PAN Lab example
Meta's cross-check secondary review programme
Two lanes, one pool of reviewers
Most moderation systems fail by acting on something they should have left alone. This one fails by doing nothing yet. Modelled on the documented record of Meta's cross-check programme, as its own external review body described it in a policy advisory opinion published in December 2022. Start with the volume, because everything follows from it: the operator told that body it was making about a hundred million enforcement attempts on content every day, and the body did the arithmetic out loud — at 99 per cent accuracy, that is a million mistakes a day. Now add a tier. When the system identifies content as breaching a standard, an ordinary account's post is actioned. A listed account's post is not. It stays fully up while as many as five successive layers of humans reconsider it: at-scale identification, then the regional market team with the language and market knowledge, then the escalation team that may finally authorise enforcement, then an enhanced review with subject-matter experts plus policy, communications and legal, then a discretionary senior-leadership review. The process stops and the content stays up the moment any of them finds it non-violating. Everyone else's flagged content goes to an automated score, which either lets the original action stand or suspends it and puts the item in a second line. Here is the engineering fact the whole board is built on: those two lines draw on the SAME reviewers, and the guaranteed line is served first. So one capacity shortfall shows up twice, in opposite forms. On the listed lane it shows up as time. The operator's internal goal was 12 to 120 hours by severity; the measured mean to a final decision was more than five days, about twelve days for content posted from the United States, about seventeen for Afghanistan and Syria, and 222 days for the longest single item in the data it supplied. The operator's own position is that most views happen when content is fresh, so the injury here is not a wrong verdict. It is the interval before a right one, priced in views during the window that matters. On the general lane the same shortfall shows up as its mirror image: an item nobody reaches within two to four days times out, and the original action is applied with no human having looked. That lane overturns roughly 70 to 80 per cent of what reviewers do reach, which is why the review body concluded that when content times out there it is highly likely a significant number of false positives are being enforced. Protection for a few, paid for in mistaken removals for everyone else, with nothing on either side connecting the two. Then ask who is on the list. Inclusion criteria referenced advertising spend or revenue across the family of apps, and an assessment of how senior an executive an enforcement mistake would pull in — escalation at the highest levels of the company corresponding to an extremely high severity tag. At the time of the review a single employee could add an entity with no required review of that decision. Forty-two per cent of the content reviewed on the listed lane came from two countries that supply nine per cent of monthly active people. Alongside the tier sits a harder exemption the operator calls technical corrections: automatic bars, about a thousand applied a day, that block enforcement outright for a preselected entity-and-violation pair before eligibility is even checked. And the programme never measured its own premise. Its founding claim is that the exception path is more accurate than ordinary enforcement, and the review body recorded that the operator did not provide it with information showing that it tracks data about the accuracy of decisions made through the system. What the review moved and what it could not move is the sharpest thing in this record. It moved everything operational: the backlogs were cleared, resolution time fell 96 per cent for 90 per cent of jobs in the first half of 2023 against the second half of 2022, the bar list was cut by more than half, and list governance gained criteria, time-bound tags, multi-person approval and an internal audit where one employee had been able to act alone. It was refused on exactly five recommendations, and they are exactly the five that would have let anyone outside see who was protected or count what the delay cost: publicly marking the protected accounts, telling a reporting user that special procedures and longer timelines apply, an open criteria-based route into the programme, an explicit rules re-commitment at enrolment, and publishing the views accrued on content left up during enhanced review and later found violating. Before you pick a target level: this board cannot be won under Service and Safety Targets or All Governance Targets, and paying more does not shorten the line. Take every instrument the parties in this record could reach, set each one to full strength, and ignore the budget, at a total of fifty-six against the eight you are given. Two pathways are still open at the end. They are a list entry buying a place in the queue instead of an enforcement action, and a clock running out and applying the first action anyway. Those two are not a gap in this programme's governance. They are the programme itself: the tier, and the timeout that pays for it. One instrument outside this board would close them, an authorisation gate on automatic copying between systems. It is barred here because both pathways were authorised by design, and this record documents no ungoverned copying for such a gate to catch. That is a measurement of the deployment this network is drawn from, not a puzzle waiting to be cracked. Explore and Service Targets Only can be won, and cheaply: two instruments, costing five of your eight.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Tiered-exemption-class with one review pool serving two lanes network: 13 components and 25 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 1 assumed · 9 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
- baseline
D48-derived new org (Phase 6, content-moderation-editorial). REGISTER FIRST, because it governs every value here: this deployment is the catalogue's inverse moderation case. Every other moderation board in the atlas fails by acting on content it should have left alone. This one fails by routing some accounts' identified content OUT of enforcement into a queue known to be under-resourced, so the protection and the error land on different populations by construction. The harm modelled here is a LATENCY rather than a wrong verdict, and the two lanes drawing on one capacity pool under a strict priority rule is the mechanism that makes one shortfall show up twice.
