When a platform fails — data exposed, harmful content amplified, a coordinated scam left running for months — the public conversation usually looks for someone to blame. A CEO who knew. A regulator who looked away. A law that had a loophole. The search for a villain is understandable, but it tends to miss the more important point: these failures follow a pattern that persists regardless of who is in the chair. Platform accountability is a structural problem, and structural problems do not get solved by replacing individuals.
This piece is a companion to the field guide already published here on who bears responsibility in a specific failure. That guide asks who. This one asks why the answer so rarely produces consequences. The gap between harm occurring and a consequence following is not an accident of enforcement. It is, in large part, a feature of how the current system was built.
The Accountability Chain and Where It Breaks
The theory is simple. Harm occurs. An affected party identifies who caused it. A mechanism exists to impose a consequence. The consequence is applied. Four links. Each one has a known failure mode.
Take a large-scale data exposure — the kind where user records are left accessible due to a misconfigured system. The harm is real but diffuse: millions of people affected, each individually in a small way, none with the resources to pursue a claim alone. The responsible actors are multiple: the platform that built the system, the contractor that configured it, the auditor that signed off, the regulator that set the standard. The mechanism — a data protection authority — is often underfunded and working through a backlog measured in years. And by the time a consequence is proposed, it has typically been negotiated down through legal process until it represents a fraction of the original exposure.
Platforms tend to sit at the centre of this chain while also having the most resources to slow every link down. That is not an accusation. It is a description of incentive structures.
Why Jurisdiction Is the First Line of Defence for Platforms
Operating across dozens of legal systems creates a structural advantage that has nothing to do with bad intent. When a platform is incorporated in one country, processes data in a second, employs its trust and safety team in a third, and serves users in a fourth, the question of which regulator has authority becomes genuinely complicated.
Regulators in smaller markets frequently lack the legal reach to pursue entities incorporated elsewhere. Even where reach exists, the budget to sustain multi-year litigation against a well-resourced opponent often does not. Platforms of significant size routinely face enforcement actions that take longer to resolve than the underlying harm took to cause.
This is not primarily deliberate evasion. It is rational legal planning — choosing structures that are efficient and that happen, as a side effect, to make platform accountability harder to impose. The outcome is the same either way.
Section 230, the DSA, and the Limits of Liability Shields
Intermediary liability protections — Section 230 in the United States being the most cited example — were designed with a reasonable goal: allow platforms to moderate content without being treated as publishers responsible for everything their users post. Without some form of protection, the argument went, any moderation attempt would expose a platform to unlimited liability.
The unintended consequence was that low liability for inaction reduced the incentive to invest in moderation. If a platform faces limited legal risk whether it acts or not, the business case for acting is harder to make internally.
The EU’s Digital Services Act attempts a different approach. Rather than focusing on outcomes, it imposes due diligence obligations — meaning platforms must demonstrate they have processes in place to identify and address risks. This is a meaningful shift. It also has a practical ceiling: a platform can document its processes thoroughly, satisfy an audit, and still produce poor outcomes. Process compliance and harm reduction are not the same thing.
Neither framework was designed with systemic harm as its primary target. Algorithmic amplification of harmful content, coordinated inauthentic behaviour, and infrastructure failures that affect millions simultaneously do not map neatly onto rules built around individual pieces of user-generated content.
Self-Regulation and Why It Tends to Produce Reports, Not Consequences
The self-regulatory cycle is familiar. An incident occurs. The platform commissions a review. The review produces recommendations. Some recommendations are implemented. A version of the incident recurs. Repeat.
This cycle persists for a structural reason: self-regulatory bodies have no enforcement power. Their findings are advisory. The platform controls the process, the timeline, and the response. Transparency reports and community standards documents serve a real function — they create a public record — but they also serve a legitimising function that can substitute for external accountability rather than complement it.
