Introduction: The DSA's Enforcement Era Has Begun
For years, the Digital Services Act was viewed as a regulatory framework waiting to prove its teeth. That uncertainty ended in December 2025 when the European Commission issued its first major enforcement decision under the Digital Services Act, imposing a €120 million fine on X. Since then, the pace of enforcement has accelerated. As VLOPs and VLOSEs operate across European markets, understanding what non-compliance actually costs—and which remediation strategies regulators accept—is no longer optional.
This article examines three landmark enforcement actions that define the current enforcement landscape: X's transparency failures resulting in the landmark fine, Meta's ongoing investigation into minor safeguards, and TikTok's groundbreaking preliminary findings on addictive design. Each case reveals critical lessons for platform operators about compliance obligations, financial exposure, and the types of mitigation measures that regulators demand.
X's €120 Million Fine: The First Major DSA Penalty
The Violations
Announced in early December 2025, the decision signals that the European Union's ambitious regulatory framework for online platforms is actively shaping how Big Tech operates in the digital sphere. The Commission's investigation, which unfolded over two years following a familiar investigative arc of risk assessment reports, responses to information requests, and formal proceedings in December 2023, resulted in findings across three core areas.
First, the Commission concluded that X's paid "blue checkmark," its sparse and unwieldy advertising repository, and its barriers to researcher access together formed a pattern of conduct at odds with the DSA's core principles of transparency and accountability. The blue checkmark violation deserves particular attention, as it exemplifies how design can mask deceptive conduct. X's use of the 'blue checkmark' for 'verified accounts' deceives users, violating the DSA obligation for online platforms to prohibit deceptive design practices.
Second, the advertising repository fell far short of transparency obligations. X's ads repository lacked critical information such as the content and topic of the advertisement and the legal entity paying for it, hindering researchers and the public to independently scrutinise potential risks in online advertising.
Third, X failed to meet its DSA obligations to provide researchers with access to the platform's public data, with X's terms of service prohibiting eligible researchers from independently accessing its public data and imposing unnecessary barriers that effectively undermined research into systemic risks.
Compliance Deadlines and Escalation Risk
X must submit remedial plans within 60 days for checkmark issues and within 90 days for ads and data access, otherwise facing further periodic fines potentially up to a significant share of its global revenue under DSA enforcement rules. This structure illustrates a critical enforcement mechanism: fines are only the opening move. Platforms that fail to remedy violations face periodic penalty payments that can compound exponentially.
Key Takeaway for Operators
X's case demonstrates that transparency obligations are not aspirational. Deceptive design, incomplete advertising repositories, and restrictive researcher access are not minor lapses—they trigger formal proceedings, reputational damage, and multi-digit million-euro fines. Platforms must audit their design practices, advertising disclosure systems, and data access frameworks before investigation begins.
Meta's Minors Safeguards Investigation: When Child Protection Gaps Become Compliance Failures
The Nature of the Investigation
While X faced its first-ever DSA fine, Meta entered a more nuanced—but equally consequential—enforcement phase. The European Commission's investigation into Meta under the Digital Services Act has moved further into the enforcement phase, reflecting the EU's broader push to strengthen platform accountability and transparency. Rather than a single fine, Meta is navigating multiple parallel investigations touching content moderation, age verification, researcher data access, and addictive design.
The minors-focused investigation is the most urgent. According to the Commission, Meta's safeguards do not effectively enforce its stated minimum age of 13, with users able to enter a false date of birth at sign-up without meaningful verification, while systems to detect or remove underage users after account creation appear ineffective.
What Regulators Are Demanding
Critically, the Commission has moved beyond detecting problems and articulated specific, measurable remedies. The Commission suggests Meta could strengthen age assurance systems, improve internal processes, resources, and testing and documentation for underage access, and better evaluate the performance of existing safeguards to prevent, detect and remove underage users.
These include making minors' accounts private by default, adapting recommender systems to reduce exposure to harmful content and "rabbit hole" effects, disabling features associated with excessive use such as streaks, autoplay and push notifications, and strengthening moderation and reporting tools.
The meta-lesson here is important: if a company's internal data, external evidence and user-facing controls do not align, the risk assessment itself may become a compliance failure. Documentation, internal sign-off chains, and demonstrated effectiveness matter as much as the controls themselves.
Penalty Exposure
Potential fines reaching up to 6% of global annual revenue would be approximately $9.87 billion for Meta, making this investigation existential for Meta's European operations and profitability.
Key Takeaway for Operators
Child protection is no longer a product feature—it is a compliance obligation that must be evidenced, tested, documented, and continuously evaluated. Vague safeguards, optional user controls, and aspirational age gates do not satisfy DSA requirements. Platforms must build verifiable, measurable child protection architectures, backed by internal governance trails and regular effectiveness audits.
TikTok's Addictive Design Case: Regulatory Focus Shifts to Platform Architecture
A New Frontier in DSA Enforcement
In its preliminary findings published on 6 February 2026, the European Commission found TikTok in breach of the Digital Services Act for its addictive design, marking the first time enforcement action has not focused on illegal content, data protection or competition, but on the harmful architecture of the platform itself, especially for minors and vulnerable adults.
