Democratic Defense Against Disinformation 2.0


his second edition of the paper, Democratic media companies, and civil-society groups invest in Defense Against Disinformation, seeks to cap- long-term resilience against disinformation, including ture the rapid development of policy responses raising social awareness of disinformation and encour- to the challenge—especially by governments aging digital literacy education, including how to dis- Tand social media companies—since initial publication cern fabricated or deceptive content and sources. in February 2018. The authors stand by the fundamen- tals of the earlier analysis and recommendations: that Democratic Defense Against Disinformation 2.0 will re- democratic societies can combat and mitigate the view developments over the past year, assess their ef- challenge of foreign disinformation while working with- fectiveness thus far, and offer suggestions for next steps. in democratic norms and respect for freedom of ex- pression. The first edition offered a “whole-of-society” Framing Solutions (Against a Moving Target) vision, with policy suggestions for governments, social media companies, and civil-society groups. Since pub- Vladimir Putin’s was perhaps first among lication of the first edition, the (EU) major powers to deploy techniques of full-spectrum, and, to a lesser degree, the US government, have taken state-sponsored disinformation for the digital age—the actions that parallel some of these suggestions. For intentional spread of inaccurate information designed their part, social media companies have moved from to influence societies. It will not be the last. Other state an initial and unsustainable denial of the problem to a actors with perhaps greater capabilities, such as , stance of willingness to help deal with it, though the and nonstate actors, such as terrorist groups with a depth of this commitment (and the effectiveness of the higher tolerance for risk, will adapt the disinformation responses) has yet to be determined. toolkit to undermine or are already doing so. There is nothing new about state and Collectively, democracies have moved beyond “admir- other means of political subversion (“” ing the problem,” meaning a sort of existential despair in was the term of art for Soviet efforts of this kind). But, the face of a new threat not easily managed. They have digital and social media, in combination with more tra- now entered a period of “trial and error,” in which new ditional methods, offer new means to achieve traditional ideas and solutions for countering, and building resil- ends. Russia’s democratic and pro-Western neighbors, ience against, disinformation are being tested, though especially Ukraine, , and the Baltic states, have unevenly and with setbacks. Meanwhile, the disinforma- contended with Russian disinformation attacks for years. tion challenge has evolved and advanced, as state and nonstate actors deploy new technologies, develop new Other targets of state-sponsored disinformation cam- methods of exploitation, and adapt to responses. paigns—the United States and some Western European countries—woke up late to the challenge, with the Supply and demand of disinformation. Many of our United States doing so only after its 2016 presidential recommendations address the “supply side” of disin- , in which Russia played a large and malign role. formation; i.e., they recommended, and continue to The Department of Justice Special Counsel Report1 and recommend, policies and actions to limit the influx of two independent reports, prepared for the US Senate’s disinformation into US and other media ecosystems. Select Committee on Intelligence and published in But, tools to block disinformation will be imperfect, December 2018, detail Russia’s disinformation tactics and some degree of disinformation will be part of the during and after the 2016 US , including by media landscape for the indefinite future. Addressing the Russian-government-supported Internet Research the “demand side” of disinformation—i.e., reducing Agency (IRA), the now-notorious St. Petersburg troll general social acceptance of fabrications and distor- farm.2 The February 2018 Department of Justice in- tions—is likely to be more important for sustained so- dictment of thirteen Russian operatives involved in the cietal immunity. It is critical that governments, social IRA information operations provides the most in-depth

democratic societies. As such, they don’t stop when the ballot box closes. Still, due to the high level of at- tention and consequential outcomes, elections provide an ideal high-impact opportunity for this type of influ- ence operation.

Ahead of elections throughout Europe and North America in 2019 and 2020, governments, social media companies, and civil-society groups must learn from each other and accelerate the implementation of best practices to defend against disinformation.

Democracies are learning that means of defense and norms of resilience applicable to traditional propa- ganda and subversion are inadequate to meet the present danger. Also, disinformation techniques will continue to evolve. For example, innovation in (AI) is producing “” and other “synthetic media” products—video and audio manipu- lation with the capability to manufacture the appear- ance of reality, such as nonexistent, but real-looking, remarks by a political leader. As these tools become more low cost and accessible, they will become perfect weapons for information warfare.4 Such technologies could drive the next great leap in AI-driven disinfor- mation.5 More generally, disinformation techniques are shifting from the use of simple automated bots to Vladimir Putin’s Russia was perhaps first among major powers more sophisticated interaction with (and manipulation to deploy techniques of full-spectrum, state-sponsored disinformation for the digital age—the intentional spread of of) domestic groups, extremist and otherwise, through inaccurate information designed to influence societies. various forms of impersonation and amplification of Photo Credit: The Russian Presidential Press and Information organic posts by domestic actors. Thus, it may be in- Office creasingly difficult to disentangle foreign-origin disin- formation from domestic social media conversations. Rather than trying to break through the noise, the new strategy aims to blend in with the noise—obfuscating research to date about the internal machinery of the manipulative activity and blurring the line between au- Russian operation.3 thentic and inauthentic content.

Exposure is not enough. Disinformation campaigns are The first edition ofDemocratic Defense Against Disinfor- not going away. Quite the opposite—other malicious mation offered recommendations on ways democratic state actors with an interest in undermining democra- governments and free societies can combat disinfor- cies, including Iran, North Korea, and China, are learn- mation, while respecting the norms and values of free ing from Russian tactics. Meanwhile, the tools of attack expression and the rule of law.6 As democratic countries are evolving and adapting to democratic responses. learned in the struggle against Soviet communism, we State-sponsored disinformation campaigns aim to need not become them to fight them: democratic so- amplify existing social divisions and further polarize cieties should not fight propaganda with propaganda,

nor should they turn to censorship. Freedom of ex- known propaganda content and suspect or misla- pression and US First Amendment protections do not beled content, based on findings from third-party rob free societies of options. US law prohibits foreign fact checkers. participation in US elections, broadly defined, and per- mits extensive regulation of commercial advertisements ■ Civil society groups, especially the tech-savvy (e.g., outright bans on broad categories, such as smok- “digital Sherlocks” skilled at identifying disinforma- ing). In general, foreign persons, especially outside the tion—such as Ukraine’s StopFake, Bellingcat, the United States, do not enjoy full First Amendment pro- Atlantic Council’s Digital Forensic Research Lab, the tections. Automated (e.g., bot) social media accounts Alliance for Security ’s Hamilton 68, EU also do not necessarily have First Amendment rights. DisinfoLab, and the Baltic Elves—have proven skilled EU/European options are still broader and include legal at identifying coordinated disinformation activity and regulatory options for enforcing versions of media driven by inauthentic accounts, often in real time.7 fairness and impartiality. And, in some countries this They, and other innovative startups, are better able includes authority to ban certain forms of hate speech, than governments to develop the tools to identify though this has drawbacks. emerging disinformation techniques (e.g., synthetic media and deepfakes). Governments, social media This paper’s initial recommendations covered three lev- companies, and philanthropic organizations should els of action, summarized below: fund such innovators and establish regular lines of communication with them, e.g., through designated ■ Governments, starting with the United States, Eu- points of contact. ropean national governments, the EU, and NATO, should introduce and enforce transparency standards, The paper’s biggest single recommendation was that the including with respect to foreign-origin political and United States and EU establish a Counter-Disinformation issue ads on both traditional and social media, and Coalition, a public/private group bringing together, on otherwise monitor and notify their publics in real time a regular basis, government and non-government stake- about the activities of foreign propaganda outlets. holders, including social media companies, traditional To that end, governments should establish “rapid-re- media, Internet service providers (ISPs), and civil soci- sponse task forces” to inform government officials ety groups. The Counter-Disinformation Coalition would and, as needed, allies, of emerging disinformation develop best practices for confronting disinformation campaigns that threaten . Govern- from nondemocratic countries, consistent with demo- ments should also expand institutional capacity, cratic norms. It also recommended that this coalition building on the EU’s East StratCom, NATO’s StratCom start with a voluntary code of conduct outlining princi- Center of Excellence in Riga, the Helsinki Hybrid Cen- ples and agreed procedures for dealing with disinforma- ter of Excellence, the Department of Homeland Secu- tion, drawing from the recommendations as summarized rity’s task force to counter malign foreign influence, above. and the US State Department’s Global Engagement Center, to identify and expose Russian and other dis- In drawing up these recommendations, we were aware information campaigns. that disinformation most often comes from domestic, not foreign, sources.8 While Russian and other disinfor- ■ Social media companies have a responsibility to mation players are known to work in coordination with stop denying and start mitigating the problem of domestic purveyors of disinformation, both overtly and foreign disinformation. The paper specified that covertly, the recommendations are limited to foreign they should: identify and label overt foreign pro- disinformation, which falls within the scope of “polit- paganda outlets (RT and Sputnik, for example) as ical warfare.” Nevertheless, it may be that these pol- state-sponsored content; experiment with labeling icy recommendations, particularly those focused on and taking down automated and fake accounts; and transparency and social resilience, may be applicable redesign to demote, de-rank, or mute to combatting other forms of disinformation.

