Machine-readable formats: Plain text · JSON
Transcripts available through this tool are created by using automatic speech recognition and are not official records nor official documents of the United Nations. Official records and official documents are available on the Official Document System of the United Nations. Learn more
Buenos dias. Welcome, everyone, to workshop four. We now go to the stage of workshop four, which is titled "Turning the Digital Age into an Opportunity: Promoting the Responsible Use of Technologies in Crime Prevention and Criminal Justice." So we are focusing on two main subjects. dual use technologies and regulatory frameworks to ensure that technology in the criminal justice system upholds human rights protections. And this subject gives way to the first subpanel. And the second subpanel will deal with international cooperation and public-private partnerships for strengthened crime prevention and streamlined criminal justice responses to cybercrime. So again, I am pleased to have the support of Ms. Ottavia Gallucci from UNICRI to moderate this panel. So I'm going to give her the floor, and she will be kind enough to also introduce briefly the substantive work, as well as the keynote speakers and the panelists of this session, as she did yesterday. Ms. O'Brien from UNODC will also summarize at the end of the discussion the key and salient points of the debate during this second session. So, Ms. Gallucci, the floor is yours.
Thank you, Mr. Chair. Good morning, ladies and gentlemen, distinguished colleagues. Thanks for joining again workshop four. Today, we're going to continue the conversation that we started tomorrow, following the two sub-panels that Mr. Chair just outlined. So the second part of Workshop 4 aims to focus on how we can govern dual-use technologies, specifically through regulation and international cooperation. In the first sub-panel, experts will present on regulatory frameworks to ensure that dual-use technologies are responsibly implemented in the criminal justice system, upholding human rights protection. With this, I would like to introduce our first panellist of this morning, Ms. Eva Pastrana, Head of Criminal Law Division at the Secretariat to the European Committee on Crime Problems in the Council of Europe. Previously, Ms. Pastrana worked as head of the Council of Europe Justice and Human Rights Training Division until January 2024. Earlier, she was the EU Human Rights Justice Attache in Georgia and the Philippines, Justice Coordinator for the Spanish MFA and Judiciary Council in Nicaragua, and for six years for a Spanish NGO's foundation in charge of Maghreb and Middle East countries. Ms. Pastrana was also elected to represent Spanish NGO coalition to ensure the ratification by Spain of the ICC in 1998. Ms. Pastrana, the floor is yours. Thank you.
Thank you. Thank you very much to UNODC, to you, the panelists, Ambassador. So I have a presentation that I would like to use. And first of all, I'd like to convey some detail about the Council of Europe. Let me see. This one? Okay. Here, here we go. So the Council of Europe is the largest intergovernmental organization. It's made-up of 46 member states of very different backgrounds, cultures, beliefs, and people. You need to imagine that we have countries from Portugal to Turkey, Iceland to Malta. So when we negotiate treaties, we are talking about very difficult negotiations. Of course, we come here under the UN roof, and we need to approach our role with humility. However, the collective agreement of these 46 countries of the world can be.
Of use for the rest, for other countries.
And many of our conventions are open to non-Council of Europe members.
We have also five observer states, Canada, the Holy See, Japan, Mexico, and the USA. And we have so far built a very successful human rights protection system out of the ashes of the Second World War with the motto of never again destruction, never again the war. So we agreed on the basics on human rights.
And we have this European Convention on Human Rights that binds all 46 member states.
We have produced pioneering global legally binding standards and conventions on topics like extradition, MLA, transfer of sentenced person, a convention signed by 70 countries worldwide, but also cybercrime, the so-called Budapest Convention, protection of personal data, bioethics, and now artificial intelligence. On this Council of Europe Framework Convention, Artificial Intelligence, Human Rights, Democracy and Rule of Law, is the first legally binding treaty in this field. It was negotiated by all our Council of Europe member states, the observer states, but other states, including Australia, Argentina and Peru. and it involved 68 civil society organizations, private sector representatives, and it gives you the idea of the scope of the negotiations. The convention is complementary to international human rights, democracy, and rule of law standards. It's also complementary to the EU AI Act. And it's technology neutral to remain future pro. So it doesn't regulate technology. The scope is applicable to both public and private sectors. And then something which is excluded from the scope is national defense, military security, and data and research associated, except if it impacts significantly human rights of a person. But in principle, it is excluded because it is not in the core mandate of the Council of Europe. It requires fundamental principles such as human dignity and individual autonomy, equality and non-discrimination, protection of privacy and personal data protection. In the Council of Europe, it's not just the data that we protect, it's the person behind the data. We spoke a lot about these principles yesterday. Transparency and oversight, accountability and responsibility, safe innovation and reliability. Then it imposes some remedies and procedural rights and safeguards for all the activities within the life cycle of AI systems. There is an obligation to document the information regarding not only AI systems, its usage, and to make it effective to a valuable person. This person may have the possibility of using this and lodging a complaint to the competent authorities. And of course, this provides procedural safeguards and rights. And it's important to include always the provision of this notice that one is interacting with an AI system. Finally, it also requires the management of risk. Currently, the Council of Europe is not in the slide, but the Council of Europe is designing with the Alan Turing Institute, a risk assessment program called Huderia, which is very, very innovative and can be very useful for countries. It is critical and a crucial element is risk and impact assessment. And there is an obligation of the relevant actors to conduct it. They should be conducted not only once, not only at the beginning, but iteratively, so periodically. I invite all of you to go to see this convention. Is it perfect? No, it's not. It is the most Is it ambitious? It's not as ambitious as many would have wished, but it was the most ambitious treaty we could achieve, considering the times and the geopolitical context we are living in. Here you have some links to explore more our work. And now let me turn into another first legal instrument, not legally binding, but a legal instrument on the field of accountability for tech facilitated violence against women and girls. This kind of violence can take many forms, stalking, hate speech, intimate images generation or sharing without the person wanted it, of course. or abuse in the metaverse. And we have seen that it has significant impact at individual, family, community, and society level. The increase of cases of reporting just in the UK, it has increased 20 from 1000 in 2024 to 25,000 in 2025. And this is a pandemic everywhere. And the mental health issues that it is generating and the costs associated to it are being paid by every country. This recommendation places, wanted to place accountability at the center. And not only offering civil and administrative remedies, but also criminal remedies. And it's not just about the perpetrator. It's a shared responsibility. Victims may talk to a lawyer, to a police officer, to an NGO. The prosecutors need to know how to manage digital evidence, and platforms need to be accountable. So it's a whole chain. And if any of the parts fail, we're failing the victims and we're failing us all. That's why this recommendation It's just to support authorities and practitioners from the beginning. I'm just gonna focus on three main sections. One is the call for a stronger legal and policy framework. As I said, criminal law and sanctions. And sanctions should not be only effective, but also dissuasive. Second, I'm going to go quick. Second, the recommendation places importance on ensuring effective and accessible justice system. They need to be easy to use and easy to access for the victims. And then finally, a very innovative chapter, which maybe it's not strange to you, it was the most difficult chapter to negotiate and to agree. And it is because recommendations of the Council of Europe adopted by 46 member states are addressed to authorities. But in this regard, the authorities have the obligation to ensure that tech companies and internet intermediaries are accountable if they cause harm. And this is why this chapter was very difficult, because we cannot ignore the power of these tech companies and the lobbies. And we had difficult issues from unexpected countries. So we ensure that it's not only safety by design from the outset, but also throughout the development. They need to have accessible and user-friendly reporting systems. You don't need 20 clicks, you don't need 30,000 pages that no one would read. It has to be very, very quick. They need to implement age-appropriate safeguards under control. and gender-responsive terms of service. This kind of violence is affecting 95% women and girls. But of course, everything that this recommendation states is also applicable for men and boys, who should be part of the picture and part of the solution. And then we need to ensure content moderation, effective content moderation policies, and removal, quick removal of content. and the stopping the re-emergence of this content later in the web. We are now working also currently on another recommendation, again, a legal instrument, no legally binding, on deep fakes. And we expect to have it adopted by early 2028. And it's very interesting to see where the conversation goes, the concerns of the countries, and how reluctant countries to undertake these negotiations. Step by step, they are binding because also their politicians, their journalists, their judges.
Are facing this phenomenon disproportionately.
So it's very, very interesting. And this is here you have the links to explore this. I encourage you to go further, again, not to neglect the collective agreement of 46 countries of the world, plus the observer.
And here is my contact. Thank you, Octavia.
Thanks a lot, Eva. That was a fantastic way to set the scene of today. Highly appreciated your experience also from the Council of Europe, the different example of regulatory frameworks, important reminders about the fundamental principles, and also the importance of risk and impact assessment, which can be quite tough to do, but important to undergo. And thanks also for bringing up the example of tech-facilitated gender-based violence, which is a topic that hasn't actually come up yet in this workshop. So thanks a lot for bringing that up. Moving forward, next panelist joining us online is Kate Fox Principe. She's an Irish lawyer, human rights expert and PhD candidate who leads work on the administration of justice in the rule of law section of the UN Office of the High Commissioner for Human Rights in Geneva. Her work focuses on the human rights implication of digital technologies, artificial intelligence and neurotechnologies in justice system. Over 26 years at OHCHR, she has specialized in civil and political rights, including extensive work with the UN Human Rights Treaty Bodies. She served for many years as Secretary of the Human Rights Committee and has published widely on Treaty Body Individual Communications procedures. Miks Fox-Principe, the floor is yours. Thank you.
Good morning, everybody, and apologies for not being able to follow the discussion yesterday. If there are things that I say that were already mentioned yesterday, I apologise in advance. Distinguished chair and moderator, excellencies and distinguished delegates, let me begin my presentation with an image. Imagine that you are a defendant in a courtroom and that you have applied for bail through your lawyer. and the judge denies bail on the basis that an algorithmic system has assessed you as high risk. You ask why, why have you been assessed as high risk, and nobody can answer, neither the judge nor your lawyer. The answer is locked inside software owned by a private company, possibly protected as a trade secret. Now, versions of this scene are already happening. And this is why I'd like to answer the question today of technology and AI, why human rights? My remarks draw on two reports of the UN Secretary General on human rights and the administration of justice. So the first is from 2024, which deals with digital technologies and AI in justice systems. And the second is a report which will soon be presented to the General Assembly on the issue of neurotechnology in the administration of justice. I know that Ms. O'Brien already spoke to the subject of neurotechnology yesterday. Both of these reports reached the same conclusion, as affirmed by the Secretary-General and the High Commissioner for Human Rights, that the development and use of AI digital technologies, and neurotechnology must be firmly anchored in international human rights law. And I will explain why. Technology is not neutral. We often talk about AI as if it were a calculator, objective, precise, and fair, but it's not. Every algorithm is designed by people It learns from data that is collected by people. It carries their choices, their priorities and, so often, their blind spots. If the past was unfair, a machine that learns from the past will learn to be unfair. The only difference is that it will be unfair faster and on a much larger scale. Human rights law exists to protect equality and prevent discrimination. That is exactly why it belongs at the centre of this conversation. So why a human rights framework and not one based on efficiency or ethics? Some say that AI will make justice faster and cheaper, and sometimes it will. But speed is not the same as justice. And a system that handles 1,000 cases a day but gets the wrong answer for the poorest people is not efficient. It is injustice on a large scale. Others say that we should rely on ethics, and ethics do matter. They often show us where the law needs to go, but ethics mean different things for different people. There is no global agreement on what they require. No court will give you a remedy because a company broke its own ethical code. We have all seen ethics washing. find principles on a website and business as usual behind it. Human rights are different; they are law. States have agreed to them through treaties such as the International Covenant on Civil and Political Rights, the Convention on the Elimination of All Forms of Racial Discrimination and the Convention on the Rights of the Child, to name but a few. They are legally binding on states, and they give us clear rules and tested ways of balancing individual freedom against the needs of society and accountability when things go wrong. They have been tested for more than 50 years. We do not need to reinvent the wheel; we need to use the one that we already have. There are many rights at stake when it comes to the use of AI in justice systems, and I will refer to just four. Those rights are all laid out in the two reports that I mentioned. The first right is that of equality. Predictive policing tools learn from historical crime data, but that data often shows us where police chose to look, not simply where crime happened. Some communities have been watched far more closely than others, so a postcode, an income level or a neighborhood can quietly stand in for race or poverty. The result is a loop. More policing produces more data, more data produces a higher risk score, and a higher score brings more policing. That can result in old discrimination with new technology. The second right that is impacted by AI is that of liberty. Under article 9 of the International Covenant on Civil and Political Rights, detaining someone before trial must be an exception that is decided by a judge who looks at that individual person. Risk assessment tools do something different. They judge you by statistics about people who resemble you on paper. That is not individual justice; it is a guess based on a group. The third right is that of a fair trial. Many of the artificial intelligence tools that are used in justice settings are described as black boxes. You cannot see the reasoning behind the decision. If you cannot see how a decision was made, you cannot challenge it. That undermines the right to a fair trial and to equality of arms under article 14 of the International Covenant on Civil and Political Rights. Detention that cannot be challenged risks becoming arbitrary. The fourth right is judicial independence. Automation bias is the human tendency to uncritically trust automated technological recommendations. Overburdened judges, eager to process heavy caseloads, may defer to algorithmic outputs. If private software companies and executive agencies control the algorithms and training data sets, judicial independence could be at risk. Crucially, AI models lack uniquely human qualities: empathy, moral reasoning, intuition, and legal discretion. These are essential to administer nuanced, contextual justice rather than rigid, automated standardization. National courts are already acting on these issues. are already referring to human rights in their judgments. In the Dutch case Siri, in 2020, a court stopped a Government system that used algorithms to flag people for welfare fraud. The court found that it violated the right to privacy. In the UK, the Court of Appeal ruled that the police use of live facial recognition was unlawful. in the Bridges case. The rules on who could be watched and where they were were too vague, the data protection assessment was flawed and the police had not checked whether the technology was biased on grounds of race or sex. There are similar cases taking place all over the world as we speak. A recent one, which is highly mediatized, relates to litigation against Meta. Courts and juries are examining claims that algorithms were designed to keep children on social media platforms, pushing addictive and harmful content, directly violating child protection standards. The lesson from those and all other cases decided by national courts is clear: the rules that we already have on human rights work; we just have to apply them. I turn briefly to the issue of neurotechnology, which, as I say, I understand you heard about from Ms. O'Brien and Interpol yesterday. Neurotechnologies are devices and procedures that measure, analyse, decode and potentially change activity in the brain and nervous system. Combined with AI, they reach into the last truly private place that we have: our own minds. Freedom of thought under article 18 of the International Covenant on Civil and Political Rights is absolute. It cannot be limited, not even in a state of emergency. Yet, some neurotechnology tools claim to detect lies from brain scans or to decode thoughts from brain signals. They threaten our absolute right to keep our thoughts to ourselves. They also threaten the right not to incriminate yourself. In the landmark case of Selvi v the State of Karnataka, the Supreme Court of India ruled that forcing a person to undergo brain-based profiling violated this right and that the evidence could not be used. Neurotechnologies can threaten mental privacy, which is protected under article 17 of the International Covenant on Civil and Political Rights. Brain data is unlike any other data. It can reveal who we are and our personality. Consumer devices such as headbands and earbuds already collect that data. Without strong protection, that data could end up with the police or in a courtroom without our free consent. So who pays for the price for this human rights shortfall in the use of technologies and AI? As so often happens, it's those with the least power. Children are especially at risk. Their brains are still developing, and they risk being labeled and watched before they have the chance to grow up. Racial minorities, indigenous peoples, and persons with disabilities face discrimination amplified by data that does not represent them and by tools that were never designed with them in mind. So what must be done? Well, the Secretary General's recommendations are many, and I invite you to read both of those reports, but I will mention just three. The first, we must draw red lines. States should ban or place moratoria on high risk AI tools in judicial decisions such as bail and parole. They should prohibit coercive neurotechnology and thought-decoding tools. They should also require human rights impact assessments at every stage of technology's life. Second, companies must be held to account. Under the UN Guiding Principles on Business and Human Rights, technology companies must carry out mandatory human rights impact assessments from design to deployment and beyond. Thirdly, We should protect the right to a human judge. Technology can help with translation, e-filing and paperwork, but it must never replace human judgment, human accountability or due process. In conclusion, let me return to that courtroom that I began with at the beginning of my presentation. You asked why I have been assessed as high risk and not granted bail. Well, human rights guarantees that this question will always have an answer. It ensures that technology serves human dignity instead of eroding it. Without it, we risk reducing people to data points, replacing judges with algorithms nobody can explain, and giving up our most basic freedoms, including the freedom of our minds. Human rights ensures that justice remains fair, open, and above all, human. Thank you for your attention.
