We gratefully acknowledge that the research underlying this paper is part of the Horizon Europe project ‘Reclaiming Liberal Democracy in Europe’ (RECLAIM) (Grant agreement: 101061330), which is funded by the European Union and led by the University of Iceland. The project addresses the implications of post-truth politics for the future of liberal democracy in Europe. However, the views and opinions expressed are those of the authors only and do not necessarily reflect those of the European Union or the European Research Executive Agency. Neither the European Union nor the granting authority can be held responsible for them.
1Ever since 2016, when the ‘Remain’ camp lost the Brexit referendum campaign in the UK and Trump won the US Presidential elections, disinformation has emerged as a ‘problem’ that policy-makers have sought to ‘solve’ through the regulation of digital platforms. In the EU (see Tuñón et al., 2025), the European Commission established the High-Level Expert Group (HLEG) on Fake News and online disinformation in January 2018. This partially led to the first Code of Practice on Disinformation, signed in October 2018 by several online platforms on a voluntary basis. Much of this work was run on the grounds that the EU should prepare itself in the run-up to the 2019 European Parliament elections. Once the critical moment of the 2019 European elections had passed, the first von der Leyen Commission (2019-24) – in the context of the COVID-19 pandemic – developed the European Democracy Action Plan (EDAP, December 2020) and included the fight against disinformation as one of the four pillars. The EDAP was a milestone in the European approach to disinformation, providing the backbone for policies in this area until 2024. During this time frame, the EU approved a series of legislative initiatives touching upon the regulation of digital platforms, the most prominent of which are the Digital Services Act (DSA) and the Digital Markets Act (DMA).
2We are interested in the role of the stakeholders that were involved in this regulatory process, primarily focusing on the HLEG, the two versions of the Code of Practice on disinformation and the DSA. Regarding disinformation, rather than defining processes to distinguish between what is ‘true’ and what is ‘fake’, the DSA aims at making social media companies more transparent and accountable for the content that circulates on their platforms and the algorithms that prioritise it. However, interestingly, the current emphasis on digital sovereignty has not resulted in stronger decision-making capacity by public authorities. Contrary to the initial responses of the major member states such as France and Germany (Griffin, 2022), the EU’s response in the DSA has not strengthened public authorities’ ability to remove disinformation but promoted ‘co-regulation’ and out-of-court solution mechanisms (Buri & van Hoboken, 2021). The regulation of disinformation has thus made the EU more cooperative with – and probably also more reliant upon – Very Large Online Platforms (VLOPs), actors who have been very active in terms of lobbying (Tarrant & Cowen, 2022; Wolfs & Veldhuis, 2023).
3Such regulation is taking place in the context of increasing European Commission entrepreneurship in the digital sphere (Bradford, 2020; Datzer and Lonardo 2022; Hoeffler & Mérand, 2024), and a broader emerging field of practices that involves Big Tech as business lobbyists, civil society, and other competitors. We argue that the DSA represents the second best preferred regulatory option by Big Tech and that it does not fundamentally address the structural underpinnings of disinformation on social media platforms. The EU's online disinformation co-regulatory response is an example of the platforms’ ‘preemptive’ cooperation strategy (Rone, 2021), whereby they cooperate closely with policy-makers to shape legislation. Analysing how it came to be adopted is particularly interesting at a time when these actors and the US administration have rapidly become embroiled in conflict with the EU. This is important for understanding the extent to which the EU is adopting a new regulatory strategy, for instance with the incorporation of the code of conduct on disinformation (code of practice between 2018 and 2025) into the DSA, as decided in February 2025, – and for evaluating the results of the 2018-2024 disinformation policy based on platform cooperation.
4We focus specifically on the DSA and the Code of Practice on Disinformation (both versions, including the initial in 2018 as well as the 2.0 signed in 2022) because they are the main (co)-regulatory initiatives that the EU has put forward to tackle disinformation. The first Code of Practice on disinformation, signed in 2018, was “the first time worldwide that industry has agreed, on a voluntary basis, to self-regulatory standards to fight disinformation” (European Commission, 2022). In 2022, however, the second version of the Code of Practice on disinformation was framed by the Commission in a different way: “For signatories that are Very Large Online Platforms, the Code aims to become a mitigation measure and a Code of Conduct recognised under the co-regulatory framework of the DSA” (European Commission, n.d.). Thus, interestingly, the DSA breaks away from the EU’s previously dominant approach of self-regulation of digital platforms and disinformation, despite having been drafted in close cooperation with Big Tech companies. Thus, in order to explain this evolution from ‘self-regulation’ to ‘co-regulation’, in this article we ask: How did the EU come to adopt a co-regulatory approach to disinformation? Our main claim is that co-regulation came as a result of actors’ demands, an approach characterised not by the antagonism towards digital platforms, but rather by regulating with them.
5Through an in-depth process-tracing based on public consultation responses, an analysis of Commission meetings, and semi-structured interviews, we contribute to tracing the genealogy of the EU’s ‘co-regulation’ approach to disinformation. We argue that co-regulation sidelines critical discourses challenging the platforms’ business model or non-market alternatives. In doing so, Big Tech platforms are recognised as key actors in an increasingly autonomous field of practice of digital governance (Bouza García & Oleart, 2024). By focusing on the role of actors, we suggest that the success of Big Tech platforms is based on their successful lobbying and preemptive cooperation in Brussels, as they skillfully navigated the field and managed to be conceived as necessary ‘partners’ upon which the success of EU regulation depended.
