Data And Regulation
Global Digital Policies Accelerate the Reshaping of the Digital Economy Landscape: Analysis of Policy Developments in January 2025
Based on Digital Policy Alert data, analyze the new trends in global digital policy in January 2025 in the fields of content moderation, AI regulation, competition policy, and data governance, and explore their profound impact on the platform economy, AI commercialization, and cross-border data flows.
Introduction
In January 2025, global digital policy entered a period of intensive adjustment. From the European Commission's expanded investigations into social media platforms to South Korea's official signing of the AI Basic Act; from the Italian Data Protection Authority's halt on DeepSeek's processing of personal data to China's drafting of an AI safety standard system—these seemingly fragmented regulatory actions are in fact jointly shaping the underlying rules of the future digital economy. For multinational tech companies, investors, and policymakers, understanding how these policies affect business models and market structures is no longer a topic exclusive to compliance departments, but a core variable that determines strategic positioning. Based on Digital Policy Alert's monthly monitoring, this article reviews key changes in four major global policy areas in January 2025 and analyzes their deeper implications from a digital economy perspective.
Content Moderation Tightens: Rising Compliance Costs for Platforms, Passive Adjustments to Business Models
In January, content moderation policies were tightened simultaneously across multiple jurisdictions. The European Commission, in cooperation with Germany's digital services coordination body, assessed large platforms' risk mitigation measures ahead of the German federal election, incorporated the code of conduct on hate speech into the Digital Services Act (DSA) framework, and expanded its investigation into X's recommendation system. France's Digital Space Security Act officially took effect, requiring platforms to remove illegal content such as child pornography and terrorism within 24 hours, and granting ARCOM the authority to block non-compliant websites. The UK's Ofcom, pursuant to the Online Safety Act, issued an age assurance code of practice, requiring adult content platforms to implement age verification immediately and imposing fines on violators.
The direct impact of these policies on the digital economy is a sharp rise in compliance costs. Platforms must invest more resources in content moderation technologies (such as AI detection tools) and human review teams, which to some extent compresses profit margins. The deeper impact is that content moderation standards are shifting from "ex-post removal" to "ex-ante prevention," forcing platforms to redesign recommendation algorithms and user interaction mechanisms. For example, the EU's investigation into X's recommendation system may force the platform to disclose its algorithmic logic, which would weaken the traffic distribution advantage based on black-box algorithms, thereby altering the content ecosystem and advertising revenue models.
In Asia, China's Cyberspace Administration launched a consultation on a draft regulation for Multi-Channel Network (MCN) institutions, prohibiting data fabrication and the spread of false information, and carried out special campaigns to combat extreme speech and vulgar content online. This shows that content moderation targets not only global platforms but also the local content industry chain. As important nodes in the content ecosystem, MCN institutions will need stricter compliance operations in the future, which may increase content production costs but also create competitive advantages for professional institutions with strong compliance capabilities.
AI Regulation Enters Deep Water: From Risk Prohibition to Industry Guidance, Compliance Becomes a Prerequisite for InnovationIn January, AI regulation showed a dual-track trend of "risk prevention and control" and "industry promotion." The provisions of the EU AI Act banning high-risk AI systems officially took effect, explicitly prohibiting the use of manipulative and deceptive technologies, setting the highest standard for global AI governance. At the same time, the EU released a "Competitiveness Compass," proposing a strategy to build an AI continent, planning to establish AI superfactories and promote the EU Cloud and AI Development Act, seeking a balance between strict regulation and industrial competitiveness.
In East Asia, South Korea signed the AI Basic Act, which will take effect one year later. The act establishes a user rights protection framework and an AI governance system, and requires AI systems to meet design standards. China, meanwhile, further improved its AI standardization system: the National Cybersecurity Standardization Technical Committee (TC260) opened consultation on the draft AI security standards and the coding rules for AI-generated content, while implementing transparency requirements for algorithm recommendation. The UK released the AI Cybersecurity Code of Practice and the AI Opportunities Action Plan, focusing on the security of AI systems and the implementation of innovation.
For the AI economy, regulatory divergence is shaping different commercialization paths. With the "risk level" at its core, the EU means that companies developing high-risk AI applications (such as medical diagnosis and recruitment tools) will face strict compliance audits, raising market entry barriers but also potentially giving rise to new business forms such as "compliance as a service." The approaches of China and South Korea place more emphasis on the integration of AI governance and industrial promotion, guiding corporate innovation through standard setting and official recognition. For example, China requires that AI-generated content be embedded with traceable coding, which directly affects the operating model of AI content creation platforms, but also creates new business opportunities for technology suppliers.
