Report /

Measuring Risk II: What EU Risk Assessments and US Litigation Reveal About Snap and YouTube

KGI’s latest report in the Measuring Risk series examines what EU risk assessments and US litigation reveal about Snap and YouTube’s approaches to risks on their platforms, with a particular focus on risks to minors. The report explores the gap between what these platforms publicly disclose about risk mitigation and what has emerged through discovery in US litigation, including their own internal research, product development, and risk evaluation.

Download PDF

Across the United States and European Union, two influential digital governance regimes are generating new evidence about how large social media companies conceptualize, assess, and respond to risks associated with their platforms. In the EU, the Digital Services Act (DSA) requires major platforms to conduct and publish annual systemic risk assessments, including risks related to the protection of minors. In the US, hundreds of ongoing lawsuits are revealing internal company documents, depositions, and expert reports that provide a window into how platforms identify, measure, and respond to many of the same risks.

KGI’s Measuring Risk II: What EU Risk Assessments and US Litigation Reveal About Snap and YouTube compares Snap and YouTube’s 2025 EU risk assessments with evidence emerging from US litigation. Building on Measuring Risk I, which examined Meta and TikTok, Measuring Risk II analyzes what Snap and YouTube publicly disclose about systemic risks on their platforms alongside what has emerged from the US litigation record – including their own internal data, research, communications, and risk evaluation – to reveal how they identify, measure, and respond to those risks in practice.  

Measuring Risk II identifies a consistent pattern across Snap and YouTube: platforms possess comprehensive internal data and robust analytical capabilities to understand risks and evaluate whether their mitigations work, yet very little of this measurement capacity is reflected in their EU risk assessments or public communication. Rather than demonstrating whether mitigations are effective, current risk assessments largely describe policies, features, and processes without reporting the outcome-based metrics needed to evaluate their impact.

Key Findings

  • Platforms collect extensive user data and possess robust analytical capabilities that could be used to assess risk and mitigation effectiveness. Across both Snap and YouTube, litigation records reveal detailed collection of user behavior data. Snap and YouTube’s internal strategies and studies reference a reliance on behavioral trace data and self-reported user experiences to understand user engagement patterns, late-night use, sleep disruption, and regret. Very little of this measurement capability is reflected in published EU risk assessments.
  • Platforms promote safety features as key mitigations without demonstrating that they actually work. Snap and YouTube describe a range of safety interventions – including age assurance, parental controls, screentime tools, and recommender system safeguards – yet neither discloses the adoption, usage, or outcome data needed to determine whether these interventions are effective. Litigation documents underscore this gap: only 0.33% of teen users were enrolled in Snap’s central parental tool, Family Center, while awareness of YouTube’s Family Link among parents was reportedly just 15%.
  • Platforms study engagement-based design risks internally but rarely disclose them in their public assessments. Internal documents suggest that key areas of risk were not consistently evaluated. Snap’s CEO told lawyers that the platform employed no full-time mental health researchers, while Snap’s head of user research told lawyers that the company’s research team never studied mental health, addiction, or anxiety. At YouTube, internal teams acknowledged in 2025 that they “don’t know if” core wellbeing features like Take a Break and bedtime reminders “work” because they had not looked “too deeply” into the effectiveness of these safety tools.
  • Internal documents highlight risks associated with product design that receive limited attention in public assessments. Litigation documents show both companies internally discuss and study risks associated with engagement-maximizing product designs, including gamification, notifications, and autoplay. Yet, public risk assessments continue to focus primarily on content- and user-generated risks, providing comparatively little evidence about the risks and effectiveness of platform design.

As EU enforcement matures and US litigation increasingly places internal research, product design, and risk metrics at the center of legal accountability, emerging evidence shows that the constraint for credible platform risk governance is not technical capacity but motivation and transparency. 

Across KGI’s Measuring Risk series, it is clear that social media companies have the tools to meaningfully assess risk and prove that risk mitigations work. What is missing is the expectation – enforced consistently by regulators and reinforced by courts – that companies proactively assess risks, mitigate them, and publicly report concrete metrics of effectiveness. This requires a shift from descriptive inventories of mitigation policies toward transparent, metrics-driven risk assessments that demonstrate whether mitigations actually work.

Measuring Risk Series

Measuring Risk I: What EU Risk Assessments and US Litigation Reveal About Meta and TikTok

Measuring Risk II: What EU Risk Assessments and US Litigation Reveal About Snap and YouTube

Close