Europe's Summer of Digital Services Act Enforcement Targets Platform Design
Peter Chapman / Aug 6, 2026Peter Chapman is Associate Director with the Knight-Georgetown Institute (KGI).

European Commission President Ursula von der Leyen, center, speaks during a report on children's safety online with co-chairs of the Special Panel Maria Melchior, right, and Jörg M. Fegert, left, at EU headquarters in Brussels, Monday, July 13, 2026. (AP Photo/Marius Burgelman)
Last month may come to be seen as a turning point for the EU’s Digital Services Act (DSA). Over the course of July, the European Commission paired major policy initiatives with a series of consequential enforcement actions involving some of the world's largest technology companies. Even seasoned DSA experts have been struck by the pace and scope of these developments.
Through enforcement decisions, the Commission began to clarify the DSA’s broad legal obligations. These actions will test Brussels’ ability to shape whether and how these companies redesign their products to better protect safety, information integrity, and user wellbeing amid a fraught transatlantic landscape.
Accelerating enforcement
July was a remarkably active month for the DSA. The Commission launched its annual report describing “prominent and recurrent” risks identified by platforms and search engines operating in Europe and released the much anticipated report of its special panel on child safety online. These reports further clarified the Commission’s interpretations of risks and expectations for protection of minors under the DSA. But it was the Commission’s enforcement activity that marked the more consequential developments.
The Commission took steps to advance enforcement against multiple companies, with developments taking place throughout July:
- On July 10, the Commission preliminarily found that Instagram and Facebook’s addictive designs breached the DSA;
- On July 16, the Commission accepted X’s action plan to bring its advertising repository and researcher data access mechanisms into compliance with the DSA, following a December 2025 non-compliance decision and fine;
- On July 20, the Commission fined AliExpress €550 million for failing to effectively assess and mitigate risks to European consumers from illegal products; and
- On July 24, the Commission preliminarily found TikTok in breach of the DSA for failing to ensure safe accounts for minors.
Each of these decisions expect platforms to make design choices that address specific consumer harms – from exposure to scams and counterfeit or illegal products to addictive features that negatively impact the physical and mental wellbeing of users.
From findings to fixes
Financial penalties alone will not ensure safe designs. Over the last decade we’ve seen technology companies weather fines and penalties arising from regulatory enforcement without fundamental change to their business practices. This makes sense given that Alphabet, Google’s parent company, brings in $1.3 billion in revenue per day, while Meta brings in $650 million.
Preliminary findings and non-compliance decisions emerging from the Commission detail how European law requires platform design that protects consumers. In preliminary findings, the Commission states that TikTok “needs to change the basic design of its service” to prevent harm to the physical and mental wellbeing of its users, including minors and vulnerable adults. Meta “needs to implement design changes to both Instagram and Facebook” that effectively tackle physical and mental wellbeing harms to users.
But how? While the DSA provides the toolkit necessary for consumer protection, effective enforcement requires more clarity. Enforcement must ensure platforms deploy safe design and data practices, not simply penalize violations after the fact. It should demand transparency into important company choices, calibrated to specific audiences, including regulators verifying compliance, researchers assessing harm, or consumers choosing where to spend their time. And the Commission needs a clear, sustained approach to monitoring compliance and progress, not just at the moment of a decision.
These implementation challenges are not unique to European regulation. Regulators across a range of domains – including US technology enforcement agencies like Federal Trade Commission (FTC), the Department of Justice (DOJ), and state attorneys general – have long grappled with the same task now facing the European Commission: how to translate legal findings into lasting changes that meaningfully protect consumers.
The Knight-Georgetown Institute, Tech Justice Law, and the USC Neely Center developed “Designing Technology Remedies” to address precisely that challenge. It serves as a forward-looking enforcement framework for US technology litigation. It was developed through a systematic review of nearly 100 prior remedies, including FTC and DOJ consent decrees, public health litigation, civil rights settlements, and technology-related cases, and offers lessons relevant to the Commission’s enforcement strategy.
In line with “Designing Technology Remedies,” effective enforcement should feature three interlocking strategies: harm prevention, harm mitigation, and governance. These strategies must complement each other. One strategy alone is unlikely to ensure the safe online experiences that consumers demand.
Harm prevention changes how companies design, develop, and deploy their products. This could include prohibitions on unsafe design features identified through enforcement, including infinite scroll or highly personalized recommendations, as well as safer default settings or limits on data collection, retention, and use.
Harm mitigation should empower users to effectively report, avoid, and respond to harmful experiences. Internal company documents and third party assessments show that existing platform user safety tools have fundamental flaws. Enforcement implementation should require measurable targets for effectiveness – for example, related to ease of adoption, impacts on user behavior, and overall user satisfaction. Companies generate considerable data and maintain robust measurement infrastructure that should be used to demonstrate that tools work.
Governance addresses how companies make decisions and enforce compliance. The DSA establishes governance mechanisms that advance safety, including risk assessments and independent scrutiny through research. These systems are not working anywhere near their potential. To effectively assess safety mitigations, platforms must do more than list policies. They must describe clear standards for how risks are assessed, including specific taxonomies of metrics related to specific risks. Independent researchers need real access to data, be it publicly available data or private access.
Finally, the Commission needs to establish rigorous protocols for credible independent monitoring of specific outcomes. More work needs to be done to prepare for monitoring Commission decisions. The Commission’s June 2025 acceptance of commitments from AliExpress, which establishes a Monitoring Trustee, signals an emerging oversight model inspired by financial services. The Commission should ensure tailored monitoring and measurement of specific design-based enforcement, similar to what is currently being proposed by US attorneys general in litigation against Meta. This should be done through a combination of internal company monitoring and measurement as well as independent third-party assessment.
The path forward
July did more than just accelerate the pace of DSA enforcement: it began to concretize how platforms can turn the DSA’s broad design principles into specific product features that advance safety. The Commission’s preliminary findings assert that platforms must alter core features like infinite scroll and personalized recommendation systems. Translating these findings into durable designs, backed by independent monitoring, remains the harder task ahead. Fines alone will fail to challenge business models built on mass data collection, economies of scale, and maximized engagement. For digital platforms to effectively address risks, the Commission’s next chapter must advance the onerous work of specifying, verifying, and enforcing how platform design can measurably reduce specific harm.
Authors

