AI Safety

New EU Toolkit Makes Big Tech Prove It Isn't Harming Your Rights

This could force TikTok, Google and Facebook to show their homework on your rights.

Deep Dive

Europe has a rule called the Digital Services Act (DSA). It says that the biggest platforms — the ones you almost certainly use, like Google, TikTok, Instagram and Facebook — must look for ways their services could harm people's basic rights, such as privacy, free expression or protection from discrimination. They must also fix those harms, and outside auditors must check their work. The problem: nobody agreed on exactly how to do that check. The law said "assess the risks" without explaining how, so results were vague and hard to compare.

A team of seven researchers, led by Marie-Therese Sekwenz and Till Winkler, built a solution: a decision-tree toolkit. A decision tree is simply a flowchart of yes-or-no questions that keeps branching until you reach a conclusion — like a choose-your-own-adventure book for auditors. Instead of vague promises, the auditor clicks through questions about which part of the platform is being examined, who might be affected, what right is at stake, and how serious the harm is. One smart twist: the toolkit treats vulnerability as a situation, not a label. Rather than asking "is this person a vulnerable user?", it asks how a particular feature or dependency pushes people into a vulnerable position. That matters, because a design choice can make anyone vulnerable in the right circumstances.

The team also made every judgment traceable. Each decision records which right was affected, how it was interfered with, and whether there was a good justification — the same logic a court would use. They tested the framework in three workshops with 4, 11 and 20 experts, using two made-up user scenarios. The catch is honest and important: this is a research method, not a law or a regulator. Platforms still write their own reports, and a tidy checklist doesn't guarantee anyone tells the truth. But it does make lying harder to hide, and harder to get away with.

Key Points
  • The EU already requires the biggest apps and search engines to review whether they harm your rights — but never said how, so reports were fuzzy.
  • This new toolkit is a flowchart of yes/no questions that guides auditors from 'which feature?' to 'how serious is the harm?' and forces them to write it down.
  • It reframes vulnerability as something a design can create, not a fixed label stuck on certain groups of people.

Why It Matters

Stronger, comparable audits could mean real fixes when big platforms quietly hurt privacy, speech or fairness.

📬 Get the top 10 AI stories daily