A bevy of states are racing to mandate “digital selection” in social media. The brand new payments promise straightforward knowledge portability and compelled interoperability amongst platforms—letting customers carry their accounts, contacts, and content material throughout companies by open protocols. Utah enacted the first such legislation in 2025, and legislatures in Virginia, South Dakota, New York, California, and New Hampshire are actually contemplating related measures of their 2026 periods.
The pitch sounds easy: give customers management over their data. A better look tells a unique story. The payments by no means determine a transparent market failure. Their interoperability mandates expose nonconsenting customers to vital privateness dangers. Their artificial-intelligence (AI) provisions don’t cohere right into a workable regulatory scheme. And lawmakers are shifting forward regardless of little proof that customers really need social-media interoperability.
Copy-Paste Federalism
As famous above, Utah set the template. Gov. Spencer Cox signed H.B. 418 in March 2025, with an efficient date of July 1, 2026. The statute requires full social-media interoperability: customers should have the ability to obtain and switch their content material and interactions, and platforms should keep “clear, third-party-accessible… interfaces utilizing open protocols.”
Lawmakers virtually instantly found the issues. Utah is already advancing a follow-up measure, H.B. 408, to patch apparent gaps, together with including consent protections for customers whose knowledge can be pulled into one other person’s switch. The necessity to amend the legislation inside a 12 months of enactment ought to itself increase alarms.
Different states have, nonetheless, shortly adopted into the breach. Virginia’s SB 85 handed the Senate 40-0 earlier this month and is now shifting by the Home. It goes past Utah by making use of interoperability mandates to AI “mannequin operators,” requiring portability of “contextual knowledge,” together with prompts, chat histories, uploaded recordsdata, and model-generated inferences.
South Dakota’s SB 111 cleared each chambers, passing the Senate 34-0 and the Home of Representatives 62-3. New York has companion payments—A8963 within the Meeting and S7476 within the Senate—pending in committee. California Assemblymember Josh Lowenthal plans AB 2169, which might amend the California Client Privateness Act to mandate portability of social-graph and AI contextual knowledge. New Hampshire’s HB 1589 stands because the lone rejection, dying in committee on a 16-0 vote recommending towards passage.
The pace is notable. The similarity is extra so. Throughout states, the payments use practically an identical language, construction, and underlying idea.
Portability With out Goal
The brink query these payments by no means reply is easy: what shopper hurt are they fixing?
Lawmakers assume platform ecosystems are a barrier to welfare. Customers deal with them as a profit. Folks preserve separate identities throughout companies as a result of the companies do various things. A pseudonymous dialogue on Reddit serves a unique goal than skilled networking on LinkedIn or sharing selfies on Instagram. These are usually not interchangeable experiences trapped behind technical boundaries; they’re differentiated merchandise customers deliberately select. Compelled real-time interoperability would collapse distinctions customers actively keep.
Supporters invoke competitors coverage and “walled gardens,” typically analogizing to telephone-number portability. The comparability fails. Phone numbers are standardized identifiers inside a regulated utility community. Social-media platforms are heterogeneous merchandise constructed round distinct norms and interactions. The declare {that a} person’s knowledge ought to transfer seamlessly from Reddit to X (previously Twitter) to Instagram to LinkedIn assumes a useful equivalence that doesn’t exist. A Reddit remark thread organized round pseudonymous, upvote-driven dialogue doesn’t resemble an Instagram story or a LinkedIn endorsement. As Gus Hurwitz has noticed, the analogy breaks down as a result of social-media content material and interactions lack any comparable standardization course of.
Implementation makes the issue clearer. What would it not imply for a Reddit publish—embedded in a topic-based, pseudonymous group—to look in an Instagram feed optimized for visible engagement or a LinkedIn timeline curated for skilled signaling? The content material would lose the context that provides it that means. Interoperability assumes user-generated content material has worth unbiased of the platform during which it arose. In social media, that assumption is normally incorrect.
Neither is there robust proof of shopper demand. Customers have already got choices. Current privateness regimes, together with the European Union’s Common Knowledge Safety Regulation (GDPR) and the California Client Privateness Act, enable knowledge downloads. Customers routinely keep accounts throughout a number of companies. Multi-homing is the norm, which undermines claims that community results meaningfully lock customers in. The actual constraint is just not the shortcoming to export knowledge; it’s that the information has little worth outdoors the setting that produced it. A follower record from one platform not often interprets into engagement on one other.
The financial literature is, at greatest, ambivalent. Analysis on China’s necessary interoperability regime discovered it supplied “very restricted comfort to shoppers” and “hardly facilitat[ed] entry of small operators,” as an alternative benefiting different massive platforms looking for growth. Geoffrey Manne and Sam Bowman likewise discover combined outcomes in the UK’s Open Banking initiative—the closest real-world analogue—enabling some fintech entry whereas creating hostile distributional results for privacy-conscious shoppers.
Your Privateness Is Not Yours Alone
The payments’ most critical flaw is third-party privateness—or, extra precisely, the shortage of it. Every proposal defines a person’s “social graph” broadly to incorporate connections, posts, feedback, reactions, shares, and related metadata. New York’s invoice is typical. It expressly covers “secondary customers’ responses to the coated person’s content material,” together with the metadata connected to these interactions.