he initial paper noted that the West’s response ■ “Tackling Online Disinformation: a European Ap- to disinformation was developing rapidly, albeit proach,” prepared by the EU Commission and pub- from a low baseline, and anticipated significant lished on April 26, 2018;9 policy progress soon. This (admittedly easy) Tprediction has been borne out, though in unexpected ■ a voluntary “Code of Practice on Disinformation” ways. The European Union has moved faster than antic- prepared by the EU Commission, published on Sep- ipated to outline and seek to operationalize solutions, tember 26, 2018, and accepted on October 16 by though it is too early to judge the implementation or Facebook, , , and Mozilla, as well as impact. The United States—perhaps reflecting the do- European trade associations representing online mestic political complexity of addressing Russian dis- platforms and the advertising industry;10 information given the controversy over the 2016 US presidential election—has struggled to frame consis- ■ an EU Commission “Progress Report” on imple- tent policy responses, though the US administration has mentation of the April recommendations published started to act at the operational level. Social media com- December 5, 2018;11 and panies, stung by their initial (and risible) denial of the disinformation problem and a host of other embarrass- ■ the “Action Plan against Disinformation” jointly pre- ing news about their questionable behavior, have sought pared by the EU Commission and European External to be seen as, and possibly to be, part of the solution. Action Service (the EU “foreign ministry”), also pub- lished on December 5, 2018.12 Europe Seeks Solutions Taken together, these documents lay out principles European assessments of the disinformation challenge and action items that, if implemented and sustained continue to vary. Prompted by experiences in recent by political will, would mark the end of Europe’s ad- elections, some EU member states are now aware of miring the problem of disinformation and the begin- Russia’s aggressive disinformation tactics and deter- ning of its credible efforts to contain and reverse it. mined to deal with them (the Baltic states, United The December papers are significantly stronger than Kingdom, Sweden, Finland, Denmark, and possibly the initial April report, which is an encouraging indica- France and others). Some member states that earlier tor of policy momentum in Brussels and key capitals. believed that state-sponsored disinformation had noth- The EU appeared to be driven in part by determina- ing to do with them now know that it does (e.g., Spain, tion to have in place at least preliminary defensive after learning of Russian involvement in the Catalonia measures prior to the May 2019 European elections, referendum, and some in Greece in the aftermath of especially given the knowledge that Russian disinfor- Russian efforts to derail the Greek-North Macedonia mation campaigns were amplifying European extremist agreement resolving the issue of North Macedonia’s groups, while undermining establishment parties and name). Others appear to remain in a state of denial centrists. Aggressive Russian use of disinformation to about the challenge. These differences of assessment cover up its use of nerve gas in an attempt to mur- are reflected in the EU’s internal debates. der a former Russian intelligence officer in Salisbury, (UK), in March 2018 also appears to Given this background, the EU’s progress in framing have contributed to Europe’s determination to address solutions to the disinformation challenge is impressive. the disinformation challenge. The EU’s policy approach to countering disinformation is contained in the following documents, all prepared The EU’s principles in countering disinformation include in 2018: fidelity to freedom of expression. Its recommended

European Commission progress reports covering implementation of the Code of Practice by social media company signatories indicate a mixed picture.

actions focus on transparency, exposure of disinfor- and designated links to each member state govern- mation, and encouragement of social media compa- ment, as well as less-specified means to exchange nies (with an implied warning of regulatory mandates) information with NATO and Group of Seven (G7) to help by identifying and combatting, rather than governments. The RAS’ mandate will include pro- accommodating, abuse of their platforms by malign viding alerts about disinformation campaigns, both Russian and other disinformation actors. The EU’s ap- publicly and officially. EU experts are thinking of -ex proach is consistent with the fundamentals of the ini- panding the RAS’ links to independent fact-check- tial paper. ing and other independent groups, though this will apparently not be part of the RAS’ initial capability. The major elements of EU-proposed action include the The EU also intends to press social media platforms following. to cooperate with the RAS. The EU “Action Plan” called for the RAS to have an initial operational ca- ■ Strengthening EU capacity to identify and expose pacity—probably meaning links to member state disinformation. This includes a call to double the bud- governments—by March 2019, two months before get for strategic communications and increase person- the EU parliamentary elections. As of early April nel prior to future European parliamentary elections. 2019, the RAS appeared to exist mostly on paper, The EU’s EastStratCom unit, based in Brussels, has a though there is hope that this will change. mandate to identify and expose Russian disinforma- tion, but has lacked consistent political support and, ■ Launch of a voluntary “Code of Practice on Disin- perhaps as a result, has been inadequately resourced. formation,” agreed to by key social media compa- Happily, this appears to be changing. nies. The code’s language is general and, in some cases, calls only for indirect steps; it has been crit- ■ Establishment of a new EU rapid alert system (RAS) icized on that basis. However, the code is the most to expose current disinformation campaigns in real ambitious effort to date to specify policy norms for time. This new mechanism is supposed to have a social media companies to mitigate the exploitation capacity for real-time response to disinformation of their platforms by purveyors of disinformation. Its

effectiveness will depend, in part, on whether the EU outlined in the code. But, it also noted insufficient has political will to insist on action to implement its information provided by social media companies, laudable objectives, given its general, non-binding and urged specific next steps, including calling on terms. EU officials appear aware of the challenge, platforms to take more serious actions to address and the EU documents make explicit that if the code transparency, particularly with respect to political proves ineffective, the next step may be formal regu- ads. The commission is issuing monthly progress re- latory action. The policy commitments cover several ports to test social media companies’ response to aspects. their commitments.13