- baseline
TOPOLOGY. Thirteen nodes, all documented, none decorative, drawn at the coarsest granularity at which every documented mechanism of this deployment stays distinguishable. TWO models because the record separates a channel that decides whether content breaches a standard from a channel that decides whether a human will look before the action lands, and folding them would hide the fact that this deployment's second model never judges content at all. THREE operator classes because the sources document three groups with different authority that act differently on the error: the review pool with the language and market knowledge, which may end a review but may not enforce; the escalation layer that may enforce and holds the allowances but works from notes and translations; and the function that maintains the lists and audits them from inside. The contracted at-scale reviewers who absorb the general lane's overflow sit inside the review pool: the record gives them less training and less tool access on the same queue by the same route, and the one thing it says about how they act on the error is that nobody compared their decisions with staff decisions, which is drawn as a comparison inside the pool at zero. THREE stores because a list that decides who is protected, a queue that accumulates the delay, and a hard bar list checked before eligibility are three separately documented objects with three separate governance histories, and a barred item never reaches the queue at all. ONE input source because the inclusion signals are a named, documented, commercially specific selection criterion rather than a modelling convenience. ONE enforcement system because the two lanes end in the same account-level consequences by different routes, and the difference between those routes is the comparison the operator is documented never having made. ONE reviewer, because there is exactly one external body in this record and drawing a second would assert an oversight channel the record says does not exist.
- baseline
THE TWO LANES ARE DRAWN AS WORKLISTS, and that choice is deliberate and bounded. The schema's worklist kind carries no flow of its own and never enters the dynamics; it names a queue that sits on a pathway. Thirty-eight orgs in the shipped catalogue carry exactly one. Two are drawn here because this deployment's structure IS the split: the guaranteed lane, promised a decision through as many as five successive layers and served first from the shared capacity pool, and the ranked lane, worked with whatever is left and governed by a two-to-four-day clock after which the original action is applied unreviewed. All the FLOW sits on the queue store the two lanes name; the lanes carry the names and the disciplines, which is what a mediator-only node is for. Neither lane is a separate store, and neither is asserted to hold anything the queue record does not.
- baseline
ABSENCES ARE DERIVED TOO, and four of them are load-bearing. There is NO external boundary and no egress pathway: nothing in this record documents content or entity data leaving the governed system, and the one disclosure question in the case runs the other way — the operator refused to hand its own list to its own reviewer. There is NO guardrail: no bounded automated screen over either channel's output is documented, and the human layers are drawn as the operator classes they are. There is NO retriever: nothing retrieves, and both channels read the stores directly. And there is NO pathway from any operator class back into either model: the PAN entry for this deployment carries no operator-into-model edge, and nothing in the record documents review outcomes retraining or re-weighting either channel. That last absence is a finding rather than a gap — a deployment whose reviewers overturn 70 to 80 per cent of what they see on one lane, with no documented channel by which that fact reaches the thing doing the identifying, is the shape the sources describe.
- baseline
WHERE THE LAB SHAPE DIVERGES FROM THE PAN SHAPE, and nothing is asserted here that the PAN file does not already record. Four divergences. First, PAN carries four operator classes and the Lab draws three of them plus one reviewer, so the external body is a reviewer here and an operator class there; its inbound reads and its two instruments are identical in both. Second, PAN folds the contracted at-scale reviewers into its frontline classes, and so does the Lab: they sit inside the review pool, and the one documented fact that singles them out, that their decisions were not compared for accuracy against staff decisions, is drawn as a comparison inside that pool. Third, PAN does not draw checks as pathways, so the five checks on this board are Lab-side: one is a PAN sideways pathway redrawn (the external body's channel into list governance, whose width still comes from PAN), and four are derived from the cited record and each drawn at zero on its own quoted absence. Fourth, PAN has no downstream consequence system, so the account-level penalty node and its three pathways are Lab-side, derived from the opinion's record of the escalation layer's discretion over account-level penalties and of the operator's statement that it had no statistically significant data distinguishing those penalties across the two populations. The Lab also draws fewer pathways than PAN: where PAN draws a second route for an influence the Lab already carries, such as an identification reaching the reviewers directly as well as through the routing cascade, or the list-governance function reading a list as well as writing it, the Lab draws the one route and states the other in that pathway's own description.
- baseline
BASELINES, and exactly how far the PAN org carries them. The PAN entry for this deployment holds twenty-eight edges. Sixteen of this network's twenty-five pathways have a one-to-one counterpart among them, and every one of those sixteen mirrors that edge's width on the single rung mapping stated in this network's derivation record, with no exceptions, including the one peer edge redrawn here as a check. The other twelve PAN edges are second routes of influences already drawn, and each one's documented content is carried in the description of the pathway it folds into. The remaining nine pathways are derived from the cited record directly and each says so on its own line. Three contrasts are load-bearing. The routing layer's write into the queue runs at the top rung while nothing in the record documents the queue's own depth as an input to the score — the layer that fills the line cannot see how long the line is. The external body's write into the queue runs at the middle rung while its write into the list runs at zero, and that pair is the whole governance finding: it moved everything operational and was refused everything visible. And the coupling from identification into routing runs at the top rung while the comparison running the other way runs at zero, which is the programme's founding claim drawn beside the measurement that would have tested it.
