Making sense of our connected world

Enforcing the Digital Services Act: A cat & mouse game?
Social media platforms move fast – but faster than the law? Ideally, law keeps up with societal change, technological advancements, and the challenges that arise from their interaction. The Digital Services Act presents a landmark piece of legislation to (finally, adequately) responsibilise the rapidly evolving online sphere. For more than two years now, it has had the chance to unleash its full potential in holding platforms accountable for their conduct. Is it working as expected or is there a need to adjust a few dials? Soon, this question is up for debate as part of the DSA’s built-in review process stipulated in its Article 91. To reflect on the regulation’s impact and lay out the starting conditions of said process, the following looks at both enforcement progress and geopolitical influences. If you are new to the DSA, please consider starting with the first part of this blogpost (Pothmann, 2026) before diving into this second part.
With the recent designation of ChatGPT as a Very Large Online Search Engine (VLOSE), in parallel to designations of Reddit and Roblox as Very Large Online Platforms (VLOPs), the European Commission (EC) took another major step towards fostering a safer online environment (European Commission, 2026a). In particular, it signaled that it is not pivotal for such designation whether, for instance, ChatGPT is called a chatbot, but whether it functions as a search engine – which it evidently does. Why is that important? Because risks emerging in the context of digital services are not (necessarily) attached to a specific type of technology, but to the functions they take on in their users’ lives. This is explicitly accounted for in Article 34: “[…] or the use made of their services”. At the end of the day, the Digital Services Act (DSA) aspires to achieve a comparable level of legal protection in the online sphere as we enjoy in the offline sphere, and not ban a piece of software.
Flexibility, not bendability
The path towards that requires careful application of established rules, as well as, where necessary, timely adjustments of those, to ensure rights-based conduct without overreach. In that sense, it is not a bug that the DSA includes a structured reflection in its Article 91 and may require refinements. It is an intentional feature, based on experience with prior (digital) regulation and, to some extent, the expectation to learn from increased transparency, as it is hard to regulate something upfront that only shows after the fact. The aim appears clear: optimising, rather than tossing achievements overboard. At the same time, some actors might not agree with the treatment of a chatbot as a search engine – or the regulation of platforms altogether. With the EC being a political actor, the regulation of economically powerful companies does not happen in isolation. To consider this, we will shortly reflect on some geopolitical context, which might make the turn of events appear more understandable. But one step at a time.
Where the DSA is picking up momentum
It would be an understatement to say that a lot has happened since the DSA fully entered into force on 17 February 2024. At the time of writing, the Commission has designated 25 VLOPs and 3 VLOSEs (European Commission, 2026b). For a detailed update on current proceedings against a handful of them, I highly recommend the regular summaries provided by Anna Pingen on the eucrim newspage (Pingen, 2026). For our purpose, a few high(–or low–)lights shall provide a sufficient impression.
X
The platform formerly known as Twitter was fined 120m Euro for their deceptive design practices in selling their blue checkmarks as identity-verifiers (violating Article 25) and an omission to establish a transparency database (violating Article 39) as well as to grant data access to researchers (violating Article 40) (European Commission, 2025a). It was the first strong sanction under the DSA, sending an important signal over the Atlantic amidst tensions between the EU and US, as discussed by Josephine Ballon and Matthias C. Kettemann in our Spotlight series (HIIG, 2026a). It should be noted, however, that the sanctioned conduct appears more like a symbolic punch to establish authority, rather than meaningfully advancing a responsible online sphere (Bovermann, 2025). Blue checkmarks arguably are not among the most pressing issues of digital policy. Famously, the fine did not exactly receive praise, given the prompt visa sanctions against the CEOs of HateAid, an organisation that has been vetted by the German Digital Services Coordinator (Bundesnetzagentur) as a Trusted Flagger under Article 22 of the DSA. Pursuant to a request by the EC, X has submitted an action plan to remedy the shortcomings, which was deemed insufficient by the European Board for Digital Services (EBDS), though it was accepted by the EC, giving the platform six months to implement changes and prove their effectiveness via an audit (European Commission, 2026c).