This represents a fundamental shift. Rather than policing content or user data, the Commission is targeting the design mechanisms themselves. TikTok breached the DSA because of the way the platform was designed to keep users scrolling, with infinite scroll, algorithmic amplification of emotionally charged content, push notifications engineered to interrupt, and the deliberate absence of stopping cues at the center of the enforcement action.
The Commission's Preliminary Findings and Remedial Path
The Commission accuses TikTok of implementing inadequate risk mitigation measures, with current measures such as screentime management and parental control tools failing to effectively reduce risks stemming from the platform's addictive design.
The Commission considers that TikTok will need to change the basic design of its service, with potential measures including disabling or limiting addictive features over time, enforcing effective screen-time breaks and adapting its recommender system. These are not marginal tweaks—they are fundamental architectural changes to how the platform operates.
Potential Outcomes and Industry Implications
If the Commission ultimately concludes that TikTok is non-compliant with the DSA, the platform could face a fine of up to 6% of its global annual turnover. Beyond the financial penalty, likely outcomes include regional fragmentation with a separate EU version bearing enforced screen-time limits, disabled infinite scroll and reduced autoplay, a decline in engagement and ad revenue, and ripple effects across the industry setting a precedent that could force Instagram Reels, YouTube Shorts and similar platforms to face equivalent scrutiny.
The implications extend beyond TikTok. This decision signals that the DSA can be leveraged to challenge any design pattern deemed systemically harmful, particularly those targeting minors or vulnerable users.
Key Takeaway for Operators
Engagement-maximizing design features are now under direct regulatory scrutiny. Infinite scroll, autoplay, algorithmic promotion of emotionally resonant content, and push notifications may be examined as systemic risks rather than product innovation. Platforms must audit their recommendations and engagement mechanics, assess their impact on minor users, and prepare alternative designs that maintain user engagement without employing manipulative architecture. Optional safeguards are no longer sufficient; the architecture itself must be defensible.
The Enforcement Landscape: Patterns and Implications for Operators
Escalating Fines and Periodic Penalties
The X case established that DSA fines are not negotiable fees—they are opening moves. The €120 million penalty can be followed by periodic fines if remediation is inadequate. For Meta and TikTok, potential penalties reaching 6% of global turnover dwarf even the largest historical tech fines. This financial exposure demands C-suite and board-level attention to compliance.
Transparency Obligations Are Non-Negotiable
Across all three cases, transparency emerges as a common thread. Platforms must provide clear information about:
- User verification and account authenticity
- Advertising sources, content, and targeting mechanisms
- Data access for vetted researchers
- Design choices and their systemic risk implications
- Effectiveness of safeguards protecting minors and vulnerable users
Mitigating Measures Must Demonstrate Actual Effectiveness
The Commission does not accept aspirational safeguards or optional user controls as compliance. Instead, platforms must demonstrate through testing, documentation, and continuous evaluation that their measures actually reduce harm. This requires investment in verification, auditing, and independent assessment capabilities.
Architectural Review Is Essential
Whether checkmarks, recommender systems, or engagement mechanisms, design itself is now subject to regulatory scrutiny. Platforms can no longer assume that design choices are purely commercial decisions. VLOPs and VLOSEs must conduct comprehensive design audits—potentially with external support—to identify features that could trigger formal investigations.
Preparing for DSA Enforcement: Practical Steps for Platforms
Conduct a Compliance Audit Immediately
Platforms should review their current systems against the three case studies:
- Are verification mechanisms transparent and accurate?
- Is advertising data accessible and complete?
- Do researcher access processes create unnecessary barriers?
- Are child protection safeguards demonstrably effective?
- Are engagement-driving design features sustainable under regulatory scrutiny?
Build Internal Governance and Documentation Trails
The Meta case highlighted that internal misalignment between risk assessments and operational reality is itself a compliance failure. Platforms must establish governance structures where design decisions, risk assessments, safeguard testing, and remediation measures are documented, reviewed, and traceable to board-level oversight.
Consider Independent DSA Audits
For VLOPs and VLOSEs seeking credibility with regulators, independent DSA audits offer a pathway to demonstrating compliance maturity. These audits can identify gaps before investigators do and provide third-party evidence of good-faith remediation efforts.
Prepare for Data Requests and Formal Proceedings
The X and TikTok investigations show that formal proceedings typically follow 18–24 months of information requests and preliminary risk assessments. Platforms should establish internal teams capable of responding to Commission queries, conducting preliminary risk assessments, and preparing remedial proposals without unnecessary delays.
Conclusion: The DSA Is No Longer Theoretical
The enforcement actions against X, Meta, and TikTok prove that the Digital Services Act is operationalizing. Fines are real, periodic penalties are enforceable, and architectural changes can be mandated. Platform operators who have treated compliance as a compliance-team responsibility must now recognize it as a strategic and governance imperative.
The stakes are highest for VLOPs and VLOSEs serving millions of European users. Non-compliance is not a distant regulatory risk—it is an immediate financial and operational threat. Platforms that audit their systems today, build credible safeguards, and demonstrate genuine commitment to DSA obligations will navigate this enforcement era far more successfully than those caught unprepared by investigations.
For more insights into building defensible compliance strategies, explore our latest articles on DSA implementation and enforcement trends.
