Video summary
The panel discussion hosted by Alex Peele explores the historical evolution and future challenges of notice-and-takedown mechanisms within internet policy, specifically focusing on their origins in the 1998 Digital Millennium Copyright Act (DMCA). Jessica Litman explains that Congress adopted this specific framework as a strategic compromise to reassure legacy media industries; it offered copyright owners an expedited removal process without necessitating costly litigation while relying on intermediaries' superior ability to identify unauthorized content. While Section 512 established formal procedures including counter-notices for reinstating removed material, large platforms like YouTube have largely bypassed these statutory requirements in favor of private automated systems such as Content ID due to risk aversion and scalability needs. These tools often result in the over-removal of non-infringing content because they lack incentives for precision, a problem compounded by Section 512F's ineffectiveness in penalizing abusive notices since its remedies rarely make litigation financially feasible for most users.
Beyond copyright law, recent U.S. legislation such as the Take It Down Act and No Fakes Act attempts to extend these frameworks to address non-consensual intimate imagery and deepfakes, though critics argue they are weaker imitations that omit critical safeguards like penalties for false claims under oath or good-faith immunity provisions. The discussion highlights a significant tension between importing copyright logic into right-of-publicity contexts versus establishing an opt-in framework where individuals retain inherent rights to prevent the creation of digital replicas without consent. Furthermore, while global regulators generally prioritize privacy violations over copyright infringements regarding platform liability, domestic debates continue on whether current intellectual property exceptions under Section 230's liability shield are politically expedient but ultimately imperfect solutions that fail to adequately protect ordinary citizens and journalists from abuse by powerful entities or bad actors using general-purpose tools.
Technological limitations pose a formidable barrier to proposed alternatives like "notice-and-stay-down" regimes, which require proactive filtering via hashing technologies feasible only for massive platforms. Hash-based matching struggles against the flood of novel deepfake variations that do not share identical hashes, making broad scaling risky given current technological inability to reliably distinguish real footage from synthetic content without causing widespread false positives. Consequently, while AI-powered management systems offer potential solutions, they cannot fully resolve the issues inherent in automated recognition where compliance remains voluntary under safe harbor provisions rather than mandatory obligations. The consensus among panelists suggests that reforming the existing notice-and-takedown regime is preferable to discarding it entirely, acknowledging a necessary need for new technological layers and legal adjustments to handle rapidly evolving AI-generated content without sacrificing user rights or enabling systemic abuse against journalists and everyday people.
Read the full video transcript
Hello all, my name is Alex Peele and I
have the pleasure of welcoming you to
this year's summer legal fellows panel.
Today we turn our attention to the past,
present, and future of notice and
takedown. The notice and takedown
requirements of the digital millennium
copyright act safe harbor provision have
been a longtime fixture of internet
policy and have greatly shaped the
relationship between online platforms
and their users both within the United
States and abroad. It was a novel legal
mechanism devised for this new thing
called the internet written before
anyone knew what it would grow into and
has been more or less unique within US
law since. But now after over 25 years
later, Congress is set on adopting this
mechanism in new and upcoming
legislation governing online platforms
like the Take It Down and No Fakes Acts.
We hope that today's panel sheds light
on why notice and takeown has become the
mechanism of choice for legislators and
how the history of the DMCA might help
us anticipate the impact these new laws
will have. Before introducing our
fantastic panelists and moderator, I
would like to thank my colleagues and
summer Wikipdia fellows Daniel Echin,
Jack and Nita whose tireless work and
commitment made this event possible.
Similarly, we want to thank Jim Buati,
our legal director, whose guidance was
crucial during our fellowship at the
Wikip Media Foundation. We'd also like
to extend the invite to any of those
interested in joining the Wikipdia
Foundation's fellowship program. If
you're a current law student or recent
law school graduate passionate about
free knowledge and open source issues,
our legal fellowship program can provide
incredible in-house experience in
internet law through leading research
and experimental projects aimed at
improving our community. Anyone
interested can feel free to reach out to
Jim at juati wikimedia.org.
Without further ado, I want to welcome
our moderator, Stan Adams. Stan is the
Wikipdia Foundation's lead public policy
specialist for North America. He's
responsible for analyzing and responding
to legislative and regulatory proposals
that could impact Wikipdia projects and
the free knowledge movement in North
America. This work includes defending
existing legal protections that protect
volunteer editors from frivolous
lawsuits like section 230 and advocating
for stronger laws to protect the privacy
of the people who read and edit
Wikipedia. Stan has spent over a decade
working on tech policy issues including
digital copyright, free expression,
privacy, and AI. Prior to his role at
the Wikipdia Foundation, Sans served as
general counsel to US Senator John Oaf
and as a deputy general counsel at the
Center for Democracy and Technology in
Washington, DC.
Joining Stan on today's panel is Jessica
Litman, the John F. Nicole Professor of
Law at the University of Michigan Law
School, adviser for the American Law
Institute for a statement of copyright,
a director of the American Trademark Law
Society, and the author of Digital
Copyright. Ranny Adams, a clinical
teaching fellow with the Intellectual
Property and Information Policy Clinic
at Georgetown Law Center. Paul Giz,
co-founder of Profina, a San Francisco
based personal data technology company
and senior lecturer at Vnius University
law faculty in Lithuania, where he
teaches courses on human centric data
privacy law and copyright X in
collaboration with Harvard's Burkeman
Klein Center for Internet and Society.
and Meredith Rose, the senior policy
council at Public Knowledge, a nonprofit
organization that promotes freedom of
expression and open internet and access
to affordable communications tools and
creative works. This is an ever evolving
field and we definitely also want to
hear your thoughts as well. There will
be plenty of time for Q&A at the end, so
please add your thoughts and questions
in the chat. With that, thanks again for
being here and we'll hand the
conversation to you, Stan.