The issue is structural. When Consumer A exports a social graph, the switch essentially consists of Consumer B’s knowledge—feedback, interactions, and relationship data—whether or not Consumer B consents or not. This isn’t hypothetical. Utah’s follow-up measure, H.B. 408, tacitly concedes the difficulty by attempting so as to add consent necessities. The repair doesn’t work. Requiring consent from each affected person would make interoperability virtually inconceivable, as a result of each social interplay entails a number of events.
The dangers multiply as soon as the information leaves the platform. Exterior a platform’s managed setting, the recipient is sure solely by its personal privateness coverage. Virginia’s SB 85 would open a considerable loophole, successfully changing private data into a conveyable useful resource indifferent from its authentic context. The recipients could also be flippantly regulated startups, international actors, or corporations with minimal privateness commitments. Broad interoperability interfaces additionally create enticing assault surfaces, whereas enforcement authorities can not realistically detect or cease misuse in actual time—particularly when the actors function outdoors the USA.
Moderation Meets the Open Gate
Mandated interoperability would additionally disrupt content material moderation. Platforms have spent billions constructing detection and removing techniques. The Congressional Analysis Service studies that Meta removes about 90% of violent or graphic content material routinely, whereas Reddit removes roughly 72% by automation. These instruments are platform-specific, educated on every service’s norms, indicators, and person conduct. Forcing content material to maneuver throughout platforms means forcing moderation techniques to function outdoors the environments they have been designed to control.
The “fediverse”—a community of federated social-media servers linked by the ActivityPub protocol—presents a preview. One examine discovered that its 18,000-plus independently operated servers create persistent moderation conflicts. When a person encounters dangerous content material originating on one other server, native moderators typically can not compel motion. Federated techniques make moderation tougher as a result of no single authority can implement guidelines throughout the community.
The implications are critical. A platform resembling Fb might be required to interoperate with companies that apply minimal moderation requirements, successfully bypassing safeguards its customers anticipate. The dangers are particularly acute for minors. Platforms that put money into age-based protections might be compelled to take care of open channels with companies that lack comparable protections altogether.
Port My Prompts, Break the Mannequin
Some proposals go additional. Virginia’s SB 85 and California’s proposed AB 2169 lengthen interoperability mandates to AI “mannequin operators.” They require portability of “contextual knowledge,” together with prompts, chat histories, uploaded recordsdata, preferences, metadata, and model-generated or inferred data. The provisions recommend little understanding of how AI techniques work.
No normal format exists for transferring a person’s full AI interplay historical past throughout fashions. The premise is confused. A dialog with a big language mannequin displays not simply the person’s inputs, however the mannequin’s coaching knowledge, fine-tuning, and structure. Transferring the transcript doesn’t reproduce the expertise; it produces knowledge indifferent from the system that generated it. Transferring a ChatGPT dialog to Claude or Gemini would depart the receiving mannequin with out the context essential to interpret model-specific outputs.
Close to-real-time interoperability would additionally create operational and safety dangers. It may expose proprietary mannequin traits, degrade efficiency, and battle with person expectations about how AI interactions are dealt with. Requiring disclosure of intermediate “reasoning” processes, for instance, would create a considerable vector for extracting proprietary data, much like latest incidents involving bot-based probing of AI techniques. These provisions learn much less like workable regulation and extra like aspirational language appended to a social-media invoice to seize the politics of AI governance.
A Resolution Nonetheless On the lookout for a Downside
The state “Digital Selection Act” motion reveals how enticing rhetoric can masks weak coverage. “Consumer empowerment” sounds compelling, however these payments by no means determine a concrete shopper hurt. As an alternative, they try to impose a single technical framework on heterogeneous merchandise that customers intentionally deal with as totally different companies. Social media is just not a standardized utility, and interoperability can not manufacture equivalence the place none exists.
The prices are clearer than the advantages. Exporting a “social graph” inevitably transfers details about nonconsenting customers. Open interfaces enlarge safety vulnerabilities and create enforcement gaps as soon as knowledge leaves a platform’s managed setting. Cross-platform knowledge flows would additionally disrupt content-moderation techniques that depend upon platform-specific norms and tooling, weakening safeguards that customers—together with minors—depend on. The AI provisions compound the issue by mandating portability of interplay knowledge that has that means solely inside the mannequin that generated it, whereas creating new dangers of proprietary data leakage.
Neither is there robust proof of shopper demand. Customers already multi-home, keep distinct on-line identities, and might obtain their knowledge underneath present privateness regimes. The central problem is just not technical lock-in; it’s that user-generated content material derives worth from context. Transferring it doesn’t recreate the expertise.
Earlier than adopting sweeping mandates, lawmakers ought to ask two questions: what market failure requires intervention, and can interoperability really clear up it? Up to now, the payments reply neither. They promise portability, however ship privateness dangers, moderation conflicts, and technical incoherence—whereas fixing no clearly recognized drawback.