6During the late 2000s and early 2010s, social media companies were perceived as a key space for democratisation transnationally, amplifying the voices of Arab Spring, Occupy, and Indignados activists that were unable to access institutional communication platforms. However, the numerous questions surrounding Big Tech companies (some of which were triggered by the Cambridge Analytica scandal in 2016) and the disinformation campaigns that have emerged on these platforms means that they are currently struggling to be perceived as being on the side of ‘democracy’. While their reputation has taken a hit, their revenues have continued to increase, and Big Tech platforms have emerged as powerful political players in the EU regulatory sphere thanks to their resources. In fact, tech has become “the biggest lobby sector in the EU by spending, ahead of pharma, fossil fuels, finance, and chemicals” (Bank et. al., 2021).
7In this way, Big Tech has reinforced its political power both through its discursive power in the public sphere and its lobbying activities. The framing power of actors is a key component of their success in EU policy-making (Klüver et al., 2015): policy issues can be framed in different ways, and setting the terms of the debate in the policy process is a key component of lobbying success. Whether the DSA is about ‘algorithmic transparency’ and ‘disinformation’ or ‘capitalism’ and the ‘business model’ of social media companies will result in fundamentally different policy outcomes. The EU’s co-regulatory framework is the result of a successful framing of the ‘problem’ by the platforms. Co-regulation essentially entails striking a middle ground between the initial self-regulatory approach of the EU towards digital platforms and an actual interventionist approach, where public authorities set the rules that the industry has to follow. The idea of co-regulation is not new (Albareda, 2008) and has a long history within EU policy-making (on EU social policy, see Verbruggen, 2009), particularly in the domain of internet regulation (Marsden, 2011). However, it is a new concept in the field of disinformation, even if it entails more continuity than change in the EU’s approach.
8From a Polanyian perspective, it has been argued that the first movement of private social media platforms creating a new market is now countered by a second movement, the EU’s regulatory efforts aimed at regulating these companies (Cioffi et al., 2022). However, this narrative is not entirely straightforward. Despite the EU’s regulatory initiatives, such as the DSA, co-regulation has emerged as a key approach, developed in collaboration between the European Commission and Big Tech companies. Co-regulation might be seen as the overall approach in the case of the DSA (see Neuray, 2024), but it is particularly useful in making sense of the disinformation dimension, primarily addressed through the second version of the Code of Practice on Disinformation and its integration within the DSA.
9As the EU has increasingly focused its regulatory efforts on addressing disinformation, lobbying from tech companies, journalists, civil society, and publishers has become more concentrated at the EU level – the political arena in which the debate over regulating disinformation and the public sphere is unfolding. The literature on the EU’s approach to content moderation and disinformation has highlighted, for example, how the DSA seeks to tackle shadow banning by promoting transparency in content moderation. However, the regulation’s focus on ‘demotion’ practices does not fully address the underlying structural ranking that social media algorithms use when curating content (Leerssen, 2023). While the concrete effects of the DSA on regulating disinformation remain uncertain and will depend on future implementation and enforcement, it is evident that the EU's approach to regulating platforms like Meta or X has been cautious. In fact, the Commission’s role is described in terms such as to “facilitate”, “invite” or “aim to ensure” (see Cauffman & Goanta, 2021, p. 768), signaling the “outsourcing” of EU policy-making to private companies. Crucially, the word “disinformation” does not appear in the DSA other than in the recitals (Ó Fathaigh et al., 2025), which indicates that the preferred way to address it has been through the Code of Practice developed independently (and largely written by the platforms themselves) from the DSA and only later linked to it.
10The concept of ‘co-regulation’ emerges from this cautious approach (see Farrand, 2024). It entails a mandate for platforms to take an active role in combatting harmful content that poses a systemic risk to public discourse and democratic elections. However, the responsibility remains with platforms to define their own policies, often through voluntary adherence to a code of practice. A recent analysis of the EU's disinformation regulation highlights that in the updated 2022 Code of Practice, “persistent transparency-accountability trade-offs were negotiated through non-binding codes subordinate to commercial constraints” (Nannini et al., 2024, p. 1245). Interestingly, in February 2025, the Commission and the European Board for Digital Services endorsed the 2022 Code of Practice as a ‘Code of Conduct’ by. In doing so, “the Code will become a relevant benchmark for determining DSA compliance regarding disinformation risks for the providers of VLOPs and VLOSEs that adhere to and comply with its commitments” (European Commission n.d.). This means that platforms have been pushed by the EU to do ‘something’ against disinformation, but this ‘something’ has been primarily left to the platforms themselves, who were the main drafters of the Code and have shaped it to their convenience.
11The DSA incorporates several requirements for platforms, such as the ‘trusted flaggers’ designated by the national Digital Services Coordinators to detect potentially illegal content and alert the platforms. However, this addition partially outsources content moderation to third parties without necessarily increasing the democratic accountability of platforms (see Appelman & Leerssen, 2022). This suggests that while the new DSA framework introduces some changes, many of the challenges seen in earlier attempts to regulate disinformation persist within the co-regulatory approach. More specifically, the EU’s co-regulation model in the DSA involves a combination of specific obligations for VLOPs, such as the removal of illegal content (including disinformation, where applicable), and a series of requirements such as tracking systemic risks to democracy (also possibly related to disinformation) based on scientific practices. The DSA also mandates increased transparency around algorithms – particularly for users – and encourages platforms to co-define best practices through the Code of Conduct. Additionally, platforms are tasked with monitoring suspicious accounts, although the methods for this are also defined by the platforms themselves.
