The Justice Department officially unbanned TikTok use by the government last month, opening the door to federal agency access to the application after a U.S.-based group of companies took over American operations.
Almost immediately, the decision unleashed federal agencies and officials upon the vertical-scrolling platform, including the Department of Homeland Security, FBI, Department of Health and Human Services, and NASA. The posts, so far, are classic fare for the Trump administration, ranging from highlight reels featuring agency leaders to content that appears to have been created with AI.
The Department of Transportation made its inaugural post on the app with an AI-generated-looking video of its logo in the 21st Century Fox intro. HHS Secretary Robert F. Kennedy Jr., who already had a separate personal account, has begun posting again under a new government official handle. And the Department of Housing and Urban Development marked its first upload with a seemingly AI-generated video of administration officials facing off against fraudsters via a Madden-style football video game.
But beyond setting administration messaging to popular audio or the latest trend, several researchers and former federal IT experts told FedScoop there are a lot of security considerations for agencies and workers in using the app, with some concluding that the decision is an unnecessary gamble.
Agencies choosing to allow workers to use TikTok will also have to ensure the application is effectively managed and adheres to records-keeping requirements. And workers themselves must weigh whether the data-collection risks are worth what they might get out of scrolling on their lunch break, the sources said.
“What I see with this calculus is very little benefit for very high risk,” said Calli Schroeder, a senior counsel at the Electronic Privacy Information Center, a nonprofit privacy research organization. “This exponentially increases security risk on all of these devices where TikTok will be downloaded, and it’s for what benefit?”
No longer illegal
The slip opinion from the Department of Justice Office of Legal Counsel allowing TikTok comes roughly six months after an Oracle-led group took control of the app’s U.S. operations. That agreement was aimed at quelling years of cross-party concerns over the app’s connection to China.
Specifically, the DOJ opinion found that the new TikTok U.S. Data Security Joint Venture does not fall within the scope of a governmentwide ban on the app established under the 2022 No TikTok on Government Devices Act. While that law prohibited versions developed or provided by Beijing-based owner ByteDance, the U.S. app is operated independently of the Chinese company and owned by a majority of American investors, the DOJ said.
ByteDance is still part of that new group but owns a nearly 20% stake of the U.S. joint venture. But what the July opinion doesn’t do is compel agencies to allow the app. In fact, the opinion makes clear that it’s not a mandate to permit employee use of the app and that agencies may decide to “ban the down of TikTok to government devices for workforce management reasons, such as promoting employee productivity.”
“Our opinion should not be understood to call those administrative decisions into question,” the opinion concludes.
That leaves the decision on government use entirely with individual agency heads. Already, agencies are coming to different conclusions about how they’re choosing to treat the app internally.
Permission to prohibition
In response to FedScoop inquiries to the civilian Chief Financial Officers Act agencies — a sample of roughly two dozen departments and agencies that encompasses a large portion of executive branch functions — a handful of spokespeople disclosed policies ranging from permissive to outright bans.
The Office of Personnel Management was the most permissive. An OPM spokeswoman told FedScoop the agency allows “limited personal use of social media on government devices where the use is minimal, does not interfere with official business, and complies with security, privacy, ethics, and records requirements.”
Now that the prohibition is lifted, TikTok gets the same treatment as other social media sites like X and LinkedIn, she said in the emailed statement.
NASA and the Environmental Protection Agency allow the app on a more case-by-case basis. Specifically, a NASA spokesperson said the agency’s “presence on TikTok is accessible by a few employees who are using the platform in alignment with federal guidance.” NASA also directed FedScoop to its publicly accessible policy for government-furnished equipment.
The Nuclear Regulatory Commission, meanwhile, prohibits use of TikTok. In an emailed statement, a spokesperson said the prohibition is “part of the agency’s broader cybersecurity efforts” and said the agency’s evaluation of social media platforms for potential use focuses on security, privacy and operational risk.
Beyond those four agencies, policies are unclear.
