Click by click
Regulatory shifts in online safety are moving beyond content takedowns and toward intentional platform design, according to experts at the Council on Tech and Social Cohesion’s 2026 Expo.
As digital technologies become increasingly embedded in social, economic, and political life, questions concerning the design and governance of online environments have assumed greater prominence within policy discourse.1 Researchers, regulators, and civil society organizations are taking closer examinations at whether the sociotechnical systems that structure online experiences adequately serve the public interest, or whether they require fundamental redesign.
“There’s many levers in the design of a technology that can incentivize, reward, or sanction behaviors,” said Lena Slachmuijlder, co-chair of the Council on Tech and Social Cohesion. “And that’s where we saw the gap.”

Our team attended the Council’s 2026 expo, “From Harm Mitigation to Intentional Design,” at the end of May, tuning into the Asia segment hosted from Bishkek, Kyrgyzstan.2 The discussion went beyond downstream responses of harmful content to the core incentives embedded into their hosted platform design, as well as the regulatory tools emerging globally to govern them.
The DSA and the move toward design accountability
For years, the most visible conversations in digital design have focused on the moderation of content that appears on user feeds. Which posts should be removed? Which accounts should be suspended? How should users be notified or allowed to appeal when platforms take enforcement action? But as policymakers and researchers look beyond individual incidents, they are progressively asking whether the systems beneath them deserve the same level of scrutiny.
A recurring theme throughout the session was the focus on the behavioral levers behind the most compelling platform design. Recommender systems shape what users see and which posts gain visibility, while interface choices can steer, delay, simplify, or complicate the decisions users make online. These levers include menu hierarchies, engagement metrics, push notifications, autoplay, infinite scroll, and other forms of digital choice architecture that can incentivize, reward, or discourage behavior.
Recommended systems: algorithmic systems that mediate information propagation on digital platforms by selecting, ranking, and prioritizing content for users (also referred to as “assemblages” by academics). Rather than merely displaying posts from accounts a user follows, they predict which content a user is likely to engage with and use those predictions to shape feeds.
“These are now peripheral features that we’re looking at,” said Niamh Hanafin, assistant director of Coimisiún na Meán, Ireland’s media regulator. “Looking at how platforms are designed and operated rather than this content model.”

The European Union’s Digital Services Act, or the DSA, is one of the EU’s most comprehensive and consequential regulatory frameworks for online platforms at this time.
The European Commission describes the DSA as a framework for regulating online services such as social media platforms, marketplaces, app stores, and travel platforms, with the goal of creating a safer digital space where fundamental rights are protected. The law also gives users greater transparency and control over their online experience, including the ability on very large platforms to choose non-personalized feeds, receive clearer information about advertising, and be protected from dark patterns.
Dark patterns: online interface designs that deceive, manipulate, or materially distort users’ ability to make free and informed decisions.
That framing treats platform architecture as a non-neutral risk environment. In the same way that vulnerable cybersecurity architecture can expose users to predictable forms of risk, poorly designed or inadequately governed social platform architecture can expose users (particularly children and vulnerable communities) to predictable forms of manipulation, escalation, compulsive engagement, harassment, and polarization.
“Regulation is a key incentive for companies to make choices, either to better enforce their own policies or to decide to explore other options,” Slachmuijlder said.
DSA is a complex legal document, and implementation has taken time to reach speed, according to Hanafin. But as of recently, there has been an increase in enforcement actions by digital services coordinators and the European Commission. Ireland’s media regulator was described as especially consequential because 16 of the 26 very large online platforms and search engines are headquartered in Ireland. As a result, enforcement by the Irish regulator can have implications across the European region, according to Hanafin.
Meta, dark patterns, and the right to choose
One of the clearest examples of design enforcement discussed during the session was Coimisiún na Meán’s decision to open two formal investigations into Meta’s Facebook and Instagram services. The investigations concern whether the platforms have complied with DSA requirements on recommender system transparency and online interface design.
The first issue concerns the user’s right to choose. Under the DSA, platforms that use recommender systems must explain the main parameters that determine why certain information is suggested to users and must provide users with ways to modify or influence those parameters. For very large online platforms and search engines, the law goes further; exceptionally large platforms must provide at least one recommender-system option that is not based on profiling (scroll down to Article 27). In practice, this means users should be able to access a version of a feed that is not ranked according to automated inferences about their personal data or predicted engagement.
The second issue concerns dark patterns. Online platforms may not design, organize, or operate their interfaces in ways that deceive or manipulate users, or otherwise materially distort or impair their ability to make free and informed decisions, according to Article 25. The DSA identifies examples such as giving more prominence to certain choices, repeatedly prompting users after a choice has already been made, or making it harder to terminate a service than to subscribe to it. In this context, dark patterns are interface arrangements that can undermine user autonomy by making some choices easier, more visible, or more persistent than others.
This distinction is interesting because it implies that digital rights are only meaningful if they can be exercised under realistic conditions. A non-profiling feed that exists but is difficult to find, confusing to activate, or easy to reverse through nudging does not provide the same level of control as one that is clearly presented and accessible from the point where recommendations are displayed. The DSA itself recognizes this problem by requiring that certain recommender system choices be directly accessible from the relevant online interface.
In this frame, the “peripheral” interface prompts and settings become matters of public accountability. They help determine whether users genuinely control their online experience or are steered toward choices that primarily benefit the platform’s data, advertising, or engagement model.
