Content that is legal but harmful, and a lack of foresight in oversight

Last week, I had the honor and pleasure of participating in the conference organized by the Columbia Global Freedom of Expression Program: Regulating the Online

Legal but Harmful Content and a Lack of Foresight in Oversight

Last week, I had the honor and pleasure of participating in the conference organized by the Columbia Global Freedom of Expression Program: “Regulating the Online Public Sphere: From Decentralized Networks to Public Regulation” (https://www.youtube.com/watch?v=DHJzcRlqZkY&t=20s). The conference, which drew more than 500 people tuning in online to listen to the panel discussions, seems more relevant than ever. During the conference, UNESCO announced a meeting to be held in February 2023 to discuss a regulatory framework for social media and cited, among other arguments, the existence of more than 190 bills around the world that seek to regulate platforms in one way or another. As Catalina Botero rightly pointed out in her introduction as the host of this event, we are witnessing a battle over how to address online expression. And there are different theories on this matter, which our host succinctly and clearly highlighted: 1) those who argue that platforms can and should self-regulate while complying with international human rights standards when implementing such self-regulation; 2) those who maintain that platforms should be neutral with regard to their users’ content and regulated like telephone companies, with no liability whatsoever for third-party content and even with the obligation to provide the platform without any discrimination regarding content (known as “common carriers”); 3) those who argue that platform self-regulation is part of the right to free enterprise and that contract law should govern the relationship between users and platforms, as well as between content and moderation; 4) those who equate platforms with media outlets and therefore advocate for the application of liability criteria similar to those for publishers. I would venture to say that several proposals touch on elements of all four positions, even when these positions are in direct and open contradiction with one another. A first observation that emerges from the positions presented—and which we carry over from yesterday’s discussion of decentralization proposals in response to moderation issues—is that I do not believe there is a consensus on exactly what “problems” we are trying to solve with these approaches. Whether we’re thinking about decentralization tools or social media regulation, it’s difficult to compare the 190 proposals, as I know for a fact that some (and I suspect many) pursue radically different objectives and even contradictory perceptions of “the problem.” Example: if we define “the problem” as the abuse of private censorship by platforms, solutions such as the one proposed in item 2 will make sense. If we define “the problem” as the proliferation of problematic discourse (a term that is beginning to appear in certain documents as a technical term, but whose definition is ambiguous and unclear in and of itself) in the face of discretionary and disproportionate interference in the moderation of public debate, we will see solutions more aligned with item 1. If, on the other hand, we view “the problem” as an editorial issue—understanding hosting and moderation as a form of content endorsement—the proposal in paragraph 4 will take precedence. If we understand “the problem” as a failure to comply with (or the need to enforce) what has been agreed upon, the perspective offered by option 3 would perhaps be the most appropriate. Ultimately, when discussing proposals to solve content moderation problems, it is important to bear in mind that the definition of the problem is not unambiguous. Or that not all proposals define the problem in the same way—whether explicitly or implicitly. All of these are likely, to a greater or lesser extent, current problems, and we probably cannot resolve them with a single regulatory proposal. Without having read all 190 bills—though I have read some, including a good number of those regularly cited in our part of the world (Latin America in general)—I ventured to say during the panel discussion I participated in that there are two significant contradictions in the regulatory proposals we’ve seen so far. The first is that, underlying this discussion, in my view, lies a peculiar problem: how to address, through the law, content or expression that is legal but “harmful” (the Americans, as always, are creative and vivid and refer to this distinction as lawful but awful, or harmful but legal). The second contradiction is evident in the oversight frameworks proposed by many of these rules—or even in the absence of such provisions. Over the next few weeks, I’ll be posting some comments on the topic. I’ll start with “lawful but awful” and follow up with the (possible) difference in the Latin American approach. Next, we’ll address oversight (which I hope will include a link to a recent paper we wrote at CELE). The category of “legal but harmful” expression does not imply a contradiction in and of itself. While a general principle of civil law is that all harm must be remedied, there are exceptions. There are behaviors—actions and omissions—that the law considers legal yet harmful. For example, smoking is, according to the state, legal but harmful. Drinking alcohol is legal but harmful. The margin of tolerance that the law allows regarding harm varies from issue to issue. Turning to an issue closer to home, in global case law on freedom of expression, we have accepted as a universal principle that public officials must be afforded a broader margin of tolerance with regard to criticism and intrusions into their privacy. The Inter-American Court, for example, following the European Court, explains that the distinction is not based on the individual but on the social role that person fulfills in a democratic society. Defamation and slander against public officials rarely succeed. This is because transparency and democracy require that public debate regarding the performance of their duties, their ethics, and their integrity be vigorous. There are potential infringements on the reputation and privacy of public officials that the law requires us to tolerate; therefore, they are not subject to remedies or penalties of any kind, except in exceptional cases (actual malice). Similarly, the Inter-American Legal Framework already establishes that the right to freedom of expression protects not only conciliatory and harmless speech but also expressions that “offend, shock, or disturb the majority.” When people talk about the problems of content moderation, the discussion has centered on this: content that is legal but harmful. Some examples, which abound in the most recent bills: disinformation, misogynistic speech, problematic speech, radicalized speech, polarizing speech, offensive speech, and violent speech. All of these, as framed in many of the proposals I have seen—as much as it may displease us—are currently lawful forms of speech that are