4 min read

Online safety regulation as community policing

A recent edition of T&S Insider called for regulators to spend more time at industry events like TrustCon. One EiM reader argues that merely showing up isn't enough.

I'm Ben Whitelaw, the founder and editor of Everything in Moderation*. I'm dropping in for Alice in this week's Trust & Safety Insider.

A couple of weeks ago, I shared my thoughts about the challenges of regulators attending industry events. It prompted a flurry of emails and direct messages, including from a number of regulators themselves.

One EiM reader had a different take on how regulators should engage with the T&S community, and agreed for me to share it here. As ever, thoughts and pushback are welcome.

A reminder that there is no Week in Review this week as I'm on holiday. But the most pressing stories are nestled at the bottom of today's edition. Thanks for reading — Ben


Regulators at TrustCon? A response

Why this matters: There’s a broader debate in T&S about regulatory enforcement: whether bodies like the eSafety Commission and Ofcom are doing enough to hold intermediaries to account, or whether their resources and powers simply are sufficient for what they’re being asked to do. Part of that debate is about the relationships regulators should have with the companies that they oversee — including at industry conferences.

Ailís Daly is head of Trust & Safety at WebPurify and host of the Trust Issues podcast. She has previously had T&S roles at TikTok, AirBnb and Twitter and is a qualified barrister.

Owen's diagnosis is right as far as it goes. Regulators do get stonewalled. The government relations function exists, in part, to stand between officials and the people who actually build and run Trust & Safety operations. And T&S teams genuinely are regulators' best allies inside these companies — nothing focuses a product roadmap like a legal obligation someone else wrote.

But collaboration is a two-way street, and the traffic has been moving in one direction. Practitioners are asked to be candid about what isn't working; meanwhile, regulators, understandably, stick to their published positions. I don't believe that to be anyone's bad faith. It's the product of institutional incentives on both sides — and it's worth naming because it limits what either side gains from being in the same room.

My consistent observation of European and UK regulators — as institutions, and as the individuals who work for them — is that they arrive at industry events with real constraints on what they can say. The brief is usually for them to listen rather than to speak. Which means much of what does get shared publicly stays close to material that has already been published, and practitioners hear a familiar version of it across different gatherings. It's rarely a window into how the regulator is actually thinking, what it's finding genuinely difficult, or where it knows it's operating at the edge of its expertise. The effect is to establish presence and to restate the consequences of getting things wrong.

Last year, at an off-the-beaten-track event that EiM co-hosted (a lovely, slightly dingy fourth-floor bar on Commercial Road, perhaps chosen because it was the kind of room where people might actually say what they think), I asked a regulatory staffer whether they were working on anything interesting. The answer, delivered plainly over screwtop Pinot Grigio (which I love FYI), was that they'd just issued a fine. It felt like cop talk. It also felt like a missed opportunity — is this how you build trust? And trust is the entire point of showing up.

So here's the model I'd suggest, and it isn't the financial services one that online safety regulators seem to be adopting. Think community policing rather than counter-intelligence. The officer who is known, who is present, who is part of the community and there to help; not the plain-clothes presence taking notes at the back of the room. The current posture leans towards watching. I think there's more value in participating.

Which brings me to Ben's point about chilling effects, and his hunch about lanyards. He's right that candour suffers when practitioners suspect they're being observed rather than met. But the answer to that isn't segregating regulators with a different colour badge, and it isn't their absence either. Perhaps, its changing the terms of the exchange.

TSPA could run a regulator track or even a regulator room. Off the record, Chatham House, sign up in advance and understand what you're agreeing to. Officials share what they're genuinely wrestling with; practitioners do the same. I'm aware that what I'm describing-everyone in one room, honest about what's not working, no minders-is unlikely to survive contact with a single legal team on either side. But a T&S veteran should be allowed dream, right?

You regulatin' me?

Got thoughts on how regulators and T&S practitioners should work together? I want to hear them.

Get in touch

Also worth reading

French court blocks social media ban for under 15s (Politico)
Why? The ban was supposed to be Macron's big finale and the push for the EU to hurry along its own cross-bloc teen ban. What's French for "spanner in the works"?

Vietnam Tightens Online Speech Controls as Cyber Law Takes Effect (Tech Policy Press)
Why? All eyes have been on the different ways that the US and EU have approach mis- and disinformation but it's important not to forget about what's happening elsewhere. Vietnam's new Cybersecurity Law is one to know about.

Federal Court Rules That Blocking Speech Is Protected By The First Amendment, But Recommending It Isn’t (Techdirt)
Why? A Californian judge who called algorithmic feeds "a mirror" gets the full Mike Masnick takedown.

Instagram Is Still Drowned in Creepy Smart Glasses Content (Gizmodo)
Why? I'm sure this headline should say "drowning". That aside, it makes for an interesting T&S challenge: how do you detect and remove often misogynistic pick-up content at scale? And if you're a Meta T&S professional: how do you that knowing it was created from a device by your parent company?