Thanks a lot for your presentation and for joining us online and for shedding lights on the importance and application of human rights. the reference also to the Secretary General recommendation. And I wrote down specifically something, the rights to keep our thoughts for ourself. I think it's a very important reminder also in relation of emerging technologies like neurotechnology. So thanks, thanks again. Moving forward, our next panelist is Major General Nisa Pillay. She's the head of Applications Portfolio Management in the South African Police Service. with 34 years of service spanning both frontline policing and technology services. Major General Pilet spent eight years serving at a police station before moving into the Technology Management Services Division. For the past 15 years, she has held senior management responsibilities, facilitating policing and business technology requirements, securing budgets and overseeing technology contracts, projects and expenditure. Her experience provides a practical perspective on the acquisition, implementation, and maintenance of technology within law enforcement. Major Pillay, the floor is yours. Thank you.
Good morning, Chairperson and distinguished delegates. It is an honor for me this morning to contribute a South African perspective to this important discussion on dual-use technologies and the regulatory frameworks required to ensure that technology in the criminal justice system upholds human rights. Julius technology serves a legitimate and beneficial purpose, but that can also be misused or applied in ways that cause harm, infringe rights, or threaten security. The defining feature of dual-use technology, therefore, is not the technology alone. It is the combination of the purpose, legal authority, the context, information used, potential impact, and safeguards. The challenge is to retain the public value of technology while preventing misuse, excessive use, and disproportionate harm. This, therefore, requires legality, necessity, proportionality, human oversight, security, or disability and access to remedy. Some of the existing and emerging dual use technology in the South African Police Service include artificial intelligence and analytics to support crime pattern analysis, operational planning and resource allocation, biometric databases containing DNA profiles, fingerprints and facial images to support accurate identification, drones and CCTV, digital forensic tools for recovery of crucial evidence from electronic devices, cybersecurity and social media monitoring tools, body-worn cameras and facial recognition being in the bed stages. In South Africa, the constitution is the starting point for evaluating any criminal justice technology. The relevant constitutional protections include dignity, equality, privacy, just administrative action, access to courts, and fair trials. Therefore, a clear legal mandate is required. Technology cannot be used merely because it is available or technically capable. The use must be connected to a defined and legitimate criminal justice purpose. The institution must determine whether the technology is necessary. This then requires an evidence-based need, rather than assuming technology will automatically improve an operation. The measure must be proportionate. Where several options are available, the least intrusive, effective option should be preferred. The system must be assessed for bias, unfairness, and unequal impact. A person affected by a technology-assisted decision should have access to an appropriate mechanism for review, correction or remedy. Technology as a human rights safeguard. The SAPS is subjected to civil claims attributed by unlawful detention. An integrated persons management system was developed and implemented to manage unlawful detention of arrestees. thus enabling human rights. Without an automated system, compliance depended heavily on manual registers, paper-based cell visit records and medical records, separate identification systems and retrospective management checks. The IPM system supports the protection of human rights by embedding accountability, monitoring identification, time-based alerts and auditable records into the management of persons in police detention. The technology facilitates compliance. However, people and institutional processes remain responsible for respecting the rights. South Africa does not rely on one single law to regulate technology in the criminal justice system. The Constitution enables the overarching human rights and rule of law framework. The Protection of Personal Information Act, or POPIA, regulates the responsible processing and protection of personal information. The Regulation of Interception of Communications and Provision of Communication-Related Information Act, the RICCA, establishes requirements for lawful interception and access to communication-related information. The Cybercrimes Act addresses cybercrime offences, investigations, reporting, and international cooperation. The Criminal Procedure Act and Law of Evidence remain relevant to lawful search and seizure, chain of custody, evidential integrity, reliability, and admissibility. The Promotion of Access to Information Act, or PAIA, and the Promotion of Administrative Justice Act, PAJA, support transparency, lawful administration, reason, and review. The South African Police Service Act and internal SAPS policies establish institutional mandate, accountability, information security and governance requirements. Specialised legislation and regulatory frameworks apply to areas such as forensic DNA, aviation, electronic communication and records management. Information security is a human rights safeguard. South Africa is progressing towards integrated digital criminal justice, enabling information sharing across criminal justice stakeholders and real-time biometric verification at police stations. Such information sharing presents great responsibility towards access to information. Information security is therefore directly connected to human rights, evidential integrity, and public trust. Data protection, identity and access management, evidence management, and monitoring are essential control areas. Data governance and information security steering committee meetings have also been established to provide oversight on such matters. Finally, suppliers are subjected to clear security and privacy obligations, audit rights, data handling requirements, and secure deletion or exit arrangements. Responsible technology governance should cover the entire technology lifecycle, from defining the operational need, legal mandate, and intended purpose, to assessing the potential effect on human rights, privacy, security, evidence, and operations. Privacy and security matters are addressed from the onset of procurement processes, where bid specifications clearly define requirements relating to information security. Then authorized use, identifying an accountable owner, testing, which will depend on the type of technology, controlled operation, access restrictions, human oversight, training and monitoring must remain in place throughout the use. Periodic review, which entails assessing effectiveness, continuing necessity, changes in circumstances and whether the technology should be modified, suspended or retired, is practised. Governance should therefore not be seen as a once-off approval; it is a continuing institutional responsibility. The SAPS has developed a draft AI acceptable use policy to enable legal, ethical, and secure development, acquisition, deployment, use, monitoring, and retirement of AI systems. This policy applies to the SAPS personnel, authorized third parties, and SAPS-managed digital environments. It is built around six guardrails, namely accountability, where human sight is mandatory and officials remain accountable for AI supported decisions. Transparency, users should understand the technology's capabilities and limitations. Fairness, reliability and safety, the systems must operate within defined parameters with acceptable error rates, realistic testing and ongoing monitoring. Privacy and security, where AI must comply with the Protection of Information Act, the government security requirements, and the SAPS information security controls. And lastly, inclusiveness. The policy translates broad legal and ethical principles into practical organisational requirements. South Africa supports technological innovation that improves public safety, strengthens investigations, enhances transparency, and expands access to justice. However, innovation must remain lawful, human-centered, fair, secure, and accountable. Thank you.
Thanks, Major General Pillay, for sharing the experience from South African Police Service. I think the importance, you share the importance of the information security with law enforcement, and you walk us through the technology life cycle and highlight the key role of governance, all topics that haven't, again, come up in this workshop. So thanks a lot also for urging that AI governance cannot wait anymore. Moving forward to our next panelist, we have Ms. Wendy O'Brien. She's cybercrime expert with United Nations Office on Drugs and Crime based in Vienna. Ms. O'Brien leads UNODC work on the ratification of the United Nations Convention against Cybercrime, and she carries an additional portfolio as she lead on emerging technologies, including artificial intelligence. Prior to joining UNODC, Ms. O'Brien held academic roles in Australia. During her tenure as senior specialist with the Australian Crime Commission, she pioneered policy innovation to enhance public safety and statutory services for victims of gender-based violence and child sexual assault. As adjunct associate professor with Deakin University, Ms. O'Brien has published widely on technology and human rights-led law reform. Her latest book, Children, Rights, and Criminal Justice in the Digital Age, was published by Palgrave Macmillan in 2024. Ms. O'Brien holds a PhD in cultural studies, a master in international law, and master's in program evaluation. Ms. O'Brien, the floor is yours. Thank you.
