Spain’s Charter of Digital Rights sits largely unknown by the businesses it is meant to guide, while Amazon quietly enrolls merchants in AI commerce experiments without their knowledge, and Meta’s CEO defends a platform accused of targeting vulnerable children. The gap between rights on paper and corporate practice has never been wider.

A founding principle of the digital age was that users consent to the terms governing how their data and digital presence are used. Yet as artificial intelligence blurs the line between browsing and buying, between scrolling and being sold, the mechanics of consent are quietly being rewritten: often by corporations, and often without the people affected having any meaningful say.
Three stories from early 2026 illuminate this problem from different angles: a Spanish digital rights charter that most of the businesses it was designed for have never heard of; an Amazon AI experiment that enrolled thousands of independent merchants as unwilling participants; and a landmark courtroom moment in which the CEO of Meta was forced, for the first time before a jury, to defend his company’s targeting of children and teenagers.
Spain’s Digital Rights Charter: A Pioneer Nobody Reads
In July 2021, the Spanish government published what it billed as a pioneering document: the Carta de Derechos Digitales (Charter of Digital Rights). Drawn up in collaboration with a wide committee of legal, technological and civil society experts, it was conceived as a comprehensive map of the rights citizens and businesses hold in the digital world, covering everything from data protection and algorithmic non-discrimination to the right to disconnect and protections against neurotechnology. Spain’s government promoted it as a model for Europe, a humanist framework for the digital transformation that was reshaping daily life.
Five years on, the charter’s reach inside the Spanish economy is startlingly thin. According to figures presented at a February 2026 event organised by DigitalES, Spain’s main technology employers’ association, only one in three Spanish companies is even aware that the charter exists. Among the workforce, the figure drops to 24% — fewer than one in four workers has heard of a document that is supposed to protect their rights in the digital workplace.
Miguel Sánchez Galindo, Director General of DigitalES, described the charter as a “pioneering” milestone that “builds the foundation of rights protection on the internet” and preserves continuity between the analogue and the digital worlds. Experts at the event argued that the charter does not inhibit innovation — quite the opposite, suggesting it could enhance the competitiveness of companies that adopt its principles. Yet awareness campaigns, university partnerships and the creation of a dedicated Digital Rights Observatory are all still required to close a gap that, four and a half years after publication, remains enormous.
The paradox is instructive. Rights that are not known cannot be exercised. A charter that businesses do not know about cannot shape business conduct. At a moment when artificial intelligence is rapidly automating decisions that affect workers, consumers and merchants, the Spanish experience suggests that publishing rights frameworks, however carefully crafted, is only the beginning of a much harder political and cultural task, which is prompting people to actually exercise these rights.
Amazon’s ‘Buy for Me’: The Opt-Out That Nobody Asked to Opt Into
In February 2025, Amazon quietly launched two linked features in its shopping app. The first, “Shop Direct”, allowed users to browse products from brands’ own websites directly within Amazon. The second, “Buy for Me”, went considerably further: an AI agent that would complete a purchase on the shopper’s behalf, navigating to the retailer’s website, filling in checkout forms, and processing payment using the customer’s encrypted Amazon account details — all without the customer ever leaving the Amazon app. Sounds cool, until you dive into behind the curtains details of this tech wonder.
Amazon framed the tools as a convenience for shoppers, enabling them to find any product they wanted, including items unavailable in Amazon’s own catalogue. What the company did not do was contact the thousands of independent retailers whose product data it was scraping in order to make those listings possible.
The backlash came in January 2026, when Angie Chua, CEO of Bobo Design Studio, a stationery and journaling accessories brand that sells through Shopify and a physical store in California, began receiving orders through Amazon that she had never solicited. She had made a deliberate business decision not to sell on Amazon. Yet there her products were, listed in Amazon’s app, and an AI agent was completing purchases, acting, legally speaking, as a customer on her website without her consent.
“We were forced to be dropshippers on a platform that we have made a conscious decision not to be part of,” Chua told CNBC. When she posted about the experience on Instagram, the video accumulated over 500,000 views. More than 180 other businesses reached out to say the same had happened to them.
The scale of Amazon’s experiment was significant. From around 65,000 products at launch, the Buy for Me catalogue had grown to more than 500,000 items by November 2025, adding roughly 60,000 products per month. Some of those listings, according to merchant complaints, were inaccurate: featuring AI-generated images that did not match actual products, or offering items that had long since been discontinued. One company, Hitchcock Paper of Virginia, only discovered it was enrolled in the programme when it began receiving orders for a product it had never stocked.
For merchants who discovered they were participants, the remedy was to email a specific Amazon address and wait for their products to be removed. The burden, in other words, fell on the unwilling participant to exit, not on Amazon to obtain permission before enrolling. The model is opt-out by default — a structure that raises serious questions about commercial consent, data ownership, and the relationship between platform power and merchant autonomy.
The irony was not lost on observers. In November 2025, just months after launching Buy for Me, Amazon sent a cease-and-desist letter to Perplexity AI, accusing the startup’s Comet agentic browser of scraping Amazon’s own website without permission — the very practice Amazon was simultaneously applying to thousands of independent retailers. Amazon later sued Perplexity, alleging computer fraud. Perplexity called the action a “bullying” tactic. Amazon has said it does not collect commissions on Buy for Me transactions, and that businesses can opt out at any time. The company describes the feature as an experiment currently in testing.
