The European Commission is expanding Digital Services Act enforcement into the architecture of major social platforms. Its preliminary findings on TikTok, followed by a similar preliminary assessment involving Instagram and Facebook, put infinite scroll, autoplay, push notifications and personalised recommendation systems at the centre of a new compliance question: whether platforms have done enough to reduce risks of compulsive use, particularly for minors and vulnerable users.
The shift matters because it moves DSA scrutiny beyond harmful content, advertising transparency and moderation processes. Product design itself is becoming an enforcement concern. For developers, product leaders and enterprise governance teams, the emerging standard is clear: engagement features may need to be assessed not only for growth and usability, but also for whether their combined effects create risks that existing safeguards do not adequately mitigate.
From content governance to safety by design
On February 6, 2026, the Commission preliminarily found TikTok's addictive design to be in breach of the Digital Services Act. The preliminary finding focuses on a set of interconnected mechanics: endless feeds, automatic playback, push notifications and a highly personalised recommender system.
The Commission said these elements can encourage compulsive use and autopilot-like engagement. Its concern is not that any single feature is inherently unlawful in isolation. Rather, the assessment examines how the design works as a system, the risks it creates and whether TikTok's risk assessment and time-management measures were sufficient to address those risks.
The Commission indicated that effective remedies could require structural design changes. Examples cited include reducing or delaying infinite scroll, introducing meaningful screen-time breaks and adjusting recommender systems. These are preliminary conclusions, so they do not determine the final outcome of the TikTok investigation. They do, however, provide a detailed indication of how the regulator is interpreting platform risk-management duties under the DSA.
On July 10, 2026, the Commission issued a separate preliminary finding that Instagram and Facebook's addictive design breached the DSA. That assessment again focused on infinite scroll, autoplay, push notifications and personalised recommendations, and raised the possibility that existing mitigations were insufficient.
| Commission action | Platform or services | Design features examined | Regulatory focus |
|---|---|---|---|
| February 6, 2026 preliminary finding | TikTok | Infinite scroll, autoplay, push notifications and personalised recommendations | Whether addictive-use risks were adequately mitigated through risk assessment and time-management measures |
| July 10, 2026 preliminary finding | Instagram and Facebook | Infinite scroll, autoplay, push notifications and personalised recommendations | Whether existing mitigations sufficiently reduced addictive-design risks |
Why the DSA interpretation matters
The DSA's two-year milestone on February 17, 2026, came amid continuing enforcement activity and policy work on minors' safety and risk governance. The TikTok and Meta cases make the Commission's broader direction more concrete. Platforms may be expected to prevent foreseeable design-driven harms through the way a service is built, rather than relying primarily on users to activate safety settings after harm has begun.
That has consequences for the meaning of compliance. A screen-time tool, parental control or notification setting may remain useful, but its existence alone may not establish that a platform has sufficiently managed systemic risk. Regulators are examining both the core engagement loop and the real-world effectiveness of the safeguards surrounding it.
The broader youth wellbeing context reinforces why this is a priority. EU data shows high social-network use among younger people, including 89.3% of 16 to 29-year-olds in 2025. The precise claims that 89% of young Europeans use social media daily and that one in three neglects school, work or family are not directly confirmed by the cited EU sources. They should not be treated as official DSA findings. Still, EU surveys have identified stress and exclusion linked to social media among a significant share of adolescents, supporting the policy focus on digital wellbeing.
What product and governance teams should reassess
For large platforms, the cases point to a more demanding product-governance model. Teams responsible for user experience, trust and safety, legal review and data science need to treat engagement architecture as a risk-management issue. This is particularly relevant where design choices may affect minors or other vulnerable groups.
Practical areas for review include:
- Feed stopping points: Assess whether continuous content delivery creates a meaningful opportunity for users to pause, rather than simply continuing by default.
- Autoplay and notifications: Examine how default settings, timing and frequency can reinforce repeated or prolonged use.
- Recommendation systems: Evaluate whether personalisation optimises engagement in ways that increase compulsive-use risk, and whether adjustments can reduce that risk.
- Safety controls: Test whether screen-time tools and parental controls are understandable, accessible and effective in practice, rather than merely available.
- Risk governance: Connect product decisions to documented risk assessments, mitigation plans and evidence of how measures perform for affected users.
This does not mean the Commission has prescribed one universal user interface. The preliminary TikTok findings instead suggest a results-oriented test: a platform should identify the risks created by its design and demonstrate that its mitigation measures are adequate. That requires closer coordination between teams that have often worked separately, including product, engineering, data science, policy, legal and user research.
For enterprises that build digital services, the signal extends beyond the platforms named in the proceedings. Any organisation that uses algorithmic ranking, real-time prompts or engagement optimisation should understand how safety-by-design expectations are evolving. The central governance question is increasingly whether a product's default behaviour supports informed, user-controlled use, especially where risk is foreseeable.
As regulators connect algorithmic design to wellbeing outcomes, businesses need governance that reaches product requirements, experimentation and model decisions. Scalevise helps organisations translate emerging AI and digital-risk expectations into workable oversight, decision rights and implementation plans through its AI consultancy services. A structured review can reveal where engagement mechanics, user controls and risk evidence need attention before scrutiny becomes a costly reactive exercise. Request a consultation to assess your product governance approach.
Frequently Asked Questions
What did the European Commission preliminarily find about TikTok?
On February 6, 2026, the Commission preliminarily found TikTok's addictive design to be in breach of the DSA. It focused on infinite scroll, autoplay, push notifications and highly personalised recommendations, and whether related risks were adequately mitigated.
Are the TikTok findings final?
No. The Commission described its conclusions as preliminary and stated that they do not prejudge the final outcome of the investigation.
Which Meta services were covered by the July 2026 preliminary finding?
The July 10, 2026 preliminary finding concerned the addictive design of Instagram and Facebook. The Commission again examined infinite scroll, autoplay, push notifications and personalised recommendations.
What does this mean for platform developers?
Developers and product teams should assess how engagement features work together, document related risks and test whether safeguards such as screen-time management and parental controls effectively reduce those risks.
Conclusion
The Commission's preliminary actions involving TikTok, Instagram and Facebook establish addictive design as a significant DSA enforcement area. The cases do not settle the final legal outcomes, but they show that platform compliance is increasingly tied to the safety of defaults, recommender systems and engagement mechanics. Product teams that treat user wellbeing as a core design and governance responsibility will be better prepared for this broader regulatory standard.
Top comments (0)