Social Media – does it need so much regulation, or is it just an easy target?

by Sabrina Steele on 19 Aug 2026

Social media companies increasingly find themselves in the regulatory, legal and political firing line. Across the UK, the direction of travel is clear; we expect more regulation in the coming months, particularly around restricting access to children, age-assurance mechanisms, recommender systems and the design of online services. At the same time, Ofcom is moving into a more active enforcement phase of the Online Safety Act, and other digital regulators are ramping up their scrutiny of social-media firms.

But there is a broader question that is sometimes lost in the regulatory debate. This blog explores whether social-media companies are in fact responsible for all of the problems attributed to social media — and, even if or when they are, whether more regulation always offers the best solution.

Social media is now deeply intertwined with modern society. It is how many people communicate with friends and family, consume news, build businesses, find communities, express political views and entertain themselves. For young people, in particular, it is simply a part of everyday life rather than a separate online activity. According to Statistica, in 2025 the UK had roughly 55.5 million active social-media users, representing close to 80% of the population. WhatsApp was the most used social-media service in the UK as of the second quarter of 2025, followed by Facebook and Instagram.

At the same time, there is significant evidence and concern about the negative effects associated with social media: including its negative impact on mental health, sleep, productivity, body image, misinformation, bullying, childhood development and exposure to harmful content. The World Happiness Report, published in May 2026, found that mental-health is directly linked to increased social-media use.

There is clearly a case for asking whether platforms are doing enough. But there is also a danger in assuming that because a problem is visible on social media, the hosting platform must be its cause — or that another piece of regulation will solve it.

Current regulatory landscape

The regulatory landscape is already extensive. The UK has multiple pieces of regulation targeting social media companies already in place, including the Online Safety Act (OSA) and Information Commissioner’s Office’s (ICO) Children’s Code.

The OSA has introduced duties on regulated online services covering illegal and harmful content as well as the protection of children. Since July 2025, platforms accessed by children have also had to comply with extensive child-safety requirements and must be able to report and demonstrate compliance. In June 2026, Ofcom published its register of categorised services which will face additional duties under the Act, with Ofcom consulting on requirements covering user-empowerment, identity-verification, complaints, terms of service, journalistic and democratic content, freedom of expression and privacy-impact assessments. There are also proposed additional duties relating to fraudulent advertising. Ofcom has already taken action against social-media firms, with TikTok being investigated for its child-safety duties.

The ICO’s Children’s Code applies to online services accessed or likely to be accessed by children. If in scope, and as with many social-media platforms, firms are required to demonstrate how they have addressed data-protection principles like privacy by default, profiling, geolocation and the use of children’s personal data. The data-protection regime has therefore become a key part of the debate. The ICO is already scrutinising how platforms use children’s data and recommender systems, including via an investigation into TikTok’s use of recommender systems for 13- to 17-year-olds.

Whilst these are the two most targeted pieces of legislation, social-media companies are also required to comply with other regulations: regarding consumer protection, advertising regulation, competition law and any other legislation applicable to platforms’ particular business model.

Is targeted regulation effective?

Some arguments for regulating social-media platforms are compelling. For example, a platform with hundreds of millions of users has capabilities that individual parents, teachers or users simply do not. Platforms control the recommendation systems and provide access to default settings, reporting mechanisms, advertising systems and the architecture through which online content is distributed. This means these firms themselves are likely to have the ability to mitigate — and probably the responsibility of mitigating — risks which individual users cannot be expected to manage. For example, it is difficult to argue that a 13-year-old should be responsible for understanding the different commercial incentives (potentially hidden in addictive-design or content-consumption features, etc.) behind a leading platform’s recommender system.

The government’s proposed under-16 restrictions will attempt to address this concern. The government plans to ban social-media companies from offering services to under-16s, with legislation expected before the end of 2026 and implementation planned for spring 2027. It is also proposing restrictions on features such as livestreaming and strangers contacting children, alongside additional default protections for 16- and 17-year-olds. There is a reasonable argument here that the party with the greatest ability to reduce a risk should carry a significant proportion of the responsibility for doing so.

But that doesn’t necessarily mean every social-media problem is a platform’s responsibility. The sheer amount of active and pending regulation shows that policymakers are still working to find and adapt to the best solutions. There are several reasons why regulating social media and its hosting platforms is so challenging.

Challenge 1: How do you regulate something that is free at the point of use?

This is perhaps the fundamental economic problem and leads to a new way of approaching traditional regulation. Most major social-media platforms are free to users; their business models are instead based largely on advertising, data, engagement and scale. This creates a difficult regulatory question: if users aren’t paying directly for a service, what exactly are they buying — and what obligations should providers have towards them?

The answer increasingly appears to be that users exchange time and data for access to the platform itself. This creates a legitimate regulatory interest, but also the risk that policymakers focus too heavily on the platform’s commercial model without addressing underlying incentives. For example, a platform profiting from keeping users engaged may have an incentive to design experiences encouraging them to spend longer on the service. The regulatory response might therefore be to prohibit particular design features such as infinite scroll.

