Steering Innovation for Autonomous Vehicles Towards Societally Beneficial Outcomes
Summary
Vehicle automation, coupled with simultaneous mobility revolutions of vehicle electrification and ridesharing, is set to have major impacts on society—perhaps the biggest impacts of any development in transportation since the introduction of cars over 100 years ago. But whether those impacts will be positive or not is still unknown. For example, widespread deployment of AVs could slash U.S. energy consumption by as much as 40% due to improved driving efficiency; alternatively, it could double U.S. energy consumption due to increased availability of cheap transport options. Similar uncertainty surrounds the potential impacts of AVs on physical safety, transportation access for disabled communities, overall traffic efficiency, and long-term greenhouse-gas emissions. Guiding the evolution of AVs towards the future we want requires evaluating AVs using metrics that prioritize societally beneficial outcomes. The Biden-Harris administration should create an Evaluation Innovation Engine at the Department of Transportation (DOT) to propose, refine, and standardize public-interest metrics for AVs.
The Evaluation Innovation Engine (EIE) would do for AV metrics what the Defense Advanced Research Projects Agency (DARPA) Grand Challenge did for AV development: ignite productive competition among companies to achieve state-of-the-art performance. The EIE should have two main tasks (1) convening stakeholders to discuss potential metrics and providing opportunities for public comment on how proposed metrics should be prioritized, and (2) administering annual funding rounds of ~$72 million each for private firms and other entities to create, test, and optimize algorithms for publicly beneficial AV outcomes. The EIE should be overseen by the Secretary of Transportation and staffed by representatives from pertinent DOT offices (Office of Civil Rights, Office of Small and Disadvantaged Business Utilization, Office of Public Affairs) and administrations (National Highway Traffic Safety Administration (NHTSA), Federal Highway Administration (FHWA), Federal Motor Carrier Safety Administration (FMCSA), Federal Transit Administration (FTA)), as well as a broad coalition of civil-society advocates.
Integrating Automated Vehicles with 5G Networks to Realize the Future of Transportation
Summary
Widespread deployment of fully automated or “autonomous” vehicles (AVs) that can operate without human interaction would make travel easier, cheaper, and safer. Reaching this highest level of automation requires AVs to be connected to 5G networks, which in turn allows AVs to communicate with “smart”, 5G-connected roadway infrastructure. The federal government can support progress towards this goal through a three-part initiative. Part 1 would establish Transportation Infrastructure Pilot Zones to field-test the integration of AV technology with 5G networks in settings across the country. Part 2 would create a National Connected AV Research Consortium to pursue connected-vehicle research achieving massive scale. Part 3 would launch a targeted research initiative focused on ensuring safety in a connected AV era, and Part 4 would create a new U.S. Corps of Engineers and Computer Scientists for Technology to embed technically skilled experts into government. With primary support from the National Highway and Traffic Safety Administration (NHTSA), the National Science Foundation (NSF), and the Department of Defense (DOD), this initiative would also help develop a basic framework for achieving a 90% reduction in vehicle crashes nationwide, deliver new transportation services, and establish national standards for AV technology. Initiative outcomes would promote U.S. global leadership in AVs, create new jobs and economic opportunities, and prepare the U.S. workforce to integrate technology of the future into systems of the present.
Mitigating Doxing Risks: Strategies to Prevent Online Threats from Translating to Offline Harms
Summary
The Biden-Harris Administration should act to address and minimize the risks of malicious doxing, given the rising frequency of online harassment inciting offline harms. This proposal recommends four parallel and mutually reinforcing strategies that can improve protections, enforcement, governance, and awareness around the issue.
The growing use of smartphones, social media, and other channels for finding and sharing information about people have made doxing increasingly widespread and dangerous in recent years. A 2020 survey by the Anti-Defamation League found that 44% of Americans reported experiencing online harassment. 28% of Americans reported experiencing severe online harassment, which includes doxing as well as sexual harassment, stalking, physical threats, swatting, and sustained harassment. In addition, a series of disturbing events in 2020 suggest that some instances of coordinated doxing efforts have reached a level of sophistication that poses a serious threat to U.S. national security. The pronounced spike in doxing cases against election officials, federal judges, and local government officials should serve as evidence for the severity and urgency of this issue. Meanwhile, private citizens have faced elevated doxing risks as disruptions from the COVID-19 pandemic and tensions around contentious sociopolitical issues have provoked cycles of online harassment.