Thank you very much. A pleasure to be with you to discuss this topic. Our shared objective, set for us in agreed language of the Kyoto Declaration and affirmed in the Abu Dhabi Declaration, is to responsibly harness the benefits of technology for the criminal justice system while mitigating risks. Many speakers at this 15th Crime Congress have noted the importance of this goal and the careful and hard work that it will demand of us all. and there is considerable work ahead of us if we are to effectively facilitate the interdisciplinary conversations and collaborations that are needed to develop and deploy technologies that are safe, effective, and accessible to all, and ensuring that these make a genuine contribution to strengthening criminal justice processes. In pursuit of this goal, my remarks today identify some aspects of the prevailing discourse globally about technology development, governance, and regulation that I see as potentially hindering our shared work. At present, discussions of technology are often limited by conceptual frameworks that are reductive and oppositional. My approach in making these remarks is solutions-focused. I problematise these simplistic polarities with a view to forging common ground for partnerships and the development of agreed approaches to the safe and innovative use of technologies that will make a genuine contribution to our work in criminal justice. So, if I may, begin with this one. The prevailing idea with good hands, bad hands is that innovative, powerful technologies are neutral or good, providing they are in good hands. The corollary is that those same technologies are dangerous if in the hands of bad actors. This oversimplification imparts several problems. It actually imparts very many related to our work in criminal justice, but I can't cover them all. Technology is not neutral, and we have heard this articulated already by Ms. Fox-Principe. It's not neutral artificial intelligence because of the data on which it was trained. I won't labour the point about neutrality. I think it's covered well already. But the fiction... in this neutrality is also that all tech is equal. And I think it is this that leads sometimes to the claim that is made when we ask questions about technology governance. People will liken that to the time when there was fearmongering around the introduction of the printing press, for example. Artificial intelligence is not as neutral as the printing press. So I think when we reduce the discourse to this level, I think it's problematic. But the second challenge that I see associated with this polarising approach is that at the global level, we see this logic also driving the AI arms race, which in turn accelerates the already rapid pace of technology development and the early release of frontier technologies before they are tested, before they're proven to be safe. These race dynamics, which are moored to a good hands, bad hands logic, complicate efforts to discuss and agree on necessary safeguards, human rights considerations, safety considerations. And they also complicate our efforts for multi-sectoral partnerships on safety by design, evaluation, and refinement. An additional limitation of this oversimplified logic of good hands and bad hands is that it diverts attention, and I think this is important for us in our discussions on criminal justice. It diverts attention from the ways in which technology developed and used in the right hands can, without regulation, without evaluation, and without appropriate guardrails, can contribute to safety issues or human rights concerns. For example, the overuse of surveillance technologies by law enforcement and the privacy breaches associated with this. Or failures inherent to the technologies themselves, but yet still used in good hands. So for example, hallucinations from generative AI tools that result in the presentation of fictitious statute or case law in judicial proceedings. These are technologies in good hands, yet the outcomes are adverse. Another is innovation and regulation. Discussions and debates about tech regulation are often characterised by a degree of acrimony. The sense, for example, that regulation would stifle innovation is framed as a reason to forestall discussions about safety, guardrails or human rights. equally the oversimplified sense that all tech regulation is antithetical to or deliberately seeking to circumvent guardrails and considerations around accuracy, safety and effectiveness. So I think there's a mischaracterisation of these two sides and my argument is that they not sides, but that really this is the shared landscape that we navigate together. Because this is not a zero-sum game, and we are harming our chances of good faith multi-sectoral partnerships if we frame this as a competition, with the idea that it's either innovation or regulation, and that we can't have both. Innovation and regulation are not opposites. Laws, standards, procurement rules, liability and oversight shape what kind of innovation happens, for whom and with what safeguards. Regulation can enable, it can be a facilitator of trustworthy innovation by creating predictability, interoperability and, crucially, public confidence. Innovation without guardrails can erode privacy, equality, democracy and trust. And this is harmful to both those who seek to implement regulation, public authorities, let's say, and those who seek to advance innovation. As a vital quantity for both public and private sectors, trust is currently in short supply. Polarised debates about innovation and regulation and the ready attribution of blame will not bring us closer to the table. The table in which we agree as humanity on the role that we wish for technology to play in our lives. At this table, we need all actors, a globally diverse group of tech innovators, tech regulators, and crucially, tech end users. With a good faith approach and a shared willingness to listen and learn, we may be able to overcome positions of oppositionality to forge agreements that genuinely build trust. Trust in technology, trust in innovation, whether this is public or private sector innovation, and trust that the regulatory mechanisms that we put in place are in our shared interest. And this is where I would propose that we rethink our relationship with the word innovation. For many, the word innovation means technology. Anything that's not technology is not innovative. But policy can also be a site of innovation. If we discard the competition and embrace the shared purpose of innovation, we recognise that this involves innovations that involve silicon, but also innovations in policy and governance. And there is a further point there around voluntary and enforcement that I would also problematise, but in the interest of time, I think I'll skip that and speak about public and private. Because I have taken care to avoid framing that preceding binary of innovation and regulation in terms of public and private, because I do think that some of these binaries interlink and create kind of deepening layers of complex misunderstanding. I propose that our thinking is limited and our chances of forging solutions are diminished if we assume that innovation only takes place in the private sector and regulation is squarely a public sector concern. We would be amiss to assume that technological infrastructure and expertise is and always will be or should be concentrated in the private sector. And if we think about conversations about whether tech adoption should be based on approaches of buy, build or both, and with this increasing attention to digital sovereignty, including ownership and control over technology infrastructure, It is vital that increased attention be paid to strengthening tech capacity and infrastructure in the public sector. This is particularly important in the field of crime prevention and criminal justice, to avoid a situation in which public sector entities that are charged with delivering essential criminal justice functions are unduly reliant on private sector technologies and technology infrastructure, a domain in which they have little access and little control. If we move there's the voluntary and enforced, it's for another day to the national and international as my closing point. The velocity with which our technological advancements have unfolded have altered all fields of human endeavour, and the geopolitical considerations around the ownership of technology infrastructure provide a backdrop for tensions related to national interests and international cooperation. This Congress, which is itself an exemplar of international cooperation, there has been a continuous theme of international cooperation and strengthening that, just as there was at the previous Congress five years ago. This is based, of course, these calls for strengthened international cooperation are based, of course, on the principle of equal international sovereignty. This is the foundation of international law. There is no conflict between national interests and international cooperation. International cooperation is predicated on national sovereignty. States, in their national interests and in their sovereign capacity, cooperate at a global level. In the digital era, this is essential. Almost all crime leaves a digital trace. terabytes of data, dispersedly located across borders and across sectors. Cooperation at the international level is now an essential feature of efforts to prevent and combat crime. It's vital, for example, that law enforcement and prosecutors can request access to electronic evidence for the investigation and prosecution of crime. An investigation led by one jurisdiction may benefit from an international joint investigation team. and access to data held in third countries and in private sector companies. Noting the fragility of electronic evidence, which can be deleted in an instant, rapid access to these data is essential for the effective prosecution of crime and for the delivery of a just outcome. Where this access is facilitated by international cooperation, the outcome is in the national interests of all countries involved, and it's in the international interest as law enforcement cooperate to combat cross-border crime and close safe havens of impunity. These interests are complementary, and we privileged to have an instrument that brings these interests together. The first comprehensive global convention on cybercrime provides a harmonized legal framework for the prevention and combating of cybercrime. But not only cybercrime, not only those offenses that are contained in the convention, all serious crime and all crime that leaves a digital trace This is our mechanism for strengthening international cooperation to ensure that the malicious use of technologies is not a tsunami of challenges for law enforcement officials, prosecutors, and judges. I would encourage member states to reach out to UNODC if you would like further information on the convention. or guidance on the process for signature and ratification. Thank you very much.
Many thanks, Wendy, for your presentation touching upon the importance of regulation as enabler of trustworthy innovation, as well as introducing the important relationship of public-private partnership. That is something we're going to cover more in depth later today. And finally, introducing the United Nations Convention against Cybercrime. Last panelist for this segment is Mr. Owen Ripley. He is Senior Assistant Deputy Minister and leads the policy sector at the Department of Justice Canada. The sector works to support the Minister of Justice and Attorney General of Canada in relation to criminal law, victims, federal family law, youth criminal justice, Indigenous justice, international development, and access to justice. Prior to joining the Department of Justice, Mr. Ripley worked for over 12 years at the Department of Canadian Heritage, where he spearheaded policy work related to the impact of digital technologies on arts, culture and media. Significant achievements included the passage of the Online Streaming Act and the Online News Act, as well as developing a legislative framework related to online safety, which is the proposed Online Harms Act. Mr. Ripley has common law and civil law degrees, as well as a Bachelor of Arts in History and Political Science from McGill University. Mr. Ripley, the floor is yours. Thank you.
Thanks so much, and colleagues, it's a pleasure to participate in this workshop today. My intervention will focus on two core themes. The first is the importance of ensuring that criminal justice responses keep pace with technological developments, and the second is the central role of safeguards in international and domestic legal frameworks so that technology and criminal justice systems uphold human rights and fundamental freedoms. It's a bit stating the obvious in this context, but around the world, we are witnessing rapid advances in digital technologies, data analytics, and artificial intelligence. These tools can strengthen investigations and support the detection and prevention of crime, improve access to justice, and facilitate more efficient court processes. and enhance the overall effectiveness of criminal justice institutions. Yet at the same time, these same technologies can be used in ways that threaten privacy, equality, due process, and other fundamental human rights. For example, data analytics and AI systems can help identify patterns of offending, allocate resources more efficiently, and support risk assessments. Yet, if poorly designed or deployed without safeguards, these systems can reproduce existing biases, disproportionately affect marginalized groups, and make opaque decisions that are difficult to review or challenge. Similarly, technologies for digital evidence collection can help solve serious crimes, but they can also enable mass surveillance or the collection of personal information far beyond what is necessary or proportionate. Our central challenge is therefore not whether to use technology, but how. How to ensure that criminal law and its safeguards keep pace with innovation, and how to design domestic and international frameworks so that technology serves justice and human rights, and not the other way around. Many of our core legal concepts, such as property, communication, search, and publication, were developed in a physical, analog world. Yet the harms we now confront are increasingly digital, borderless, and instantaneous. If criminal law lags too far behind, excuse me, we face a double risk. The first is that serious misconduct may go unaddressed, and the second is that overly broad or outdated offences may capture behaviour that should not be criminalized. Updating our laws is therefore not a technical exercise. It is essential to preserving effectiveness and legitimacy, ensuring accountability, and ultimately maintaining public confidence in the administration of justice. In developing criminal justice responses to technology-facilitated or technology-enabled crime, governments must balance law enforcement and public security needs with respect for human rights and fundamental freedoms, including freedom of expression, freedom of the press, and the protection of privacy. I'll turn a little bit to Canada's approach to these matters. In Canada, criminal law offences are generally drafted in a technology-neutral manner, such that they can apply to specified conduct whether or not it is carried out by technological means. For example, a person can be prosecuted under the general extortion offence whether they have extorted another person in person or online, including in ransomware cases. However, Canada's Criminal Code also includes specific offences for conduct that can only be committed through the use of technology, such as unauthorized use of a computer and child luring. These tailored offences provide greater clarity and explicitly denounce the misuse of technology for criminal purposes. Canada is also actively taking steps to address emerging harms. For example, in July 2026, so a couple months ago, Canada criminalized the non-consensual distribution of sexual deepfakes. This new offence responds to the growing misuse of artificial intelligence technologies and provides an important tool to protect victims, particularly women and girls, from serious online harm. Because technology is often global in origin and reach, cybercrime frequently transcends borders. Effective international cooperation is therefore indispensable. Canada is a party to the Council of Europe Convention on Cybercrime and has signed its second additional.
Protocol, as well as the UN Cybercrime Convention.
These instruments share a common objective of strengthening cooperation among states and improving the prevention, investigation, and prosecution of cybercrime and other offences involving electronic evidence. Importantly, these frameworks recognize that investigative powers must be accompanied by safeguards. Under all these instruments, procedural powers are subject to conditions and safeguards established under domestic law, and such safeguards must ensure adequate protection of human rights and fundamental freedoms. The UN Cybercrime Convention contains an additional safeguard by providing that its implementation must be consistent with international human rights law and cannot be used to justify restrictions on fundamental freedoms. Canada also recognizes the broader opportunities and risks associated with emerging technologies, including AI. In this regard, Canada signed the 2025 Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy, and the Rule of Law. This treaty aims to ensure that the activities within the life cycle of an AI system, including when used by public authorities, are fully consistent with human rights, democracy, and the rule of law. Strong safeguards, transparency, and accountability are equally important within domestic legal frameworks. In Canada, the use of investigative technologies by law enforcement is subject to numerous legal safeguards, and so I will talk about a few of these. In the procedural law and safeguards, investigative tools such as digital forensics, location data, automated analysis of large data sets, and facial or pattern recognition can dramatically increase the capacity of law enforcement. However, their use does raise important questions about privacy and surveillance and the risk of error or bias, including disproportionate impacts on certain marginalized communities. Safeguards, including judicial authorization, clear thresholds for use, Transparency about capabilities and meaningful avenues to challenge evidence are critical to maintaining the right to a fair trial and the presumption of innocence in a digital environment. Canada's Criminal Code contains a number of different authorities governing the use of investigative techniques, including preservation orders, production orders, search warrants, and authorizations for the interception of private communications. where the legal thresholds and safeguards associated with these techniques differ, they have been carefully tailored to balance the intrusiveness of the investigative technique and the expectation of privacy engaged by the information sought. Importantly, in Canada, for every government bill introduced in Parliament, the Minister of Justice is required to table an accompanying charter statement that identifies potential effects the bill may have on rights and freedoms guaranteed under the Canadian Charter of Rights and Freedoms. These charter assessments help inform parliamentary and public debate on the bill and promote transparency about the rights and freedoms engaged by the proposed legislation. speak now to a few concrete examples, the first being body-worn cameras. Canada's Steering Committee on Justice Efficiencies, comprising of federal, provincial and territorial government officials, the judiciary, legal bar organizations and law enforcement, is examining the operational impacts of body-worn cameras by Canadian police. The committee is gathering information from jurisdictions that use body-worn cameras consulting a wide range of stakeholders and identifying lessons learned and best practices on how best to use and manage the technology, including the vast amounts of video evidence generated from body-worn cameras. Work will continue to inform policy regarding the use of this technology and its implications for public confidence and access to justice. Second, facial recognition and new technologies. The Office of the Privacy Commissioner of Canada has investigated the Royal Canadian Mounted Police's use of Clearview's AI facial recognition technology and concluded that the RCMP's collection of personal information from Clearview AI was illegal. In response, the RCMP established the National Technology Onboarding Program to ensure that any new technology meets privacy, legal, policy, and ethical standards. This program's assessments are guided by principles such as legality, constitutionality, effectiveness, necessity, and proportionality, and extend to technologies including algorithmic policing tools, biometrics, and other digital systems. Turning to on-device investigative tools, ODITs, and parliamentary review. Police use of on-device investigative tools, software used to covertly access data directly from digital devices, has been reviewed by Canada's Parliamentary Standing Committee on Access to Information, Privacy and Ethics. The committee has recommended measures such as reviewing the Criminal Code framework for authorizing the interception of private communications, considering controls on spyware and surveillance technologies, and conducting privacy assessments before using high-risk tools. To conclude, keeping criminal law aligned with technological change is not simply a matter of catching up with innovation. It is about deliberately shaping how technology is used in the criminal justice system so that it advances the rule of law, fairness, and human dignity. Canada believes that we must approach new technologies with both openness and caution, open to their potential to improve justice and cautious to ensure that this potential is realized within strong legal and human rights frameworks. Canada looks forward to continuing this conversation with our partners and to working together on international standards and cooperation that will help ensure that technology in the criminal justice system upholds rather than undermines the rights of all individuals. Thank you so much.