12A crucial component of the DSA is Article 14, which requires platforms to apply their terms and conditions with “due regard” to fundamental rights, including “freedom of expression” (Article 11 of the EU Charter). This provision ensures that platforms consider fundamental rights when making content moderation decisions, aiming to enhance accountability in their content moderation processes (Ó Fathaigh et al., 2025). However, the DSA does not recognise social media platforms as media with editorial responsibility. Indeed, the DSA maintains the key principle of the 2000 E-commerce directive, the non-liability of platforms for third-party content provided they have no knowledge of its illegal content, adding a duty of care against legal but harmful content. In this sense, the dominant policy frame is that the DSA was ‘an update of the e-commerce directive’, thereby maintaining the principle of non-liability for third-party content and aiming to render illegal activities online that were already illegal offline. This emphasises the continuity of the ordoliberal approach to the EU’s digital regulation agenda (Farrand, 2023).
13The business model of social media companies is rooted in ‘surveillance capitalism’. This logic is oriented towards mass data extractivism and claims “human experience as free raw material for translation into behavioural data” (Zuboff, 2019, p. 8). Within the wider group of Big Tech, social media companies (especially Google and Meta) are more specifically driven by their targeted advertising business model. This model relies on selling personalised ads which, in turn, has taken much of the revenue away from traditional media. Meanwhile, unlike traditional media, the DSA broadly exempts social media platforms from liability for the content that circulates on them. Focusing on Google and Meta’s lobbying role in the DSA, Kausche and Weiss (2024, p. 3) argue that “platforms succeeded in removing the idea of ‘liability’ from the reform agenda and replaced it with the notion of responsibility, which ultimately discharged them from legal obligations”.
14We attempt to explain the European preference for co-regulation as a result of social relations and emerging practices in the field of digital policy. In their endeavour to protect their advertisement-based business model, social media companies have played a crucial role in shaping the definition of disinformation policies at the EU level. The role of business lobbying in EU policy-making is central to make sense of EU policies (Coen et al., 2021). Rather than a process of institutional entrepreneurship (Datzer & Lonardo, 2023), the emergence of digital policies results from the oppositions and alliances within the field of actors lobbying on tech regulation. The European Parliament (EP) and the Council are also relevant, but they play different roles: the member states have had a fragmented approach to disinformation (de Blasio & Selva, 2021) and the Commission has tried to put together a general framework that still allows member states to put forward legislation with different emphases. In turn, the EP has mostly played the role of pushing the Commission to be more ambitious. This also explains our methodological decision to focus on consultations over six years between the Commission and interest groups (see section 3).
15From the EU’s perspective, Big Tech companies seem to understand their platforms better. This contrasts with the more interventionist approach of national responses, such as Germany’s and France’s NetzDG and Avia Laws (de Blasio & Selva, 2021). This explains why these companies engage in preemptive cooperation with the EU because the co-regulatory approach will override most national approaches. In their response to the DSA consultation, Google (2020, p. 7) clearly expressed a preference for a clear distinction between the removal of illegal content and the co-regulation of harmful content at EU level, as opposed to national obligations against both:
“Governance should support the digital Single Market and the country-of-origin principle. We note that the trend towards Member States imposing varying obligations around notifying, detecting, and removing content has caused fragmentation in the Single Market.”
16Furthermore, we see the response to disinformation as part of a wider technology agenda (Ördén, 2020), which includes Media Literacy, Intellectual Property, and Artificial Intelligence (AI). This approach reveals that actors who often see themselves as relatively distant, such as political activists, digital platforms, journalists, foreign policy officials, and institutional experts, are actually working on connected issues and increasingly cooperating and competing with each other in this field.
17We therefore approach EU regulation on disinformation through the relational context of the different approaches of the EU to the online ecosystem (see Gorwa, 2019). There is extensive literature on the phenomenon of disinformation and ‘fake news’, and there have already been attempts to unpack the complex approach to regulate the “digital” in the EU (see Bonnamy & Perarnaud, 2023; Bonnamy, 2024). However, we know relatively little about the specific ways in which different actors compete at the level of EU public policy to regulate Big Tech and, more specifically, disinformation. The normative dimension is inherently embedded in this issue because fighting disinformation is a key part of the Commission’s strategy to defend democracy (Oleart & Theuns, 2023) and is also central to the EU’s geopolitical narrative. In fact, the Commission has championed the DSA as a means of fighting disinformation and ‘protecting’ European democracy.
18This article is part of a broader research project analysing the regulation of post-truth by the EU. Using process tracing, it seeks to understand how the EU regulatory response emerged as a result of actors’ demands and struggles. To accomplish this, the project analyses eight public consultations carried out by the Commission between 2018 and 2024. The main body of evidence for this article is the AAEDR dataset (Bouza García et al., 2025b), which is constituted of stakeholders’ responses to the consultation processes on the eight pieces of regulation from 2018 to 2024 (Figure 1 below), 45 in-depth interviews with stakeholders and EU officials, and evidence about coalition patterns. The rationale for using multiple sources of data in order to triangulate them is that business lobbying is multidimensional. For instance, Meta did not participate directly in the public consultations, but it was very active both in arranging meetings and in the 2018 HLEG. This indicates that some business actors have been very strategic about which forums to participate in directly and under which conditions, often preferring ‘quiet’ politics to submitting responses to public consultations.
Figure 1. The topics and the eight public consultations analysed in the data set
Source: The authors
19Using process-tracing (Beach & Pedersen, 2013), we seek to explain how EU regulatory responses to disinformation result from actors’ demands and struggles. Our analysis sheds light on the issues related to disinformation that have been identified and complements the existing process-tracing perspectives on the DSA (Kausche & Weiss, 2024).