But the episode illustrates a broader dynamic in the emerging world of agentic AI commerce: platforms with the scale to impose terms will do so, while smaller businesses either adapt or are simply absorbed. Consent becomes a technicality.
Zuckerberg in the Dock: What Did Meta Know About Its Young Users?
On 18 February 2026, Mark Zuckerberg entered a Los Angeles courtroom to testify before a jury for the first time. The occasion was a landmark trial brought by a young woman identified as “Kaley” (now 20 years old), who alleges that Instagram and Google’s YouTube were deliberately engineered to be addictive, and that she was hooked from the age of six. Features including infinite scroll, auto-play, and beauty filters amounting to what the lawsuit calls a “digital casino” are said to have driven her into addiction, worsening body dysmorphia, depression, and suicidal thoughts.
The case is the first of more than 1,500 similar lawsuits nationwide to reach a jury. A verdict against the companies could reshape how technology platforms are held liable for the products they design, not just the content hosted on them, but the design choices themselves: the mechanics that keep users scrolling, the algorithms that surface content calibrated for maximum emotional engagement.
Zuckerberg spent more than five hours on the stand. The questioning, led by plaintiff’s attorney Mark Lanier, pressed repeatedly on what Meta knew about the harm its platforms caused to young users, and whether it acted on that knowledge or suppressed it. Internal documents put before the jury were revealing. A 2018 Instagram presentation included the line: “If we want to win big with teens, we must bring them in as tweens.” A 2022 document listed incremental goals for time spent on the app — from 40 minutes per day in 2023 toward 46 minutes in subsequent years. Zuckerberg argued these were milestones, not objectives.
The jury also heard that Meta’s own experts, when consulted on the impact of appearance-enhancing beauty filters, concluded they contributed to body-image problems among young girls. Zuckerberg chose not to remove the filters. Asked about that decision in court, he said removing them would have been “paternalistic.” An internal email from a Meta employee, herself the mother of two teenage daughters, warned that the pressure on teenage girls was intense and that keeping the filters was “not the right call.”
Lanier confronted Zuckerberg with a 2015 internal figure estimating that more than 4 million children under the age of 13 — the platform’s own minimum age, were using Instagram in the United States. Zuckerberg acknowledged those children existed but argued that age verification is better handled by Apple and Google, which control the app stores through which Instagram is downloaded. “You expect a 9-year-old to read all of the fine print?” a lawyer for the plaintiff asked. Instagram did not require users to provide a birthdate until late 2019.
During Zuckerberg’s 2024 congressional testimony, he had turned to face the audience and apologised to families who said their children had been harmed or had died because of social media — a moment parents in the courtroom gallery recalled with a mix of recognition and frustration. “I don’t have any satisfaction,” said Tammy Rodriguez, whose 11-year-old daughter Selena died by suicide in 2021 after what the family attributed to Instagram and Snapchat addiction. Rodriguez had attended both hearings. “I feel just like I did when I left that day, but we’re here and we’re in a courtroom, so that’s a big thing.”
Meta has denied the core allegations. The company’s lawyers argued in opening statements that Kaley faced significant challenges prior to any social media use, and that Instagram was a coping mechanism rather than a cause of her difficulties. Zuckerberg himself insisted he is “focused on building a community that is sustainable” and that products which make users feel bad will eventually lose those users. TikTok and Snapchat settled before the trial began.
The case, and the thousands of similar lawsuits behind it, represent a test of whether product design choices can constitute harm and whether the business model that links children’s attention to advertising revenue can be made legally accountable.
While the lawsuit over social media effect on teenagers is still not over, it is reported Meta is planning to quietly introduce yet another feature infringing on citizens privacy and rights: facial recognition in Meta smart glasses products that could identify people seen through the glasses and provide info through AI. The potential functionality causes tricky questions like where would the tech giants actually get this data that appear on display and whether it would get proper consent of the people who would be deanonymized by its AI tools. Those questions remain without any legitimate answers so far.
A Common Thread: The Architecture of Non-Consent
These three episodes are distinct in geography, industry and legal context. But they share an underlying logic. In each case, a powerful digital actor has operated on the assumption that the absence of explicit refusal constitutes sufficient permission. Amazon did not ask merchants whether they wished to participate in Buy for Me; it enrolled them and provided a mechanism to exit. Meta did not disclose to its youngest users or even to their parents the extent to which its algorithms were calibrated to maximise their time on the platform. Spain’s digital rights charter, for all its careful construction, was never matched by an investment in making those rights legible to the people they were meant to protect.
The emerging vocabulary of digital rights — transparency, consent, the right to disconnect, algorithmic accountability, describes a world of fair dealing between technology platforms and the individuals who use or are affected by them. The gap between that vocabulary and current practice is not simply a regulatory failure. It reflects an asymmetry of information, power and incentive that runs deep through the economics of the digital economy.
Closing that gap will require more than charters and courtroom testimony. It will require default settings that protect rather than expose, consent models that are opt-in rather than opt-out, and an honest reckoning with the fact that for many of the largest technology companies, the extraction of attention and data is not a side effect of their products but the product and value itself. In this battle for customer focus, our digital and human rights shall remain protected not only on paper but in real settings.


