow in the following days.

ChatGPT’s mobile app revenue saw its biggest spike yet following GPT-4o launch

Dating app maker Bumble has acquired Geneva, an online platform built around forming real-world groups and clubs. The company said that the deal is designed to help it expand its…

Bumble buys community building app Geneva to expand further into friendships

CyberArk — one of the army of larger security companies founded out of Israel — is acquiring Venafi, a specialist in machine identity, for $1.54 billion. 

CyberArk snaps up Venafi for $1.54B to ramp up in machine-to-machine security

Founder-market fit is one of the most crucial factors in a startup’s success, and operators (someone involved in the day-to-day operations of a startup) turned founders have an almost unfair advantage…

OpenseedVC, which backs operators in Africa and Europe starting their companies, reaches first close of $10M fund

A Singapore High Court has effectively approved Pine Labs’ request to shift its operations to India.

Pine Labs gets Singapore court approval to shift base to India

The AI Safety Institute, a U.K. body that aims to assess and address risks in AI platforms, has said it will open a second location in San Francisco. 

UK opens office in San Francisco to tackle AI risk

Companies are always looking for an edge, and searching for ways to encourage their employees to innovate. One way to do that is by running an internal hackathon around a…

Why companies are turning to internal hackathons