Challenging Big Tech’s Business Model: Regulatory Coherence or Contradiction?
On July 10, 2026, Meta was found preliminarily in breach of the European Digital Services Act (DSA), a regulation that aims to protect user’s fundamental rights online. The investigation took issue with specific design features of Meta’s platforms, Facebook and Instagram, such as personalised recommendations, autoplay and infinite scroll. The Commission argued that Meta did not adequately assess the risks of its platform's “addictive designs”, particularly how those features could affect the physical and mental wellbeing of minors and vulnerable adults. In addition, the Commission alleges that Meta “disregarded available information about the time minors spend on Instagram or Facebook at night and how the optimisation of its different formats - such as reels and stories - could lead to excessive or compulsive use of the services.”
This follows similar findings of potential non-compliance by Bytedance for its social platform, TikTok, with the European Parliament noting that this was the first time enforcement action "has not focused on illegal content, data protection or competition, but on the harmful architecture of the platform itself.” However novel, such interventions are not isolated; the European Commission has various tools in its digital rulebook which target the design of social media, from competition regulation to industrial policy. But how well do these pieces fit together, and how successfully do they work together to challenge the business models that encourage user engagement and, arguably, “addictive design”?
DSA and Child Safety
Both Meta and Bytedance are in the process of non-compliance investigations under the DSA due to concerns over their platform's "addictive" designs. Facebook, Instagram and TikTok are all designated Very Large Online Platforms (VLOPs) under the DSA, meaning that they must comply with various obligations including identification, analysis and mitigation of “systemic risks” and potentially redesigning their services to mitigate identified risks to minors. The European Parliament notes that the term “addictive design” is not written explicitly in the DSA, but “the legal link lies in Article 34 (including risks to public health, minors, and users' physical and mental well-being) and Article 25,” which prohibits deceptive or manipulative interface design.
For both companies, the preliminary findings by the Commission are similar. In the case of TikTok, the Commission takes issue with TikTok's “recommender systems and engagement-maximising interfaces” as they generate “systemic risks to the mental well-being of minors and vulnerable adults. Thus, the harm arises from prolonged, compulsive engagement that users struggle to control, stemming from the persuasive design choices made by the platform.” Such findings are similar to the Meta investigation, and both cases conclude that both companies have yet to put in effective guardrails for users, with current interventions like parental control or screen time controls deemed insufficient.
The Commission considers that TikTok needs to change the basic design of its service “by disabling key addictive features such as ‘infinite scroll' over time, implementing effective ‘screen time breaks', including during the night, and adapting its recommender system.” Similarly, the Commission suggests that Meta disable “key addictive features such as 'autoplay' and ‘infinite scroll' by default, implementing effective ‘screen time breaks', and adapting its recommender system to make it less engagement-oriented.” It is notable that such findings come as global organisations are increasingly calling for platform “safety by design” enforcement, recognising that regulatory efforts have often looked only to downstream effects caused by design decisions.
Challenging platform incentives
What makes these suggestions radical is the fact that the interventions suggested shoot at the very heart of the business models employed by both companies, which design for maximum engagement. Because platforms like TikTok and Instagram are supported through advertising, or specifically, personalised advertising, platforms need to collect lots of data about its users to target relevant ads that are more likely to get clicked, meaning that the platforms are incentivised to keep users interacting with the platform. Additionally, the longer users are on the platform, the more ads can be shown, meaning more ad revenue. This creates incentives to design platforms with features like endless scroll, and engagement maximising features to produce more user data and user interaction, even if this prioritises potentially problematic content. It is additionally significant that both platforms, driven by the need to exhibit growth, are incentivised to tip the market as they compete to dominate. Indeed, much has been written about the network effects of these platforms, which gain value the more users engage with them.
The Commission directly seeks to disrupt this model through prohibitions on addictive features. TikTok’s value largely derives from its For You feed, which relies on personalisation to provide users with recommended content, designed for users to remain engaged. Equally, Meta’s platforms also prioritise engagement, which the Commission has explicitly called for the company to redesign. While it is certainly technically possible for such platforms to offer alternative recommendation feeds, for instance, chronological or other filters, such changes threaten to upend both companies' established business models, which is premised on keeping users engaged for as long as possible. If they do not comply, the companies face fines of up to 6% of the total worldwide annual turnover. Though not directly connected to the DSA, the Commission is also considering a ban for minors under 16 to access social media platforms unless providers can prove their designs are safe, further adding pressure on platforms to reconsider how to design their platforms.
