Online Misinformation: Regulate the Architecture, Not the Speech
Online misinformation isn't a
speech problem—it's a design problem. Here's how Canada, the EU, and U.S.
courts are learning to regulate platform architecture instead.
In March 2026, a jury in Santa Fe
took less than a day to decide that Meta had known, for years, exactly what its
recommendation algorithms were doing to teenagers—and kept them running anyway.
The company was ordered to pay $375 million. A day later, a Los Angeles jury
reached a similar verdict against Meta and YouTube. Neither case turned on a
single false post, a banned account, or a censored opinion. Both turned on
architecture: the infinite scroll, the notification cadence, the ranking
systems that decide what gets seen and how often.
That distinction is the one
almost everyone gets wrong when they argue about misinformation. We keep asking
whether a given claim should be allowed to exist online. We rarely ask why a
false, emotionally charged claim reaches ten million people in an afternoon
while a careful correction reaches ten thousand a week later. The first
question is about speech. The second is about engineering. And regulators,
quietly and unevenly, have started answering the second one instead of the
first.
The Core Tension
The debate over online
misinformation has been trapped for a decade in a false binary: either
governments police what people are allowed to say, risking the kind of state
overreach that silences dissent and minority viewpoints, or platforms are left
to self-police, in which case engagement-optimized systems keep doing what they
were built to do—reward whatever spreads fastest, true or not. Neither horn of
that dilemma is acceptable, and neither is actually necessary, because the
thing driving the crisis isn't the existence of false claims. It's the
machinery that decides which claims travel. A regulatory approach aimed at that
machinery—rather than at content itself—can reduce the velocity of falsehood
without a government or a platform ever having to rule on what's true.
Why Speech-Focused Regulation
Keeps Failing
For years, the default policy
instinct has been content-level: take down the post, ban the account,
fact-check the claim, throttle the source. It's intuitive, and it's also where
most public debate still lives. It's also largely not working, for a reason
that predates the current AI moment by nearly a decade.
Researchers at MIT, in a widely
cited 2018 study led by Soroush Vosoughi, Deb Roy, and Sinan Aral, analyzed
roughly 126,000 stories spreading on Twitter and found that false news reached
1,500 people six times faster than true news, and that this effect was driven
by humans, not bots—novelty and emotional charge made falsehoods more
shareable. Nothing about the underlying mechanism has changed since; if
anything, generative AI has lowered the cost of producing novel, emotionally
potent fabrications to near zero. Content moderation, no matter how fast, is
chasing a system engineered to outrun it.
There's a second, less discussed
failure mode: content-level enforcement is where free-speech harm actually
concentrates. When a moderator or an algorithm has to decide, post by post,
whether something is false enough to remove, the error rate is unavoidable, and
the errors don't fall evenly. A 2025 BBC investigation by journalist Marianna
Spring, drawing on more than a dozen internal whistleblowers at Meta and
TikTok, found that both companies' own research made clear that outrage-driven
engagement was a known, monetizable feature of their systems—yet the
public-facing conversation about "solutions" stayed fixed on
takedowns rather than on the incentive structure the whistleblowers were
describing. Every takedown decision is a judgment call about truth, made at
platform scale by parties with no democratic accountability. That's the
overreach civil libertarians are right to fear—it's just coming from corporate
terms-of-service departments as often as it comes from governments.
Featured Snippet Opportunity
Q: What is the difference between content moderation and platform
architecture regulation? A: Content moderation evaluates individual posts
or accounts for removal, requiring judgment calls about truth or falsity.
Architecture regulation instead targets the underlying systems—recommendation
algorithms, engagement incentives, and amplification design—that determine how
quickly and widely content spreads, without ruling on the content's veracity.