20Responses by interest groups to Commission public consultations are valuable for understanding policy framing and framing power, particularly when studied over time. However, to our knowledge, studies on the EU regulation of disinformation have not used these data. We focus on the demands of actors, studying the emergence of claims, their chronological continuity, adoption by other actors, their transformation, and the eventual disappearance of said claims. A second advantage of working on policy consultations is that it does not require us to identify actors in advance or based on theory. Instead, actors are identified through our empirical work, focusing on those actors that self-selected themselves by submitting a response to the Commission’s public consultation. We analysed all documents from EU level actors (see Table 1 for the classification of actors). and actors in Spain, France, Italy, Ireland, Belgium, Finland, Sweden, Czech Republic, Croatia, and Bulgaria as part of forthcoming national case studies. The result is a total of 167 documents from 160 different organisations. Because of our interest in analysing actors’ struggles over time, we analyse the responses of actors involved in more than one consultation on disinformation regulation.
Table 1. Actors' documents analysed divided by type of organisation
|
Sector
|
Fake news number of documents & % of total contributions
|
DSA number of documents & % of total contributions
|
|
Audiovisual media companies
|
9
|
12,00%
|
8
|
8,70%
|
|
Digital platform companies
|
3
|
4,00%
|
9
|
9,78%
|
|
Editors and associations
|
11
|
14,67%
|
3
|
3,26%
|
|
Factchekers
|
3
|
4,00%
|
0
|
0%
|
|
Federations of journalists & Trade Unions
|
4
|
5,33%
|
2
|
2,17%
|
|
General interests associations
|
11
|
14,67%
|
12
|
13,04%
|
|
Other economic interests groups
|
4
|
5,33%
|
22
|
23,91%
|
|
Other groups
|
14
|
18,67%
|
7
|
7,61%
|
|
Other professional associations and trade unions
|
1
|
1,33%
|
10
|
10,87%
|
|
Other tech interests (manufacturers, operators, users)
|
6
|
8,00%
|
11
|
11,96%
|
|
Regulators
|
1
|
1,33%
|
5
|
5,43%
|
|
Think tanks & observatories
|
8
|
10,67%
|
3
|
3,26%
|
|
Total
|
75
|
100%
|
92
|
100%
|
Source: The authors
21Table 1 above demonstrates that despite a relatively comparable number of selected organisations, the two key consultations on disinformation were very different. The 2018 Fake News consultation attracted a higher number of media outlets, think tanks, journalists, and editors, whereas the DSA’s clearly economic nature is reflected in the significant presence of non-tech economic interests. As for the coding (the codes identified inductively are available in the AAEDR dataset), we adopt a framing perspective. Framing entails both a diagnosis and a prognosis: the ‘problem’ identified leads to a potential ‘solution’ for it. If the ‘problem' is ‘disinformation’, then fact-checking becomes a logical solution. However, if the problem is the role of privately owned social media companies in democratic processes, then the type of solution will necessarily be different. The essence of the framing perspective is the scrutiny of how issues are constructed discursively as actors strategically define issues in particular ways according to their worldview. As Pan and Kosicki argue (2005, p. 177), framing ‘means adopting an interpretive framework for thinking about a political object’. The framing approach is inherently political, given that ‘to study framing is to study power: the power to shape — and distort — public perceptions; the power to promote — or marginalise — competing perspectives on public problems; and the power, therefore, to promote or inhibit the political goals of various societal groups’ (Lawrence, 2010, p. 278). Framing is a relational and dynamic process as frames do not operate in a vacuum, but within a discursive environment where they are in competition with alternative ways of making sense of political objects, such as disinformation. We combine descriptive coding, which aims to understand policy narratives and framing – i.e., what stakeholders speak about – in order to identify themes, diagnoses, and frames, with claims making. This involves making more specific and targeted demands in order to understand what actors demand specifically in terms of policy.
22At the same time, consultations often constitute a preliminary filter for accessing lobbying opportunities (Bouwen, 2002, p. 377, Binderkrantz et al., 2021, pp. 473-474). It is therefore necessary to analyse how framing power and access interact in advocacy strategies. In order to understand how involvement in policy framing translates into agenda-setting power, we also use network analysis to study the Commission cabinet meetings during the drafting phase of the DSA. Finally, we also analyse the existence of collective action patterns by focusing on shared access, i.e., when several organisations meet EU officials simultaneously.
23In January 2018, following the 2016 Brexit referendum and the Cambridge Analytica scandal, the Commission set up the High-Level Expert Group on Fake News and Online Disinformation (HLEG), comprised of a diverse range of actors (see Table 2 below). The HLEG is interesting because it heavily contributed to setting the grounds for EU regulation on disinformation. In its final report, it recommended the establishment of a ‘multi-stakeholder coalition’ to develop a ‘Code of Practice’ with a strong emphasis on ‘fact-checking’, transparency indicators, and improving understanding of algorithms. The report also included long-term recommendations such as media literacy training and improving funding for quality journalism and media in general. The platforms played a crucial role in these recommendations. Initially, the platforms had a clear preference for limited regulation, which was rooted in a supposed “freedom of expression fundamentalism”. This fed arguments about the contribution of platforms to democratisation, as well as arguments about protecting their business model under constitutional protections for speech (Zuboff, 2019, p. 109). Their ability to set the agenda at EU level is expressed in the HLEG final report: “Most of the responses will be of a non-regulatory character and involve a wide range of different stakeholders as government or EU regulation of disinformation can be a blunt and risky instrument.” (European Commission: Directorate-General for Communications Networks, Content and Technology, 2018, p. 19).