TikTok
This popular short-video platform was preliminary found to breach Articles 34, 35, and 28 through addictive design techniques, including infinite scrolling, autoplay, push notifications, and personalised recommender systems (European Commission, 2026d; Lievens et al., 2026). All of these carry identifiable risks that should have been mitigated via basic design changes, not just screentime management or parental controls, both of which show limited effectiveness. Notably, the EC underlined how the effects do not just affect minors, but all users, presenting a sharp observation relevant to ongoing discussions on social media age bans (European Commission, 2026e). Nevertheless, recent preliminary findings by the EC suggest a failure to ensure safety specifically for minors on their platform (European Commission, 2026f). The proceedings also fall in a context where, over in the US, courts are starting to classify comparable practices as product defects under product liability law to put a stop to excuses based on exemptions from content liability (Cedarbaum, 2026). For now, TikTok has slammed the former accusations as false (Chee, 2026), indicating further escalation on the horizon.
Pornhub & similar platforms
In the erotic video sector, preliminary findings suggested inadequate protection of minors by granting them access to their platforms (European Commission, 2026g). As the EU did not consider the steadfast self-declaration via a serious button to be effective, they published new guidelines for better protection, which such platforms should adhere to (European Commission, 2025b). According to number 49 of those guidelines, any age verification method should be accurate, reliable, robust, non-intrusive, and non-discriminatory. To ensure this, the platforms might even adopt the EU’s new dedicated app, or they might consult with Meta & Co., should they need to incorporate age restrictions as well in the foreseeable future. Well beyond this sector, the if and how of age-specific bans on platforms are hotly debated across Europe. Looking at France, the Constitutional Council recently ruled such a legislative proposal unconstitutional. This could be a first indication that Australia’s approach in that regard, i.e., a social media ban for children under 16 years, might not bear fruits in the EU. To learn more about the protection of minors online, make sure to revisit our recent Learning Call with Jessica Galissaire and Paddy Leerssen (HIIG, 2026b).
Together, these developments demonstrate how the EU is taking incremental steps from the first stage of transparency-box-ticking to substantive design and safety enforcement.
No access, no answers
In other news, researchers, after a significant delay, are finally starting to gain access to some data on platforms’ inner workings in accordance with Article 40 of the DSA, promising the opportunity to collect evidence for further possible breaches of the regulation (di Stefano & Vergnolle, 2025). Being able to first-handedly assess platform-related effects based on large-scale data is a major achievement of the DSA. It allows researchers to test for relationships between certain content, dynamics, or feature-changes and outcomes related to systemic risks. For example, better understanding social media addiction (Amirthalingam & Khera, 2024), deceptive design patterns (Weinzierl, 2024), or echo chambers (Watolla, 2025). In the spirit of evidence-based regulation, this is crucial.
Still, there are relevant practical hurdles in the way of getting useful access to data, even if platforms comply (Goanta & Iamnitchi, 2026). This includes, in particular, proving to their Digital Service Coordinator that they are capable of “fulfilling the specific data security and confidentiality requirements corresponding to each request and to protect personal data” (DSA, 2022, Art. 40 paragraph 8 lit. d). Depending on the institutional circumstances of the applying researchers, this can quickly become a showstopper – and it is a fitting illustration of a broader pattern.
Valid critique or grumbling noise?
The past four years were not just characterised by euphoria and zeal for action. Common criticisms of the DSA include exactly this kind of interpretive leeway (Leerssen, 2023), alongside charges of regulatory overreach (Turillazzi et al., 2022), and censorship (Husovec, 2024). In defense of the referenced authors, very few academics believe those are unresolvable, or – in the case of censorship allegations – even remotely justified claims, as elaborated on in a recent piece by Matthias C. Kettemann and Wolfgang Schulz (Kettemann & Schulz, 2026). If respected properly, the DSA’s transparency measures could bring some clarity into what is actually being ‘censored’, countering fears of over-removal (Rodríguez de las Heras Ballell, 2021). And that is precisely why data access for research is essential. Paraphrasing a famous quote by Václav Havel, the EU’s paradigm remains to promote a content governance of truth-seeking, not truth-finding, which is an important difference. Still, criticisms remain, some louder than ever.
