Despite private corporations and citizens advocating for states to take the reins on fleshing out standards for online content regulation, thus far many Western governments have been hesitant to tread into such territory, but where they have, their responses have been relatively weak. In the European Union, some rules for online content regulation have emerged, while in the United States, no such government policy has been enacted. Regulatory efforts in the United States with regard to algorithmic transparency and accountability have also been limited and largely restricted to public use cases of such technology. Criticisms of algorithmic software used in criminal trials, and sentencing in particular, have created cause for concern with regard to citizens’ civil liberties. Legal scholars have argued that “due process requires that those who deprive individuals of liberty interest do so without unwarranted bias or direct financial interest in the outcome,” and have called for algorithmic decision-making to provide users with “procedural data due process . . . [to] ensur[e] greater fairness with predictive analytics.” In the United States, the Supreme Court has held that the Constitution requires administrative agencies and government actors to provide due process where they risk causing an erroneous deprivation of rights through decision-making: due process generally requires consideration of three distinct factors: First, the private interest that will be affected by the official action; second, the risk of an erroneous deprivation of such interest through the procedures used, and the probable value, if any, of additional or substitute procedural safeguards; and finally, the Government’s interest, including the function involved and the fiscal and administrative burdens that the additional or substitute procedural requirement would entail.
In algorithmic decision-making, the risk of erroneous deprivation can be extremely high as automated processes are often not properly understood or monitored by the human elements utilizing them. While utilization of algorithmic technology and automation eases the government’s administrative burden, the private interest of individuals affected by such algorithmic decision-making is arguably of much greater import. This is made particularly evident in the case of software used in criminal adjudications and sentencing where a flawed algorithm can result in false imprisonment. By ceding such important tasks to algorithmic decision-making systems, “over time, deference to algorithms may weaken the decision-making capacity of government officials along with their sense of engagement and agency . . . undermin[ing] a person’s sense of her own moral agency . . . [whereby] human dignity is eroded and individuals may consider themselves to be largely unaccountable for the consequences of their computer use.” Diminishing the agency of government officials and distancing them from accountability in turn erodes the confidence of the public in the governing body. This erosion of trust related to the provision of due process is incredibly harmful to democracy—as due process is a foundational aspect of the social contract ensuring the individual’s freedom, without it the arbitrariness of the decision-making process begins to recall authoritarian rule.
In light of the significant liberty interest implicated, industry leaders and legal theorists have argued greater federal agency oversight of algorithmic technology is necessary in the United States. In particular, the majority have pushed for greater algorithmic transparency overseen and enforced by administrative government agencies. However, the definition of algorithmic transparency and the degree to which corporations should be held accountable for harms caused by their algorithms is still a point of contention. “Government officials and tech executives have argued that too much transparency could imperil companies’ intellectual property and dissuade [them] from working with governments.” Revealing the function and inputs of an algorithm could divulge proprietary information that, if leaked, would put technology companies at severe business risk. Furthermore, where an algorithm has caused an unintended harm to a consumer or bystander of such technology, it is unclear who, if anyone, should be held responsible for the technological malfunction. Many worry that holding technology companies, especially market newcomers, strictly liable for harms caused by their algorithmic innovations would place too high a financial burden on industry players and fail to take into account the “significant difference between mistakes that harm consumers due to maleficence, negligence, willful neglect, or ineptitude on the part of the company, and those that harm consumers as a result of a company striving to innovate and benefit society.” Furthermore, it is unclear to what extent intent should be factored in, “when an algorithm causes harm . . . to determine if an operator acted responsibly.” However, as capitalism and democracy often go hand in hand, the market economy repercussions of regulation cannot be taken lightly. Rather, in a democratic system, any means of oversight must take into account not only the public’s interest, but also that of the corporate actors it seeks to control.
In the European Union, attempts at regulating the cyber sphere have thus far resulted in the General Data Protection Regulation (hereinafter, GDPR), which provides citizens with a nearly direct right to due process where algorithmic decision-making is concerned. The GDPR requires data controllers to “implement suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision,” if they are subjected to “a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.” In addition, the GDPR focuses heavily on users’ privacy and consent rights, as well as data localization and securitisation. However, measures focused primarily on ensuring informed consent risk falling prey to the consent fallacy whereby they place too great an emphasis on user knowledge in relation to practices that these users have no power to change. Rather, such measures may have the opposite of their desired effect, normalizing the existing manipulative practices by accepting them through notice and agreement instead of demanding change. Online consent thus carries little meaning when it, “is most often obtained by displaying a link to a privacy policy . . . and asking the user to accede to these terms and conditions by ticking a box [with] no chance to negotiate and little evidence that the majority of users either read, understand or truly consider these conditions, [making it] hard to see how this consent is either ‘freely given, specific, informed and unambiguous’ despite these being conditions for valid consent.” As a result, while such measures may make users aware of the type of personal data they are allowing companies to access, they fail to provide meaningful insight into how such data is used and do not seek to instil greater fairness in the technology’s development from the start. Thus, while the GDPR takes a step in the right direction, it has been criticized for placing an outsize burden on many businesses. Furthermore, it should be noted that the GDPR, while adopted by largely democratic societies, was imposed by the European Union’s supranational governing body, which is much less concerned with electoral bias and election pandering. As a result, the passage of legislation at this level, while still representative in essence, is further from democracy than the direct system found in many of the nation states composing the Union.