Table 2. Members of the HLEG by type of actor
|
Type of actor
|
Number of people
|
|
Academics
|
7
|
|
Journalists
|
7
|
|
Big Tech
|
6
|
|
Fact-Checkers
|
4
|
|
Private media/publishers
|
4
|
|
Public Media
|
3
|
|
Civil Society
|
3
|
|
Trade Unions
|
1
|
|
Other
|
4
|
|
Total
|
39
|
Source: The authors
24As outlined in Table 2, the 39 members of the group were mostly academics, journalists, representatives of Big Tech companies, fact-checkers, private and public media, and civil society actors. Interestingly, there were no representatives from digital rights organisations. The most contentious actor towards Big Tech was Monique Goyens, president of BEUC. She voted against the final report of the HLEG on the grounds that:
“This report contains many useful recommendations but fails to touch upon one of the core causes of fake news. Disinformation is spreading too easily online. Evidence of the role of behavioural advertising in the dissemination of fake news is piling up. Platforms such as Google or Facebook massively benefit from users reading and sharing fake news articles which contain advertisements. But this expert group chose to ignore this business model. This is head-in-the-sand politics.” (BEUC, 2018, March 12)
25Following the HLEG, on 26 April 2018, the Commission published the Communication “Tackling online disinformation: a European approach”, in which it argued in favour of a long-term solution involving “broad stakeholder involvement and the cooperation of public authorities, online platforms, advertisers, trusted flaggers, journalists, and media groups”. This led to the first code of practice on disinformation, agreed in October 2018 with the 2019 EU elections in mind. It defined disinformation as “verifiably false or misleading information”, but “does not include misleading advertising, reporting errors, satire and parody, or clearly identified partisan news and commentary, and is without prejudice to binding legal obligations, self-regulatory advertising codes, and standards regarding misleading advertising.” The 12 pages of jargon in this self-regulatory code indicate the involvement of industry lawyers. In September 2020, the Commission published its assessment of the first Code, arguing that it provided a “valuable framework for a structured dialogue between online platforms and ensured greater transparency and accountability of their policies on disinformation” (Commission, 2022). The first code of practice was initially signed by industry representatives from Facebook, Google, Twitter, Mozilla, and several communications and advertising associations. Later, Microsoft and TikTok also signed the code.
26Conscious of the limits of the first code, and considering the upcoming DSA, the Commission initiated the revision of the code in June 2021. The second version was signed and presented on 16 June 2022. This version of the code was even more technical. It was 40 pages long and included the main digital platforms and advertisers, as well as several civil society actors, such as Alliance4Europe, Avaaz or Reporters without Borders, and fact-checkers such as Newtral, Maldita, and the European Fact-Checking Standards Network. What makes the second version of the Code particular is that, while it was coordinated by the European Commission autonomously from other ongoing regulations, it was ultimately included in the DSA as a ‘co-regulatory’ initiative. When the Code was transformed into a Code of Conduct within the DSA in February 2025, this meant that it was no longer purely self-regulatory. In other words, platforms complying with the Code knew that they were on the right side of regulators, and they also knew that non-compliance could lead to penalties. Although the Commission celebrated it as a way to ‘force’ platforms to abide by some minimal standards, the fact that the processes were overwhelmingly dominated by platform representatives meant that they were the ones essentially creating their own regulatory obligations and making the very rules they would have to abide by.
27The rationale for this co-regulatory approach lies in the perceived epistemic authority of tech companies. The framing power of business tech companies is based on convincing regulators that they ‘know better’ because of their higher level of expertise. Accordingly, disinformation is conceived as a ‘technical’ question, which situates tech companies as the actors best placed to solve the problem. This paradigm of technological solutionism, a concept advanced by Evgeny Morozov (2013), suggests that societal problems can be ‘solved’ through technology. It inherently situates Big Tech companies as part of ‘the solution’ rather than as part of the problem. This was made explicitly visible in an interview with a Microsoft representative when discussing the code of practice:
a code of conduct is inherently a type of self-regulation. (...) [But] this is more than that, it's co regulatory. So it's linked to a regulatory instrument. (…) In order to have such deep regulation, you need people who are really very close to the substance. The normal legislator is not well equipped to do that job. We will see the Commission hopefully developing that knowledge to do that on a day-to-day basis. (…) We are the ones that understand the service, if you look at the code of practice it is much more detailed than regulation. And it's exactly because it's that much deeper level of detail, that it's important that the companies that understand how the platforms work and what type of metrics are available and are even possible technically (Interview with a Microsoft representative, November 2023)
- 1 AAEDR code: Frames\\F - ONLINE SPHERE\F - OS - Rationale for digital regulation\F - OS - Level of r (...)
- 2 AAEDR code: Claims\\C - General & content regulation\C- Content regulation\Regulatory Action Agains (...)
- 3 AAEDR code: Claims\\C - Digital Market Regulation\C - Platform accountability\C - Accountability - (...)
