Summary
- European regulators are examining whether TikTok’s account settings, discoverability, and recommendation systems provide adequate protection for minors.
- The preliminary finding treats product design as part of the platform’s legal compliance record, rather than leaving safety to optional controls.
- A final decision could require changes across TikTok’s European service and establish a wider standard for platforms used by children.
Europe’s online safety regime is moving into the mechanics of platform design, after regulators provisionally concluded that TikTok had not provided sufficiently safe accounts for children using its service.
The European Commission said accounts belonging to minors did not meet the standards required under the Digital Services Act, particularly where public settings could make their profiles and content visible, searchable, and available for recommendation to people they did not know.
The finding remains preliminary, which gives TikTok an opportunity to inspect the Commission’s evidence and respond before any final decision is made. Even so, the proceedings place account defaults, visibility controls, and recommendation systems inside the formal compliance record of a very large online platform.
Earlier approaches to child safety concentrated heavily on identifying harmful content after publication, whereas the Commission is examining the systems that decide how far a post travels and who can interact with its author. A platform may remove individual videos promptly while its ordinary account journey still exposes younger users to unwanted attention.
Defaults become evidence
European guidance on protecting minors under the DSA favours private accounts, limits on unsolicited contact, and design choices that reduce unnecessary collection or distribution of children’s data. The Commission’s preliminary findings against TikTok bring those principles into an enforcement process.
Although platforms commonly provide extensive menus of safety settings, the existence of a control says little about whether a child will find, understand, and use it. Regulators are consequently looking at the combined journey through account creation, age estimation, privacy choices, recommendations, search, messaging, and later attempts to alter settings.
That approach changes the work required inside platform companies because legal teams cannot assess compliance from policy documents alone. Product managers, engineers, data scientists, trust and safety specialists, and senior executives may need to preserve evidence showing how design decisions were tested, which risks were identified, and whether safeguards worked after release.
A change that increases discoverability or removes friction from sharing could therefore require a safety assessment alongside its commercial and technical review. Engagement metrics may reward broader distribution, while the compliance record must show that the same design does not expose children to foreseeable harm.
Age assurance remains one of the more difficult parts of that system. Platforms need enough information to apply protections reliably, yet collecting more identity data creates additional privacy and security risks, particularly where a service is used by hundreds of millions of people.
Errors also run in both directions. A weak system may treat children as adults and withhold appropriate protections, whereas an intrusive or inaccurate system can block legitimate users, require unnecessary documents, or give a private provider access to sensitive identity information.
Safety reaches the business model
The DSA gives the Commission investigative powers over the largest online platforms, including the ability to demand information, inspect systems, order remedial measures, and impose penalties of up to six per cent of global annual turnover for a confirmed breach. A redesign order could carry a larger operational consequence than the financial penalty if it changes how content is distributed across the service.
Product alterations introduced for Europe may also spread elsewhere because maintaining separate account journeys, recommendation rules, and control systems across jurisdictions creates engineering and governance costs. Applying a stricter default more widely can be simpler than operating several versions of the same service, although global adoption is not guaranteed.
Other social networks, video services, messaging products, and online communities will be watching how the Commission defines an adequately safe account. The eventual reasoning could influence procurement of age assurance, moderation, identity, safety testing, and audit technology well beyond TikTok.
Commercial incentives sit close to the regulatory dispute because public content, recommendations, notifications, and easy interaction help platforms increase viewing time and advertising inventory. The same mechanisms can make a child’s activity visible to a much larger audience than the user expected when opening an account.
Reducing that exposure may lower some forms of engagement, which means safety cannot remain a peripheral function with little authority over product decisions. A platform claiming that protection is fundamental must be able to show where it accepted slower growth, additional friction, or weaker distribution to reduce a documented risk.
TikTok can challenge the Commission’s analysis before the proceedings conclude, and a preliminary view should not be treated as a final finding of infringement. Nevertheless, the case already demonstrates that an impressive collection of safety features will carry limited weight when the standard account journey produces a less protected result.






