Europe bears its teeth, political panic about OpenAI hack and YouTube refines partner policy
Hello and welcome to Everything in Moderation's Week in Review, your need-to-know news and analysis about platform policy, content moderation and internet regulation. It's written by me, Ben Whitelaw and supported by paid members like you.
I’m writing this on the train from Heathrow after getting minimal sleep on the flight from San Francisco. But it was all worth it to meet so many EiM readers in person at TrustCon and to experience the amazing support we had at the live recording of Ctrl-Alt-Speech. Go and have a listen wherever you get your podcasts (Spotify, Apple Podcasts).
We had a lot of stories to choose from on the podcast but there’s been several significant regulatory stories since we recorded on Wednesday. One of them — another platform breach announcement landed from the European Commission — landed just as I was about to hit send. It’s all gearing up for another almighty transatlantic clash over whose speech ideals should govern the internet.
Big thanks to new free subscribers from SatorLabs, Cloudflare, Discord, Roost, Zefr and the Siegel Family Endownment and a handful of new paying members. It’s very easy to do if you haven’t already.
Welcome to your Week in Review and thanks for reading — BW
The trust layer needs a redesign.
At TrustCon 2026, the looming pressure points were hard to miss: AI agents acting with more autonomy, synthetic content testing verification systems, physical AI moving risk beyond the screen, and governance models straining to keep pace.
PwC’s Trust and Safety Outlook 2026 builds on those conversations — and on PwC’s two-part Ctrl-Alt-Speech discussion with Dan Hays — to examine what needs to change next.
The annual Trust & Safety Outlook makes the case that trust and safety can no longer sit downstream as a reactive operating function. It needs to move earlier into product design, governance, operations, and accountability as AI reshapes how digital, physical, and institutional trust are built.
Policies
New and emerging internet policy and online speech regulation
Google was yesterday found in breach of the Digital Markets Act and handed an €890m fine for preferencing its own services on Google Search and steering consumers via its Play Store. It has instructed the search giant to treat third-party services in a “fair and non-discriminatory manner” and said Google had already started testing changes.
If you ask me (which I realise you didn’t), I’d say that Google doesn’t seem likely to appeal; it’s not mentioned in its short statement from its president of global affairs and the fine pales in comparison with its $400bn in annual revenue.
Broader backdrop: We’re ramping up for the latest round in the ding dong between US and EU officials over the bloc’s speech laws. According to Politco, a joint declaration draft has been circulated by the US administration ahead of September’s UN General Assembly that asks countries to commit to recognise that disinformation, misinformation or hate speech that doesn’t incite violance hinders “freedom of expression”. Sarah Rogers (EiM #335) is involved, as you may not be suprised to learn.
The European Commission has quickly followed up its finding that Meta breached of the Digital Services Act (EiM #344) by fining AliExpress a record €550 million for failing to assess and mitigate risks relating to the sale of illegal, unsafe or counterfeit products on its platform. It surpasses the fine handed out to Temu in June for similar violations (EiM #338)
Also in this section...
- Investigation into an online suicide discussion forum and its compliance with duties to protect its users from illegal content (Ofcom)
- This online curfew is a PR stunt. Internet users don’t need to be regulated – internet platforms do (The Observer)
- Addressing “Lawful but Awful” Content (CNTI)

Products
Features, functionality and technology shaping online speech
The major story of the week concerns to the lack of safeguards that allowed two OpenAI models — including one launched just last month with its “most robust safety stack to date” — to hack Hugging Face and obtain answers to a test it had been asked to complete. The Register described the incident as “no more surprising than locking a bear in a supermarket and finding a mess the following day.”
In the days since, politicians have embarked on a collective panic attack as questions about global AI regulation have re-emerged:
- Two US lawmakers have put forward a bill known at the AI Kill Switch Act to give the Department of Homeland Security authority to shut down a model deemed dangerous - which isn’t the reasurrance that they think it is
- The UK government-backed AI Security Institute is “studying the behaviour seen in this incident” - ironically, just days after it signed a memorandum of understanding with OpenAI.
- Word out of the EU is that the disclosure — as odd and performative as it was — resulted from obligations under the EU’s AI Act, according to Euractiv (although I can’t read the full story)
Want more? Mike and I chatted about the implications with Kat Duffy (Council on Foreign Relations) and Zoe Darmè (Google) on this week’s Ctrl-Alt-Speech.
You may have come across the accelerationists, safetyists and sceptics triad in the AI community. Now Politico has sought to flesh out the different views on AI safety. It spoke to 20 AI experts and used their responses to create a guide to the different AI safety factions. Which one of the seven categories are you?
Also in this section...
Platforms
Social networks and the application of content guidelines
Another product-focused lawsuit against Meta has been settled after the 15-year-old plaintiff dropped the case before he was due to go in trial. The teen — known as R.K.C — claimed that autoplay and infinite school led to anxiety and sleep deprivtion in an echo of the claims made by Kaley Glenn-Mills in the Los Angeles trial a few months back. But he had now retracted the claims without payment. =
Also in this section...
- San Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App Stores (Wired)
- Loss of up to 300 Irish jobs at TikTok will have 'knock-on impact' on user safety, warns union (Irish Examiner)
- FIFA detects 7 million abusive comments targeting players and staff during World Cup (Reuters)
People
Those impacting the future of online safety and moderation
AI’s impact on policy enforcement was a running theme at TrustCon but its emergence has also raised policy questions, particularly when it comes to monetisation.
YouTube is figuring this out and this week announced a refining of its “inauthentic content” policy for its Partner Program that creators must abide by to make money from the platform. It now prohibits three types of content: generic and repetitive; unsatisfying or off-putting, and AI personas talking about sensitive topics such as finance, legal or healthcare issues.
Matt Halprin, YouTube’s VP of Trust & Safety, explained to Creator Insider how this kind of content amounted to a type of “content farming” that the platform didn’t want its users to encounter. Gizmodo has more.
Although somewhat vague — how do you measure whether something is unsatisfying? — the new categories feel a step in the right direction and could curb the latest AI grift of using a combination of ChatGPT, ElevenLabs and other tools to create automated “faceless content”.
I met someone in San Francisco this week who was pumping out film explainers across YouTube Shorts using 20 channels and made $1,000 a month from each — all without doing a thing. I’m sure we can do without that.
Posts of note (non TrustCon edition)
Handpicked posts that caught my eye this week
- “The regulation will be published in the Official Journal of the European Union in the coming days and will enter into force three days after its publication.” - Eurochild’s Francesca Pisau with an update on the European Parliament amendments know as ‘Chat Control 1.0’.
- “We went to Nigeria to find our scammer. We found him, and a whole lot more” - Paul Raffile on getting to the root of the rise in sextortions.
- “After ~2 years doing research-based work, this is a shift into a more operationalized role, one where I get to directly help protect communities on the platform” - Fatima Faisal Khan celebrates her new role.


Member discussion