- baseline
DEMAND 3 / CAPACITY 1. Demand 3 on the operator's own disclosure to its reviewer: about 100 million enforcement attempts on content every day at the time of the briefings, from which the reviewer's own arithmetic is that 99 per cent accuracy would still leave a million mistakes a day; against that, roughly 0.01 per cent of content identified as needing enforcement reached reviewers empowered to apply context-specific policies and allowances. Capacity 1 because the counterfactual human floor at that volume is the lowest rung the scale admits, and because the record measures the shortfall rather than inferring it: a mean of more than five days to a final decision on the guaranteed lane against an internal goal of 12 to 120 hours, about twelve days for United States content, about seventeen for Afghanistan and Syria, 222 days for the longest observed item, and a two-to-four-day timeout on the general lane after which the original action is applied with nobody having looked. The 2023 remediation cleared the backlogs and cut resolution time by 96 per cent for 90 per cent of jobs; it is drawn on the pathways, and it does not move the counterfactual floor, because the floor is about what humans alone could do at this volume rather than about how well the queue is currently run.
- baseline
EVIDENCE STATUS, labelled where it is used, because this record mixes four registers and the honesty burden here is entirely about keeping them apart. OPERATOR DISCLOSURE, treated as established because the operator disclosed it to its reviewer and has not disputed the reviewer's account: the architecture and the five review layers; every latency figure; the two-to-four-day timeout; the overturn ranges; the 0.01 per cent routing fraction; the 42 per cent, 20 per cent and 9 per cent geography; roughly a thousand technical corrections a day with four active on 21 September 2022; the 35 per cent of programme content that could not be escalated; single-employee list additions; and the 58, 11 and 5 split of the reviewer's 74 questions. EXTERNAL REVIEWER CHARACTERISATION, always attributed because it is evaluative: that the programme appears more directly structured to satisfy business concerns, and that the operator's public statements that the same policies apply to all users are misleading. JOURNALISM, attributed and never carried as finding: the September 2021 reporting's exemption framing and the internal characterisation of the practice as not publicly defensible. PRELIMINARY REGULATORY REGISTER ONLY, and about channels adjacent to this programme rather than about it: the European Commission's October 2025 preliminary findings on notice-and-action mechanisms, dark patterns, appeal mechanisms and researcher data access, which expressly do not prejudge the outcome. No parameter on this diagram is scaled by a figure from the third or fourth register.
- baseline
TWO OVERTURN RATES THAT MUST NEVER TOUCH. This deployment's overturn figures — 30 to 90 per cent across periods on the listed lane, about 80 per cent and then about 70 per cent on the ranked lane — are the programme's OWN internal efficacy metric, computed on the content it routed. The shipped sibling board on the same operator carries an external body's overturn rate on the emblematic cases it selects, which is a different quantity on different content with a different denominator. They share a name and nothing else. Neither number appears on this board's pathways, and the sibling's appears nowhere in this bundle at all. What this board does carry is the reviewer's reading of the ranked-lane figure: because that lane overturns most of what it reviews, an item that times out unreviewed is highly likely to be a false positive being enforced.
- assumed
Served people are not in the dynamics, and on this board that boundary has an unusual shape worth stating plainly. The operator network here is the review capacity: the review pool of regional market teams and the contracted overflow capacity inside it, the escalation layer, the internal list-governance function and the external body. The listed entities are beneficiaries and are not operators — they are not even told they are enrolled. Ordinary users are the population the error lands on, as posters subject to unreviewed default enforcement and as reporters given no notice that a different clock applies. People harmed by content left up during the wait are outside the network entirely. None of them is modelled, no outcome for any of them is computed from anything drawn here, and the geographic allocation figure and the routing fraction are recorded external observations from the reviewer's published opinion rather than quantities this network derives. The named individuals in the record's most vivid example stay on the case-file and audit side and appear in no game content; the person harmed in that example appears nowhere at all.
What this example does not show
- LITIGATION AND REGULATORY POSTURE, verbatim from the evidence dossier and load-bearing. Live and renamed, with a partly implemented and partly declined remediation record. Implemented and externally confirmed: the ERSR/SSR backlog was cleared and time-to-decision fell sharply (Board, Oct 2023); the technical-corrections allowlist was cut by more than half; list governance gained criteria, tag expiry, multi-person approval and internal audit; cross-check kept expanding toward all users through GSR and, from 2025, Dynamic Multi-Review. Declined outright: publicly marking protected accounts (rec 12), telling reporting users that special procedures apply (rec 13), an open application route into the program (rec 5), an explicit re-commitment on enrollment (rec 6), and publishing the metric that would quantify the program's own harm - views accrued on content left up during enhanced review and later found violating (rec 29). Still outstanding as of 2026-08-28: the cross-check-specific annual transparency report Meta committed to under rec 30 has not been located as published; Meta's cross-check tracker was last updated Oct 3, 2024; the H2 2025 bi-annual Board report contains no cross-check reporting. No litigation. Regulatory exposure is DSA-shaped and adjacent rather than cross-check-specific.
