In the final weeks before Romania’s presidential vote in November 2024, TikTok accounts that had previously spent years posting about manicures or fashion suddenly started promoting a little-known politician named Calin Georgescu.His posts, espousing hard-line views on immigration and anti-Semitic tropes, were viewed 120 million times before the vote. Georgescu, who had previously been polling in the single digits, stunned observers by winning the election’s first round with 23 percent of the vote.In the Netherlands, Adriana Iamnitchi was watching closely. As chair of computational social sciences at Maastricht University, she leads the research into disinformation campaigns. She wanted to know how pro-Georgescu content was being monetized on TikTok through hidden- influencer marketing and livestreamed political content.On October 28, 2025, a month before Georgescu won the first round, she and her team applied for access to TikTok’s Application Programming Interface (API) under the EU’s recent Digital Services Act (DSA).Their request was denied. TikTok said they had failed to prove they were established researchers or to explain their commercial interests or to meet security requirements, Iamnitchi wrote in a blog post.But two month’s later, TikTok flagged 116k accounts as potentially compromised before taking action against more than 27,000 fake accounts in a coordinated network run by a third-party “fake engagement vendor” that was promoting Georgescu and his party, the Alliance for the Union of Romanians (AUR). TikTok said it did not know who operated the network or where it originated.The the first round of voting was annulled and in the runoff in May 2025, independent candidate and former Bucharest mayor Nicușor Dan beat AUR’s George Simion, who took over the party after Georgescu was barred from running again. Georgescu said on his YouTube channel that annulling the 2024 results was “practically a formalized coup d’état” by Romania’s Constitutional Court.Declassified Romanian intelligence showed he “benefited” from massive exposure and preferential treatment by TikTok and that Russia had allegedly coordinated the online campaign to elect Georgescu.Calin Georgescu Photograph: Getty ImagesIamnitchi believes her team might have been able to identify who created and profited from the pro-Georgescu content had they gained access to the data. “If you are a scholar interested in how social media shapes society, the past years have been tough,” she wrote. “When you need data to investigate that impact, and that data is privately held, it can become practically impossible to research this space.”Iamnitchi is one of several misinformation researchers who told WIRED that, despite being legally entitled to obtain platform data under EU law, they face obstacles, obfuscation, and, in some cases, court battles to obtain it. Last year the law was broadened to increase researcher access, but it’s the implementation not the scope of the law itself that researchers say is the issue.In recent years, social media companies shut down public access tools like Meta’s CrowdTangle and replaced them with content libraries, or, like X, paywalled their API data, forcing academics to pay “hundreds of dollars a month,” said Duncan Allen, a research officer at Democracy Reporting International (DRI) in Germany. Researchers say that without API access, what Iamnitchi describes as the “black holes” in what society knows about how these platforms recommend content or handle reports regarding sensitive content will only grow.Others, like TikTok, cap how many posts any researcher account can pull each day, which Allen said can make it “impossible to study anything at scale.”The DSA was meant to solve this by allowing vetted researchers at credible institutions to have access to API data if they could show it would help in studying systemic risks, from illegal content to threats to fundamental rights. But two years after the law took effect, researchers say they struggle to meet its security requirements and face narrow interpretations from platforms of what qualifies as a systemic risk.Application forms differ by platform, but most require data to be stored on infrastructure that cannot be compromised—such as a machine physically disconnected from the internet—a resource most universities lack, Iamnitchi said.Even for researchers who secure approval, “there's no guarantee that the data is good,” said L. K. Seiling, coordinator of the DSA40 Collaboratory, a German initiative that tracks 46 DSA applications. API data is often difficult for a colleague to reproduce, so a researcher’s work cannot be checked for errors, which Iamnitchi said is a “basic requirement of science.”DSA40 data shows that of 46 tracked applications, 20 were approved and 14 rejected. But approval rates vary widely: TikTok approved 11 of 13 applications, while X rejected 11 of 23. The true rejection rate is likely higher because the tracker relies on voluntary reporting, Seiling said.“There's no structured advantage for researchers to use this pathway,” Seiling said. “Data access as it’s set up right now tries to disincentivize researchers.”A TikTok spokesperson told WIRED the company has given more than 1,500 research teams access to its tools, approved 130 applications in the EU in the second half of last year, and that its daily quota of 1,000 API requests lets researchers pull up to 100,000 video and comment records a day, or up to 2 million follower records. TikTok said it considers its research tools compliant with the DSA but “would welcome further public guidance.”A Meta spokesperson said CrowdTangle covered only a fraction of the company’s public data, while the Meta Content Library and API that replaced it are “the most comprehensive research tools to date.” They cover Facebook, Instagram, WhatsApp Channels, and Threads with “robust privacy protections,” and qualified nonprofit researchers, including journalists, can apply.There are few workarounds. Iamnitchi and Allen said they resort to scraping on the platforms that allow it, a time-consuming process that exports website data into spreadsheets. Even with sophisticated tools, scraping “is not very comprehensive,” Allen said. It cannot capture an account’s complete follower list, making coordinated disinformation networks difficult to map.One way to challenge a rejected request is to take the platforms to court. Allen said DRI and the Society for Civil Rights applied for access to X’s API in April 2024 to study political discourse ahead of Germany's federal election. X rejected the request in November, prompting DRI to sue in February 2025.The court ruled X should have granted access, in what DRI believed could become a precedent-setting case. But months later the organization was back in court after X denied access for research ahead of Hungary’s election. That case nearly collapsed when a Berlin court ruled the researchers should have sued in Ireland, where X is based. DRI won on appeal.“EU law is still not uniformly applied,” he said, reflecting on the Hungarian case. “It's cost us a lot of time and energy, and there is an ongoing calculus of whether or not it’s worth having these lawsuits every time we apply for data access.”In December 2025, the European Commission imposed its first DSA penalty, fining X €120 million ($137 million) partly for creating “unnecessary barriers” to researcher access that “effectively undermin[e] research into several risks in the European Union.”On February 20, 2026, X appealed, calling the investigation “incomplete and superficial” and accusing the EU of “systemic breaches of rights of defence and basic due process requirements.”Last week, the commission accepted X’s action plan to fix the researcher screening process, provide data free of charge, cut processing times, and lift restrictions on data scraping. X has six months to put these changes in place.Allen called the plan “a step in the right direction” but remains sceptical about how it will be implemented. He wants X to be more specific about how it will improve the vetting process used to determine whether researchers qualify for API access under the DSA.The EU, having said in another DSA investigation that Meta and TikTok “may have put in place burdensome procedures and tools for researchers to request access to public data,” leaving them with partial or unreliable data, started meeting with platforms in May to work on a new standard for vetting researchers.Late last year, the commission also expanded researchers’ access to nonpublic platform data to study risks including illegal content, financial scams, and recommender systems. Researchers say the new provisions have yet to be tested, but they are cautiously optimistic.The new regulations on nonpublic data could force X to release an account’s full follower list. This gives disinformation researchers a much clearer view of how coordinated attacks spread online, because they can use this data to map out which accounts interact or follow one another and how they amplify content, Allen says.
European researchers want to study social media’s harms but can’t get the data
Full Article
Original Source
Read the full article at Wired →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.