Politics & media · Media ownership & influence

Algorithms, amplification & regulation

What a recommender system is actually built to do, what the evidence says about it — including where that evidence genuinely disagrees — and what UK law does and does not require of it.

Introduction

Why there is no algorithm bias score here

This page follows the same rule as the rest of this section: no invented score. There is no reproducible way to reduce “how much does this platform’s ranking distort what you see” to a single number — every attempt bakes in an assumption about what an undistorted feed would even look like. What replaces it is the same structure used everywhere else in this section: named mechanisms with their own evidence strength, including one that is honestly unsettled; the regulatory record of what UK law actually requires; and one rigorously documented case.

Four numbers that frame everything else

89%

of UK internet users use social media

Ofcom’s own survey, base 6,297 social media users. Rises to 97% of 16–34s, and is still 68% of over-75s.

51 min

a day, on the most-used platform

YouTube, average minutes per day among its visitors, May 2025 — the most time spent on any platform. Facebook/Messenger is second at 43 minutes.

36%

of harm encountered while scrolling a feed

"Scrolling on a feed or the For You Page" was the single most common activity when UK adult internet users most recently encountered a potential online harm (June 2025) — rising to 47% among 18–34s.

Live since Mar 2025

Online Safety Act risk-assessment duty

The Online Safety Act’s illegal-content risk-assessment duty — which explicitly names recommender systems as a risk factor — has been in force since 16/17 March 2025; the children’s equivalent since Jul 2025.

Sources: Ofcom, Adults' Media Use and Attitudes Report 2026 (2 Apr 2026); Ofcom, Online Nation Report 2025 (10 Dec 2025). Correct as of 7 September 2026 — the Online Safety Act status line in particular is a live regulatory picture; see the regulation section below for what is settled and what is still moving.

Reach and time spent, by platform

Monthly reach among UK internet users, May 2025

Ofcom, Online Nation Report 2025, Figure 22 (p.34), 10 December 2025. Ipsos iris metered panel data, UK internet users 18+, May 2025. Base differs from Ofcom’s own 89% survey figure above — this is share of UK internet users on the Ipsos panel, not share of all UK adults — so the two should not be read as the same measurement repeated.

  • YouTube — 51 min/day among its visitors94%

    Time-spent series not comparable to years before 2024 (Ofcom’s own methodology note).

  • Facebook / Messenger — 43 min/day among its visitors93%
  • Instagram — 20 min/day among its visitors78%
  • TikTok — 28 min/day among its visitors56%

    Daily audience rose 37% year-on-year to May 2025 — faster than its monthly reach grew.

  • Reddit — 4 min/day among its visitors60%
  • X — 6 min/day among its visitors39%

    Only platform in the top 6 with falling reach (−13% year-on-year).

  • Snapchat — 27 min/day among its visitors23%

Scale: 0–100%. Ofcom, Online Nation Report 2025

Four distinctions this page refuses to collapse

The same discipline as the rest of this section’s own “four distinctions” device — kept apart because most public argument about algorithms fails by treating these as one thing.

  1. 1

    Engagement-optimised is not the same as biased

    A feed ranked to predict what you will engage with is a business-model choice, not evidence of a political thumb on the scale. The academic record below shows engagement-optimisation systematically favours emotionally arousing and out-group content over neutral content — a real distortion, but a different one from partisan bias, and one that cuts across every political direction at once.

  2. 2

    Personalisation is not the same as manipulation

    Ranking content by predicted relevance to you is what every recommender system is built to do, including ones nobody objects to (a shopping site, a music app). The question worth asking is not whether a feed is personalised — it always is — but what it is being optimised for, and who gets to know.

  3. 3

    Virality is not the same as representativeness

    What spreads furthest on a platform is not a random or typical sample of opinion — it is the content that survived a filter for what gets shared. Out-group animosity is the single strongest documented predictor of social-media sharing found in this research; treating the most-shared post as "what people think" mistakes the filter’s output for the input.