Navigating rough seas
A major outlet of the above-mentioned critiques is situated ‘across the pond’. The transatlantic relationship rarely served as such a literal metaphor as it does in the current geopolitical climate. Tides are rough, with fierce disagreements, particularly in regard to what constitutes freedom of speech and censorship (Ollig, 2025; Wennberg, 2025). This is why the DSA presses sensitive buttons in that political dispute: it conflicts with the US conception of free speech – which, ironically, is under attack in the US as well, by the very actors that purport to defend it abroad – and constrains US platforms in their behaviour. Clearly, the EU does not have to adopt the same understanding of free speech, and just as clearly, politically motivated sanctions and threats against legitimised actors who do their part in preventing illegal activity on the web should not be tolerated. As the German Chancellor put it earlier this year, in the same setting where the US Vice President in 2025 accused the EU of censorship: “Freedom of expression ends here […] when words oppose human dignity and the Basic Law” (Federal Government, 2026).
Sovereignty in times of geopolitical shifts
But this is not just about free speech. It also relates to public-private relationships and the power to shape online spaces. In principle, the DSA fosters sovereignty (Turillazzi, 2022). In a market where international players do not adhere to local understandings of fundamental rights, it enables competition by leveling the playing field. At the same time, conflicts on the world stage cannot be ignored in the governance of digital spheres. Especially given that private companies are taking on the role of geopolitical actors in a digital world order that is less constrained by physical borders as avocados and cars (Messina, 2026, p. 173). Particularly, when co-dependent partnerships and competitive compulsions are on the line for said actors – pushing them to take advantage of their powerful position – geoeconomical considerations gain weight (Markeviciute, 2026). States can either do their best to get a grip on this potent power-dynamic or fall prey to it. With a ‘self’-updating DSA (and DMA, for that sake), the EU aims for the former, to prevent the latter. To make matters even more complicated, many states are not just concerned with EU-related, but also national sovereignty. This can present a challenge, when having to balance national autonomy with supranational regulation (Troitiño & Mazur, 2026, p. 319). Even more so, considering that – between the 27 member states – understandings of illegal content differ, powers in shaping regulation are unequal, and resources for implementing the regulation are unbalanced (Orlando-Salling, 2025).
Where do we stand?
Taken together, the fines against X, the preliminary findings on TikTok and adult platforms, and the slow but real opening of data access under Article 40 show a DSA that is starting to demonstrate its potential. Yet this momentum unfolds in a Union that is not fully aligned internally, in addition to enormous external pressure that treats every fine as a geopolitical provocation rather than a legal act. This creates a challengingly dynamic climate for regulators, demanding adaptability and determination. As a regulation of international companies, this strongly affects the DSA. Still, enforcement has clearly gained ground. Whether the DSA can hold and extend that ground depends less on the law itself than on the EU’s willingness to keep enforcing it under pressure.
Ultimately, diplomatic credibility requires consistent enforcement, without risking isolation (Rodríguez de las Heras Ballel, 2021). Therefore, a strategic political concession to selective deregulation in digital policy matters that lowers users’ rights could be estimated pointless (Mariniello, 2025), given the current absoluteness of demands from certain actors. This fits in with the European Democracy Shield (European Commission, 2025c), a commitment to enforce EU law and not shy back. If and how this will manifest in the upcoming DSA review process, remains to be seen. In our responsibility as researchers and civil society actors, the least we could do is support them by providing ideas on how to come out on top in this cat and mouse game.
If you are interested in concrete ideas on how to update the DSA, we will take a closer look at this in an upcoming discussion paper, drawing from ideas accrued in the collaborative DSA research network project between the Alexander von Humboldt Institute for Internet and Society, the Leibniz-Institute for Media Research | Hans-Bredow-Institute, and the DSA Observatory of the University of Amsterdam, funded by the Mercator Foundation. So stay tuned.