>> Thanks, Alex, and thanks again to our
panelists for joining us today.
Um, let's do a little bit of scene
setting and I'm going to turn the first
question to to Jessica with a little bit
of intro here. When the DMCA, which was
uh enacted in 1998,
um became law, uh it included but was
not limited to the notice and takedown
provisions of section 512.
Um it had been the product of years of
discussion and negotiation about the
future of copyright in the digital
millennium. Why was notice and takedown
chosen uh as the vehicle to enforce
copyright online? And why weren't other
policy tools such as the framework
codified in section 230 of the
Communications Decency Act chosen
instead?
Oh, you're still muted there, Jessica.
The notice and takedown provisions are
one moving part in a huge compromise
with many moving parts. Um, and it's
worth appreciating just how terrified
uh, legacy entertainment and information
media were about the whole idea of the
internet.
Um, and the Clinton administration
basically promised them that they would
make the internet safe uh for movies and
music and software and everything else.
So, the compromise evolved with a bunch
of different pieces.
One of them was an investment in copy
protection that would, if not prevent,
at least make it extremely difficult to
gain unauthorized access or make
unauthorized copies of
any copyrighted material.
And uh a second was a an expedited way
for copyright owners to get stuff taken
down if an unauthorized copy made it
into the wild. And initially copyright
owners argued that any time an
unauthorized copy appeared in any
computer connected to the internet that
was a copy. it was actionable on a
strict liability basis.
And the telephone companies that were
that error as internet service providers
said that's absolutely crazy talk. Uh
but the Church of Scientology
uh responded to the unauthorized posting
of some of its secret church documents
by suing
everyone who had a copy uh from the
Washington Post onto the internet
service providers who transmitted the
files from Usenet
uh to various people's screens.
And the judge who decided that case
said, "Well, look, I'm not going to hold
computer systems liable for stuff they
can't know about and can't control.
They're just putting the systems in
place and people are using them. But if
they know, if someone informs them that
this is infringing, then I'm comfortable
holding them liable for not taking
reasonable steps to block it or take it
down."
And Congress in essence took that
compromise
and embodied it in the notice and
takedown rules. Now, the notice and
takedown rules got very complicated uh
because of different kinds of safe
harbors for different kinds of copies,
and Senator John Ashccraftoft insisted
on the putback
uh provisions that allowed people whose
material had been unfairly or wrongly
blocked to
uh get stuff put back. But the basic
judgment was that copyright owners are
in the best position to figure out
whether their stuff is online online and
it isn't authorized. Internet service
providers have no way to know whether uh
that file is there with permission or
without permission. whereas internet
service providers are in a better
position to take stuff down or block it
than anyone else. And so that struck
people as an acceptable deal.
>> Thank you. Um before I turn to Meredith,
I think worth pointing out that there
actually is no adjudicatory process
involved in sending a notice. Correct.
It was just a an allegation of
infringement that then
>> Right. That's what made it uh easier
because before this to get something
taken down you had to sue for
infringement and that took seven years
and $7 million. So in that sense
copyright owners were better off because
they got an expeditious
way of taking stuff down. On the other
hand, no one imagined uh today's
internet. If you're thinking well
copyright owner is going to see a file
and send a notice to Google which is
going to look at it and says yeah that
looks infringing. Uh that just didn't
scale. So many many people are relying
on automated processes and one of the
problems with automated processes is
there's no incentive to set them to be
less touchy than you might want them to
be. So they have pretty much been
overincclusive and uh involved the
blocking of a whole lot of stuff that is
not in fact copyright infringement.
Turns out uh risk aversion is hard to
code for I suppose. Um and also thank
you for you know bringing in church of
Scientology. You always know you're in a
good panel and that is part of the
response to question number one. Um all
right turning to you Meredith. uh can
you help us elaborate on the mechanics
of notice and takeown processes under
DMCA? Like how do they work? How do uh
the entities handle notices they
receive? How do various sizes of
entities deal with compliance? Uh how
have these online service providers
adapted to the requirements of notice
and take down beyond just complying with
the letter of the law? Um I think
Jessica teed that up just a bit, but why
don't you fill us in a little more?
>> No, she teed it up beautifully. Um, so
keep in mind, uh, there's what the law
requires and then there are sort of
private ordered solutions that are often
stacked on top of this. So if we're just
looking at the letter of the law, um,
essentially it's sort of a back and
forth system of notices. Um the reason
that this came about in the first place
as Jessica mentioned is that there is
this potential for secondary liability
uh on the behalf of platforms who you
know courts essentially will secondary
liability is the sort of court- created
doctrine where courts will go well
you're not the one who did the
infringing but you're sort of one order
down the chain and we think that there's
some sort of secondhand liability that
you can pick up from your failure to act
in certain situations. So in order to uh
sort of cover themselves from that um
platforms take advantage of what's
called a safe harbor. And the safe
harbor essentially works like this. If
you uh are a copyright holder or someone
authorized to act on their behalf, you
will then send a notice to the
designated agent um for that website or
that platform. Um the designated agents
are all listed on a website, I believe,
maintained by the copyright office. You
have to update your agent every so
often. Um and then you have to send a
notice which has a list of sort of
formalistic requirements. You know, how
do you contact me? Here's the work that
is um that we believe is being infringed
upon. Uh information that will allow the
online service provider to be able to
identify the infringing activity that
you are referring to. This can often
become very contentious because
sometimes they'll just say um copies of
my song and then if you're YouTube, you
go, I have several trillion videos on my
platform. this isn't helping. Um, but
essentially you send that notice and so
long as the platform uh I believe the
phrase is expeditiously uh acts
expeditiously to remove or disable
access to the material then they are
insulated from potentual secondary
copyright infringement liability. Um
then there is a second half to it which
is implemented less often uh by a lot of
platforms. Um, and the idea behind that
is that theoretically the platform could
be liable to the person who posted that
in the first place for taking it down.
