Government & Policy

EU watchdog questions secrecy around lawmakers’ encryption-breaking CSAM scanning proposal

Comment

Artificial intelligence technology futuristic background. Green binary coding letters on black.
Image Credits: cundra / Getty Images

The European Commission has again been urged to more fully disclose its dealings with private technology companies and other stakeholders, in relation to a controversial piece of tech policy that could see a law mandate the scanning of European Union citizens’ private messages in a bid to detect child sexual abuse material (CSAM).

The issue is of note as concerns have been raised about lobbying by the tech industry influencing the Commission’s drafting of the controversial CSAM-scanning proposal. Some of the information withheld relates to correspondence between the EU and private firms that could be potential suppliers of CSAM-scanning technology — meaning they stand to gain commercially from any pan-EU law mandating message scanning.

The preliminary finding of maladministration by the EU’s ombudsman, Emily O’Reilly, was reached on Friday and made public on its website yesterday. Back in January, the ombudsman came to a similar conclusion — inviting the Commission to respond to its concerns. Its latest findings factor in the EU executive’s responses and invite the Commission to respond to its recommendations with a “detailed opinion” by July 26 — so the saga isn’t over yet.

The draft CSAM-scanning legislation, meanwhile, remains on the table with EU co-legislators — despite a warning from the Council’s own legal service that the proposed approach is unlawful. The European Data Protection Supervisor and civil society groups have also warned the proposal represents a tipping point for democratic rights in the EU. While, back in October, lawmakers in the European Parliament who are also opposed to the Commission’s direction of travel proposed a substantially revised draft that aims to put limits on the scope of the scanning. But the ball is in the Council’s court as Member States’ governments have yet to settle on their own negotiating position for the file.

Europe’s CSAM-scanning plan is a tipping point for democratic rights, experts warn

In spite of growing alarm and opposition across a number of EU institutions, the Commission has continued to stand behind the controversial CSAM detection orders — ignoring warnings from critics the law could force platforms to deploy client-side scanning, with dire implications for European web users’ privacy and security.

An ongoing lack of transparency vis-à-vis the EU executive’s decision-making process when it drafted the contentious legislation hardly helps — fueling concerns that certain self-interested commercial interests may have had a role in shaping the original proposal.

Since December, the EU’s ombudsman has been considering a complaint by a journalist who sought access to documents pertaining to the CSAM regulation and the EU’s “associated decision-making process”.

After reviewing information the Commission withheld, along with its defence for the non-disclosure, the ombudsman remains largely unimpressed with the level of transparency on show.

The Commission released some data following the journalist’s request for public access but withheld 28 documents entirely and, in the case of a further five, partially redacted the information — citing a range of exemptions to deny disclosure, including public interest as regards public security; the need to protect personal data; the need to protect commercial interests; the need to protect legal advice; and the need to protect its decision-making.

According to information released by the ombudsman, five of the documents linked to the complaint pertain to “exchanges with interest representatives from the technology industry”. It does not list which companies were corresponding with the Commission, but U.S.-based Thorn, a maker of AI-based child safety tech, was linked to lobbying on the file in an investigative report by BalkanInsights last September.

Other documents in the bundle that were either withheld or redacted by the Commission include drafts of its impact assessment when preparing the legislation; and comments from its legal service.

When it comes to info pertaining to the EU’s correspondence with tech companies, the ombudsman questions many of the Commission’s justifications for withholding the data — finding, for example in the case of one of these documents, that while the EU’s decision to redact details of the information exchanged between law enforcement and a number of unnamed companies may be justified on public security grounds there is no clear reason for it to withhold the names of companies themselves.

“It is not readily clear how disclosure of the names of the companies concerned could possibly undermine public security, if the information exchanged between the companies and law enforcement has been redacted,” wrote the ombudsman.

