The European Commission has issued €870 million in Digital Services Act (DSA) fines in just eight months. Three platforms. Three penalties. One common failure: they could not detect and remove harmful content at scale.
This is not a warning. It is a pattern.
TL;DR: €870M in DSA fines across AliExpress, X, and Temu. Every fine hinged on inadequate detection infrastructure, not bad policies. Automated, multi-modal, audit-ready detection is now a survival requirement for EU platforms.
The fines so far
--- · --- · --- · ---
AliExpress · €550M · 2026 · Insufficient detection of counterfeit / unsafe products
Temu · €200M · 2026 · Inadequate detection and removal of harmful content
X (Twitter) · €120M · 2025 · Inadequate detection and removal of harmful content
Total · €870M · 8 months · Detection failure
The AliExpress ruling (20 July 2026) specifically noted the platform had not hired enough people to check listings. All three fines were issued by the European Commission directly, bypassing national regulators.
The common thread: detection, not intention
Every fined platform had content policies. Every fined platform had moderation teams. Every fined platform had terms of service prohibiting harmful content. None of that mattered.
The DSA does not evaluate whether a platform intended to allow harmful content. It evaluates whether the platform detected and removed it. Good intentions do not reduce fines. Effective detection does.
The standard has moved from "did you try?" to "did you succeed?"
Why hiring more moderators does not solve this
Problem · Human-only moderation
--- · ---
Speed · Minutes/hours per item vs. milliseconds for automation
Worker safety · Repeated exposure to CSAM, self-harm, violent extremism
Human moderation works for appeals and edge cases. It does not work as a primary detection layer.
What the DSA actually requires
The Digital Services Act imposes specific obligations, with the strictest falling on Very Large Online Platforms (VLOPs) and Search Engines (VLOSEs):
- Systemic risk assessments identifying how design and systems contribute to illegal content
- Mitigation measures addressing those risks
- Independent audits of compliance
- Transparency reports documenting detection and enforcement activity
An audit that finds harmful content regularly reaching users despite existing moderation will result in enforcement action, regardless of stated commitments.
The child safety dimension
Current DSA fines focus on counterfeit goods, but child safety enforcement is accelerating in parallel:
- EU DSA: protect minors from developmentally harmful content
- US KOSA (bill, not yet law) - the drafted text asks for prevention across a defined list of harm categories
- UK Online Safety Act: up to 10% of global revenue for failing to protect children
- G7 (29 May 2026): seven common principles for protecting children online
Regulatory convergence is here. The question is not whether child safety regulation will affect your platform, but whether your detection infrastructure will hold up when the audit arrives.
Detection infrastructure: the missing layer
Effective detection infrastructure shares five characteristics:
--- · ---
Real time · Content is analysed as it is created, not after harm
Multi-modal · Text, image, audio, and video, harm crosses formats
Multi-language · Harmful content does not respect linguistic boundaries
Audit-ready · Regulators require documented evidence of detection and action
Zero content retention · GDPR alignment when processing sensitive content
The cost equation has changed
Before the DSA, automated detection was an efficiency play. After €870M in fines in eight months, it is a survival play.
A platform with €1B in EU revenue faces potential DSA fines of up to €60M (6% of global turnover). The cost of detection infrastructure is a fraction of that.
What platforms should do now
- Audit current detection capabilities. Identify gaps between what your systems detect today and what the DSA requires, especially across modalities and languages.
- Implement multi-modal automated detection covering text, image, audio, and video.
- Ensure detection generates audit-ready evidence. When the independent audit arrives, your system must document what was detected, when, and what action was taken.
- Address child safety proactively. DSA, KOSA, and the UK Online Safety Act are converging. Acting now beats reacting later.
About Tuteliq
Tuteliq is AI-powered child safety infrastructure for online platforms. A single API detects grooming, CSAM, sextortion, bullying, self-harm, fraud, and substance-use signals in real time across text, voice, image, and video, with AI-generated media detection and age verification built in.
The platform reads conversational context and calibrates to a user's age instead of matching static keyword lists. It is built on Tuteliq's own trained models and a patent-pending forensic pipeline (PRV 2630405-5). It covers 13 harm categories, including every harm named in the drafted KOSA text, and aligns with COPPA, the EU Digital Services Act, and the UK Online Safety Act. All data is processed within the EU with zero content retention: submitted content is deleted immediately after inference.
Learn more at tuteliq.ai or explore the documentation.