Now, in order to insulate themselves
from that, that's when you have the sort
of notice and putback provision. Um,
which is the opportunity for the person
who uploaded it to go back and say, "No,
no, no. This is, you know, I have the
rights to upload this, or I believe it's
a fair use, or the upload is kosher in
some way, shape, or form." Um when the
platform gets that counter notice, they
have between 10 and 14 days to put that
back um they have to notify the person
who filed the original complaint and
then the person who filed the original
complaint has until the end of that
window to bring it to court uh and file
a lawsuit and notify the service
provider that they have done so at which
point it all gets punted out to a
federal court. uh because that
counternotice provision is really about
protecting the uh platform from
potential liability against their user
who uploaded it. That is not as widely
adopted. Um certain websites such as
Twitch straight up do not have uh
counter notice uh provisions or at least
have not had them at various provisions
in their history. Um and so that is kind
of touchandgo.
um failure to reinstate you know we get
into conversations about risk aversion
you know as Jessica and Stan have both
mentioned um now again because this is
you know this was designed in the late
90s under an assumption that websites
and service providers were run by a
small team of guys uh you know there was
there was a person who was reading the
email and analyzing it and thinking
about it and investigating it and going
hm we should take this down uh that
doesn't scale very well and so what a
lot of the larger platforms in
particular YouTube is kind of the
example that most folks think about.
They have created these sort of private
ordering systems that exist on top of
the law um which really kind of prevent
people from or or act as a sort of a
buffer between the actual user
experience of managing copyrighted works
and actually invoking the DMCA. Um so
YouTube for example has content ID which
is a sort of private internal system
which uh does a million in one things
all of which somewhat poorly. uh which
you know is designed to identify uh it's
allow it's designed to allow copyright
holders to upload samples to upload
their work so that it gets fingerprinted
and is scanned and they can send uh you
know they can demonetize videos they can
have takedowns they can strike things
sort of back and forth and back and
forth um but those are not strictly DMCA
systems I think a lot of folks get them
conflated because they're dealing with
copyright management on these large
platforms but going through that is the
step often in practical cases before you
end up invoking the DMCA. Some folks
decide to skip them altogether,
especially if you're a very small
creator. You do not have access to the
full suite of tools that things like
content ID allow you to use. Um, and so
oftentimes people will just go straight
to DMCA takedown notices. Um, but you do
end up with this very complicated
layered kind of system across these
different ecosystems. Um, each of which
is often bespoke to the different um,
sort of needs of every platform. And in
some ways that's a good thing. Um
because one of the problems that we have
run into a lot uh in the 27 years now
that we've been dealing with DMCA
takedowns is bad and abusive takedowns.
Um there was a statistic I believe from
2017 where uh Amazon's Kindle Direct
Publishing uh which again this is 2017
this is before it's kind of at the scope
that we know of today um commented that
out of all of the takedown notices they
get for their self-publishing platform
about 50% of them were just attempts by
rival authors to knock uh self-published
books out of the rankings. So a full
half of them were fraudulent um and were
specifically designed as sort of a keep
your name my name out of your mouth uh
kind of you know gaming the competition
within the system. And so every kind of
platform is going to have a different
threat model for the kinds of misuse of
notices. Um and you know the ability of
platforms to kind of develop their own
systems overall is a good thing. um even
when it leads to situations like Twitch
where there's no sort of putback
mechanism that they necessarily honor um
because they're not super worried about
their users being the ones to hold them
liable.
>> So I want to get you to say a little bit
a little bit more about uh about that
piece in particular. Um, in uh for the
legal nerds watching, uh, DMCA section
512F is at least part of the anti-abuse
mechanisms built in here. Meredith uh,
and or Jessica, could you say a little
bit more about just like what uh, what
has been the fate of 512F? Do people use
it and does it work to actually prevent
abuse of this existing notice and
takeown system? Uh functionally I think
the legal term is dead as a door. Um
it's uh yeah it has been litigated
before. Um it was I believe it was the
um Lens v Universal was the uh the
Prince dancing baby case uh where for
folks who are not familiar with it. This
is a very pretty famous case. A woman
uploaded a video of her toddler dancing
in her kitchen. And in the background,
you can hear a couple of bars of uh
Let's Get Crazy by Prince. Uh Prince's
estate um andor Universal uh took issue
with that and had it taken down off of
YouTube. Um she had it put back and then
we got there was a back and forth. I
don't remember the exact sort of
litigation posture of it in the early
stages, but one of the claims um that uh
Lens brought represented by the
Electronic Frontier Foundation um was
this claim under 512F which essentially
uh ostensibly punished sort of
misrepresentations and takeown notices.
