> ## Content Index
> Fetch the complete content index at: https://www.digitalpolitics.co/llms.txt
> Use this file to discover other available public pages before exploring further.

# Rethinking how AI should be governed
- URL: https://www.digitalpolitics.co/operational-ai-governance-meta-settlement-industry-rules-2026/
- Published: 2026-08-31T11:00:41.000Z
- Updated: 2026-09-02T11:03:26.000Z
- Description: AI oversight isn't needed just in the lab. It's required for all the AI-powered systems out in the wild and potentially causing real-world harm.
- Author: Mark Scott
- Tags: Artificial Intelligence, age verification, AI governance, Anthropic, Australia, Brussels, children, digital services act, European Union, Facebook, Instagram, meta, New Mexico, Online Safety, platform governance, platforms, Snapchat, tiktok, YouTube, operational AI governance, OpenAI, Mark Zuckerberg, US states, #edition, #artificial-intelligence, #platforms-online-safety, #ai-feature-1

**IT'S MONDAY, AND THIS IS DIGITAL POLITICS.** I'm [**Mark Scott**](https://www.linkedin.com/in/markscott82/?ref=digitalpolitics.co), and here's a date for your diary. I'll be hosting a panel discussion in Brussels on **Oct 8** to dissect the current and future EU-US digital relationship, based on this recent [report](https://dfrlab.org/2026/08/17/sovereignty-without-borders-decoding-the-transatlantic-digital-relationship-at-a-time-of-change/?ref=digitalpolitics.co) that I published for my day job.

**If that sounds like your cup of tea,** please [fill in this form](https://forms.gle/YyHZnQ5L8EGd2XBY7?ref=digitalpolitics.co) to express your interest in joining me and leading European and US voices (including a drinks reception after the panel.) I'll be in touch later in September to confirm participation.

**— Most artificial intelligence oversight** focuses on how these models are trained and created. Operational AI governance is how policymakers should police these systems in the wild.

**— Meta's $18 billion dollar child safety settlement** gives the social media giant the tacit power to set an industry benchmark that rivals may be forced to follow.

**— Three-quarters of Europeans now back an** Australian-style social media ban.

**Let's get started:**

---

## AI GOVERNANCE CANNOT STOP AT THE LAB

**WHEN MOST OF US THINK OF AI OVERSIGHT,** we picture internal corporate red teams (and some [recent high-profile failures](https://openai.com/index/hugging-face-incident-and-the-road-ahead/?ref=digitalpolitics.co)), discussions about biases and copyright in training data, and debates over proprietary and open-weight models. To fully grasp what that looks like, you need a PhD in computer science and be able to churn out analysis like Stanford University's annual [Foundation Model Transparency Index](https://crfm.stanford.edu/fmti/December-2025/index.html?ref=digitalpolitics.co). 

**All this is God's work, and must continue**. But the more I delve into this world, the more I believe it's only half of the discussion. 

**Much of current AI governance** — even the United States' recent [conversion](https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/?ref=digitalpolitics.co) to the topic — is framed around one question: should a next-generation model be released? That's what happened with Anthropic's Mythos, including [analysis](https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing?ref=digitalpolitics.co) from the United Kingdom's AI Security Institute that flagged unexpected cybersecurity threats with the company's latest model. It was also preceded by the White House's [short-term export](https://www.anthropic.com/news/fable-mythos-access?ref=digitalpolitics.co) ban on the same model after US national security agencies similarly flagged ongoing vulnerabilities. Anthropic said it had instituted strong safeguards to mitigate such behavior.

**But what that oversight is missing is** the reams of AI models that have already been released into the wild. Yes, they may not be the fanciest of systems. But from how Google serves up search results to how TikTok ranks online content to how Amazon splices e-commerce queries, all of these online services are now driven by underlying AI systems that equally need to be held to account.

**Policymakers have built a governance ethos** and infrastructurearound frontiermodels. What they haven't done is do the same for the AI systems that determine what people see, buy and interact with. Those are still treated as separate problems of platform regulation, consumer protection and administrative law.

**This is what I'm calling operational AI governance.**

Thanks for reading Digital Politics. If you've been forwarded this newsletter (and like what you've read), please sign up [here](https://www.digitalpolitics.co/newsletter058/#/portal/). For those already subscribed, reach out on digitalpolitics@protonmail.com

**That term can be used to describe how companies** implement in-house AI policies. But I'm using it more broadly to describe public-interest oversight of already deployed AI systems whose rankings, recommendations and automated decision-making already affect people. 