Thank you, Mr. Ripley, for your presentation and for sharing insights into the importance of ensuring that criminal law keeps pace with innovation, different measures and safeguards, and also for sharing Canada's approach and ongoing efforts to criminalize online harms. Thanks again. So let me thank again all the panelists for your insightful presentation. And I will now pass the floor back to the chair. Thank you.
Thank you very much, Ms. Gallucci. I thank also all the panelists for their presentations. We still have some time for hopefully a good interaction with the audience. So I open the floor for any comments or questions, please. see the gentleman there. You have your nameplate or not.
Thanks. Certainly. I just represent the Russian Federation. I didn't take a plate from the...
You have the floor. Just identify yourself. And later, after you, I see South Africa. So please go ahead.
Can I speak, right? Very good. My name is Ernest Chernukhin. I am the Deputy Director of the Department of International Information Security of the Ministry of Foreign Affairs. At the same time, I am the elected Vice Chair of the Ad Hoc Committee on the Elaboration of the Cybercrime Convention. some comments and some statements. First of all, I would like to thank--.
Sorry to interrupt, but you mentioned the Ministry of Foreign Affairs of which country, please?
Russian Federation. Thank you. Probably my language is not OK. No, I-- I am not a native speaker, certainly. Sorry.
No, probably it was when I was putting on my-- Good, good.
Excellent, excellent. So first of all, I would like to thank you very much, UNODC, for-- Ms. O'Brien, for wonderful presentation. excellent one, because as an almost employee, as the some vice chief, I am very well interested in incorporate this whole mechanism in practice. Hope that with the support of the UNODC, the Secretary of that committee, we will achieve wonderful results. So my question first to you should be, what is your forecast for the ratification and signature? The next item, well, many thanks for all the panelists for wonderful presentations, excellent. So remarks regarding the latest Canadian one. Probably I don't want to see any minor remarks, but from the theory point of view, your statement is excellent. Well, that should be much, much better if you did tell it just 10 years ago. You're absolutely right saying that we have to see the balance between the human rights on one hand, data protection, personal data protection, and some regulatory issues. Probably I will regret you, my friend, that You mentioned the Budapest Convention, and precisely why the Article 32 of the Budapest Convention, the violation of the human rights is totally unacceptable. And one practical example of that, we know we've got everyone iPhone. Is it a very good equipment? We know perfectly, very comfortable for life. Certainly, we think that our business society should produce much more such equipment on one hand. On the other hand, the question is, what is the security of the using of this technology? Now, if you don't know, probably it's not a secret. Well, the latest iPhone 17, I've got very old model, but the latest one does have five vulnerabilities. 5. Why that and why the Article 32B of the Budapest Convention? I will regret to you, the citizens of Canada, of United States, of Russia, and many countries cannot be survived because the violation of the human rights. We don't know how this unauthorized, well, just access to our life, where the technology is widely used by someone, by criminals or not. So that is the story that we would like to discuss. What is the balance between who would control the producers of these wonderful technologies like iPhones, and how we can protect our citizens from some vulnerabilities in this equipment in order to prevent or just find some safeguards, as you fairly tell. So this issue that I would like to raise And if you try to give your reply, that would be wonderful. But it is very, very interesting dispute that together with the chair, we did see today. Many thanks.
Ms. Abrahim, would you like to answer the question now?
Thank you very much. I extend my thanks to the distinguished delegate from the Russian Federation for the remarks regarding the presentation, firstly. and also for the question. I do wish that I could tell you what the forecast is. All I can say is that we are working as hard as we can to ensure that all member states are aware of the practical benefits of the convention, and we do really spend a lot of time explaining how this is going to work very well as a tool for prosecutors, investigators to respond more effectively and more rapidly to crime. And I think that we are at a situation now where we have 95 signatories to the convention, which is excellent. There were 13 new signatories during the treaty event last week in New York. and a couple of days prior to that as well. So that was really, I think the momentum is really building around the convention and I can also share that we are receiving many requests from member states for information about the convention. We are aware that very many member states are moving towards ratification. So while we have three states parties now, I would say that by mid next year, we will have very many more than that. And I look forward to collaborating with all in this room on that. Thank you.
Mr. Ripley would like to add.
Yeah, so thanks very much for the comments from the floor. And I I agree that at the end of the day, the challenge is how you actually give practical effect to the balancing of these considerations. And that is actively-- I'll give you an example-- that is actively playing out right now in Canada as Canada seeks to move forward lawful access legislation. So we have a bill before the Canadian Parliament that is seeking to update certain police powers for the current environment to facilitate the collection of digital evidence, particularly certain basic personal information, subscriber information that can be right now quite difficult to obtain because you're required to kind of seek it via a general production order. And so the bill would seek to help facilitate police investigations, particularly at the front end of a criminal investigation so they can get that information more easily, while ensuring that there are obviously safeguards in place to govern the use of those tools. And then Canada is proposing a framework to mandate service providers having the ability to effect certain information requests or production orders from police. That is a very lively debate in the Canadian context about how to strike the appropriate balance between privacy rights, especially when it comes to technologies like encryption, and the needs of law enforcement. That bill is not through. It is still in our Senate right now. We saw amendments when the bill was considered by the House of Commons in Parliament, for example. to clearly specify that, you know, that lawful access legislation would not require a service provider to mandate the breaking of encryption if the service provider itself does not have the ability to break that encryption, right? And obviously there are different perspectives on that issue, but Canada does recognize that technologies, yes, can be co-opted by criminal organizations, but they are also critical to freedom of expression and freedom of assembly. And so that is, I think, a very practical example that is playing out right now in the Canadian context of the balancing of those important rights that are engaged by lawful access legislation with the needs of law enforcement.
Thank you very much. I now give the floor to the delegation of South Africa, please.
Thank you so much, Mr. Chair. We join you and the previous speaker in expressing our gratitude to all the panelists for the valuable presentations made. The question that we do have is for Ms. Pastrana from the Council of Europe. First, of course, we thank you for enlightening us with the frameworks that have been developed by the Council of Europe. In particular, we were really interested in the framework convention on AI, human rights and democracy. The question we really have here is with regards to, again, it's the question of balance. How did you ensure that this framework convention does not duplicate already existing international human rights instruments? This is something that we've battled with when we were trying to draft the Convention against Cybercrime. So it'll be interesting to know how the Council of Europe did that. And the second question that we do have is with regards to the responsibility across the AI system cycles. As we all know, the AI systems involve developers, distributors, and of course, users across multiple jurisdictions. So basically, how does the framework convention determine who should ultimately be accountable when AI systems cause human rights harms? If I can put the question a bit more frankly, does the convention consider the private sector accountability at all? And if it does, how will this be enforced? Thank you.
Ms. Pastorella, please.
Thank you. Thank you very much for the questions and the appreciation. So first of all, this is a framework convention. We in the Council of Europe, we have a more classic convention. Let's say the Budapest Convention on Cybercrime is much more detailed, prescriptive. When it comes to framework conventions, we're talking about more general frameworks, so more into principles less prescriptive and not necessarily less difficult to negotiate with, but it's more, it doesn't have these, again, these very detailed provisions as the cybercrime, the anti-trafficking, the mutual legal assistance, convention, extradition, these kind of prescriptive conventions. So the framework convention on AI, human rights, democracy and rule of law, we're talking about a difficult concept, artificial intelligence. Remove the artificial. Even intelligence is not an easy concept to define. What is intelligence? So when we had artificial intelligence, it's much worse. But what we managed was to agree on basic principles so that The human also remains in the loop. He's like in the driving seat. We are the drivers. We do not know that would maybe self automatic driving cars in the future, but still we will need to say where we want to go. So it's like calculators didn't exist 1000 years ago, but now we can use them. So is it is the minimum. is the common denominator, is the basis. With the Council of Europe, we agree on minimum denominator, and nothing prevents countries later for going further and going beyond these minimum standards. Second, how we can ensure it's compatible with other international agreements? Well, in this case, it's very easy because it's the only one. And because it's the only one, I think it has this value of having so many members negotiating it, and not only from the Council of Europe side, but from outside, as I referred to. Then, you referred to how we ensure implementation. So, first of all, this convention has 21 signatories, including the first ratification by the European Union from May this year. And then when it enters into force, and it requires a very reduced number of ratification, like five, out of which three Council of Europe member states, meaning the urgency of this convention. Then a conference of the parties will have to be established. And this Conference of the Parties will be in charge of the monitoring of its implementation. But it is also a trusted community of people that decide, that exchange on best practices and bad practices. It is very valuable to participate in this Conference of the Parties. And then the it will be as good as the members integrating the conference of the party. So not an easy task. And that's why we are in the meantime working on this Hutteria risk assessment of the usage and implementation of AI. And I invite you to go into the website of the Council of Europe to look at this. both the convention and the advances and progresses of Hudderia. We have also work associated in the Council of Europe. There is a the Ato Committee, intergovernmental committee, now called CD Net. That is also exploring and discussing and exchanging things. And the the it will be as again as good as the members and commitment of the countries be beyond this, I mean, forming this conference of the parties. Thank you.
Thank you very much. We have two requests for the floor, and I will close after those two interventions. First, the United States, and then China, and with that, we will wrap up the first panel.
Thank you, Chair, and thank you to the panelists for the very interesting presentations this morning. The United States supports technological innovation and does not believe that technology itself is the problem, but that the problem that we should be focusing on is criminals exploiting technology and states not having the operational readiness to take down these criminal networks. As a general matter, the United States believes widespread government regulation of digital tools is not the answer to criminal exploitation, because there will always be a new tool, a new way to steal and harm. The best criminal justice response is deterrence in the form of effective law enforcement interventions and strategies and real and punitive outcomes. This is distinct from industry driven safety standards, which the private sector is best positioned to design and implement without a new layer of super national bureaucracy. Victims, whether they be victims of child sexual abuse and exploitation, ransomware attacks, online fraud, or forced criminality and online scams, need trained investigators, access to digital evidence, and swift and successful prosecutions. We believe we must stay focused on our core enforcement objective to bring criminals to justice using technology where helpful to catch, prosecute, and convict offenders. We appreciate the points made today from the panelists that we need to strengthen international cooperation and that states must strengthen their technological capacity for criminal investigations and prosecutions. and that criminal justice responses need to keep pace with technological developments. One of the new criminal threats that we've seen is the creation and dissemination of deepfakes, which I believe the Council of Europe speaker also mentioned, and perhaps other panelists as well. In the United States, we have the recently enacted Take It Down Act, which prohibits the publication of both authentic and forged or deepfake images of minors for a malicious purpose, as well as the non-consensual distribution of authentic and forged intimate images of adults, which we sometimes call revenge ****. And this law also requires providers to create a mechanism for a depicted individual to seek the removal of those images published on their platform, with providers required to remove those images as soon as possible, but in any event, no later than 48 hours. I would be curious to hear more about the discussions that you've had at the Council of Europe or on thoughts or concrete legal and technical tools that are being considered to address this problem. Thank you.
Thank you, the US, for the intervention, the statement. And I also kind of interpret there's a question to seek the opinion or further information from Ms. Pastrana.
Yes, first of all, again, it was not easy to get the agreement of the 46 member states to go into developing a legally binding instrument. We were looking at the intersection between criminal law and AI, and in the beginning, there was an idea years ago about focusing it exclusively on the topic of self-driving cars. And then as time evolved, we disregarded that topic and we focus on deepfakes that actually it will be called in future more digital forgeries. But for the time being, because we need to understand what we are talking about, we decided to name it deepfakes still. Then we agreed on the scope of it and we had a long list and this long list was reduced to now currently three, four topics. The first topic is sexual abuse content. We are speaking about intimate because sexual can have very different connotations depending on the country you come from. So we say intimate images. Then second, digital child sexual abuse material that may be also renamed. So we try not to use the term pedophile *********** because we try to put the focus on the victim, on the child, not on the final user of this. And then third, another aspect where we agreed was scams and frauds. And there was a longer list, but we couldn't.
Agree so far.
So we approach the development of this new legal instrument, but not legally binding.
Maybe as a foundation to be more ambitious if member states agree to it in the future to go further.
But so far, this is the times and the framework that Member States have given me. So my task as Secretary to this Committee is to make sure that there will be a draft recommendation by the end of 2027 that the Committee of Ministers agree.
Thank you. And now I give the floor to Mr. Ripley, please.
Thanks very much for the comments from our colleague from the United States. Perhaps just to share a little bit of the Canadian perspective on the issue. So there was a gap in Canadian law relating to the distribution of sexual deepfakes. And so in July, that gap has now been closed. And it is a criminal offense to distribute an intimate image without consent, whether that image is a real one or whether it has generated by AI or some other form of technology. And we also criminalize the threat to distribute those images as well. And so it also is an offense to threaten the distribution of a sexual deepfake. I think, you know, and you alluded to it in your comments, right? I think one of the challenges that we continue to see in the Canadian example is you can have a successful prosecution of distributing an intimate image, but from the victim perspective, unless you have a meaningful mechanism to have that image taken down, you know, it often leads to continued re-victimization and trauma for that. And so, you know, what we have heard very, very clearly from victims in this space, and this also would extend to, you know, images of child sexual abuse or exploitation material, is, you know, very practically, they want the content down. And so, you know, I think there is a very legitimate debate to be had about whether the criminal law is kind of, you know, an effective mechanism in that space. And I Thank you for sharing the way that the Take It Down Act is seeking to address that. But I think from the Canadian perspective, we are advancing a regulatory fix in that space as well to close that gap. So we have the Safe Social Media Act, which is currently before Canadian Parliament. And that also reflects the needs of victims who sometimes don't necessarily want to pursue a criminal law remedy in the space. They just want the content down, right? And so I think that is, you know, just to share that, I think you do have to think about it from both sides because it is unclear whether criminal law is going to be a fully kind of effective remedy for victims of these crimes.