◆ Scrutiny of ad placements, including restricting ■ Improving social resilience against disinformation, placement of ads by demonstrated purveyors of including: creating a European network of indepen- disinformation, with determinations made in co- dent fact checkers; launching a secure online plat- operation with fact-checking organizations; form addressing disinformation; exploring means of reliable identification of information suppliers; ◆ Transparency of political and issue-based adver- and supporting long-term social media literacy. tisements. These should be accurately labeled, Supporting nongovernment, independent fact check- and their sponsors identified; ers and researchers—e.g., the existing civil society groups that already possess the skills to expose ◆ Integrity of services, meaning that social media disinformation campaigns, or journalists’ associa- companies have committed to put in place poli- tions—and potentially bringing them into close co- cies to identify and remove fake accounts, includ- operation with the official rapid alert system, is a ing bots; sound idea. However, government bodies, even the relatively nimble EastStratCom team, are unlikely to ◆ Empowering consumers, meaning that social match the best civil society groups in cutting-edge media companies have committed to “help peo- techniques for uncovering disinformation. The EU ple make informed decisions,” inform users of po- may also want to empower its researchers to obtain tential disinformation, and increase transparency. access to social media company data, as is provided This is the weakest commitment in the code, long in a general way in the Code of Practice. As of late on generalities and short on specifics. It does not, March, little progress was reported in implementing for example, require social media companies to this objective. de-rank or mute known deceptive sites; and In addition, in a wide-ranging article on Europe pub- ◆ Empowering the research community, meaning lished March 4, 2019, French President Emmanuel that social media companies will support inde- Macron proposed a new “European Agency for the pendent “good-faith” efforts to research disinfor- Protection of Democracies,” which included provid- mation. This does not constitute a commitment ing each EU member state with expertise to protect to provide key information, e.g., algorithms about election processes against cyberattacks and manipu- placement of information, but merely “not to pro- lation.14 While his proposals did not go into detail, and hibit or discourage” such research. may be only notional, his engagement could boost EU efforts to turn its policy framework into action. ■ European Commission progress reports covering implementation of the Code of Practice by social The G7 in the Game media company signatories indicate a mixed pic- ture. The commission has recognized efforts by so- The Canadian G7 Summit in June 2018 produced the cial media platforms to take down fake accounts, “Charlevoix Commitment on Defending Democracy restrict ad purchasing by purveyors of disinforma- from Threats,” which included general language tion, identify and block inauthentic behavior, and about cooperation to share lessons and information take other steps to meet the (general) commitments to counter disinformation, including a commitment to

The Canadian G7 Summit in June 2018 produced the “Charlevoix Commitment on Defending Democracy from Threats,” which included general language about cooperation to share lessons and information to counter disinformation. Photo Credit: Casa Rosada (Argentina Presidency of the Nation)

“Establish a G7 Rapid Response Mechanism [RRM] to The United States Tries to Get a Grip strengthen our coordination to identify and respond to diverse and evolving threats to our democracies, in- The United States has fallen behind the EU, both in cluding through sharing information…”15 The Canadian terms of conceptual framing and calls for concrete ac- government has now established such a mechanism, tions to meet the disinformation challenge. Ahead of reportedly with a staff of twelve and a mandate to an- the 2018 US congressional elections, Dan Coats, the di- alyze disinformation campaigns, with an initial focus, rector of national intelligence, warned that “lights were which included the May European elections. The blinking red” on the threat of foreign interference.16 RRM has established the State Department’s Global But, Coats’ statement suggests that the US govern- Engagement Center (GEC) as its US government point ment’s priority was election security in the context of of contact. Thus, the RRM could link up with the EU’s the 2018 US congressional elections, rather than ad- RAS and the State Department’s GEC, creating an in- dressing disinformation more broadly. While protecting stitutional basis to share information about disinforma- election infrastructure (such as updating or replacing tion campaigns, hopefully in near real time. The RRM electronic voting machines, hardening security around has already started to share information about current voter-data storage, and harmonizing information shar- counter-disinformation projects beyond governments ing between local, state, and federal election authori- to the wider expert community. ties) is critically important, such a policy approach risks

US Cyber Command began operations ahead of the 2018 congressional elections, to deter Russian operatives from potential interference. Photo Credit: US Army/Steve Stover

becoming episodic and narrow, whereas disinformation disinformation, with an appropriated budget of $120 campaigns are continuous and consistent.17 million. The GEC has begun to disperse significant funding to civil society groups and private-sector Disinformation campaigns are ongoing between elec- partners, including: for research into disinformation tion cycles, and they need not focus on specific can- and counter-disinformation tactics ($9 million); to didates or parties. For this reason, efforts to resist and journalists, fact checkers, and online influencers ($9 build resilience against foreign disinformation must be million); to partner organizations to support local sustainable and involve the whole of government. counter-disinformation efforts; and to develop new technologies useful for counter-disinformation ac- The United States has made little progress in address- tions. The GEC is also actively participating in the ing this challenge over the last year. Still, there have G7 RRM, the UK-US bilateral coalition, and the been notable activities. Australian-led counter-interference effort.

■ The Department of Defense funds the GEC (man- US Executive dated under a National Defense Authorization Act). ■ The Mueller Report (Volume One) outlined in de- Beyond the traditional strategic communications tail Russia’s interference in the 2016 US presidential functions conducted by its public-affairs apparatus, campaign, including its cyber hacking, intelligence the Defense Department’s policy arm has a narrow operations, and broad disinformation efforts. mandate to direct information support activities under the Special Operations/Low Intensity Conflict ■ The Global Engagement Center, a State Department (SO/LIC) unit, typically in support of US military unit within the Public Diplomacy Bureau, initially in- activities overseas or relations with allies and part- tended to focus on countering extremist Islamist ners. US European Command (EUCOM) supports the ideology, has turned to countering state-sponsored broader US effort to counter Russia’s disinformation,

and conducts information operations as part of its foreign-presence exercises in Europe, e.g., in .18 “ While not a new policy, the

■ The mandate of the Federal Bureau of Investigation’s Department of the Treasury (FBI) Foreign Interference Task Force (FITF), estab- used existing authorities to lished in October 2017, includes engagement with US technology and social media companies to ad- impose sanctions on Russian dress the challenge of false personas and fabricated stories on social media platforms (as well as “hard” entities tied to disinformation cybersecurity for voting infrastructure and other efforts, including those potential US election-related targets). At least one social media company has credited the FITF with directed at the 2016 US advancing US government (USG)-social media com- pany discussions to address the threat. presidential election.”

■ US Cyber Command began operations ahead of the 2018 congressional elections, to deter Russian oper- atives from potential interference.19 Cyber Command, ■ The State Department has worked with like-minded together with the National Security Agency (NSA), European governments to establish an informal con- reportedly developed information about Russian sultative group on disinformation efforts. This is a trolls and their activities, and alerted the FBI and worthy step, though it has not yet generated com- Department of Homeland Security (DHS).20 The oper- mon actions or standards, or even framed solutions ation followed the Department of Justice’s February on a conceptual level. 2018 and July 2018 indictments of Russian individu- als, intelligence officers, and companies involved in ■ A USG interagency working group—the Russian In- the Internet Research Agency and cyber operations fluence Group (RIG)—includes the relevant US gov- against the US elections.21 Cyber Command has re- ernment agencies, including DHS, the intelligence portedly sent messages to specific individuals active community, the State Department, and the Depart- in disinformation operations, de facto outing them ment of Defense. It has generated little high-level and their activities. action and few recommendations to date and, as of this writing, no USG senior official has been -em ■ The Department of Homeland Security—the agency powered to take the lead on counter-disinformation that should lead the counter-disinformation efforts efforts. Policy issues without senior-level ownership in the United States—has an internal working group tend to drift. focused on countering malign influence, but its ac- tivities seem more focused on technical election se- ■ While not a new policy, the Department of the Trea- curity around critical infrastructure than on broader sury used existing authorities to impose sanctions disinformation. on Russian entities tied to disinformation efforts, including those directed at the 2016 US presidential ■ The US State Department’s Bureau for European and election. This included the sanctions designation on Eurasian Affairs has established a new position— December 19, 2019, of entities and individuals tied to the senior adviser for Russian malign activities and the IRA and nine GRU (military intelligence) officers. trends (SARMAT)—tasked with coordinating policy Material accompanying the Treasury Department’s on Russian malign influence.22 sanctions designations exposed details of Russian