For Meta, the legal question remains unresolved while the investigations are ongoing.
TikTok and addictive design as systemic risk
The European Commission’s TikTok investigation moves platform regulation deeper into the mechanics of engagement. In February 2026, the Commission preliminarily found TikTok in breach of the Digital Services Act over what it described as addictive design. The features under scrutiny included infinite scroll, autoplay, push notifications, and TikTok’s highly personalized recommender system.
“We know how effective their recommender system is. It’s incredibly personalized, it’s extremely compelling,” Hanafin said. “This is what makes TikTok the system and the success that it is. It’s core to their business model.”
The Commission’s preliminary findings focused on whether TikTok had adequately assessed the risks that these design features could pose to users’ physical and mental well-being, particularly for minors and vulnerable adults. It also questioned whether TikTok’s existing safeguards, including screen time tools and parental controls, were sufficient to mitigate risks created by the platform’s design.
From a safety and security perspective, this question reframes engagement itself. Time spent on a platform is often treated as a measure of product success. Under a systemic risk approach, however, engagement can also become evidence of risk when it is produced through design choices that weaken user agency, encourage compulsive use, or make disengagement difficult.
“This [case] will potentially be setting some very important precedent,” Hanafin said.
That shift is particularly relevant within the backdrop of emerging technology. As AI-powered personalization becomes more powerful, the line between recommendation and manipulation may become harder for users to see. Regulators will need to understand how systems shape attention, agency, and behavior alongside the platforms’ output in order to proactively mitigate the risks tied to them.
The same design questions now apply to AI systems built for, used by, or likely to affect children. The 5Rights Foundation’s Children & AI Design Code argues that those who build and deploy AI systems should identify, evaluate, and mitigate known risks to children while also preparing for “known unknowns.” It calls for foreseeable risks to children to be considered “by design and default,” rather than addressed only after harms emerge.
“Children do not only need protection from spaces, but they also need better spaces that are designed with their rights and safety in mind,” said Head of International Affairs at 5Rights Marie-Eve Nadeau.
If recommender systems can amplify harmful dynamics, AI systems may personalize those dynamics further. If dark patterns can steer users through interface design, AI assistants and generative systems may steer users through more personal language, timing, and automated suggestions. If children are already navigating systems that adults struggle to understand, AI raises the stakes for transparency, testing, and accountability of design.
The insight from the DSA discussion is that regulators should ask design questions regarding optimization, reward behaviors, and foreseeable risks early. Who benefits when a user keeps scrolling, clicking, or staying on emerging networks?
Global regulation without overreach
Any serious discussion of online safety must also confront the risk of regulatory overreach.
In many parts of the world, civil society groups worry that online safety laws may become tools for censorship, surveillance, or political control when they are framed too broadly or enforced without adequate safeguards. A law written in the language of protection may empower governments to silence critics, suppress dissent, or expand state authority over speech.3
The session thus expanded Europe’s regulatory turn within a wider global movement toward both child safety and rights respecting design. Recent developments in Brazil and Indonesia suggest that governments outside Europe are beginning to impose clearer duties on digital platforms and services, especially where children are likely to be users, according to Nadeau.
Brazil’s Digital Statute for Children and Adolescents, known as the ECA Digital, establishes obligations for digital products and services accessed or likely to be accessed by minors, including duties related to inappropriate content and parental supervision. Indonesia’s Government Regulation No. 17 of 2025 similarly imposes child protection obligations on electronic system providers. Beyond Latin America and Asia, the African Union’s Child Online Safety and Empowerment Policy, adopted in 2024, signals a regional effort to frame children’s online safety as a topic of privacy, participation, and the best interests of the child.
In jurisdictions where legal overreach has greater opportunity to succeed, the session offered grounding corporate accountability in international human rights law and focus on system design rather than political content policing. That distinction begins by asking how platform architecture shapes amplification and user control rather than asking governments which political content should be removed (hence, the “harm mitigation” aspect of the expo).
To ask how platform systems make certain content viral, how recommender systems amplify harmful dynamics, how engagement incentives shape behavior, and how companies profit from risky architecture is not the same as monitoring content that compromises or benefits certain agenda off- and online.
Such an approach offers a more principled starting point for regulation, shifting attention away from individual viewpoints to the systems that structure how users interact and utilize the very platforms that are shaping lives.
“We can design technology differently to bring out the best of humans, to not exploit our vulnerabilities,” Slachmuijlder said.
If you are an industry professional who would like to contribute or be interviewed, feel free to message us below:
The OECD argues that digital transformation requires coordinated, overarching government policy responses across society, trust, markets, jobs, innovation, and access. UNESCO’s platform governance guidelines, in addition, outline multi-stakeholder duties and roles for states, intergovernmental organizations, civil society, media, academia, the technical community, and others, with freedom of expression and access to information at the center of governance processes.
The expo was co-hosted with Search for Common Ground Central Asia and the Alliance for Peacebuilding. Our team attended the event online.
International human rights law offers one way to draw the line between legitimate efforts to address online harms and regulatory measures that unduly restrict freedom of expression or expand state control over lawful speech. Under Article 19 of the ICCPR, restrictions on expression must be provided by law and necessary for a legitimate aim, such as protecting the rights of others, national security, or public order, health, and morals. The UN Human Rights Committee’s General Comment No. 34 further supports that restrictions must “not put in jeopardy the right itself.” These guidelines synthesize that online safety regulation should be lawful, necessary, proportionate, and subject to oversight.