28Similarly, a representative from the Computer and Communications Industry Association (CCIA), who represents several Big Tech companies, argued in an interview that “one of the problems that we see is that the legislators don't really understand how the technology works”. However, in the specific context of the Code of Practice on Disinformation and the DSA, the CCIA representative was positive about the Commission’s consultation process, because “this is very fruitful because in the end, you also need online platforms and tech companies to be at the table, because we think that we are the ones that know how the technology works” (Interview with a CCIA representative, October 2023). The capacity of Big Tech lobbyists to influence disinformation-related regulation is thus visible throughout the multiple EU initiatives, all of which incorporate tech industry actors as central players. Table 3 below contains the evidence coded about the explicit formulation of co-regulation as a solution1. The first column includes all the actors that have argued about co-regulation in this process, the second one (position) whether they agree with it or not, and the third and fourth columns provide additional information about each actor’s involvement in agenda setting as members of the HLEG or a code of practice. Finally, columns five and six provide contrasting evidence about each actor’s claims regarding eventual regulatory action on disinformation (column 52) and on reinforcing platform liability in general (column 63).
Table 3. Reference to co-regulation
|
Name
|
Position
|
Member HLEG?
|
Signatory Code of Practice?
|
Claims on regulatory action
|
Increase platform liability
|
|
ACT
|
Yes
|
|
|
Yes
|
Yes
|
|
Adobe
|
Yes
|
|
2022
|
|
|
|
ARD
|
Yes
|
Yes
|
|
|
Yes
|
|
Association of European Radios
|
Yes
|
|
|
|
Yes
|
|
Bertelsmann
|
Yes
|
Yes
|
|
|
|
|
BEUC
|
Yes
|
Yes
|
|
|
|
|
Bitkom
|
Yes
|
|
|
|
|
|
Civil Liberties Union of Europe
|
No
|
|
|
|
|
|
COMECE
|
No
|
|
|
|
|
|
DigitalES
|
Yes
|
|
|
|
Yes
|
|
EASA
|
Yes
|
|
|
|
|
|
EAVI
|
Yes
|
|
|
|
Yes
|
|
EDIMA / DOT Europe
|
Yes
|
|
2018 / 2022
|
|
Yes
|
|
EMMA-ENPA
|
Yes
|
|
|
|
|
|
EU Pet Advertising Advisory Group
|
Yes
|
|
|
|
|
|
European Business Press
|
Yes
|
|
|
|
|
|
European Cancer Organization
|
Yes
|
|
|
|
|
|
Faktograf
|
Yes
|
|
2022
|
Yes
|
|
|
Google
|
Yes
|
yes
|
2018 / 2022
|
|
|
|
GONG
|
Yes
|
|
|
Yes
|
|
|
GSMA
|
Yes
|
|
|
|
Yes
|
|
Microsoft
|
Yes
|
yes
|
2018 / 2022
|
|
|
|
News Media Europe
|
Yes
|
yes
|
|
|
|
|
Telefonica
|
Yes
|
|
|
|
|
|
The Broadband Association
|
Yes
|
|
|
|
|
Source: The authors
29The following question emerges: where did the co-regulatory framework of the EU come from? Public consultations are helpful in tracing the origins of this approach. More specifically, our analysis traces the actors’ responses throughout the 2018-2022 period. Multiple actors participated in the HLEG and/or signed the Codes of practice on disinformation, most notably Google and Microsoft, who were present in the HLEG and signatories of both codes of practice. Table 3 provides significant evidence that the principle of co-regulation is strongly consensual. Indeed, the views on co-regulation influence demands for regulation: of the 25 participants referencing co-regulation only two disagree and only three have further demands for regulatory responses to disinformation, with only seven demanding increased platform liability (column 6 in Table 3). First, we analysed whether coding in the co-regulation frame in Table 3 coincided with claims for platform responsibility. We found only one reference, which coincided very strongly with specific claims to co-regulate harmful content. We then checked whether support for the principles of co-regulation, as expressed in the HLEG and code of conduct, anticipates weaker claims on regulation. This was confirmed: only one out of 11 organisations in Table 3 involved in HLEG or the Codes support regulatory action, and only two out of 11 demand stronger liability for platforms.
30As it appears, all organisations but two agree on the principle that platforms should be obliged to fight disinformation, while allowing them to decide on the specificities of their policy. Comece and the Civil Liberties Union of Europe formulated a similar critical argument:
“Having businesses make decisions about content is not only a heavy burden on the commercial sector, but it is also highly non-transparent, which is an entirely inappropriate way for democracies to regulate such an important issue as freedom of expression” (Civil Liberties Union of Europe, 2018)
31However, the time dimension is of great importance here as it also shows the specificities of voluntary cooperation by platforms. The notion of co-regulation was first formulated by organisations other than the platforms in the context of the HLEG, after all regulatory options are discarded. Furthermore, they do so in a tone that is critical of platform power:
The European Commission should therefore further explore the concept of “enforced hybrid regulation”. This type of regulation refers to the mix of regulatory measures (hard and soft law) and actors (state and corporate), as well as the “possible synergies between binding and non-binding mechanisms”. In other words, Member States pressuring corporate actors to exceed their legal responsibilities voluntarily. (News Media Europe 2018)
32In this way, co-regulation appears as a response to criticism of the self-regulation of platforms. In fact, in 2018, several organisations called for co-regulation as a means of addressing platform responsibilities and the flaws of self-regulation. These organisations included Civil Liberties, Commission of the Episcopates of the European Union, EAVI, European Business Press, and News Media Europe. Hence, the formulation of co-regulation corresponds with the demand for a stronger engagement of platforms against disinformation, which contrasts with the HLEG report’s strong caution against regulation. It is in the context of the EDAP that regulation appears as a more likely possibility, and therefore co-regulation is being reshaped by insider actors such as Microsoft:
