On the occasion of CREATe’s relaunch on 11 March 2024, we hosted a roundtable with UK digital regulators, policy makers and leading academics. The discussion, held under a variation of the Chatham House Rule, revolved around the successive waves of digital regulation, from the Online Safety Act (OSA), currently under implementation, to the Digital Markets Competition and Consumers Bill (enacted as DMCCA 2024) and the UK’s approach to AI, as well as lessons from longer-term regulatory experience. This summary of the discussion is based on notes by Aline Iramina, Stefan Luca and Zihao Li.
Martin Kretschmer (as chair) opened the roundtable by explaining the rules and offered three prompts for discussion.
Rule of record
Under the Chatham House Rule, participants are free to use the information received, but neither the identity nor the affiliation of the speaker(s), nor that of any other participant, may be revealed. In CREATe’s roundtables, we typically use a variation. It will be public that the meeting took place and who was here (see list of participants at the end of this blog). There will be a summary, non-attributed record of the discussion.
Prompts for discussion
In a moment where digital regulation globally is in flux, key issues in the UK context include:
- the interface between regulators (reflected in the formal and informal coordination of responsibilities between regulators, for example for mergers, algorithmic targeting, AI);
- the emergence of new modes of regulation (e.g., codes of conduct, codes of practice, behavioural obligations);
- the UK’s geopolitical position in a changing world (including its ‘freedom to operate’ after Brexit); the UK appears to have chosen a model of participatory regulation – highly tailored and flexible.
The need for coordination
There was recognition that the UK was in the middle of two waves in terms of digital policy and legislation. The first wave relates to new Online Safety and Competition related laws and the second relates to AI. UK regulators do not have the answer yet.
At national level, there is a sensitive interaction between policies. ‘Digital’ seems to bring together different policy objectives. The DRCF (‘Digital Regulation Cooperation Forum’), for example, is in its fourth year and was able to make headway on some important areas such as age assurance, both from a safety and data protection point of view. Other regulators also work with data protection (e.g., CMA works on competition and data protection). This indicates areas of mutual interest between regulators where they need to work together. It is complex and requires deep commitment from the top down and lots of interrelationships (as discussed for example in Philip Schlesinger’s work, there are preconditions for this sort of relationships to work, particularly a ‘concurrence/concurrency framework’, which already exists in the UK).
At least three of the regulators already have these cooperative concepts and ties (for example, OFCOM and ICO in relation to security). Other countries are following suit and adopting similar models, but in general they are not investing as much as the UK. It could be envisaged that at some point, every country will need a DRCF type coordination mechanism. The DRCF’s influence can go beyond mapping the terrain, findings, or joint statements. Remedies can also be influential when interventions are well thought through between regulators and strike an appropriate balance between different objectives.
International context
At international level, questions were raised about how these policies and regulations will play out in debates about convergence and divergence. For example, OFCOM cannot ignore the interdependencies in its work to implement the UK’s Online Safety Act (OSA) and the EU’s Digital Services Act (DSA). OFCOM invests in engagement and influence internationally. It has received early government funding to build up resources. Moreover, the OSA has considerable flexibility with a systems-and-processes approach, while the DMCC regime provided more flexibility in designating covered firms and services than the EU Digital Markets Act (DMA).
This flexibility allows for faster responses, drawing on previous experience in digital markets, e.g., the Adobe-Figma and Microsoft-Activision mergers. What happens in the UK will matter, perhaps not to the same extent as in the EU, but the UK is a significant economy and a potential regulatory trend setter.
The UK’s international influence and effective impact on the largest tech companies, mostly based in the US, were recurrent subjects. Digital firms provide global services and regulatory divergence is undesirable unless it is necessary. It was discussed if the UK can capitalise on its position as a regulatory innovator, its existing experience, and the flexibility built into the safety and digital markets regimes. Relations with other big players, such as the US and China, need to be navigated. While countries are adopting different systems, the resulting international fragmentation needs to be resolved, as trade requires common rules.
Different jurisdictions adopt different methodologies based on their preferences, institutional experience and practice; for instance, the Australian competition authority is proposing a framework very similar to the UK. The UK may manage the potential friction between the DMA and DMCC legislation in two ways. First, the CMA has been quite clear that unless there are good reasons to do something different, either because of a different market structure or because existing evidence suggests that there might be more effective remedies than those in the DMA, it is not going to do something different just for the sake of it. Secondly, through international cooperation: under the leadership of the last three chief executives, the CMA has played an important role in engaging with international fora, such as the G7 and the OECD. Nevertheless, the extent of engagement with other jurisdictions was a challenge. Existing information gateways through the competition regime may not translate to the context of a forward-looking regime, but ultimately that is a matter for inter-governmental engagement and treaty signing.
