In the space of a few days the European Commission has shown the two faces of Digital Services Act enforcement. On 20 July 2026 it fined AliExpress €550 million for failing to diligently assess and mitigate the risks of illegal, unsafe or counterfeit products spreading through its e-commerce platform. Five days earlier it had accepted the action plan by which X undertakes to remedy the breaches established in December 2025. Two opposite outcomes, a fine and an accepted plan, that converge on the same point: the decision does not close the matter, it obliges the platform to put things right under supervision.
The largest fine so far, and how it was built
By amount, the measure against AliExpress is the highest pecuniary penalty adopted so far under the regulation. The Commission finds that the platform failed to diligently assess the risk of illegal, unsafe or counterfeit products spreading through its services, and it does so on three precise grounds. AliExpress did not properly evaluate whether it had enough staff to review potentially illegal products, overestimating the effectiveness of its detection and removal system and disregarding the disproportion between the number of human moderators and their workload. It inadequately assessed how its recommender and advertising systems amplify the circulation of those products: testing by the Commission’s services showed that many illegal items were recommended or advertised to consumers before they were effectively removed. And it relied on a single quantitative indicator that did not properly measure the phenomenon.
The amount reflects the nature and gravity of the infringements, the number of Union users affected and the duration, which ran at least until June 2025, when the Commission issued its preliminary findings. Among the mitigating circumstances weighs the very novelty of the regulation.
Why the fine does not close the case
The decision is a non-compliance decision, and from here the regulation sets a path in motion. AliExpress has until 20 October 2026 to submit an action plan remedying the breach of its obligations to assess and mitigate systemic risks. The European Board for Digital Services has one month from receipt of the plan to issue its opinion; the Commission then has a further month to adopt its final decision and set a reasonable period for implementation. If the platform fails to comply, it faces periodic penalty payments. The fine, then, sets a price for the past, but the real obligation looks to the future: to build, and to evidence, the risk-assessment processes that are currently missing.
It is worth recalling that the proceedings against AliExpress were opened on 14 March 2024 and that, on 18 June 2025, the Commission had already accepted and made binding a set of commitments offered by the platform for most of the concerns. The fine therefore bites on the residual and most serious part: diligence in assessing and mitigating risk.
The other face: X’s plan accepted but not endorsed
On the other side, the Commission has accepted X’s action plan on transparency obligations and researchers’ access to data, following the December 2025 decision that established the breach and the related fine. X undertakes to improve its advertising repository with more effective search features and faster response times, to publish more information about advertisements and to enable access through an API. It also promises eligible researchers effective access to public data, speeding up the screening of applications, making it free of charge and amending its terms so as no longer to prohibit, on a contractual basis, the scraping of public data.
The sensitive point lies elsewhere. The European Board for Digital Services, once consulted, issued its opinion on 15 June and considered the measures only partially adequate, deeming the audit measures, and consequently the whole plan, insufficient. The Commission accepted the plan nonetheless, but clarified several points that X must observe in implementation. The platform has six months to apply the measures and must then have the results certified by an independent external audit to be submitted to the Commission; should the audit make recommendations, X must implement them in full. The corrective route, too, therefore ends not with a clean bill of health but with supervised and verified implementation.
An architecture that looks like supervision
Placed side by side, the two cases describe an enforcement that resembles continuous supervision more than one-off punishment. AliExpress and X are both very large online platforms (VLOPs) designated under the regulation, which is why the Commission acts directly. The path is the same: proceedings, commitments or a fine, an action plan, an opinion of the Board, supervised implementation, penalties for non-compliance. The document that matters is not the fine but the plan and its audit.
A problem this blog has met before returns here. The case against AliExpress turns on the inability to measure risk with adequate indicators, and X’s plan stumbles precisely on its audit measures: in both, the difficulty is not asserting that one has acted, but proving it with verifiable metrics, the same knot we saw when cyber accountability reached the board before the standards to prove it had been written. The logic of systemic risk, after all, is the same one that governs platform design and default settings, as with the obligations protecting minors. And enforcement rests on an architecture of cooperation, between the European Board for Digital Services and the national Digital Services Coordinators, that closely echoes the EDPB’s call to make regulators talk to one another.
For those working in compliance, the message of the two decisions is consistent. A financial penalty, even when it reaches €550 million, does not extinguish the obligation: it opens a phase in which the platform must submit a plan, put it before the Board, have it audited and implement it within a deadline, on pain of further penalties. The Digital Services Act is not enforced through isolated fines, but as supervision that demands documented and measurable processes. The burden remains on platforms to build them before the scrutiny, not after; and it remains with the Commission, together with the Board, to say when a plan is genuinely adequate.




