Skip to content

How the effects of AI systems compound in people and society

Governing AI for cognitive integrity part four

This is part four of “Governing AI for cognitive integrity”, a report examinig AI’s impact on human autonomy through a cognitive lens. Read the other chapters here

Introduction

The governance limitations discussed across our cognitive integrity framework have a shared structural problem: every instrument is calibrated to govern a single layer of the system, while the harms this framework has documented emerge from the interaction of multiple layers simultaneously. Governance architectures designed for discrete, identifiable violations are applied to harms that are diffuse, cumulative, systemic, and developmentally complex. Some harms emerge only at the collective level. Others accrue to individuals through repeated exposure rather than single incidents. All are produced by the compounding of business model incentives, data infrastructure, and system design operating together — manifesting differently depending on developmental stage, mental health status, and situational context.

Enforcement fragmentation

The GDPR, the AI Act, the DSA, the DMA, and the CSDDD are each enforced by different authorities operating under different mandates. Our overview table summarises how these and other EU instruments protect cognitive integrity and where their coverage falls short. Please refer to our Governance map for a more detailed view of the relevant instruments and provisions.

 

Across instruments, the problem compounds. For example, a single practice — engagement optimisation through recommender systems — simultaneously triggers GDPR data protection obligations, AI Act market surveillance, DSA systemic risk assessment, UCPD consumer protection enforcement, DMA market power review, and Charter-based dignity and mental integrity claims. No single authority has comprehensive oversight, and each sees one dimension of a harm produced by all of them operating together. A direct consequence of this is that restricting harmful content without governing the recommendation architecture that surfaces it addresses one dimension of a multi-dimensional harm. Effective enforcement requires integrated assessment, but the current architecture makes that structurally unavailable.

The redress mismatch

Redress mechanisms assume users can identify a violation, understand its effects, and navigate a complaint procedure — conditions that the cognitive mechanisms documented in this framework actively undermine. Users cannot meaningfully “access” inferred psychological profiles, “rectify” engagement optimisation algorithms, or “erase” the cognitive habits those systems have progressively shaped.

Beyond the individual level, in order to prove psychological harm at scale, collective redress requires longitudinal data, technical analysis, and platform data that companies consistently withhold, directly impacting research in this area. Consequently, courts lack established frameworks for assessing cognitive harm causation, and platforms can invoke multiple alternative causes. The Representative Actions Directive enables qualified entities to bring collective claims, but without data access and established causation standards, high barriers remain even where population-level harm evidence is substantial.

Compounding this, redress mechanisms such as product liability operate after it occurs, which is structurally inadequate when harms — especially developmental harms — may be irreversible. The modernised Product Liability Directive explicitly extends its scope to cover software, including AI systems, and recognises medically relevant psychological harm as compensable damage[1]. It further clarifies that defectiveness must be assessed in light of expected safety, taking into account factors such as product design, presentation, and reasonably foreseeable use. However, the Directive continues to require claimants to establish defectiveness, damage, and a causal link between them. In the context of engagement-optimised digital systems, what constitutes a “defect”, and how individual causation can be demonstrated where harms are cumulative, probabilistic, and mediated by complex socio-technical environments, remains legally unresolved[2] . The reform acknowledged this uncertainty without actually resolving it.

The case for acting now

The growing movement of offline clubs[3] — spaces where young people gather without devices around shared activity and face-to-face connection — signals that the demand for less mediated experience exists, is being expressed collectively, and is generating social innovation that the market has not produced. These initiatives are evidence of genuine appetite for alternatives.

That appetite is also an opportunity for the industry itself. The framing of cognitive integrity governance as a constraint on innovation misreads both the science and the market. Users who are cognitively depleted, emotionally dependent, and progressively less capable of autonomous judgement are a liability to public health, to democratic functioning, and ultimately to the platforms themselves as regulatory and reputational pressure mounts.

The governance challenge is how to make cognitive integrity the condition on which human rights, competitiveness, and genuine technological benefit are built together. That is the standard Europe’s constitutional commitments demand. The following principles and recommendations set out how to meet it.

Governing principles

The recommendations that follow are grounded in 10 governing principles, naming the structural conditions for effective and legitimate governance of cognitive integrity.

Cognitive integrity.The protection of human autonomy over the cognitive processes through which individuals think, decide, and act is the foundational standard against which AI governance must be assessed.

Explicit duty of care. Governance must be anchored in an explicit obligation requiring operators to protect the cognitive integrity of their users, establishing that its protection is enforcement of fundamental rights, not regulatory overreach.

European values. Governance must be grounded in EU constitutional commitments and empirical understanding of cognitive harms, and oriented toward cultivating the conditions in which cognitive integrity can be developed and exercised.