operation, including establishment of an online En- conceivably curtail Russian-placed and other for- glish-language website, “USA Really.” eign-placed issue ads with a partisan purpose, in- cluding ads placed under hidden or misleading sponsorship. In any case, the legislation has not US Congress moved through either chamber of Congress. ■ The 2019 National Defense Authorization Act (NDAA) added significant (albeit second-order) provisions ● Possibly to preempt legislation, both Twitter and defining the importance of countering disinforma- Facebook have announced that they are imple- tion for US national security.23 menting many Honest Ads Act requirements. The impact of these announcements is not yet clear ● Cementing the role of the GEC by defining its and would be limited if these social media com- counter-disinformation task within the param- panies apply the Act’s definitions narrowly.25 eters of US national security, likely securing the center’s longer-term funding in future iterations ● Even if Congress were to pass this legislation, its of the NDAA. impact may not be great. Political ads make up a miniscule portion of the overall ads industry. In ● Defining “malign influence” as “the coordinat- addition, ads are a secondary tool for spreading ed, integrated, and synchronized application of disinformation; organic posts, albeit under false national diplomatic, informational, military, eco- identities, are becoming the major Russian disin- nomic, business, corruption, educational, and formation tool. other capabilities by hostile foreign powers to foster attitudes, behaviors, decisions, or out- ■ The Senate Special Committee on Intelligence (SSCI) comes within the United States.” commissioned two major reports on the IRA’s tactics and techniques, based on data shared by Twitter, ● Authorizing the establishment of a new position Facebook, and Google.26 in the National Security Council (NSC) responsi- ble for coordinating the interagency process for ■ The Senate introduced the Data Protection Act of countering foreign malign influence. This NSC di- 2018, which would have placed standards on what rector-level position now exists and was filled at online service providers can do with end-user data. the time of this writing. While the bill has not been reintroduced in the new Congress, it laid out the responsibilities of providers ■ The Honest Ads Act, introduced in October 2017 and in handling user data, and it enjoyed wide support likely to be reintroduced in the current Congress, from platforms.27 This legislation should be reintro- would require that political ads be identified as such duced. The Senate has reintroduced the Defending on social media platforms.24 On one level, the leg- American Security from Kremlin Aggression Act of islation would address only a small number of on- 2019 (DASKA); while mostly devoted to sanctions, it line ads (those strictly defined as sponsored by a also “calls for the establishment of a National Fusion political candidate or campaign). But, by making Center to Respond to Hybrid Threats, a Countering social media companies liable should they provide Russian Influence Fund to be used in countries vul- a platform for foreign expenditures aimed at influ- nerable to Russian malign influence, and closer coor- encing US elections (already prohibited under US dination with allies” 28 (sections 704, 705, and 706). campaign-finance law), the Honest Ads Act could

Senator Mark Warner and Senator Marco Rubio speak to the press following their public remarks at a July 16 event on the Kremlin’s interference in elections. Photo Credit: Atlantic Council

■ In April 2019, Senators Mark Warner (D-VA) and Deb ● Congress has not, however, decided what specif- Fischer (R-NE) introduced the Deceptive Experiences ic steps it wants the social media companies to to Online Users Reduction (DETOUR) Act,29 which take to address issues of data privacy, online ad- seeks to limit tactics used by social media platforms vertising transparency, algorithmic transparency to steer users in various directions. DETOUR appears with respect to placement of news, or more trans- directed against domestic deceptive online practices, parency on how the companies are identifying or not foreign disinformation. But, the bill suggests that de-prioritizing/de-ranking disinformation cam- Congress is moving beyond pushing transparency (as paigns, or removing them from their platform. in the Honest Ads bill) and toward introduction of more intrusive standards of conduct for social media ● This lack of focus does not indicate a lack of un- companies. The precedent could provide a basis for derstanding of the problem: Senator Warner has legislation targeting disinformation. developed a draft white paper illustrating pro- posals that could become the basis for regula- ■ Congress’s main activity on countering disinforma- tion. Like the EU policy papers and Code of Prac- tion has been to hold hearings with social media tice, it focuses on transparency (e.g., information companies and their executives. Since 2016, the US about the origin of posts and accounts, manda- Congress has held five open hearings with Google, tory labeling of bots, identification of inauthentic Facebook, and Twitter executives. These have accounts, a degree of algorithmic transparency, captured intense media attention and may have and other measures).30 generated political pressure on the social media companies to be seen as constructive with respect ● Domestic political issues, such as allegations of to disinformation issues. partisan bias on the part of social media compa-

nies, have become distractions in some congres- identify “coordinated inauthentic behavior”—groups sional hearings. of pages or people working together to mislead oth- ers and manipulate the conversation.33 The companies have announced changes to their algorithms aimed Social Media Companies on the Spot at reducing the visibility of content from automated Twitter, Facebook, and Google have been in the hot seat spammers, suspicious impersonator accounts, and for failing to do more to address the manipulation of other distracting content. To prevent foreign influence their platforms, their handling of personal data and pri- in elections, Google, Facebook, and Twitter have also vacy, their initial lack of cooperation, and denials that changed policies around political advertising during the disinformation problem even existed. Over the last elections in the United States and Europe, including three years, the political climate has shifted in significant tougher certification requirements for individuals or ways, as has the companies’ approach to the problem. groups seeking to promote candidates and parties.34 Since the 2016 elections, the US Congress held five hear- ings with social media companies’ representatives.31 The ■ “Takedowns” (i.e., removal) of coordinated inauthen- European Parliament has held one.32 Under pressure, so- tic activity—accounts, pages, and content working to cial media companies pivoted to a stance of acknowl- actively manipulate discourse on social media—have edging the problem and seeking to be seen as part of become a common tool for Facebook and Twitter. the solution. Yet, their efforts fall significantly short of In January 2019, Facebook removed a network addressing the dual challenges of platform manipulation of pages and accounts from both Facebook and and data collection and sharing. While disinformation that were linked to Sputnik and its em- will never be fully “solved” through the actions of social ployees, primarily operating in Eastern Europe and media companies alone, these large content distributors Central Asia.35 This operation followed a November are the first line of defense against information manip- 2018 takedown of accounts and pages with sus- ulation and, with that, they have a large share of the pected links to the IRA.36 So far in 2019, Facebook responsibility for mitigating the problem. has also taken down coordinated inauthentic activ- ity in , Pakistan, Iran, Macedonia, Kosovo, the Social media companies have made welcome changes Philippines, Moldova, Romania, the United Kingdom, in their policies, advertising rules, and postures vis-à- Indonesia, and Ukraine.37 Facebook said it worked vis governments and researchers. While companies’ ap- with tips from the FBI and pre-released the data proaches vary, they have, on the whole, become more for analysis by some independent researchers, but open in sharing disinformation content with research- Facebook remains unwilling to share data with most ers, civil society organizations, and targeted govern- researchers, making it difficult to assess the scope ments. They have also established internal teams to of manipulation on the platform.