Accountability of regulators
Divergence from the EU was further explored. In the context of the ‘Brussels effect’ and the allure of validating Brexit, it was posited that the CMA was putting itself on the map, initially as the only major regulator to oppose the Microsoft-Activision merger. The differences between the DMCC regime to the DMA were highlighted to illustrate how the UK can create a slightly different regulatory framework, drawing comfort from greater democratic accountability: the CMA as a regulator is directly accountable to government and Parliament, not 27 governments and parliaments.
On different approaches to the Microsoft Activision merger, the concerns and harms identified by the CMA, the EU Commission and the US Department of Justice were broadly similar, the difference being evidence and experience-based. The EU has a tradition of accepting behavioural remedies, particularly in merger control, while the CMA does not have the same level of tolerance. Particularly in dynamic markets, there were risks in relying on clear thresholds when assessing a large player acquiring a reasonably small firm. These differences were based on evidence, rather than on doing things differently for the sake of it.
While new modes of participatory regulation, relying on highly-tailored, flexible and ongoing dialogue with companies, are not exclusive to the UK, they have been taken particularly far in the UK. This co-operative approach prompted a two-pronged discussion, addressing parliamentary scrutiny and the UK’s capacity compared to other jurisdictions and tech companies themselves.
Regarding parliamentary oversight, it was recognised that complex issues needed to be negotiated with companies, e.g., regarding child safety, and that it was difficult for Parliament to have significantly more responsibility for secondary legislation, simply because things are going to change so fast. Concerns were reiterated over the Secretary of State’s potential role in directing regulators’ actions. Nevertheless, for the Online Safety Act, drafts of codes of practice and other secondary legislation would be voluntarily presented to the select committees in both Houses of Parliament under the Parkinson rule. In contrast, there are no such arrangements for the Media Bill.
Broader issues of societal legitimacy were discussed. Regulators typically are accountable to Parliament, appearing before select committees quite frequently. Ultimately, this accountability framework builds trust that enables regulators to respond at speed. They can tackle emerging issues, such as cloud computing or partnerships on AI foundation models, faster than the years required to secure parliamentary time.
Participatory approach
An effective digital markets regime must enable regulators to work with platforms to tackle issues faster, clearer, and in a proportionate way. The DMCC legislation was designed to safeguard fairness and an even playing field for smaller competitors, while ensuring continued innovation and consumer benefits. For businesses, the CMA will make sure that for designated firms a set of tailored conduct requirements is developed to ensure that they do not exclude or exploit business relations. For consumers, the CMA will make sure that firms will not set exploitative terms, in particular for collecting and processing data. By engaging with the firms on the development of their products and services under this regulatory framework, wider economic benefits may be achieved.
The CMA’s provisional position on the new DMCC regime detailed the participatory approach and accountability mechanisms before both Government and Parliament. This process will be iterative, with the CMA learning over time as it grows from its traditional ex-post role, into an ex-ante regulator.
The evolving roles of various regulators were briefly touched upon, e.g., the ICO under changes to the Data Protection Act and OFCOM under the Media Bill. The policy and legislative drafting responsibilities of the Intellectual Property Office was considered, being an executive agency, rather than a regulator. It facilitates agreements, often industry-led, between parties with different objectives, working with academics to provide evidence. It secured broad industry support for the music streaming metadata agreement and the recent transparency code. However, no agreement was reached about a copyright code relating to AI.
On ex-ante regulation, while each regime was said to be unique, the regulatory building blocks have existed before in different configurations. OFCOM may draw on a long history to consider risks and build strong supervisory relationships where proportionate. Similarly, the CMA could draw on experiences of rulemaking and enforcement of secondary legislation in the retail and energy sectors between 2010 and 2020, to inform the DMCC regime. Ultimately, regulators were bound by clear statutory objectives, e.g., promoting competition for the CMA. While they had reasonably broad discretion in their application and interpretation they were guided by strategic steers given regularly by government and parliament.
Regulatory capacity
A contrast was observed between the OSA covering hundreds to thousands of companies and the DMCC regime that may apply to 5-7 companies. The toughest rules under the EU AI Act may reach only 2 firms. While the ‘scary thousands’ are new for OFCOM, this is not the case in the regulatory landscape, e.g., the Financial Conduct Authority (FCA, a member of the Digital Regulation Coordination Forum DRCF) oversees a huge number of firms. Regulatory supervision will be prioritised based on company scale and impact.