- The external body in this record is not a court and not a regulator. It is a quasi-judicial body the operator established and funds through an irrevocable trust: independent-adjacent, with binding force on the individual cases it takes and none at all on its policy recommendations, and with no audit power, no subpoena power and no way to compel anything. Its December 2022 policy advisory opinion is an external-oversight finding, and this scenario describes it as one. No court and no regulator anywhere has adjudicated this programme.
- The October 2025 European Commission findings are PRELIMINARY, expressly do not prejudge the outcome, and are NOT about this programme. They concern whether the operator's platforms provide a user-friendly notice-and-action mechanism for illegal content, whether they use dark patterns in it, whether their appeal mechanisms let users supply explanations or supporting evidence, and researcher data access, with exposure up to 6 per cent of worldwide annual turnover if confirmed. The honest framing, and the only one this scenario uses, is a structural adjacency rather than a legal one: the reporting channel and the appeal channel the Commission is examining are the same two channels the review body found this tier quietly bypasses. Nothing on this diagram is derived from those findings.
- TWO OVERTURN RATES SHARE A NAME AND NOTHING ELSE. This deployment's figures — 30 to 90 per cent across periods on the listed lane, about 80 per cent then about 70 per cent on the ranked lane — are the programme's own internal efficacy metric, computed on the content it routed. The shipped sibling board on the same operator carries an external body's overturn rate on the emblematic cases it selects: different content, different denominator, different question. Neither figure appears on this board's pathways and the sibling's appears nowhere in this bundle. Conflating them would misstate both.
- THE COUNT DISCREPANCY IS STATED, NOT RESOLVED. The review body's opinion and its annex enumerate 32 recommendations, and the operator's own tracker page also enumerates 32; the operator's Q1 2023 quarterly update says it 'responded publicly to all 33 of the board's cross-check recommendations, committing to implementing 82% either in part or in full'. This scenario uses 32 as the body's count and quotes the operator's 33 and 82 per cent as the operator's own framing. Aggregate implementation tallies for this opinion are unstable across renderings of the operator's tracker and across press summaries, so no aggregate is asserted here — only the per-recommendation statuses that reproduced consistently and are corroborated by a downloaded primary document: no further action on recommendations 5, 6, 12, 13 and 29; implementing in part on 30; implementing fully on 32.
- CURRENCY LIMITS, stated as an absence found by search rather than as abandonment. The operator's cross-check recommendation tracker was last updated 3 October 2024; its half-yearly report on the review body, published 19 March 2026 and covering 326 recommendations responded to as of 31 December 2025, contains no cross-check material; and no annual report on the programme's functionality and impact was located as published as of 28 August 2026. The honest statement is that no such report was located, not that the operator never published one and not that it abandoned the commitment.
- THE PROGRAMME WAS RENAMED AND EXTENDED, and this scenario dates rather than freezes it. The entity-list pathway was renamed from Early Response Secondary Review to Secondary Sensitive Entity Review effective 25 April 2024, and in March 2025 the operator's teams sought the review body's input on expanding coverage to more users, with the result including further investment in a Dynamic Multi-Review system. Every mechanism figure on this board is from the period the December 2022 opinion covers, and the two later developments are carried as dates rather than as changes to any drawn value.
- Everything sourced to the operator's transparency centre or newsroom is operator self-report — including the backlog-cleared and 96-per-cent resolution-time claims in origin, though both were adopted and republished by the review body in its own transparency report, which is the citation this bundle uses for them. The clients of that distinction are the reader and the integrator: where a figure is the operator's own account of its own remediation, this board says so.
- The record's most vivid example of latency becoming exposure involves a named individual and, separately, a victim of non-consensual intimate imagery. Both stay on the case-file and audit side, both are handled at the level of what the operator itself confirmed to the review body — that the only consequence applied was content removal, where the ordinary penalty would have been account disabling — and the person harmed appears in no register at all. A views figure attached to that episode is journalism cited inside the opinion rather than an operator disclosure, and it is attributed that way wherever it appears.