While several states have proposed anti-doxing bills over the past year, most states do not offer adequate protections for doxing victims or mechanisms to hold perpetrators accountable. The doxing regulations that do exist are inconsistent across state lines, and partially applicable federal laws—such as the Interstate Communications Statute and the Interstate Stalking Statute—neither fully address the doxing problem nor are sufficiently enforced. New federal legislation is a crucial step for ensuring that doxing risks and harms are appropriately addressed, and must come with complementary governance structures and enforcement capabilities in order to be effective.
Prioritize Funding for High-Speed Internet Connectivity that Rural Communities Can Afford to Adopt
Summary
Access to high-speed internet is essential for all Americans to participate in society and the economy. The American Jobs Plan (AJP) proposal to build high-speed broadband infrastructure to achieve 100% high-speed internet coverage is critical for reaching unserved and underserved communities. Yet widespread access to high-speed broadband infrastructure is insufficient. Widespread adoption is required for individuals and communities to realize the benefits of being online. Federal programs that have recently funded new broadband infrastructure—namely the Federal Communications Commission (FCC) Connecting America Fund Phase II (CAF II) and Rural Digital Opportunity Fund (RDOF) reverse auctions—have not adequately tied the input of broadband infrastructure funding to the desired outcome of broadband adoption. Consequently, funding has gone to internet service providers (ISPs) that offer expensive internet service that communities are unlikely to adopt. To use the AJP’s broadband infrastructure funds most effectively, the Biden-Harris Administration should prioritize affordability in funding allocation and ensure that all recipients of federal subsidies, grants, or loans meet requirements for affordable service. Doing so will support widespread internet adoption and contribute to the AJP’s stated aims of reducing the price of internet service, holding ISPs accountable, and saving taxpayers money.
Creating a National Infrastructure for Digital Mental Health Services
Summary
The COVID-19 pandemic is exacerbating an existing mental health crisis to such a degree that many fear it will overwhelm the fragmented mental health delivery system in the United States. Rates of mental health problems—including depression, trauma- and stressor-related disorders, substance abuse, suicidal ideation, and suicide attempts—have increased during the COVID-19 pandemic. Scarce access to mental health services compounds the problem. Nearly 25 million Americans with mental health needs go untreated each year, and half of U.S. counties have no access to mental health care whatsoever. However, the current moment presents an opportunity. Even as the pandemic increased needs for mental health services, so too did pandemic-related shifts reveal the broad utility of and interest in digital solutions such as mobile apps, digital therapeutics, and digital therapy.
In the absence of regulation, however, ineffective and potentially harmful digital mental health products may make their way into consumer hands. Estimates suggest that over 20,000 digital mental health products exist, yet only five have received Food and Drug Administration (FDA) clearance. The FDA temporarily reduced their enforcement and review of these products due to COVID-19. But moving forward, addressing the largely unregulated space of digital mental health products is critical to mitigate harm of unverified digital mental health solutions. As examples of potential harms, companies have used digital products to offer services but from unlicensed providers, withheld client information from providers, or made data available to various third parties without following stated terms of services. Developing an infrastructure to regulate these products while also helping provide and reimburse effective and safe digital mental health solutions is essential to meet the overwhelming need for mental health services and ensure quality and equity in mental health care.
Federal Accessibility Standards for Fully Autonomous Vehicles
Summary
Self-driving technology is uniquely positioned to benefit people who cannot drive, including people with travel-limiting disabilities and many older adults. However, the lack of federal policy guiding the development of this technology has led to piecemeal recommendations that largely fail to guarantee accessible use in both public and private implementation scenarios. To leverage the full potential of self-driving technology, the Department of Transportation (DOT) should adopt accessibility standards to support autonomous transportation for people with disabilities and older adults. The Biden-Harris Administration has an important opportunity to reimagine accessible transit, capitalize on ongoing federal research programs such as the Inclusive Design Challenge, and extend the benefits of self-driving technology to those who need it most. If enacted, these recommendations will lead to increased independence, workforce participation, and mobility in the future of transportation.