“We believe the Code [of practice on disinformation] is sufficiently robust yet also flexible enough, to allow the Commission and the signatories to respond to threats of disinformation as and when they emerge (e.g., on COVID-19). […] we recognize the exceptional risks associated with disinformation about the COVID-19 pandemic, and we are working hard to support the Commission in tackling this issue. […] We do not agree, however, that these or other reporting requirements should extend to other areas of disinformation without prior consultation and agreement with the signatories of the Code.” (Microsoft, 2020)
33With the DSA, co-regulation is “mainstreamed”, as evidenced by the spike in references. Therefore, the key issue becomes what exactly the regulatory obligations should be. As shown in the quote below, co-regulation is re-appropiated by platforms to meaningfully separate the liability regime under the DSA from their obligations to address systemic risks of legal but harmful content:
Finally, the changing nature of and norms around harmful content make it unsuitable for the liability regime. That said, the focus on illegal content and activity in the new framework need not preclude further evaluation and action on “lawful but harmful” content through self- and co-regulatory initiatives, such as the EU Code of Practice on Disinformation (Google, 2020, p. 6)
34In some ways, Big Tech platform companies are comfortable with the idea of ‘updating’ the 2000 e-commerce directive rather than rethinking the underlying philosophy on which e-commerce was initially based. On the contrary, their competitors, such as publishers, expect specific obligations to be laid down in the non-voluntary section:
In addition, existing and further signatories should be made more accountable to the public, work with independent fact checkers, and demonetise disinformation by removing their ability to profit from advertising. (News Media Europe, 2021)
35In a nutshell, the framing of co-regulation shifts the object of contention from the specific obligations to fight disinformation to the design of the code of practice. One of the key practices that was consolidated and legitimated in the HLEG report and code of practice is fact-checking. This contrasts with the absence of journalists from regulatory debates, who for the most part did not even contribute to the Code of Practice on Disinformation. Fact-checkers have appeared as a new ‘stakeholder’, largely supporting platforms – in fact, fact-checking organisations are often (at least partially) funded by these very same platforms. While the opposition between platforms and publishers is obvious, the framing is more complex. Both types of actors share a distrust of content regulation and its potential impact on their business model and fundamental rights. Therefore, despite the strong wording often used about platforms’ responsibility for disinformation, both publishers and platforms agree that content should not be directly regulated by the EU.
36Furthermore, interviewees from democracy promotion and digital rights civil society organisations also confirm a rejection of the principle of content regulation:
“there definitely shouldn't be legislation on disinformation. Because that is always dangerous. If you do legislation on disinformation, somebody's gonna have the brilliant idea to ban it.” Iinterview number 13, carried out in Brussels with an employee of a general interest group on 07/11/2023)
- 4 AAEDR code: Claims\\C - Media claims\Copyright\
- 5 AAEDR code: Claims\\C - Digital Market Regulation\C - Platform accountability\C - Accountability - (...)
- 6 AAEDR code: Claims\\ C- Non reg. solutions\Civic education
37It therefore appears that despite their critical narrative about digital platform’s responsibility for disinformation, two important constituencies, namely content creators and democracy advocates, shared the principle that content itself should not be regulated, therefore leaving co-regulation as the middle ground. Their demands then focused on issues not contemplated in the Commission policy framework, such as copyright4, platform liability5, or civic education6, making their demands less central. This is not identical to the coalitions identified by Heerman (2024) in the field of copyright, but there is a convergence between digital giants and certain organisations concerned about democracy and rights, despite their disagreements on other issues (see Bouza García et al., 2025a).
38If the explicit presence of Big Tech among the consultation respondents is modest (only 12 of the 167 documents), their ideational presence is high, as illustrated by the HLEG and the Codes of Practice. This policy dominance is further confirmed by access to the Commission via meetings. Figure 2 below shows the meetings between actors involved in the consultations and the Commission during the DSA policy debate (see also Neuray, 2024). The colour code indicates the different communities, and the tag size the number of meetings. Big Tech companies exchanged ideas frequently and had stronger ties with DG CNECT and the Cabinet of Commissioner Breton. Only three civil society organisations, EDRi, BEUC, and Access Now had comparable access to DG CNECT. One professional association, Reporters without borders, had a strong link to Breton’s cabinet. By contrast, other tech actors and media companies in the lighter green and orange communities had only occasional contact with other Commission services (DG COMP in particular) and virtually no interaction with each other during these meetings.
Figure 2. SNA actor's meetings on DSA
Source: The authors
39The framing power of Big Tech is therefore consolidated by frequent meetings with a coalition of powerful actors with a common voice. This is in contrast to a more disparate collection of organisations that have specific claims and, broadly speaking, do not have a clearly formulated alternative to co-regulation. Overall, our analysis shows that the most significant achievement of Big Tech lobbyists in the EU field of disinformation is the consensus across the board (including among those opposed to Big Tech from a regulatory perspective) that they are essential ‘partners’ in tackling disinformation. Without their ‘expertise’, data, and willingness, solutions simply will not work. As one of our interviewees from civil society (Interview, November 2023) put it, the platforms are the “powerholders” in the EU tech regulatory field. This is not only because of the number of lobbyists they employ, but also because of their ability to make other actors in the field reliant on them.