How successful these investigations will be in overhauling platform design remains to be seen, as the DSA findings are only in their preliminary stage. Platforms could relent and turn off certain features by default in the EU. Turning off video autoplay, for example, seems like lightweight intervention. However, larger interventions which overhaul recommendation feeds may be existential for platforms like TikTok, which is premised on personalisation. Users could get the option to choose how their social feeds are displayed, though it is highly likely that platforms will push back against this, considering how fundamental personalisation is to platform business models.
Regulatory intervention to amend addictive design largely focus on harms to teenagers and children, so platforms may be incentivised to amend design only for accounts for minors, boosting the arguments of those in favour of age assurance implementation. However, many warn about the threats to privacy due to age assurance providers or verification methods as well as threats to freedom of expression. Additionally, age checks can be bypassed through tricking assurance methods or using VPNs. Therefore, whether the focus remains on protecting minors through age-gating or enforcing safety by design for all will be of significant importance.
Digital Markets Act
The Digital Markets Act (DMA), is part of the Digital Services Act Package, with the aim to improve the “fairness” and “contestability” of digital markets. Whereas the DSA aims to protect users rights, the DMA regulates the digital market by complementing EU competition law. The legislation was introduced in tandem, and despite having different aims, should be seen as aligned and consistent with the other.
Under the DMA, Meta is a designated gatekeeper for its core platform services Facebook and Instagram. This means that the company must adhere to the DMA’s list of prohibitions and obligations, including Article 5(2) of the DMA which requires gatekeepers to obtain consent from users when they intend to combine or cross-use their personal data across different core platform services. To bring it within compliance, Meta offered users the choice between continuing to access its platforms for free in exchange for their data, which is used for personalised advertising, or an ad free service through a paid subscription.
The European Commission launched a non-compliance investigation as the solution was deemed not to give users a meaningful choice if they did not consent to its personalised service. The UK’s Competition and Markets Authority previously found in a market study that consumers faced a “take it or leave it” decision to hand over their data in exchange for access to its dominant platforms, which arguably was not being solved by the pay or consent binary offer. Following a non-compliance decision, Meta offered a third option, which offered less personalised non-skippable ads, which was deemed compliant by the Commission.
Though an important step toward rebalancing the power between users and dominant tech firms which have largely been able to set the terms of participation, the decision does not fully address the engagement maximising business model which incentivises data collection by Meta. Though Meta outlined in its 2025 compliance workshop how the less-personalised ads option relies on less data signals, it does not touch features like recommender feeds or engagement maximisation that the business model relies on.
Interoperability and user switching
A far more structural intervention would be the imposition of interoperability obligations on an entrenched firm like Meta. Interoperability, or the ability of systems and technologies to work together, is an intervention which has successfully reduced concentration in the past. Interventions such as Open Banking in the UK, which required the UK’s nine largest banks to cooperate in creating and implementing technical standards to open up financial services, is considered a success, leading to “hundreds” of complementary fintech solutions. A bigger case to consider might be IBM, which was incredibly dominant in computing hardware for large institutions in the 1960s. As recounted by Tim Wu in his book, The Curse of Bigness: How Corporate Giants Came to Rule the World:
Over the 1960s, there were long-standing complaints that IBM was maintaining its mainframe monopoly and scaring people away from supercomputers using anticompetitive, predatory and unethical practices. In 1969, after a long investigation, the US Justice Department charged IBM with ‘monopoly maintenance’. According to the Justice Department, IBM had undertaken ‘exclusionary and predatory conduct’ to maintain its dominant position in ‘general purpose digital computers’.
IBM had been “bundling” software with its dominant hardware, therefore, leveraging its dominance to keep out competition. Fearing a break up by the Justice Department, IBM pre-emptively unbundled its software, which gave rise to entirely new industries. Companies began to develop personal computers shortly thereafter, with IBM, fearing antitrust, taking a far more open approach than it had in the past, preferring to interoperate with other hardware and software companies. Wu argues that this approach “breathed life” into nascent industries and firms, making way for new industries to develop the PC as we know it. He argues that it is an example of “the law at its best – challenging the powerful, and changing the incentives of firms and the structure of the market in a way that creates new industries and opportunities.” Though much of the interoperability at play here was voluntary from IBM, it only came about due to strict antitrust enforcement, and illustrates the potential for innovation when dominant firms' grips on technology and markets are loosened.