Mitigating and Preventing the Existing Harms of Digital Surveillance Technology
Summary
The rapid adoption of Digital Surveillance Technology (DST) by state and local agencies is taking place in an under-regulated environment that is causing tangible harm to the communities and individuals these same agencies are tasked to protect. DST itself is plagued by fundamental flaws and vulnerabilities, issues compounded by a lack of safeguards in the environments where DST is deployed. The four biggest problems with government use of DST today are:
- Governments falling prey to predatory or negligently marketed DST that fails to consistently achieve stated functionalities or meet reasonable standards.
- Governments deploying DST in a way that does or could falsely implicate innocent individuals in criminal matters.
- A lack of systematic oversight that fails to ensure accountability, equity, transparency, or cybersecurity.
- Governments utilizing DST in a manner inconsistent with existing laws, ordinances, and regulations.
While these issues affect everyone, they disproportionately affect those who are falsely implicated in criminal matters as a result of DST, as well as the working poor (who have been historically over-surveilled). In addition to such human costs, overuse or misuse of DST exposes cash-strapped jurisdictions to multimillion-dollar lawsuits for violation of privacy and civil rights.
This proposal offers a set of actions that the Biden-Harris Administration could take to limit the harms of DST. Specifically, we recommend that the administration:
- Issue an Executive Order to create two mandatory filings for vendors and government agencies involved in active federal contracts for DST.
- Empower and fund the Federal Trade Commission (FTC) with $10 million over two years to study and produce rules regarding DST marketing and sales.
- Allocate $50 million for a Privacy Pilot Program that would allow municipalities to utilize a tailored hybrid model of government and civilian oversight for DST.
- Condition federal dollars spent on DST for law enforcement on compliance with a set of assessments.
- Instruct the Department of Justice to create a DST Task Force to study the benefits and tradeoffs of different types of DST.
These actions would together begin to rein in the unchecked power of the surveillance complex that has attached itself to our nation’s law-enforcement systems. Doing so would advance racial and community equity across the United States while also helping restore public trust in law-enforcement institutions.
Section 230 Is Essential to the Internet’s Future
Summary
Section 230 is not a gift to Big Tech, and eliminating it will not solve the problems that Big Tech is causing. Those problems stem from a severe lack of competition. Repealing Section 230 will exacerbate those problems.
Section 230 is critical to the proper functioning of the Internet. To rein in Big Tech, the law should be supported, not weakened or repealed. The Trump Administration’s executive order on Section 230 should be repealed. Further, action to limit the power of large tech companies should be taken on three fronts: antitrust, privacy, and interoperability.
A Strategy to Blend Domestic and Foreign Policy on Responsible Digital Surveillance Reform
Summary
Modern data surveillance has been used to systematically silence free expression, destroy political dissidents, and track ethnic minorities before placement in concentration camps. China’s surveillance-export system is providing a model of authoritarian stability and security to the 80+ countries using its technology, a number that will grow in the aftermath of COVID-19 as the technology spreads to the half of the world still to come online. This technology is shifting the balance of power between democratic and autocratic governance. Meanwhile, the purported US model is un-democratic at best: a Wild West absent of accountability and full of black box, NDA-protected public-private partnerships between law enforcement and surveillance companies. Our system continues to oppress marginalized communities in the US, muddying our moral claims abroad with hypocrisy. Surveillance undermines the privacy of everyone, but not equally. Most citizens remain unaware of, unaffected by, or disinterested in the daily violence propagated by the unregulated acquisition and use of surveillance. The lack of coordination between state and local agencies and the federal government around surveillance has created a deeply unregulated surveillance-tech environment and a discordant international agenda. Digital surveillance policy reform must coordinate both domestic and foreign imperatives. At home, it must be oriented toward solving a racial equity issue which produces daily harm. Abroad, it must be motivated by preserving 21st century democracy and human rights.
Digitizing State Courts
To overcome the unprecedented backlog of court cases created by the pandemic, courts must be reimagined. Rather than strictly brick-and-mortar operations, court must consider themselves digital platforms. To accomplish this, the U.S. Department of Justice (DOJ) – with support from 18F, U.S. Digital Service, the Legal Services Corporation, and the State Justice Institute – must build and fund professional and technical capacity at the state level to develop and adopt standardized digital infrastructure for courts and other justice agencies. Due to the replicable nature of this solution across states, the federal government is perfectly positioned to lead this effort, which will be more cost effective than if each court system attempted this work on their own. The estimated cost is $1 billion.
