Report /

Measuring Risk I: What EU Risk Assessments and US Litigation Reveal About Meta and TikTok

Across the EU and US, two influential digital governance regimes are producing new evidence about how large social media companies assess and respond to potential risks on their platforms. KGI’s latest report compares Meta and TikTok’s EU risk assessments with internal documents emerging from US litigation, revealing significant gaps between public claims about risk mitigation and evidence of how these risks are actually addressed.

Download PDF

Systemic risk assessments in the EU and legal discovery in the US are revealing new insights around how platform design and recommender systems can contribute to risk and mitigation, with a particular focus on risks and harms impacting minors. 

KGI’s report “Measuring Risk I: What EU Risk Assessments and US Litigation Reveal About Meta and TikTok” examines what can be learned by reading these two bodies of emerging evidence side-by-side. The report identifies critical gaps in how Meta and TikTok communicate publicly about risks and the actual steps they take to mitigate risks based on evidence and data. 

Regulatory processes in the EU and legal frameworks in the US have notable differences in scope and approach. However, they converge on a key concern: potential risks to minors. Risk assessments and investigations under the EU’s Digital Services Act (DSA) as well as complaints in US courts have identified overlapping concerns related to compulsive use and addiction-like behaviors, sleep deprivation, self-harm, eating disorders, and other mental and physical health impacts for minors. Each regime produces distinct evidence and disclosures, creating opportunities for cross-jurisdictional learning.

KGI’s report finds that there are significant gaps between the risk mitigations that Meta and TikTok describe in their EU risk assessments and the actual effectiveness of these measures revealed through internal documents in US litigation.

While the DSA has created an obligation for platforms to identify and mitigate systemic risks in Europe, the first two years of risk assessments rely heavily on high-level company descriptions of policies, tools, and user controls. Assessments provide extremely limited detail into whether any of these interventions meaningfully reduce harm, particularly for minors. By contrast, US litigation is surfacing previously unreleased internal platform data, experiments, and deliberations that reveal how platforms internally measure risk and define acceptable trade-offs related to risk, engagement, and revenue. But US litigation is largely reactive and limited to the facts of each specific case. 

Key Findings:

  • Platforms collect extensive user data and possess robust analytical capabilities that could be used to assess risk and mitigation effectiveness. Litigation documents reveal that Meta and TikTok collect detailed internal data on youth online engagement, including time spent, patterns of compulsive use, late-night engagement, and unwanted contact from adult users. Very little of this measurement capability is reflected in published EU risk assessments.
  • Platforms promote safety features as key mitigations without demonstrating that they actually work. Meta and TikTok describe parental controls, screen time limits, take a break reminders, and other wellbeing features as key mitigations in their EU risk assessments, yet neither company discloses the adoption, usage, or outcome data needed to determine whether these interventions are effective. Internal documents indicate that many of these tools have extremely low adoption rates, often below 2% of minor users. For TikTik, between January 2024 and January 2025, just 1.5% of users enabled screentime breaks and only 0.7-1.8% enabled sleep reminders. Meanwhile, at Meta, as of March 2025, only 0.15% of minors were enrolled in Facebook’s parental supervision tools and just 0.0038% of Instagram users had adopted parental controls. 
  • Internal documents suggest engagement goals constrained the design of safety interventions. Litigation records indicate that TikTok leadership initially imposed “guardrail” metrics requiring that new screentime tools reduce usage by no more than 5% – maintaining engagement over safety, meaning the platform’s heaviest teen users would still spend nearly six hours a day on the app. Meta’s internal projections accurately predicted that 99% of teens would not use optional opt-in take a break features. Together these findings raise important questions about whether safety interventions were designed to meaningfully reduce risk or to minimize impacts on engagement.
  • Platforms study engagement-based design risks internally but rarely disclose them in their public assessments. Internal documents show that Meta and TikTok studied how recommender systems, notifications, and engagement-maximizing product features contribute to prolonged use and risks to minors. Yet their EU risk assessments focus primarily on content-related harms, providing comparatively little evidence about the risks posed by platform design or the effectiveness of design-based mitigations.
  • Internal records reveal platform design can expose minors to harms. Litigation documents provide concrete evidence linking product features to risks for minors. Internal Meta records indicate that Instagram’s “Accounts You Might Follow” feature recommended adult groomers to nearly 2 million minors over a 3 month period in 2023, while TikTok’s internal research documented compulsive use and evaluated safety tools using detailed behavioral data. These findings demonstrate that platforms possess granular evidence about how product design influences youth safety that is largely absent from their public disclosures.

The evidence emerging from EU risk assessments and US platform litigation underscores a central gap in current approaches to platform governance: risks are increasingly well-described, but mitigations are rarely communicated using rigorous, outcome-oriented data and evidence. 

Addressing this gap will require aligning platform expectations with rigorous research and evaluation. Systemic risk assessments in the EU should move beyond descriptive inventories of mitigations toward transparent, metrics-driven statements of risk and mitigation effectiveness. While insights generated through litigation are still emerging and incomplete, they highlight the types of data, methods, and benchmarks that should inform more credible, forward-looking platform governance. 

Measuring Risk Series

Measuring Risk I: What EU Risk Assessments and US Litigation Reveal About Meta and TikTok

Measuring Risk II: What EU Risk Assessments and US Litigation Reveal About Snap and YouTube

Close