The EU has issued €870M in Digital Services Act fines since late 2024. Every fine was for the same failure: platforms that could not detect harmful content.

The European Commission has issued €870 million in Digital Services Act (DSA) fines in just eight months. Three platforms. Three penalties. One common failure: they could not detect and remove harmful content at scale.

This is not a warning. It is a pattern.

TL;DR: €870M in DSA fines across AliExpress, X, and Temu. Every fine hinged on inadequate detection infrastructure, not bad policies. Automated, multi-modal, audit-ready detection is now a survival requirement for EU platforms.

The fines so far

--- · --- · --- · ---

AliExpress · €550M · 2026 · Insufficient detection of counterfeit / unsafe products

Temu · €200M · 2026 · Inadequate detection and removal of harmful content

X (Twitter) · €120M · 2025 · Inadequate detection and removal of harmful content

Total · €870M · 8 months · Detection failure

The AliExpress ruling (20 July 2026) specifically noted the platform had not hired enough people to check listings. All three fines were issued by the European Commission directly, bypassing national regulators.

The common thread: detection, not intention

Every fined platform had content policies. Every fined platform had moderation teams. Every fined platform had terms of service prohibiting harmful content. None of that mattered.

The DSA does not evaluate whether a platform intended to allow harmful content. It evaluates whether the platform detected and removed it. Good intentions do not reduce fines. Effective detection does.

The standard has moved from "did you try?" to "did you succeed?"

Why hiring more moderators does not solve this

Problem · Human-only moderation

--- · ---

Speed · Minutes/hours per item vs. milliseconds for automation

Worker safety · Repeated exposure to CSAM, self-harm, violent extremism

Human moderation works for appeals and edge cases. It does not work as a primary detection layer.

What the DSA actually requires

The Digital Services Act imposes specific obligations, with the strictest falling on Very Large Online Platforms (VLOPs) and Search Engines (VLOSEs):

  • Systemic risk assessments identifying how design and systems contribute to illegal content
  • Mitigation measures addressing those risks
  • Independent audits of compliance
  • Transparency reports documenting detection and enforcement activity

An audit that finds harmful content regularly reaching users despite existing moderation will result in enforcement action, regardless of stated commitments.

The child safety dimension

Current DSA fines focus on counterfeit goods, but child safety enforcement is accelerating in parallel:

  • EU DSA: protect minors from developmentally harmful content
  • US KOSA (bill, not yet law) - the drafted text asks for prevention across a defined list of harm categories
  • UK Online Safety Act: up to 10% of global revenue for failing to protect children
  • G7 (29 May 2026): seven common principles for protecting children online

Regulatory convergence is here. The question is not whether child safety regulation will affect your platform, but whether your detection infrastructure will hold up when the audit arrives.

Detection infrastructure: the missing layer

Effective detection infrastructure shares five characteristics:

--- · ---

Real time · Content is analysed as it is created, not after harm

Multi-modal · Text, image, audio, and video, harm crosses formats

Multi-language · Harmful content does not respect linguistic boundaries

Audit-ready · Regulators require documented evidence of detection and action

Zero content retention · GDPR alignment when processing sensitive content

The cost equation has changed

Before the DSA, automated detection was an efficiency play. After €870M in fines in eight months, it is a survival play.

A platform with €1B in EU revenue faces potential DSA fines of up to €60M (6% of global turnover). The cost of detection infrastructure is a fraction of that.

What platforms should do now

  1. Audit current detection capabilities. Identify gaps between what your systems detect today and what the DSA requires, especially across modalities and languages.
  2. Implement multi-modal automated detection covering text, image, audio, and video.
  3. Ensure detection generates audit-ready evidence. When the independent audit arrives, your system must document what was detected, when, and what action was taken.
  4. Address child safety proactively. DSA, KOSA, and the UK Online Safety Act are converging. Acting now beats reacting later.

About Tuteliq

Tuteliq is AI-powered child safety infrastructure for online platforms. A single API detects grooming, CSAM, sextortion, bullying, self-harm, fraud, and substance-use signals in real time across text, voice, image, and video, with AI-generated media detection and age verification built in.

The platform reads conversational context and calibrates to a user's age instead of matching static keyword lists. It is built on Tuteliq's own trained models and a patent-pending forensic pipeline (PRV 2630405-5). It covers 13 harm categories, including every harm named in the drafted KOSA text, and aligns with COPPA, the EU Digital Services Act, and the UK Online Safety Act. All data is processed within the EU with zero content retention: submitted content is deleted immediately after inference.

Learn more at tuteliq.ai or explore the documentation.

Get Started Free · Read Documentation · View Pricing