This once-in-a-generation investment will allow courts to collect granular, raw data, which can help overcome the current backlog, increase access to the justice system, inform policies that drive down mass incarceration, improve transparency, and seed a public and private revolution in justice technology that improves access to justice for all Americans.
Challenge and Opportunity
The COVID-19 pandemic brought physical shutdowns to American courts and an unprecedented backlog of cases. In Connecticut, pending civil and criminal cases jumped 200 percent, and many trials are not scheduled to start until 2021. As of June, New York City had 39,200 criminal cases in backlog. Meanwhile, San Diego, California has 20,000 criminal cases waiting to be heard. These are just a small sample of a widespread national trend.
In an attempt to manage this moment, courts rapidly moved online and opened Slack channels and Zoom accounts. Quick action like this should be applauded. However, these solutions are undercut by the justice system’s long-term lack of investment in digital infrastructure.
Across the country, courts fail at data collection, publication, and use. States like California, Colorado, and Florida passed laws in recent years to collect more data created by the justice system, but they are in the minority. Many states still operate on paper and have little-to-no digital data. In Massachusetts, a state that spent over $75 million to digitize court infrastructure, courts still don’t electronically track judges’ decisions, bail rates, or even a party’s gender. Nationally, a 2015 study found that 26 state court systems could not provide “an accurate report on how many cases were filed and disposed in any given year” — the most basic of court data. Meanwhile, public trust in the courts recently fell by double digits and the U.S. ranks 36th globally on access to civil justice— behind Rwanda and on par with Kazakhstan.
This lack of reusable data puts a ceiling on our understanding of individual courts and what courts can do with technology. Without data, software solutions like those that help analyze a court’s caseload, automate court processes, or provide assistance to people representing themselves without an attorney, are out of reach. While the relationship between data and improved court understanding and efficiency has been well-known for at least 30 years, the existing failures of the justice system compounded by the pandemic demand sweeping action.
Plan of Action
To fix this systemic problem at its foundation, the DOJ should support state courts in the adoption of open data standards, modern data collection methods, and application programming interfaces (APIs). Collectively, this is the digital infrastructure needed to help courts manage the tens of thousands of cases that have piled up, become more efficient, and increase access to justice.
This approach is different from how justice system actors currently conceptualize managing information. Currently, agencies generally think about data only in its finished form: a court order, a pamphlet, or a website. Thinking as a digital platform requires justice system leaders to consider data not only in its end form, but as raw data that is accurate, publicly available, secure, and reusable.
To make this a reality, the reconstituted Office of Access to Justice in the DOJ, with support from 18F, U.S. Digital Service, the Legal Services Corp., and the State Justice Institute, needs to offer grant and technical support so local court systems can digitize court data and services. To do this, three layers must be created: information, platform, and presentation. This proposal supports the creation of the first two layers, setting the foundation for the development of the third.
The information layer encompasses all of a justice system’s structured and unstructured data, including case filing and case outcome data. Creating this layer means collecting and cleaning the standardized data that exists across court systems, but also turning unstructured data – like court rules and orders that are usually housed in PDFs or on paper – into structured data. Creating this layer is time-consuming and painstaking, but the process is replicable across jurisdictions, which is why funding and technical support from the federal government is important and more cost effective than relying on each state to recreate this process. The National Center for State Courts published open data standards for courts in 2019. By using these standards across the country, court-to-court and state-to-state comparisons become possible, which can better inform local need and complementary federal support.
The platform layer gives the data utility. This includes the adoption of data management processes and software and APIs. This creates a multitude of benefits. Most significantly, it allows courts to quantify and manage the case backlog by giving them ready access to usable information about what types of cases are pending, for how long, and why. Having readily useable data will also increase transparency by allowing administrators, policymakers, and researchers to dig into how courts function.