The European Commission had considered extending DMA Article 7, which currently mandates that designated messaging services (Meta’s WhatsApp and Facebook Messenger) are interoperable with third parties, thus allowing users to message their networks from a service of their choosing. The extension would have captured social media platforms, thus forcing a designated gatekeeper operating a social media core platform service, such as Meta’s Facebook and Instagram and Bytedance's TikTok, to open their platforms and allow users to communicate with their networks on other interoperating social media services, lowering a significant barrier to switching. Users may feel compelled to remain on dominant social networks where their connections are, an issue which is corrected when networks are interoperable.
The platforms locked us into their systems and made us easy pickings, ripe for extraction. Twitter, Facebook and other Big Tech platforms are hard to leave by design. They hold hostage the people we love, the communities that matter to us, the audiences and customers we rely on. The impossibility of staying connected to these people after you delete your account has nothing to do with technological limitations: it's a business strategy in service to commodifying your personal life and relationships. [...] Interoperability will tear down the walls between technologies, allowing users to leave platforms, remix their media, and reconfigure their devices without corporate permission.
- How to Seize the Means of Computation by Cory Doctorow
However, the Commission decided not to go ahead with this extension. This decision was largely based on the fact that there has been limited uptake by third parties to interoperate with designated messaging services, though without much interrogation as to why that may be, and also acknowledging that social media and messaging services are very different services. This is significant because mandated interoperability would have opened a pathway to allow users to more easily switch away from harmful platforms in favour of a growing number of networks building on top of open protocols, which the next section will further explore.
Tech Sovereignty Strategy
The European Tech Sovereignty Package is a set of legislative proposals to boost the bloc’s autonomy over its digital infrastructure, targeting semiconductors, artificial intelligence, cloud and open source. Under the Open Source Strategy, the Commission pledges support and encourages adoption of open source social networks. Open source software allows developers to access the source code of the software, with little to no restrictions on distribution, allowing for modification by developers. The European Commission recognises that open source solutions reduce vendor lock in significantly, can often be more secure and cost effective, as well as providing building blocks to encourage further innovation.
As part of the Open Source Strategy, the Commission states its intention to adopt “open and interoperable digital ecosystems for public administrations, including EU institutions,” which includes support for decentralised and open source social media. Though the Commission may have almost immediately undermined this pledge by migrating their institution’s Bluesky social networking account to a closed source application, the Commission continues to maintain its own Mastodon instance, an open source federated social network. This is generally a positive step toward reducing reliance on dominant tech platforms, ensuring that EU citizens do not need to remain on platforms to receive communications from EU institutions. It also means that governments are not expending time and resources fuelling dominant platforms, often the same ones that they are attempting to regulate.
Supporting protocols, not platforms
Supporting the facilitation of alternative social media is crucial to include in conversations about building safer social spaces. First, it provides alternative spaces for users to switch to or multi-home. This could put pressure on dominant platforms to improve their policies or user design features if users have a viable alternative to go to, and reduce market concentration and therefore, power.
More significantly, alternative social media has the potential to reduce the very harms that the Commission is attempting to regulate at the design level. The current dominant social platforms are built to maximise engagement, with network effects locking users in. Meanwhile, social networks built on top of protocols, meaning a standard set of rules for software to speak to each other, have more choice and control built in. For instance, the AT Protocol, which the Bluesky social network is built on, allows developers to build custom feeds for users of AT Protocol apps. Bluesky, for example, by default has a feed showing you recent content from those you follow, as well as a “Discover” feed which shows trending content from your personal network. Beyond this, there are a huge variety of many other feeds to try, such as “Mutuals” which highlights posts from those who also follow you back, “News” which shows verified news headlines in reverse chronological order, as well as topics like “Gardening”, “Birds”, “Booksky”, and so on. This algorithmic variety gives users much more choice and removes the incentives that platforms like Instagram and TikTok have been built to serve. Rather than serving only one feed designed to maximise user engagement, serve ads and collect data, the modular controls given to users on Bluesky gives them the choice of over 40,000 different feeds. Such design entirely challenges the platform logic we have grown accustomed to on dominant platforms.