40The paper has empirically traced the genesis of the EU's co-regulatory approach to disinformation, from the 2018 HLEG all the way to the inclusion of the Code of Practice on Disinformation as a Code of conduct within the DSA framework in 2025. During the drafting of the codes of practice, HLEG recommendations, and the DSA, platforms succeeded in presenting themselves not as the “problem”, but as part of the “solution” to disinformation. They also attempted to use regulation to establish their businesses as essential to democracy. As we have shown, demands for ‘co-regulation’ exclude actual regulation. The co-regulatory framework consequently sidelines systemic alternatives – such as a stronger liability regime for platforms or a systemic change in the advertising market – and assumes that platforms are willing to collaborate to fight disinformation. This technical framing of the ‘problem’ facilitates a technosolutionist paradigm in which disinformation is reduced to a ‘bug’ in social media platforms rather than a logical consequence of their business model (see Oleart & Rone, 2025). Our findings are in line with Griffin’s (2023, p. 60) assertion that the EU’s approach reinforces “the image of platforms as benevolent stewards of the public interest, rather than companies pursuing private gain”. In doing so, lobbyists for these companies have managed to frame the policy debates on these issues and participate in discussions as “third-party-experts” (Kausche & Weiss, 2024, p. 20), acting almost as ‘neutral’ partners. Therefore, the EU’s approach has been marked by an epistemic and regulatory capture (Obendiek & Seidl, 2023) that has systematically sidelined policy demands that could challenge the dominance of platforms and their business model.
41The business model of social media platforms is largely based on targeted advertisement. This means that much of the advertising revenue that used to be invested in traditional media (mostly in private companies, but also in some public media that include advertisement) is now primarily going to digital platforms. While initially there were discussions among the Council, Commission, and Parliament about the possibility of banning targeted advertisement completely, this option was discarded after extensive lobbying by the platforms. The co-regulatory framework then allowed platforms to retain the advertisement-oriented business model of social media companies while also avoiding platform liability and instead focus on aspects where a compromise is possible, such as the transparency of the algorithms, recommendation systems, and reporting of internal functioning, as detailed in the Code of Practice. Thus, the EU’s co-regulatory framework is the result of the platforms successfully framing the ‘problem’.
42Our analysis is particularly timely as it empirically confirms the close cooperation between social media platforms and the EU in constructing this co-regulatory framework at a time when leaders of Big Tech companies are changing their position vis-à-vis the EU. In fact, following the second Trump election in November 2024, Mark Zuckerberg, the CEO of Meta, announced on January 7, 2025, that he would remove fact-checkers in the US and replace them with community notes, while also criticising the institutionalisation of censorship by the EU. Zuckerberg’s announcement would violate the EU’s Code of Practice (now the Code of Conduct) on disinformation. Whether this will apply to Facebook or Instagram within the EU remains to be seen, but Zuckerberg’s words illustrate that the EU’s co-regulatory framework is dependent on the platforms willingness to cooperate.
43While the European Commission references the DSA as an attempt to set “a benchmark for a regulatory approach to online intermediaries also at the global level” (European Commission, 2024), the EU’s co-regulatory approach empowers rather than hinders Big Tech companies. It therefore further entrenches them as gatekeepers and institutionalises their position of power, shifting the focus away from the targeted advertisement business model that most of them rely on. Big Tech’s greatest success is that there appears to be a consensus in the field, even among some civil society actors, that the EU has to regulate with tech companies, rather than against them. This counters the double movement argument of Cioffi et al. (2022), as our analysis suggests that we may not yet be in the second movement. This is because EU regulation (in this case, the DSA) has mostly reproduced and legitimised the market power of these companies. A market-oriented regulatory choice has become normalised, whereby the infrastructure of the public sphere continues to depend on a small group of private tech private companies whose business model is not questioned. While the EU presents itself as taking a fundamentally different approach to that of the US, there are in fact close similarities in terms of the influence of the ‘Tech Lobby’ on policy-making (see Popiel, 2018). Such business-friendly dynamics are likely to be reproduced in other areas of tech policy, such as Artificial Intelligence (AI), where the EU has attempted to create an artificial sense of legitimacy through ‘citizenwashing’ (Petit & Oleart, 2025). However, co-regulation remains the underlying logic with which the EU has approached AI – for instance through the General-Purpose AI Code of Practice – and it appears to have overplayed global leadership in terms of regulation through the AI Act (Crum, 2025).
44Therefore, there is more continuity than rupture in the EU’s approach to regulating disinformation. The co-regulatory approach of the DSA can be traced back to the HLEG and the initial 2018 Code of Practice on Disinformation, in which companies were allowed to set their own regulatory obligations, thereby privatising the promotion and demotion of narratives on their platforms. The DSA confirms and reinforces this already existing co-regulatory approach, whereby the EU recognises the position of platforms and thus reinforces their position of power. In practice, this also means that different Big Tech platforms apply the regulation differently (Cipers & Meyer, 2023), with different definitions of what constitutes ‘political’ or ‘harmful’ content and ‘disinformation’.
45Last, the accompanying narrative of ‘protecting democracy’ lends itself to a geopolitical approach in which foreign state-actors, such as Russia or China, are held responsible for the spread of disinformation (Wagnsson & Hellman, 2018; Broeders et al., 2023). This narrative also normalises the political power of Big Tech platforms, which EU policy-makers conceive as necessary ‘partners’ and ‘allies’ in the fight against ‘foreign interference’ and disinformation (Proto et al., 2025). Thus, while there is a consensus that disinformation is a ‘problem’ that ought to be addressed, there is a struggle in terms of how disinformation is defined and conceived by different actors. So far, Big Tech platforms are winning. The EU’s market-based regulatory responses within the DSA rely entirely on the decisions made by these private companies. Despite the existence of a significant network of critical civil society networks, their demands and discourse have had little impact on regulators. This supports the argument that Big Tech has successfully engaged in some form of pre-emptive cooperation to minimise the impact of EU regulation on its business model.