A Narrower Settlement Than It Looks
On 15 July 2026, the European Commission accepted a binding action plan from X to close out two of the three Digital Services Act (DSA) breaches it had found against the platform: an opaque, hard-to-search advertising repository, and barriers that kept qualified researchers from accessing public data. The commitments are specific and measurable — X must cut ad-repository response times from roughly 200 seconds to "the minimum time technically achievable," publish full ad content and destination URLs, open an API, and give eligible researchers free, timely access to public data without the contractual scraping bans it previously relied on to keep them out. An independent auditor will check X's work, with a report due within six months.
What the settlement does not touch is telling. The Commission's €120 million fine, issued 5 December 2025, covered three breaches: the ad repository, researcher access, and the paid "blue checkmark" that the Commission says misleads users about account authenticity and enables impersonation scams. Only the first two are resolved by this action plan. The verification-badge finding — arguably the one most directly about user deception rather than data plumbing — remains open, unremedied, and unmentioned in the July acceptance notice.
The Case for the Commission's Approach
Before arguing the other side, it's worth taking the DSA's transparency logic seriously. Ad repositories and researcher APIs are not abstract compliance boxes — they are the infrastructure that lets outside investigators, journalists, and academics verify a platform's own claims about influence operations, political advertising, and algorithmic amplification. A repository that takes 200 seconds to return a search, or a scraping ban buried in terms of service, functions as a de facto research embargo regardless of intent. TechPolicy.Press has argued that platforms have a track record of "transparency-washing" — technically complying while making the compliance functionally useless — and a 28-platform regime (the DSA's very-large-platform tier, now covering ChatGPT, Reddit, and Roblox alongside X, Meta, and Google) only works if the Commission is willing to specify remedies down to the second, as it did here.
Why the Split Decision Still Matters
But the structure of this settlement exposes a real weakness in DSA enforcement, not just in X's compliance. Splitting a single non-compliance finding into a fast-resolving technical track (repository speed, API access — engineering problems with engineering solutions) and a slow-moving substantive track (deceptive design aimed at users) lets a platform bank a public "case closed" narrative on the easier two-thirds while the harder finding — the one that actually alleges user deception rather than researcher inconvenience — sits unresolved indefinitely. If the Commission wants credibility for proportionate, evidence-based enforcement, it needs to explain why blue-checkmark remediation is on a different clock, not leave it unaddressed in the press release.
The political backdrop makes this worse, not better, for the Commission's case that this is ordinary regulatory business. Elon Musk called for the EU's abolition after the December fine, and Secretary of State Marco Rubio, Vice President JD Vance, and President Trump each framed it as an attack on American platforms rather than a transparency remedy. Political scientist Joris van Hoboken told TechPolicy.Press that the censorship framing "lack[s] persuasive force" precisely because the underlying findings concern misleading users and data access, not content moderation or speech restrictions — a distinction our editorial position shares. That makes it more important, not less, for Brussels to resolve every finding on a visible, consistent timeline. A partial settlement that leaves the most speech-adjacent charge open hands critics a talking point — "they fined X for censorship-adjacent reasons and then quietly let two-thirds of it go" — that a fully resolved case wouldn't.
The Proportionality Test That Actually Matters
The DSA's non-compliance regime can theoretically reach 6% of a platform's global annual turnover — a number designed to be credible against companies far larger than X. Used against genuinely measurable failures like a 200-second search lag or a contractual scraping ban, that threat produces the kind of specific, auditable commitments X just made, which is exactly what proportionate regulation should look like: painful enough to bite, precise enough to be complied with, and reviewable by an independent auditor rather than enforced by ministerial discretion. Used against something as amorphous as "deceptive design," the same tool risks becoming an open-ended lever with no clear compliance test — which is why the Commission should be pushing X toward a concrete, time-bound verification-badge remedy with the same specificity it just applied to ad repositories, rather than letting the finding linger as unfinished business. Enforcement that resolves the easy findings first and leaves the contested one open indefinitely does not build the credibility the DSA needs to survive its first real transatlantic stress test.