
Privacy & Surveillance · 11 min read
The Attention Economy Is an Institutional Problem, Not a Personal Failure
When people lose an evening to an endless feed, the usual explanation is personal: weak willpower, poor habits, insufficient discipline. That story is comforting to the institutions around the problem. It turns a design
When people lose an evening to an endless feed, the usual explanation is personal: weak willpower, poor habits, insufficient discipline. That story is comforting to the institutions around the problem. It turns a design question into a character question, and it makes the remedy sound private too: set a timer, delete an app, try harder tomorrow.
But the evidence points toward a different frame. Recommendation systems, notifications, interface patterns, advertising markets, data collection, product teams, regulators, schools, parents, researchers, and lobbyists all shape the environment in which attention is spent. The question is not simply whether a particular person can stop scrolling. It is whether powerful institutions have incentives to make stopping difficult, and whether public safeguards are capable of changing those incentives.
Research on algorithmically curated social media connects these systems with outcomes including anxiety, depression, loneliness, self-esteem concerns, and political polarisation, while also stressing that the research base is complex and that causality is not always easy to establish.[S1] The appropriate response is neither denial nor panic. It is institutional realism: recognise uncertainty where it exists, identify where incentives are clear, and build protections that do not depend on every user winning a daily contest against a personalised engagement system.
This perspective also changes what counts as success. A healthier digital environment is not one in which users are told to become perfectly self-regulating. It is one in which companies must show that their products do not systematically undermine users’ ability to make meaningful choices about their own time, attention, and mental wellbeing.
The Business Model Determines What the Product Is Optimised To Do
Many large platforms are not merely communication tools that happen to contain advertisements. Their commercial model links revenue to advertising effectiveness, the number of advertisements displayed, the data available for targeting, and the time people spend inside the service.[S6] That does not mean every feature is designed with harmful intent. It does mean that the central performance measures of an ad-funded platform can reward keeping people present, responsive, and predictable.
This is why discussions about individual features can be misleading when separated from their financial context. Infinite scroll is not simply a convenient layout. Persistent notifications are not simply helpful reminders. Autoplay is not simply a way to reduce friction. In an attention-driven system, these features can work together to reduce stopping points, prompt returns, and extend sessions.
The institutional issue is therefore more precise than the slogan that platforms are “addictive.” Companies can test changes, segment audiences, measure retention, and refine recommendation systems at scale. Users usually cannot see the relevant objectives, experiments, trade-offs, or downstream effects. They encounter the result as a feed that seems personally compelling.
That asymmetry matters. A user may notice that they stayed longer than intended, but cannot easily tell whether the experience arose from social connection, useful information, a poorly timed notification, emotional content promoted by a recommender system, or an interface deliberately designed without natural stopping cues. A product team, by contrast, may have access to far richer behavioural data and testing capability.
This is not an argument that people lack agency. It is an argument that agency is exercised in an environment that others have designed, measured, and continuously adjusted. Responsibility should follow power. If an institution has the capacity to shape attention at scale, it should bear meaningful duties to assess and reduce foreseeable harm.
Evidence Should Inform Precaution, Not Excuses for Inaction
The relationship between social media and mental health is difficult to study. People bring different vulnerabilities, circumstances, social networks, and reasons for using technology. Correlation does not automatically establish causation, and broad claims about “screen time” can conceal important differences between activities, products, and users.
Those limits should make public discussion more careful. They should not make it passive.
The available research described in the supplied catalog identifies possible links between algorithmic curation and mental-health-related outcomes, including anxiety, depression, loneliness, self-esteem, and polarisation.[S1] Legal and policy analysis likewise argues that social-media design and the ad-based business model create plausible risks to individual mental wellbeing, public mental health, and mental integrity.[S6] A reasonable institutional standard does not require proof that every user is harmed by every feature. It asks whether a provider can identify foreseeable risks, examine how its systems contribute to them, and demonstrate proportionate mitigation.
That distinction is crucial. Public-health protection often operates under uncertainty. A school does not need proof that every child will be injured before installing a safer crossing. A manufacturer does not need a perfect causal account of every accident before investigating a credible design risk. The relevant question is whether the risk is plausible, material, and within the institution’s capacity to reduce.