Moreover, the purpose of the protocol is to go beyond Bluesky and build many interoperable apps that users can switch between and connect to, which completely challenges the model of centralised apps. While TikTok and Instagram use network effects to become monopolies, protocol based apps use network effects to build an ecosystem. The fact that apps like Bluesky are open source mean that it is also much easier for developers to build new apps and services and share knowledge.
Beyond institutional adoption, how does the Open Source Strategy support the development of such an ecosystem?
As highlighted by Nicholas Gates, Aimilia Givropoulou, and Jaakko Karhu in their analysis of the strategy as a whole, funding remains a challenge, particularly for maintenance of open source software. The authors point to the example of Germany’s Sovereign Tech Fund, which supports open software (including Mastodon) through structured financing. They argue that such a model should extend to an EU Sovereign Tech Fund at the EU-level which is currently being piloted. While the Open Source Strategy proposes funding, Gates, Givropoulou and Karhu state that the funding level is too low and recommend finding additional resources.
Separate to the Open Source Strategy, the European Commission has also published a call for proposals to create and test safer and more inclusive features for new social media platforms for young audiences. It is a €1.48 million pilot project involving young people from across Europe who will give their input to test new features with a focus on user safety, mental health, privacy and ease of use. The project seeks to produce “at least one protocol-based service that is actively centred around the needs of young user audiences and is in line with European values such as being protective of users’ privacy, autonomy and wellbeing.” Such an initiative recognises the need for safer socials and sees protocol based networks as a key facilitator of this. It moves the conversation beyond merely regulating dominant companies and closer toward supporting a better alternative.
How do the pieces fit together?
Considering all the regulatory instruments above, are there potential contradictions or do they work together coherently?
The Commission has signalled its intention to directly challenge the core business model of Bytedance and Meta’s platforms through mandated platform re-design. It has also adopted industrial policies like the Open Source Strategy which could help facilitate alternatives which are designed without the core incentives that drive problematic design in the first place. Together, these seem generally coherent, and suggests the EU wants to take an active role in shaping the future design of public spaces.
However, by not extending interoperability obligations on platforms like TikTok or Instagram, the Commission severely undermines its own efforts. As Laurens Hof articulates in his analysis, the “Commission has closed off one of the potential pathways for mass adoption of open social networking protocols for the foreseeable future.” While the Commission openly supports protocol-based open networks through policy such as the Open Source Strategy, it actively hinders the ability to move from centralised platforms onto those networks by refusing to impose interoperability.
If alternatives to Big Tech are not being sufficiently supported, how feasible are the threats of regulatory intervention and penalties? As stated above, when faced with pressure from competition, platforms are more likely to amend harmful practices. Without the threat that they may lose business, platforms are only incentivised to further “enshittify”, answering only to shareholders. Beyond this, monopolies that face no competitive threat continue to accrue power.
This doesn’t just mean unchallenged market power, but economically, they remain powerful if business users continue to be forced to do business through these gatekeepers. Such dominant market power is also leveraged into political power. This has been seen most starkly during US President Donald Trump’s 2025 inauguration, with tech CEOs taking front row seats following their political endorsement. The BBC pointed out that it was “a striking spectacle. The last public event in Washington to bring so many tech bosses together in the same room was a 2020 congressional hearing aimed at their companies.” Trump has subsequently ensured that US Big Tech interests are protected, with tariffs repeatedly leveraged against the EU as punishment for enforcing tech regulation. This has led to the perception that the EU is limiting financial penalties against Big Tech for breaking its digital regulations, with worries that enforcement is being weakened due to conflict with the US administration.
The political persuasion enjoyed by such large firms means that they can sway policy decisions and create the rules of the game to their benefit. This is why it is fundamental that their power be broken. The EU, as a powerful regulatory force, possesses the tools to attempt to chip away at the sources of Big Tech’s dominance, but this must be done coherently. Threatening fines may not be enough to undermine such dominant business models, however, the EU could seize the public popularity of digital regulation and the rising popularity of the digital sovereignty movement to both regulate the existing harms and also help to facilitate and build alternatives.