But there is another possible response: increasing transparency and user choice. Rather than prescribing exactly how a platform must operate, regulation could require companies to explain how recommendation systems work, give users meaningful control over their feeds, provide stronger default settings for children and make it easier to leave or change the service. This type of approach may be less intrusive for platforms to implement while still addressing the underlying incentive problem.

Ofcom’s emerging Category 1 regime moves partly in this direction, with proposed requirements around user-empowerment, terms of service, identity-verification and transparency.

Challenge 2: How do you future-proof regulation when technology changes so rapidly?

This is one the greatest challenge facing policymakers, as the technology being regulated today will not necessarily be the same six months from now, much less in five or ten years. Social media has already evolved from simple social-networking sites into algorithmically-curated video feeds, livestreaming platforms, creator economies, private communities and — increasingly — AI-driven experiences. The scope and features of social-media platforms are also constantly changing, with many now combining social media, search, messaging, gaming and AI assistants.

We know legislation moves slower than technological innovation, and policymakers are therefore looking more and more at adaptable principle-based frameworks rather than rules specifying particular platforms or firms. And yet there remains a risk that a broad framework can be too broad: rendering it either unenforceable or else causing it to sweep up unintended targets.

One potential solution regulators are looking to is requiring firms in scope to undertake their own assessments prior to any business-model changes. This would mean requiring platforms to proactively consider any risks and to assess appropriate mitigations and then implement them before rolling out a new feature or product.

Ofcom and the ICO already do this to an extent, with companies often required to share compliance assessments. Regulatory guidance expects platforms to review their risk assessments when making significant changes to the design or operation of their services.

Challenge 3: How do you balance greater protections with freedom of expression?

This is one of the trickiest areas, and one of the reasons the OSA took such a long time to design and introduce. A majority of the population supports the idea of removing harmful content online, but defining what this means remains challenging. Examples often raised include political speeches, satire and some journalism, where the topics are not illegal but could be considered harmful to certain audiences.

Whilst this may be easier to introduce for children, Ofcom is consulting on requirements that explicitly address freedom of expression and privacy-impact assessments for Category 1 services, alongside protections for journalistic content, news-publisher content and content of democratic importance. This demonstrates how hard it is likely to be to balance safety regulation with indirect content control.

Challenge 4: How much responsibility belongs to the individual, how much to the platform?

Platforms are increasingly required to anticipate and mitigate a growing range of risks to their users, which, as mentioned above, is often appropriate for platforms’ size and role but fails to acknowledge the extent to which users can maintain control over their social-media experience. Whilst often not the case for children, adults make choices about how much time they spend online, which accounts to follow and which communities to participate in. Equally, parents make choices about when their children receive smartphones, and schools make choices about technology use. These differences should be acknowledged in future regulations. For example, a platform should arguably have a very high level of responsibility for preventing children’s accessing pornography; but it is much harder to argue the same platform should be responsible for an adult’s decision to lose sleep during the week while scrolling for hours through political commentary.

The answer is probably some sort of balance, and the government’s proposed approach to restricting social-media use for children does include proactive support for parent and media literacy.

Is social media just an easy target? What else should be considered?

Social-media companies are enormous, visible and often unpopular. Their business models are hugely profitable and can be difficult for the public to understand, making them an attractive political target.

But they are not necessarily the only fair game; to genuinely improve people’s relationship with technology, regulation should be just one part of the solution.

Digital and media literacy: people need to understand algorithms, advertising, misinformation, persuasive design and how platforms make money. Ofcom itself is developing recommendations around media literacy as part of the wider online-safety framework, and the government is prioritising media literacy as part of both the restrictions on social media for children and its work on news media online.

Better parental support: parents need practical advice rather than simply being told that technology is dangerous. The government has begun developing guidance for parents on healthy screen use for children aged 5-16, recognising that the issue extends beyond social media itself.

Better product design: platforms could be encouraged to compete on safety, privacy and user-control rather than simply engagement.

Independent research: we need better evidence about causation — not simply correlations — between social-media use and negative outcomes.

Greater transparency: researchers and regulators need meaningful access to information about recommendation systems and platform risks without compromising privacy or security.

Competition: if users can easily move between services and take their social networks or data with them, platforms may have stronger incentives to compete on the quality of the user experience rather than relying on lock-in.

Conclusion

There is a strong case for rules addressing clear and demonstrable harms — particularly where platforms have the ability to prevent those harms and where users, especially children, cannot reasonably protect themselves. There is also a strong case for requiring large platforms to understand the risks inherent to their models, be transparent about how their services operate and give users meaningful control. But regulation should never become a substitute for evidence, education, parental responsibility or wider public policy.

Topics: Regulation, Technology, Innovation, Social media

Sabrina Steele

Written by Sabrina Steele

Get the latest updates from our blog

Related Articles

The promise of AI has already resulted in massive amounts of investment and spending, leading to huge ... Read more

As the UK prepares for a new Labour leader and prime minister, the focus is already shifting to devolution, ... Read more

This blog looks at the UK government’s discussions and actions around online safety over the past year, ... Read more

Throughout March and early April 2026, rumours swirled that leading AI firm Anthropic was developing a tool ... Read more

Comments