Thank you very much for that reply. And I now give the final comment opportunity to the delegation of China, please.
Thank you, Mr. Chair. Dear colleagues, so I would like to take advantage of this chance to introduce some experience and the best practice of China and make some recommendations. So in recent years, technological advancements have brought unprecedented opportunities for the development of criminal justice. For instance, emerging technologies such as AI, big data and biotechnology have significantly enhanced the efficiency of case investigation and resolution. Meanwhile, the adoption of digital case files, intelligent case handling assistance systems and the remote judicial hearing technologies has enhanced judicial efficiency and reduced litigation costs. However, the application of technologies also poses severe challenges. First, new criminal methods are evolving at an accelerating pace, making it difficult to collect evidence, track suspects, or make qualitative analysis, which has become a kind of a new normal. Secondly, there are concerns regarding technological reliability and accuracy. Third, some technological applications still lack clear standards, norms, and guidelines. Fourth, cross-border crime has become increasingly professionalized and intellectualized, posing new challenges to international judicial cooperation. So China's criminal justice agencies, such as police, justice, court, et cetera, consistently upholding the principle of responsible use of technology, have accumulated valuable practical experience and achieved some remarkable results. For example, during the special campaign to crack long unsolved homicide cases, Modern criminal forensic technology and information-based tools were employed in strict accordance with evidentiary rules and statutory procedures, substantially enhancing both the quality and efficiency of investigations. Another example is in the operation of Reunion, we call it in Chinese. which means to bring back the trafficked kids. So relevant technologies were applied comprehensively for precise searching, scientific matching, and rigorous verification by combining technical comparison with human review. Therefore, misidentifications were minimized to the greatest extent possible, significantly improving the success the success rate of family reunification. And another example is in the fight against telecom and online fraud. All our efforts have been made to strengthen early warning mechanisms and technical countermeasures. This includes promoting the use of anti-fraud tools, such as we have a national anti-fraud center application. and 96110 early warning hotline and the 12381 fraud early warning SMS system, thereby preventing crimes to the greatest extent possible and minimizing property losses among the general public. So to promote the responsible use of technology in crime prevention and criminal justice, China would like to promote the following recommendations. First, enhancing capacity building to address new types of criminality. A regular technical training mechanism should be established to regularly upgrade the skill sets of criminal justice personnel in emerging technologies and investigative techniques. Furthermore, specialized technical investigation teams should be developed. fostering interdisciplinary professional proficiency in cyber technology, data analysis and AI and related fields. Secondly, improving technical reliability and algorithmic transparency. We should promote the application of explainable artificial intelligence technologies so that algorithms algorithms can provide decision making support and explanations of the reasoning process. At the same time, a human review mechanism should be established for algorithm outputs and regular performance assessments and bias audits should be conducted so that potential problems can be identified and rectified in a timely manner. Third, accelerating The establishment of a standard system for technology application. A systematic review should be conducted of standardization needs in the application of technology to criminal justice, with priority given to formulating technical standards in urgently needed and critical areas. Meanwhile, the dissemination and implementation of these standards should be strengthened to ensure that relevant personnel are thoroughly familiar with them and enforce them in strict accordance with requirements. Fourth, deepening international judicial cooperation and technological collaboration. Countries should enhance exchanges of experiences and best practices in the application of technology to criminal justice and promote cooperation in areas such as intelligence and information sharing, joint investigations, technical assistance and standard setting, so as to strengthen their capacity to jointly combat transnational crimes. Thank you, Mr Chair.
It is really me who thanks you for that very comprehensive overview. And I think that will be very helpful if we can request from you, if possible, to deliver a written version of your intervention to the Secretariat so we can also take into the account for the integration of the final report. With that, I would like to just proceed to give my my comments on or highlights on what caught my my eye on this very impressive panel on dual use technologies and other aspects that I think that the first thing that it will I will underscore is that most of this panel was was walking a tightrope between the use of technology and respecting human rights and rights to privacy and other issues related to, let's call them unforeseen, non-predicted consequences of the use of technology. And so let's go from Ms. Pastrana's first presentation, I would highlight that I was very much impressed by the Council of Europe's framework convention, highlighting or underscoring the need to protect personal data, and not only the data, but the people behind the data. Second, that it was necessary to notify users in any application or tech instrument that they were indeed interacting at that moment or at the precise, at any given moment with an artificial intelligence counterpart. Thirdly, that according to the framework, the artificial intelligence actors have a duty to perform risk and impact assessments, and not only once, but on a continuous or periodic manner. From Ms. Principi, Fox Principi, presentation, I found her presentation the one that really brought us head on to the heart of the matter between human rights and the the reality of new technologies being used in the judicially, in the crime and judiciary activities. So she made, she illustrated her point with a case of someone being refused bail due to recommendation or the judge resorting to an app or a computer analysis instrument that recommended that that person would not be given bail because of an assumed risk. And that connects us to yesterday's intervention by India, in which we also dealt with that conception of seeing artificial intelligence as or not only artificial intelligence, but but computer based systems that assessment systems that we do not know how they reason or how they are building the the the road to the decisions and in legal terms, in a criminal case terms, she said, if you cannot know how this was reasoned, then you cannot challenge it legally. And that is completely unfair, and it is something that she correctly pointed out. She also went very, very much further into the issue when she said that neurotechnologies plus artificial intelligence can violate the utmost human right, which is the right to keep our thoughts and our minds private and to our own selves. So I thought that her presentation was extremely, extremely thought-provoking and probably one of the ones that go deeper into the matters that we are discussing in this workshop. Major General Pilet gave us a different perspective. She approached the issue from the side of an institution whose job is to basically provide security to the citizens and investigate the crimes, and she also is noteworthy that South African police forces are very much aware that these technologies improve their capacities but also get them on this tightrope towards having to be extremely careful not to go into human rights violations. She said that the use of technology must be based on a direct link to a legitimate objective or result, and not just for the sake of saying, "We are very modern and we are using the artificial intelligence of X or Y technology." She also said that information security is a human rights safeguard, and I think that was a very valuable statement. I liked very much Ms. O'Brien's presentation because she not only explained the role of the Cybersecurity Convention, which I think is on the frontier, it's breaking ground on the next matters that we really need to engage as an international community to keep our populations safe and to confront the new threats that we are being faced as societies by the use of these technologies. But also she went explaining her points through the use of dichotomies, which I thought were very valuable. I'm not going to repeat them, but just for you to recall, good hands, bad hands, innovation versus regulation. And she was very, very able in disassembling or in breaking down common perceptions or common knowledge that were not necessarily true regarding these dichotomies. Mr. Ripley gave us a Canadian perception on how to approach all these matters and gave concrete examples on how to approach the problem from the perspective of the Ministry of Justice, basically, which is the policy-making institution, and how to promote the necessary tools to protect society through Parliament and working with the legislature. Here, underscored, there's a central question, it's how to use technology, because not if we use technology or not use technology. Technology is there. The matter is how to use it. And finally, he concluded by saying that tech should be used with openness, but also with caution. I think that will be it. And I like the, from the floor comments, I like first the concept of the China put forward of algorithmic transparency. I think that it is something very, it's a concept that if we looked further into it, it's very valuable. And also, I would like to conclude there basically so I don't take more time and with this I close the panel and now give the floor to Miss Wendy O'Brien from UNODC to carry on and present and moderate the second panel of the day. As is customary we will break for one minute so the panelists can the new panelists can come to the high table and I with that I also want to thank and ask you for helping with an applause to the to the outgoing panelists So we're going to start again. Please take your seats. Well, so we're ready to start the second panel. I already mentioned the title and the subject of the panel four, which is there on the screens now. And I am now happy that We are getting great support from Ms. Gallucci, who has accepted to step in and moderate the panel in order to allow Ms. O'Brien to work on the synthesis or the summary of salient points of this workshop four panels. And with that, I Thanking again, Ms. Gallucci for helping us. I give her the floor to moderate the current panel, the panel number four of workshop four.
Many thanks, Mr. Chair, and it's my pleasure to be here and moderate this last panel of workshop four. Thanks to all ladies and gentlemen and distinguished panels and expert being here again today. So this second, as a quick recap, this second part of workshop four aims to focus on the relevance of international cooperation and public private partnership for strengthened crime prevention and streamline criminal justice responses to cybercrime. Experts will share insights into how diverse stakeholders from government institutions to civil society organizations and the private sector play a key role in effective international cooperation and multi-stakeholder responses to cybercrime. So without any further ado, I would like to introduce you to our first panelist joining online, Judge Mohamed Elsend, Deputy to the Assistant Minister of Justice for International Cooperation Affairs and Chair of the Egyptian Committee for Preventing and Combating Cybercrime. Judge Elsend has over two decades of experience in the Egyptian judiciary. He began his career as a public prosecutor and advanced to become a vice president at the High Courts of Appeals. His expertise spans economic and organized crime, international judicial cooperation, cybercrime, electronic evidence, and the intersection of law and technology. He holds a master's degree in cyber law and cybercrime investigations and has contributed to major judicial development and legislative reform initiatives, including the integration of AI into judicial system, as well as Egypt's draft artificial intelligence law. Judge Elsend, the floor is yours. Thank you.
