6 min read

Open-weight sovereignty, 'unprecedented' Meta and Bonta subpoenas

The need-to-know developments shaping digital platforms, online speech and internet safety - edition #358

Hello and welcome to Everything in Moderation's Week in Review, your in-depth guide to the policies, products, platforms and people shaping the future of online speech and the internet. It's written by me, and like you.

Today is like Christmas for EiM. The much-awaited Social Reckoning — the big-screen depiction of the leak of thousands of Facebook documents by civic integrity team member, Frances Haugen — comes out today.

I wrote about it when it happened (EiM #181 and others) and, ever since hearing there would be be a film, have been interested to see how Aaron Sorkin would depict both T&S workers and the subsequent WSJ reporting that emerged from the leaks. Having seen a preview here in London on Wednesday, there’s a fair bit to say.

My review will be in Monday's T&S Insider — with an extended version for EiM members — but drop me a line if you see it this weekend. And if the written word is more your thing, Alice and I have you covered.

In the meantime, here's what you need-to-know from the last week — BW


Policies

New and emerging internet policy and online speech regulation

Ofcom has announced an investigation under the Online Safety Act into Meta's launch of its disappearing photo feature, Instagram Instants. Launched in May to allow users "to share life’s moments with friends as they happen", it appears that the company hasn't carried out what the UK regulator calls "a suitable and sufficient content risk assessment and children's risk assessment". It marks the first time that Meta has been investigated under the OSA since it came into force in 2023 and the first enforcement measure targeted at a major social media platform by Ofcom since its TikTok investigation was announced in June.

Fraught words: It comes in the same week that Meta — alongside TikTok and X/Twitter — argued in court that Ofcom's requests for information created unprecedented regulatory burdens. I sympathise with the compliance and safety professionals preparing documentation for the regulator and don't see the long-term benefit of regulators posing overly broad asks. At the same time, I don't have unlimited supplies of empathy for the platforms; the stage of the UK enforcement regime — and the amount riding on it — meant Ofcom was always going to ask for more info than less. Politico has more.

Greece has said it can't wait for the EU KIDS Act (EiM #355) to come into place and is moving ahead with its own social media ban for under 16s. The country's Digital Governance Minister also told media this week that it would push for AI chatbots to be added to the bloc-wide act, despite unclear evidence for its inclusion and the fact that Greece last year made a massive push for OpenAI to be integrated into its education system — much to the anger of students.

Also in this section...

CTA Image

In this week's Ctrl-Alt-Speech Podcast....

Patreon supporters can already listen to this week's episode with a freshly returned Mike Masnick, a splash of Sonic The Hedgehog and an extended look at what happened at Disinfo 2026 in Lithuania this week.

Whether you think the United States should be classed as foreign interference or otherwise, have a listen.

LISTEN TO THE EXTENDED EPISODE

Products

Features, functionality and technology shaping online speech

The tech sovereignty debate traditionally reserved for government policy and regulation is becoming a not-so-subtle part of new open weight model releases. This week, there were two announcements that made that apparent:

  • French AI lab Mistral released ML4 — otherwise called "Le Chonk" for its hefty size — which specialises in cybersecurity and defence capabilities and claims to be the most developed open model outside of China. It's co-founder and Chief Science officer played down the debate "over [models from] the US, versus Europe, versus China" but still framed the new release that the company was "still in the race of getting the best model" — by which he presumably means versus US and Chinese companies.
  • US lab Reflection released its first open weight model, Beam, with a focus on agentic and coding tasks. But the model is ultimately in service of its 'AI factories' idea; it has been working on with the Republic of Korea to build its own model, trained on Korean data and deployed across national infrastructure.

Risky business?: It's worth remembering that, for all the innovation benefits, there are trade-offs with open models. Safeguards that might be baked into a closed model can more easily be removed when it can be run locally, which makes things like better filtered training data and more stringent release audits more important. The UK's AISI published a good guide and checklist last year.

Also in this section...

T&S workers are picking up the pen
For years, academics and lawyers have written the books that explain T&S to the public. A run of new titles from people who’ve done the work could change that. Here are six we’re reading

Platforms

Social networks and AI labs and the application of content guidelines

[warning: distressing details] TikTok is under the spotlight for its child safety policy enforcement after UK magazine Prospect identified 176 TikTok accounts, collectively followed by more than two million people, that acted as contact points for trading or selling child sexual abuse material (CSAM) via Telegram and other messaging apps. Innocuous LGBTQ+ hashtags were hijacked to grow the account followings while potential buyers used algospeak like 'cheese pizza' to evade takedowns and bans.

Whack-a-mole: One particular detail stood out: 35 of the accounts found by the reporter used a headshot image of a red-haired man called Matthew Estes, who, it turns out, is a convicted sex offender serving 60-years in prison. His image was being used as a calling card to CSAM buyers but that would have been almost impossible to detect without the context of his crime and imprisonment.

One thing I'm following closely is the debate around whether Claude is conscious (I'm on the 'no' side, if you're asking) and what that means for users' interactions with it. Anthropic clearly has a view; as reported by The Verge, it announced policy changes this week that including preventing "sustained and needless abusive or cruel behaviour" towards its model. CEO Dario Amodei previously said "we don't know if models are conscious".

Also in this section...

People

Those impacting the future of online safety and moderation

Rob Bonta doesn't believe the AI industry’s narrative that model safety is purely an engineering problem.

Last week, California’s attorney general served an investigative subpoena to OpenAI seeking information about the security of its models and the risks they pose. It follows the Hugging Face attack (EiM #353) and subsequent reports of models accessing government websites without authorisation.

Bonta told Politco that this "fact gathering process" needs to take place before determining "what we do next" — which, from other quotes, sounds like it could focus on product liability and consumer protection. New York's attorney general has pursued a similar line, presumably encouraged by the mass Meta settlement in August (EiM #352).

OpenAI is still investigating the hack and could take "months" to come to a conclusion,. As it does so, the company has sent incident notices to more than 100 organisations after models bypassed controls or disrupted services.

Posts of note (INHOPE summit edition)

Handpicked posts that caught my eye this week

  • "My core message was that the people exploiting young people online don't respect our silos. They build their operations in the gaps between hotlines, platforms, law enforcement, regulators and researchers." - Resolver's Henry Adams on giving the keynote at the 9th annual INHOPE conference in Dublin.
  • "The convergence of harms online is personified in the COM environment and siloed thinking within the law enforcement and the public health model (the ultimate solution with early intervention) or in Industry is a key weakness in response." - Mick Moran, CEO of Irish Internet Hotline, would like a more joined up approach.
  • "We’re ready to work with any new tech who want to build in deterrence messaging as a key layer in their prevention work." - Sarah Smith from the Lucy Faithfull Foundation on one of its impactful interventions. Work checking out if you're not familiar.