US platform transparency DSA reporting

The EU's X Settlement Shows DSA Transparency Enforcement Can Be Narrow — But Its Audit Regime Sets a Precedent Worth Watching

Brussels accepted X's plan to fix ad-repository and researcher-access failures, but the six-month audit regime is a model that could reach further than this case.

X's DSA Compliance Case, By the Numbers People of Internet Research · US €120M Original DSA fine First-ever DSA non-compliance fine… 6 months Enhanced supervision period Deadline for X to implement its ac… ~58% Ads actually in repository Share of X's real ads the Commissi… ~96% Researcher applications rejected Rejection rate for researcher data… peopleofinternet.com
X's DSA Compliance Case, By the Number… People of Internet Research · US €120M Original DSA fine 6 months Enhanced supervision peri… ~58% Ads actually in repository ~96% Researcher applications rej… peopleofinternet.com

Key Takeaways

A narrow remedy, a broad precedent

On July 16, 2026, the European Commission accepted an action plan from X to resolve two of the three violations behind its €120 million Digital Services Act fine — the first non-compliance decision the Commission has issued under the law. X now has six months to implement the plan under what the Commission calls close monitoring, with an independent external audit required to verify the changes before the case can close.

The underlying fine, issued December 5, 2025, covered three findings: a "deceptive" blue-checkmark verification system, an opaque advertising repository, and researcher data-access barriers. The action plan accepted this month addresses only the latter two — the checkmark question remains open. X committed to faster ad-repository search, additional API-accessible ad data, and a streamlined, free researcher-access process that drops contractual bans on public-data scraping for qualifying applicants.

Steelmanning the case for enforcement

The strongest argument for this action isn't about speech at all — it's about measurable disclosure failures. According to reporting drawing on the Commission's case file, only 58% of X's actual advertisements appeared in its public ad repository, and searches averaged over three minutes each — a design that functions as an access barrier regardless of intent. On researcher access, 95.8% of data-access applications were rejected as of May 2024, with some applicants turned down solely for being outside the EU. These are the kinds of concrete, auditable facts that transparency law is supposed to catch: not a judgment about what content should exist, but whether a platform is giving outside researchers and regulators the tools to check its work. Independent researchers studying election interference, scams, or platform manipulation have a legitimate interest in ad and API data that a company controls unilaterally — and self-policing by platforms has a poor track record when the incentive is to obscure inconvenient patterns.

Where the concern is real

The US political reaction has been sharp. House Judiciary Republicans, in a February 2026 report titled "The Foreign Censorship Threat, Part II," argued the Commission applied DSA data-access rules extraterritorially by penalizing X for limiting researcher access to EU-only applicants while withholding data tied to American content — reading the case as a pretext for pressuring a US platform over content decisions. The Trump administration escalated further: Secretary of State Marco Rubio imposed visa bans on five Europeans tied to content-moderation policy in December 2025, and administration officials have floated a Section 301 trade investigation into the DSA itself.

Tech Policy Press's own analysis pushes back on the censorship framing directly, noting the Commission's enforcement here is "content-agnostic": none of the three findings required X to remove, demote, or label any post, account, or viewpoint. The remedies are procedural — search functionality, API fields, application processing times. That distinction matters, and it's the reason this case reads differently than, say, a takedown order or an algorithmic-amplification mandate. A rule requiring a platform to disclose who is paying for an ad, or to let vetted academics query public posts without a scraping ban, is closer to a securities-disclosure regime than a speech restriction.

The proportionate-regulation case

Our position is that the underlying violations here — ad-repository omissions, researcher-access barriers — are legitimate targets for transparency regulation, and the Commission's remedy is appropriately narrow: fix the specific gaps, verify with an audit, done. That's a materially better model than open-ended content mandates. Where we'd push back is on what enhanced supervision becomes as a tool. A six-month audit cycle enforced by a foreign regulator, with compliance judged by an EU-selected auditor against EU-drafted criteria, is a governance structure that could just as easily be pointed at genuinely speech-adjacent obligations in a future case — and the DSA's own risk-assessment provisions (Article 34) reach well beyond ad transparency into content-recommendation systems. The House Judiciary Committee isn't wrong that extraterritorial researcher-access mandates create real friction for a US company operating under US law; it's wrong to extend that friction into a claim that this specific fine was about censoring speech, when the Commission's own findings are about search latency and application rejection rates.

The test for whether DSA enforcement stays proportionate won't be this case — it will be whether the next one, under the same enhanced-supervision machinery, stays this narrow.

Sources & Citations

  1. EC: Commission accepts X's action plan
  2. EC: Commission fines X €120 million under the DSA
  3. Tech Policy Press: What the EU's X Decision Reveals
  4. Tech Policy Press: How House Judiciary GOP Misread the Decision
  5. Lawfare: Trump Administration Targets EU Content Moderation Laws