The challenges of competing with industry to recruit for technical and commercial expertise were discussed. OFCOM benefits from the ability to set its salary structures, while the CMA had a first mover advantage, having set up its data team in 2019. Beyond salaries, regulators were pleasantly surprised by the talent that had come in, motivated by significant interest in online safety and the unique combination of skills across technology and behavioural science.
Regulating AI
Expectations on regulators are enormous, particularly in relationship to AI, where a fine balance needs to be struck between protective regulation and not stifling innovation. The UK’s pro-innovation approach to AI regulation (under the Conservative government) was seen as an international outlier in its focus on existing regulatory capacity. Concern was raised about the sustainability of a sectoral approach to AI given that some sectors, such as labour, did not have a statutory regulator, the Equality and Human Rights Commission was on more adversarial terrain and underfunded, while in other sectors participatory regulation seemed business-focused. Furthermore, it was questioned whether participatory tailored regulation meant engaging with two large AI firms or meaningfully addressing the entire AI value chain.
Several discussants emphasised that as a matter of democratic legitimacy it was for elected members of Parliament to decide whether or not regulation was required in those spaces, not for regulators. The UK has a tradition of sectoral regulation and any new approach under consideration should be consistent with what’s already there, to avoid headache-inducing overlaps, not just for regulators but for the sectors themselves. That said, the CMA is a general economy regulator and Ofcom’s remit under the OSA relates to content broadly, irrespective of how it is generated, including risks associated with recommender systems. Regulators also play a role through their horizon scanning programme, which has examined algorithms over the last three to four years and is now focusing on AI foundation models.
It was observed that the failure of the AI-copyright code so far, was a good example of attempting to find a compromise between the interests of the creative industry and of the AI companies. The issue had reached a policy pause, allowing room for reflection. Ideally, policy would be informed by balanced advice and impact assessments, in turn based on independent economic analysis. Yet sometimes a conflict simply cannot be resolved, and a political decision was needed based on a national vision.
It was suggested that the CMA’s and ICO’s consultations on AI seemed not entirely coordinated. Consultations address the implementation and deployment of technologies for different purposes, so by their very nature there will be differences. There may still be a benefit in individual consultations, instead of collective ones, to ensure each regulator obtains the information to inform their own needs, whilst making sure that they can coordinate a coherent approach to digital regulation.
The goals of innovation and a functioning public sphere
As innovation is not value neutral and all regulation inevitably affect innovation, how are the values underpinning desirable innovation determined, between parliament and regulators? Sometimes regulatory intervention effectively deems business-model innovation to be harmful. These considerations feature both in actual assessments and in reflections over the use upcoming regulatory tools. One approach to innovation sees it as a benefit of competition in practice, but there are also innovation-linked theories of harm, such as the reasonably-novel notion of predatory innovation, which has not been deployed in many contexts.
The CMA does not consider innovation in isolation, but through the lens of its statutory objectives and strategic sphere, both in terms of how it thinks about issues, but also in prioritising emerging markets, such as the AI foundation models, or whether to launch new investigations into the Microsoft – Open AI partnership. Ofcom in turn considered the impact of both innovation and regulation, balancing pros and cons based on stakeholder input.
The issue of applying standards of truth, accuracy and impartiality to all media, was raised, in context of digitisation and the emergence of AI use in the media.
For economists the question is not necessarily more or less regulation and innovation, but of good and bad regulation and innovation. Once the arrival of Open AI’s ChatGPT changed the landscape, everyone was in a reactive mode and the UK’s flexibility may be advantageous. The proof will be in the pudding. Will innovation happen in the UK? We tend to think that markets don’t want regulation, but innovation and investment require a lot of certainty.
Regulatory capture
The discussion turned to defining positive outcome amidst competing economic, social and human rights considerations. It was emphasised that regulators are creatures of statutes. What a good outcome looks like depends on the outcome that each regulator is required to fulfil. But in a general sense, an outcome that is proportionate, which is technologically feasible, addresses the concerns regulators have, works well for people that are using these services (consumer or business) and does not lead to unintended consequences. For an evidence-driven regulator, it is important that identified harms are addressed by the new regime and that specific circumstances inform good outcomes in particular sectors, from search engines to social media platforms, or messaging services.