■ Facebook also announced in early 2019 that it will es- tablish an independent “oversight board” of experts to review Facebook’s content decisions.38 In essence, the board will complement Facebook’s existing al- gorithmic review with human review, which was also recommended in the first edition of this report. It re- mains unclear, however, how the membership will be selected, which content the board will review, how independence will be ensured, and what information Facebook will share publicly. Ahead of the European Parliamentary elections in May 2019, the company opened a “war room” in Dublin to monitor manipu- lation on Facebook, Instagram, and WhatsApp (the company set up similar command posts ahead of the 2018 US elections and elections in India).39

■ Twitter has focused on improving algorithmic re- view of accounts suspected of abuse, harassment, hate speech, or manipulation. In the first half of 2018, Twitter identified and challenged 232.4 mil- lion accounts that the company identified as engag- ing in spammy or manipulative behavior.40 Twitter has also been transparent and willing to share data with researchers on a regular basis. The challenge that Twitter and other social media companies face today is less about automated accounts, however, and more about impersonators and organic disin- Facebook CEO Mark Zuckerberg. Since 2016, the US Congress formation shared by real people. The company also has held five open hearings with Google, Facebook, and Twitter established an election-integrity data archive, which executives. These have captured intense media attention stores and makes available content on information and may have generated political pressure on the social media companies to be seen as constructive with respect operations from state actors, including Russia, Iran, to disinformation issues. Photo credit: Anthony Quintano at and .41 And Twitter barred RT and Sputnik from advertising on its platform.42

■ Google and YouTube, in contrast, have been less trans- ■ In March 2018, Google announced that it would com- parent about their activities to limit false and manip- mit $300 million to support quality journalism and ulated information on their platforms. In 2017, the combat false information on its platform by, among then-chairman of Alphabet, Eric Schmidt, said that RT other things, supporting youth education and part- and Sputnik would be de-ranked from appearing at the nering with research organizations.44 In February top of Google result searches.43 As of this writing, how- 2019, the company published a white paper on its ever, that policy change has not been implemented. ongoing efforts to fight disinformation.45 Identifying

SIgn at YouTube headquarters in San Bruno, California. Unlike FacebookYouTube has received little scrutiny from lawmakers, despite reporting that it has promoted radical content. Photo credit: © BrokenSphere/Wikimedia Commons

and preventing manipulation by malicious actors re- or highly misleading content—however, the change mains a challenge, according to the paper, because will affect less than 1 percent of YouTube content.49 “[a]lgorithms cannot determine whether a piece of Google and YouTube frame these moves as part of content on current events is true or false, nor can a company effort to counter extremism and reduce they assess the intent of its creator just by read- the prevalence of harmful content. Certainly, limit- ing what’s on a page.” Google’s answer has been to ing recommendations of low-quality content is an prohibit impersonation in its terms of use, augment important part of a broader set of actions aimed algorithmic review with human review, and invest in at identifying and tackling foreign disinformation. better detection of “spammy” behavior. However, as this paper has argued, content controls are both more controversial and probably less ef- ■ YouTube is quickly catching up with Facebook in fective than dealing with fake and inauthentic on- terms of the number of active users, which could line presences. YouTube’s content-control-policy soon make the video channel the most popular social changes do not address how the company plans to media site in the world.46 Compared to Facebook, deal with foreign manipulation or coordinated inau- however, YouTube has received little scrutiny from thentic behavior, likely making the impact on disin- lawmakers, despite reporting that YouTube has pro- formation campaigns negligible. moted radical content.47 In 2017, Google announced a change in YouTube’s terms of service, which Social media companies’ actions to curb manipula- would de-rank, label, and remove from promotion tion of their platforms vary, but the trend is positive, potentially extremist or offensive videos, making a welcome change from initial denials. But, to vary- them harder to find.48 In January 2019, YouTube an- ing degrees, the companies still seem reticent to fully nounced that it would change its recommendations cooperate with lawmakers and researchers. For ex- system to no longer recommend conspiracy theories ample, the two independent research organizations

commissioned by SSCI to analyze the IRA data pro- vided by Facebook, Twitter, and Google noted that the “One core problem remains: companies provided incomplete and, in some cases, unusable data. The firms have a long way to go to social media companies’ convince users and regulators of their commitment to business models are premised tackle disinformation and manipulation. on increasing ad revenues, One core problem remains: social media companies’ business models are premised on increasing ad rev- and sensationalist content enues, and sensationalist content sells best. The on- sells best.” line advertising ecosystem that supports this business model has ballooned into a multibillion-dollar business, without much attention from regulators. more sophisticated in their analysis of social media In addition, the tools social media companies have de- data, tracking of disinformation campaigns, and expo- veloped to maximize ad revenue, including microtarget- sure of such campaigns. ing, rely on increasing amounts of precise personal data to develop sophisticated social graphs of US and other ■ Graphika, Oxford University’s Computational Propa- societies. Under pressure to compete for data, these ganda Project, and New Knowledge were enlisted companies will continue pushing to get access to users’ by the Senate Intelligence Committee to study mil- data. Facebook, for example, ran a research program lions of posts released to the committee by major that paid young users a nominal sum ($20) in exchange platforms. for detailed access to their phone-use habits.50 Social media companies’ objectives are primarily commercial, ■ The Atlantic Council’s Digital Forensic Research Lab but their methodology (and the data access it provides) has been given access to data ahead of major take- has served the purposes of the IRA, Russian military in- downs by Facebook and has been able to offer anal- telligence, and other purveyors of disinformation. ysis of the pages and increase understanding of the information operations. Data protection is, thus, not just a privacy issue. Access to data provides a commercial suite of tools to deliver ■ AlgoTransparency is a program, developed by a precise disinformation to bespoke slices of the popu- former YouTube employee, that tracks YouTube’s lation. In other words, social media companies may be recommended-videos , which accounts providing valuable research for purveyors of disinfor- for seven hundred million view hours per day.51 The mation, including Russian intelligence. None of the so- project aims to “inform citizens on the mechanisms cial media companies have pushed to seriously address behind the algorithms that determine and shape our this core problem, preferring to instead focus on filter- access to information.” As the project finds, most ing content, because it risks undercutting profit mar- such videos tend to lean toward conspiracy theories, gins. Yet, this is exactly where the industry will have to radical content, and . YouTube’s re- change its approach and policies if it is serious about cent change in its recommendations system seems solving the disinformation problem. to reflect input from AlgoTransparency.

