How platforms, states, and courts have governed social media bots, 2016–2026
An annotated bibliography of 111 legal, policy, and regulatory-studies papers on bot governance — bot typologies, platform bot policies, and the shift from voluntary codes to statutes like the DSA and NetzDG — drawn from the governance_review/ systematic search (SCOPUS-substitute + Semantic Scholar + citation chaining, 2016–2026).
621 unique candidates after dedup·111 passed keyword screening·90 confirmed on-topic on manual review
Search & screening funnel
Two SCOPUS-substitute boolean queries (run against Semantic Scholar), four native phrase searches, and forward/backward citation chaining from three seed papers (Bodó 2022; Gorwa, The platform governance triangle). Full methodology, raw query logs, and PDFs are in the governance_review methodology.
621unique candidates, all sources
−510pre-2016 / off-topic by keyword
111passed keyword screen
90confirmed on-topic (this review)
The keyword screen behind the 111 was deliberately permissive (see methodology), so a second manual pass was run for this page: 21 of the 111 are false positives — things like veterinary antibiotic rules or rideshare economics that matched on stray terms ("bot", "regulat*", "platform") without being about social media bot governance. They stay in the browse table below, marked excluded, for audit purposes; the charts and narrative below use only the 90 on-topic papers.
Types of bots the governance literature actually argues about
The legal/policy literature doesn't use one bot taxonomy — it argues about bots in terms of the harm channel regulators are trying to close. Harmonizing the 90 papers' own vocabulary into seven recurring types:
Political / propaganda bots
Automated accounts amplifying political hashtags, candidates, or narratives — the original "computational propaganda" object of Howard & Kollanyi's Brexit study and most election-law scholarship since.
Coordinated inauthentic behavior (CIB) networks
Clusters of bot/sockpuppet/troll-farm accounts acting in concert (synchronized posting, shared URLs) — the unit Meta and academic detection papers now use instead of "bot," since coordination, not automation alone, is what platforms police.
Engagement-for-hire bots
Bots sold as a service to inflate likes/followers/views ("engagement as a service") — a commercial market that authenticity-governance research treats as a distinct enforcement target from political bots.
Platform / community-management bots
Bots platforms and volunteer moderators deploy — Reddit AutoModerator-style tools, third-party Discord bots — i.e., bots as a governance instrument, not just a governance target.
Conversational & companion AI
Chatbots and AI companions (Weibo's "Robot," character-based companion apps) that raise consent, intimacy, and youth-safety questions distinct from disinformation bots — the fastest-growing category in 2025–2026.
LLM-generated / generative-AI bots
Post-2023 bots whose text/persona is produced by a generative model rather than templated scripts — BotSim-style malicious botnets, and the "cyborg propaganda" hybrid of a verified human plus algorithmic amplification.
Fake / fraudulent accounts
Sock puppets, cyborg accounts, and compromised accounts framed as a security/fraud problem (return fraud, review manipulation) rather than a speech problem — governed through detection engineering more than law.
Reading the 90 papers in publication order surfaces four rough eras. Years overlap heavily — older models don't disappear, they get layered under new ones — but the center of gravity moves. Each era below expands into the actual papers and the actual platform/government primary sources (with links) that the claim rests on.
2016–2019 · Discovery & self-regulationBots are "discovered" as a policy problem (Brexit, 2016 US election). Response is almost entirely platform self-regulation and voluntary EU codes of conduct (hate-speech takedowns, terrorism-content removal) — states pressure platforms publicly but pass little hard law. Scholarship in this era is mostly typology-building and free-expression critique of privatized enforcement.Further details — papers & primary sources
EU Code of conduct on countering illegal hate speech online (European Commission, May 2016, with Facebook, Microsoft, Twitter, YouTube; later joined by Instagram, TikTok, LinkedIn, Twitch). Official Commission page. The archetype of this era: entirely voluntary, no statute behind it until it was folded into the DSA's Code of Conduct framework in 2025.
X/Twitter automation & platform-manipulation rules (help.x.com). X's automation development rules · Authenticity policy. The platform-side counterpart to Gorwa & Guilbeault's critique — the terms-of-service definition of "bot" regulators had to work around.
2020–2021 · Co-regulation experimentsGermany's NetzDG (2017, scholarship peaks ~2021) becomes the reference case for statutory intermediary-liability law. India's IT Rules, Australia's News Media Bargaining Code, and the EU's own Digital Services Package proposal all explicitly frame themselves as co-regulatory hybrids of statute plus platform self-policing, rather than pure command-and-control.Further details — papers & primary sources
Wilding, D. (2021). Regulating News and Disinformation on Digital Platforms. Journal of Telecommunications and the Digital Economy. Covers Australia's News Media Bargaining Code and Disinformation Code as the same era's co-regulatory instruments.
