EU digital regulation · Analysis
What held, and what did not
Three years of the Digital Services Act, obligation by obligation
A pattern runs through the record. The obligations addressed to platforms and enforced by a single central authority have held. The obligations that depend on decentralised capacity — national regulators, certified civil society bodies, vetted researchers — have not, or not yet. That distinction is more useful to a legislature designing its own framework than any comparison of texts, because it says where the effort has to go. It says nothing, on its own, about whether the regulation protects anyone — a question the closing section takes up and does not answer.
Fatima Ghilassene, avocate at the Lille Bar — 8 September 2026
What held
Central enforcement against the largest services. On 20 July 2026 the Commission fined AliExpress €550 million for failing to assess diligently, and to mitigate effectively, the risk of dissemination of illegal, unsafe and counterfeit products. Whatever one thinks of the amount, the mechanism worked as designed: an obligation to assess and mitigate systemic risk, documents the platform was required to produce, and a decision built on them.
Enforcement of the transparency obligations themselves. On 5 December 2025 the Commission adopted its first non-compliance decision under the DSA and fined X €120 million: for the deceptive design of its blue checkmark (Art. 25 §1), for the lack of transparency of its advertisement repository (Art. 39), and for failing to give researchers access to public data (Art. 40 §12). The third head is the one worth noting — the provision that arrived latest and works least well is also the one the Commission chose to enforce first. Its formal investigation into illegal content and information manipulation, opened on 18 December 2023, remains open.
An open-textured obligation made operational by guidance. Article 28 requires platforms accessible to minors to put in place appropriate measures to ensure a high level of privacy, safety and security. On its own the wording decides nothing. The Commission guidelines published on 14 July 2025 turned it into expectations a compliance team can act on and a regulator can check: accounts private by default, autoplay and notifications off by default, no design that optimises engagement against a minor’s explicit signals. The lesson is that an obligation drafted at that level of generality needs a second instrument, and the legislature should plan for it rather than discover the need afterwards.
Reporting, once it was harmonised. Transparency reports were owed from the start, but in incomparable formats. The Commission adopted an implementing regulation with harmonised templates, announced on 4 November 2024; providers collect data under it from 1 July 2025, and the first comparable reports were due at the beginning of 2026. Two reporting cycles were therefore spent producing documents that could not be set side by side.
What did not hold
The statements of reasons, as data. Every platform must give a reasoned explanation for each moderation decision and file it in a public database. The volume arrived: 131 million statements in November 2023 alone. The usefulness did not. In the empirical study of that month by Kaushal, van de Kerkhof, Goanta, Spanakis and Iamnitchi, a single service — Google Shopping — accounted for 52.2 % of all filings, TikTok for 17.1 % and Amazon for 10.8 %; Google Shopping used an identical template in 99.5 % of its statements and TikTok in 98.5 % of its own; 99.8 % of the filings concerned breaches of terms of service and only 0.2 % illegal content; and the database schema carried no field for the redress information the regulation requires. A duty to explain, discharged by a template, produces a very large quantity of nothing.
Trusted flaggers. Article 22 gives priority treatment to notices from entities certified for their expertise. As of January 2025 sixteen had been certified across the entire Union. The obstacles are structural rather than administrative: the entities that have the expertise rarely have the funding, and those that find funding often find it with the platforms, which puts the independence requirement in question. Certification criteria are also applied inconsistently from one Member State to another.
Researcher access to platform data. Article 40 was supposed to let independent research verify what platforms report about themselves. The delegated act organising it was adopted on 2 July 2025 and the first researchers could be vetted from October 2025 — three years after the regulation entered into force, and more than a year after it became fully applicable. That the Commission’s first non-compliance decision rests in part on this very provision says how far the obligation was from being met.
The national regulators. Each Member State had to designate a Digital Services Coordinator, endow it with the powers the regulation lists, and lay down rules on penalties, by 17 February 2024. On 7 May 2025 the Commission referred five of them to the Court of Justice: one had neither designated nor empowered a coordinator, four had designated one without the necessary powers, and all five had failed to adopt penalties.
The funding of supervision. The annual fee charged to the largest services, capped at 0.05 % of worldwide annual net income, was the mechanism meant to pay for their supervision. On 10 September 2025 the General Court annulled the decisions setting the 2023 fee for Facebook, Instagram and TikTok, because the method for counting average monthly active users was an essential element that had to be adopted by delegated act rather than by an implementing decision. The effects were maintained provisionally, for no more than twelve months from the date the judgments become final.
The pattern, and what it costs to ignore it
Sort the list and the line falls in the same place each time. What worked runs from one authority to one company: an obligation on the platform, an investigation, a decision. What did not work runs through many hands — twenty-seven national regulators to be empowered, civil society organisations to be certified and funded, researchers to be vetted, a database to be made usable by people who did not design it.
This is not a European peculiarity. It is what happens whenever a statute assigns a role to actors it neither creates nor funds. The provision exists on the day the law enters into force; the capacity does not, and nothing in the text produces it.
Three consequences for a framework built elsewhere. A duty to give reasons should specify the granularity expected, or it will be discharged by template. A role given to civil society should come with the means to occupy it, or it will stay empty. And a regulator should receive its powers and its penalty regime in the same instrument that names it, because the European record shows that the naming happens and the empowering does not always follow.
Why none of this measures whether the regulation works
Everything above concerns machinery: decisions taken, bodies certified, acts adopted, deadlines met or missed. That is not what the Digital Services Act was made for. When the Council agreed its position on 25 November 2021 it put the aim in one line — the proposal follows the principle that what is illegal offline should also be illegal online — and stated the objective as keeping users safe from illegal goods, content and services, and protecting their fundamental rights online.
Against that yardstick, nothing in this note is a measure of effect. Whether people encounter less illegal content, whether minors are better protected, whether a person who has suffered an online harm obtains redress more often or faster: none of it is established by counting fines and certifications. The one indicator available points in an uncomfortable direction — 99.8 % of the moderation decisions filed in the public database concerned breaches of the platforms’ own terms of service and 0.2 % concerned illegal content — but that figure describes what platforms report, not what the regulation has changed. And the provision that would allow the question to be studied independently, researcher access to data, is the one that arrived last.
There is also a chronological objection, and it cuts in the instrument’s favour. Three years is short for a text of this scale, and several of the failures listed above are delays rather than defects: the delegated act was adopted, the harmonised templates now apply, the infringement procedures are running. A reader in 2029 may find that much of the second column has moved into the first.
So the conclusion is narrower than either camp would like, and it is a position rather than a finding. It is too early to pronounce on the effectiveness of the Digital Services Act, because effectiveness here means the protection of people online and that cannot yet be measured. It remains, imperfect and unmeasured, a model worth drawing on — because it is the first attempt to state the principle in binding terms, and because its failures are documented, dated and public, which is more than most regulatory models offer to those who come after.
Sources verified on 8 September 2026 against primary sources — the Commission’s decisions and announcements, the judgments of the General Court, and the delegated and implementing acts cited — with the exception of the figures on the transparency database, which come from the academic study named above and are attributed to it. This note is limited to what the public record establishes; it is not an evaluation of the regulation’s substantive effects.
Read: what implementing the DSA actually requires