- Served people are not modelled. Listed entities, ordinary posters, reporting users and the people harmed by content left up during the wait are all outside the operator network this board draws, and no outcome for any of them is computed from anything here. The geographic allocation figure (42 per cent of listed-lane content from two countries supplying 9 per cent of monthly active people) and the routing fraction (approximately 0.01 per cent) are recorded external observations from the review body's published opinion — they measure allocation, never error, and nothing on this diagram derives them.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
Meta's cross-check programme is an exemption tier bolted on top of at-scale content enforcement, and it inverts the usual order of moderation: for entities on Meta's lists, content its own systems identify as violating is NOT removed as it would be for an ordinary user, but is left fully accessible pending additional human review. Meta disclosed the surrounding scale to the Oversight Board directly — about 100 million enforcement attempts on content every day at the time of the Board's briefings, from which the Board's own arithmetic is that 99 per cent accuracy would still leave a million mistakes a day — and disclosed that approximately 0.01 per cent of all content identified as needing enforcement was escalated through cross-check to reviewers empowered to apply context-specific policies and allowances. The programme has two pathways. Early Response Secondary Review, the entity-list pathway, renamed Secondary Sensitive Entity Review effective 25 April 2024, commits a listed entity's content to human review through as many as five successive layers: initial automated or at-scale human identification; the Regional Market Team, whose staff and contractors have language and market knowledge; the Early Response Team, the first layer that may authorise enforcement and the holder of the escalation-only policies and the newsworthiness and spirit-of-policy allowances, which is not required to have language or regional expertise and works from Market Team notes and translations; an enhanced Early Response Team review with subject-matter experts plus Public Policy, Communications, and Legal; and a discretionary global senior-leadership review. The process stops and the content stays up if any reviewer finds it non-violating. General Secondary Review, built in 2021 and extended to content from all users in early 2022, is the content-ranked pathway: an automated ranker scores a flagged item on topic sensitivity, enforcement severity, false-positive probability, predicted reach, and entity sensitivity — topic sensitivity and entity sensitivity being the most heavily weighted — and either suspends enforcement and queues the item or lets the original action stand. The decisive engineering fact, which Meta disclosed, is that both pathways draw on the SAME Regional Market Team capacity, with the entity-list pathway guaranteed and served first, and the same teams also carry non-cross-check work.
empirical- Reference Oversight Board (2022, December 6). Policy advisory opinion on Meta's cross-check program (PAO-NR730OFI), full text with the annex of recommendations and measures of implementation https://www.oversightboard.com/wp-content/uploads/2026/03/512630074120983.pdf
- Reference Oversight Board (2022, December 6), Policy Advisory Opinion on Meta's cross-check program https://www.oversightboard.com/news/501654971916288-oversight-board-publishes-policy-advisory-opinion-on-meta-s-cross-check-program/
- Vendor Meta Platforms, Inc. Transparency Center. PAO on Meta's Cross-Check Policies (recommendation-by-recommendation response tracker; last updated 3 October 2024) https://transparency.meta.com/oversight/oversight-board-cases/pao-cross-check-policy/
- Vendor Meta Platforms, Inc. (2021, September). Requesting Oversight Board Guidance on Our Cross-Check System https://about.fb.com/news/2021/09/requesting-oversight-board-guidance-cross-check-system/
The harm this programme generates is a latency rather than a wrong verdict, and Meta disclosed the measurements. Its internal goal for Market Team cross-check review was 12 to 120 hours by severity. The actual mean time to a final Early Response Secondary Review decision was more than five days; approximately 12 days on average for content posted from the United States; about 17 days on average for Afghanistan and Syria; and the longest single piece of content in the queue in the data Meta supplied had sat 222 days. Meta's own stated position is that most views happen when content is fresh, so violating content on this pathway stays up through its peak-virality window. The general pathway carries the mirror image of the same shortfall. Content ranked high by the cross-check ranker has its enforcement suspended and enters a queue that Market Teams serve with residual capacity after the guaranteed pathway is satisfied; if reviewers do not reach it, it times out after two to four days and the original enforcement action is applied unreviewed. That pathway's overturn rate was about 80 per cent at the February 2022 briefings and about 70 per cent for March to May 2022, from which the Board concluded that when General Secondary Review content times out 'it is highly likely that Meta is enforcing a significant number of false positives'. Meta told the Board it 'never intended to operate with a consistent backlog' but that 'operational capacity constraints and increasing volumes have led to a backlog in Early Response Secondary Review'. Meta's own research identified the drivers of users seeing violating content as incorrect overturns and the delay of enforcement for non-overturns slowed by the secondary review process. These overturn figures are the programme's internal efficacy metric on the content it routed — a different quantity from the Oversight Board's overturn rate on the emblematic cases it selects, and the two are never combined.