  4. 4

    Algorithmic amplification is not the same as editorial endorsement

    A newspaper that leads on a story has decided the story matters. A platform whose ranking system boosts a post because it is predicted to hold attention has made no equivalent judgement about its truth, importance or quality — which is exactly why the Online Safety Act regulates recommender systems as a harm-and-risk mechanism, not as an editorial one.

Five mechanisms, and what actually supports each one

Named and evidenced individually, on purpose — “the algorithm” is not one mechanism, and lumping five different, differently-evidenced claims into one verdict is how this subject usually goes wrong.

  • Moral-emotional contagion

    Evidence: well established, contested effect size

    Why does outraged or moralised content spread further than neutral content?

    Messages containing moral-emotional language (words that are both about morality and charged with emotion) are retweeted at a higher rate than otherwise similar messages — in one large study, each additional moral-emotional word raised a tweet’s diffusion by 20%. The effect is stronger within a political in-group’s own network than across the divide, which is one documented pathway by which morally charged content can deepen rather than bridge political separation.

    Basis: Brady, Wills, Jost, Tucker & Van Bavel, "Emotion shapes the diffusion of moralized content in social networks," PNAS 114(28), 2017 (n=563,312 tweets on three US political topics) — explicitly correlational; the authors themselves call for controlled experiments to test causation on attitudes and behaviour, not just retweet counts.

  • Out-group animosity as an engagement driver

    Evidence: well established, contested effect size

    What single content feature best predicts whether a political post gets shared?

    Across 2.7 million Facebook and Twitter posts from US news outlets and members of Congress, language about the political out-group was the strongest predictor of shares and retweets found — posts about opponents were shared about twice as often as posts about one’s own side, and each out-group word raised the odds of a share by 67%. This out-group effect was several times stronger than either negative-emotion language or the moral-emotional language measured in other studies of this kind.

    Basis: Rathje, Van Bavel & van der Linden, "Out-group animosity drives engagement on social media," PNAS 118(26), 2021 (n=2,730,215 posts). The authors state plainly that the design is correlational and that "it is unclear how algorithmic choices... might contribute to the amplification of out-group animosity, since social media companies are not transparent about how their algorithms work" — i.e., this paper documents what content people reward with engagement, not what a ranking algorithm then does with that signal.

  • Engagement-optimised ranking as a business-model choice

    Evidence: weak

    Why would a platform’s algorithm favour emotionally arousing content at all?

    Feed-ranking algorithms are built to maximise predicted engagement — the metric platforms’ advertising business depends on — not to maximise accuracy, civility or representativeness. Academic reviewers describe content algorithms as an "attentional filter" that pre-selects the moral/emotional content people are already disposed to notice, "designed to increase engagement and profit for the platforms." A former Facebook product manager testified to the same underlying logic under oath: the company "programs its algorithms to maximize profits, which means it decides which speakers are heard and which are not," and Facebook’s own 2017 decision to weight "angry" reactions as five times more valuable than a "like" in its ranking formula is documented by investigative reporting on internal company documents.

    Basis: Brady, Crockett & Van Bavel, "The MAD Model of Moral Contagion," Perspectives on Psychological Science 15(4), 2020 (peer-reviewed theoretical review, not new experimental data on the algorithm itself). Frances Haugen, Written Testimony to the US House Energy & Commerce Subcommittee, 1 Dec 2021 (sworn testimony from a named former insider; not independently verified against the underlying internal documents by this research pass). Merrill & Oremus, "Five points for anger, one for a ‘like’," Washington Post, 26 Oct 2021 (investigative reporting on leaked internal Facebook documents; documents themselves not directly examined). Rated Weak because no source isolates the ranking algorithm’s own causal contribution from the entangled effects of human sharing behaviour, moderation policy and account/monetisation design — the mechanism is well-argued and consistent with insider testimony but not independently measured end-to-end.