For digital platforms, this means moving beyond generic safety statements. A company should be able to answer concrete questions. Does a particular recommender system increase repeated exposure to distressing material after an initial interaction? Do notification patterns lead users to return more often than they wish? Does an interface make it hard to leave, rest, or choose a less personalised feed? Are certain effects more pronounced for younger users or for people already showing signs of vulnerability?
If the company cannot answer, that is not evidence that the risk is absent. It may be evidence that the institution has not designed its measurement systems around the right questions.
Design Choices Can Protect Autonomy or Undermine It
The most useful practical standard is autonomy. People should be able to use digital services deliberately, understand the meaningful choices available to them, and leave without unreasonable resistance.
This standard avoids two bad extremes. It does not require banning social media or treating users as incapable of deciding for themselves. But it also rejects the idea that a consent screen or a buried setting is enough to make any design acceptable.
Autonomy-supporting design has visible characteristics. It gives people clear choices about recommendation systems. It makes time-use information easy to see rather than hiding it behind menus. It creates natural stopping points. It does not use urgent, emotionally loaded prompts simply to trigger a return. It allows people to choose a chronological or less personalised experience without having to understand a complex privacy dashboard.
The legal analysis in the source catalog identifies measures such as always-visible time information, time restrictions, and easier control over recommendation and engagement features as possible ways to increase user control.[S6] The Corporate Europe Observatory report similarly describes proposals including pagination instead of infinite scroll, default limits on attention-seeking features, and greater user control over recommender systems.[S7]
These measures matter because they alter the default environment. A setting available only to determined users is not the same as a protective default. In behavioural terms, friction is not neutral. The placement, wording, timing, and reversibility of a choice all influence what users actually do.
A practical safeguard should therefore be judged by its real-world accessibility. Can a person find it without specialised knowledge? Is it available at the moment they need it? Does it remain active, or does the product repeatedly pressure them to reverse it? Is the safer option as easy to use as the engagement-maximising one?
If the answer is no, the safeguard may function more as public relations than protection.
Regulation Must Target Systems, Not Just Content
Policy debates often focus on content: illegal material, misinformation, harassment, or particular categories of harmful posts. Those issues are important, but they do not capture the whole institutional problem.
A feed can contain lawful content and still be organised in a way that creates harm. A recommender system may amplify emotionally intense material because it drives engagement. Notifications can encourage compulsive checking without containing objectionable speech. Infinite scroll can extend a session regardless of the quality of the content being consumed.
The Digital Services Act offers a route for addressing some of these systemic issues. The legal analysis in the catalog argues that the Act’s risk-assessment and risk-mitigation duties for very large online platforms can encompass risks to mental wellbeing, public mental health, and mental integrity.[S6] Its argument is not that the law supplies an effortless solution. Rather, it proposes that existing obligations can require providers to evaluate risks produced by platform design and business incentives, not merely risks created by user behaviour.
That matters because it rejects a convenient deflection. Platforms can portray harm as something users do to one another while treating their own design decisions as neutral infrastructure. Yet ranking, recommendation, notification, interface design, and monetisation shape what people see, how often they return, and how difficult it is to disengage.
System-level regulation should require companies to document these choices and their effects. It should also distinguish between a company’s own risk assessment and independent scrutiny. A business that profits from engagement cannot be the only authority deciding whether its engagement practices are safe.
The goal is not a single universal formula. Different services, user groups, and features create different risks. But the duty to investigate, disclose, and mitigate should be common.
Transparency Is Necessary, but It Is Not a Complete Safeguard
Calls for transparency are often sensible and often insufficient. A platform can publish policies, issue reports, and offer data dashboards while the most consequential decisions remain opaque. Information alone does not correct a power imbalance if only the company can access the underlying systems, conduct large-scale experiments, or determine what counts as a relevant outcome.
Meaningful transparency needs several layers.
First, users need intelligible explanations. They should know when a feed is being personalised, what broad signals influence it, and how to select an alternative. This is a basic condition for informed choice.