Um, and this became this big litigation
question of whether a rights holder was
legally obligated to consider things
like is this a fair use or could they
just sort of fire indiscriminately when
they were issuing takedown notices. Um,
and the answer was
kind of maybe. Uh, Jessica can
definitely give a little more gloss on
that than I could. I mean, I think the
court held that yes, you have to
consider fair use, but one of the
problems with 512F is it doesn't really
have a remedy. So, it was also showed up
in a suit that Debold brought way back
early uh when a whole bunch of college
students at Sworthmore posted some
Debold internal documents that pretty
much revealed that its voting machines
were hackable.
uh and so it uh filed DMCA notices to
get that stuff off the internet and
ultimately uh was found liable under
512F for uh having misused the notice
and takedown procedure. But one problem
with that is that you don't collect
enough in the way of damages under 512F
to make any lawyer uh but a real public
servant willing uh to take the case. It
it's more of a slap on the hands. The
other problem is what you mentioned.
Most big service providers don't use
512. They use their in-house automated
systems and what uh so when
Mega Upload
uh posted a song, it got taken down by
uh I think Universal
and Mega Upload said, "No, this doesn't
violate any copyright of anyone. It's an
original song. you're just upset because
your artists are singing it
and brought a 512 F action and Universal
and Google said, "Whoops. Uh, there was
no 512C takedown notice. We didn't take
it down using the notice and takeown
procedure. we used content ID and that's
completely private and there is no
remedy
uh for abuse of our private content ID
system. And so another lovely story is
new NY NYU's Angelberg Center uh did a
webinar uh about music copyright
infringement in which it had two
musicologists
uh test tell the people in the webinar
about their methodology and how they
decided that songs in some famous
copyright infringement cases were were
not infringing.
uh the copyright owner uh in those songs
used content ID to take down
their webinar
and there they tried to use the internal
uh putback device and were completely
unsuccessful.
They only got it restored because some
of the faculty members of NYU Law School
knew some of the people in the general
counsel's office uh at Google and made a
phone call. But the Google putback
device is just completely ineffective
for normal human beings who don't have a
former student who's a lawyer with the
company.
>> All right. Thank you both. I think we've
done a pretty good job of establishing
how it started and how it's going um
here in the United States, but let's uh
turn our focus uh abroad for just a
minute. Uh Paul, I'd like to start with
you and then Rian, you may have some
followup on this as well. Uh what what
legal regimes have jurisdictions outside
the United States chosen for
intermediary liability? Um, and is there
a similar sort of split between
requirements for liability protection
dealing with copyright versus
non-copyright claims?
>> Thanks Dan and really happy to be here
to discuss this exciting topic. I also
came to realize that you know it's
almost 30 years since it was adopted. So
obviously there is a lot to unpack but I
think it's great to start by just noting
that DMCA was the first uh historically
the first legal act of its kind and it
obviously had global effects in shaping
the legal frameworks around the world
and it set the foundations not only for
laws but also for business models hash
content ID and also fostering debates
among policy makers, lawyers and
practicing attorneys as well as
academics. So outside of the United
States, countries have adopted many
framework different frameworks let's say
for intermediate liability and they
often try to balance uh different policy
goals such as harm prevention, free
speech or speech protection and
innovation. And uh briefly I would like
to highlight three possible variations
that maybe are worthy of attention uh
with regard to frameworks outside of the
United States. So the first one is a
actual knowledge or awareness approach
adopted in countries like Australia,
India, Japan and Philippines.
Briefly put uh intermediary liability
depends on whether the intermediary has
actual knowledge over the illegal
content. It means that intermediar is
required to promptly act typically by
removing access or disabling access to
the content once they are actually aware
of this illegal content. And maybe Japan
could be a great example uh of this
framework. So in 2001, Japan adopted a
provider liability limitation act uh
which uh under which uh intermediaries
are not liable uh for damages caused by
third party information unless it is
technically feasible for them to prevent
the transmission and they must have
either actual or constructive knowledge
about the infringement.
The second framework uh from foreign
jurisdictions could be defined as let's
say PR takedown sorry PR notice and
takeown system. So in New Zealand and
South Africa so far as I know uh there
is like a framework which requires
intermediaries to promptly remove the
content once they are notified and
failure to do that means that the
intermediary loses the protection and
the third one is probably most prominent
in Europe it's called mere condiate
approach adopted in Europe and now also
followed in the United Kingdom
but the idea is that interers are seen
as passive passive actors, passive
conduits and they are exempted from
liability as long as they do not
initiate, select, modify the content.
And uh here the e-commerce directive of
2000 distinguishes between three levels
of intermediary
uh responsibility mere conduit, catching
and hosting. depending on the
intermediate involvement
liability let's say or duties might
increase but uh but the idea is also
similar that intermediers have to act
expeditiously I think it's worth noting
and it's probably a segue into this AI
debate but there is a new act uh uh
digital services act which follows the
path established by the e-commerce
directive but also adds additional DSA
acts additional obligations on actors,
intermediaries, platforms in terms of
transparency and reporting about the
content they host. And to your second
part of the question, Stan, uh there is
obviously very clear bifurcation between
copyrightable or copyrighted content and
then other type of content. Another big
Pandora's box is privacy and free speech
uh type of infringements. So if I may
summarize obviously it's overstatement
uh but I think from a legislative
perspective we can see that regulators
around the world deem copyrighted
content as less harmful type of
violation than privacy invasions. So in
case of privacy violations, privacy
invasions, uh platforms are more induced
to respond promptly and there is a
greater let's say enforcement
opportunity for individuals to take down
the content. It's different framework
probably we can identify similar
patterns of notifying the platform but I
think privacy rights privacy related
violations are more uh important from
the regulatory point of view and are
worthy of greater protection. It's
probably overstatement but I think it's
worth making this point. Thanks.