  • Filter bubbles and the "backfire" evidence

    Evidence: contested — credible evidence points both ways

    Does algorithmic personalisation trap people in one-sided information, and does removing it fix polarisation?

    The "filter bubble" thesis (Eli Pariser, 2011) argues personalised ranking narrows what people see to content that confirms their existing views, deepening division. The empirical record on this is genuinely split, and splits along method: studies measuring actual browsing/exposure data have found that individual choice about what to click narrows a person’s information diet more than Facebook’s ranking algorithm does, and that social/search channels can even increase exposure to opposing views compared with direct browsing. Separately, a large randomised experiment that switched real Facebook and Instagram users from the algorithmic feed to a plain chronological one during the 2020 US election found it substantially changed what they saw and how long they spent on the platform — but did not produce a measurable change in political polarisation, political knowledge, or belief in false claims over the three-month study. A 2024/2025 systematic review of 112 studies found the field’s disagreement tracks research method (network-based computational studies tend to confirm echo chambers; content-exposure and survey studies tend to reject the strong version of the thesis), not a converging answer.

    Basis: Pariser, "The Filter Bubble," 2011 (the originating thesis; a book, not an empirical study). Bakshy, Messing & Adamic, "Exposure to ideologically diverse news and opinion on Facebook," Science 348(6239), 2015 (n=10.1m users; Facebook-employee authors). Flaxman, Goel & Rao, "Filter Bubbles, Echo Chambers, and Online News Consumption," Public Opinion Quarterly 80(S1), 2016 (n=50,000 browsing histories). Guess, Malhotra, Pan, Barberá et al., "How do social media feed algorithms affect attitudes and behavior in an election campaign?", Science 381(6656), 2023 (n=44,764 across Facebook/Instagram; Meta-funded, several co-authors are Meta employees — disclosed here alongside the finding). Hartmann, Pohlmann, Wang & Berendt, systematic review of 112 studies, J. Computational Social Science, 2025 / arXiv:2407.06631, 2024 — finds the literature’s disagreement is methodological, not yet resolved either way.

  • Social-feedback reward loop for outrage expression

    Evidence: well established, contested effect size

    Does getting likes for angry posts make people post angrier content again?

    In preregistered Twitter studies and behavioural experiments, receiving positive social feedback (likes, shares) for an outrage expression increased the likelihood a user would express outrage again — a pattern consistent with reinforcement learning. Users also matched their outrage expression to their network’s normative level of outrage, an effect that was strongest where the reward signal (feedback) was the main available cue and weaker where the network norm was already highly visible.

    Basis: Brady, McLoughlin, Doan & Crockett, "How social learning amplifies moral outrage expression in online social networks," Science Advances 7(33), 2021 (two observational Twitter studies, n=7,331 users / 12.7m tweets, plus two preregistered behavioural experiments, total N=240). The authors state the observational studies "cannot draw causal inferences" on their own (self-selection into extreme networks is a plausible alternative explanation) and note the behavioural experiments, while causally identified, use a simulated rather than real platform environment.

On the filter-bubble/backfire debate specifically. There is no responsible way to present the filter-bubble/backfire debate as resolved in either direction. The field’s own newest and most rigorous verdict on the question — a 2024/2025 systematic review of 112 studies — says the disagreement tracks methodology, not a settled answer. A single well-powered randomised experiment found real behavioural and exposure effects from changing the algorithm but no measured effect on the downstream outcomes (polarisation, misinformation belief) the filter-bubble thesis predicts should move: a genuine complication for the simple version of the thesis, not proof it is wrong.

What UK law actually requires — extending “three regimes, one news diet”

The rest of this section already establishes that platforms carry no impartiality duty, unlike broadcasters, and that Ofcom’s Online Safety Act powers reach harm, not plurality. Everything below is the detail behind that line, not a revision of it.

Platforms and search

No impartiality duty

Not covered by the media ownership rules and not subject to any impartiality duty, despite being used for news by six in ten UK adults. The Online Safety Act gave Ofcom powers over harm, not over the plurality of what people see.