Thank you so much, Mr. Chair, esteemed panelists, distinguished representatives, colleagues, experts, ladies and gentlemen. Bismillahirrahmanirrahim. Assalamu alaikum. Peace be upon all of you. I would like to begin by expressing my heartfelt gratitude to Dr. Wendy O'Brien and to the UNODC for the opportunity to contribute to this meaningful discussion at such an important and prestigious event. It's a great honor to join you today and to share some few reflections on the Egyptian approach and perspective on the responsible and ethical use of technology in criminal justice. Please confirm that you have my presentation on the screen. Yes. In this very concise short presentation, during my allocated time, I will try my best to cover why international cooperation is very important when it comes to countering cybercrime and the importance of national coordination. Also shed some light on how we can achieve an accountable public private partnership in this regard. And I will give one or two examples on the Egyptian approach on the use of technology in criminal justice. First of all, this won't take much time. The next few slides, as you are all esteemed experts, and colleagues in this field, we know that cybercrime is a borderless criminal justice challenge. The expanding use of ICT has transformed what I like to call the five S's: the scale, speed, scope, stealth, and sophistication of all the criminal activities nowadays. The increasing intersection between cybercrime, all other forms of organized crime, terrorism, fraud, money laundering, child exploitation, and a long list is increasing, maybe on a daily basis. Offenders, victims, data, infrastructure, proceeds often span multiple jurisdictions. The electronic evidence, as we all know, can be very volatile, remote, frequently held by foreign service providers. This is why the effective justice response depend on a timely, lawful and trusted cooperation, not only between national authorities, also on an international level and through the partnership with private sector as well. Actually, we have for decades, countries has evolved and developed the national legislations, also regional instruments like the Budapest Convention, Arab Convention for Cybercrime, the Malabo Convention of the African Union, and many other attempts. Also the bilateral agreements, judicial cooperation, so on and so forth, has tackled cybercrime. However, Cybercrime requires a broader, more comprehensive, inclusive cooperation. This is why the new UN Convention provides this common global framework. It bridged the gaps between legal systems while respecting the national sovereignty. This is very important point. And we all know that the five main pillars that this convention provides which is the global framework, the strengthening international cooperation, the exchange of electronic evidence, support capacity building and technical assistance, which is very important, especially for the developing countries, and also preventing safe havens for criminals and achieving justice for victims while preserving and upholding the rule of law and human rights. The international cooperation is a must, as we have just discussed together. This is why Chapter 5, which is dedicated to international cooperation, is the longest chapter in the Convention. And I recall Article 40, which is on the mutual legal assistance, is also the longest article in the Convention. What does that tell? It tells us that the international cooperation is the main pillar and of the countering into cybercrime in an international level. But is it, are we done now? No, I recall the interventions from the colleagues in the previous panel that we need to move forward from the convention to the implementation and ratification. This is our challenge nowadays to benefit from all the innovative mechanisms that help promote international cooperation and effective countering to cybercrime. Now I will move to the second part of my presentation, which is the national coordination. We always speak about the international cooperation, how challenging it can be, but we sometimes forget, sometimes we forget about the national coordination, as if it's something that is always there and it's a given fact and it's always for granted, but this is not the case. And I would like also to always highlight that without an effective and real national coordination, there is no international cooperation. This is why Egypt has developed the Egyptian Committee for Preventing and Combating Cybercrime last year. It has been established by the ministerial decree of the Minister of Justice, 2025. Specifically on March 2025, this committee is affiliated to our National Committee for Crime Prevention and Criminal Justice. Next slide, please. Yes. Next one. Yes. And then next slide. One more slide. Thank you. So again, it has been established by the ministerial decree and then affiliated to the national committee, the ministerial decree of the Minister of Justice in his capacity as the chair of the Egyptian National Committee for Crime Prevention and Criminal Justice, which has been established by the prime ministerial decree on 2021. And I would like to here mention a couple of words. When we were establishing this cybercrime committee, we have had two options, whether to establish it as a standalone committee or to affiliate it to the National Committee for Crime Prevention and Criminal Justice. And here I give some details as a best practice for other colleagues who would like to know more about this initiative. Because this increasing intersection between cybercrime and other forms and modalities and patterns of criminal activities, we thought to avoid overlapping and duplicating the efforts that affiliating this committee to the National Committee for Crime Prevention and Criminal Justice is more efficient and it will save us a lot of time and effort. This is something very important and it helped a lot after, like, using this national coordination mechanism. We now, we are sure that this was the right decision to make. This committee is chaired by a representative of the International Cooperation Department of the Ministry of Justice, which is the central authority of international judicial cooperation in Egypt. Humbly and proudly, this is myself. The formation. The committee includes representatives of the following entities: the Ministries of Justice, Defense, Interior, Foreign Affairs, Communication and Information Technology, also the General Intelligence, Public Prosecution, Administrative Control Authority, Central Bank of Egypt, the Egyptian Anti-Money Laundering Unit or the Egyptian FIU, the EG-CERT, National Coordinating Committee for Human Trafficking and Unlawful Migration, Personal Data Protection Authority, Egyptian Intellectual Property Authority, and the Supreme Permanent Committee for Human Rights. These are all the members of the committee, and it's very, actually, we are very proud that we have received requests from more national authorities to join the committee. The mandate, five main pillars compose the committee. First of all, developing policies and strategies and proposing legislative and regulatory measures. This is a very important one, and I'm very proud to announce that we have been working for the past few months on a dedicated strategy for preventing and combating cybercrime. To the best of my knowledge, it might be when being launched and published, it might be the first globally, the first dedicated cybercrime strategy. I know that there has been. few strategies that are tackling cybercrime under criminal justice or crime prevention, organized crime, maybe cybersecurity in some countries, but not a specialized, dedicated strategy. And we are very proud about the advancement and progress of the work. The second mandate is raising public awareness to mitigate and reduce the risk. Of course, all the risks, societal, economic, and psychological also as well, throughout some raising awareness campaigns, school curricula. We are also trying our best in this regard, and this will promote the prevention role of the committee. The third one is strengthening national coordination mechanism between judicial authorities, prosecution, law enforcement agencies, and relevant national institutions, including, by the way, some private sector and civil society organizations. And let me add two words about this. Simply, when we bring together around the same table all the relevant authorities, a lot of coordination has been already achieved even before discussing the meeting agenda or anything. It's amazing how when we sit together, we overcome some operational challenges. And this is why this committee of a dual nature, strategic but also operational. And in this regard, specifically, we achieve a lot of operational coordination. Moving to The mandate number four is promoting international cooperation frameworks for the exchange of information, expertise, and best practices. This is very important as we have tackled international cooperation at large, not only mutual legal assistance and judicial cooperation, not only information exchange, but also the partnership with the UNODC, relevant UN agencies, international organizations, also Council of Europe, the EU. also on a bilateral level with other countries, capacity building initiatives. And we are now about to launch the Egyptian African Center for Preventing and Combating Cybercrime in partnership with the UNODC. And these are all things that has been achieved through this committee. And it's also worth mentioning that through this committee, we have been negotiating and elaborating the national perspective towards the UN Convention. and preparing for the Egyptian participation in Hanoi signing ceremony. It was very good one and we were very proud about this. And we are now lead notification to that convention through this national mechanism as well. Finally, reviewing and analyzing reports and statistics on cybercrime trends, emerging developments for data informed decision, and this is linked to the mandate from the Council, which is the different legislations, because without this data-informed and data-driven decision-making process, we will be not adopting the right methodology or doing the right thing. This is briefly about the committee. We have already achieved a lot. We have drafted proposals to bills and sent them to the government. Many things have been achieved. I'm not here to list out the accomplishments of this committee, but to let you know more about this practice generally. Because now I want to move to one very important topic, which is the public-private partnership. Next slide, please. Private actors, when we speak about the governance, I have listened carefully to the discussion in the previous panel. And I agree with all opinions, but there were two opposing perspectives is that we need to regulate or we need to mitigate the criminal use of technology. We do need to acknowledge itself. Actually, my perspective is we need both. We need to promote innovation, but also maintain governance over the actors of the cyberspace and technology. The private sector are very important actors when it comes to the governance of the digital space and the cyberspace. Infrastructure, the data that they have, is very, very important to the criminal investigations and prosecution. But the cooperation with service providers is very, very essential and it happens already. We need to work more on this and to engage them in the, let's say, decision making or the policy making process. This is very important and we all agree on this. But this should be done in compliance with the lawful duties. It's not a matter of incentive because I hear sometimes in some different occasions, some narratives about that we need to give incentives to the private, need to show more flexibility to engage them in this decision-making process and to engage them in the efforts or to promote the public-private partnership. I'm sorry, I do not agree with this. So I agree strongly about the importance of the private sector, technology companies, service providers, but I do not agree that we need to give some legal privilege due to the importance of the role of the service provider, because we are or should always think to uphold the rule of law, which is equality. Next slide, please. Because the equality of all the legal and natural persons is a must. It's not optional. It's not an accessory. All service providers, all natural persons, and all other legal persons, companies of making medicine, the companies of agriculture, the companies of export and import, they are all bound by the rule of law. So this public-private partnership should not replace the sovereignty and the responsibilities of the states. The criminal justice remains a sovereign state responsibility. The aim and we understand the private sector importance for the economics and for the financial circle of every country and for the global economic, but the goals and aims of the state is different. Upholding the rule of law, keeping the public peace, public order, safety, upholding the human rights is the responsibility of the states. It is the case and it will always be. So the core public power should not be transferred. We do not need to give some privilege or to give, show some flexibility to avoid upholding the rule of law in order to achieve this very important and needed much needed public private partnership. The legal obligations must remain distinct from voluntary cooperation. This is very important as well. Next slide, please. Now we have to reassure the equality, accountability and rule of law. Because the rule of law applies, as we all agree, to all natural and legal persons. And the rule of law is the due process, equality, accountability, independency of judiciary. This has to be applied to everyone. regardless of the aims, objectives, or the legal establishment or the legal nature of this entity. Cooperation must remain subject to oversight and accountability, and due process and fundamental rights must always be protected. This is why the effective partnership, in my opinion, must... sovereign authority I have finished this third part of my presentation and I'm sorry if I'm taking longer than expected, but to highlight those points. Finally, I would like to showcase examples of the responsible use of technology in the Egyptian criminal justice system. We now try to expand our approach, which combines the technological modernization with legal and institutional safeguards to achieve or to strike the right balance. Digital transformation of judicial services has been adopted for years now, and we have made such a huge progress in this regard. The development of electronic litigation systems was very important. The integration of AI into judicial processes is very important as well, very useful, and this is the positive side of the use of AI. Strengthening electronic evidence capabilities, the capacity building for judges and prosecutors, the legislative reforms is always there to give this legal umbrella for all those initiatives to expand the responsible use of technology. I will give one example with the economic court in Egypt, not because it's my court, or maybe because it's my court, but I know more about this experience. We have established a full electronic litigation system in the economic courts of Egypt. And by the way, the economic courts of Egypt is the competent court for the crime by the way, and that well established electronic system to achieve this. On this, please, the last slide. The final message. Next slide, please. Next one as well. Technology should strengthen justice, not weaken its safeguards. And the response to know the previous slide, please. The responsible next. Yes. Previous. Yes. Responsible use of technology in criminal justice requires National coordination, international cooperation, and accountable public-private partnership. Thank you so much for your listening. Thank you.
Many thanks, Judge Elzan, for sharing insights from Egypt, going from the national coordination and all the best practices and measures you put in place within the national ecosystems, also to international cooperation. I believe many of the examples you share about the committee could be quite inspiring for many in the room. So thanks. Thanks again. Moving next, our panelist is Lieutenant Colonel Khaled Al-Khabe. He has served as the director of the Child Protection Center at the Ministry of Interior since 2021 and brings more than 20 years of experience in policing and law enforcement. from the United Arab Emirates Ministry of Interior. He holds a bachelor degree in police sciences and criminal justice, a master of business administration, and as well as specialized diplomas in combating human trafficking and security statistics and analysis. He is also a lecturer and national expert in crime analysis with extensive experience in child protection and crime prevention. Throughout his career, he has contributed to various national and international committees and initiatives dedicated to combating crimes against children, including online crimes and emerging digital threats affecting children. Lieutenant Colonel Al-Kabi, the floor is yours. Thank you.
Thank you so much. Excellencies, ladies and gentlemen, dear colleagues, in the old days here in the United Arab Emirates, we lived in a neighborhood where a child didn't belong to one family only. A child belonged to everyone. If a neighborhood saw a child in danger, he didn't stop to ask, "Whose child is this?" He ran to protect them. That was simply who we were. Today, the neighborhood has changed. It has become a digital world, open and without walls, and danger no longer knocks on the door. It can reach a child through a screen. in their own room, while their family thinks they are safe. When we talk about AI and online child sexual exploitation, it is easy to focus on the technology, but we must never forget who we are protecting. Behind every image, every video, and every case, there is a child, a real child waiting for someone to find them, protect them, and give them justice. Every image is a crime scene, and every time it is shared, that a child is harmed again. Many of us in this room are parents. Some of us are grandparents, and every one of us was once a child. Today, investigators around the world focus a growing flood in the material, thousands of images, videos, and leads to review, and every moment we lose is a moment a child may remain at risk. This is where technology can help us. In 2020, the United Arab Emirates Ministry of Interior and UNICRI launched artificial intelligence for safer children, AI for Safer Children. The idea was simple, make AI a practical and trust tool that law enforcement can use lawfully, ethically, and effectively to prevent and investigate the online sexual abuse and exploitation of children. Since then, AI for Safer Children has trained more than 2,700 law enforcement officers from 64 countries. It has built a community for more than 1,500 investigators across 129 countries. And through its global hub investigator, can access more than 100 AI and technology tool along with training and expertise. But AI for Safer Children is not only about technology, it's about people standing together to protect children. It is the old neighborhood again only. This is time as big as the world. These are not just number, each of us are trained could be the one who find a child tomorrow. This is same commitment is now stronger through the Abu Dhabi Declaration. It's calls for stronger action against online child sexual abuse and exploitation. Better protection for victim, more information sharing, and closer cooperation between government, law enforcement, and private sector. Now we must turn the commitment into action. Not every country has the same technology, resource and expertise, but no country should ever have to face the same crime alone. If one country has a tool that can help another, let's share it. If one police force has experience that can help another, let's connect them. Because a child should never receive less protection simply because of where they live. The Abu Dhabi Declaration gives us the commitment, AI for Safer Children, give us one way to make it real. So my message today is simple. If you have the tool, share them. If you have the experience, share it, bring it. And if you need support, ask for it. Because behind every case, there is a child waiting to be protected. Technology can help us reach that child faster. Cooperation can help us reach more children. And together, we can turn our promise into protection. In the old neighborhood, no one asked, "Whose child is this?" Let us not ask it today either. Every child in every country is our child. Thank you so much.
Thanks, Lieutenant Colonel Alkabi. Thanks a lot for joining us and for your insight into child online exploitation. The reminder that we should never forget who we are protecting and our every image is unfortunately a crime scene. On behalf of UNICEF, let me say that we are extremely grateful for the partnership with the United Arab Emirates Minister of Interior on our collaboration of the AI for Safer Children initiative, and we hope that we can collaborate on many more years together. Thank you. Next panelist is Mr. Glen Pritchard, the Chief of Cybercrime and Technology Section at the United Nations Office on Drugs and Crime. This section specifically oversees UNODC work to support the ratification and implementation of the UN Convention against Cybercrime. Mr. Pritchard joined the UNODC in 2013. Before joining UNODC, he worked at the Australian Crime Commission from 1999 in various investigation management roles, commencing his career in the Queensland Police Service in Australia in 1986. where he worked in various criminal investigation roles. Mr. Pritchard holds a master's degree in criminal justice. Mr. Pritchard, the floor is yours. Thank you.