Legislative efforts have also sought to address the external threats posed by the digital revolution through the expansion of national security. The invocation of national security has often provided a blunt tool by which executive powers may be expanded without concern for the checks and balances otherwise required in a democratic system. While national security exceptions are necessary in order to preserve the sovereign, the over-expansive interpretation of exigent circumstances threatens both the liberty interests of its subjects as well as the legitimacy of the democratic system. The Foreign Investment Risk Review and Modernisation Act of 2018 (FIRRMA) and the Export Control Reform Act of 2018 (ECRA) are examples of such an expansion in the United States. Taken together, these acts provide the executive branch a great degree of oversight in trade and investment by establishing a broad category of industries and transactions that may be deemed critical to national security. Under FIRRMA, “national security” is read to “include those issues relating to ‘homeland security,’ including its application to critical infrastructure.” The amended Defence Production Act of 1950 (DPA) under FIRRMA gives the Committee on Foreign Investment in the United States (CFIUS) oversight broadly of “covered transactions,” which extends not only to mergers, acquisitions and takeovers that result in foreign control of a U.S. business related to national security.
The inclusion of “critical technologies” here is particularly noteworthy, as it expands the oversight of Committee on Foreign Investment in the United States (CFIUS) to nearly all innovations in the digital world by capturing “emerging and foundational technologies controlled pursuant to section [1758 of the Export Control Reform Act of 2018]” The referenced Export Control Reform Act of 2018(ECRA) provision provides a statutory basis for the President to “establish and . . . as appropriate, lead, a regular, ongoing interagency process to identify emerging and foundational technologies that—(A) are essential to the national security of the United States; and (B) are not critical technologies described in [Foreign Investment Risk Review and Modernization Act of 2018 (FIRRMA) definition of “critical technologies].” As a result, the amendments to the Defence Production Act of 1950 (DPA) allow for a constantly fluctuating scope of technologies to be subject to review, and furthermore consolidate the discretion by which this scope may be determined in the hands of the executive (rather than requiring legislative agreement). Security exceptions have generally been considered necessary, “in [a] time of war or other emergency in international relations. . . [or]. . .under the United Nations Charter for the maintenance of international peace and security.” However, the concerns of the United States with regards to “national security” have been significantly expanded to encompass potential as well as actual threats. Economic competitiveness, particularly in the technology sector, has clearly been incorporated into the terminology of “national security” in the United States. In the past year alone, these expansive provisions have been used to conduct reviews of social media apps. Some American lawmakers have gone so far as to seek to bar government employees of any kind from the ability to use such apps. However, the United States is not alone in raising security concerns about the use of foreign-made social media applications, nor are their concerns completely unfounded: “India’s military has prohibited personnel from installing Chinese social platform WeChat due to security concerns. The Australian armed forces have also banned WeChat. The Pentagon banned the military’s use of geolocating fitness trackers in August 2018 after live GPS data was found on the public Internet, making it possible for researchers to track the location of troops on military bases and spies in safe houses.”
Democracy thus battles itself when trying to compete in the cyber sphere as its governing mechanism is slow and burdensome, while the foe it faces is nimble and quick. In order to address the harms posed by online speech, it would have to re-evaluate its commitment to absolute freedom of speech. In order to remain competitive against its foreign enemies, it would have to cooperate to a greater degree with its national tech companies and move away from the laissez-faire capitalism of years past. In order to address the threats posed by cyber warfare, it would need to re-evaluate the role of the balance of powers and adequate due process in order to defend itself fully against the threats it faces both domestically and from abroad. As a result, rather than taking a primary role in governing online spaces, democratic governments have been forced to acquiesce to the norms imposed either by private actors or their more dominant and forceful authoritarian counterparts.
Copyrights ©️
OBSERVERTIMES GLOBAL NEWSNETWORK PRIVATE LIMITED reserves the rights to all content contained within its official website https://observertimes.in /Online Magazine/ Publications