Recommender systems are a named legal threshold, not an afterthought

A regulated user-to-user service is Category 1 if it has more than 34 million average monthly UK users and uses a content recommender system; or more than 7 million average monthly UK users, uses a content recommender system, and lets users forward or share content with each other. A "content recommender system" is one of the two legal threshold conditions for the entire Category 1 tier — not an incidental detail of platform regulation, but one of its two load-bearing tests.

Category 1 services currently listed (11): Facebook, Instagram, Pinterest, Quora, Reddit, Roblox, Snapchat, TikTok, WhatsApp, X, YouTube.

Ofcom’s own statutory guidance, quoted directly.Our evidence, for example, indicates that if not properly tested and deployed, content recommendation systems may amplify hateful content if they are optimised for user engagement.

What is live now, and what is still in consultation

Online Safety Act implementation timeline, as of 7 September 2026
DateDutyStatus
16 Dec 2024Illegal-content Codes of Practice & Risk Assessment Guidance published — recommender systems named as an explicit risk factorIn force
16/17 Mar 2025Illegal-content risk assessment duty and safety-measures duty live for all in-scope servicesIn force
24/25 Jul 2025Children’s risk-assessment duty and Children’s Codes safety-measures duty liveDates corroborated by multiple independent legal-commentary sources, not independently re-verified against Ofcom’s own statement page in this research pass.In force
30 Jun 2026Register of categorised services (Category 1 / 2A / 2B) publishedDetermines which platforms carry Category 1’s extra duties, once those duties are finalised. Register last updated 14 Aug 2026 — check before long-term reuse.In force
10 Jul 2026 →Draft Category 1 Code of Practice (user empowerment, identity verification, complaints) — the duties that would most directly target algorithmic amplification, not just risk-assessment paperworkConsultation closes 2 October 2026; final version expected mid-2027 at the latest.Consultation open
Autumn 2026 (expected)Updated Codes covering AI / automated moderation toolsUpcoming

As of 7 September 2026: the illegal-content risk-assessment duty (including its explicit recommender-systems risk factor) and the children’s risk-assessment/codes duty are both live and enforceable now. The categorisation register is published, but the extra duties that attach specifically to Category 1 status — the ones that would reach algorithmic amplification directly, rather than via a risk-assessment paperwork exercise — are still in draft and consultation, not yet final or in force.

What has not (yet) been found. No confirmed Ofcom enforcement action specifically targeting a platform’s recommender system — as opposed to risk-assessment paperwork, age assurance, or generated content — has been found in this research as of 2026-09-07. This is stated as "not found," not "does not exist": it is exactly the kind of live regulatory fact that can change without notice, and should be re-checked directly against Ofcom’s enforcement pages before being relied on.

A second regulator, a second legal theory: the ICO and children’s data

ICO Children’s Code, Standard 12, quoted directly.If you are using children’s personal data to automatically recommend content to them based on their past usage/browsing history then you have a responsibility for the recommendations you make. This applies even if the content itself is user generated... Data protection law doesn’t make you responsible for third party content but it does make you responsible for the content you serve to children who use your service, based on your use of their personal data.

In February 2025 the ICO opened an investigation into how TikTok processes 13–17-year-olds’ personal data in its recommender systems, and issued an information notice requiring TikTok to provide information. TikTok has appealed the notice to the First-tier Tribunal on "special purposes" (journalistic/artistic) grounds, and — as of the ICO’s own most recent update, 1 December 2025 — is not required to comply while that appeal is unresolved. This is an open investigation with an unresolved procedural dispute, not a completed finding about TikTok’s recommender system, and the position will have moved on since the research date.