**It builds on existing work around algorithmic** accountability. But the concept reflects a change in both scale and character. AI systems now power different parts of digital services, and companies routinely tweak the models, data and objectives behind them. It's no longer about auditing "an algorithm." It's about unpicking interconnected AI systems that are the engine behind the online world.

**Operational does a lot of heavy-lifting in this definition.** It refers to how the world is already flooded with all forms of artificial intelligence — and how most of these systems are opaque to outsiders and already have real-world consequences. 

**That includes how automated decision-making** systems in the Netherlands, more than a decade ago, [incorrectly profiled](https://europeanaifund.org/newspublications/how-ai-driven-welfare-systems-are-deepening-inequality-and-poverty-across-europe/?ref=digitalpolitics.co) individuals applying for childcare benefits that reinforced biases related to race, ethnicity and alleged benefits fraud. It relates to the [string of US lawsuits](https://www.pbs.org/newshour/nation/a-new-mexico-judge-ordered-new-child-safeguards-for-meta-advocates-hope-other-courts-follow?ref=digitalpolitics.co) (more on the recent Meta settlement below) that raised concerns about how AI-powered content recommender systems displayed harmful and explicit content to children. It is baked into the European Commission's [recent $230 million fine](https://ec.europa.eu/commission/presscorner/api/files/document/print/en/ip%5F26%5F1178/IP%5F26%5F1178%5FEN.pdf?ref=digitalpolitics.co) against Temu over how European consumers were displayed illegal goods via the Chinese e-commerce giant's AI-enabled search results.

**Traditionally, these examples would fit somewhere** between consumer protection and platform governance. But as AI systems have steadily taken over the back-end of almost all digital services, there is now a disconnect between how policymakers define what they see as consumer-facing goods and what is happening within companies as they optimize internal procedures to take advantage of increasingly powerful AI tools.

**This isn't technically a new concept. AI researchers** [have been calling](https://www.nature.com/articles/d41586-023-02094-7.pdf?ref=digitalpolitics.co) for years for a focus on short-term harms associated with large language models instead of the existential risk associated with [artificial general intelligence](https://en.wikipedia.org/wiki/Artificial%5Fgeneral%5Fintelligence?ref=digitalpolitics.co) (aka: the SkyNet dilemma.)

**But what is missing is a reframing among** the regulatory, policymaking and (non-AI) research communities — and I put myself in that bucket — toward the concept of operational AI governance. It's less about everyone becoming AI experts. It's more about acknowledging that all digital services are now AI-powered, and that has to become embedded in the types of required oversight.

**Part of this is about infrastructure.** For those seeking to govern next generation AI models, there's a growing cottage industry of funders, institutions and research institutions dedicated to protecting against harm created by these latest releases. Yet within the operational AI governance world, there's still a lack of similar infrastructure (and, ahem, funding) to keep pace with how less-advanced AI systems are out in the wild, potentially causing harm. 

**That is because so-called platform governance**, or efforts to quell problems on social media, has fallen out of fashion. Funders, government bodies and researchers are pivoting away to protect themselves against attacks from the US government, which claims (incorrectly) that such oversight is an [illegitimate attack on free speech](https://www.whitehouse.gov/presidential-actions/2025/01/restoring-freedom-of-speech-and-ending-federal-censorship/?ref=digitalpolitics.co). Confronted with these claims, many have turned to less politically-sensitive topics like [online fraud](https://about.fb.com/news/2026/03/fighting-scammers-protecting-people-with-new-technology-and-partnerships/?ref=digitalpolitics.co).

**But for officials and lawmakers still eager** to dip their toes into social media oversight — especially when it comes to [kids' online safety](https://www.digitalpolitics.co/social-media-bans-platform-liability-2026/) — to approach such policymaking without framing it via operational AI governance would be like trying to referee a football match blindfold. You could probably do it. But it would not lead to good outcomes.

**So, too, must regulators stop distinguishing** online safety rules from AI governance. That's a hard one as many of these agencies in countries across the European Union, as well as in the UK and Australia, have specific mandates that include the former, but not the latter. But as platform governance [shifts](https://www.digitalpolitics.co/platform-design-enforcement-un-ai-governance-2026/) toward how these social media companies are designed, regulators can no longer pretend they don't have skin in the AI game.

**Similarly, non-AI researchers who focus on** online safety, consumer protection and other adjacent policymaking areas need a "Come to Jesus" moment. 