It is worth noting that in January, the Italian Data Protection Authority (Garante) ordered DeepSeek to stop processing personal data of Italian users. This event is symbolic: data collection during the training and inference of AI models is becoming a focus of attention for regulators in various countries. Cross-border AI companies handling personal data must reassess the legality of their data sources and processing, which poses a direct challenge to AI business models that rely on large-scale data training.
Competition Policy Focuses on Digital Markets: Platform Dominance Faces Systemic Challenges
Competition policy in January sent a clear signal: global regulators are no longer satisfied with fines, but are directly targeting structural barriers in digital markets. Indonesia fined Google (specific amount undisclosed), continuing Southeast Asian countries' tough stance toward big tech companies. An Indian court issued a ruling in the Meta case; although the outcome was not made public, it shows that the judicial system is becoming involved in platform disputes. The UK's Competition and Markets Authority (CMA) continued to investigate Google and Apple's mobile ecosystems, and accepted Google's commitments regarding fake reviews, requiring it to rectify.The core economic logic behind these actions is that platforms maintain high profit margins through default settings, app store commissions, and ecosystem lock-in. Regulatory intervention aims to lower market entry barriers and create space for smaller competitors. For example, the UK’s investigation into mobile ecosystems could force Google and Android to adjust their pre-installation agreements with phone manufacturers, which would disrupt the dominance of default search and app stores and reshape traffic distribution. For small and medium-sized enterprises that depend on platforms, this may mean a fairer competitive environment, but it could also weaken platforms’ willingness to invest and affect the quality of ecosystem services.
The Korea Communications Commission’s penalties against gaming companies and Kakao show that competition regulation is extending from traditional tech giants to emerging digital services. Kakao operates a super-app-like ecosystem in South Korea, and regulatory action may force it to open up its ecosystem, thereby affecting its business model. This trend is expected to accelerate in 2025, and full enforcement of the EU Digital Markets Act (DMA) will further rewrite the operating rules for global tech giants.
Data Governance and Cross-Border Flows: The Deepening Contradiction Between National Sovereignty and Data-Economy Efficiency
In January, multiple key actions emerged in the field of data governance, focusing on three dimensions: data security, AI training data, and biometric data. China issued data security measures and facial recognition payment guidelines, clarifying the boundaries for handling sensitive data. Italy’s ban on DeepSeek reflected Europe’s strict stance on AI models’ use of personal data. South Korea fined tech companies for unauthorized cross-border data transfers, strengthening the regulatory framework for data exports. Brazil restricted Worldcoin’s collection of biometric data to protect citizens’ data rights.
These policies have far-reaching implications for the data economy. Data has been elevated to the level of national sovereignty, and multinational companies face increasingly stringent data localization requirements. For AI companies, training data must come from diverse and legitimate sources; if regulators in major markets no longer allow cross-border data flows, the cost and difficulty of model training will surge. For example, China’s facial recognition payment guidelines require localization of data storage and analysis, which could affect global payment giants’ business layout in China while also providing local companies with room to grow behind policy barriers.
Another economic effect of data governance is the emergence of a new compliance industry. Demand for data protection officers, privacy impact assessments, and cross-border data transfer compliance consulting is growing rapidly. Over the past decade, the data economy relied on “free flow” to create value; in the next decade, business models must be rebuilt around “controlled flow.” Companies are no longer simply pursuing data scale but are placing greater emphasis on data governance capabilities, which has become a new core competitive advantage.
Global Digital Policy Convergence and Divergence: Enterprises Need to Build Adaptive StrategiesLooking at global policy developments in January 2025, a notable feature is the "coexistence of convergence and divergence." Convergence is reflected in the fact that most economies have strengthened regulation of platform responsibility, AI risks, and data sovereignty, as if competing for the "rule-making power" in digital economy governance. Divergence, on the other hand, is reflected in specific paths: the EU tends toward strong regulation supported by industrial stimulus; the UK and US place more emphasis on balancing innovation and security; China promotes autonomous AI standards under the premise of security; while countries such as South Korea attempt to attract AI investment through legislation.
The impact of this complex landscape on the digital economy is not linear. On the one hand, rising compliance costs will squeeze the profit margins of small and medium-sized enterprises, potentially accelerating industry consolidation; on the other hand, clear policy expectations also reduce legal uncertainty, which benefits long-term investment. For multinational enterprises, it is necessary to abandon a "one-size-fits-all" globally consistent strategy, and instead implement "flexible compliance" across different jurisdictions, while actively participating in policy feedback to influence regulatory details.
Use note · digitalecononews
digitalecononews frames this note through Digital Markets / AI Economy / Platforms & Apps (Source URLs should be opened before the summary is reused). Digital Markets / AI Economy / Platforms & Apps explains the local editorial angle; dates, names and status changes still need checking.