Who Audits the Algorithm? Europe Is Turning Online Safety Into an Evidence Test
Europe is shifting online safety from policy promises to requiring platforms to demonstrate how their systems identify and reduce risk with measurable evidence.

Europe’s digital rulebook is entering a harder phase. It is no longer enough for a platform to publish safety policies or say that harmful recommendations have been reduced. Regulators, researchers and civil-society groups increasingly want evidence: risk assessments, data access, measurable mitigations and explanations of how recommender systems behave. A European Commission roundtable held on 23 September 2026 put that evidence problem at the centre of Digital Services Act enforcement — alongside protection of minors, online marketplaces, AI-related risks and the newly proposed KIDS Act.
Key takeaways
- On 23 September 2026, the European Commission held its fifth DSA roundtable with around 60 civil-society organisations and researchers, focused on systemic risks and mitigation measures.
- The discussion examined platform risk-assessment reports, independent research, data access and practical barriers to scrutinising large online services.
- Under the DSA, platforms accessible to minors must take appropriate measures to ensure a high level of privacy, safety and security for younger users.
- The proposed EU KIDS Act would push the model further by requiring relevant services to demonstrate that they are age-appropriate and safe by design.
- For users, the important question is shifting from “Does this platform have a safety policy?” to “Can the platform show that its product actually reduces risk?”
Europe is moving online safety from promises to evidence, asking platforms to show how their systems identify and reduce risk.
From safety promises to safety evidence
For years, the public conversation about social platforms revolved around rules: community standards, reporting buttons, parental controls and statements about harmful content.
Those things still matter. But Europe’s regulatory model is increasingly interested in what happens underneath them.
On 25 September, the European Commission published an account of its fifth roundtable with civil-society organisations and researchers on implementation of the Digital Services Act. The meeting itself took place on 23 September and brought together around 60 organisations.
The focus was systemic risk and mitigation: how platforms identify risks created by their services, what they do about those risks, and how outsiders can test whether the measures work.
Participants discussed analysis of platforms’ risk-assessment reports, independent research, research methods, data access and the practical difficulties researchers encounter. The Commission also highlighted recent enforcement priorities, including protection of minors, online marketplaces, AI-related risks and the KIDS Act proposal.
That may sound technical. In practice, it asks one of the most important questions in modern technology policy: who gets to check whether an algorithm is doing what a company says it is doing?
Safety by design asks whether the product architecture itself reduces foreseeable risk — not merely whether a policy exists.
Why algorithms need scrutiny
A social platform is not simply a collection of posts. Ranking systems decide what appears first. Recommendation systems decide what comes next. Notifications decide when people are pulled back in. Search, suggested accounts, autoplay and engagement predictions can all shape a user’s experience.
For a child, those systems can matter as much as the content rules themselves.
A platform might prohibit harmful material while still operating a recommender system that repeatedly steers a vulnerable user towards borderline or increasingly extreme material. It might offer parental controls that are technically present but difficult to find. It might provide a reporting function while making the surrounding experience confusing or slow.
That is why safety-by-design increasingly focuses on the behaviour of the product, not merely the existence of a policy.
Ireland is already testing implementation
Ireland’s regulator, Coimisiún na Meán, is the country’s Digital Services Coordinator and plays a central role in Ireland’s Online Safety Framework.
The regulator states that, under the DSA, providers of online platforms accessible to minors must put appropriate measures in place to ensure a high level of privacy, safety and security for minors.
Ireland’s Online Safety Code adds specific obligations for designated video-sharing platforms. On 8 September 2026, Coimisiún na Meán opened its first formal investigation under that Code, examining X’s implementation of age-assurance mechanisms and parental controls.
The opening of an investigation is not a finding of wrongdoing. That distinction matters. But the case illustrates the direction of travel: regulators are examining not simply whether a safeguard exists on paper, but whether its implementation may be effective, visible and usable.
The KIDS Act raises the bar again
The European Commission proposed the EU KIDS Act on 17 September 2026. It is a proposal, not final law, and its text can change through the legislative process.
Its core direction is nevertheless significant. The Commission says the proposal would require online services to be safe by design and would reverse the burden of proof so providers must demonstrate that services are age-appropriate and safe.
The proposal also establishes an EU-wide age of 15 for autonomous social-media accounts, alongside a gradual model for younger users, age assurance, parental responsibility and stronger enforcement.
Put beside the DSA, the emerging philosophy becomes clearer. Europe does not want child safety to depend entirely on a child recognising danger, a parent finding a hidden setting or a regulator discovering a problem after harm has occurred. It increasingly expects the service itself to identify foreseeable risks and engineer against them.
Researchers and civil-society organisations are increasingly important to independent scrutiny of systemic online risks.
What does an algorithm audit actually need?
There is no single magic test for a recommender system.
Meaningful scrutiny can require several layers of evidence. Researchers may need to understand what signals influence ranking, how recommendation pathways differ between user groups, whether safety interventions change outcomes, and whether certain groups experience disproportionate exposure to risks.
Access matters because outsiders cannot reliably evaluate a complex platform from public screenshots alone. Yet access must also respect users’ privacy, security and legitimate protections for confidential information.
This creates a difficult balance: enough transparency to permit serious scrutiny, without creating a new route to expose personal data or make systems easier to abuse.
The Commission’s September roundtable is important precisely because researchers and civil society are part of that equation. Regulators cannot independently reproduce every user journey on every major platform. Independent expertise can help identify patterns, challenge assumptions and test whether mitigation claims survive contact with real-world behaviour.