In another instance, the ombudsman takes issue with apparently selective info releases by the Commission pertaining to input from tech industry reps, writing that: “From the very general reasons for non-disclosure the Commission provided in its confirmatory decision, it is not clear why it considered the withheld ‘preliminary options’ to be more sensitive than those that it had decided to disclose to the complainant.”

The ombudsman’s conclusion at this point of the investigation repeats its earlier finding of maladministration on the Commission for refusal to give “wide public access” to the 33 documents. In her recommendation, O’Reilly also writes: “The European Commission should re-consider its position on the access request with a view to providing significantly increased access, taking into account the Ombudsman’s considerations shared in this recommendation.”

The Commission was contacted about the ombudsman’s latest findings on the complaint but at press time it had not provided a response.

EU lawmakers under pressure to fully disclose dealings with child safety tech maker, Thorn

More TechCrunch

WazirX, one of India’s largest cryptocurrency exchanges, has “temporarily” suspended all trading activities on its platform days after losing about $230 million, nearly half of its reserves, in a security…

WazirX halts trading after $230 million ‘force majeure’ loss

Featured Article

From Yandex’s ashes comes Nebius, a ‘startup’ with plans to be a European AI compute leader

Subject to shareholder approval, Yandex N.V. is adopting the name of one of its few remaining assets, an AI cloud platform called Nebius AI which it birthed last year.

From Yandex’s ashes comes Nebius, a ‘startup’ with plans to be a European AI compute leader

Employees at Bethesda Game Studios — the Microsoft-owned game developer that produces the Elder Scrolls and Fallout franchises — are joining the Communication Workers of America. Quality assurance testers at…

Bethesda Game Studios employees form a ‘wall-to-wall’ union

This week saw one of the most widespread IT disruptions in recent years linked to a faulty software update from popular cybersecurity firm CrowdStrike. Businesses across the world reported IT…

CrowdStrike’s update fail causes global outages and travel chaos

Alphabet, the parent company of Google, is in advanced talks to acquire cybersecurity startup Wiz for $23 billion, the Wall Street Journal reported on Sunday. TechCrunch’s sources heard similar and…

Unpacking how Alphabet’s rumored Wiz acquisition could affect VC

Around 8.5 million devices — less than 1 percent Windows machines globally — were affected by the recent CrowdStrike outage, according to a Microsoft blog post by David Weston, the…

Microsoft says 8.5M Windows devices were affected by CrowdStrike outage

Featured Article

Some Black startup founders feel betrayed by Ben Horowitz’s support for Trump

Trump is an advocate for a number of policies that could be harmful to people of color.

Some Black startup founders feel betrayed by Ben Horowitz’s support for Trump

Featured Article

Strava’s next chapter: New CEO talks AI, inclusivity, and why ‘dark mode’ took so long

TechCrunch sat down with Strava’s new CEO in London for a wide-ranging interview, delving into what the company is prioritizing, and what we can expect in the future as the company embarks on its “next chapter.”

Strava’s next chapter: New CEO talks AI, inclusivity, and why ‘dark mode’ took so long

Featured Article

Lavish parties and moral dilemmas: 4 days with Silicon Valley’s MAGA elite at the RNC

All week at the RNC, I saw an event defined by Silicon Valley. But I also saw the tech elite experience flashes of discordance.

Lavish parties and moral dilemmas: 4 days with Silicon Valley’s MAGA elite at the RNC

Featured Article

Tracking the EV battery factory construction boom across North America

A wave of automakers and battery makers — foreign and domestic — have pledged to produce North American–made batteries before 2030.

Tracking the EV battery factory construction boom across North America

Featured Article

Faulty CrowdStrike update causes major global IT outage, taking out banks, airlines and businesses globally

Security giant CrowdStrike said the outage was not caused by a cyberattack, as businesses anticipate widespread disruption.

Faulty CrowdStrike update causes major global IT outage, taking out banks, airlines and businesses globally

CISA confirmed the CrowdStrike outage was not caused by a cyberattack, but urged caution as malicious hackers exploit the situation.