■ Public Editor is a start up that provides credibility Civil Society Stays the Course scores for news articles, journalists, public figures, Since the launch of the first report, civil society has and news sites by guiding volunteers to complete continued to be instrumental in raising awareness and online media literacy tasks identifying argumenta- understanding the breadth of the challenge. Civil soci- tive , psychological biases, inferential mis- ety groups and researchers are becoming savvier and takes, and other misleading content.52

responsibility for countering foreign disin- The US Executive Should Get Serious formation. On the bright side, vacuums of ■ Get organized policy leadership—one way to describe the situation within the US administration with ◆ Designate a lead agency or office, and a lead -se respect to countering disinformation—tend nior official, for counter-disinformation policy and to be filled when the politics of an issue start operations. The mandate should be broadly es- generating pressure, providing incentives to tablished to cover disinformation generally, rather step up first. than focusing on a specific actor (such as Russia). ■ Work with friends, starting with the EU ● As noted in the previous edition of this paper, DHS could take the lead in devising counter-dis- ◆ Stand up a transatlantic Counter-Disinformation information policy, working with and through Coalition, as recommended in the first edition of the State Department as the United States this paper, bringing in like-minded governments seeks to build common action with European (e.g., the United States, the EU, other willing Eu- and other governments. ropean national governments, and possibly G7 member states), social media, relevant tech com- ● Given the broad nature of the challenge, the panies, and civil society groups. USG could establish an interagency “Count- er-Disinformation Center,” perhaps a smaller ● The coalition would serve as a platform to version of the National Counter Terrorism Cen- share experience and information with respect ter established after the terrorist attacks of Sep- to foreign disinformation, and develop, in non- tember 11, 2001, as an operating arm for moni- binding fashion, best practices for dealing with toring of foreign disinformation, with a mandate it in ways consistent with common commit- for real-time liaison with foreign governments, ments to freedom of expression. social media companies, civil society, and oth- er relevant actors. DASKA legislation includes a ● The coalition could draw from the EU’s Code proposal for a similar “fusion cell.” of Practice as the basis for a broader set of ex- pectations for social media companies’ behav- ✱ A key task for such a center should be to ior. It could also serve as a place to develop develop a baseline and outflowing set of consistent approaches to issues of data priva- metrics and indicators for when and how cy, transparency, and identification (and possi- the government should respond to an iden- bly removal) of bots, foreign trolls, imperson- tified state-sponsored disinformation attack ators, and other malign actors. against the United States, and who within the government should do so. Not all disin- ● The USG and EU should also engage private formation efforts warrant a USG response, cybersecurity companies for support in de- as there is risk of further amplifying disinfor- tection of disinformation. Some of these are mation content. Identifying when the ben- led by, or employ, former US intelligence offi- efit of exposure outweighs the risk of inad- cers whose technical expertise can help spot vertent amplification is critical. A common Russian and other disinformation techniques, set of guidelines is sorely needed. while also evaluating social media companies’ counter-disinformation actions. ✱ US government employees and officials should be regularly informed of detected dis- ● There are organizational variants for an infor- information attacks and, where appropriate, mal coalition. trained on how to handle and respond to such attacks when their agencies are targeted. ✱ A G7 institutional base, building on the Charlevoix Commitment from the Canadian ✱ What will not do is the current situation, presidency. The G7’s Rapid Response Mech- in which no one in the USG seems to have anism, already functioning, could be its core.

Ahead of the 2018 US congressional elections, Dan Coats (front right), the director of national intelligence, warned that “lights were blinking red” on the threat of foreign interference Photo Credit: Official White House Photo by Shealah Craghead

✱ While the Organization for Economic Co- now to pool assessments of social media compa- operation and Development (OECD) has lim- nies’ performance in terms of their counter-disin- ited political weight, it has resources and a formation commitments—including through the broad membership beyond the G7 and trans- Code of Practice, via testimony to Congress, and atlantic community. in public statements—and use their combined leverage to encourage greater transparency and ✱ Alternatively, the existing NATO Strategic implementation. Communications Centre of Excellence in Riga or the European Centre of Excellence ■ Establish a USG rapid alert system (RAS) to inform for Countering Hybrid Threats could play a the public, allied governments, and social media role as a resource hub for such a coalition.53 companies of emerging disinformation campaigns that threaten national security. ◆ As a potential longer-term objective, practices of cooperation and informal groups could grow into ◆ The European rapid alert system (if established formal arrangements. Former Danish Prime Min- along lines forecast by the EU Action Plan) can ister Anders Fogh Rasmussen has proposed es- help the USG judge the potential of this idea. tablishment of a digital “Alliance of Democracies,” Some of the challenges can be anticipated: given with extensive norm-and-rule-setting authorities US politics and traditions, issues will arise around like those of the World Trade Organization.54 a US RAS’s mandate (e.g., the definition and at- tribution of disinformation, as opposed to media ◆ Whatever the short- and long-term institutional ar- content the USG doesn’t like) and its composition, rangements, the United States and EU should start credibility, and independence. Issues regarding

the current administration’s credibility on media ■ In approaching regulation (and associated legisla- independence and freedom will also have to be tion), start with low-hanging policy fruit, then de- addressed. termine how far to proceed.

◆ The authors judge the effort to establish a US ◆ Regulation of advertisement and sponsored con- RAS worthwhile, challenges notwithstanding. An tent seems relatively straightforward, as precedent independent board could be established, pos- exists for limits on commercial speech. Social me- sibly by legislation, with Senate confirmation of dia companies can be mandated to post accurate its members. The precedent of a European RAS information about sponsors of ads, rather than eu- could give the idea legitimacy. phemistic or misleading self-descriptions. (“Amer- icans for Puppies” is not an acceptable label for an ■ Follow the money ad sponsor if the ultimate placer of the ad is the St. Petersburg Internet Research Agency.) ◆ The USG should continue to impose sanctions on foreign official, or officially-controlled or direct- ● Regulation and limitation of foreign ads are ed, purveyors of disinformation and their spon- useful, but may be of limited impact, especially sors, and to identify and prosecute violations of given the shift to organic content. federal elections laws (prohibitions on foreign contributions). ◆ More complex would be mandatory identifica- tion of bots. This would raise major domestic ● On September 12, 2018, the Trump administra- commercial issues, given that bots play a role in tion issued Executive Order 13848, which pro- domestic, non-political advertising and are used vides for sanctions imposed against persons for benign purposes, e.g., bots distribute content found to have interfered in US elections. While, from major media organizations such as the New in part, simply an effort by the administration York Times. Individuals also use bots to schedule to preempt stronger legislation (i.e., the “DE- their tweets or re-post their own content. Still, TER” Act introduced by Senators Marco Rubio identification could be mandated for foreign-ori- (R-FL) and Chris Van Hollen (D-MD)), it pro- gin bots or for bots disguised as persons, follow- vides a useful vehicle, should the administra- ing principles of transparency and integrity, or for tion use it. specific behaviors.

● US sanctions laws restrict US citizens from fi- ◆ Still more complicated would be regulatory man- nancial dealings with or “providing material dates to disclose or remove inauthentic accounts support” to foreign persons under sanctions. and impersonators, e.g., a Russian troll masquer- Enforcement of these and federal election laws ading as “Jimmy” from Minneapolis, or a purport- could limit the ability of Russian or other for- ed domestic “news organization” that was, in fact, eign purveyors of disinformation to work with controlled from Russia or Iran. We favor removal of US agents. inauthentic accounts and labeling of anonymous accounts if they engage in misleading presenta- ◆ The USG should continue to share findings about tion. Using a pseudonym online may be legitimate Russian disinformation methods, financing, and for human-rights activists operating in authoritar- relevant individuals and organizations with the ian countries but could also provide cover for for- EU and affected member states, the G7, and eign . (Russian human-rights activists, other friends and allies—seeking, among other however, have told us that the marginal protection things, coordinated sanctions. of anonymity in Russia is insignificant; this is likely true in China as well.) In any case, there is a dif- ■ Develop “forward-defense” and asymmetric options. ference between an anonymous online persona US Cyber Command’s reported actions targeting and a deceptive one, and this paper recommends Russian disinformation actors raise the question of steps to limit the latter. whether the USG toolkit for countering disinforma- tion should include asymmetric options for deterrence ◆ As a further (and yet more complicated) step, or retaliation, including in the cyber realm. This pol- transparency regulation could mandate an on- icy question leads to broader issues of cybersecurity line sign-in system for access to part, or all, of and cyber deterrence, which are generally beyond the the Internet. All identified human beings, but scope of this paper, but worth noting. only identified human beings, would have access

to social media accounts. Some sites could be placed off limits to minors. This could (but need not necessarily) be combined with requirements that online persons also be identified, i.e., no more anonymity.