>> Thanks Paul. Uh, Rian, anything to to
add to that from a international
perspective?
>> Um, I'm sorry. I I jumped out of the
call for a moment, so hopefully I'm not
um repeating anything that Paul said,
but um I just wanted to add one in kind
of uh recent update from the United
Kingdom, which I'm sure everyone has
heard about in terms of the online
safety act um which you know does not
pertain to uh copyright infringement,
but you know, we're going to be
discussing a bit later on about
non-copyright um re related liability
and um the online safety act concerns
intermediary liability in the UK.
concerning userenerated um illegal or
harmful content and and actually imposes
a duty of care on platforms um
particularly in relation to protecting
children from inappropriate content. So
I think that this really um
um moves into a platform responsibility
for non-copyright um harms which I think
has been like quite an interesting and
controversial um update from the United
Kingdom. Could you say just a few words
to compare the duty of care sort of
approach compared to the notice the you
know providing some point of knowledge
through a through a notice system just
just briefly outline what that looks
like.
>> Yeah. So um platforms are really
expected to be proactive. So this is
including um content moderation.
Platforms are really required to
implement systems and processes to
identify and remove that legal content.
So I think that kind of uh creates a
burden on um platforms really to take on
that responsibility.
>> Thank you. Um I guess it might be fair
to characterize that as sort of a an
assumption of some form of knowledge on
the platform's port and then they're
already required to take action there
rather than having the notice come from
>> uh a user for a specific instance of
something and then they respond to that.
Um so let's I think we'll we'll move
sort of away from copyright slightly
here uh with the next question. Um this
year in particular but um not not
constrained to this year uh we've seen
an expansion in the sort of interest in
and logic of notice and takeown of other
kinds of notice based frameworks uh for
conditioning intermediary liability
protections. For example, the recently
enacted Take It Down Act and then the
recently introduced No Fakes Act. Uh
both pertain to non-copyright
material per se, but do involve a a
similar notice and takeown system. Uh
what does the use of this kind of
framework for non-copyright legal claims
show about either the success or
popularity of the DMCA framework or
whatever else it may say about uh that
framework? Um, and how will or won't
this approach to uh online copyright
enforcement translate into non-copyright
contexts? Um, Rihanna, do you want to
kick us off and then I think this is
probably a question that everyone might
like to take a piece of.
>> Yeah, hopefully I can kind of provide a
bit of a background on the act um and
then that can kind of start off the
conversation. Yes,
>> please. Um but yeah, the take take it
down Act provides a really helpful
example of how notice and takeown
framework translates into a a
non-copyright context and um it
regulates the non-consentual
distribution of intimate imagery or NDI
um and it was passed by Congress as as
you mentioned this year and it's it's
the first federal law that's regulating
um AI generated content. So, it's quite,
you know, um it's it's a first of its
kind and and the take it down act is
really supposed to fill in gaps in the
resources available for victims of NDI
um under the DMCA as well. Um notice,
you know, the the notice and removal
provisions under the DMCA are available
for those who have been affected by D
NDI, but only where the individual of
course owns the copyrights. This is
primarily selfies. Um so, the take it
down act addresses that gap. um when the
individual doesn't own the copyright. So
this might be when there is a synthetic
depiction of the individual created by
artificial intelligence for example. And
and the legislation um specifically
includes uh a definition um where the
deep fake realistically depicts the
individual such that the that a
reasonable person would believe that the
individual is actually depicted. And
then maybe we can go into a bit of a
conversation later on about that um
about concerns over that definition, but
the the the act really requires covered
platforms to remove NDI within 48 hours.
So it it models the um DMCA's section
512 and um it requires platforms to
create a process through which victims
of NDI can send notice to them about the
existence of such material. But the the
issue with the take it down act is that
it's not it hasn't included any of the
DMCA's safeguards. So, you know, we
we've spoken about this and and in
particular Jessica and Meredith have
have gone over um the provisions for the
counter notice. Um there's also um
individuals must attest under a penalty
of perjury that they are authorized to
act on behalf of the injured person
under the DMCA. Um the DMCA imposes
liability on individuals who make
knowing and material misrepresentations
about the um the nature of the content.
But under the uh take it down act we
don't we don't have any of these. So
there's no requirement for an individual
submitting to a test under the penalty
of perjury um and instead any any
removal notice about an intimate visual
depiction may be submitted um by a
person claiming to be the depicted
individual or their representative. So
there's there's no legal consequence for
impersonating someone or falsely
claiming to act on their behalf. Um
there's no not counter notice provision.
Um
you know we we've gone into a bit of
detail about whether or not that's been
a success or not, but um uh individuals
also cannot claim against platforms
under the Take It Down Act for the good
faith disabling of access to or removal
of content. So there there's no recourse
against platforms. um even if that
visual depiction is later determined to
be um lawfully published and and this
this good faith standard is rather vague
um and opens up opportunities for
misuse. Um
also the law requires only a reasonably
sufficient identification of the
content. Um and really you know I think
that under the DMCA this level of
ambiguity um would likely invalidate a
request. So, you know, in in summary,
we're we're seeing the DMCA framework um
implemented in new ways in non-copyright
context, but it's kind of a far far
weaker imitation of of the original.