Recommender systems shown to children are regulated twice, by two different regulators, on two different legal theories: the Online Safety Act treats them as a systemic-risk factor a platform must assess and mitigate (Ofcom); the UK GDPR’s Children’s Code treats them as personal-data processing a platform is directly responsible for (ICO). Neither regime gives any UK regulator a duty over the plurality or viewpoint-diversity of what an algorithm shows a user — that is the gap lib/media-orientation.ts’s REGULATORY_ASYMMETRY already names, and nothing found in this research closes it.

Southport, 2024: the three days the law was silent and the algorithm wasn’t

A dance-class attack on three children, a false name, and the clearest UK case yet of the gap between what regulated broadcasters can say and what an unregulated feed will amplify — plus a live regulatory dispute, a year on, about how much of the blame that gap deserves.

Why Southport, not the Southsea/Portsmouth protests

James’s brief suggested the 2025 Southsea/Portsmouth migrant-hotel protests as a possible case study. Those protests are real and dated, but no primary source could be found comparing their online and broadcast coverage, and no independent post-mortem exists for that specific event — most local reporting on it was also unreachable behind bot protection. Southport is different: it has a primary regulator’s letter (read in full below), at least four independent research-organisation analyses, a statutory inspectorate review, a live Law Commission reform process, and a contemporaneous fact-check — documented to a standard well above this section’s existing Brexit case study.

Timeline

  1. 29 Jul 2024A 17-year-old attacked a Taylor Swift-themed children’s dance class in Southport with a knife. First 999 call 11:47am; suspect arrested at the scene within ten minutes.
  2. 29 Jul 2024 (same day)The false name "Ali Al-Shakati" began circulating on social media, originating from the site Channel3Now, alongside false claims the attacker was a Muslim asylum seeker who arrived by small boat.
  3. 30 Jul 2024Two of the three girls attacked died (a third died in hospital the same week). By 3pm the false name had over 30,000 mentions on X from over 18,000 unique accounts. Merseyside Police publicly stated the name was incorrect.
  4. 30 Jul 2024, eveningA vigil outside Southport Mosque was followed by violent disorder: bricks and rocks thrown at the mosque, a police vehicle set alight, a shop looted; 39 officers injured.
  5. 31 Jul 2024 onwardDisorder spread to towns and cities across England and to Belfast; over 1,000 arrests followed nationally in the following weeks.
  6. 1 Aug 2024Liverpool Crown Court lifted reporting restrictions and the suspect was formally named as Axel Muganwa Rudakubana — three days after the attack — the judge citing the risk that continued anonymity would let misinformation keep spreading in a vacuum.
  7. 22 Oct 2024Ofcom CEO Dame Melanie Dawes wrote to the Secretary of State assessing how illegal content spread after the attack — the fullest primary regulatory document on the case.
  8. 23 Jan 2025Rudakubana sentenced to life imprisonment (minimum term 52 years) after pleading guilty to all sixteen charges.
  9. 3 Mar 2025The Law Commission opened a consultation on contempt-of-court law, prompted specifically by the Southport case, on whether more could be published after arrest to counter misinformation.
  10. May 2025HMICFRS (the police inspectorate) published its Tranche 2 review of the policing response, finding "no conclusive or compelling evidence" the disorder was "deliberately premeditated and co-ordinated by any specific group or network" — directly qualifying the stronger framing in Ofcom’s October letter.
  11. 6 Aug 2025Amnesty International published an analysis of X’s design and recommender-system choices in relation to the disorder, based on X’s own published recommender source code.

What was actually measured

Each figure above is its own organisation’s measurement, over its own time window, on its own platform — they measure different things and are not additive. A widely-circulated "155 million impressions / 1.7 billion reach" aggregate figure could not be traced to any primary source in this research and is deliberately excluded.

The online-vs-broadcast contrast

UK contempt-of-court and under-18 reporting-restriction law legally prevented anyone — broadcasters, the press, and in principle individual social media users alike — from naming the Southport suspect or speculating about him in ways that could prejudice a trial. Regulated broadcasters observed this restriction. An anonymous aggregator site and a large number of pseudonymous social media accounts did not, and a false name and false identity claims reached tens of thousands of mentions within a day and millions of views within the following days. A judge lifted the restriction on day three, citing the ongoing spread of misinformation as a reason. This is a case about the gap between regulated and unregulated space, not a case about broadcasters being "slow" for its own sake — nothing in this case suggests broadcasters breached their existing due-impartiality or due-accuracy duties.