Intersectionality and multidisciplinarity. The cognitive mechanisms through which AI systems produce harm are shared across all users, but their effects fall unevenly across individuals. Understanding how requires coordination across regulatory instruments and disciplines.

Anticipation and precaution. AI-mediated technologies impacting cognitive integrity evolve faster than regulatory cycles and governance cannot afford to arrive late. Where clear harm mechanisms, vulnerable populations, and mounting evidence exist, precaution is warranted — targeted at system design and platform architecture, not individual users.

Iteration. Regulatory standards must evolve through structured feedback between independent research and regulatory obligations. Different evidence streams (scientific, legal, civil society documentation) operate on different logics and timelines. Governance frameworks should be explicit about which evidential standard justifies each intervention, act proportionately on available evidence without waiting for scientific certainty, and revise standards as evidence accumulates.

Institutional resilience. Enforcement must be insulated from political cycles, with standards that are evidence-based rather than discretionary.

State power. Governance must be oriented toward structural regulation of the conditions under which systems operate rather than the content they carry, and require proportionality and independent oversight when intervention reaches individual freedoms.

Ownership concentration. Governance must be structurally alert to ownership concentration, ensuring that regulatory design and enforcement are resilient to the power asymmetries that concentration creates.

Sectoral maturity. Effective governance requires that industry develops genuine professional standards and internal accountability mechanisms alongside state regulation, as a complementary layer to keep pace with innovation.

Recommendations

Recommendation 1. Integrate enforcement of existing regulatory frameworks around cognitive integrity

The GDPR, AI Act, DSA, DMA, CSDDD, consumer protection law, and the Charter collectively reach every layer through which cognitive harm is produced. What they lack is integrated enforcement: separate authorities assess isolated practices under separate mandates, missing the systemic character of the harm. Cognitive integrity should serve as the shared interpretive standard that connects them.

Actions

  • The Commission should use its supervisory competence under the DSA[4]  and AI Act[5] to develop integrated enforcement strategies for cumulative cognitive harm across regulatory domains.
  • The DSA’s systemic risk assessment framework[6] should be extended across the full governance architecture and codified in enforcement standards, accompanied by a reversal of the burden of proof: operators should be required to demonstrate that their systems incorporate adequate safeguards against known cognitive harm mechanisms, shifting the burden of proof from regulators to operators.
  • The EDPB should issue binding guidance connecting GDPR profiling and consent obligations to the cognitive harm mechanisms documented in this framework.
  • National Digital Services Coordinators and data protection authorities should coordinate systematically, including through joint investigations, where the same practice engages obligations across multiple instruments.
  • A reassessment of the Commission’s enforcement capacity should evaluate whether the current architecture can withstand sustained industrial and geopolitical pressure and enable integrated learning across instruments. Where existing structures prove insufficient, a dedicated independent enforcement body with a mandate for integrated assessments of cognitive harms merits serious consideration.

Recommendation 2. Recognise cognitive vulnerability as a universal gradient

The Digital Fairness Act (expected Q4 2026) is the most proximate legislative opportunity to operationalise cognitive integrity in EU consumer law. How vulnerability is defined will determine whether the DFA reaches the harms this framework documents.

Actions

  • The DFA should define consumer vulnerability in cognitive terms, recognising that vulnerability to the design features this framework documents operates through cognitive architecture all users share. Developmental stage, mental health status, and situational context modulate severity along a gradient, but they do not define a boundary between vulnerable and non-vulnerable users.
  • Dark pattern assessment under the DFA should account for cumulative effects: practices that become manipulative through repeated exposure over time, and that compound when operating simultaneously.

Recommendation 3. Require safety evaluation of AI systems for their cumulative impact on human cognition, behaviour and cascading societal effects

Safety evaluations of AI systems should extend to longitudinal and cumulative impact on human cognition and behaviour, and to the societal effects that follow when those impacts occur at population scale. Independent research should establish benchmarks accounting for cumulative exposure rather than isolated encounters, and for developmental, neurocognitive and situational differences in cognitive vulnerability.

Actions

  • Operators should assess and report the longitudinal effects of their systems on users’ cognitive functioning and behaviour, and their aggregate effects at population level. In the absence of settled benchmarks, evaluations should apply the best available measures and be revised as the evidence base develops.
  • Building on DSA Article 40, operators should be required to provide ongoing, disaggregated data access for independent research, with scope determined by research needs and appropriate privacy safeguards.
  • Evidence should build on pre-registered longitudinal study designs, standardised outcome measures for cognitive harm beyond self-reports, and shared methodological frameworks so that findings from different studies can be compared and combined.
  • Governance frameworks should require active verification of funding sources and conflicts of interest in research cited in regulatory proceedings, and should invest in publicly funded research programmes.
  • The Commission should establish or mandate an existing multidisciplinary expert body tasked with developing provisional cognitive integrity benchmarks, centred on whether AI systems undermine human autonomy in the exercise of cognitive capacities. Benchmarks should be developed through a transparent process with civil society and affected community participation, and revised as evidence accumulates.