Publicly available, structured data also lowers the barrier to entry for entrepreneurs and researchers building solutions to mass incarceration and the access-to-justice gap, thus creating the presentation layer. We’ve already seen this in other markets: data from weather.gov informs weather forecasts on our devices and local government transit data populates real-time information on map applications. For courts, this layer may include a court data portal where the public can see, in real time, what’s happening at the court. The presentation layer could come in the form of a text message reminder system that helps people appear for their court date, which would decrease bench warrants and pre-trial detention. This data will also assist the adoption of online dispute resolution software, which allows courts to quickly resolve high-volume, low-stakes cases without requiring in-court hearings, saving time, money, and trouble.
Conclusion
By focusing on data infrastructure, localities will have the information to uncover and tackle the most pressing issues that they face. However, if the justice system continues on its current path, fewer people will have access to the courts, people will continue to languish in prison, and faith in the justice system will continue to erode.
Compliance as Code and Improving the ATO Process
A wide-scale cyber-attack in 2020 impacted a staggering number of federal agencies, including the agency that oversees the United States nuclear weapons arsenal. Government officials are still determining what information the hackers may have accessed, and what they might do with it.
The fundamental failure of federal technology security is the costly expenditure of time and resources on processes that do not make our systems more secure. Our muddled compliance activities allow insecure legacy systems to operate longer, increasing the risk of cyber intrusions and other system meltdowns. The vulnerabilities introduced by these lengthy processes have grave consequences for the nation at large.
In federal technology, the approval to launch a new Information Technology (IT) system is known as an Authority to Operate (ATO). In its current state, the process of obtaining an ATO is resource-intensive, time-consuming, and highly cumbersome. The Administration should kick-start a series of immediate, action-oriented initiatives to incentivize and operationalize the automation of ATO processes (also known as “compliance as code”) and position agencies to modernize technology risk management as a whole.
Challenge and Opportunity
While the compliance methodologies that currently comprise the ATO process contribute to managing security and risk, the process itself causes delays to the release of new systems. This perpetuates risk by extending the use of legacy—but often less secure—systems and mires agencies with outdated, inefficient workflows.
To receive an ATO, government product owners across different agencies are required to demonstrate compliance with similar standards and controls, but the process of providing statements of compliance or “System Security Plans” (SSPs) is redundant and siloed. In addition, SSPs are often hundreds of pages long and oriented toward one-time generation of compliance paperwork over an outdated, three-year life cycle. There are few examples of IT system reciprocity or authorization partnerships between federal agencies, and many are reluctant to share their SSPs with sister organizations that are pushing similar or even identical IT systems through their respective ATO processes. This siloed approach results in duplicative assessments and redundancies that further delay progress.
The next administration should shift from static compliance to agile security risk management that meets the challenges of the ever-changing threat landscape. The following Plan of Action advances that goal through specific directives for the Office of Management and Budget (OMB) Office of the Federal CIO (OFCIO), General Services Administration (GSA), Technology Transformation Service (TTS), and other agencies.
Plan of Action
The Office of Federal Chief Information Officer (OFCIO) should serve as the catalyst of several of activities aimed at addressing inefficiencies in the ATO attainment process.
OFCIO should draft an OMB Compliance as Code Memorandum that initiates two major activities.
First, the Memorandum will direct GSA to create a Center of Excellence within the Technology Transformation Service (TTS). The goals and actions of the Center of Excellence are detailed under “Action Two” below. Second, the Memorandum should require Cabinet-level agencies to draft brief “exploration and implementation plans” that describe how the agency or agencies might explore and adopt compliance as code to create efficiencies and reduce burden.1
OFCIO should offer guidance for the types of explorations that agencies might consider. These might include:
- The integration of development, security and operations (DevSecOps)2 in major systems to allow for the automated validation of security controls.
- The identification of a pilot system or application within each agency that can be leveraged for the conversion of SSPs into a machine-readable format that allows for experimentation with compliance automation.
- The appointment of a single, accountable leader within each agency to guide and oversee compliance as code explorations as well as provide regular reporting to agency Chief Information Officers.
During the plan review process, the OFCIO should collaborate with the Resource Management Offices (RMOs) at OMB to identify agencies that offer the most effective plans and innovations.3 Finally, OFCIO should consider releasing a portion of the agency plans publicly with the goal of spurring research and collaboration with industry.