● Any effort to verify the identity of individuals may raise objections on grounds of free speech, or unintended discriminatory impact if online sign-in requires documentation to verify iden- tity. Additional concerns around online surveil- lance would also have to be taken into account.

◆ Mandating standard terms of service for social media companies would ease implementation of regulatory limitations. Precedent exists; the Credit Card Accountability Responsibility and Disclosure (CARD) Act of 2009 required credit-card compa- nies to standardize the terms used in their terms of service (e.g., fixed rates).55 In the context of so- cial media companies, this could mean requiring platforms to agree on both common definitions of impersonator and inauthentic accounts and standards on removing bots, and, though this is more questionable, what qualifies as hate speech, credible versus weak content, and violent or harm- ful content (e.g., anti-vaccination propaganda).

◆ Social media platforms have created a com- modity from aggregated personal information. In 2017, the then-chairman of Alphabet, Eric Schmidt, said that RT and Sputnik would be de-ranked from appearing at the top This has the unintended consequence of turning of Google result searches. As of this writing, however, that policy social media companies into potential research change has not been implemented. Photo credit: Hecker/MSC engines for foreign intelligence agencies or other malign actors. The issue of corporate responsibil- ity for safeguarding personal data, based on pri- exploited by those with intention to inflame and vacy protocols, thus takes on a new dimension. distort. Government mandates with respect to The policy challenge is whether to mandate pri- overall social media algorithms are apt to be con- vacy protocols and/or what some scholars have tentious, (e.g., what would a “fairness doctrine” termed “information fiduciaries” to help set cor- look like when applied to social media?) and porate standards for safeguarding personal data could easily become the object of partisan pol- beyond areas already limited, e.g., health and itics (e.g., Senator Ted Cruz (R-TX) has publicly banking.56 This would complicate the business advocated regulation to counter what he claims model of social media companies, so at this stage is liberal bias in social media). the recommendation is for further exploration. ◆ Thus, we prefer not to start with a mandated ◆ Another difficult regulatory issue, also affecting makeover at this stage, but to start with targeted social media companies’ business models, has to fixes, such as: do with social media platforms’ algorithmic bias toward sensational content, driven by commer- ● Systems in place to de-rank, rather than re- cial preference for user engagement but easily move, false or deceptive sites or posts while at

disinformation, whether foreign or domestic, will con- “ Democratic societies will need stantly bump against norms of free expression.

to invest in building resilience ■ Remember resilience to (digital) disinformation, ◆ Public policy and regulatory efforts only go so far even as they take steps by themselves. Democratic societies will need to invest in building resilience to (digital) disinforma- to mandate norms that tion, even as they take steps to mandate norms that diminish vulnerabilities to diminish vulnerabilities to disinformation exploita- tion. The “supply side” of disinformation and the disinformation exploitation.” “demand side” go together: social media platforms’ transparency measures, such as labeling and identi- fication of bots, impersonator trolls, etc., work best when people recognize and shun them by habit. the same time focusing on elevating high-quali- ty content. (“Deceptive” could be defined to re- ◆ Building social resilience will be a generational chal- fer not to content, but to deceptive provenance, lenge. Successful campaigns that have changed e.g., RT, Sputnik, or known propaganda outlets.) individuals’ behavior included effective public pol- icy, (sometimes) buy-in from industry, and mobi- ● System improvements around “data voids” or lization of civil society groups. These have taken search terms for which there is little available decades, a great deal of trial and error, and strug- content and thus the void can be filled by mali- gle. The US anti-smoking campaign is one example cious actors (e.g., Russian outlets strategically of successful societal change coupled with regu- launching a barrage of content on a specific lation and changes in industry approaches (the search query to crowd out any other sources).57 latter only under sustained social and regulatory This is a particular problem for search engines pressure).59 The digital revolution is young—Face- including Google and YouTube. book, Google, and Twitter are still young compa- nies—and democracies in the beginning stages of ◆ Facebook is reportedly introducing such chang- grappling with the disinformation challenges of es to its algorithms to de-rank questionable con- the twenty-first century. More trial and error will tent.58 Google, however, is reportedly not review- follow, but democracies must stay the course. ing ranking of individual sites. ◆ There are bright spots. For example, Lie Detec- ■ We remain skeptical about government-mandated tors is a European project that sends journalists into content control. Taking down pornography, hate classrooms to teach schoolchildren about the dif- speech, and terrorist-related sites is challenging, but ference between false and real news.60 It is showing seems within the realm of the possible for democratic impactful early results, while empowering youths societies with robust norms and laws protecting free with digital literacy skills. If instituted at scale, such expression. Broader content restrictions (against efforts could begin to yield results quickly. false information, for example), however, are more difficult. While arguments can be made for restricting The US Congress Should Fill the Gap or eliminating dangerous content, e.g., how to build weapons of mass destruction or anti-vaccine propa- ■ Hold additional (and better prepared) public and ganda, the application of content restrictions against private hearings with social media companies’ chief

technology officers (CTOs) or equivalent, including gests that these standards be established evenly on algorithmic bias, manipulation of search engine across the tech industry, not just for social media optimization (SEO) (i.e., how malicious actors game firms. This act, revised and strengthened along the search engine results), data collection, and pri- the above lines, could be a vehicle for this effort. vacy practices. ◆ The DETOUR Act, noted above, suggests that ◆ Such hearings should be designed to encourage Congress is prepared to consider legislation to (and, if necessary, force) companies to inform regulate what has been standard social media policymakers and the public, in clear language, company practice to steer (or manipulate) users. how their data and behaviors are tracked, collect- This suggests Congress is getting ready to con- ed, stored, and shared with third parties, and how sider legislation to support a regulatory frame- the profit incentive drives such practices. If com- work to deal with disinformation. pany representatives are later revealed to have misled congressional leaders, they should once ◆ This paper also recommends legislation to provide again be called to testify and held accountable. a framework for regulation to address transparen- cy (especially with respect to bots), integrity and ■ Authorize and appropriate funds to “build capac- authenticity of service (i.e., targeting deceptive ity of civil society, media, and other nongovernmen- and impersonator accounts, whether individuals or tal organizations,” countering Russian and other false-front organizations), and common terms of sources of foreign disinformation (from DASKA Sec service across the social media industry. 705(b)), in coordination with the EU, NATO, and other bodies. Funding is already available to the ◆ Legislation to address the problem of algorith- State Department’s Global Engagement Center; this mic bias toward the sensational, or to de-rank should be increased. deceptive content, appears more complex, and should be addressed separately from (and prob- ■ Develop in-house expertise on disinformation. If ably after) initial efforts. Congress and the executive branch establish reg- ulatory frameworks to combat disinformation (e.g., ◆ Congress could also mandate that media outlets as suggested above, with respect to ads, standards, determined by the Department of Justice to be act- and expectations for removal of bots, identification ing as agents of foreign governments be de-ranked and/or removal of impersonation accounts, privacy/ in searches and on newsfeeds and be barred from information fiduciary standards, de-ranking of falsi- buying ads. RT, for example, was required to reg- fied or deceptive organic content), Congress’s ca- ister under the Foreign Agents Registration Act pacity for detailed analysis, independent from social (FARA). Governmental assessments and FARA de- media companies, will be critical. termination should be one of many variables con- sidered in rankings for search engines. ■ Prepare legislation—on a step-by-step basis—to support a regulatory framework for social media ◆ Congress should explore establishing a federal companies. This paper has recommended (above) statute that would limit companies’ collection of a layered approach to regulation, starting with sim- personal data about individuals. Such a statute pler steps. In similar fashion, it recommends “light” would specify that any personal data collected legislation (and, probably, discrete legislative pack- would be specific to the stated purpose of the ages) to build a regulatory framework, rather than technology. Such data collection limitation would an attempt at comprehensive regulatory legislation, make microtargeting and exploitation of individ- given the issues of freedom of expression—and the uals’ personal data more difficult while also -re difficulty of legislating at an evolving threat from a ducing the ability of malicious actors to influence. relatively low knowledge base in Congress. The California Consumer Privacy Act of 201861 could serve as precedent for a federal mandate. ◆ The Honest Ads Act, introduced in the last Con- gress, is a solid step toward setting transparen- ◆ The issue of social media companies’ use of per- cy standards around online advertising (not just sonal information (the issue of “information fidu- narrowly defined political ads). This analysis sug- ciaries”) should await additional study.