The contrast is with co-regulation, where an external body sets the standards and the platform implements them under independent audit. Co-regulation produces better outcomes in the cases where it has been applied, but it is rare. It requires regulators willing to set specific, measurable standards and platforms willing to accept external audit findings as binding — neither of which is the default position.
What Effective Oversight Actually Requires
Four conditions tend to distinguish oversight that produces real consequences from oversight that produces paperwork:
- Independent authority with enforcement power — not advisory, not dependent on the platform’s cooperation
- Access to internal data — regulators who must rely on what a platform chooses to share cannot verify what they are being told
- Penalties that exceed the cost of non-compliance — a fine that represents a small fraction of quarterly revenue is a pricing mechanism, not a deterrent
- Consistency across jurisdictions — enforcement that applies in one market but not others creates an obvious arbitrage
Most existing oversight arrangements fall short on at least two of these four. The resource asymmetry is stark: in almost every significant enforcement action involving a major platform, the regulator is outspent and outlawyered. This is not a complaint about individual regulators. It is a description of what happens when public bodies with fixed budgets face opponents with variable legal spending.
The most effective accountability mechanisms have often been indirect. Competition law, financial regulation, and procurement rules have produced more concrete outcomes in some cases than platform-specific frameworks. One lever that has shown consistent value is mandatory incident reporting — requirements that platforms notify regulators of significant failures within a defined window. This at least creates a factual record, even when enforcement does not follow.
How to Use This as a Reference
This page is intended as a structural map. When you encounter a specific platform accountability failure — a scam that ran unchecked, a data breach with no consequence, a moderation failure that was documented and then repeated — the patterns described here are the underlying reason it happened the way it did.
For the question of who specifically bears responsibility in a given case, the field guide already published here is the right starting point. For the question of why consequences did not follow, come back to this one.
If you are working through a specific case, four questions help organise the analysis:
- Where is the harm concentrated, and who experienced it?
- Who had the capacity to prevent it — not just the legal obligation, but the practical ability?
- What mechanism exists to impose a consequence, and which body controls it?
- What would it take to activate that mechanism — a complaint, a threshold, a political decision?
Accountability does not require a single responsible party. It requires a system where consequences are possible. That system does not emerge on its own. It has to be built deliberately, funded consistently, and given the independence to function. Where those conditions are absent, the gap between harm and consequence will stay open — not because no one cares, but because the structure does not support closing it.
Frequently asked questions
Why do platforms rarely face serious consequences even after major failures?
Several structural factors combine. Harm is often diffuse, making it hard for any single affected party to pursue a claim. Responsible actors are multiple, so liability is contested rather than clear. Enforcement bodies are typically slower and less well-resourced than the entities they oversee. And the legal process through which consequences are imposed gives well-resourced parties significant tools to reduce or delay outcomes. No single factor is decisive; the combination is.
Does the EU’s Digital Services Act actually improve platform accountability?
It moves the dial in specific ways. By imposing due diligence obligations on large platforms — requiring them to assess and document systemic risks — it creates a basis for enforcement that did not exist before. Regulators can now ask not just what happened but whether the platform had adequate processes to prevent it. The practical limit is that process compliance and harm reduction are not identical. A platform can satisfy a due diligence audit while outcomes for users remain poor. The DSA is a meaningful step; it is not a complete solution.
What is the difference between self-regulation and co-regulation for platforms?
Self-regulation means the platform sets its own standards, reviews its own performance, and decides how to respond to its own findings. The findings are advisory and the platform controls the outcome. Co-regulation means an external body — a regulator or an independent standards organisation — sets the standards, and the platform implements them under audit by someone outside the company. Co-regulation produces more consistent outcomes because the findings are not controlled by the party being assessed. It is also harder to establish, because it requires both a willing regulator and a platform prepared to accept external audit as binding.
Scams, fraud, bots and manufactured noise keep spreading because the internet was built with no reliable way to know who anyone actually is. Everyone deserves authenticity and accountability online, and that is the mission we are working on. Subscribe to follow the work as it develops.