Ofcom, 22 Oct 2024 letter

Accounts (including some with over 100,000 followers) falsely stated that the attacker was a Muslim asylum seeker... Posts about the Southport incident and subsequent events from high-profile accounts reached millions of users, demonstrating the role that virality and algorithmic recommendations can play in driving divisive narratives in a crisis period.

HMICFRS, Tranche 2 review, May 2025

No conclusive or compelling evidence [the disorder was] deliberately premeditated and co-ordinated by any specific group or network — citing instead longstanding social deprivation, eroded trust in police, and widespread political disaffection. The review also cites the Children’s Commissioner’s own finding that interviews with those arrested "do not support the prevailing narrative... that online misinformation, racism or other right-wing influences were to blame."

The three levels, and where the dispute actually sits

From a false name to a national disorder: what is documented, and what is disputed

  1. 1The false claim spread, and reached a large audienceDocumented

    The false name and false identity claims reached tens of thousands of mentions within a day, and individual posts reached millions of views within days — see the metrics above, each independently sourced.

    ISD, CCDH, Amnesty International, Marc Owen Jones
  2. 2That spread contributed to the riotsDocumented, but disputed

    Ofcom’s own letter states illegal content "appears to have contributed to the significant violent disorder." HMICFRS’s statutory review, seven months later, found "no conclusive or compelling evidence" of coordinated premeditation and pointed instead to deprivation, distrust of police and political disaffection — directly qualifying the stronger reading of Ofcom’s letter. Both are authoritative, both are dated, and they do not agree.

    Ofcom (22 Oct 2024) vs HMICFRS Tranche 2 review (May 2025)
  3. 3Who originated the false claim, and whyNot established

    Channel3Now published the false name first; Pakistani police arrested an individual linked to the site on 20 August 2024, then dropped the case six days later for lack of evidence he was the originator. The BBC found no evidence for separately-circulated claims of Russian state involvement. No source establishes who wrote the false claim or why.

    Wikipedia (Channel3Now), cross-checked against contemporaneous press reporting

Verdict. The false name spread fast and reached a real, measured audience within hours, in a three-day window when the law kept regulated broadcasters silent about the suspect’s identity. Whether that spread was a primary cause of the riots, a contributing factor, or one strand among several deeper causes is a live, sourced disagreement between Ofcom and the police inspectorate that reviewed the same events — and this page does not resolve it more confidently than the sources themselves do.

What still cannot be concluded. See the full list below — this is not a settled causal story, and the page does not treat it as one.

What this case study cannot be used to conclude

  • That "the algorithm" specifically — as opposed to a platform’s moderation policy, its verification/monetisation design, or individual users’ own sharing choices — was the cause of the false name’s spread. Ofcom names "virality and algorithmic recommendations" as a factor; Amnesty’s report analyses X’s recommender code specifically; neither isolates the algorithm’s contribution from these entangled design choices.
  • That online misinformation was the cause, or even the primary cause, of the riots. HMICFRS’s statutory review and the Children’s Commissioner explicitly pushed back on that "prevailing narrative," citing deprivation, distrust of police and political disaffection as more complex underlying drivers.
  • Who specifically originated the false claim, or why. The one investigation into this (Pakistani police, against a Channel3Now-linked individual) was dropped for lack of evidence.
  • A precise reach total. The individual figures above measure different platforms, accounts and time windows and are not additive — and a widely-circulated aggregate figure could not be traced to any primary source and is excluded.

Back to the media section for ownership, funding, and the regulatory picture this page extends — and to the Brexit case study for the equivalent treatment of a broadcast-and-press campaign.