Canada's Safe Social Media
Act: A Design-First Template
Canada offered the clearest
recent illustration of the shift when it introduced Bill C-34, the Safe Social
Media Act, on June 10, 2026. The bill would create two new statutes—the Digital
Safety Act and the Digital Safety Commission of Canada Act—and establish an
independent regulator with real enforcement teeth: administrative penalties of
up to the greater of 3% of an operator's global revenue or CAD 10 million, and
criminal fines reaching 5% of global revenue for the most serious violations.
What makes C-34 notable for this
argument isn't its headline provision—a minimum age of 16 for social media
accounts, with an exemption pathway for platforms that can demonstrate adequate
safeguards. It's the structure underneath. The bill's Duty to Act Responsibly
requires regulated services to assess and mitigate risk across categories of
harmful content, label synthetically generated material, and give users
functional tools to flag content and block other users. Nowhere does the
statute empower the Digital Safety Commission to adjudicate whether a specific
claim is true. It regulates exposure design, not truth.
Legal analysts at the firm DLA
Piper have noted that C-34 is still only at first reading, with most
substantive obligations to be fleshed out later through regulation—meaning the
practical compliance burden on platforms, and the practical protection for users,
remains genuinely undetermined. That's not a flaw so much as an honest
acknowledgment of how young this regulatory approach is. Canada is building the
plane while flying it, and it knows it: the bill mandates a full ministerial
review within three years, with a separate review of the age provisions on the
same timeline.
The EU's Longer Head Start—and
Its Growing Pains
The European Union has been
running this experiment longer, and its scars are instructive. Under the
Digital Services Act, very large online platforms must identify and mitigate
"systemic risks," a category that explicitly includes threats to civic
discourse, electoral integrity, and public security—risks the European Board
for Digital Services has repeatedly tied to algorithmic amplification and
coordinated inauthentic behavior in its 2025 annual risk report.
The enforcement record shows both
the promise and the limits of the design-first approach. In December 2025, the
Commission fined X €120 million for DSA breaches. By January 2026 it had opened
a fresh investigation into how X's Grok AI tool interacts with the platform's
recommender systems, examining whether X properly assessed the risk before
deploying features that materially changed what users see. In July 2026, the
Commission went further, preliminarily finding that the addictive design of
Instagram and Facebook itself breaches the DSA—not any specific post on either
platform, but the design.
The friction is real, too.
Poland's president vetoed legislation designating a national DSA enforcement
authority in January 2026, warning against what he called a "Ministry of
Truth"—a reminder that even architecture-focused regulation can be perceived,
rightly or wrongly, as a speech-control apparatus if the public isn't shown the
difference. And a February 2026 Berlin court ruling ordering X to give outside
researchers access to platform data, so they could study election-related
amplification patterns independently of the Commission, points to where this
regulatory model probably needs to go next: transparency and researcher access
as a check on regulators as well as on platforms, so that the power to define
"systemic risk" doesn't quietly become the power to define acceptable
opinion.
The Turn: Litigation Is Doing
What Legislation Hasn't
Here's the nuance most commentary
on this topic misses entirely. While legislators in Ottawa and Brussels have
been writing statutes, American courts—working in a legal environment usually
assumed to be the world's most speech-protective—have been the ones actually
forcing platforms to redesign. And they've done it without touching a single
word of content.
The New Mexico and Los Angeles
verdicts against Meta and YouTube didn't allege that any post was false or
should have been removed. New Mexico's attorney general built the case around
the state's Unfair Practices Act, arguing that Meta made misleading statements
about platform safety and engaged in unconscionable trade practices—a strategy
explicitly designed to sidestep Section 230 of the Communications Decency Act,
which shields platforms from liability over user-generated content but does not
shield them from liability over their own product design decisions. In the
case's second phase, New Mexico prosecutors asked the court to order specific
architectural changes: redesigned recommendation algorithms that no longer
optimize purely for engagement, limits on infinite scroll, and changes to
notification defaults. Meta's own defense leaned partly on free-speech grounds,
arguing the state's proposed remedies would "infringe on parental rights
and stifle free expression"—which is exactly the tension this article is
describing, playing out in a courtroom instead of a legislature.