legally protected. There is no legitimate reason for the state to restrict them. In fact, there is a legitimate reason for the state not to restrict it. The fact that the focus is on speech that is legal but harmful may stem from various reasons. I suspect—and this is what I’m writing about with Paulina Gutierrez—that the adoption of Section 230 of the CDA can help explain this focus to some extent: the CDA grants immunity to companies for third-party content and also grants immunity for the moderation of that content. Something similar, though not identical, happened in Europe with the E-Commerce Directive. Our theory is that Section 230 removed the platforms’ conduct from the legal sphere. Moreover, case law following the adoption of Section 230 expanded this immunity to the point where nothing companies do with that third-party content can even be analyzed from a legal standpoint. The immunity is such that, to date, most lawsuits have been dismissed outright, without even undergoing a legal analysis. This—which initially allowed the internet to flourish—now means that the actions taken within the various services provided by platforms (organizing, indexing, displaying, hosting, moderating, recommending, highlighting, hiding, and any other “-ing” actions one can think of) are, in the current collective imagination, exempt from the realm of law and left exclusively to the realm of ethics, morality, and good customs, or corporate social responsibility. While this framework made sense in the beginning, when companies in the sector were engaged in only a few activities (hosting, organizing, indexing, and a few others), now, given the power that internet companies—particularly social media platforms—have to inform, shape, limit, or fuel public debate, such immunity seems problematic. It is in this context that modern regulatory proposals emerge: those focused on content, but also those focused on processes. And here’s a second observation: the distinction between legal and illegal content is made by the state. Until now, the distinction between ethical or responsible content has been made by the platforms. However, the vast majority of regulatory proposals for social media that we see today are not neutral with regard to lawful content. Underlying this is a state concern about lawful discourse and a desire to impose new limitations on freedom of expression in the name of ethics or corporate social responsibility. Many of the bills and laws we see today—including those intended to regulate processes—involve a certain renegotiation of the legitimate limits on freedom of expression on platforms. And since what is being regulated is the medium through which expression circulates, this renegotiation takes place indirectly: by placing on companies the obligation to self-regulate in order to prevent harm in a broad sense—not strictly a legal one—and by imposing obligations on companies regarding their users’ lawful but “problematic” speech. Harm that, under our substantive laws, is lawful—or at least, in the eyes of the law, should be tolerated. The “problem” with content moderation in general is not illegal speech. Illegal expressions are regulated, whether or not the company hosting the content states so, since limits on freedom of expression are negotiated in each state and each region in accordance with their needs, cultures, and history, and always in accordance with minimum human rights standards. Individual liability for such expressions is clearly enforceable. The problem is lawful speech. If the state cannot legitimately restrict it (except in matters of time, form, and place), neither can it instruct a third party to restrict it, either directly or indirectly. In these cases, perhaps, we should seriously debate whether the permissible limits on freedom of expression that we have today are adequate. It is also worth addressing the legal analysis of new phenomena, such as virality or permanence. What was once tolerated by the law because it was not permanent or did not have significant visibility may no longer be so today. In any case, this debate is a more honest, substantive discussion about permissible limitations on the right to freedom of expression. That said, there are legislative proposals that, in addition to these indirect limitations, promote other measures that could be welcome. Among them are the many initiatives proposing greater transparency regarding the platforms’ own actions. There is a widespread consensus regarding the need for greater transparency. However, there is no consensus on the need for transparency that is mandated or supervised by the state. Nor is there a consensus regarding the scope of transparency—specifically, what information should be disclosed and for what purpose. And here, once again, substantive issues intersect with procedural ones. Depending on the answers to these questions, we will emphasize certain information over others. The objective that transparency pursues will be decisive in giving it meaning. Transparency must be understood as a means to an end. And the end must be legitimate, especially if it is the government that mandates such transparency. Depending on what we are seeking to achieve, we will request certain information and not others. We will highlight some aspects and not others. We will audit certain sectors and not others. I fear that there is no broad consensus here either, at least not in the regulatory proposals that currently exist. Perhaps the most advanced proposal in this regard is the DSA, and even there, there are issues regarding the breadth of the definition and a lack of clarity about how such transparency will be implemented. On the one hand, there are general transparency obligations regarding terms and conditions of service, moderation mechanisms, criteria used for moderation, and aggregated information on the volume of content affected, users affected, decisions made, and follow-up on reports; on the other hand, it is established that the information supporting these reports may be audited, although it is not yet clear how. Finally, two additional transparency obligations are established: one is to justify moderation decisions and communicate them to users. The other, in the case of large platforms (more than 45 million users in the European Union), is the obligation to conduct risk assessments of their products regarding potential harm to democracy, the well-being of minors, and the safety or security of users (in English, the distinction between the terms is perhaps clearer: “safety and security”), among others. I return here to the central point of this piece: the risks identified by the proposal—and regarding which transparency and action are required (risk analysis and the obligation to mitigate such risks)—stem from lawful, albeit potentially harmful, expressions. The details regarding what these risks entail, how to conduct such audits, the criteria for evaluating results, and the indicators of success or failure for these initiatives were left to be defined during the implementation phase, along with the oversight mechanism I’ll discuss in the next installment ;)