**Again, this isn't about cramming for a** PhD in artificial intelligence or jumping on the AI hype-train. Instead, it's rethinking how potential harms are created, at the source, and acknowledging that many of the digital services that we all monitor are not what they once were, even three years ago. Over that short period, AI systems — albeit not as powerful as the latest models — have taken over, and that requires a reappraisal of how we all go about our business.

**Currently, operational AI governance** is happening, but in dribs and drabs via [specific regulatory decisions](https://digital-strategy.ec.europa.eu/en/news/commission-preliminarily-finds-tiktoks-addictive-design-breach-digital-services-act?ref=digitalpolitics.co) or [researcher outputs](https://algorithmwatch.org/en/instagram-algorithm-nudity/?ref=digitalpolitics.co). 

**What's needed isn't a fundamental reworking** of existing platform governance and consumer protection. Instead, we need to be honest with how much everyday AI systems have eaten the digital universe — and how that step change needs to become a core principle in how these platforms are policed worldwide. 

---

## Chart of the week

**Across the EU's five most populous** countries and the UK, just under three-quarters of those polled by YouGov would support an Australia-style social media ban for kids.

**The one outlier in Poland where only** 53 percent of adults said they would back such a moratorium.

**Across all age groups, however, the concept** of an Aussie-style ban was still highly popular. Though it's also true that YouGov did not survey teenagers about how they would feel about such proposals.

![](https://storage.ghost.io/c/df/80/df8046d2-bf27-4315-9b97-ced0ef736260/content/images/2026/08/Untitled-2-3.jpg)

Source: YouGov's [European Political Monthly](https://yougov.com/articles/54429-most-europeans-in-six-countries-support-banning-social-media-for-under-16s?ref=digitalpolitics.co)

---

## META JUST BECAME A DE FACTO RULEMAKER

**FOR A COUNTRY WITH NO COMPREHENSIVE** federal law governing kidsonlinesafety rules, the US just scored a doozy against Meta. In a landmark settlement and consent judgment, Meta agreed to pay up to $18 billion to 48 US state attorneys general over allegations that its Facebook and Instagram services may have caused harm to children (see [here](https://www.wsj.com/tech/meta-reaches-18-billion-settlement-with-48-states-over-child-safety-claims-cf725a2b?ref=digitalpolitics.co), [here](https://www.nytimes.com/2026/08/26/technology/meta-settlement-social-media-addiction-lawsuit.html?ref=digitalpolitics.co), [here](https://www.techpolicy.press/whats-in-metas-teen-social-media-settlement-and-what-hinges-on-its-rivals/?ref=digitalpolitics.co), [here](https://portal.ct.gov/ag/press-releases/2026-press-releases/settlement-with-meta?ref=digitalpolitics.co) and [here](https://oag.dc.gov/release/attorney-general-schwalb-announces-meta-will-pay?ref=digitalpolitics.co).) 

**The Big Tech giant did not admit fault.** But the 10-year settlement — whose payout equated to just a little less than Meta's [quarterly net income](https://investor.atmeta.com/investor-news/press-release-details/2026/Meta-Reports-Second-Quarter-2026-Results/default.aspx?ref=digitalpolitics.co) — is a clear example of how platform governance is shifting toward how these services [are designed](https://www.digitalpolitics.co/platform-design-enforcement-un-ai-governance-2026/).

**There's a lot to the settlement.** Under the agreement, Meta will pay roughly $12 billion in payments to the affected US states over the next decade. It will institute a daily two-hour limit across its apps (with pauses after 15 minutes of continuous use, and further pauses at 60 and 90 minutes) for children. It will block access to social media feeds for minors overnight. It will also silence notifications over roughly the same period, and stop weekday push notifications during the school day. 

**Other commitments include stronger age assurance** checks, mostly to determine which users are children; greater parental controls, including the ability to turn off algorithmic-powered feeds; and a limit on some beauty filters. 

**Yet as I reread the** [**settlement**](https://storage.courtlistener.com/recap/gov.uscourts.cand.401490/gov.uscourts.cand.401490.3447.1.pdf?ref=digitalpolitics.co)**, the more confused I became.** 

**What Meta has agreed to is significant.** But the negotiated deal also includes a second level of commitments — so long as Meta's corporate rivals also agree to the same kid-focused online protections.

**This is the unusual part. Meta accepted** a baseline set of rules for Facebook and Instagram. But it also negotiated a second phase of design changes that apply if Snap, TikTok and YouTube also become bound by equivalent kid-focused safety obligations. If that happens, Meta will pay an additional $5 billion, tighten its own time-management rules on its apps, and gain what it wants more than anything else: a level playing field with its bitter rivals. 