The contrarian point worth
sitting with: total deregulation isn't a free-speech victory. It's a
free-speech loss. When engagement-optimized architecture buries accurate
information under whatever is most emotionally provocative, the marketplace of
ideas doesn't get freer—it gets flooded, and the flood itself becomes the
barrier to entry for anyone trying to have a good-faith argument. The New
Mexico jury and the DSA's systemic-risk framework arrived at the same
underlying insight through completely different legal traditions: unmanaged
amplification isn't neutral. It's already a thumb on the scale. The only
question is whether democratic institutions put a second, accountable thumb
there or leave the first one—corporate, opaque, and optimized for shareholder
value—as the only one in the room.
The Friction-Accountability
Matrix: An Original Framework
Most policy debates treat
"regulate platforms" as a single dial, running from light-touch to
heavy-handed. That's the wrong mental model, and it's why so much of the public
conversation talks past itself. After tracking how Canada, the EU, and U.S.
courts have actually approached this problem, I've come to think about
interventions along two separate axes instead of one.
Axis one: Friction, not
filtering. Does the intervention slow down how content spreads (friction)
or does it decide which content is allowed to exist (filtering)? Friction
tools—non-personalized feed options, synthetic content labels, circuit breakers
on rapid resharing, cooling-off prompts before a post goes viral—preserve the
existence of every viewpoint while reducing the velocity advantage that
falsehood currently enjoys. Filtering tools remove or suppress specific content
and inherently require someone to judge truth.
Axis two: Accountability, not
opacity. Is the mechanism deciding what gets amplified auditable by outside
parties—researchers, regulators, courts—or is it a black box whose only
oversight is the company that profits from it? The Berlin court's data-access
ruling and the DSA's researcher-access provisions sit on the accountable end. A
platform's internal, undisclosed ranking model sits on the opaque end,
regardless of how it's used.
Plot any policy proposal on those
two axes and you get four quadrants. High friction, low accountability is what
critics fear most, and rightly so—it's government-mandated slowdown with no way
to check whether it's being applied evenly. Low friction, high accountability
is closest to where healthy self-regulation would sit, if platforms could be
trusted to get there alone, which the whistleblower record suggests they can't.
High friction, high accountability—Canada's Digital Safety Plans, subject to
regulatory review and complaint mechanisms; the DSA's systemic-risk audits,
subject to researcher data access—is where durable, rights-respecting
regulation actually lives. That's the quadrant worth building toward, and it's
the test I'd apply to any new proposal, including the next one that lands on
your desk: does it slow the spread, and can someone outside the company check
that it's being done fairly?
Practical Takeaway
One action: The next time
you evaluate a piece of misinformation legislation—or a platform's
self-reported "transparency report"—ask a single question before
anything else: does this measure target content, or does it target amplification
mechanics? If the answer is content, treat the free-speech objections as
serious, because they are. If the answer is amplification mechanics, the
relevant question shifts from "Does this violate speech rights?" to
"is the process auditable by someone other than the platform itself."
That single reframing does more to clarify a messy debate than any amount of
additional reading on what counts as "misinformation."
Closing
I keep coming back to a detail
from the New Mexico trial: prosecutors didn't spend six weeks arguing about
which posts Instagram should have taken down. They spent six weeks establishing
what the algorithm was built to reward and why the company kept rewarding it
after its own researchers said not to. That's the tell. The fight was never
really about the posts.
The countries and courts getting
this right in 2026 aren't the ones drawing brighter lines around acceptable
opinion. They're the ones asking a more uncomfortable question of the machines
doing the sorting: not what should people be allowed to say, but what should a
system be allowed to reward. Get that second question right, democratically and
transparently, and the first one mostly takes care of itself.
What would it take for you to
trust the sorting, rather than just the source?
A hand adjusting a control dial labelled "amplification," with tangled network lines representing social media engagement branching outward on a dark background.
Comments
Post a Comment