Tech Legal Brief 17 – Europe Can Be Ignored Technologically, But Its Tech Regulation Can’t
Introduction
The title of today's post is inspired by a quote from Luciano Floridi’s paper Rules Without Models: Why Europe Must Build the AI It Regulates:
“A decade of rule-making has produced a Europe that others are legally obliged to consider yet can ignore technologically.”
That is as true for AI as it is for social media and the entire digital infrastructure Europeans depend on every second of every day.
During the 90’s, 00’s, and early 10’s it seemed fine to live on borrowed land in cyberspace. During that time, global society was governed by soft power, international norms and treaties; a trust-and-rules based order.
But that is no longer the case. We are regressing back to a dark age of hard power and force, underlined by world events such as Russia’s invasion of Ukraine, the re-election of Trump, the war in Iran, and the lack of sanctions and diplomatic consequences on Israel.
In a world without effective rules on those in power, where words and commitments cannot be counted on, and accountability for human rights violation is often unenforceable, can countries, and people, still afford to depend on a digital infrastructure they have no control over?
To me it seems that our dependency on borrowed digital infrastructure is strengthening Big Tech, the American AI project, and Trump by extension, while giving away the agency we hold as individuals, and collectively, as nations. The EU’s strategy is to regulate foreign digital infrastructure without much leverage besides its laws and values and principles in writing. The successfulness of that strategy is becoming more questionable by the day. Even though the push towards digital sovereignty is an enticing slogan, I see it more as a fading news trend while the underlying issue is not treated with the urgency and intellectual rigor it deserves.
Human rights scholar Jacob Mchangama provides an interesting counterpoint in Foreign Affairs:
“When Iran crushed protests in January, the regime imposed digital darkness, shutting down the Internet across the country to prevent the world from bearing witness. Iran’s UN ambassador blamed the protests on externally orchestrated terrorism and asserted the regime’s “sovereign right” to stop “unauthorized transmissions.” The blackouts were the ultimate display of government control over the flow of information—one that should serve as a warning to Western policymakers about where the idea of digital sovereignty logically leads.”
The claim here is that digital sovereignty is a sliding slope leading to authoritarian government control.
However, the concept of digital sovereignty is not about governments blocking access to information and deciding what people and businesses are allowed to do online. It’s really about rethinking how we use the internet.
For example, should critical infrastructure run on foreign servers we have no control over? Should Meta, SpaceX, and other profit-driven corporations be the arbiters of public town squares? Is it actually beneficial for children to connect with other children and adults through videos on TikTok and what could an alternative look like? Do we trust OpenAI and Anthropic in their mission to build American superintelligence and will it in fact benefit humanity?
What about cyber incidents, where rogue AI agents are allowed to hack organizations without criminal liability for the sake of PR and more investment? The Prime Minister of Australia, Anthony Albanese, said last Wednesday that a rogue OpenAI agents had breached four Australian government websites and gained access to non-public information. OpenAI identified the breach two months later in August, but didn’t notify Australia before September 10. The frontier AI labs are currently probing tens of thousands of similar incidents (Axios).
Digital sovereignty isn’t mainly about regulating and policing. It’s about questioning status quo, innovating and building. Contrarily, outsourcing important technology to foreign providers means giving away leverage and apparently, according to the US government, accepting the laws of a foreign jurisdiction in place of your own.
In the paid segment of this post, I will analyze Meta’s settlement with 47 state attorneys general, the proposed KIDS Act in the EU, how a European digital infrastructure provider was forced to shutdown after being designated as a terrorist organization by the US government, quick updates on state regulation of AI data centers, a fun story about a court ruling on AI slop, and some links to other interesting stories.
Creating Tech Legal Briefs is a time-consuming process, but I continue to make them, because I think they provide a lot of value to those who have just a hint of interest in tech policy and regulation of the digital. To support and gain full access to my work, please consider taking on a paid subscription of $5/ month or $50/year.