Recommendation 4. Enable collective redress where individual causation cannot be established

Existing redress mechanisms predominantly require individual causation and are not designed to capture the downstream costs of extractive design on public health, productivity, and democratic functioning. Where science documents that specific design features impair cognitive functioning and population studies show correlated harms, collective redress should be available. Collective redress should extend to cases where harm to a single individual cannot be traced to a single design decision.

Actions

  • Collective claims should be supported by population-level evidence of cognitive harm, without requiring proof of individual causation.
  • Meaningful collective redress depends on the data access provisions in Recommendation 3 being in place. Without them, the evidentiary bar for collective claims becomes a structural shield for industry.
  • Collective redress, funded through enforcement penalties, should recognise the inherently collective character of these harms. A portion of penalty revenues should be allocated to digital literacy education, independent research on cognitive harms, and the development of public interest alternatives to engagement-optimised platforms.

Recommendation 5. Address ownership concentration and industry accountability

Competition policy should treat cognitive harm as within its remit. The concentration of AI infrastructure in a small number of already-dominant companies is constitutive of the harms this framework documents: engagement-driven business models leave no incentive to protect cognitive integrity, and the same firms control the alternatives or the infrastructure  that would otherwise correct for it.

Actions

  • Investment in European AI infrastructure, including open-source models and shared compute, is a structural precondition for credible governance. Without viable alternatives, enforcement against dominant players lacks practical leverage.
  • The DMA’s provisions on interoperability, data portability, and self-preferencing should be enforced with cognitive harm dynamics explicitly in view.
  • The traditional consumer welfare standard, assessed in price, quality, and innovation, should be reformed to incorporate the downstream costs of free digital services on public health and democratic functioning.
  • Co-regulatory frameworks, in which public authorities set binding legal requirements while industry develops detailed technical standards with civil society involvement, should be pursued through the AI Act’s standardisation mandate, the DSA’s voluntary commitments infrastructure, and the forthcoming DFA. Standards should be revised when evidence requires it, and the enforcement architecture must be credible enough to prevent co-regulation from becoming self-regulation.

Recommendation 6. Empower individuals and communities

Individuals, families, and communities are active agents whose choices shape how technologies are experienced. Empowering that agency is a complement to structural governance, not a substitute for it. Effective empowerment requires that people understand how the systems they use interact with their cognitive functioning, and that alternatives to engagement-optimised environments are available and supported.Actions

  • Investment in digital literacy programmes should be grounded in multiple disciplines, including cognitive and computer science, building genuine understanding of how recommender systems, generative AI, and engagement-optimised design interact with cognitive functioning and how individuals can empower themselves on top of regulatory action.
  • Digital literacy curricula should be adopted evenly across Member States[7] [8], with EU-level coordination to address current gaps in provision.
  • Public investment should support community-level alternatives to engagement-optimised environments, recognising that cognitive integrity is exercised collectively as well as individually.

[2] European Commission, Impact Assessment accompanying the revision of the Product Liability Directive, SWD(2022) 316 final (discussing causation challenges, information asymmetries and multi-causal harms in digital and AI systems https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52022SC0317#:~:text=2.,when%20victims%20face%20disproportionate%20difficulties; ii) EPRS, Civil liability regime for artificial intelligence (noting lack of established case law and difficulties in proving causation): chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://www.europarl.europa.eu/RegData/etudes/BRIE/2023/739342/EPRS_BRI(2023)739342_EN.pdf 

[3] The Offline Club, “Swap screen time for real time Offline hangouts and events to unplug, relax and connect with like-minded people.,” The Offline Club, 2026, theoffline-club.com, accessed 9 March 2026.

[4] DSA Regulation (EU) 2022/2065, Article 56(2).

[5] AI Act Regulation (EU) 2024/1689, Article 88.

[6] DSA Regulation (EU) 2022/2065, Articles 34-35.

[7] European Schoolnet, “Artificial Intelligence in School Education. An overview of policy priorities and initiatives across 23 education systems,” European Schoolnet, 2025, eun.org/documents/411753/12100059/Agile+collection+of+Information+vol.6-11.12.25_Updated.pdf, accessed 12 March 2026.

[8] European Parliament Research Service, “Growing focus on digital skills,” European Parliament Think Tank, 2025, epthinktank.eu/2025/03/04/growing-focus-on-digital-skills, accessed 6 February 2026.

Subscribe

Stay up to date on the research, debates, and governance of climate intervention technologies

A view into the world of neurotech, covering new tech, policy, research, and the debates that matter



Centre for Future Generations
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.