A narrow remedy, a broad precedent
On July 16, 2026, the European Commission accepted an action plan from X to resolve two of the three violations behind its €120 million Digital Services Act fine — the first non-compliance decision the Commission has issued under the law. X now has six months to implement the plan under what the Commission calls close monitoring, with an independent external audit required to verify the changes before the case can close.
The underlying fine, issued December 5, 2025, covered three findings: a "deceptive" blue-checkmark verification system, an opaque advertising repository, and researcher data-access barriers. The action plan accepted this month addresses only the latter two — the checkmark question remains open. X committed to faster ad-repository search, additional API-accessible ad data, and a streamlined, free researcher-access process that drops contractual bans on public-data scraping for qualifying applicants.
Steelmanning the case for enforcement
The strongest argument for this action isn't about speech at all — it's about measurable disclosure failures. According to reporting drawing on the Commission's case file, only 58% of X's actual advertisements appeared in its public ad repository, and searches averaged over three minutes each — a design that functions as an access barrier regardless of intent. On researcher access, 95.8% of data-access applications were rejected as of May 2024, with some applicants turned down solely for being outside the EU. These are the kinds of concrete, auditable facts that transparency law is supposed to catch: not a judgment about what content should exist, but whether a platform is giving outside researchers and regulators the tools to check its work. Independent researchers studying election interference, scams, or platform manipulation have a legitimate interest in ad and API data that a company controls unilaterally — and self-policing by platforms has a poor track record when the incentive is to obscure inconvenient patterns.
Where the concern is real
The US political reaction has been sharp. House Judiciary Republicans, in a February 2026 report titled "The Foreign Censorship Threat, Part II," argued the Commission applied DSA data-access rules extraterritorially by penalizing X for limiting researcher access to EU-only applicants while withholding data tied to American content — reading the case as a pretext for pressuring a US platform over content decisions. The Trump administration escalated further: Secretary of State Marco Rubio imposed visa bans on five Europeans tied to content-moderation policy in December 2025, and administration officials have floated a Section 301 trade investigation into the DSA itself.
Tech Policy Press's own analysis pushes back on the censorship framing directly, noting the Commission's enforcement here is "content-agnostic": none of the three findings required X to remove, demote, or label any post, account, or viewpoint. The remedies are procedural — search functionality, API fields, application processing times. That distinction matters, and it's the reason this case reads differently than, say, a takedown order or an algorithmic-amplification mandate. A rule requiring a platform to disclose who is paying for an ad, or to let vetted academics query public posts without a scraping ban, is closer to a securities-disclosure regime than a speech restriction.
The proportionate-regulation case
Our position is that the underlying violations here — ad-repository omissions, researcher-access barriers — are legitimate targets for transparency regulation, and the Commission's remedy is appropriately narrow: fix the specific gaps, verify with an audit, done. That's a materially better model than open-ended content mandates. Where we'd push back is on what enhanced supervision becomes as a tool. A six-month audit cycle enforced by a foreign regulator, with compliance judged by an EU-selected auditor against EU-drafted criteria, is a governance structure that could just as easily be pointed at genuinely speech-adjacent obligations in a future case — and the DSA's own risk-assessment provisions (Article 34) reach well beyond ad transparency into content-recommendation systems. The House Judiciary Committee isn't wrong that extraterritorial researcher-access mandates create real friction for a US company operating under US law; it's wrong to extend that friction into a claim that this specific fine was about censoring speech, when the Commission's own findings are about search latency and application rejection rates.
The test for whether DSA enforcement stays proportionate won't be this case — it will be whether the next one, under the same enhanced-supervision machinery, stays this narrow.