European Union flags flutter outside the EU Commission headquarters, in Brussels, Belgium, February 1, 2023
Yves Herman | Reuters
When Gerard de Graaf moved from Europe to San Francisco almost a year ago, his job had a very different feel to it.
De Graaf, a 30-year veteran of the European Commission, was tasked with resurrecting the EU office in the Bay Area. His title is senior envoy for digital to the U.S., and since September his main job has been to help the tech industry prepare for new legislation called The Digital Services Act (DSA), which goes into effect Friday.
At the time of his arrival, the metaverse trumped artificial intelligence as the talk of the town, tech giants and emerging startups were cutting thousands of jobs, and the Nasdaq was headed for its worst year since the financial crisis in 2008.
Within de Graaf’s purview, companies including Meta, Google, Apple and Amazon have had since April to get ready for the DSA, which takes inspiration from banking regulations. They face fines of as much as 6% of annual revenue if they fail to comply with the act, which was introduced in 2020 by the EC (the executive arm of the EU) to reduce the spread of illegal content online and provide more accountability.
Coming in as an envoy, de Graaf has seen more action than he expected. In March, there was the sudden implosion of the iconic Silicon Valley Bank, the second-largest bank failure in U.S. history. At the same time, OpenAI’s ChatGPT service, launched late last year, was setting off an arms race in generative AI, with tech money pouring into new chatbots and the large language models (LLMs) powering them.
It was a “strange year in many, many ways,” de Graaf said, from his office, which is co-located with the Irish Consulate on the 23rd floor of a building in downtown San Francisco. The European Union hasn’t had a formal presence in Silicon Valley since the 1990s.
De Graaf spent much of his time meeting with top executives, policy teams and technologists at the major tech companies to discuss regulations, the impact of generative AI and competition. Although regulations are enforced by the EC in Brussels, the new outpost has been a useful way to foster a better relationship between the U.S. tech sector and the EU, de Graaf said.
“I think there’s been a conversation that we needed to have that did not really take place,” said de Graaf. With a hint of sarcasm, de Graaf said that somebody with “infinite wisdom” decided the EU should step back from the region during the internet boom, right “when Silicon Valley was taking off and going from strength to strength.”
The thinking at the time within the tech industry, he said, was that the internet is a “different technology that moves very fast” and that “policymakers don’t understand it and can’t regulate it.”
Facebook Chairman and CEO Mark Zuckerberg arrives to testify before the House Financial Services Committee on “An Examination of Facebook and Its Impact on the Financial Services and Housing Sectors” in the Rayburn House Office Building in Washington, DC on October 23, 2019.
Mandel Ngan | AFP | Getty Images
However, some major leaders in tech have shown signs that they’re taking the DSA seriously, de Graaf said. He noted that Meta CEO Mark Zuckerberg met with Thierry Breton, the EU commissioner for internal market, to go over some of the specifics of the rules, and that X owner Elon Musk has publicly supported the DSA after meeting with Breton.
De Graaf said he’s seeing “a bit more respect and understanding for the European Union’s position, and I think that has accelerated after generative AI.”
‘Serious commitment’
X, formerly known as Twitter, had withdrawn from the EU’s voluntary guidelines for countering disinformation. There was no penalty for not participating, but X must now comply with the DSA, and Breton said after his meeting with Musk that “fighting disinformation will be a legal obligation.”
“I think, in general, we’ve seen a serious commitment of big companies also in Europe and around the world to be prepared and to prepare themselves,” de Graaf said.
The new rules require platforms with at least 45 million monthly active users in the EU to provide risk assessment and mitigation plans. They also must allow for certain researchers to have inspection access to their services for harms and provide more transparency to users about their recommendation systems, even allowing people to tweak their settings.
Timing could be a challenge. As part of their cost-cutting measures implemented early this year, many companies laid off members of their trust and safety teams.
“You ask yourself the question, will these companies still have the capacity to implement these new regulations?” de Graaf said. “We’ve been assured by many of them that in the process of layoffs, they have a renewed sense of trust and safety.”
The DSA doesn’t require that tech companies maintain a certain number of trust and safety workers, de Graaf said, just that they comply with the law. Still, he said one social media platform that he declined to name gave an answer “that was not entirely reassuring” when asked how it plans to monitor for disinformation in Poland during the upcoming October elections, as the company has only one person in the region.
