Executive summary
Major technology platforms have built significant public-policy and trust-and-safety infrastructure over the past five years: billions of dollars, hundreds of policies, and billions of content decisions each quarter. Taken together, this is the largest private-sector governance experiment in history. Yet the dominant model remains reactive — platforms detect and remove harms that have already occurred, and rarely prevent the conditions that produce them. This brief surveys what platforms are doing, weighs the evidence, and applies a strategic-foresight lens to locate the preventive-governance gap and what closing it would require.
1. What platforms are doing now
Between 2020 and 2026, the major platforms — Meta, TikTok, Google, YouTube, Microsoft, OpenAI — invested at scale in four policy domains: content enforcement, transparency, election integrity, and AI governance. What follows is a factual survey grounded in the platforms' own disclosures and independent assessments.
Content enforcement is the largest of the four, and its scale is unprecedented in the history of private governance.
Source Meta Q1 2025 Enforcement Report; TikTok Newsroom; industry layoff trackers.
| Platform | Key enforcement actions (2024–2026) | Source |
|---|---|---|
| Meta | In Q1 2025, Meta acted on 1 billion fake Facebook and Instagram accounts, up from 631 million a year earlier. Hateful-conduct removals fell from 7.4 million to 3.4 million after a January 2025 policy shift reducing automated enforcement. | Transparency Center H1 2026; Q1 2025 Enforcement Report |
| TikTok | In 2024, TikTok removed over 500 million videos for community-guideline violations and spent over $2 billion on trust and safety, committing a further $2 billion for 2025. Automation drives over 80% of removals; EU automated-moderation accuracy reached 99.1% under DSA reporting. | TikTok Newsroom; NY AG ToS Report |
| Google / YouTube | Election-integrity work spans 200+ elections since 2020; YouTube reduced recommendation of borderline content from 2019. In February 2024, twenty AI companies signed the Munich AI Elections Accord, pledging watermarking, metadata tagging, and AI classifiers. | Google Public Policy; Brennan Center 2025 |
Key finding
Meta's January 2025 rollback of automated moderation — halving hateful-conduct removals — is the most significant reversal of platform safety infrastructure since the 2017 Myanmar crisis. Amnesty International and civil-society researchers have flagged it as a possible precursor to harm in fragile political contexts. This is a live prevention failure in progress.
Content actioned per quarter (millions)
Source Meta Community Standards Enforcement Report, Q1 2024 and Q1 2025.
Transparency reporting has become the most institutionalised form of accountability, mandated in the EU under the Digital Services Act (DSA) and extended voluntarily to other markets.
| Domain | Current state of practice |
|---|---|
| Transparency reports | Meta publishes semiannual integrity reports, quarterly enforcement reports, and government data-request disclosures; TikTok produces quarterly enforcement and DSA-specific European reports. Meta's independent Oversight Board has issued 326 recommendations, with Meta committing to implement or explore 80% as of end-2025. |
| DSA compliance (EU) | TikTok's DSA reporting covers proactive removals (18 million pieces in H2 2024), Trusted Flagger reports, and AI-content labelling. Zero-view removals — content taken down before anyone sees it — reached 90% for civic and election-integrity violations in H1 2025. |
| AI content provenance | TikTok became the first platform to implement C2PA Content Credentials, letting AI-generated content from other platforms be identified and labelled automatically — the leading edge of preventive AI governance. |
| The critical gap | A March 2026 UK parliamentary session found that platforms 'react without looking forward.' The Online Safety Act 2023 does not require prospective risk assessment for systemic harms to civic discourse or public health. Transparency is retrospective; prevention is not yet mandated. |
Elections are the clearest convergence of platform power and democratic risk. Platforms have invested more in election integrity than in any other public-good domain, and the evidence on effectiveness is mixed.
| Dimension | Evidence |
|---|---|
| What platforms built | TikTok applied its playbook across 200+ elections since 2020, banning nearly 3,000 impersonation accounts in H1 2025; Meta introduced Community Notes in the US in Q1 2025; Google and YouTube provide election information panels across 100+ countries. |
| The AI elections accord | In February 2024, twenty companies signed the Munich accord, committing to watermarking and metadata tagging, risk assessment of models, and removal of deceptive AI election content. The Brennan Center's 2025 review found progress on tools but insufficient public evidence of effectiveness. |
| What the evidence shows | The January 2025 replacement of professional fact-checking with Community Notes removed a layer of verification just as AI-generated disinformation began to scale — a compound risk with no clear institutional owner. |
| The prevention gap | No platform conducts prospective scenario analysis of election risk. Safety remains reactive: detect the deepfake, remove the campaign. The preventive equivalent — designing platforms so these harms cannot scale — is not yet a systematic practice. |
2. The preventive governance gap
Across all four domains the same structural signature appears: investment optimised for detection and response, not anticipation and prevention. This is the exact problem the Prevention Architecture was built to diagnose.
