It is, without question.
I think two conditions are required.
The companies themselves have to be mandated to share a certain subset of information that they control and have access to. This has been done in some other jurisdictions, with varying degrees of success, and is one of the core requirements in the duty to act responsibly, which is the main provision of the online harms act. The way it's designed.... The language of the previous version of the bill is quite good and could be adapted to some of the AI issues I talked about.
Then you need institutions and the capacity to make sense of those data. This is not easy, and it requires collaboration among researchers around the country and a central data steward that is neither the companies nor the government. We do not currently have this infrastructure. It would need to be built if the online harms act were legislated in some version of its previous form—making this a requirement.
Those two things are the table stakes. Other countries saw this far earlier than we did.