That’s why the rules include transparency about what exactly the platforms are doing.
“There’s a lot we don’t know, like how these companies moderate content,” de Graaf said. “And not just their resources, but also how their decisions are made with which content will stay and which content is taken down.”
De Graaf, a Dutchman who’s married with two kids, has spent the past three decades going deep on regulatory issues for the EC. He previously worked on the Digital Services Act and Digital Markets Act, European legislation targeted at consumer protection and rights and enhancing competition.
This isn’t his first stint in the U.S. From 1997 to 2001, he worked in Washington, D.C., as “trade counsellor at the European Commission’s Delegation to the United States,” according to his bio.
For all the talk about San Francisco’s “doom loop,” de Graaf said he sees a different level of energy in the city as well as further south in Silicon Valley.
There’s still “so much dynamism” in San Francisco, he said, adding that it’s filled with “such interesting people and objective people that I find incredibly refreshing.”
“I meet very, very interesting people here in Silicon Valley and in San Francisco,” he said. “And it’s not just the companies that are kind of avant-garde as the people behind them, so the conversations you have here with people are really rewarding.”
The generative AI boom
Generative AI was a virtually foreign concept when de Graaf arrived in San Francisco last September. Now, it’s about the only topic of conversation at tech conferences and cocktail parties.
The rise and rapid spread of generative AI has led to a number of big tech companies and high-profile executives calling for regulations, citing the technology’s potential influence on society and the economy. In June, the European Parliament cleared a major step in passing the EU AI Act, which would represent the EU’s package of AI regulations. It’s still a long way from becoming law.
De Graaf noted the irony in the industry’s attitude. Tech companies that have for years criticized the EU for overly aggressive regulations are now asking, “Why is it taking you so long?” de Graaf said.
“We will hopefully have an agreement on the text by the end of this year,” he said. “And then we always have these transitional periods where the industry needs to prepare, and we need to prepare. That might be two years or a year and a half.”
The rapidly changing landscape of generative AI makes it tricky for the EU to quickly formulate regulations.
“Six months ago, I think our big concern was to legislate the handful of companies — the extremely powerful, resource rich companies — that are going to dominate,” de Graaf said.
But as more powerful LLMs become available for people to use for free, the technology is spreading, making regulation more challenging as it’s not just about dealing with a few big companies. De Graaf has been meeting with local universities like Stanford to learn about transparency into the LLMs, how researchers can access the technology and what kind of data companies could provide to lawmakers about their software.
One proposal being floated in Europe is the idea of publicly funded AI models, so control isn’t all in the hands of big U.S. companies.
“These are questions that policymakers in the U.S. and all around the world are asking themselves,” de Graaf said. “We don’t have a crystal ball where we can just predict everything that’s happening.”
Even if there are ways to expand how AI models are developed, there’s little doubt about where the money is flowing for processing power. Nvidia, which just reported blowout earnings for the latest quarter and has seen its stock price triple in value this year, is by far the leader in providing the kind of chips needed to power generative AI systems.
“That company, they have a unique value proposition,” de Graaf said. “It’s unique not because of scale or a network effect, but because their technology is so advanced that it has no competition.”
He said that his team meets “quite regularly” with Nvidia and its policy team and they’ve been learning “how the semiconductor market is evolving.”
“That’s a useful source information for us, and of course, where the technology is going,” de Graaf said. “They know where a lot of the industries are stepping up and are on the ball or are going to move more quickly than other industries.”
A YouTube tool that uses creators’ biometrics to help them remove AI-generated videos that exploit their likeness also allows Google to train its artificial intelligence models on that sensitive data, experts told CNBC.
In response to concern from intellectual property experts, YouTube told CNBC that Google has never used creators’ biometric data to train AI models and it is reviewing the language used in the tool’s sign-up form to avoid confusion. But YouTube told CNBC it will not be changing its underlying policy.
The discrepancy highlights a broader divide inside Alphabet, where Google is aggressively expanding its AI efforts while YouTube works to maintain trust with creators and rights holders who depend on the platform for their businesses.
YouTube is expanding its “likeness detection,” a tool the company introduced in October that flags when a creator’s face is used without their permission in deepfakes, the term used to describe fake videos created using AI. The feature is being expanded to millions of creators in the YouTube Partner Program as AI-manipulated content becomes more prevalent throughout social media.
