Default settings: the value nobody touched is still a choice you made
6 min read
On 24 July 2026 the European Commission sent TikTok its preliminary findings: in its preliminary view, minors’ accounts do not meet the safety standards required by Regulation (EU) 2022/2065, the Digital Services Act (press release IP/26/1679). One thing first, because almost every news report flattens it: this is not a finding of infringement, it is the act by which the Commission puts its objections in writing and opens the exchange. “These preliminary findings do not prejudge the final outcome of the investigation,” the Commission writes.
We cover it for a reason that has nothing to do with social media. What is objected to is a default configuration. Not illegal content, not a secret algorithm, not a data breach: the preset value of an option.
What has been objected to
From the press release: on TikTok minors can set their account to “public”, and then “any user, including those without a TikTok account, may be able to view minors’ content”; the same setting allows content by “older” minors (16-17) to be recommended to anyone through the For You Feed. The Commission preliminarily considers that TikTok “should adjust the default settings” of those accounts, so that content is visible only to users the minor has accepted and does not end up in the feed.
The obligation invoked is Article 28(1) of the DSA: providers of platforms accessible to minors “shall put in place appropriate and proportionate measures to ensure a high level of privacy, safety, and security of minors, on their service”. The press release cites no article numbers, but that provision appears in the formal proceedings opened on 19 February 2024 — alongside Articles 34(1), 34(2), 35(1), 39(1) and 40(12) — which already named default privacy settings for minors among the areas investigated.
TikTok has responded, in a spokesperson’s statement carried by news agencies — no dedicated post appears on its newsroom: protecting minors online is “a goal we share”, teen accounts come with “more than 50 preset privacy and safety features” from the moment they are created, and under-18 accounts are private by default. The two positions do not exclude each other, and the friction is in the press release itself: the guidelines on the protection of minors — 14 July 2025, Article 28(4) — recommend designing minors’ accounts to stay safe even when those settings are modified.
What happens next, in exact terms
The mechanism sits in Articles 73 and 79. Preliminary findings necessarily precede a non-compliance decision and set out the measures the Commission considers necessary (Article 73(2)). From that moment the company may be heard, may access the file “under the terms of a negotiated disclosure” — internal documents and confidential information excluded — and may submit written observations within a period that “may not be less than 14 days”; the Commission then decides only on objections the parties could comment on (Article 79). In parallel the European Board for Digital Services is consulted (Article 66(4)).
Three outcomes are possible, not one: closing the investigation by a decision (Article 73(5)); making the company’s commitments binding (Article 71), as on 5 December 2025 on the advertising-transparency strand, closed without a fine; or adopting a non-compliance decision. Only in the third case does Article 74(1) come into play: no more than 6% of total worldwide annual turnover in the preceding financial year, and only where the infringement is committed “intentionally or negligently”; the amount follows nature, gravity, duration and recurrence, with the Court of Justice holding unlimited jurisdiction over it (Article 81).
The same proceedings have already produced other preliminary findings — 24 October 2025 on researchers’ data access, 6 February 2026 on addictive design — at the same stage: written objections, no definitive finding.
A default value is a compliance decision
Here is the lesson that holds outside platforms, for anyone installing systems in a company or a public body. European law already regulates the default: Article 25(2) of the GDPR requires the controller to ensure that “by default, only personal data which are necessary for each specific purpose” are processed — covering amount, extent, storage and accessibility — and in particular that “by default personal data are not made accessible without the individual’s intervention to an indefinite number of natural persons”.
The consequence is uncomfortable: every setting left as it came from the factory is a choice, and not having touched it is not a defence. Whoever asks you to account for it one day — an authority, a client, an auditor, a judge — will not distinguish the value you decided from the one you inherited. They will find the value.
Five defaults almost nobody decides
Typical scenarios, not real cases:
- Preset sharing level. A new collaboration space starts on “anyone with the link”. Nobody changes it. Six months later it holds tender documents.
- Log retention. The product keeps thirty days; Article 26(6) of the AI Act asks the deployer for at least six, an internal investigation for more.
- Telemetry on. Diagnostics and statistics start on, flowing to the supplier: nobody authorised that in writing.
- Supplier access. Remote assistance is enabled at installation. The question is not “do we trust them?”, but “who came in, when, and how do you prove it?”.
- Training on customer data unless you object. The objection must be exercised and documented before use. Between a consumer and an enterprise account the difference is largely one of default values: the heart of shadow AI.
What to put in writing
The remedy is not switching everything off: it is recording settings the way decisions are recorded. For every option touching personal data, trade secrets or evidence: value chosen, factory value, who decided, when, on what grounds, who may change it, how you find out if it changes. It belongs in the same folder as the NIS2 evidence and makes the internal AI policy enforceable, otherwise a set of principles without values. Then the rule the Commission set out in its guidelines: the configuration must hold even after it has been modified. A safe default that two clicks disable protects only until somebody tries.
A default value can be decided, justified and documented only if the environment is yours. On a shared service the supplier chooses the default, an update changes it, and you find out afterwards. That is why we deliver in two modes, never one: on-premise inside the client’s infrastructure, or on a dedicated cloud reserved for the single client, with a dedicated VPN, a data centre resident in Italy and premises we staff ourselves. In both, the initial configuration is a written decision, and AI governance starts there: no value arrives “from the factory” without someone approving it.
Want to know which of your default settings you should be able to justify, and how to keep the evidence? Half an hour with one of our experts for a first map.
Sources
- European Commission — preliminary findings on TikTok and minors’ accounts, press release IP/26/1679 (24 July 2026)
- European Commission — opening of formal proceedings against TikTok, with the list of DSA provisions (19 February 2024)
- Regulation (EU) 2022/2065 (DSA) — Articles 28, 66, 73, 74, 79 and 81 (EUR-Lex)
- Eunews — the Commission’s objection and TikTok’s response (24 July 2026)