And, you know, we've we've all seen
that, you know, even with its guard
rails, the DMCA has successfully um been
used to remove protected speech. Um and
when we don't have any of those
safeguards at all, I think this raises
some um real concerns about how the take
it down act is going to be implemented.
>> Indeed. And uh no fakes I think is
similarly situated. Um I I do want to
move us on to questions from the
audience, but I also want to hear from
Jessica, Meredith, and Paul on take it
down or no fakes before we before we
skip ahead. Well, I think what made the
notice of takedown regime attractive
here was that it's administerable.
Indeed, most of the online service
providers already have a system in place
to do this. so that to the extent that
they uh needed to sign on in order for
this to get through Congress saying,
"Okay, but let's use a system we're
familiar with and we have and we've
implemented." All of the safeguards in
the DMCA were achieved because of people
negotiating on behalf of
other folks who worried their speech
would be suppressed or worried that uh
uh there would be wrongful takedowns.
And to the extent it's really hard for
someone to stand up and say, "Hi, I want
to post uh naked selfies of my
girlfriend without her permission.
please give me uh the safeguards to
allow me to do that. Um there wasn't
anyone pressing for the kinds of
protections
uh for legitimate speech that people
might want to take down to cause
Congress to say, "Okay, we'll
incorporate those safeguards into this,
too."
>> Great point. Uh Meredith, any comment on
either of these? I'll note that 48 hour
takedown notice uh notice to removal is
pretty short. Um
>> it's pretty fast. Um, one of the other
things that we've seen, you know, and
this is part of a general trend is that
ever since the DMCA was passed, so for
the last, you know, upwards of a quarter
century, um, you know, I think content
holders would prefer, uh, that we move
to what's called a notice and stay down,
uh, regime, which is essentially this
idea of once I have it taken down, you
must now proactively filter so that it
never comes up again. uh which is a bit
of a pipe dream technologically for all
but the absolute largest of these
platforms and even then uh everybody's
got a story about content ID. It's the
most expensive and high-end system out
there and it's still kind of a disaster
at times. Um and so take it down I
believe has a notice and stay down type
framework in it. um which is only sort
of administerable because there is a um
there is sort of a mechanism that is
used um for CESAM which is um uh is I
don't remember exactly what the acronym
stands for child sexual abuse uh imagery
uh or material um which is that there's
a a sort of there's a technical
workaround involving hashing and the
Nickmick database that they can they can
glom this on to um one of the concerns
though as somebody who works in
copyright policy is We see a lot of
situations where this happens and you
had this notice and stated in a much
narrower context. Um, which is, you
know, again, you're you're dealing with
a a semi-nown universe of potential
problems and a semi-known universe of
files that you need to keep an eye out
for. Um, copyright because it is so
extensive and applies to anything that
is sufficiently expressive and embodied
in a tangible medium of expression. Um,
you cannot that that is the entire
universe essentially. And so when we
start seeing um notice and stay down
mechanisms, uh one of the things that we
try to keep an out eye out for is you
know is this going to be used as proof
of concept that actually we can do this
for the entire universe of copyrighted
material and the answer is no. But that
doesn't stop people from saying well
maybe you need to nerd harder at the
problem.
>> Um yes, nerding harder is quite often
part of the solution implied in many
pieces of legislation these days. Um, I
will just note before passing it over to
Alex for audience Q&A that the no fakes
act um also requires a stayown type of
thing and uh strongly implies that uh
online service providers should build
their own hashbased matching system and
filter uh to prevent the upload of
identical copies of deep fakes I
suppose. Um, so lots of uh lots of nerds
to be employed in the future should that
become law. Uh, over to you Alex for
questions from the audience.
>> Amazing. Well, on the subject of the no
fakes act, uh, let's start with this
one. Uh, no fakes includes language that
seems to create a right of publicity
that is very similar to to a copyright.
How well would or wouldn't importing the
logic of substantive copyright
protection into a right of publicity
work?
So I can I can hop on that one. Um one
of the so the fundamental aims of
copyright and rights of publicity are
different. Um, so the idea behind a
copyright is that you or between the
American conception of the copyright,
I'm speaking at a very very broad level
here, but the American conception of
copyright is a policy decision that a
creator has put effort into creating a
work and in order to allow them to
potentially recoup the cost of creating
it in terms of their time and their
energy, we will give them a limited
monopoly for some amount of time. But
it's it's designed specifically to
incentivize the creation um the
production of more works that are then
made available to the public in
exchange. Um right of publicity and name
image likeness rights which are sort of
cousin a cousin framework to right of
publicity are um in the United States
generally only available to folks whose
uh likeness has commercial value. So
they are available to um you know the
high high-profile cases are famous
actors, singers um you know sort of
folks like that. I do not have rights of
publicity. Uh I think most people on
this panel um no shade to anybody
involved but and most of us on the panel
are not going to be recognized on the
street by our faces alone. We're not
cutting licensing deals for ads. Um, and
so the idea behind publicity rights is
that if you have a likeness that is
valuable and someone goes and uses your
likeness uh without your permission to
make it appear as though you were
endorsing a product that they don't just
kind of get away with that scot-free.
They do owe you some financial
compensation for it. Um, again, this is
like grossly oversimplifying it. Um, the
problem that happens when you create
when you try to scale these publicity
rights is that when you're you're
creating an all-purpose tool in the
process of trying to create something to
get these things taken offline, right?
So, the question is, well, if you're a
famous actor and you want your uh
likeness or a deep fake of you removed
from YouTube, how do you do that? Um,
well, there needs to be some kind of
mechanism to do that. How do you
restrict that to only people whose
likeness is commercially valuable? Do do
you have a content ID situation where if
you're a super special rights holder?