US cyber agency CISA says malicious hackers are ‘taking advantage’ of CrowdStrike outage

The global outage is a perfect reminder how much of the world relies on technological infrastructure.

These startups are trying to prevent another CrowdStrike-like outage, according to VCs

The CrowdStrike outage that hit early Friday morning and knocked out computers running Microsoft Windows has grounded flights globally. Major U.S. airlines including United Airlines, American Airlines and Delta Air…

CrowdStrike outage: How your plane, train and automobile travel may be affected

Prior to the ban, Trump’s team used his channel to broadcast some of his campaigns. With the ban now lifted, his channel can resume doing so.

Twitch reinstates Trump’s account ahead of the 2024 presidential election

This week, Google is in discussions to pay $23 billion for cloud security startup Wiz, SoftBank acquires Graphcore, and more.

M&A activity heats up with Wiz, Graphcore, etc.

CrowdStrike competes with a number of vendors, including SentinelOne and Palo Alto Networks but also Microsoft, Trellix, Trend Micro and Sophos, in the endpoint security market.

CrowdStrike’s rivals stand to benefit from its update fail debacle

The IT outage may have an unexpected effect on the climate: clearer skies and maybe lower temperatures this evening

CrowdStrike chaos leads to grounded aircraft — and maybe an unusual weather effect

There’s a man in Florida right now who wants to propose to his girlfriend while they’re on a beach vacation. He couldn’t get the engagement ring before he flew down…

The CrowdStrike outage is a plot point in a rom-com 

Here’s everything you need to know so far about the global outages caused by CrowdStrike’s buggy software update.

What we know about CrowdStrike’s update fail that’s causing global outages and travel chaos

This serves as an example for how easy it is to spread inaccurate information online during a time of immense global confusion and panic.

From the Sphere to false cyberattack claims, misinformation runs rampant amid CrowdStrike outage

Today is the final chance to save up to $800 on TechCrunch Disrupt 2024 tickets. Disrupt Deal Days event will end tonight at 11:59 p.m. PT. Don’t miss out on…

Last chance today: Secure major savings for TechCrunch Disrupt 2024!

Indian fintech Paytm’s struggles won’t seem to end. The company on Friday reported that its revenue declined by 36% and its loss more than doubled in the first quarter as…

Paytm loss widens and revenue shrinks as it grapples with regulatory clampdown

J. Michael Cline, the co-founder of Fandango and multiple other startups over his multi-decade career, died after falling from a Manhattan hotel, New York’s Deputy Commissioner of Public Information tells…

Fandango founder dies in fall from Manhattan skyscraper

Venture capital giant a16z fixed a security vulnerability in one of the firm’s websites after being warned by a security researcher.

Researcher finds flaw in a16z website that exposed some company data

Apple on Thursday announced its upcoming lineup of immersive video content for the Vision Pro. The list includes behind-the-scenes footage of the 2024 NBA All-Star Weekend, an immersive performance by…

Apple Vision Pro debuts immersive content featuring NBA players, The Weeknd and more

Biden centering Musk in his campaign is a notable escalation, considering he spent most of his presidency seemingly pretending the billionaire didn’t exist.

Elon Musk is now a villain in Joe Biden’s presidential campaign

Waymo would need a ground transportation permit to operate at SFO, which has yet to be approved.

Waymo wants to bring robotaxis to SFO, emails show

When Tade Oyerinde first set out to fundraise for his startup, Campus, a fully accredited online community college, it was incredibly difficult. VCs have backed for-profit education companies in the…

Why it made sense for an online community college to raise venture capital

Canadian private equity firm PartnerOne paid $28.2 million for HeadSpin, a mobile app testing startup whose founder was sentenced for fraud earlier this year, according to documents viewed by TechCrunch.…

PE firm PartnerOne paid $28M for HeadSpin, a fraction of its $1.1B valuation set by ICONIQ and Dell Technologies Capital