The Small Business Administration did not address FedScoop’s questions about how many employees were allowed to use the application, instead providing a statement through a spokesperson touting the agency’s use.
“As millions of small business owners use TikTok to grow and scale their operations, the SBA leverages the platform to deliver timely, relevant resources directly to them — ensuring America’s entrepreneurs have the tools they need to compete and succeed,” an agency spokesperson said.
The Department of Justice provided a general statement on the slip opinion and HUD directed FedScoop to the opinion and President Donald Trump’s executive order on TikTok, but neither addressed its own policies. The remaining 15 CFO Act agencies either did not respond, didn’t provide a comment, or declined to comment.
When asked whether it planned to send additional guidance to agencies on the decision, the White House asked FedScoop to share more detail about its reporting but did not respond to a request for clarification.
The opinion, however, did reference previous White House communications to agencies regarding TikTok.
According to the opinion, the DOJ advised the executive branch in March that the U.S. version of TikTok wouldn’t violate the law after reviewing a letter from the venture’s general counsel. The DOJ also said it understood that the White House had since instructed executive branch agencies that they could download the app onto official devices.
In a memo dated Monday, the Office of Management and Budget officially rescinded previous guidance prohibiting the app.
Records retention, visibility
Individual agency policies are ultimately a decision likely informed by a host of agency leaders and have traditionally varied by agency, former government IT officials told FedScoop.
Jonathan Alboum, former chief information officer of the Department of Agriculture, said that the decisionmaking process might involve the CIO, who would consult from a cybersecurity and implementation perspective, as well as general counsel and policy officials.
But the first thought Alboum said he would have as a federal IT leader is not whether the decision was good or bad, but rather, how to implement the policy in a way that allows the agency to quickly make adjustments as needed. For example, that policy might touch the mobile device management system, endpoint security, and network and access controls, in addition to underlying technologies that support those capabilities.
“Without policy orchestration, without a sort of ‘platform thinking’ that allows you to do something once and have that decision effectuated in subordinate systems, you end up relying on emails and spreadsheets and other things to track compliance and to track execution and actions,” said Alboum, who is currently chief technology officer and principal digital strategist at ServiceNow, a company that sells cloud-based products.
Outside of just TikTok, Alboum said there’s a broader question about agency visibility and readiness to make adjustments to what may operate on their networks, including AI models, at the speed of decisionmaking.
“Maybe TikTok is allowed now. Maybe in the future it won’t be, and you have to reverse that decision,” Alboum said. “So, you know, could you do that quickly?”
A second former cabinet-level IT leader, who was granted anonymity to share more detail about their former agency, said that while it depends on the CIO, leaders have leaned more toward allowing users to have social media on their devices in recent years. The challenge, the source said, is records retention.
The source said the CIO generally had to work with the privacy, transparency, and records team to determine what constitutes a record and how that information would be retained for Freedom of Information Act-related or records-management purposes.
That responsibility is sometimes passed on to the individual users granted access to the app, the source said, and can even include a waiver that employees are required to sign prior to installation that they would agree to retain those records.
It’s not clear exactly how that would apply to TikTok, but other policies in government cite the need to preserve messages and the National Archives and Records Administration views social media content as likely constituting a federal record.
The former official told FedScoop that if they were still in a federal IT role and it were up to them, they probably wouldn’t actively enable the app, citing a lack of underlying benefit for the workforce.
User data concerns
The decision has attracted a variety of critics who generally argue that allowance creates unnecessary risk — albeit for different reasons.
On one hand, some critics blasted the decision as risky because the version of TikTok in the U.S. still has ties to ByteDance, and it isn’t clear that the data being collected is not making its way back to China. Sen. Maria Cantwell, D-Wash., for example, pointed to those concerns in her assessment of the decision as “deeply concerning.”
“Federal phones contain sensitive government communications, contacts, and location data, making them attractive targets for foreign intelligence,” Cantwell, ranking member of the Senate Committee on Commerce, Science, and Transportation, said in an emailed statement. “Before clearing TikTok, Congress needs answers: Have operational ties between ByteDance and TikTok’s U.S. operations truly been severed? Who controls the algorithm? Can ByteDance access or update it?”