Um, you know, if you're the special boy
that uh YouTube decides you get to have
access to the special control panel or
whatever. Um, no fix creates a sort of
general purpose tool that is available
to anyone. um including folks like me
who I when I if I there's a deep fake of
me out there. It's a I have a very
different threat model and a very
different damage model for what that's
going to look like than if it's Brad
Pitt. Um I'm not losing out on licensing
revenue. I'm worried about somebody deep
faking me either into non-consentual
intimate imagery, which is things like
take it down um or deep faking me into
doing something embarrassing that would
potentially be like a defamation claim
um if I was to pursue it in court. Um,
and the other thing that we've learned,
again, as at my local angle as somebody
who deals with DMCA takedowns, is these
things are abused like crazy. Um, and
right now we do not have the technology
to sufficiently detect whether or not
something is an AI deep fake or not. Um,
and so the second one of these tools
comes out that says, you know, you are
now hereby legally uh empowered to
demand the removal of something that is
a deep fake of you, uh, there's no way
to reliably distinguish between deep
fake and real footage. And so the very
first thing you will see this being used
for if it becomes law is taking down
embarrassing footage of politicians. It
will be used to take down videos um of
police brutality or public misconduct.
You know with the claim that oh this is
absolutely a deep fake of me. Um and no
fakes has no no putback mechanism. You
know we sort of discussed this in the
DMCA. There is a putback mechanism. It's
not a particularly robust one and a lot
of people ignore it. Um no fix doesn't
even have that. It's it's once it's been
taken down it needs to go down. needs to
stay down. Um, so it's a very very
dangerous framework because it's been
designed explicitly for um for actors,
for celebrities. It's been designed with
this economic model and not for the rest
of us.
Okay, amazing. Uh, moving on to our next
question. Um, has there been any legal
push back to the automated content
recognition systems used in DMCA
compliance, which I assume means AI and
and automated uh processes.
Um, so there's a fair amount of
scholarship now, legal scholarship and
technical scholarship documenting the
problems. Um there isn't really any
legal cause of action
uh because
the notice and takedown in the DMCA is
uh styled as a safe harbor. No one has
to comply with it. It's just what
service providers can do if they want to
avoid liability.
So failing uh to
uh provide
any of the elements of it isn't
independently actionable. Uh all it is
is a shield from liability. So, while
there's lots and lots of scholarship
documenting tons of problems,
uh the only case I'm aware of is the
case against uh the case brought by Mega
Upload uh for wrongful takedown and that
got dismissed because the takedown was
not pursuant to uh DMCA notice.
All right. Um, so another question. Um,
with the new administration in the US
utilizing the law somewhat haphazardly
and with an eye towards results rather
than focusing on the process itself, how
do we view triaging takedown requests?
For instance, if a site gets to request
to take down information related to DEI
from the executive branch, but it's not
necessarily within the executive
branch's jurisdiction.
So technically, if the request is for
anything other than a copyright related
uh infringement claim, it's not
considered a valid notice. So this is
something that is baked into the DMCA.
Um, no, as a practical matter, uh, what
actually often ends up happening, as
anybody who's followed YouTuber drama
can attest. Um, what usually happens is
it's framed as a copyrighted claim, a
copyright claim, and really there's sort
of a secondary motive for that. Um,
having said that, websites, especially
smaller websites, do have the, you know,
a lot of them are still using individual
review. Um, you know, we work a lot with
the organization for transformative
works, which runs archive of our own,
the the very large fanfiction archive.
Um, they manually review their takedown
requests. Uh, they don't get a ton
because they're a fanfiction archive.
So, people sending DMCA takedowns to
fanfiction are kind of wild to make uh,
conceptually, but they do get some and
they they manually review them. Um, you
know, and a lot of them are not valid
requests. Um so to that extent on an
implementation level you know websites
do have some choice in how they want to
review this thing. Um and typically if
you get political pressure to remove
content from a website it tends to come
through other avenues rather than a DMCA
request.
All right. Uh next question. Does the
DMCA or case law pertaining to the
notice and takedown regime address the
issue of enabling the heckler's veto
through this regime?
I mean, I think that's what the 512F
uh cause of action for misrepresentation
is trying to do. Um the reason it's been
ineffective is largely that it doesn't
include the kind of remedies that make
it financially feasible to litigate. Uh
so it's uh uh an option that few people
are motivated to use because it's just
too expensive.
But that's uh indeed baked into the
structure of of the DMCA.
Amazing.
Um, so next question. How does the fact
that AI generated content isn't
protected by copyright affect notice and
takedown regimes versus no fakes that
has a textual uh recognition of AI
generated content?
>> Maybe I can take this.
I think actually there is a very big
debate on I think gray zone in terms of
what is protected and not protected by
copyright and it's a long conversation
but I think uh it has been
oversimplified by the US copyright
office uh by stating which was stating
that you know if you use AI tool it's
not copyright protected. I think it's a
very narrow perspective and it does not
reflect how real creators use AI tools.
