This Research Spotlight highlights findings from a pilot empirical study conducted between January and March 2023, funded by the EPSRC Trusted Autonomous Systems Hub. The full report is available here.
Generative AI models and global governance
Generative AI models, which allow the automated production via prompts of text, images, code or other creative products similar to those produced by humans, have, since the debut of ChatGPT in November 2022 captured the public’s and media’s imagination ( though they are not in fact entirely a recent development) and ridden a wave of global hype and venture capital. Big tech companies such as Google, Meta, Alibaba, Amazon, and Apple have integrated foundation model technology into their flagship products, apparently whether helpful or not. Literature highlights however that these models may create serious risks for users and society, including generating “hallucinations”, fake news and harmful content, infringing copyright and privacy laws, and raising environmental, security, and workplace concerns. These worries have lead many nations to consider regulatory measures, including bespoke legislation such as that found in the EU AI Act or the Chinese Generative AI Measures; adapting existing laws; and implementing ‘soft law’ measures like codes of conduct and industry guidelines.
Private ordering and generative AI
Until the relevant parts of new legislation such as the EU AIA comes into force (still at least a year off) governance of AI providers remains, quietly, largely in their own hands. Companies set their own rules through terms and conditions (T&C) or “terms of service” (ToS), privacy policies, and licenses. Legally binding documents are augmented by more flexible guidelines like “acceptable use” policies and codes of conduct. In the contractual context these rules are known as private ordering . Understanding these terms is important because, in the absence of specific litigation or new legislation, they largely determine the rights of users and creators. Historically, ToS in the business-to-consumer (B2C) digital services context have been trenchantly criticised for being largely unread, poorly understood and non-negotiable in semi-monopolist markets, leading to oppression of users : Palka has labeled these “terms of injustice” . Drawing on this history of platform ToS research, we decided to investigate if the issues around online platforms ToS were recurring in the context of generative AI services.
Thus between January and March 2023, we conducted an early pilot study to evaluate the terms of ToS of 13 generative AI providers, encompassing both major global firms such as Google and OpenAI, as well as lesser-known companies thoughout the globe. Our analysis covered a range of AI models, including Text-to-Text (e.g., ChatGPT and ERNIEbot), Text-to-Image (e.g., MidJourney and Nightcafe), and Text-to-Audio/Video (e.g., Synthesia and Gen-2). We specifically examined clauses related to privacy and data protection, handling of illegal and harmful content, dispute resolution, and copyright. Some areas such as copyright were familiarly crafted, while at this early stage data protection was often ignored. ToS drew heavily and perhaps inappropriately on state of the art in social media contracts.
AI providers as ‘neutral intermediaries’? The ‘platformisation paradigm’
Crucially, our analysis of ToS showed that genAI providers, almost without exception, assigned all risks including copyright infringement and content liability to users, even though it is the providers who control and obscure many of the factors productive of risk (eg the contents of the training sets), exercise or fail to exercise restraints over users (eg guardrails on prompts) and also, of course, take the profits. By way of quid pro quo, however, providers invariably assigned ownership of and copyright in outputs to users. AI providers thus appeared to be positioning themselves in their ToS as “neutral intermediaries” in a way similar to traditional social media providers and search engines. These online platforms have long argued they are mere intermediaries, and liability should accrue to users, not themselves, and largely to date the law, at least in the US and EU, has agreed with them, albeit with the addition of notice and take down obligations. However, AI providers do not merely host or give access to user-generated content but rather publish AI generated content as a service, and therefore should in principle retain liability for the outputs. Instead however they are using ToS to offload liability on to users while also evading the enhanced responsibilities for platforms that more modern laws such as the EU Digital Services Act (DSA) are introducing, displacing the old “neutral intermediary” model. We term this a ‘platformisation paradigm’, where genAI providers recreate the neutral host status of platforms while avoiding newer governance responsibilities. We argue that this issue needs to be addressed, potentially through consumer protection law or by extending the DSA to cover generative AI and foundation models.
While the DSA is a significant European regulatory tool, it’s important to consider global perspectives as well. Currently, China is leading in regulating generative AI, requiring pre-approval from its regulator (CAC) for AI models before they are publicly available. This pre-market approval process includes scrutiny of ToS and privacy policies, which offers a potential model for harmonising and regulating AI contracts more broadly. Moreover, we suggest that the idea of a regulatory body overseeing AI models, similar to the concept of a ‘Food and Drug Administration for AI’ could help standardise and ensure fair practices both in relation to B2B and B2C contracts While the DSA and other European regulations protect consumers, they do not largely address the power imbalances in B2B contracts, such as those between AI model providers and smaller deployer firms. The European Parliament had previously proposed regulation for unfair terms in contracts with SMEs in the EU AIA, but this provision did not make it into the final version.
In conclusion, the current ‘platformisation paradigm’ allows AI model providers to evade accountability by shifting risk to users in their ToS, an inequity which may not be met by laws such as the DSA or consumer law, especially in B2B contexts which importantly arise down the AI value chain. We suggest a case exists for amending the DSA to include foundation models.