The prevention paradox in platform governance
Platforms know that certain design and algorithmic choices will produce harm — the research on engagement-maximising amplification is not seriously disputed — yet they systematically underinvest in changing the conditions that produce harm and overinvest in cleaning it up afterward. This is the platform-specific form of the institutional prevention paradox.
- 1DesignRanking and amplification choices set the conditions for harm.
- 2DeployFeatures ship without prospective harm modelling.
- 3PropagationHarmful content scales through the recommendation system.
- 4DetectionAutomated systems flag content already circulating.
- 5RemovalThe item is taken down — the harm has largely occurred.
- 6ReportingVolumes are disclosed after the fact.
- 1DesignRanking and amplification choices set the conditions for harm.
- 2DeployFeatures ship without prospective harm modelling.
- 3PropagationHarmful content scales through the recommendation system.
- 4DetectionAutomated systems flag content already circulating.
- 5RemovalThe item is taken down — the harm has largely occurred.
- 6ReportingVolumes are disclosed after the fact.
Source The Prevention Lab, after the Prevention Architecture.
Each of the seven pillars of the Prevention Architecture maps to a specific failure mode in current platform governance — and to the investment that would close it.
| Pillar | Platform failure mode | What prevention requires |
|---|---|---|
| Strategic awareness | Extensive harm-detection systems, but no systematic horizon scanning for emerging risk types, so synthetic media and novel influence techniques are caught after deployment, not before. | Structured horizon scanning for emerging threat types, published as a public good in the manner of the OECD's strategic-foresight work. |
| Political / commercial incentives | Engaging content generates more revenue and tends to be emotionally activating, which correlates with harm; no platform has redesigned its core model around public-benefit metrics. | Independent measurement of harm externalities, akin to environmental-impact accounting; mandates for algorithmic impact assessments that include revenue-harm tradeoffs. |
| Institutional capacity | Trust-and-safety teams have been cut across the sector since 2022 — 40,000+ tech layoffs fell disproportionately on safety and policy roles. TikTok's $2 billion a year is the exception. | Minimum staffing ratios for trust and safety relative to platform scale; the DSA's systemic-risk-assessment duty is a partial model. |
| Financing | Safety is treated as a cost centre, not an investment with measurable social return; no platform publishes a cost-benefit analysis including external costs to democracy or mental health. | A platform harm-accounting standard, analogous to ESG reporting, that quantifies the social costs of unsafe design and the returns on prevention. |
| Public legitimacy | Platform policy decisions lack democratic mandate; even Meta's Oversight Board is limited to individual content decisions, not systemic design. | Genuine co-governance including civil society, affected communities, and independent researchers in policy design — not post-hoc consultation. |
| Technology | AI is both the problem (generating synthetic harmful content at scale) and the proposed solution; the current equilibrium is an arms race with no clear owner. | Mandatory adoption of C2PA and equivalent content-provenance standards; open-source detection tools for smaller platforms. |
| Implementation | Even good policies are applied inconsistently and without meaningful external audit; the DSA's dispute system received only 173 appeals in H2 2024 — access, not near-perfect enforcement, is the likelier explanation. | Standardised, independent auditing of moderation decisions with comparable metrics across platforms — the equivalent of financial-audit standards. |
3. Four futures of platform governance
Four plausible futures for platform public policy can be sketched for the 2026–2035 horizon. These are not predictions but structural scenarios, designed to surface the decision points at which the trajectory can still be shaped. Each answers the core question differently: who is responsible for harm that platform design makes predictable?
Fragmented compliance
The DSA sets the high-water mark; adoption elsewhere stays inconsistent. Reactive, regional, asymmetric — the current trajectory. Prevention outlook: low.
Anticipatory breakthrough
A major crisis generates political will; forward-looking risk assessment and independent audits become mandatory. Prevention outlook: high.
Power concentration
Safety is subordinated to political alignment as AI outpaces regulation. Prevention outlook: very low.
Distributed governance
Interoperability and open standards redistribute authority to auditors, researchers, and communities. Prevention outlook: high, with transition risk.
Source The Prevention Lab. Positions are indicative, not predictive.