The question platforms should be able to answer
A useful safety claim should increasingly be testable.
If a company says it has reduced unsolicited adult contact with minors, what changed and what evidence shows the reduction?
If it says a recommender system is safer for teenagers, how is “safer” measured?
If it says age assurance prevents younger users from accessing restricted material, how robust is the process — and what personal information does it require?
If a parental control exists, can ordinary parents actually find and understand it?
These questions move the debate away from slogans and towards outcomes.
A safety feature matters only if people can find it, understand it and use it effectively.
What this means for Safegram — live, developing and planned
Safegram’s editorial position is that trust should be designed into a platform and supported by evidence, rather than treated as a marketing claim.
Live Safegram functionality includes verified participation for relevant account types, privacy-oriented communication, Safegram Exchange functionality and tools for businesses and creators. Safegram has also been developing age-aware teen and family safety architecture intended to create stronger separation between teenagers and adults in discovery and messaging, while preserving the privacy of conversations.
Those teen/family elements should be described as developing, testing or staged rollout unless a particular feature has been confirmed in the current production build. Safegram should likewise not claim that it has a formal DSA algorithm-audit programme, a KIDS Act compliance certification, regulator-approved risk assessments or a public researcher-data-access programme unless those systems are actually established and verified.
The opportunity is to build towards measurable safety from the start: define what a safety feature is supposed to achieve, record whether it achieves that outcome, minimise unnecessary personal data, and make important protections understandable to the people using them.
That is stronger than saying “trust us”. It creates the possibility of showing why trust is deserved.
Why this matters beyond Big Tech
The largest platforms attract most regulatory attention, but the underlying lesson is relevant to smaller services too.
Startups often have an advantage: they can make architectural choices before legacy systems, advertising incentives and billions of existing interactions make changes expensive.
A young platform can decide early whether minors and adults should interact in the same way. It can decide whether verification is merely cosmetic or connected to accountability. It can design reporting, discovery and messaging rules before harmful patterns become entrenched.
But smaller does not automatically mean safer. Good intentions are not evidence. The same discipline should apply: define risks, test controls, document decisions and improve when evidence shows a weakness.
The next phase of online safety
Europe’s online-safety debate is becoming less abstract.
The DSA created obligations around systemic risk. Ireland is moving into investigations under its Online Safety Code. The proposed KIDS Act would add a more explicit safety-by-design regime for children. Researchers and civil-society organisations are pressing for the access and methods needed to examine how platforms behave in practice.
The result is a new standard of credibility.
A safety page on a website is useful. A setting is useful. A policy is useful. But increasingly, the decisive question will be whether a platform can demonstrate that its systems produce safer outcomes.
For the next generation of social technology, that may become one of the clearest dividing lines between safety as branding and safety as engineering.
Frequently asked questions
What is the Digital Services Act?
The Digital Services Act is EU-wide legislation governing online intermediary services, including online platforms. Among other obligations, it creates duties around illegal content, transparency, systemic risks and protection of fundamental rights. Platforms accessible to minors must take appropriate measures to ensure a high level of privacy, safety and security for minors.
What is a systemic risk?
In the DSA context, systemic risks are large-scale risks linked to the design, functioning or use of very large platforms and search engines. Risk assessment and mitigation can involve issues such as illegal content, fundamental rights, public security, civic discourse and effects on minors, depending on the service and legal provision involved.
Can researchers inspect platform algorithms?
There are mechanisms under the DSA for vetted researcher access to certain data from very large online platforms and search engines, subject to legal requirements and safeguards. Practical data access and research methodology remain active areas of discussion.
Why did the European Commission meet researchers in September 2026?
The Commission’s fifth DSA civil-society and researcher roundtable, held on 23 September, focused on systemic risks, mitigation, analysis of platform risk assessments, data access and practical research challenges.
Is the EU KIDS Act already law?
No. The European Commission proposed it on 17 September 2026. It must proceed through the EU legislative process, and the final rules may change.
Is Ireland already enforcing online-safety rules?
Yes. Coimisiún na Meán oversees Ireland’s Online Safety Framework and is Ireland’s Digital Services Coordinator. On 8 September 2026 it opened its first formal investigation under the Online Safety Code. An investigation does not itself establish a breach.
Does Safegram currently have an independent algorithm audit programme?
Safegram should not claim that such a programme is live unless it has been formally implemented and verified. Its safety direction can be designed around measurable controls, but planned or developing governance should remain clearly labelled as such.
Source references
-
European Commission, “Fifth Roundtable with Civil Society Organisations and Researchers on the implementation of the Digital Services Act”, published 25 September 2026; meeting held 23 September 2026.
-
European Commission, “EU KIDS Act to restrict social media platforms’ access to children in the EU”, 17 September 2026, updated 22 September 2026.
-
European Commission, “Proposal for EU KIDS Act — EU Keeping Internet Digital Spaces Accountable and Trustworthy”, 17 September 2026.
-
European Commission, “KIDS Act”, Shaping Europe’s Digital Future, updated 18 September 2026.
-
Coimisiún na Meán, “Digital Services Act”, Online Safety Framework.
-
Coimisiún na Meán, “Investigation commenced into X under Online Safety Code”, 8 September 2026.
More from Safegram
Try Safegram
Privacy-first social and a verified marketplace, built in Dublin.