The European Commission has launched formal enforcement action against TikTok, concluding that the platform's design and account settings place children at unacceptable risk and contravene protections established under the bloc's landmark Digital Services Act. In a statement released on July 24, the regulator outlined a series of structural failings in how the Chinese-owned company, operated by ByteDance, manages accounts belonging to minors across its user base of more than 200 million Europeans.

At the heart of the commission's case lies a fundamental architectural problem: TikTok permits children to maintain public-facing accounts by default, meaning any internet user—including those without their own TikTok account—can access and view content posted by minors. This visibility creates a direct pathway for potential malefactors seeking to initiate contact with vulnerable young people, and simultaneously makes the shared content available for harassment and cyberbullying by other users. The regulator argues this design choice represents a basic failure to embed safety into the platform's foundation, rather than treating protection as an afterthought.

Compounding this concern is TikTok's algorithmic system, which actively promotes content created by teenagers aged 16 and 17 to broader audiences through its recommendation engine. By amplifying teenage creators' posts, the platform exponentially increases their exposure while simultaneously normalising their visibility within the wider user community. The commission also identified a secondary vulnerability in how TikTok structures its discovery mechanisms, allowing supposedly private accounts to be located and accessed with relative ease, further undermining the privacy protections that such settings purport to offer.

European Commission Vice President Henna Virkkunen framed the enforcement action as an essential assertion of protection standards that should not require parental intervention or conscious opt-in by users. She emphasised that the Digital Services Act mandates platforms build safeguards directly into their operational design from inception, not as optional features. This philosophical stance reflects a broader shift in how European policymakers view corporate responsibility toward children online—moving away from a model where companies sell safety as a premium upgrade, and instead demanding it become the baseline experience.

The timing of this investigation reflects a gathering momentum within the EU toward comprehensive restrictions on children's social media access. In February, the same commission had already published separate allegations concerning TikTok's potential to encourage addictive behaviour through its algorithmic feed and design choices. That earlier finding fed into ongoing parliamentary debates about establishing a statutory minimum age for social media use across member states, with several countries now considering national legislation to restrict younger children's platform access entirely.

France has emerged as the first EU member to codify such restrictions through legislation, with parliament passing a law by substantial majority on July 21 that prohibits children under 15 from using social media platforms. The French measure provides a working model for other nations considering similar approaches, and signals that the conversation has shifted from voluntary industry compliance toward hard legal boundaries. Commission President Ursula von der Leyen has previously voiced support for age-based restrictions, suggesting that such measures could gain broader EU-level support.

TikTok now faces a formal opportunity to respond in writing to the commission's allegations before any final enforcement decision. Should the regulator ultimately determine that the platform has violated EU law, the consequences carry significant financial weight. The commission possesses authority to impose fines representing up to six per cent of the company's global annual turnover—a calculation that could translate into hundreds of millions of euros given ByteDance's substantial international revenue. This penalty structure represents the EU's most potent regulatory tool short of ordering a service suspension, and has proven effective in compelling compliance across the technology sector.

The platform's response has so far emphasised its existing safeguarding infrastructure, with TikTok representatives highlighting that teenage accounts include more than 50 pre-configured privacy and security features automatically enabled upon account creation. The company further notes that younger teenagers on its platform cannot utilise direct messaging functionality—a significant distinction from many competitors that permit unrestricted one-to-one communication. These defences suggest TikTok will argue that it has adopted reasonably robust protections, even if the commission contests whether they satisfy the Digital Services Act's standards.

For Malaysian policymakers and parents, the EU's enforcement action carries particular relevance given TikTok's extraordinary popularity throughout Southeast Asia and among Malaysian youth specifically. While Malaysia has not yet pursued age-based restrictions comparable to France's approach, the EU's regulatory findings and the underlying evidence of design flaws merit serious attention from local authorities and platform governance specialists. The commission's detailed examination of how algorithms amplify minor creators' content and how public-by-default settings create vulnerability offers a comprehensive analysis applicable across jurisdictions.

The investigation also underscores a growing international divergence in how governments approach technology regulation, with the EU adopting an aggressive enforcement posture toward platform design, while other regions remain less interventionist. This regulatory divide could ultimately force TikTok and similar platforms to implement differentiated safety architectures across geographic markets—potentially offering stronger protections to European users while maintaining weaker defaults elsewhere. Such fragmentation raises questions about why Malaysian and Southeast Asian children should receive fewer protections than their European counterparts, and whether regional regulators should seek comparable commitments from major social platforms.

Beyond the immediate compliance question, the case reflects deeper tensions about who bears responsibility for protecting children in digital spaces. The EU's framework assigns primary accountability to platforms through design requirements, shifting away from approaches that emphasise parental monitoring or individual user choice. This represents a philosophical statement that certain harms are too severe and exploitation risks too substantial to delegate to parents alone, particularly given power imbalances between technology companies and individual users navigating complex settings.

The commission's action also arrives amid broader scrutiny of TikTok's business practices and governance structures across multiple continents. Regulatory concerns about child safety intersect with geopolitical questions about data handling and content moderation, though the July 24 statement focuses narrowly on minor protection rather than these wider controversies. Nevertheless, the confluence of investigations creates cumulative pressure on the company to demonstrate that it takes young user welfare seriously rather than subordinating it to engagement metrics.