Usually it's a collaboration with
multiple tools, traditional digital
tools and modern AI tools. So I think uh
it's very let's say it's very contested
position by US copyright office just to
suggest that using AI tools is not
necessarily or necessarily leads to no
copyright. So that's one big problem and
I think the big challenge is that okay
so if we have a uh content that is
created with the assistance of AI tools
uh how do we identify you know the
copyrightability how does it fit within
the DMCA framework I guess it's a topic
for the next h next webinar but in terms
of uh I would like to address Meredith's
points uh on no fakes and the deep fakes
I guess yes notice and take framework is
really needed for individuals, not
necessarily who are celebrities, but
each and every one of us. We need to
have tools to be able to request
platforms to remove the content that
maybe is impersonating us, not only our
visual appearance, but also it can be
our voice, right? It can be other
biological physical traits that we might
have. So notice and take down framework
or similar framework is needed for all
of us. But I would say that we probably
need to go one step forward and
establish a bit more clearer framework
that actually it must be like some sort
of opt-in framework so that third
parties that are using AI tools to
create digital replica of Jessica who I
would argue is a celebrity right but
also me and myself right if someone is
trying to impersonate me I think by
default we should see that it's our
inherent right to give a ex anti-consent
for third parties to create replicas
because in Silicon Valley you can
imagine there are many companies that
are making digital rep replicas not only
of celebrities that could be your
shopping assistant but also
impersonating anyone right any
individual. So we need some kind of a
new framework uh new contract with
technology that people actually should
be given the opt-in rights for third
parties to create their digital
replicas. So it's kind of a new
framework we need to think of not only
notice and takedown but what happens
before that can someone take my voice
and and use it
>> for different purposes. So I think it's
important that that framework not be
modeled on copyright. That is the thing
about copyright law not only in the US
but also in Europe is it's really
designed to encourage people to alienate
to transfer to sell their rights to
someone else. And I think one thing
we've learned about right of publicity
regimes is as soon as this right is
assignable, it start co starts causing
all sorts of trouble. So there are for
sure companies in California right now
who are hiring um actors
to do voice work and asking them to sign
a uh all rights in those recordings of
their voice so that they can use them
for AI. I think we also need some
opportunity
uh to take back
assignments that we've made. Um and that
it needs to be a right that if we have
it isn't something we're encouraged to
sell uh when we need the money and then
we don't own it anymore. So that
requires a kind of thinking that is less
based in intellectual property and I
think more based in tort
uh and in dignitary considerations.
>> I will I completely agree. I will just
piggyback on I think the reality of why
why just contextually sort of in the US
in particular why we've seen a lot of
these ticket copyright framework comes
partly from the fact that the first
industries to jump into action in
response to this were major
entertainment industries. And when you
have a hammer kind of everything looks
like a nail. Um and also uh the
complication posed by section 230 um
which is again for non-American I'm
grossly oversimplifying. Um section 230
essentially says that platforms
generally speaking cannot be held liable
for things that their users put on the
platform. Um and there's a handful of
exceptions to that and one of those is
intellectual property. Um, every time
Congress tries to punch a new hole and
add a new exception to 230, it turns
into an absolute circus. Um, and so the
political reality is that most folks see
that the only way they can get any kind
of takeown mechanism. You have to find
one of those existing tunnels through
section 230 and intellectual property is
one of them. And so that is they have
been funneling it through that as a
matter of political expedience.
>> Amazing. And I think we have time for
one last question. Um, bit of an
open-ended one, but I I I think an
interesting one to to end on. Uh, have
there been any proposals for alternate
regimes to the notice and takeown
regime?
Uh, well, we've seen proposals for
notice and stay down. Um, that's been
the that's been the main contender. Um,
again, you run into a lot of
technological problems. um some of which
were foreseen pretty aptly by Congress
in the late 90s and many of which were
not. Um I think that's been the big one.
Um you know again even speaking as
somebody who spends a lot of time
dealing with notice and takedown abuse I
think there is a very begrudging
near consensus in a lot of folks on the
policy side of this that notice and
takeown perhaps not as instantiated
right now. I think we've all got
complaints about the way that it
actually works, but conceptually ends up
being kind of the best solution to a
otherwise pretty much intractable
problem. Um, and the question becomes
really how do we reform that really more
than how do we toss it and build
something entirely different?
Also I can add
in the age of AI with with this advent
of new let's say AI assisted AI
generated content clearly there are
efforts to create new frameworks that
are already AI powered frameworks to
manage what gets out and what gets noted
what gets uh let's say flagged clearly
there are companies working on that I
think it will take years to make it into
let's say something actionable but uh
the technologies are moving so fast it's
obvious that we cannot really cope uh
with that much AI assisted content with
existing frameworks. So we need to come
up with new technological layer to let's
say organize
the content.
>> I think Paul's right. I'm going to jump
in to close this out here. But before I
do, I'll just observe on on Paul's point
here. you know, talking about content ID
as a hashbased matching system uh sort
of built on top of in addition to the
DMCA requirements.
I wonder if those type of systems will
work less well against uh sort of a
flood of novel images, we'll call them
that, right? You can you can generate
easily any number of variations of a of
a deep fake that will not have the same
hash as each other. Um, and so it could
be quite difficult to automate a system
uh at least based on that technology.
What uh what might fill in that gap uh I
think is an open question at the moment.
Um so you know tune in again next summer
when we're talking about the latest and
greatest from uh the AI industry on how
they're self-regulating this problem.
I'm sure they will all get right on. All
right. Thank you so much to our
wonderful panelists uh Rihanna, Jessica,
Meredith Paul. It's been a pleasure
hearing from you all today. Thanks again
to our legal fellows who did a wonderful
job putting this panel together um and
for organizing the whole thing. Um we
welcome you back anytime. Um thanks for
being with us today.
>> Thank you all. Thank you.
>> Thank you.