The General Services Administration should create a Cybersecurity Compliance Center of Excellence.
OMB should commission the creation of a Cybersecurity Compliance Center of Excellence at the General Services Administration (GSA). Joining the six other Centers of Excellence, the Cybersecurity Compliance Center of Excellence (CCCE) would serve to accelerate the adoption of compliance as code solutions, analyze current compliance processes and artifacts, and facilitate cross-agency knowledge-sharing of cybersecurity compliance best practices. In addition, OMB should direct GSA to establish a Steering Committee representative of the Federal Government that leverages the expertise of agency Chief Information Security Officers (CISOs), Deputy CISOs, and Chief Data Officers (CDOs) as well as representatives from the National Institute of Standards and Technology (NIST) and the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA).
The CCCE Steering Committee will research potential paths to propagate compliance as code that are not overly burdensome to agencies, deliberate on these initiatives, and guide and oversee agency innovations. The ultimate goal for the Steering Committee will be to devise a strategy and series of practices to increase compliance as code adoption via the Cybersecurity Compliance Center of Excellence and OMB oversight.
The following sections detail potential opportunities for CCCE Steering Committee investigation and evaluation:
Study IT System Acquisition Rules for Vendor Compliance Information. The Steering Committee should review existing acquisition guidance and consider drafting a new acquisition rule that would require software vendors to provide ATO-relevant, machine-readable compliance information to customer agencies. The data package could include control implementation statements, attestation data and evidence guidance for the relevant NIST controls.4 In addition, the new system and process improvements should be agile enough to allow the incorporation of controls unique to a particular application or service.
Shifting the responsibility of managing compliance information from agencies to vendors
saves time and taxpayer dollars spent in the duplicative discovery, creation, and maintenance
of control implementation guidance for common software. The rule would be doubly
effective in time saved if the vendor’s compliance data package has common reciprocity
between agencies, allowing for faster adoption of software government wide.5 Finally, the
format of the data package should be open sourced, fungible and accessible.
Examine and Improve the Utility of System Security Plans (SSPs). System Security Plans are the baseline validator of a system’s security compliance and a comprehensive summary of an IT system’s security details.6 OMB and the CCCE Steering Committee should direct agencies to investigate the reusability and transmutability of System Security Plans (SSPs) across the Federal Government. A research-focused task force, composed of federal data scientists, compliance subject matter experts, auditors, and CISOs, should research how SSPs are utilized and draft recommendations on how best to improve their utility. The research task force would collect a percentage of agency SSPs, compare time-to-ATOs for various government organizations, and develop a common taxonomy that will allow for reciprocity between government agencies.
Create a Federal Compliance Library. The Steering Committee should investigate the creation of an inter-agency Federal Compliance Library. The library, most likely hosted by NIST, would support cross-agency compliance efforts by offering vetted pre-sets, templates, and baselines for various IT systems. A Federal Compliance Library accelerates the creation and sharing of compliance documentation and allows for historical knowledge and best practices to have impact beyond one agency. These common resources would free up agency compliance resources to focus on authorization materials that require novel documentation.
Explore Open Security Controls Assessment Language (OSCAL). The Steering Committee should explore the value added by mandating the conversion of agency SSP components to machine readable code such as Open Security Controls Assessment Language (OSCAL).7 OSCAL allows for the automated monitoring of control implementation effectiveness while making documentation updates easier and more efficient.
Conclusion
Federal compliance processes are ripe for innovation. The current system is costly and perpetuates risk while trying to control for it. The Plan of Action detailed above creates a crossagency collaborative environment that will spur localized innovations which can be tested and perfected before scaling government wide.
Eliminating Cookie Click-Thrus: A Strategy for Enhancing Digital Privacy
Summary
Everyone hates cookie notifications, click-thrus, and pop-ups. While cookies give the web more functionality, their excessive use and attendant consent system can interfere with user experience and raises serious privacy concerns. The next administration should commit to finally resolving these and related issues by creating a digital privacy task force within the White House Office of Science and Technology Policy (OSTP). The task force would coordinate relevant agencies—including the Federal Trade Commission, Federal Communications Commission, and Department of Commerce—in working with Congress, state actors, and European Union partners to develop meaningful data-privacy protections.