References
Amirthalingam, J., & Khera, A. (2024). Understanding social media addiction: A deep dive. Cureus, 16(10), Article e72499. https://doi.org/10.7759/cureus.72499
Bovermann, M. (2025, December 18). The limits of symbolic regulation: Why the EU should not enforce the DSA (right now). Verfassungsblog. https://doi.org/10.59704/abccb790b8a300ee
Cedarbaum, J. G. (2026, March 26). Does product liability offer a route around Section 230? Lawfare. https://www.lawfaremedia.org/article/does-product-liability-offer-a-route-around-section-230
Chee, F. Y. (2026, February 6). TikTok charged for breaching EU rules with app’s addictive features. Reuters. https://www.reuters.com/business/media-telecom/tiktok-hit-with-charges-breaching-eu-online-content-rules-app-may-have-change-2026-02-06/
di Stefano, S., & Vergnolle, S. (2025, December 5). Hack the DSA: Four actionable ways to improve DSA reporting. Verfassungsblog. https://doi.org/10.59704/96d8bd0247c07d9e
European Commission. (2025a, December 5). Commission fines X €120 million under the Digital Services Act [Press release]. https://ec.europa.eu/commission/presscorner/detail/en/ip_25_2934
European Commission. (2025b, October 10). Communication from the Commission – Guidelines on measures to ensure a high level of privacy, safety and security for minors online, pursuant to Article 28(4) of Regulation (EU) 2022/2065(C/2025/5519). Official Journal of the European Union. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:C_202505519
European Commission. (2025c, November 12). European Democracy Shield and EU Strategy for Civil Society pave the way for stronger and more resilient democracies [Press release]. https://enlargement.ec.europa.eu/news/european-democracy-shield-and-eu-strategy-civil-society-pave-way-stronger-and-more-resilient-2025-11-12_en
European Commission. (2026a, August 31). Commission designates ChatGPT, Reddit, Roblox under Digital Services Act[Press release]. https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1772
European Commission. (2026b). Supervision of the designated very large online platforms and search engines under DSA. Shaping Europe’s Digital Future. https://digital-strategy.ec.europa.eu/en/policies/list-designated-vlops-and-vloses
European Commission. (2026c, July 16). Commission accepts X’s action plan to comply with Digital Services Act [Press release]. https://digital-strategy.ec.europa.eu/en/news/commission-accepts-xs-action-plan-comply-digital-services-act
European Commission. (2026d, February 6). Commission preliminarily finds TikTok’s addictive design in breach of the Digital Services Act [Press release]. https://digital-strategy.ec.europa.eu/en/news/commission-preliminarily-finds-tiktoks-addictive-design-breach-digital-services-act
European Commission. (2026e, July 13). Europeans concerned about child safety online as new report publishes recommendations. https://commission.europa.eu/news-and-media/news/europeans-concerned-about-child-safety-online-new-report-publishes-recommendations-2026-07-13_en
European Commission. (2026f, July 24). Commission preliminary finds TikTok in breach of Digital Services Act for failing to ensure safe accounts for minors [Press release]. https://digital-strategy.ec.europa.eu/en/news/commission-preliminary-finds-tiktok-breach-digital-services-act-failing-ensure-safe-accounts-minors
European Commission. (2026g, March 26). Commission preliminarily finds PornHub, Stripchat, XNXX and XVideos in breach of the Digital Services Act for allowing minors to access their services [Press release]. https://ec.europa.eu/commission/presscorner/detail/en/ip_26_722
Federal Government [Germany]. (2026, February 13). Speech by the Federal Chancellor at the Munich Security Conference on 13 February 2026 in Munich. https://www.bundesregierung.de/breg-en/federal-government/speech-munich-security-conference-2407298
Goanta, C., & Iamnitchi, A. (2026, March 12). If at first you don’t succeed: Reflections on a rejected Art. 40 DSA data access request. DSA Observatory. https://dsa-observatory.eu/2026/03/12/if-at-first-you-dont-succeed-reflections-on-a-rejected-art-40-dsa-data-access-request/
Alexander von Humboldt Institute for Internet and Society. (2026a, March 18). Under pressure: The DSA as source of transatlantic tensions [Video]. YouTube. https://www.youtube.com/watch?v=lLgvyIUsTUc
Alexander von Humboldt Institute for Internet and Society. (2026b, August 24). Are the kids alright? The protection of minors online and social media bans [Learning call]. https://www.hiig.de/en/events/are-the-kids-alright-the-protection-of-minors-online-and-social-media-bans/