The Wall Street Journal editorial board — known for its right-of-center lean — raised similar questions, pointing to documents recently declassified by the White House that suggested China was continuing efforts to collect data on Americans. Federal workers have historically been a target of those efforts, including a 2015 breach that exposed government personnel data.
“Does President Trump consider the Chinese a security threat or not? It’s hard to tell from his contradictory actions,” the editorial board wrote.
Privacy experts, meanwhile, argued that purely creating a U.S. version of the app was never the solution to the issues posed by social media apps like TikTok that collect vast amounts of user data.
“The problem that privacy advocates have been saying this entire time remains, and that problem is TikTok still collects unbelievable amounts of very sensitive information on its users,” EPIC’s Schroeder said. “And so the only thing that’s shifted is now it’s a U.S. company collecting that information rather than a non-U.S. company.”
Schroeder said she understands that makes a difference for the DOJ from a security perspective, but it only matters as much as a U.S.-based company can be trusted with that information. “And we have seen a whole bunch of examples of U.S. companies misusing personal data,” she said.
Patrick Lin, deputy director of New York University’s Technology Law & Policy Clinic, similarly said he’s viewed the national security concerns over TikTok “as a bit of a ruse.” In his mind, the push to bring the app under U.S. operations was motivated by the ability to grant commercial and government entities in the U.S. easier access to the app’s data, as well as dulling the competitive edge of a non-U.S. tech company.
In fact, the American version of the app has new potential privacy exposures, Lin said. Shortly after the TikTok USDS was created, Lin noticed the app updated its privacy policy to reflect a change in its location collection practices.
An older version of the policy stated the app did not collect GPS data, but a new version said that if location services are enabled, it will collect “approximate or precise location information” from the device, he wrote in an article at the time. That new policy also stated that the app is collecting user data from interactions with the app’s AI tools, he said.
“We have to sort of assume that Oracle is going to be a responsible steward of this data,” Lin told FedScoop, dubiously. Lin’s article referred to Oracle’s control of the U.S. TikTok venture as an example of “surveillance capitalism” — akin to the work companies are doing to aid Immigration and Custom Enforcement’s aggressive actions targeting immigrant communities.
FedScoop reached out to the TikTok USDS for comment. A spokesperson directed FedScoop to its website for details on the organization but was not able to respond in full by publication.
One of many apps
But Lin called the unique treatment of TikTok “fascinating” considering many of the same privacy concerns can be applied to other social media, such as Snapchat, Facebook or Instagram. He said that government practices for social media would likely cover the app like any other.
Generally, government agencies tell employees not to post about sensitive topics, such as information related to investigations or non-public information about rulemaking, Lin said. “I think those same protocols apply here,” he said.
Ben Winters, who leads AI and privacy work for the Consumer Federation of America, noted that one of the risks from social media apps is the data they collect when they’re not being used. Apps cross-collect information from users’ browsers, when they click off the app, and through other sources, “so it just seems like a whole collection of needless risks,” he said.
Winters said he’d expect that in agency discussions about employee use, security officials would be among the loudest voices in the room, and that agencies would take tiered approaches to employee access, with restrictions for employees accessing more sensitive data on their devices.
He also said that agencies having a presence on the app isn’t, in itself, a bad thing.
If social media presence “enhances and improves access and knowledge about what the agencies are doing, I think that’s … generally a positive outcome,” Winters said. But he argued that’s generally not how the Trump administration has been handling social media. The Trump administration has come under fire time and time again for provocative posts that appear to be intended to rally the president’s base. That includes a picture Trump shared on his own social media app depicting him as a figure that looked like Jesus Christ, and on X, the White House shared an image of a woman being arrested by federal authorities that was doctored to make it look like she was crying.
Winters said people want government social media to inform them of things like when a rule change means they need to update their driver’s license or when there’s a tornado warning. “But right now, what the agencies are doing on social media is not particularly helpful for folks on average,” he said.