| Scenario 1 · Fragmented compliance | The current trajectory — reactive, regional, asymmetric |
|---|---|
| Narrative | The EU's DSA becomes the global high-water mark, but adoption elsewhere stays inconsistent and contested; platforms comply in Europe while operating under lighter regimes at home, and voluntary accords multiply without verifiable outcomes. |
| Prevention outlook | Low. Compliance frameworks are backward-looking; the DSA's systemic-risk assessments are self-reported and unverified. |
| Decision point | Whether the DSA's systemic-risk requirement evolves into genuine prospective harm modelling or remains a compliance checkbox. |
| Scenario 2 · Anticipatory governance breakthrough | High-value, lower-probability — prevention becomes a mandate and an advantage |
|---|---|
| Narrative | A major platform-enabled crisis in a large democracy generates the political will for a systemic shift: forward-looking risk assessment becomes mandatory, independent systemic-harm audits are required, and one or two platforms adopt prevention as a competitive differentiator. |
| Prevention outlook | High. The shift from reactive compliance to anticipatory governance closes the structural gap — the equivalent of moving from treatment to public health. |
| What it requires | Frameworks that reward prevention rather than only punishing detected harm; independent harm-accounting standards; multi-stakeholder co-governance; board-level accountability for prevention. |
| Scenario 3 · Platform power concentration | A risk scenario — safety retreats under geopolitical and commercial pressure |
|---|---|
| Narrative | Fragmentation accelerates, safety investment is subordinated to domestic political alignment, AI capability outpaces both regulation and safety infrastructure, and the arms race between synthetic content and detection tilts toward generation. |
| Prevention outlook | Very low. The capacity for prevention is eroded by commercial, political, and geopolitical pressure at once. |
| What prevention requires | Civil society, academia, and international institutions maintaining independent monitoring capacity as internal platform governance weakens. |
| Scenario 4 · Distributed governance | A structural shift on the 2030+ horizon — authority redistributed to institutions and users |
|---|---|
| Narrative | Interoperability mandates and open moderation standards disaggregate platform authority, letting auditors, researchers, and communities share in governance, supported by public-interest detection infrastructure modelled on public-health surveillance. |
| Prevention outlook | High in the long run, with high uncertainty in transition; community-controlled moderation has stronger accountability but risks coordination failure. |
| Key enabler | C2PA Content Credentials, already implemented by TikTok, as the technical foundation for distributed provenance. |
4. A preventive governance agenda
The question is not whether platforms will govern; they already do. It is whether they will govern preventively — designing conditions that reduce harm before it occurs — or reactively — removing harm after it has propagated. The evidence through 2026 points to the latter, and the foresight analysis suggests the window for a preventive shift is narrowing.
| Scale what works | In practice |
|---|---|
| Zero-view enforcement | Adopt TikTok's 90% zero-view removal for civic-integrity violations as a target metric across high-risk categories, with public reporting. |
| C2PA content provenance | Make TikTok's first-mover implementation a minimum standard; mark all AI-generated content with interoperable provenance, and build C2PA into AI APIs by default. |
| Independent oversight boards | Extend the Oversight Board model from 'was this decision correct?' to 'is this policy designed to prevent harm?', and establish equivalents at other platforms. |
| Election-integrity playbooks | Publish TikTok's documented playbook as a shared methodology and extend it to non-electoral civic events. |
| Systems-level transparency | Move from output counts to reporting on how recommendation systems shape the information environment and what the harm externalities of engagement-maximising design are. |
| What platforms are not yet doing | What it requires |
|---|---|
| Prospective harm modelling | Scenario-based risk assessment before features ship, as pharmaceutical, financial, and nuclear-safety regulation already require; the OECD's 2024 anticipatory-governance framework supplies the method. |
| Platform harm accounting | A quantified, published assessment of the social costs design imposes, analogous to environmental-impact accounting, so prevention investment shows a social return. |
| Chief Prevention Officer | A proactive, foresight-oriented function with board-level accountability, on the model of the Chief Risk Officer role that became standard after 2008. |
| Cross-platform prevention commons | Extend the GIFCT's threat-sharing to AI-generated disinformation, with a permanent, independent multi-stakeholder secretariat. |
| Independent monitoring | Public investment in research infrastructure with guaranteed data access, since self-reported transparency cannot substitute for external audit at scale. |
5. Conclusion: the prevention curve applied
The Prevention Curve holds that the cost of managing a crisis rises exponentially as the window for preventive action narrows. Applied to platforms, the cost of designing safer systems at the architecture stage is a fraction of the cost of managing the harms that unsafe design produces at scale. The Myanmar crisis, which Amnesty International found Meta substantially contributed to, cost thousands of lives and billions in humanitarian response; the investment required to design Facebook differently there before 2017 would have been a small fraction of that.
What makes this urgent in 2026 is that AI-generated content is compressing the timeline. The interval between a new harmful capability and its deployment at scale — months or years in the social-media era — is now weeks or days. That compression is what makes the reactive model structurally inadequate and the preventive model structurally necessary.
The platforms that will be most valuable over the next decade — commercially, politically, and socially — are those that build the capacity to identify and address harm before it scales. That requires not just better detection but a redesign of the governance architecture: from reactive compliance to anticipatory governance, and from trust and safety as a cost centre to prevention as a strategic investment.
The preventive governance agenda
Scale immediately: zero-view enforcement targets · C2PA provenance across platforms · extended oversight-board mandates · shared election-integrity playbooks · systems-level transparency. Build over five years: prospective harm modelling · a platform harm-accounting standard · a Chief Prevention Officer function · a cross-platform prevention commons · independent monitoring infrastructure. The core question is not how to remove harm after it occurs, but how to design institutions and incentives so that harm is less likely to occur at all. That agenda is, as yet, largely unbuilt.