The tool scans videos uploaded across YouTube to identify where a creator’s face may have been altered or generated by artificial intelligence. Creators can then decide whether to request the video’s removal, but to use the tool, YouTube requires that creators upload a government ID and a biometric video of their face. Biometrics are the measurement of physical characteristics to verify a person’s identity.
Experts say that by tying the tool to Google’s privacy policy, YouTube has left the door open for future misuse of creators’ biometrics. The policy states that public content, including biometric information, can be used “to help train Google’s AI models and build products and features.”
“Likeness detection is a completely optional feature, but does require a visual reference to work,” YouTube spokesperson Jack Malon said in a statement to CNBC. “Our approach to that data is not changing. As our Help Center has stated since the launch, the data provided for the likeness detection tool is only used for identity verification purposes and to power this specific safety feature.”
YouTube told CNBC it is “considering ways to make the in-product language clearer.” The company has not said what specific changes to the wording will be made or when they will take effect.
Experts remain cautious, saying they raised concerns about the policy to YouTube months ago.
“As Google races to compete in AI and training data becomes strategic gold, creators need to think carefully about whether they want their face controlled by a platform rather than owned by themselves,” said Dan Neely, CEO of Vermillio, which helps individuals protect their likeness from being misused and also facilitates secure licensing of authorized content. “Your likeness will be one of the most valuable assets in the AI era, and once you give that control away, you may never get it back.”
Vermillio and Loti are third-party companies working with creators, celebrities and media companies to monitor and enforce likeness rights across the internet. With advancements in AI video generation, their usefulness has ramped up for IP rights holders.
Loti CEO Luke Arrigoni said the risks of YouTube’s current biometric policy “are enormous.”
“Because the release currently allows someone to be able to attach that name to the actual biometrics of the face, they could create something more synthetic that looks like that person,” Arrigoni said.
Neely and Arrigoni both said they would not currently recommend that any of their clients sign up for likeness detection on YouTube.
YouTube’s head of creator product, Amjad Hanif, said YouTube built its likeness detection tool to operate “at the scale of YouTube,” where hundreds of hours of new footage are posted every minute. The tool is set to be made available to the more than 3 million creators in the YouTube Partner Program by the end of January, Hanif said.
“We do well when creators do well,” Hanif told CNBC. “We’re here as stewards and supporters of the creator ecosystem, and so we are investing in tools to support them on that journey.”
The rollout comes as AI-generated video tools rapidly improve in quality and accessibility, raising new concerns for creators whose likeness and voice are central to their business.
YouTuber Doctor Mike, whose real name is Mikhail Varshavski, makes videos reacting to TV medical dramas, answering questions on health fads and debunking myths that have flooded the internet for nearly a decade.
Doctor Mike
YouTube creator Mikhail Varshavski, a physician who goes by Doctor Mike on the video platform, said he uses the service’s likeness detection tool to review dozens of AI-manipulated videos a week.
Varshavski has been on YouTube for nearly a decade and has amassed more than 14 million subscribers on the platform. He makes videos reacting to TV medical dramas, answering questions on health fads and debunking myths. He relies on his credibility as a board-certified physician to inform his viewers.
Rapid advances in AI have made it easier for bad actors to copy his face and voice in deepfake videos that could give his viewers misleading medical advice, Varshavski said.
He first encountered a deepfake of himself on TikTok, where an AI-generated doppelgänger promoted a “miracle” supplement.
“It obviously freaked me out, because I’ve spent over a decade investing in garnering the audience’s trust and telling them the truth and helping them make good health-care decisions,” he said. “To see someone use my likeness in order to trick someone into buying something they don’t need or that can potentially hurt them, scared everything about me in that situation.”
AI video generation tools like Google’s Veo 3and OpenAI’s Sora have made it significantly easier to create deepfakes of celebrities and creators like Varshavski. That’s because their likeness is frequently featured in the datasets used by tech companies to train their AI models.
Veo 3 is trained on a subset of the more than 20 billion videos uploaded to YouTube, CNBC reported in July. That could include several hundred hours of video from Varshavski.
Deepfakes have “become more widespread and proliferative,” Varshavski said. “I’ve seen full-on channels created weaponizing these types of AI deep fakes, whether it was for tricking people to buy a product or strictly to bully someone.”
