> Who determines which problems are valid? Unless I overlooked something, this article seems really vague.
We're still early doors on this, but presumably the legislation when it's written will have more details.
But based on how most other regulation in the EU is handled, and thinking of how these questions are handled in the banking industry, I assume the company gets to decide. But the company will be expect to demonstrate to regulators that their content guidelines are:
1. A a minimum restrict illegal content, already defined in law
2. Don't discriminate against protected classes
3. Are fair, along with an explanation of why they're fair
4. There are policies and procedures that ensure they're applied fairly (again with explanation of why it's fair), and there's evidence they're actually being followed.
I expect that there will be significant latitude for regulators to decide what level of evidence is required, and how you demonstrate fairness. After all no one really know how to do this, so it doesn't make sense to write prescriptive detailed laws which are guaranteed to wrong. The different regulators will end up converging on a common understanding, if the don't, then expect the EU to setup a super regulator or similar to force greater convergence.
As for the standard argument of "oh but then how am I meant to know what to do" etc
1. Regulators will publish guidelines
2. Regulators will work with companies to make sure everyone agrees nothing draconian is happening, and equally make sure companies don't get off scot free.
3. Regulators won't punish companies that are clearly making a best effort attempt to follow the spirit of the law.
4. The EU has plenty of expertise doing this, look at financial regulation, GDPR etc No one who's actually had to follow tricky EU regulation before is worrying about this, unless it looks like the regulation basically outlaws their business.
> Hopefully this authentication mechanism can be inexpensive such that it doesn't disenfranchise too much legitimate business at the small end of the spectrum;
You'll be glad to hear it basically already exists in the EU. Open banking will make this process so much easier. Amazon will be able to lean on banks to handle some of this process, rather than building from scratch, with Open banking providing unified APIs to connect to almost any bank in the EU. And talking as someone whos help build bank grade Know Your Customer and Know Your Business processes and systems, it's much easier than you think (not easy, but Amazon won't struggle). Not to mention there's a flourishing industry of tech companies already solving these problems for FinTechs.
> I'm really wary of "disinformation that could sway elections" and "unjustified targeting of minority groups"; how do you litigate these fairly? One person's "racial advocacy" is another person's "racial patronization". These seem super subjective and thus ripe for abuse. Hopefully this too is just a case of poor journalism and the legislation is better.
As with the "trusted flaggers" above, I expect there to be quite a lot of latitude for regulators to decide. With your specific example, entities like the European Court of Human Rights will be the ultimate backstop for preventing abuse. It may take 5-10 years for all the court cases to be raised and litigated to that level, but it'll happen. The EU has good track record of balancing these concerns, and providing the legal infrastructure to allow these thing to be litigated. No doubt it'll figure it out, just like its done plenty of times before.