Five critical lessons from three years of DSA risk assessments
Reviewing three annual rounds of filings (2023-2025) from Facebook, Instagram, TikTok, X and YouTube, ECNL found reports ‘despite often exceeding 100 pages... still lack the necessary detail’ to understand platforms’ decisions. It identified five recurring gaps: vague risk statements, less diligence on fundamental-rights risks than other systemic risks, unsubstantiated claims, missing detail on stakeholder-consultation feedback, and inconsistent treatment of linguistic/geographic diversity.
About this research
This original report draws on API/data analysis.
- Publication
- Original report · 10 pages
- Research approach
- API/data analysis
- Research materials
- Public-source data is described in the publication
- Methodological notes
- The authors discuss limitations in the source publication.
Publication details prepared by Social Media Transparency from the original source.
Executive summary
AI-generatedThis summary was generated by AI from the original report to make it easier to scan and cite. It is not a substitute for the source. Read the original above.
ECNL’s policy brief is the first cross-year audit of the actual risk-assessment documents Facebook, Instagram, TikTok, X and YouTube have filed since the DSA’s 2023 rollout, rather than a prescriptive framework. Using the three published annual cycles as its dataset, it assesses whether the disclosures meet a basic transparency bar for external scrutiny. It concludes they largely do not, and recommends the European Commission issue clearer guidance on required data disclosure and reporting standards so future rounds move beyond compliance theater.
Think this summary is wrong? Contact us.