At the moment, creators have no way to monetize unauthorized use of their likeness, unlike the revenue-sharing options available through YouTube’s Content ID system for copyrighted material, which is typically used by companies that hold large copyright catalogs. YouTube’s Hanif said the company is exploring how a similar model could work for AI-generated likeness use in the future.
Earlier this year, YouTube gave creators the option to permit third-party AI companies to train on their videos. Hanif said that millions of creators have opted into that program, with no promise of compensation.
Hanif said his team is still working to improve the accuracy of the product but early testing has been successful, though he did not provide accuracy metrics.
As for takedown activity across the platform, Hanif said that remains low largely because many creators choose not to delete flagged videos.
“They’ll be happy to know that it’s there, but not really feel like it merits taking down,” Hanif said. “By and far the most common action is to say, ‘I’ve looked at it, but I’m OK with it.'”
Agents and rights advocates told CNBC that low takedown numbers are more likely due to confusion and lack of awareness rather than comfort with AI content.
MongoDB shares ripped more than 25% higher on Tuesday after the company blew past Wall Street’s third-quarter expectations and lifted its forecast as its cloud database platform gained traction with customers.
The database software provider posted adjusted earnings of $1.32 per share on $628 million in revenue. That topped the 80 cents adjusted per share and $592 million in revenue expected by analysts polled by LSEG. Revenues grew 19% from last year.
MongoDB said its Atlas platform grew 30% from a year ago and accounted for 75% of total revenues for the quarter. The company said it ended the period with more than 60,800 Atlas customers, with revenues expected to grow 27% for the platform in the current period.
“Q3 was an exceptional quarter that was driven by our continued go-to-market execution and the broad-based demand we are seeing across business,” said CEO Chirantan “CJ” Desai in his first earnings call at the helm of the company.
Dev Ittycheria, who ran the company for 11 years and took it public, stepped down in November.
Read more CNBC tech news
Desai believes the company is approaching a “once in a lifetime” opportunity as artificial intelligence, cloud and data trends reach a “true inflection point.” He told investors he plans to focus on building customer relationships and innovation in the coming months.
Citing those tailwinds, MongoDB boosted its guidance for the full year on Atlas growth and tailwinds from ongoing artificial intelligence demand. The company now anticipates revenues between $2.434 billion and $2.439 billion, up from prior guidance of $2.34 billion and $2.36 billion.
Analysts at Bernstein lifted their price target on shares to $452, expecting the stock to continue benefiting from accelerating growth as other software companies struggle.
“We expect strong consumption demand, potential upside from AI, and benefits from an easing interest rate environment to continue driving re-rating upside in the near term,” they wrote.
Ben Seri (CTO), Sanaz Yashar (CEO), Snir Havdala (CPO) of Zafran Security.
Courtesy: Eric Sultan | Zafran
Zafran Security, a cybersecurity startup created by an Iranian-born spy whose story helped inspire the hit Apple TV series “Tehran,” has raised $60 million, the company said Tuesday.
Sanaz Yashar, the former spy and CEO of Zafran, told CNBC that the funding round comes as a result of the accelerating speed and pace of cyberattacks due to the on-going AI boon. Zafran uses artificial intelligence and automation technology to manage threat exposure.
It’s “becoming much more severe that it was even a year ago,” she said in an exclusive interview.
The round brings Zafran’s total funding to $130 million since its founding in 2022. Zafran did not disclose the valuation at which it raised, but the startup said it has more than tripled annual recurring revenue since its last round for $70 million in September 2024. Annual recurring revenue is a term often used to measure income expected on a 12-month basis for a product.
The company plans to use the money to hire more people, Yashar said.
Menlo Ventures led the funding round, with participation from Sequoia Capital and Cyberstarts, which was an early investor in the startup Wiz that sold to Google for $32 billion in March.
Companies are looking for ways to reinvigorate their cybersecurity capabilities as AI reshapes the sophistication and capabilities of cyber criminals.
Yashar and co-founders Ben Seri and Snir Havdala created Zafran following an investigation into a ransomware attack on a hospital in Israel.
“The data was there,” Yashar told CNBC, adding that cohesive security tools might have prevented the attack. “If the security tools were talking to each other, they could block it.”
Yashar, who moved to Israel from Tehran at 17, served for 15 years in an elite cybersecurity intelligence unit within the Israel Defense Forces known as Unit 8200. She also led major investigations at threat detection firm FireEye and Mandiant, which Google bought in 2022.