TikTok Withheld Safety Features for 10% of Users, Including Minors, in A/B Test – Senators Demand Answers
What Happened — TikTok deliberately disabled its “filter‑bubble prevention” safety mechanisms for an internal control group representing roughly 10 % of its user base, including children, to measure the impact on engagement. The experiment was uncovered after a Bloomberg report linked the test to the suicide of 16‑year‑old Chase Nasca, who had viewed thousands of harmful videos. U.S. senators have now asked TikTok to explain the practice and to release the full internal review.
Why It Matters for Compliance & Audit Readiness
- The scenario exemplifies a control‑gap that SOC 2‑compliant programs must identify, document, and continuously monitor (CC6.1 Security, CC6.2 Availability).
- Evidence of A/B‑testing governance, feature‑toggle logs, and risk assessments is essential audit evidence; without it, organizations cannot demonstrate due diligence.
- Verisq’s Control Mapping capability can automatically capture and correlate such policy changes with SOC 2 controls, providing a defensible audit trail.
Who Is Affected
- Social‑media platforms and any SaaS product that runs algorithmic experiments on user feeds.
- Companies that serve minors or handle user‑generated content.
Recommended Actions
- Map safety‑feature toggles to SOC 2 controls and establish continuous evidence collection for any experimental changes.
- Institute a formal A/B‑testing policy that requires risk review, documentation, and senior approval before disabling protective controls.
- Audit logs of feature enable/disable events and retain them for the audit period.
Technical Notes – The “attack vector” was an internal misconfiguration (intentional disabling) of TikTok’s content‑safety algorithm. No CVE or external exploit is involved; the risk stems from governance and policy failure. Source: The Record