Recent coverage here tracked addictive design becoming a DSA compliance surface and France banning under-15s without building the gate. The new development is sharper: the European Commission has adopted the DSA data-access delegated act, accepted X’s corrective plan for researcher screening, and researchers are now documenting the machinery platforms use to slow lawful scrutiny.
Europe gave researchers a legal right to inspect very large platforms. The platforms answered with forms, quota ceilings, security demands, venue fights, incomplete APIs, and datasets that other researchers struggle to reproduce. That is the whole platform-governance problem in miniature. A right exists on paper. The control surface lives in the API.
the law entered the API queue
The Digital Services Act says vetted researchers can request platform data when the work studies systemic risks: illegal content, fundamental-rights harms, recommender systems, scams, civic manipulation, and other failures that giant platforms are uniquely positioned to create or hide. The Commission’s delegated act fills in the procedural machinery: Digital Services Coordinators vet researchers, platforms and search engines publish application information, and a DSA data-access portal becomes the exchange layer.
That sounds procedural because law often hides its teeth inside procedure. Affiliation, independence from commercial interests, funding disclosure, data-security plans, confidentiality commitments, privacy controls, formats, documentation, and access channels now decide whether a researcher can see the system being studied.
WIRED’s July report makes the seam concrete. Adriana Iamnitchi’s Maastricht University team applied to TikTok’s API in October 2025 to study Romanian election manipulation before the presidential vote. The request was denied. TikTok later flagged 116,000 accounts as potentially compromised and took action against more than 27,000 fake accounts tied to a third-party fake-engagement vendor promoting Calin Georgescu and his party. Romanian intelligence said Georgescu benefited from massive TikTok exposure and alleged Russian coordination. The first round was annulled.
The question sitting under that sequence is ugly. If a platform denies outside researchers before an election and later confirms a coordinated network after the damage, the access process has become part of the incident timeline.
reproducibility is the missing civil right
Platform data access gets framed as transparency. That frame is too soft. The useful standard is reproducibility. If one approved lab pulls an API dataset and another lab cannot re-run the query, check the fields, or inspect what was missing, the public receives a story instead of evidence.
DSA40, a German tracker of DSA data requests, told WIRED it had tracked 46 applications: 20 approved, 14 rejected, with platform-by-platform gaps. TikTok approved 11 of 13 tracked requests. X rejected 11 of 23. The tracker relies on voluntary reporting, so the rejected and abandoned cases are probably undercounted.
The denial can arrive through the front door. The constraint can also arrive through architecture. Researchers described daily caps, narrow definitions of systemic risk, data-security requirements that imply isolated machines many universities cannot maintain, and datasets that are difficult for peers to validate. X paywalled API access after shutting off broader public access. Meta retired CrowdTangle and replaced it with the Meta Content Library and API. TikTok says its quota can deliver large record counts, but researchers still describe scale limits that break network studies.
court venue became an API parameter
The DSA also exposes a jurisdiction problem that platform lawyers adore. Democracy Reporting International and the Society for Civil Rights requested X API access in April 2024 to study political discourse before Germany’s federal election. X rejected the request in November. The researchers sued in February 2025 and won an order that X should have granted access.
Then a similar Hungary-election request ran into a venue trap. A Berlin court said the researchers should have sued in Ireland, where X is based. They won on appeal, but the damage is visible: every denial can become a procedural expense before it becomes a dataset.
The Commission has started to push. In December 2025, it fined X €120 million under the DSA, including for unnecessary barriers to researcher access that undermined research into European risks. In July 2026, it accepted X’s corrective measures: improve researcher screening, provide data without charge, reduce processing time, and lift data-scraping restrictions. X has six months to implement the plan.
That six-month clock matters because it turns platform access into measurable infrastructure. Either the application route gets faster, cheaper, broader, and more reproducible, or the corrective plan becomes another PDF in the compliance archive.
platforms are being asked to expose their own weather
Social platforms used to treat research access as charity, partnership, or public-relations upholstery. That era is dead. Very large platforms are now civic weather systems. Elections, public health scares, scams, riots, teen self-harm loops, harassment campaigns, and state influence operations move through recommendation, ads, livestreaming, account graphs, moderation queues, and creator monetization.
A weather station that owns the storm data cannot be allowed to define every research instrument after the tornado passes.
The platforms are right about one thing: raw access can expose private data and create security risk. Researcher access needs vetting, purpose limits, audit logs, secure storage, and penalties for abuse. Fine. Build that. Then make the machinery public enough to test. Publish denial categories. Publish median processing time. Publish quota ceilings. Publish field dictionaries. Publish schema changes. Preserve query reproducibility. Keep appeal paths outside the platform’s own legal maze.
the dashboard is where the law either lives or dies
The useful fight ahead will be dull on purpose. Regulators should treat access workflows as audited infrastructure, not correspondence. Researchers should stop accepting screenshots of transparency as transparency. Platforms should be forced to prove that lawful scrutiny survives normal university resources, hostile election timelines, peer review, and cross-border appeals.
The DSA can make social platforms legible only if the access layer is legible first. Otherwise Europe will have built a strong legal theory that dies inside a ticket queue.