Open Letter on UVA's Use of X for Emergency Alerts

2026-08-30 → 2026-09-11

Update: UVA’s response#

The office explained that it also shares emergency communications, including Safety Advisories and UVA Alerts, on Instagram and Facebook. Its use of X is tied to RAVE, the platform it uses to send alerts by text and email. RAVE automatically posts alerts to @UVASafety and @UVAPolice on X, and the office values the immediacy of this integration. My understanding that X was its only social-media alert channel was therefore incorrect. The office said Instagram and Facebook attract more student and community engagement, and that they often coordinate with other UVA accounts to broaden their reach.

They also acknowledged that omitting Instagram and Facebook links from the “Take 3 For Safety” email was an oversight and said they would include them going forward. The respondent was unfamiliar with Mastodon and had not considered Bluesky for official emergency communications, but was open to considering it as part of their communications strategy.


Letter#

Dear Office of Emergency Management,

I noticed that UVA lists @UVASafety and @UVAPolice on X as its only social-media channel for emergency notifications. I understand that social media is only one part of UVA’s multi-layered, redundant system, but I would like to ask why that layer is exclusive to X.

Access#

My first concern is access. Without an X account, a visitor to @UVASafety’s account page can see only a short list of about five recent posts. Visitors must log in to open an individual post, view its replies, or see more recent posts. By contrast, most other social platforms provide public web access; see Meta, Bluesky, and Mastodon, for instance. Why does UVA use such a closed platform as its only social-media option?

Reach#

Maybe the office’s rationale for choosing X is reach. However, X is no longer dominant: Meta reported 500 million monthly users for Threads in June 2026, while Similarweb estimated 141.5 million daily mobile users for Threads and 125 million for X that January.

X is also not clearly dominant in academic community, which is especially relevant to UVA. Despite Bluesky’s much smaller overall user base, Altmetric found that it hosted more original posts linked to new research than X on most days in March 2025, suggesting that headline user counts understate Bluesky’s reach within academic communities. A large-scale study of more than 2.6 million Bluesky posts later found substantially higher interaction than previously reported for X, while Techdirt reported that Bluesky sent it far more referral traffic than X in 2025.

Neither global user counts nor these narrower comparisons establish local usage and reach. However, visible engagement with UVA’s emergency-alert posts on X appears limited. For instance, three @UVASafety updates posted later during UVA’s August 14 tornado warning (5:52 p.m., 6:02 p.m., and 6:37 p.m.) received little engagement (3–10 likes, 0–1 replies, and 1–2 reposts), comparable to or lower than that of two Bluesky posts about the same storm by local meteorologist Travis Koshko (6:36 p.m. and 7:37 p.m.). Four recent @UVAPolice emergency-alert posts—the July 31 all-clear and the August 7 initial alert, gas-leak update, and all-clear—showed similarly little visible engagement: 0–1 likes, no replies, and 0–3 reposts. Of course, this is not a rigorous comparison, but these examples suggest that the official accounts’ reach and visible engagement on X is quite limited and not substantially greater than engagement with similar posts on much smaller platforms.

Another access concern is that X has a documented history of reducing exposure to outbound links, as well as selectively delaying access to links from rival platforms and news organizations. An alert on X that links to further instructions or news articles may therefore receive less visibility and fail to reach some users. This suppression of external links is not universal: for instance, Bluesky says external links are not penalized.

Misleading identity signals#

There is also an information-integrity and trust problem. On X, a blue check means that an account has an active Premium subscription or is affiliated with a paying organization; it does not mean that the account’s identity has been verified. In 2025, the European Commission found the design deceptive because X did not meaningfully verify who controlled an account, making it difficult to judge the authenticity of accounts and content. The risk is not hypothetical: paid blue-check accounts have impersonated Eli Lilly, LeBron James and Nintendo, and customer-service agents in refund scams. An emergency-alert account requires strong, immediate trust in the sender’s identity, making X’s ambiguous blue check particularly ill-suited to the task.

By contrast, Meta Verified requires a government-issued ID for Instagram creators, and Threads carries over Instagram verification. Bluesky and Mastodon offer identity signals tied to trusted organizations or control of a website.

Grok and information integrity#

X’s deep integration of Grok into the platform raises several concerns. First, in 2025, xAI acknowledged that an “unauthorized modification” caused Grok to inject a specific political response into unrelated public conversations. Second, X has placed a Grok button directly on posts and made @grok available in public replies as an instant fact-checker, inviting users to treat it as a source of “facts.” During the 2025 Los Angeles protests, Grok misidentified real photographs as recycled from Afghanistan, driving hours of debate before the bot corrected itself.

These incidents were not isolated. In February 2025, xAI acknowledged a hidden instruction telling Grok to ignore sources that criticize certain people. In July 2025, xAI removed a public system instruction telling Grok not to shy away from “politically incorrect” claims after it posted antisemitic tropes and praised Hitler. Together, these incidents show that hidden system instructions have altered Grok’s public answers. An AI system so deeply integrated into X may itself spread misinformation, making the platform a problematic choice for emergency alerts.

X’s CSAM and safety problems#

In 2026, Canada’s Privacy Commissioner reported that Grok had been used to create abusive imagery, including child sexual abuse material (CSAM) and non-consensual intimate imagery. X had removed 126 reported posts, but the Commissioner found that X and xAI had not demonstrated safeguards. More recently, xAI has been accused of training Grok on CSAM.

X’s safety problems extend beyond Grok. The company reduced its safety-engineering staff by 80% after the acquisition. Harassment is not unique to X, but it remains widespread there. In a 2024 Pew survey, 73% of U.S. X users said harassment was a problem on the platform, including 32% who called it a major problem. In a Nature survey, 65% of the 201 researchers who used Twitter to discuss COVID-19 said that they had experienced trolling or personal attacks there at least sometimes.

The consequences can extend beyond the platform. George Washington University researcher Rebekah Tromble received death and rape threats after participating in research on Twitter discourse; she moved her office and had police patrols outside her home. In 2024, Australia’s eSafety Commissioner Julie Inman Grant said that Musk’s attacks on X resulted in death threats against her and doxxing of her family. In a 2026 first-person account, Eugene Vinitsky described receiving antisemitic slurs and death threats that referenced his workplace after his posts went viral on X. These cases show how harassment on X can follow researchers and public officials into their workplaces and homes.

Although this may not be unique to X, it is generally understood that other platforms enforce safety more rigorously and the problem is most severe on X.

Cost#

UVA’s use of X also raises a separate question about cost. X says a blue check can come from Premium or Premium+, whose published U.S. web prices are $8 and $40 per month, respectively. Its separate Premium Organizations plan costs $1,000 per month plus $50 per affiliated account. X also charges for API access under pay-per-use pricing. By contrast, Bluesky’s AT Protocol and Mastodon’s ActivityPub protocol are open protocols that third parties can implement without paying a platform-level API fee. Their authenticated APIs let authorized applications publish Bluesky posts and publish Mastodon statuses.

Question for UVA#

Given these concerns, why does UVA single out X as its only social-media alert channel rather than other free, more accessible, and safer platforms that may offer comparable or greater reach?

Sincerely,
YY Ahn
School of Data Science, University of Virginia

Receive my updates

YY's Random Walks — Science, academia, and occasional rabbit holes.

YY's Bike Shed — Sustainable mobility, urbanism, and the details that matter.

×