empirical- Reference Oversight Board (2022, December 6). Policy advisory opinion on Meta's cross-check program (PAO-NR730OFI), full text with the annex of recommendations and measures of implementation https://www.oversightboard.com/wp-content/uploads/2026/03/512630074120983.pdf
- Reference Oversight Board (2022, December 6), Policy Advisory Opinion on Meta's cross-check program https://www.oversightboard.com/news/501654971916288-oversight-board-publishes-policy-advisory-opinion-on-meta-s-cross-check-program/
Entity selection was tied to the cost of a mistake to Meta rather than to the value of the speech, and the Oversight Board's opinion records the criteria. Entitlement 'is also determined by an assessment of the impact a potential enforcement mistake would have on the company in terms of the level of company leadership that would be involved in finding a solution', with 'escalation at the highest levels (CEO, COO)' corresponding to an 'extremely high severity' cross-check tag; inclusion criteria referenced advertising spend or revenue across the family of apps, enforcement history, and follower reach; and at the time of the opinion a single Meta employee could add an entity to a cross-check list with no required review of that decision. Listed entities carry tags in six categories — civic and government; significant world events; media organisations, businesses, communities and creators, including advertisers; historically over-enforced; legal and regulatory; and entities whose content is under review — which generally expire after a year, with civic-and-government tags carrying no default expiry. The people on the list are not told they are enrolled. Meta disclosed the resulting allocation: 42 per cent of content reviewed through the entity-list pathway originated from the United States or Canada and 20 per cent of listed entities corresponded to those two countries, against 9 per cent of Facebook monthly active people. Alongside cross-check sits a harder exemption Meta calls 'technical corrections': automatic bars that override almost all enforcement attempts for a preselected entity-and-violation pair, checked before cross-check eligibility is assessed. Meta applied about a thousand a day and stated four remained active as of 21 September 2022, primarily on spam or inauthentic behaviour and impersonation, and acknowledged that a past 'lack of governance over practices [...] inadvertently resulted in some entities not receiving many enforcement actions'. Public reporting had described the practice as allowlisting or whitelisting, and the Board agreed the label is apt. Separately, the Board found that a user reporting a listed entity's content is not told that special procedures and longer timelines apply, and Meta declined the recommendation that they be told.
empirical- Reference Oversight Board (2022, December 6). Policy advisory opinion on Meta's cross-check program (PAO-NR730OFI), full text with the annex of recommendations and measures of implementation https://www.oversightboard.com/wp-content/uploads/2026/03/512630074120983.pdf
- Vendor Meta Platforms, Inc. Transparency Center. PAO on Meta's Cross-Check Policies (recommendation-by-recommendation response tracker; last updated 3 October 2024) https://transparency.meta.com/oversight/oversight-board-cases/pao-cross-check-policy/
- Investigative Horwitz, J. (2021, September 13). Facebook Says Its Rules Apply to All. Company Documents Reveal a Secret Elite That's Exempt. The Wall Street Journal (publisher refuses automated fetch and is paywalled; carried only through the external reviewer's recounting in the December 2022 opinion) https://www.wsj.com/articles/facebook-files-xcheck-zuckerberg-elite-rules-11631541353
The Oversight Board is not a court and not a regulator. It is a quasi-judicial body Meta established and funds through an irrevocable trust: its decisions on the individual cases it takes bind, its policy recommendations do not, and it holds no audit power, no subpoena power, and no way to compel anything. It learned of cross-check only because it asked a question during the Trump case, which Meta had not disclosed in its referral; after The Wall Street Journal's September 2021 reporting the Board found that 'the team within Facebook tasked to provide information has not been fully forthcoming in its responses on cross-check', and Meta requested a policy advisory opinion days later. During the opinion Meta refused the Board's repeated requests for the entity list itself, citing user-privacy obligations, and almost five months later supplied only aggregate fields — entity type, self-selected country and language, a civic flag, and a partner flag — and for a quarter of the listed Instagram entities disclosed only that they existed. Meta answered 58 of the Board's 74 questions fully, 11 partially, and 5 not at all. The Board's opinion of 6 December 2022 found four shortcomings — unequal treatment of users, delayed removal of violating content, failure to track core metrics, and lack of transparency — and concluded that while Meta told the Board cross-check advances its human rights commitments, 'the program appears more directly structured to satisfy business concerns'. On unequal access to the rulebook it wrote that 'Meta has repeatedly told the Board and the public that the same set of policies apply to all users. Such statements and the public-facing content policies are misleading.' It issued 32 recommendations, the largest set it had issued at once. Two further findings define the governance shape. Meta 'did not provide the Board with information showing that it tracks data about the accuracy of decisions made through its cross-check system', and had no statistically significant data distinguishing account-level penalties applied to cross-checked versus non-cross-checked entities — so the programme's founding claim, that the exception path is more accurate than ordinary enforcement, was untested by its own operator. And the Board's own finding on the remedy it obtained is that internal auditing without external oversight falls short: there is no external audit of cross-check anywhere in the record. The Board's reach into the programme was itself tiered: for May and June 2022 an average 35 per cent of cross-check content could not be escalated to the Board at all, so the highest-reach accounts' content was systematically the least appealable to the external reviewer.