Thank you very much. Distinguished delegates and colleagues, first of all, thank you for the opportunity to join this workshop here today, and a special thanks to our host, the UAE, who have demonstrated strong leadership in criminal justice through their hosting of the Crime Congress. I would like to focus my intervention on a dilemma that exists in the world of criminal justice regarding to the need to know in order to protect public safety versus the need to protect privacy. In essence, I want to explore a little bit deeper some of the challenges raised by Mr. Owen Ripley from the Canadian Department of Justice that he raised in the previous panel in relation to the lawful access to encrypted communications while still respecting the rights of privacy, ultimately highlighting the need to develop solutions through trusted relationships with the private sector. I will discuss how these two competing important paradigms creates a tension between telecommunication providers and the criminal justice sector, with both parties continuing to struggle to achieve the right balance in order to ensure government can ensure public safety while also protecting the privacy of their citizens. I think it is important to first look at the broad context of this situation and how we arrived here. I think everybody in this room is well aware that social media and messaging applications, digital collaboration tools are omnipresent in our lives. Everything we do these days, we're connected to our phones, to our computers. In the wake of this digital proliferation, the importance of privacy has been considerably magnified. As technologies continue to evolve, I am sure that similar dilemmas will continue to arise. In the same way that digital communications are everywhere in our lives, they also play an almost integral role in nearly every part of crime. It is hard to imagine that there is any type of crime that does not leave some form of digital footprint in today's world. Investigators need to access information to prove a case and to further investigate the case when achieved during the course of the investigation. And there's the range of evidence of electronic evidence. I can go on and list them all. But I liked our co-panelist's comments in the previous intervention when he made the powerful statement, "Every illicit image is a crime scene." We need to think about that. How do we do any investigation if we don't treat the electronic evidence as a crime scene? And it just brings home some of the importance of this type of data. In today's digital world, electronic evidence has become a fundamental and integral component of almost every criminal investigation and subsequent criminal justice proceeding. With the proliferation of digital communication, telecommunications service providers are at the forefront of handling vast amounts of data that ultimately would be crucial evidence in criminal cases. As a consequence, telcos have found themselves in the middle of a highly complex legal and ethical dilemma. They must constantly balance their legal obligations to assist law enforcement in their efforts to provide public safety by sharing electronic evidence against their fundamental duty to protect the user privacy and digital rights. What sometimes is referred to as the end-to-end encryption wall creates a really difficult dilemma. This really accentuates these competing values between the need to lawfully access end-to-end encrypted data as part of a criminal investigation that they have lawfully obtained a warrant or a production order for against the rights for the privacy of customers. The end-to-end encryption issue is a strong example of the growing global difficulties faced in striking the balance between the right to privacy and the imperatives of public safety. As digital technologies advance, encryption has emerged as a cornerstone for protecting sensitive data, ensuring secure communications and safeguarding individual privacy. That is There are very real and valuable reasons for why we want our data to be encrypted. I think we can all agree that we want that privacy when we use our telecommunication services. How do we strike that balance where we need that fundamental right to have privacy against when criminal justice needs to lawfully access that data as part of an investigation? Privacy supports the establishment of trust in the digital environment. Without privacy, users remain vulnerable to identity theft, fraud, phishing and illegal forms of surveillance. End-to-end encryption protects sensitive information related to medical history, financial transactions, political opinions and personal conversations from being exploited. However, as part of the government's responsibility to combat a range of different offences, terrorism, cybercrime and all forms of serious and organised crime, they have increasingly advocated for the introduction of encryption backdoors to allow law enforcement agencies to access encrypted data following judicial approval to obtain such data. The dilemma is that the end-to-end encryption ensures that only the communicating partners hold the decryption keys. Consequently, even when presented with a valid warrant or production order, a provider may technically be unable to view or hand over the content data. This leads to regulatory pushback, with governments demanding backdoors that tech privacy advocates argue would fundamentally compromise internet security for all users. While one can easily argue that privacy needs are sacred and the protection of data is paramount, controversy can very well arise when access to such data is lawfully requested as part of criminal investigations. As I mentioned earlier, digital evidence is vital for all law enforcement activities and judicial processes nowadays. but under the end-to-end encryption, service providers cannot decrypt messages, even with a court-issued search warrant. This stalemate has been sometimes referred to as a 'going dark' scenario, where communication channels remain impenetrable to criminal justice, even with legal authorisation. In different jurisdictions, the efforts to find the correct balance ends up being met with differing degrees of tolerance for encryption according to the constitutional values, legislative traditions, and institutional structures. Domestic legislation and regulatory proposals within some jurisdictions dominate the global conversation on digital privacy, enforcement access, and limits to surveillance. These jurisdictions form the basis for the data protection approaches with far-reaching implications. The approaches themselves critically pose many questions for policymakers as they try to balance the protection of encrypted communications with the need for lawfully investigative tools in an increasingly digitalised society. One of the many debated aspects that I mentioned before was the concept of encrypted backdoors, which are deliberate vulnerabilities inserted into encryption systems to provide authorised entities with the means of accessing encrypted data without requiring the decryption key. Encryption backdoors are typically presented as a solution to facilitate investigation into criminal activities, enabling authorities to bypass the encryption and access potentially vital evidence that would otherwise hidden. However, the introduction of backdoors into encryption systems raises serious concerns about security and privacy, as it is claimed they create a potential entry for malicious actors, including hackers, to exploit, thereby eroding trust in the digital communications platform. The growing reliance on encrypted platforms such as messaging apps and cloud storage devices only amplifies the significance of this debate. There's also another issue that has arisen in that end-to-end encryption is sometimes only available to the communicating parties. That means that even the platform providing the encryption cannot decrypt it; only one of the parties can decrypt it, which has raised alarms to governments, especially in relation to the inability of law enforcement to access such data and communications. In some countries, governments have pushed for legislation that would mandate the creation of backdoors in encryption software to facilitate lawful interception. In others, there is a strong resistance to such measures, based on the belief that any compromise in encryption security would have far-reaching negative consequences for individuals' privacy and the integrity of their digital communications. Apart from domestic legislation, other solutions are being explored that address the competing priorities through criminal justice entities developing trusted private-public partnerships with telecommunications companies that have the potential to achieve mutually beneficial outcomes. One of the main key areas in this is when they, the lawful access by design. This concept explores standardised, auditable interfaces built into communication systems to retrieve targeted data under judicial oversight without creating random vulnerabilities. While I am confident that sensible and workable solutions to this challenge will ultimately be established and applied, But I believe it is important to raise this dilemma to demonstrate the challenge that often exists as technologies continue to evolve, often raising these challenges to strike a balance between competing issues in criminal justice. All of which, I think all of these issues, the competing issues, are ones we want to see have a proper solution to, where we want the right to privacy, but we also need to have public safety protected through lawful access to this data. So it's a matter of solving that. Once again, I thank you for your attention, and I'm looking forward to the rest of the interventions. Thank you.
Thank you, Mr. Pritchard, for your intervention and for bringing up a topic that I think we actually haven't covered a lot in this workshop, with all electronic evidence, but particularly end-to-end encryption. and the dilemma behind it, data privacy and data security, also references to the encryption backdoors and to going dark scenarios. These are all important topic in regards particular to public-private partnerships. So thanks, thanks again. Moving forward, our next panelist is joining online. Dr. Camilo Tamayo Gomez is Associate Professor at the University of Huddersfield, United Kingdom. Dr. Gomez is a sociologist whose research examines the relationships between violence, security, human rights, social justice, and citizen participation, with particular attention to societies affected by conflict and inequality. His work focuses on how civil society organizations, social movement, victims, and other non-state actors contribute to governance, accountability, public policy, and the protection of rights. His research also explores the role of communication, collective action, and institutional responses in transforming conditions of insecurity and strengthening more inclusive rights-based approaches to security and justice. Dr. Gomez, the floor is yours. Thank you.
So thank you very much, Otavia, for that really, really nice introduction. And, well, good afternoon, everyone. I want to start saying thank you to the UNODC and to UNICRI for inviting me to be part of this workshop. I'm going to share a presentation with you. So what I want to do in the next 10, 15 minutes is trying to present to you a different kind of approach to understand cybercrime governance. And this kind of approach try to address the ecosystem of governance from a perspective that we call from below. So if you can share my presentation and move to the second slide, I will really, really appreciate. And the next slide, please, and the next one, please. So thank you. So what I'm going to start doing is try to reframe the problem, because when we start thinking and reflecting regarding governance and how governance can provide a different kind of outcome to reframe the problem of cybercrime, I think that we need to start thinking in a different kind of ways to create a better approach and a better way to fix this problem. And what we say, and we're thinking in the International Association and in other academic organizations, is that we need to move from a governance system that plays the state and different kind of legal frameworks at the center and trying to move this more to the role and the capacity of civil society, social movements, and citizens in order to create a different kind of ecosystem. What I am going to do in the next 10 to 15 minutes is try to develop this core argument. We believe that international cooperation can be stronger when local knowledge, independent evidence, public accountability and rights protection are built into the governance ecosystem before starting the ecosystem and not added afterwards. What I want to highlight and stress is the important role and the pivotal role of citizens, social movements, and the public in general to create a different kind of governance ecosystems. We have identified four elements that are not working really well in the actual governance ecosystem. One is the fragmented laws. We are seeing the different kind of treaties and different kind of legal approaches are really fragmented, like and are not really robust and are not creating a dialogue to address the problem more coherently. We are seeing an uneven capacity of institutions, states and different kind of like providers in order to address the problem and to create a more. let's say, interesting and important approach to create this ecosystem and to, of course, fight this problem of cybercrime. We're seeing a slow adaptation of the states and different kind of like legal frameworks to address like problems that are happening regarding cyber crime. And one of the elements that we're seeing, and I'm going to stress this, is that we're seeing a kind of like a level of low trust regarding the systems, the organizations, and the institutions who are creating these governance ecosystems. So what we're going to try to do is to stress the idea that if we create a different kind of from-below approach to this ecosystem, we can create four elements that for us could be more relevant. And if you want to move to the next slide, please. So we believe that if we do this from-below approach to create a better ecosystem, we can add five things, and we can do these five things. First of all, we can detect arms and we can start thinking how we can approach different kind of risk for a more interesting, if you don't say approach, but more importantly is how we can reflect about the meaning of harm. in the world of cybercrime and, of course, in the field of cybercrime. But more interestingly is how we can bring to non-state actors like social movements, citizens, and so on, a more strong cooperation to add knowledge, accountability, and, of course, to bring some practical support to institutions, states, and governments. So we believe that this governance from below can contribute to detect this kind of new arms, and we're talking about deep fakes, for example, in the previous panel, And the influence, of course, and the impact of AI in our everyday lives that are creating new kind of arms and new kind of challenges and problems. So we believe that this approach can provide a better way to detect these arms. Another contribution is the independent evidence that social movements and community can provide in order to create better research and to create better evaluations of the tools that organizations and states are creating to fight against cybercrime. And of course, in order to create a better audits to the different kind of implementations and governments and states are doing. But the creation of this kind of independent evidence can help us to address the problem in a more robust way. Other element that can contribute this governance from below is how we can translate context and how we can start thinking about the social cultural differences that we need to have into consideration when we are implementing solutions against cybercrime. So how this combination between laws, legal legislations, new elements of technology and socio-cultural regimes can create a better dialogue in order to address this problem in different kind of context. Another contribution is the building of better capacity and how we can create digital literacy and more better tools to train people to fight against cybercrime. So once again, this governance from below is giving more power, more agency to citizens and social movements in order to create a better ecosystem to fight against cybercrime. And finally, of course, one contribution that we think is really important is how human rights can be at the center of the discussion at this kind of rights scrutiny that we think that is important to test the due process and accountability. Just to put it really simple, is how we can start thinking human rights as at the center of the ecosystem in order to defend human rights, but more importantly, to the capacity and bring capacity to social movements and citizens to claim human rights in these kind of digital ecosystems and in this scale of new governance. Please, the next slide. After reflecting what would be the added value, like why we need to start thinking and reflecting about this from-below approach, our main goal is how we can create a more durable entry point for scrutiny, challenge, and justification. How this kind of from-below approach can give us a more robust approach to fight against cybercrime. So we have identified four elements here that I want to present to you that I think is important to see the value. What is that value that organizations, institutions, multi-lateral organizations can start thinking? So one is the value, of course, to create a better international cooperation to face asymmetry. And this is important when we talk about asymmetry and is how organizations, how states are accessing to some technologies that are providing the reproduction of asymmetries. So we are seeing here in the dialogue between the global south and the global north, how they access to some technologies to defense against crime, but to commit crime. So we need a better international cooperation to face these asymmetries and of course to fight against crime, but to reinforce different to fight against that asymmetry. Another important value is how we can fight against opacity and how some institutions and how some private companies are using this actual ecosystem to just basically hide their intentions and fight against the public good. So I think this kind of from below can add value in order to fight against opacity and at the same time we can build more trust, like a public trust and social trust regarding how how to fight against cybercrime. So another important value is how we can create better elements to create social trust to fight against cybercrime. And more interestingly, how we can fight against different kind of tensions that this asymmetry, opacity and distrust are creating and once again, putting the human rights discussion at the center. So this from below approach is basically claiming that we can create better local capacity if we can create a more peer learning basing on the interest and the, of course, the main elements of civil society, creating independent research. advocating for more transparency regarding these ecosystems and of course making accountable the companies that are behind some technologies and the governments that are using some technologies to produce harm. How we can create a better dialogue and participation to create a better social structure to fight against cybercrime and of course how we can respect the rule of law and how we can follow due process and the rights assessment regarding the fighting against a cybercrime. And finally, in the next slide, I want to finalize thinking and showing that in some ways how we can design a more effective international cooperation. And my message is like how we can move from participation to create better infrastructures. And this is what is tricky. And this is why these scenarios and these congresses are really important, because it's start thinking collectively how we can move just not just giving the voice to civil society or to social movements or with any kind of like a civil society organization to be part of the discussion, but it's more interesting to see how they can be part of the whole infrastructure. It's not just about giving the voice to civil society when we talk about all these topics, it's how they can be part in a more robust and important capacity into the infrastructure to create towards a more effective cooperation, create better capacity, better legitimacy, fight, and of course, like against cybercrime for a human rights approach. But more importantly, this is the main message, how we can be more adaptable. because when we are seeing it's like a cyber crime is is really that all we change is changing all the time so we need to be more flexible we need to be more adaptable in order to create tools to find again to fight against cyber crime so we need to adapt and civil society and social movements can give us some elements some tools to fight against cybercrime with this kind of like adaptability that they have. So we are thinking that institutional participation, the co-production of evidence, building more elements or contestability, how we can create better elements of transparency, and how we can redistribute the capacity of the whole ecosystem governance can be a key element to fight in a better way against cybercrime. So I just want to finish with this, like, I would like to invite you to rethink and to readdress how we can redistribute the capacity between all these different kind of elements, like institutions, government, civil society, to create a more robust ecosystem to fight against cybercrime. Once again, thank you so much for giving me the opportunity to present these ideas, and I will look forward to the conversation in a couple of minutes. Thank you.