Concerns were raised around which voices were heard and which ones were left out in the regulatory process, with a particular focus on surfacing issues for small players on platforms. In some academic circles, legislators were seen as fixated on innovation and too close to tech. Businesses may write their own rules through lobbying, while the UK government appeared to welcome a more recent trend towards direct rulemaking through codes of conduct and self-regulation. Such forms of ‘private ordering’ or law-making increasingly extended to what online content remained available and what was taken down. Reflection was invited on the risks of delegating too much to private business.
The problem of which voices are heard is not new. In policy creation, a range of inputs and consultations were said to be needed. Regulators may research consumers or engage in round tables such as this. For online safety in particular there’s a huge need and interest in academic contributions. Regulators are not engaging only with SMS firms, but trying to engage with challengers, as well as smaller scale enterprises. One of the challenges in reaching out to small innovators is that they typically do not have resources for public policy professionals. While for example the IPO’s open consultations aim to reach as many as possible, it is important to be realistic about the difficulties in reaching individuals and small businesses.
Concluding thoughts
The value of open conversations in a forum such as this roundtable was recognised, highlighting both the dynamics and constraints of the digital regulatory field. Reviewing regulatory innovation in the UK, expectations needed to be tempered about the depth and pace of developments. Forced by the pace of digital change, regulation was intensifying everywhere, yet capacity varied.
Regulatory crossovers were to be expected in response to similar questions and facilitated by international cooperation networks. Yet regulation is shaped decisively by the systems within which it developed. Relevant geopolitical effects ranged from the competition for convening power to the national securitization of the digital space, the latter acutely apparent in the trade in chips, as well as responses to foreign interferences in the democratic order.
Lastly, the balance of powers remains a critical issue, for example whether the executive (Secretary of State) should be able in effect to write the script. How can democratic accountability be assured, how can divergent voices be heard? Disparities of scale and the cost of entry into a discussion were highlighted, with smaller enterprises needing to develop a policy intervening capacity. Wider democratic participation into the regulatory discussion was to require a sort of levelling up.
Thinking about digital regulation is highly complex in this extremely dynamic moment and even more so from a cross-disciplinary position. To gain a diachronic perspective, please consult the summaries of the regulatory fora convened by CREATe in March 2023 and February 2020.
Participants of the CREATe Roundtable (Glasgow, 11 March 2024, 14:00-16:00)
Dr Jiahong Chen, Law, University of Sheffield
Bob Downes, Ofcom Board Member for Scotland
Prof. Michele Battisti, Applied Economics, Adam Smith Business School, University of Glasgow
Prof. Lilian Edwards, Law, Innovation & Society, Newcastle University
Prof. Gillian Doyle, Media Economics, Centre for Cultural Policy Research (CCPR), University of Glasgow
Prof. Giorgio Fazio, Macroeconomics, AHRC Creative Industries Policy & Evidence Centre (PEC), Newcastle University
Bernard Hay, Head of Policy, PEC, Newcastle University & RSA
David Humphries, Head of Research – Economics, Research and Evidence, Intellectual Property Office
Prof. Dinusha Mendis, Director, Centre for Intellectual Property Policy & Management (CIPPM), Bournemouth University
Prof. Guido Noto La Diega, Intellectual Property Law and Technology Law, University of Stirling
Chia Seiler, Public Policy Principal, Ofcom
Dr James Stewart, Science and Technology Studies, University of Edinburgh
Lord Wilf Stevenson, House of Lords, Labour Shadow, Dept for Science, Innovation and Technology
Prof. Ruth Towse, Economics of Creative Industries, Bournemouth University and CREATe Fellow in Cultural Economics
Robin Van Mulders, Principal Adviser, Digital Markets Unit, CMA
CREATe team
Prof. Martin Kretschmer (chair), Intellectual Property Law and Regulation
Prof. Philip Schlesinger (co-chair), Cultural Theory, CCPR
Dr Magali Eben, Competition Law, Deputy Director, CREATe
Prof. Kris Erickson, Social Data Science, Deputy Director, CREATe
Dr Arthur Ehlinger, Creative Industries
Dr Ula Furgał, IP & Information Law
Aline Iramina, Intellectual Property Law
Dr Zihao Li, Technology Law
Dr Stefan Luca, Platform Regulation
Dr Stavros Makris, Competition Law
Bartolomeo Meletti, Copyright Law
Prof. Konstantinos Stylianou, Competition Law and Regulation
Dr Amy Thomas, IP & Information Law