empirical- Reference Oversight Board (2022, December 6). Policy advisory opinion on Meta's cross-check program (PAO-NR730OFI), full text with the annex of recommendations and measures of implementation https://www.oversightboard.com/wp-content/uploads/2026/03/512630074120983.pdf
- Reference Oversight Board (2022, December 6), Policy Advisory Opinion on Meta's cross-check program https://www.oversightboard.com/news/501654971916288-oversight-board-publishes-policy-advisory-opinion-on-meta-s-cross-check-program/
- Investigative Horwitz, J. (2021, September 13). Facebook Says Its Rules Apply to All. Company Documents Reveal a Secret Elite That's Exempt. The Wall Street Journal (publisher refuses automated fetch and is paywalled; carried only through the external reviewer's recounting in the December 2022 opinion) https://www.wsj.com/articles/facebook-files-xcheck-zuckerberg-elite-rules-11631541353
Meta responded publicly to the opinion on 6 March 2023, stating in its Q1 2023 quarterly update that it had 'responded publicly to all 33 of the board's cross-check recommendations, committing to implementing 82% either in part or in full' — a count of 33 against the 32 the Board's opinion and annex enumerate and the 32 Meta's own tracker page enumerates. Both counts are stated here and neither is silently reconciled, and no aggregate implementation tally is asserted, because the tallies on Meta's tracker are unstable across renderings; only per-recommendation statuses that reproduced consistently and are corroborated by the downloaded quarterly-update PDF are used. What Meta implemented is recorded independently by the Board's own Q2 2023 transparency report of 26 October 2023: Meta 'has cleared all outstanding backlogs in its cross-check review queues dedicated to potentially violating content from entities on its lists', 'producing a 96% decrease in resolution time (time taken for review and any subsequent enforcement) for 90% of the jobs created in the first half of 2023, compared with the second half of 2022'; and the new technical-corrections approach 'led to an immediate decrease in the overall size of the technical corrections list by more than half (55%)'. Meta also established add-and-remove criteria, time-bound cross-check tags, multi-person approval, and internal audit over the lists, and committed to staffing cross-check decisions with reviewers who speak the language and have regional expertise. What Meta declined is equally specific: its own tracker records recommendations 5, 6, 12, 13, and 29 as 'No Further Action' — an open, criteria-based application route into the programme; an explicit rules re-commitment at enrolment; publicly marking the accounts of state actors, political candidates, business partners, media actors, and commercially included public figures; telling a user who reports such an account's content that special procedures and longer timelines apply; and publishing metrics quantifying the adverse effects of delayed enforcement, such as views accrued on content left up during enhanced review and later found violating. Meta cited targeting and gamification risk for the two marking-and-notice recommendations, and pointed to a promised cross-check-specific report under recommendation 30 in place of the harm metric. The Board's five-year retrospective of 4 December 2025 cites this work as a flagship impact, in a document that is the body assessing its own effect.
empirical- Reference Oversight Board (2023, October 26). Q2 2023 Transparency Report: Board's Recommendations Lead to Key Changes in Meta's Cross-Check Program https://www.oversightboard.com/news/228158946731169-q2-2023-transparency-report-board-s-recommendations-lead-to-key-changes-in-meta-s-cross-check-program/
- Vendor Meta Platforms, Inc. (2023, May). Q1 2023 Quarterly Update on the Oversight Board (the 60-day public response of 6 March 2023 and the quarterly record of recommendations marked no-further-action) https://about.fb.com/wp-content/uploads/2023/05/Meta-Q1-2023-Quarterly-Update-on-the-Oversight-Board.pdf
- Vendor Meta Platforms, Inc. Transparency Center. PAO on Meta's Cross-Check Policies (recommendation-by-recommendation response tracker; last updated 3 October 2024) https://transparency.meta.com/oversight/oversight-board-cases/pao-cross-check-policy/
- Reference Oversight Board (2025, December 4). From Bold Experiment to Essential Institution (the body's own five-year assessment of its impact, cited as such) https://www.oversightboard.com/news/from-bold-experiment-to-essential-institution/
The transparency the Board asked for has not arrived in the form it asked for, and the honest statement is an absence found by search rather than an abandonment. Under recommendation 30 Meta says it will produce 'an annual report containing metrics on the functionality and impact of cross-check' and describes this as a long-term effort; no such report was located as published as of 28 August 2026. Meta's cross-check recommendation tracker was last updated 3 October 2024. Its H2 2025 bi-annual report on the Oversight Board, published 19 March 2026 and covering 326 recommendations responded to as of 31 December 2025, contains no cross-check reporting. Meanwhile the programme continued and grew: the entity-list pathway was renamed Secondary Sensitive Entity Review effective 25 April 2024, and in March 2025 Meta's cross-check teams sought the Board's input on expanding coverage to more users, with the result including further investment in a Dynamic Multi-Review system intended to reduce over-enforcement at scale while keeping sensitive activism and journalism content with specialised reviewers. A population-level over-enforcement metric did arrive, but not the exemption-path one: Meta began publishing global enforcement precision in 2025, reporting around 91 per cent on Facebook and around 92 per cent on Instagram at the end of H1 2026, and reported roughly a 50 per cent reduction in United States enforcement mistakes between Q4 2024 and Q1 2025 following its 7 January 2025 policy overhaul, in which it said one to two of every ten December 2024 enforcement actions may have been mistakes, ended third-party fact-checking in the United States, and narrowed automated enforcement to illegal and high-severity violations while requiring user reports for less severe ones. None of those figures is disaggregated for the cross-check pathway the Board asked about.