**Importantly, the agreement also contains a so-called** "Most Favored Nation" provision. If a settling US state, for instance, later gives Snap, TikTok or YouTube more favorable terms over comparable kids safety claims, Meta can require that state to modify the company's comparable obligations to match them accordingly. 

**In essence, Meta, which agreed to** up to $18 billion in payments and a flurry of design changes in the name of children's online safety, has helped negotiate a potential de facto rulebook for kids-focused social media in the US. Its negotiated deal — and the incentives that come with it if YouTube, Snap and TikTok agree to equivalent design changes — may become the standard for how minors use these platforms for potentially the next 10 years across the US. 

**That means Meta's willingness to, say,** silence notifications for children between 10pm and 7am may also become what YouTube institutes in the future. Similarly, Meta's expanded age assurance provisions might be accepted by TikTok. And if Snap, at some point, reaches a more favorable settlement over similar kids' online safety claims, then Meta has the right to rewrite its own deal to match that of its rival.

**None of these platforms may agree** to such changes. But the financial and design incentives built into the agreement if Meta's rivals agree to the same safeguards give US state attorneys general a significant stick to whack other social media companies to fall in line. 

**This isn't necessarily a bad thing.** 

## Sign up for Digital Politics

Thanks for getting this far. Enjoyed what you've read? Why not receive weekly updates on how the worlds of technology and politics are colliding like never before. The first two weeks of any paid subscription are free.

Subscribe 

Email sent! Check your inbox to complete your signup. 

No spam. Unsubscribe anytime.

**As the recent New Mexico ruling, also involving Meta,** [outlined](https://www.digitalpolitics.co/platform-governance-limits-transatlantic-data-privacy-framework-2026/), these platforms are in ongoing competition with each other. As much as platform governance is important, it must be weighed up against other issues, including the ability for all companies to be treated the same under the law. Much of the recent settlement's provisions are also good practice. If there's an industry-wide push to reduce children from seeing harmful content online, then I'm all in.

**For me, the oddity is not that US states extracted** concessions from Meta. It's that they allowed the Big Tech giant, which was accused of creating harms for children online, to participate in defining the competitive conditions under which those concessions could spread across the industry. 

**In the absence of federal legislation,** this multi-state settlement with Meta has become a possible route to US-wide social media governance. And it's true that Meta did not write these rules alone. It did so with US states. But the settlement gave the tech company a seat at the table, a financial incentive to US states for competitors to adopt the framework and contractual protections for Zuck & Co against being left behind if rivals secured a better future deal. 

**That may keep kids safer online.** It may even be a pragmatic response to how teenagers split their time between rival platforms. But, let's be clear: it's an unusual way to make digital policy. 

**Typically, the alleged source of harm does not** get to negotiate a potential industry benchmark. Nor does it get to rewrite its landmark settlement if a competitor later receives a less harsh outcome.

---

## What I'm reading

**— Ofcom, the UK online safety regulator, outlined** its approach for ensuring digital platforms comply with its supervision and compliance obligations. More [here](https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/our-approach-to-online-safety-supervision-and-compliance?ref=digitalpolitics.co).

**— Oliver Patel explains how China is gradually** building up one of the world's most advanced AI governance structures. More [here](https://www.linkedin.com/posts/oliver-patel%5Fchina-is-quietly-developing-one-of-the-world-share-7497995145691303937-%5FP2z/?utm%5Fsource=share&utm%5Fmedium=member%5Fios&rcm=ACoAAATsaZ8BQ5eV2dLTB4ajT1y1P-2vC9wlPbU).

**— Meta published its now twice-yearly threat report**, including details on financial scams and coordinated inauthentic behavior on its platforms. More [here](https://transparency.meta.com/sr/H2-2026-adversarial-threat-report/?ref=digitalpolitics.co).

**— The Union of Concern Scientists** and the Association of Computing Machinerypublished separate open letters in support of the ability of academics to publish research without fear of intimidation. More [here](https://www.acm.org/about-acm/statement-on-academic-freedom-and-scientific-collaboration?ref=digitalpolitics.co) and [here](https://blog.ucs.org/guest-commentary/protecting-science-from-government-intimidation/?ref=digitalpolitics.co).

**— France's Mistral announced that it would host** third-party open-weight models on its platforms, including those from China. More [here](https://mistral.ai/news/regional-inference-open-models-new-compute/?ref=digitalpolitics.co).

---