Commission preliminary finding
The European Commission has preliminarily concluded that Meta Platforms Incorporated violated the Digital Services Act through the addictive design of Instagram and Facebook. The announcement was made on 11 July 2026. The investigation centred on four core features: infinite scrolling, automatic video playback, push notifications and highly personalised recommendation systems. According to the EU Digital Strategy, Meta failed to adequately assess the risks these elements pose to the physical and mental health of users, particularly minors and vulnerable adults. The Digital Services Act, which applies across all twenty-seven EU member states, requires very large online platforms to identify and mitigate systemic risks arising from their services, including negative effects on mental health.
Specific design features under scrutiny
The Commission’s evidence indicates that Meta’s existing measures to limit these risks have proven ineffective. The EU AI Office, which supports the implementation of the AI Act and coordinates AI governance across the Union, stated that the safeguards introduced by Meta failed to address the negative impacts of addictive design. Executive Vice-President Henna Virkkunen, who oversees digital policy and technological sovereignty for the Commission, emphasised that protection of the physical and mental health of Europeans must be a priority for social networks and that the DSA provides a clear framework for holding platforms accountable. The finding marks the first time the Commission has explicitly targeted behavioural design patterns as a source of systemic risk under the regulation.
Formal proceedings and potential sanctions
The Commission has opened formal proceedings to examine in detail the effects of algorithmic systems on user behaviour and mental health. Meta must now respond to the findings and demonstrate compliance with legal requirements. If the violations are confirmed, the company faces significant sanctions under the strict oversight regime for digital services, including fines of up to six percent of global annual turnover for repeated breaches. The proceedings will assess whether Meta’s design choices constitute a systemic breach of the DSA’s obligations on risk assessment and mitigation, and whether the platform’s recommender systems amplify harmful content in ways that the company failed to anticipate or address.
Implications for platforms operating in the EU
The decision signals increased regulatory pressure on companies operating in the European Union to audit and document risks linked to user interface and algorithm design. Implementation of artificial intelligence and personalisation systems will face closer scrutiny, requiring demonstrable compliance with the DSA and readiness for potential sanctions in cases of non-compliance. The broader context shows the DSA’s emphasis on transparency and user protection against harmful practices, ensuring platforms cannot exploit addictive mechanisms without proper risk assessment and mitigation. For security engineers and compliance leads, the case establishes a precedent that product design decisions, previously treated as internal business choices, are now subject to regulatory review when they affect user wellbeing at scale.