empirical- Vendor Meta Platforms, Inc. Transparency Center. PAO on Meta's Cross-Check Policies (recommendation-by-recommendation response tracker; last updated 3 October 2024) https://transparency.meta.com/oversight/oversight-board-cases/pao-cross-check-policy/
- Vendor Meta Platforms, Inc. Transparency Center (2026, March 19). H2 2025 Report on the Oversight Board (carried for a verified absence: no cross-check reporting appears in it) https://transparency.meta.com/oversight/meta-H2-2025-bi-annual/
- Vendor Meta Platforms, Inc. Transparency Center (2025). H1 2025 Report on the Oversight Board (the March 2025 request for input on expanding coverage and the successor multi-review system) https://transparency.meta.com/oversight/meta-H1-2025-bi-annual-report/
- Vendor Meta Platforms (quarterly). Community Standards Enforcement Report. Meta Transparency Center. https://transparency.meta.com/reports/community-standards-enforcement/
- Vendor Meta Platforms (2025, May 29). Integrity Reports, First Quarter 2025. Meta Transparency Center. https://transparency.meta.com/reports/integrity-reports-q1-2025/
- Vendor Kaplan, J. (2025, January 7). More Speech and Fewer Mistakes. Meta Newsroom. https://about.fb.com/news/2025/01/meta-more-speech-fewer-mistakes/
No court and no regulator has adjudicated cross-check. The nearest regulatory pressure is Digital Services Act-shaped and adjacent rather than about the programme: on 24 October 2025 the European Commission issued PRELIMINARY findings that Facebook and Instagram appear not to provide a user-friendly, easily accessible notice-and-action mechanism for illegal content and appear to use dark patterns in it; that their appeal mechanisms appear not to allow users to provide explanations or supporting evidence; and that Meta and TikTok both breached researcher data-access obligations. The investigation was conducted with Coimisiun na Mean, the Irish Digital Services Coordinator. Preliminary findings expressly do not prejudge the outcome; if confirmed, exposure runs to fines of up to 6 per cent of total worldwide annual turnover. The reason this belongs beside cross-check is a structural adjacency rather than a legal one, and it is stated as such: the reporting channel and the appeal channel the Commission is examining are the same two channels the Oversight Board found cross-check quietly bypasses, since a user reporting a listed entity's content is not told that special procedures and longer timelines apply, and an average 35 per cent of cross-check content could not be escalated to the Board at all in May and June 2022. No DSA systemic-risk finding, proceeding, or risk-assessment document naming cross-check was located.
empirical- Government European Commission (2025-2026). Preliminary findings on TikTok's ad repository (IP/25/1223, 15 May 2025), on researcher data access (IP/25/2503, 24 October 2025), on addictive design (6 February 2026) and on minors' account settings (IP/26/1679, 24 July 2026); with the advertising-transparency commitments decision of 5 December 2025 and the TikTok Lite Rewards closure of 5 August 2024 (IP/24/4161). PRELIMINARY FINDINGS ARE NOT FINDINGS OF BREACH https://ec.europa.eu/commission/presscorner/api/files/document/print/en/ip_25_2503/IP_25_2503_EN.pdf
- Reference Oversight Board (2022, December 6). Policy advisory opinion on Meta's cross-check program (PAO-NR730OFI), full text with the annex of recommendations and measures of implementation https://www.oversightboard.com/wp-content/uploads/2026/03/512630074120983.pdf
Where this connects
Institutional pressures in this domain
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
- Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
All of them in context on the Content moderation & editorial AI domain page.
Levers available here and the patterns behind them
- Review the riskiest first — Risk-tiered oversight
- Understand the system — Understand the system
- Mark AI-written records — Provenance labeling
- Check with a second model — Cross-model verification
- Gate record entries — Human-in-the-loop write gating
- Store less data — Data minimization
- Review on schedule — Oversight cadence & retrospectives
- Pause AI on alarms — Deployment circuit-breaker
- Escalate checks — State-feedback vigilance
- Check copied records — Reconcile copied records
- Upgrade model — Improve the model
- Peer sharing rules — Peer-edge governance
Documented case histories
- Meta cross-check: the enforcement-exemption tier
- The errors that became visible when the reviewers went home
- The most built-out correction structure and the reach it doesn't have
- The byline nobody was behind
- A staff byline the AI wrote and the review it implied
- StopNCII & Take It Down
- X Multilingual Hate-Speech Enforcement
- X Community Notes (crowd annotation)
- GIFCT hash-sharing database
- Google CSAM detection and total account closure
- The CyberTipline: triage under a rule against looking
- Sama Nairobi: the review workforce as the governed subsystem
- TikTok EU and UK trust-and-safety staffing substitution
- The score is published and the service cannot act on it
- YouTube Content ID