News from Across the Sea #10
Welcome to the first issue of 2026 of our bimonthly newsletter on the European Union’s Digital Services Act (DSA). We hope you’ve had a good start to the new year.
News from Across the Sea #10:
Welcome to the first 2026 issue of our bimonthly newsletter on the European Union’s Digital Services Act (DSA). We hope you’ve had a good start to the new year. February 17 marked two years since the DSA fully came into effect. The details of the European Commission’s multi-million fine against X were leaked. CELE traveled to the Netherlands to present a work-in-progress. Several investigations into platform design are moving forward.
Details of the Multi-Million Fine Imposed on X
In our last edition, we discussed the 120-million-euro fine that the European Commission imposed on X—the highly anticipated first infringement decision under the DSA. The details of the decision remained confidential until January, when a group of lawmakers obtained the full text of the decision through a formal request and made it public. The document contains few surprises compared to what had already been made public, confirming suspicions that the allegations of censorship were unfounded. This, in turn, puts the European Commission in the awkward position of having to explain why it is not making most of its decisions public.
CELE at the DSA and Platform Regulation Conference
On February 16 and 17, the second edition of the DSA and Platform Regulation Conference was held at the University of Amsterdam. CELE was represented by its director, Agustina Del Campo, who presented a work-in-progress paper, co-authored with Nicolás Zara and Ramiro Álvarez Ugarte, on the role of the state in the enforcement and oversight of the European Union’s Digital Services Act and its potential implications for freedom of expression. The conference, a regional benchmark in the field of platform regulation, is organized by the DSA Observatory at the Institute for Information Law (IViR) at the University of Amsterdam and brings together academics, regulators, and civil society experts from across Europe and the rest of the world. Discussions at the conference were shaped by the growing tension between the U.S. government and U.S. platforms on one hand and European institutions on the other, as well as the pressure these private actors exert on regulations that affect them, such as the DSA and the DMA. CELE had already participated in the first edition of this conference in 2024. The program can be viewed here.
More Trouble for X: The European Commission Investigates Grok
Earlier this year, the Grok chatbot on the X platform added the ability to edit images and videos. Since then, users have begun to abuse this feature and ask the chatbot to edit photos of real women and even children so that they would appear in underwear. The app had no qualms about doing so, to the point that, within a matter of days, millions of such images had already flooded the platform (according to the Center for Countering Digital Hate, there were some 3 million sexualized images, including about 23,000 of children). On January 25, the European Commission launched an investigation into X to determine whether the company fulfilled its obligations to assess and mitigate risks associated with the use of Grok, including, primarily, the dissemination of illegal content, negative effects related to gender-based violence, and serious negative consequences for people’s physical and mental health (Articles 34.1.a and 34.1.d of the DSA). The official press release explains that such risks allegedly materialized through digitally manipulated sexually explicit images and even content that could be considered child pornography. The Commission’s response is one of many taken by various national regulators, including some in Europe such as France. In addition, the Commission expanded its previous investigation into X’s recommendation systems, which had been ongoing since 2023.
Further Investigations: Shein in the Crosshairs
The Commission launched a formal investigation against Shein, on suspicion that the company has violated the DSA in three areas: the use of a highly addictive design for consumers, such as reward programs and the gamification of the service; a lack of transparency in its recommendation systems; and the sale of illegal products, including some that could constitute child abuse material, such as child-like sex dolls as previously mentioned in an earlier post.
Last Chance for TikTok
The Chinese giant was preliminarily found liable for violating the DSA in connection with its addictive design. The European Commission reached this conclusion after evaluating features of the service such as infinite scrolling, autoplay, push notifications, and its highly personalized recommendation system. It concluded that the company had failed to fulfill its obligations to adequately analyze and mitigate the risks that these addictive features could pose to the physical and mental well-being of its users, including children and vulnerable adults. In the official press release, the Commission stated that “by constantly rewarding users with new content, certain design features of TikTok encourage the need to keep scrolling and trigger ‘autopilot’ mode in users’ brains.” They noted that, according to research, this “can lead to compulsive behaviors and reduce users’ self-control.” The Commission maintains that TikTok must change the basic design of its service by disabling features such as infinite scrolling, implementing screen breaks—including at night—and adjusting its recommendation system. The platform will now have the opportunity to respond to the European Commission’s preliminary findings. The company has already dismissed the Commission’s findings as “a categorically false and completely unfounded description” of the platform. Once the company has submitted its defense, the Commission will be in a position to evaluate it and decide whether to issue a non-compliance decision, which could result in fines of up to 6% of the company’s total annual revenue. The process is being closely watched by Meta, whose Facebook and Instagram platforms are also under investigation for their addictive design since May 2024. The two previous cases filed against TikTok (#1 and #2) concluded with settlements in which the company agreed to comply with certain regulatory requirements to avoid financial penalties.
Designation of WhatsApp as a VLOP
In late January, the European Commission ruled to designate WhatsApp as a Very Large Online Platform (VLOP) under the DSA. This designation does not apply to the entire app, but only to the “Channels” feature, which falls under the legal definition of an online platform. The designation came after it was confirmed that this feature had reached the legal threshold of 45 million active users in the EU. Following the designation, this platform feature must comply with the more stringent obligations of Section 5 of the DSA, including those related to assessing and mitigating systemic risks arising from its design, operation, or third-party use. This article by Sarah Eskens analyzes the classification of WhatsApp channels and Telegram’s public groups and channels as online platforms under the DSA.
New CELE Publication
In this new policy paper, our director, Agustina Del Campo, analyzed the data access regime for research under the Digital Services Act, taking into account its main challenges and practical implications for researchers in the Global South. This work is part of the data access agenda, in which CELE has been supporting for years the efforts of the European Union and other actors to regulate and implement this framework, which is still in its early stages.
The DSA in Court: Another Victory for Data Access
On February 17, a Berlin appeals court ruled that the German NGO Democracy Reporting International (DRI) has the right, under the DSA, to access public data from that platform. The decision came after X refused to provide DRI with the platform’s public data related to the Hungarian parliamentary elections in April. The appeals court’s ruling overturned the decision of the trial court, which had declared itself without jurisdiction and had directed DRI to pursue access to the data through the platform’s headquarters in Ireland.
What Are We Reading?
- [This report from the Knight-Georgetown Institute](https://www.delorscentre.eu/en/publications/detail/publication/the-european-democracy-shield-papering-over-the-cracks) on what Meta and TikTok’s internal documents reveal versus what they report in the context of their obligations to mitigate systemic risks under the DSA.
- [This article by Toni Lorente and Kathrin Gardhouse](https://www.cambridge.org/core/journals/european-law-open/article/mustcarry-special-treatment-and-freedom-of-expression-on-online-platforms-a-european-story/0A1E5B2512C3145E9B8DD61BFCD9D4F6) on the applicability of the DSA to ChatGPT, its classification as a platform or search engine, and an analysis of its risk profile under the criteria of Articles 34 and 35 of the DSA.
- [This blog post by John Albert](https://peepbeep.blog/2025/12/08/decoding-russmedia-did-the-cjeu-just-see-red-and-mess-it-up/) offers a critical look at independent audits under Article 37 of the DSA, using X as a case study. Thank you very much for reading this far. See you soon! Until next time!