Husovec, M. (2024). The Digital Services Act’s red line: What the Commission can and cannot do about disinformation. Journal of Media Law, 16(1), 47–56. https://doi.org/10.1080/17577632.2024.2362483
Kettemann, M. C., & Schulz, W. (2026, July 7). Between accusations of censorship and platform power: What the Digital Services Act actually regulates. HIIG Digital Society Blog. https://doi.org/10.5281/zenodo.21259802
Leerssen, P. (2023, January 30). Counting the days: What to expect from risk assessments and audits under the DSA – and when? DSA Observatory. https://dsa-observatory.eu/2023/01/30/counting-the-days-what-to-expect-from-risk-assessments-and-audits-under-the-dsa-and-when/
Lievens, E., Shala, V., & Verdoodt, V. (2026, March 2). Just one more video…: Down the (legal) rabbit hole of TikTok’s addictive design. Verfassungsblog. https://doi.org/10.59704/fdfba886e92b0b19
Mariniello, M. (2025, September 30). It is time for an independent European Digital Authority. Bruegel. https://www.bruegel.org/first-glance/it-time-independent-european-digital-authority
Markeviciute, E. (2026, April 20). Can Europe keep its industrial champions in the AI era? EU Tech Loop. https://eutechloop.com/can-europe/
Messina, D. (2026). Digital platforms: A new form of non-state sovereignty. In R. Bocchini (Ed.), Digital platforms: From technical foundations to legal and economic implications (pp. 173–187). Springer. https://doi.org/10.1007/978-3-032-07982-4_12
Ollig, C. (2025). Report on the Academic Round Table, 30 April 2024, New York City: Freedom of online communication across transatlantic borders. GRUR International, 74(1), 57–60. https://doi.org/10.1093/grurint/ikae106
Orlando-Salling, J. (2025). The Digital Services Act in the European periphery: Critical perspectives on EU digital regulation. European Law Open, 3(4), 849–864. https://doi.org/10.1017/elo.2024.52
Pingen, A. (2026, April 24). Overview of the latest developments under the Digital Services Act: November 2025 – February 2026. eucrim. https://eucrim.eu/news/overview-of-the-latest-developments-under-the-digital-services-act-november-2025-february-2026/
Pothmann, D. (2026, August 5). Cards on the table: Making sense of the Digital Services Act. HIIG Digital Society Blog. https://www.hiig.de/en/making-sense-of-the-digital-services-act/
Rodríguez de las Heras Ballell, T. (2021). The background of the Digital Services Act: Looking towards a platform economy. ERA Forum, 22(1), 75–86. https://doi.org/10.1007/s12027-021-00654-w
Troitiño, D. R., & Mazur, V. (2026). Navigating the intersection of national and European digital regulations: Estonia’s implementation of the DSA and DMA. In F. Decarolis, B. Marchetti, & L. Torchia (Eds.), The EU digital regulation and its impact on member states (pp. 307–320). Springer. https://doi.org/10.1007/978-3-032-06490-5_12
Turillazzi, A., Taddeo, M., Floridi, L., & Casolari, F. (2023). The Digital Services Act: An analysis of its ethical, legal, and social implications. Law, Innovation and Technology, 15(1), 83–106. https://doi.org/10.1080/17579961.2023.2184136
Watolla, A. (2025, August 20). Annahmen über Desinformation: Was wir zu wissen glauben und was wir wirklich wissen. HIIG Digital Society Blog. https://doi.org/10.5281/zenodo.16911431
Weinzierl, Q. (2024). Dark Patterns und die innere Sphäre der Grundrechte: Grundrechtlicher Schutz vor dem Ausnutzen von Rationalitätsdefiziten (Internet und Gesellschaft, Vol. 36). Mohr Siebeck.
Wennberg, R. (2025, September 22). Does the EU’s Digital Services Act violate freedom of speech? CSIS. https://www.csis.org/blogs/europe-corner/does-eus-digital-services-act-violate-freedom-speech
This post represents the view of the author and does not necessarily represent the view of the institute itself. For more information about the topics of these articles and associated research projects, please contact info@hiig.de.

You will receive our latest blog articles once a month in a newsletter.
Discussion Dossiers
AI startups made in Germany — Specialisation instead of computing power
What role do AI startups play in Germany’s position in the global AI race? This article draws on ten interviews to offer insight into their business models.
Brave new world of work? Narratives on AI and the future of work
A comparison between German and US-American public discourse shows how different narratives on AI shape the future of work.
Democracy without borders? Global citizenship between platform power, AI and the crisis of knowledge
A look back and ahead at ten years of constitutional thinking across state borders.