Second, regulators and independent researchers need access that is sufficient to evaluate systemic risks. The source catalog notes that providers hold data that outside researchers often lack, while public authorities can use investigative powers in assessing platform risks.[S6] Without credible access, public debate can become a contest between corporate assurances and anecdote.
Third, reporting should be outcome-focused. It is not enough to say that a company has a wellbeing team or a set of controls. The more relevant questions are whether people use those controls, whether harmful patterns fall, whether safeguards work for vulnerable groups, and whether product changes create new risks.
Transparency can also support institutional memory. Platforms change rapidly. A safety measure announced today may be weakened, relocated, or overridden by a later product decision. Public records, independent audits, and recurring risk assessments make it harder for protections to disappear quietly when commercial pressure rises.
Lobbying Reveals Why Voluntary Promises Are Not Enough
The gap between a company’s public safety language and its policy preferences can be revealing. If a firm says user wellbeing is central but resists enforceable limits on the design patterns that drive engagement, the conflict may not be a misunderstanding. It may reflect the underlying business model.
The Corporate Europe Observatory report describes organised industry opposition to proposed EU action on addictive design and frames the debate as a conflict between public safeguards and commercial incentives.[S7] It reports that technology companies and lobby groups have argued that existing rules, voluntary practices, or flexible goal-based approaches are preferable to stronger requirements.[S7]
Some objections deserve consideration. Poorly designed rules can be vague, burdensome, or easily gamed. Regulation should not assume that every notification or personalised recommendation is harmful. But calls for flexibility should not become permission for institutions to define their own obligations so weakly that nothing changes.
The practical lesson is that public safeguards need enforcement mechanisms. Voluntary codes can complement regulation, but they cannot substitute for it where the commercial incentive points in the opposite direction. A promise to protect wellbeing is least reliable when the protection threatens the metric that drives revenue.
This is why lobbying transparency matters too. Policymakers should know who is advocating for which outcomes, what evidence they rely on, and whether claimed compliance costs are being used to avoid scrutiny of profitable design choices.
Practical Safeguards for Institutions and Individuals
The institutional frame does not make personal tools irrelevant. It puts them in their proper place. Individuals can benefit from turning off non-essential notifications, setting time boundaries, choosing less personalised feeds where available, and keeping devices away from sleep and focused work. These measures can reduce exposure to the most persistent prompts.
But the strongest safeguards should not rely on individual vigilance alone.
Platforms should make non-personalised or chronological options easy to select and retain. They should provide visible, accurate time-use information and durable session limits. They should avoid designs that hide exit points or repeatedly undermine choices to reduce engagement. They should assess whether recommendation systems repeatedly intensify exposure to distressing content after minimal signals of interest.
Schools and families can teach digital literacy that includes design literacy: not only how to spot misinformation, but how attention is monetised and why certain features feel difficult to resist. This should be taught without shame. The point is not to tell young people that they are failing. It is to help them recognise an environment built to compete for their attention.
Regulators should require recurring risk assessments, credible independent auditing, researcher access, and meaningful consequences when companies ignore known risks. Policymakers should also test whether a safeguard works in practice rather than accepting its existence on paper.
Finally, public institutions should resist false choices. The choice is not between unregulated engagement systems and a joyless, censored internet. There is substantial room for services that support communication, creativity, discovery, and community without making prolonged, compulsive engagement their defining measure of success.
Conclusion
The debate about social media and attention should move beyond the question of whether individuals are using their phones too much. That question is real, but it is incomplete.
The deeper issue is institutional: who designs the environment, what they are rewarded for, what they know about its effects, and what obligations they have when risks emerge. The evidence does not justify simplistic claims that every digital interaction is harmful or that every mental-health outcome has one cause. It does justify closer scrutiny of systems designed to capture attention and monetise it at scale.[S1] [S6]
Practical safeguards begin with a change in responsibility. Users deserve tools that support deliberate use. Researchers and regulators need meaningful access and oversight. Companies should be required to assess and mitigate foreseeable risks rather than treating engagement as an unquestionable good. And public policy must be strong enough to withstand the commercial pressure that arises whenever attention becomes a source of profit.[S6] [S7]
A healthier digital future will not be built by asking people to become infinitely disciplined. It will be built by making institutions accountable for the environments they create.