Moderation should work peer-to-peer. If somebody wants to post they have to first review posts which were flagged by users to violate the TOS. If sufficient users agree on the flag, the post is taken down.
This. You should read up about how recaptcha worked in the early days to do 'authority of the masses'. (I don't know any particular sources, maybe these methods are properly defined now in some framework.)