Many thanks, Camilo, for joining us online and sharing your presentation and idea on how to reframe the problem and the criticality of including citizens and social movements the governance from below approach is definitely something that many actors should think about, particularly for the flexibility and adaptability that we might all need in fighting cyber crimes. Thanks. Thanks again. Last but not least, our last panelist for this section is Mr. Cherif Aza, CEO of Intelligence Support and Security Consulting. Mr. Aza has more than 25 years of hands-on cybersecurity experience with strength in hacking, offensive security, and intelligence, and particularly hacking since 1992. That's quite a long time. Mr. Aza has been involved in various consulting roles on cyber defense with governments, military, energy sectors, and he led consulting roles internationally, including North America, Europe, Middle East, and North Africa. Mr. Hazai has been active in the security research and has been part of several international groups. He has achieved various copyrights in security and a patent in secure data exchange using cryptography and a number of GPL open source projects serving the security industry. Mr. Hazai, thanks for being here, and the floor is yours.
Thank you for the introduction and thank you for the opportunity to speak over here. And I think I'm the only private sector in the panel, so I hope that's a good thing. It's going to be short. It's about how we use private sector skills and expertise in fighting cybercrime. And I think I'm going to talk as well about when you talk about human rights, it's not only against the private sector, sometimes there is violation also by governments. So we're going to stick into this. This is a simple framework that we have existing since, I think, 2008, 2009, where you monitor everything online, social media, all the OSINT stuff. You classify using machine models. It's not the crazy LLMs. It's not the big AIs. You can actually run it on a PC. You extract the information and you classify, and then you basically have a person of interest or a suspect, and then you work on identifying the actual identity. One of the violations we've seen, this was supposed to combat, like, let's say, narcotics, human trafficking, and terrorism. It was used in different countries, majority of countries, against fighting opposition, actually. So we had to pull it down, we pulled the plug, we isolated certain engines, and then we started offering it now commercially as a brand protection and takedown of offensive reputation thing. So it was created and supposed to be used by something, but what the abuse actually was by the government itself, not by the private sector or us. Finally, I'm putting everything on just a table for easier follow-up. The methods we've used is lawful interception. You deploy it at the operator mainly. Now you have challenges with the SSL and encryption and end-to-end encryption. You can bypass it in certain points, but again, what gives you the right to do this? But one of the advantages you go even when an encrypted communication is you can build a relation, who knows who, how frequently they talk to each other, how frequently they know each other. Detection from, we usually say victim, but from anyone on the network will be low. They wouldn't know that you're intercepting unless you actually use a dark certificate, which they can trace it back. OSINT, which I think is the increasing one, everyone is using it. It's public information. Somebody posted it willingly online. but it's somehow different or like actually difficult to identify the real identity behind the account. So you have a fake account is doing a crime, selling narcotics or anything, and then you don't really know who's behind it because it's just, I don't know, a weed master or something. So advantage, you don't need to target anyone. Everything is available online. You can find the relation. It's not detectable, but It's very weak on the identity stuff. We also can use darknet or leaked, you might know it as info stealers, if you ever wanna buy this, it's called info stealers. And this will give you an actual identity of somebody using an e-mail or an account or a Facebook ID or a phone or just like any handle. But they have to have been infected at some point. And at this point, you actually get the entire machine as an information. So you don't really have to go and do an offensive operation. Offensive is basically infection. You infect the victim or the person of interest or however. Now it also has a human right issue. Like do you have a warrant or not? Are you allowed to infect or not? All of that. One of the challenges actually to exploit and gain access to the machine or the device or the phone, because the way it works is Government doesn't have the actual commercial vehicle to buy zero days, which is newly exploits. They don't have the commercial vehicle for that. And that hinders the whole process. But it will give you a full access on the machine. Its detection is high, super high. If it's a cheap solution, it's super high. If it's open source, it's definitely detectable. And then the latest one, which is the holy grail of the whole thing right now, is called offensive OSINT. Nothing is required, no backend is required, no infection is required, nothing is required, but you will get the true identity of the account, IP address, real IP address, phone number, sometimes location, address, names, everything, with zero intervention from the client side. So that's everything from the private sector. I know we're looked at controlling and having data and I don't know, I think everything I'm hearing, think we're like the very bad guys in this, but we have our own social responsibility. Thank you.
Thanks a lot, Mr. Azar. And at least I would speak personally, absolutely, you're not the bad guy here, and we are very glad to have you here. We know that sometimes it's hard for private sector entities to join this type of conversation. So again, we are very grateful that you were willing to participate and share your experience from the private sector and also different references to more technical type of, in this case, deployment and and and and detection. I think it's very interesting how you mentioned different level of of the detection by victims of this technical type of type of attacks and that is often time is zero, right? So thanks. Thanks again for for joining today. So I would just like to thank all panelists for their insightful presentations once again. I hope also the audience found this panel interesting. So I will now pass the floor back to the chair. Thank you.
Thank you very much, Ms. Eliussi. I must tell everybody that we are over time, but anyway, I think that it is worthwhile to get a couple of interventions from the floor. I see Egypt first, please. And then on the back, very back, which is it? Can you raise it? Or let us know where I cannot see so far.
Chair, India. India.
And European Union, Mr. Chair.
We have those three. First, Egypt, then the European Union, and finally, India. Okay, you have the floor, Egypt.
Thank you, Mr. Chair. Mr. Chair, distinguished delegates and colleagues, before I address my question, allow me a brief personal note. I would like to warmly welcome my colleague, panelist, and expert, Judge Mohamed Zind, one of the leading members of our team at the International Cooperation Department, the Ministry of Justice of Egypt, who could not be with us today due to unforeseen hardship. though his determination to participate remains undiminished. With that, Mr. Chair, allow me to turn to the panel. Cybercrime confronts us with a structural reality. The infrastructure, data, and technical expertise essential to detection and prosecution are largely in private hands. The evidentiary trail runs through servers and platforms governed by different legal systems, different incentives, different standards of cooperation. With reference to the Abu Dhabi Declaration that commits states to deeper public-private engagement, and the UN Cybercrime Convention provides the legal framework as well, the UNODC's own planning identifies trust as the single most critical enabler of effective public-private cooperation. Yet, private entities face real reputational, commercial, and legal risks when sharing information with law enforcement. So I would like to put two questions to the panel. First, what specific mechanisms, whether legal safe harbors, confidentiality frameworks, or structured trust platforms, have proven most effective in overcoming this trust deficit in practice? And how can the provisions of the new UN Cybercrime Convention, including its technical assistance framework, be used to scale those mechanisms to countries where the capacity gap is greatest. Second is, Egypt is finalizing ratification of the UN Cybercrime Convention and developing a national strategy on cybercrime, as referred in our pledge for justice, structured around four Ps, prevent, prosecute, protect, and promote. From the panel's experience, how should a national strategy integrate public-private partnership as a cross-cutting element rather than a standalone component? And what indicators should be used to measure whether that partnership is actually improving investigative outcomes? Thank you, Mr. Chair.
Thank you. And I would consult the panelists if someone would like to respond, including dear Judge Elson, if he would like to also take the floor from his office online in Cairo. Okay, can I ask the technical staff to put him on screen? Thank you so much, dear judge.
Thank you, His Excellency, Assistant Minister of Justice, for his warm message. And I really wish if I was able to be there with you in person. Going back to the question, and I will tackle the question partially, but also reflect on the concluding comments from my esteemed panelists representing the private sector. I would like to reaffirm that we all appreciate the amazing work and cooperation and the engagement of private sector. And we always highlight that due to the data infrastructure and some technological aspects, you became, when it comes to combating cybercrime, one of the main actors in this field and this context. And if I understood correctly, maybe your comment was directed to me or to similar comments, when I mentioned that in order to recognise and promote the partnership and engagement of private sector technology companies and service providers, we should not violate the law. This is not directed to the private sector at all, because this is not the narrative of the private sector. However, some colleagues and member states, in some negotiations and under some circumstances, They have every good intention like us to make sure that the private sector is well represented and engaged properly. In order to do so, they are willing to, not intentionally, to give some privilege to the private sector and technology company, and this is where my intervention came from, or where my comment about this part came from. It's not directed to you at all. We all recognize the technology companies and the private sector, but in order to do so, we must also reaffirm that all actors are bound by the law. This is the main safeguard. This is not something negotiable. There should be no room for concessions, no for pleadings with technology companies to cooperate or engage in combating cybercrime. We are all bound by law, again, and well. are all bound by law and by law only. Thank you so much.
Thank you very much, Judge. I think that you've reinforced the point that you've made in your presentation. I now give the floor to the European Union, please.
Yes, thank you, Mr. Chair. I'm mindful of time, but I would still like to take the opportunity to thank all the panelists for their valuable insights and briefly state the position of the European Union and its member states on these matters. There seems to be broad agreement that new technologies present significant opportunities to strengthen our collective responses in crime prevention and criminal justice. And when used responsibly, they can enhance efficiency, accessibility, and transparency of criminal justice systems. They can support secure cross-border cooperation and improve access to justice for citizens. They can help law enforcement and justice practitioners process large volumes of data more efficiently. They can identify links between data sets, support real-time analysis, improve the handling of evidence, and streamline information exchange. And they can also make information and services more accessible, including by facilitating reporting and whistleblowing. At the same time, digital technologies also create significant risks. And as the panelists have well explained, criminal networks and other malicious actors are often quick to leverage technology, including in the areas of cybercrime, fraud, exploitation, and other forms of organized crime. The use of such technologies in criminal justice requires us to mitigate a number of risks, and these include unlawful surveillance and data access, bias, lack of transparency, difficulties in challenging evidence effectively, risks to equality of arms and fair trial rights. Digitalization may also generate challenges for upholding victims' rights in the context of cross-border and large-scale digital offenses. and they may deepen inequalities in access to justice for those who lack the skills or resources to navigate digital tools. For the EU, it is essential to harness the opportunities that modern technology offers. And let me give you just one example. In recent years, we have invested heavily in digitalising cross-border judicial communication and expanding the use of video conferencing. The next major task is to harness the potential of AI in practice, in accordance with the framework established by the EU AI Act, while effectively preventing the risks and manage the challenges that this brings. In criminal justice, its use must be responsible and firmly anchored in human rights, the rule of law, due process, necessity, proportionality, accountability, transparency, and meaningful human oversight. Technology must serve people and their legitimate interests, not the other way around. Digital tools should support, not displace, the human role in criminal justice and must be an asset in upholding the rights of victims, should not be an additional source of victimization. Their deployment must therefore be accompanied by appropriate safeguards, capacity building and training for professionals. Chair, only a balanced approach that combines innovation with robust legal and ethical safeguards will allow justice systems to harness the benefits of technology while protecting human dignity and equal access to justice. The EU, including its agencies, bodies and networks, remain committed to strengthen multilateral cooperation, technical assistance and inclusive dialogue, including with the private sector and with civil society, to advance responsible rights-based and effective digital transformation in crime prevention and criminal justice. Thank you, Mr. Chair, and thank you again to all the panelists.
I thank the European Union for that all-encompassing statement. And now I give the floor to India, and we will finish the interventions from the audience with the delegation from the United States. So India, you have the floor.
Thank you so much, Mr. Chair, for the opportunity, and special thanks to the esteemed panelists for the wonderful presentations. I have a couple of small observations, Chair. With your permission, I would request a response from the esteemed panelists. Chair, we often talk about the need for meaningful human oversight and transparency while using artificial intelligence in criminal justice. Let us say a private company's facial recognition system compares a suspect's face with CCTV footage and reports a 99% match. The investigator may naturally rely on such a strong result without fully understanding the algorithm. Later, If the accused challenges the evidence in the court of law, the company might refuse to disclose as to how the algorithm works on grounds of the so-called commercial confidentiality. In such situation, how can we, number one, ensure a meaningful human oversight on part of the investigator, and number two, protect the accused person's right to effectively challenge the evidence? Chair, Another issue is with regard to the cross-border electronic evidence. For instance, an investigation is happening in one country, but the crucial data is held by a company in another country. How can investigators obtain it quickly while ensuring its admissibility in the court of law? Is there a practical model available as we speak here? Thank you so much, Chair.
Thank you very much. I think that the point you made on technology as a black box was dealt with by Ms. O'Brien in her presentation originally. And also this last part on an offense done through technology or electronically, but across borders, I think that was also, um, dealt by the…