NetzDG (Gesetz zur Verbesserung der Rechtsdurchsetzung in sozialen Netzwerken, Germany, in force 1 Oct 2017). Official text, gesetze-im-internet.de. Requires platforms to remove "manifestly unlawful" content within 24 hours or face fines up to €50M — the model most later co-/hard-law proposals cite or react against.
IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (India, Ministry of Electronics & IT, notified 25 Feb 2021). Official MeitY page. Imposes trace-the-originator and grievance-officer duties on "significant social media intermediaries."
News Media and Digital Platforms Mandatory Bargaining Code (Australia, Treasury Laws Amendment Act 2021). Federal Register of Legislation · ACCC explainer. Statutory backstop designed to make voluntary commercial deals the default outcome — the co-regulatory logic in its purest form.
2022–2023 · Hard law arrivesThe EU's Digital Services Act is adopted (Nov 2022) and becomes the dominant object of study: transparency-reporting mandates, systemic-risk assessments, and the DSA Transparency Database turn "show your moderation decisions" from a self-regulatory nicety into a legal obligation. Criminal-liability framings (paid disinformation, bot farms) start appearing outside the EU too (UAE, Indonesia).Further details — papers & primary sources
Digital Services Act — Regulation (EU) 2022/2065, adopted 19 Oct 2022, in force 16 Nov 2022. Official text, EUR-Lex (CELEX 32022R2065). First EU-wide statutory (not co-regulatory) content-moderation, risk-assessment, and transparency regime for platforms.
DSA Transparency Database (European Commission, live since 25 Sept 2023). transparency.dsa.ec.europa.eu. Publicly queryable database of every "statement of reasons" platforms file for a content-moderation decision — the empirical object Kaushal et al. (above) analyze.
2022 Strengthened Code of Practice on Disinformation (European Commission, June 2022; 34 signatories). Official signatories page. Still self-regulatory in form when adopted; the Commission formally folded it into the DSA as a Code of Conduct in Feb 2025 — the co-regulation-to-hard-law splice Galantino's paper (above) anticipates.
2024–2026 · Generative AI forces a rewriteVolume roughly triples (14 → 34 → 14 papers/yr, 2026 partial). Two new fronts open: companion-chatbot regulation (Australia, California, New York move fast after high-profile harms) and cross-platform CIB detection for election integrity (2024 U.S. election, multilingual coordination). Several papers explicitly argue social-media governance's mistakes (reactive, fragmented, self-regulation-first) are being repeated for generative AI rather than learned from.Further details — papers & primary sources
Cited in the literature
Qiao, B., Li, K., Zhou, W. et al. (2024). BotSim: LLM-Powered Malicious Social Botnet Simulation. AAAI. Shows LLM-driven bots can now simulate realistic personas/conversations at a fidelity that breaks prior detection assumptions.
Fraser, H., Szczuka, J.M., Ciriello, R. (2026). Regulating Artificial Intimacy: From Locks and Blocks to Relational Accountability. ACM FAccT. Direct legal-textual analysis of the California/New York/Australia companion-chatbot laws (below), arguing "locks and blocks" (age gates, content filters) under-regulate relational harm.
California SB 243 (companion-chatbot safety law, signed 13 Oct 2025, effective 1 Jan 2026). Official bill text, California Legislative Information. First U.S. state law mandating self-harm-detection protocols and periodic "you are talking to AI" disclosures for companion chatbots.
New York AI Companion Models law (enacted as part of the FY2026 budget, in effect 5 Nov 2025; General Business Law §1700). Bill page, NY State Senate. Requires session-interruption notices every 3 hours and a mandatory self-harm/crisis-referral protocol; enforced by the state Attorney General.
Meta Transparency Center — Inauthentic Behavior policy (current). transparency.meta.com. Meta's post-2023 policy language explicitly separates "coordinated inauthentic behavior" from individual fake accounts — the actor-level distinction Cinus et al. (above) build their cross-platform detection on.
TikTok Community Guidelines — Integrity and Authenticity (current). tiktok.com/safety. Explicitly bans "using bots or scripts...to increase likes or shares" — the platform-policy side of the engagement-for-hire bot type.
Reading note — the four-era grouping is a first-pass synthesis from title/abstract-level classification of the 90 papers, not a coded/validated content analysis. The expandable citations above are real and directly checkable (click through); treat the era labels themselves as a scaffold for browsing, not a settled finding.
Charts: bot type, governance model, and actor, by year
Counts are the 90 on-topic papers only. A paper can be tagged with more than one bot type / governance category / actor, so bars sum to more than 90 per year. Click a bar segment or legend entry to filter the browse table below.
Bot types discussed, by year
Governance model invoked, by year
Governance actor addressed, by year
Browse the annotated bibliography
All 111 papers that passed the keyword screen. The 21 marked excluded are keyword false positives kept for audit (hover title for reason); the rest are the 90 used in the charts and narrative above. Click a row to expand its full tagging. Full text, where retrieved, is in governance_review/pdfs/; see the full annotated bibliography for citation-count context on the source review.