Platform Accountability

Verify platform data during election: researchers locked out by TikTok

Adriana Iamnitchi, a researcher at Maastricht University, asked TikTok for access to its API. TikTok said no. According to her own account, the platform told her she had failed to prove she was an established researcher, failed to explain her commercial interests, and failed to meet its security requirements.

"If you are a scholar interested in how social media shapes society, the past years have been tough," Iamnitchi wrote. "When you need data to investigate that impact, and that data is privately held, it can become practically impossible to research this space."

TikTok published its own account of what had been happening on the platform. It said it had flagged 116,000 accounts as potentially compromised and removed more than 27,000 fake accounts in a coordinated network. The network, TikTok said, was run by a third-party "fake engagement vendor," and it had been promoting the Romanian candidate Calin Georgescu and his party, AUR.

The two events are not directly linked in the reporting, and I am not going to pretend otherwise. But the problem sits cleanly in the gap between them: the one party positioned to explain what the recommendation system did was also the party that had just declined to let an outside researcher look.

The only version in circulation

The stakes here are not hypothetical. Georgescu's posts — espousing hard-line immigration views and anti-Semitic tropes — were viewed 120 million times on TikTok before Romania's first-round presidential vote in November 2024. He won 23 percent of the vote after previously polling in the single digits.

Declassified Romanian intelligence later concluded that Georgescu "benefited" from massive exposure and preferential treatment by TikTok, and that Russia had allegedly coordinated the online campaign to elect him. That is the intelligence assessment's language: preferential treatment, benefited. It is not a finding that the algorithm was designed to favor him. Whether the amplification was deliberate, incidental, or the product of the vendor network TikTok later dismantled is exactly the kind of question an independent examination of the data would exist to answer.

No such examination happened. TikTok's internal accounting — the 116,000 flagged, the 27,000 removed, the unnamed vendor — is the only version of events in circulation. It may be accurate in every particular. The point is that there is no way for anyone outside the company to check it. The audit trail belongs to the operator, and the operator investigated itself and reported the result.

A law built for exactly this

The European Union anticipated this scenario. The Digital Services Act gives vetted researchers a legal right to platform data, precisely so that a platform's own narrative about what its systems did during an election is not the last word. Iamnitchi's request was an attempt to use that right. It was denied.

The denial is not an isolated obstruction. The reporting describes a pattern that runs across TikTok, X, and Meta, in which the legal right survives on paper while the process around it makes exercising the right impractical.

Consider the infrastructure demands. Iamnitchi has said that most universities lack the infrastructure platforms require for storing researcher data securely — such as a machine physically disconnected from the internet. A requirement like that does not reject an application. It just quietly excludes every applicant who does not already have an air-gapped machine and the staff to run it.

Then there is reproducibility. Iamnitchi has said API data is often difficult for a colleague to reproduce, which means a researcher's work cannot be checked for errors — something she called a "basic requirement of science." A dataset that cannot be regenerated cannot be peer-reviewed in the normal sense. The tool grants access while stripping out a property the work needs to count as science.

The European Commission has noticed. In a DSA investigation, it said that Meta and TikTok "may have put in place burdensome procedures and tools for researchers to request access to public data," leaving them with partial or unreliable data. That investigation has not concluded, and it has produced no findings yet. It is an allegation the Commission is examining, not a verdict.

Researchers describe the effect in blunter terms. L. K. Seiling, who coordinates the DSA40 Collaboratory, put it this way: "There's no structured advantage for researchers to use this pathway. Data access as it's set up right now tries to disincentivize researchers."

What the numbers actually show

The approval statistics are worth sitting with, because they cut two ways. The DSA40 Collaboratory tracked 46 researcher applications across platforms: 20 approved, 14 rejected. TikTok approved 11 of 13 tracked applications. X rejected 11 of 23.

An approval rate like TikTok's looks like compliance. It is the kind of figure that goes in a transparency report. But approval is measured at the point of application, and the friction researchers describe lives everywhere else — in the security requirements that filter who can apply, in the reproducibility gaps that hollow out the data once granted, in the caps on how much can be pulled.

TikTok told researchers it has given 1,500 research teams access to its tools and approved 130 EU researcher applications in the second half of last year. It also caps API access at 1,000 daily requests per researcher, allowing up to 100,000 video and comment records a day, or up to 2 million follower records. Those are real limits on the shape of a study. Whether they are reasonable operational ceilings or a way of keeping analyses small is not something the raw numbers settle. The same figure — an approval, a cap, a headcount — reads as diligence from the platform and as obstruction from the researcher. That gap is the whole story.

The one action that landed

The DSA is not toothless. In December 2025, the European Commission fined X €120 million ($137 million), partly for creating "unnecessary barriers" to researcher access that "effectively undermin[e] research into several risks in the European Union." The Commission later accepted a corrective action plan requiring X to fix its researcher screening process, provide data free of charge, cut processing times, and lift restrictions on data scraping within six months.

That is the law working. It is also a single action, arriving after a long stretch of the behavior it targets, against one platform, with a six-month runway to comply. Set it against the pattern the reporting describes across three companies and it looks less like a deterrent than a demonstration of how much has to go wrong, and how slowly, before enforcement moves.

The researchers who have pushed hardest are candid about the toll. Duncan Allen said of the data-access law: "EU law is still not uniformly applied. It's cost us a lot of time and energy, and there is an ongoing calculus of whether or not it's worth having these lawsuits every time we apply for data access." Note what that describes: not scholars who lost interest, but scholars weighing whether litigation is a sustainable cost of doing research at all. That calculus is the disincentive Seiling named, expressed as a decision a person actually has to make.

When the operator owns the log

Strip the politics out and a structural fact remains. An automated system produced an outcome with public consequences. The only party able to produce the record of what the system did was the party whose conduct was in question. Everyone else got a summary and an assurance that the matter had been looked into.

"We looked into it" is not independent verification. It is a report from the interested party. The DSA exists to convert that report into something checkable, and the reporting suggests the conversion is failing more often than the approval rates admit.

This generalizes past social platforms, and it should worry anyone running automated decision-making in production. If the only account of what your system did is the one your system's operator chooses to assemble after the fact, you do not have an audit trail. You have a press release. The record has to be built as the actions happen, by machinery separate from the party whose behavior it documents, and it has to be legible to someone who did not run the system.

That is not free. An independent, reviewable action log — what was done, by whom, under what authorization, and on what basis — is real infrastructure, and it costs engineering time to build and discipline to maintain. The EU's experience is the cautionary version: a legal entitlement to the record turned out to be a long way from anyone actually holding the record in their hands. Designing for auditability is cheaper than being compelled into it, but it is not cheap, and pretending otherwise is how you end up with a log nobody can reconstruct when it matters.

This is the problem Pipeer is built around for internal AI systems: source-linked answers that cite the ticket, document, or message they came from, permission-aware access that respects the grants a user already has, and a complete action history of what was done and on what basis — so the record exists before anyone thinks to ask for it, and it is not assembled by the actor after the fact. The tradeoff is honest: that record is infrastructure you have to run, and it will not maintain itself.

What the Romanian case leaves unresolved is whether the law can force the same discipline on platforms that would rather not produce it. One fine says maybe. The pattern behind it says not yet.


Photo by Winston Chen on Unsplash