■ Explore legislation that could be applicable to social manipulation activity and demonstrable deception media, based on precedent in other industries. of identity, which may be easier to establish.

◆ The issue of data portability, or the user’s ability ■ Provide adequate resources and political backing to take their data across platforms, was resolved to EastStratCom. This innovative institution needs in the telecom sector through legislation. Indi- to be supported without ambivalence. Recent indi- viduals have the right to own, control, and move cations are promising and need to be maintained. their data between telecom providers. The same In the best case, EastStratCom would have the should be true for social media companies. resources to work with independent civil society groups to identify disinformation campaigns in real ◆ Regarding network manipulation for malicious time and disseminate that knowledge through the purposes: the social media sector shares similar- RAS to member states and to European publics. ity with the financial sector, in that both indus- tries operate networks of sensitive data that flow ■ Continue to monitor social media companies’ im- globally. Financial institutions are legally required plementation of the Code of Practice (with the to investigate and identify illicit financial flows (or option to proceed to regulation), especially with the malicious misuse of their processes) and re- respect to control over foreign bots, political ads, port any finding to federal agencies. A similar set fake accounts closed, and cooperation with civil so- of compliance practices, with supporting federal ciety researchers. agencies, could be considered for social media companies. ◆ The current arrangement under the Code of Prac- tice could be termed audited or monitored self- regulation. Should this prove inadequate, next Europe Should Make it Real steps could include a move to formal EU Commis- ■ Use the RAS. The rapid alert system was intended to sion review and approval of social media industry be online and active in advance of the May European codes, or to a full-fledged regulatory system. parliamentary elections, but reports of its effective- ness are mixed. If successful, the RAS could (and ◆ In any case, the United States and EU should hopefully will) develop operational ties with regular consult closely about common regulatory stan- and social media, and with civil society groups and dards; establishing a pattern of consultation for tech companies involved in counter-disinformation green-field regulatory standards will be far easier efforts. While this paper focuses on foreign-origin before, rather than after, respective US and EU disinformation, information sharing about disinfor- regulatory standards are established. mation generated within EU Member States is valu- able. Making the RAS effective as soon as possible ◆ Establishment of an “algorithmic ombudsman”— will be an important indicator of the credibility of a credible figure designated by the EU (or USG) the EU’s promising start at tackling disinformation.62 to work with social media companies to reform their algorithmic bias toward sensational content, ■ Establish and use the fact-checkers network, as and the related vulnerability to exploitation by called for under the EU Action Plan, though this el- purveyors of disinformation—has been circulating ement was relatively less developed. The issue of among various experts seeking a middle ground “arbiters of truth” (e.g., empowering independent between self-regulation by social media com- groups to render editorial judgement) is complex, panies and their full regulation by governments. and even fraught. Still, a networks of fact check- While sympathetic to the intent behind this con- ers and independent journalists can be on alert to cept, the authors prefer to tackle the challenge identify new disinformation sites as they emerge, through incremental regulation, on the grounds track the credibility of outlets based on their track that regulatory standards either make sense or record of publishing false or misleading content, and do not, and the intermediary of an ombudsman share this information with governments and indus- will not alter those categories. try. Organizations focused on social media analysis, such as Graphika, New Knowledge, and DFRLab, ■ Empower independent civil society researchers. can work to identify and monitor coordinated The EU should expand and simplify its grant-making

■ Reassess anonymity on these platforms. To that “ Facebook, Twitter, and Google end, the companies should make publicly available an accurate report on the number of anonymous or should continue to improve unverified accounts on their platforms. Such a report transparency requirements should also assess how, and if, ending anonymous accounts could negatively affect vulnerable civil so- for content produced by ciety or human-rights groups operating in authori- tarian countries. A next step could be introduction state-funded media outlets, of “authentic spaces” accessible only to verified including due diligence human beings—not bots, cyborgs, or impersonators. This would mean use of online sign-in systems capa- around the parent companies ble of identity verification for access, either to some behind the content.” or all social media platforms. ■ Start algorithmic reform. As an initial example, and without waiting for regulatory mandates, Google system to support civil society groups, both inside could set the industry standard by seeking to pre- and outside the EU, with expertise in identifying vent overt authoritarian-state-sponsored media out- disinformation campaigns. These groups are on the lets from appearing at the top of any search results. front lines of counter-disinformation efforts, and RT and Sputnik continue to appear in top search re- those operating inside their home countries are sults for current event searches on a variety of top- likely to be best placed for these efforts. ics. Google, and others, should not censor or delete this content. Rather, social media platforms should use search algorithms to prioritize content from in- Social Media Companies Should Step Up dependent media over identified propaganda, which In a March 30, 2019, op-ed in the Washington Post, should not be regarded as either relevant or author- Facebook Chief Executive Officer Mark Zuckerberg itative. Social media companies should be transpar- expressed support for Internet regulation, including: ent about their efforts. content standards (not defined in detail); “election in- tegrity,” including political ad transparency; privacy and ■ Facebook, Twitter, and Google should continue data protection based on current EU standards (from to improve transparency requirements for content the EU’s General Data Protection Regulation); and data produced by state-funded media outlets, includ- portability. These are useful areas to explore, and a wel- ing due diligence around the parent companies come indication of changing thinking at Facebook. behind the content. Laudably, in February 2019, Facebook suspended pages run by Maffick Media, The regulatory challenges covered above include far a company largely owned by a subsidiary of RT.63 more than Zuckerberg’s relatively modest suggestions. Unlike YouTube, which publishes disclaimers on vid- Moreover, social media companies need to do more eos funded by the Russian government and other than cede responsibility to government regulators. As state-media outlets, Facebook and Twitter do not initial steps, they could do the following. have a similar policy. They should.

■ Institutionalize cross-platform coordination pro- ■ Large tech companies, not just social media plat- cesses for tracking, monitoring, and taking down forms, should work closely with innovative nonprof- disinformation campaigns, which often work across its, such as AlgoTransparency, to identify problems platforms simultaneously to amplify their content. in their algorithms and correct them, as YouTube For example, when Facebook deletes or mutes suspi- is starting to do. To that end, private-sector firms cious accounts, other platforms should de-rank or de- should establish independent funding mechanisms lete their corollaries or amplifiers. Some coordination (e.g., foundations) to fund civil society initiatives and already exists, but, as manipulators increasingly work innovators who are using new technologies, such as to amplify content across platforms simultaneously, AI and , to identify problems before much more nuanced coordination will be needed. they arise.

