What the first half of 2026 tells us about DSA enforcement 

Posted on September 03, 2026 in Explainers, News.

In the first half of 2026, the European Commission opened new investigations, issued preliminary findings, imposed fines, designated new VLOPs and VLOSEs, and accepted compliance plans under the Digital Services Act.  

The substance of these actions shows where enforcement is heading. Regulators are putting platforms’ systemic risk assessments to the test, while children’s safety has become a clear priority. The Commission is also beginning to challenge design choices at the heart of platforms’ business models. 

Platforms cannot mark their own homework 

Systemic risk assessments are becoming a central enforcement tool. 

Under the DSA, the largest platforms must identify the risks their services create and explain how they will mitigate them. Recent enforcement actions suggest that the European Commission expects more than a procedural exercise. It is examining whether platforms’ assessments are based on evidence, specific to their services and capable of identifying how their own systems contribute to harm.  

The Commission’s preliminary findings against Meta over children under 13 accessing Facebook and Instagram are a clear example. It described Meta’s assessment as “incomplete and arbitrary”, pointing to the company’s failure to adequately consider external evidence about how many children use its services and their heightened vulnerability to harm. 

The message is clear. Platforms cannot rely solely on opaque internal judgments. Their assessments must engage with independent research and real-world evidence. 

The Commission took a similar approach in its action against Temu. It found that the company’s risk assessment relied on general information about e-commerce rather than examining the risks created by Temu’s own service, including whether its recommender system amplified illegal products. 

These cases show the systemic risk framework into a meaningful accountability tool. Platforms are increasingly being asked to show which risks they identified, how they reached their conclusions and whether their methodology stands up to scrutiny. 

Children’s safety is becoming an enforcement priority 

Children’s safety runs through much of the Commission’s recent enforcement work. 

Proceedings against Snapchat examine whether minors are being exposed to grooming, criminal recruitment and information about illegal goods. The Commission is also investigating whether Snapchat’s age-assurance measures and default settings provide children with sufficient privacy and security. 

Preliminary findings against TikTok similarly challenge design choices that allow minors’ accounts and content to remain widely discoverable. Children can make their accounts public, leaving profile information visible and allowing their content to be recommended beyond accepted followers. 

The Commission appears increasingly willing to use its guidelines on the protection of minors as a practical enforcement benchmark. These guidelines call for children’s accounts to receive the highest levels of privacy, safety and security by default. 

The same approach can be seen in preliminary findings against Pornhub, Stripchat, XNXX and XVideos. The Commission criticized both the platforms’ risk assessments and their reliance on self-declared age gates. Content warnings and blurred pages also did little to prevent children from accessing pornography. 

Taken together, these actions suggest that asking users to confirm their age or expecting children to configure their own safety settings will not be enough. Platforms will be expected to build age-appropriate protections into their services by design, as outlined by the Article 28 guidelines. 

The Commission is beginning to target the root causes of harm 

Perhaps the most significant development is the Commission’s growing scrutiny of platform design. 

Its preliminary findings against TikTok, Facebook and Instagram focus on features such as infinite scroll, autoplay, push notifications and highly personalized recommender systems. The Commission is examining whether these features are designed to encourage compulsive use, with consequences for users’ physical and mental well-being. 

Crucially, it has also questioned whether screen-time reminders, parental controls and online safety centers can adequately address these risks. Such measures place responsibility on users and parents while leaving the systems that create the harm largely untouched.  

The Commission has indicated that platforms may need to disable addictive features or adapt their recommender systems. 

If enforced, this approach would push the DSA beyond demands for better transparency and moderation. It would reach the architecture of platforms themselves. 

That could bring regulators into direct conflict with business models built around maximizing attention and engagement. The real test will be whether the Commission requires meaningful design changes and imposes strong consequences when platforms resist. 

The direction is promising. The outcome is still uncertain. 

These actions are an encouraging sign that the Commission is prepared to use the DSA’s systemic risk framework as intended. 

Many of the cases discussed above remain at an early stage. Preliminary findings allow companies to respond before the Commission reaches a final decision, while newly opened proceedings may take time to conclude. 

The DSA will ultimately be judged by what happens next. Investigations must lead to timely decisions. Platforms must make changes that reduce harm in practice, and penalties must be strong enough to change corporate behavior. 

Promising enforcement means little unless people are safer when they go online. The Commission must now turn its findings into changes that platforms cannot treat as optional.