By Dr Ben Collier, Dr Morgan Currie, & Dr Benedetta Catanzariti
We are a team of researchers at the University of Edinburgh’s department of Science, Technology, and Innovation Studies, with a broad range of expertise and experience relating to digital technologies. The Scottish Parliament has commissioned us to conduct this research study evaluating the potential threats, risks, and mitigations to parliamentary business associated with novel generative AI technologies. We have been asked to consider particularly the threat of deepfaked video to the integrity of the Parliament video livestream and archived recordings of parliamentary business - a phenomenon which one of our participants dubbed ‘chamberfakes’. Scottish Parliament makes its live streamed and archived video of chamber and committee business widely accessible to major broadcasters and to the public directly through its website and on major social media platforms. Parliamentary video is produced as a neutral record of parliamentary business, and its accessibility serves a core democratic function of making the Scottish Parliament visible to the public. At the same time, this broad accessibility could lead to security vulnerabilities, including deepfake attacks. The report identifies three main deepfake-related risks: 1. Hacking the video livestream, either through a cybersecurity breach or by compromising a live participant dialing in through Zoom 2. Disseminating deepfakes on social media platforms 3. Creating deepfakes using parliamentary video material as a training resource for online harassment and abuse of MSPs While deepfake technologies are part of concerning broader trends in the proliferation of misinformation, abuse, and organised political interference, they do not generally represent a step change in capabilities for most hostile actors in the context of Parliamentary video. Instead, they generally offer small-to-medium scale reductions in barriers to entry for some existing forms of harm. Scottish Parliament has no formal processes in place to respond to these deepfake threats. However, Parliament’s strong institutional resilience - particularly the deep knowledge and experience of its staff - can play a current role in preventing or mitigating threats. The broadcasting team has multiple people who monitor both the live transmitted video and online video stream, ensuring the video transmission chain proceeds correctly. Parliament’s strategic risk register is already set up to respond to cybersecurity and personal online security threats to MSPs. The Official Report of Parliament, the transcript of all the Parliament's public proceedings, offers a record to check video suspected of tampering. Beyond current practices of risk management there are several technical, educational and legal solutions that could be adopted as future mitigations to deepfake risks. Considering deepfakes in relation to a broader constellation of risks and finding an optimistic picture of the resilience of Parliament to these threats, this report focuses its recommendations on several key institutional solutions that Scottish Parliament could adopt. Recommendations: 1. Develop formal intervention plan and reporting procedures for a deepfake or misinformation attack, involving the assignment of responsibility for this process to a specific individual via the risk register and establishing reporting procedures to UK Parliament and ministers and to MSPs 2. Institute further material and human-in-the-loop checks, including having cameras dump a live feed to file locally straight from the recording apparatus itself, authentication checks for participants dialling in to give evidence, and retaining an in-house staff to monitor the feed in comparison with live proceedings 3. Establish a communications team (or hire a small number of dedicated communications staff) within the broadcasting unit to support to MSPs who encounter or are victims of misinformation, track how parliamentary content is being circulated and used, and promote the use of parliamentary video through communications campaigns and direct engagement with broadcasters and platforms
Edinburgh: The Scottish Centre for Crime and Justice Research (SCCJR), 2024. 29p.