Digital Services Act platform policy proposal tracker
- Authority
- European Commission (EU)
- Rule type
- regulation
- Jurisdiction scope
- EU
- Source text
- Read primary rule text ↗
Track DSA obligations across legislative amendments, Commission implementation instruments, and enforcement decisions; the DSA text alone is not a complete compliance picture.
Scope and verification status
In this tracker, DSA means the EU Digital Services Act. It is platform regulation, not a rule of attorney conduct. The reason it belongs in a legal-AI and platform-policy workflow is narrower: platform obligations now affect how very large online platforms, very large online search engines, marketplaces, app-distribution channels, and embedded AI systems are supervised, procured, documented, and risk-assessed. The Commission’s DSA policy hub remains the starting point for the regulation itself, while the Commission’s VLOP/VLOSE supervision tracker is now a separate source that has to be checked record by record for active supervision and enforcement status.[1][2]
- Category treatment: Regulation & Ethics; slug: regulation-ethics.
- Non-advice banner: This is an editorial tracking record, not legal advice and not a substitute for jurisdiction-specific counsel review.
- Legal-background reviewer: Maya R. Chen, JD, editorial legal-background review only.
- Verification date: 3 Aug 2026. Each record below is current only as last verified on that date.
- Citation rule used here: dates, statuses, amounts, article references, and institutional conclusions are tied to the source listed in the record or paragraph where they appear.

The DSA text is no longer enough to answer “what applies now.” The Article 91(1) evaluation report, published on 17 Nov 2025 as COM(2025) 708, confirmed that the 45 million-user designation threshold remained fit for purpose and mapped the DSA’s interaction with 54 other EU legal acts.[3] That matters because the Commission is not only enforcing the original regulation; it is also using implementation instruments, adjacent legislative amendments, and individual decisions to clarify what compliance looks like in practice.
Digital Services Act platform policy proposals list: master tracker
The tracker is divided into three tracks because the legal effect is different. A legislative amendment can change the formal obligation map. A Commission implementation instrument can change what a platform has to operationalize even when the statutory wording stays still. An enforcement decision or proceeding may not amend the DSA, but it can still become the most practical statement of what the Commission expects from platforms under broad provisions.
Track 1 — legislative amendments and proposals
| Record | Date | Status as of 3 Aug 2026 | Affected DSA/platform obligation | Next milestone to re-check | Primary source | AI relevance |
|---|---|---|---|---|---|---|
| Digital Omnibus on AI / Digital Omnibus Regulation Proposal | Commission proposal package in Nov 2025; Parliament adoption reported 16 Jun 2026; Council adoption reported 29 Jun 2026; in force Jul 2026 [4][5][6] | In force, subject to implementation dates and grace periods | Changes the DSA-AI interface by extending AI Office supervision to AI systems constituting or embedded in DSA VLOPs/VLOSEs and to deployers within the same undertaking; also affects transparency-marking timing and new AI-related prohibitions [5] | 2 Dec 2026 grace-period and safeguards milestone for AI transparency/prohibition-related items [5] | Commission proposal library; Freshfields; CENTR [4][5][6] | High |
| Digital Omnibus on Data | Proposal context in late 2025; agreement expected H1 2027 [7][8] | Proposed / not a binding DSA amendment as of 3 Aug 2026 | DSA-adjacent data and digital-rule simplification context; should not be treated as changing platform DSA duties until adopted | H1 2027 agreement expectation | Skadden; Kliemt/Ius Laboris [7][8] | Indirect |
| Digital Fairness Act | Consultation window 17 Jul–24 Oct 2025; proposal expected Q4 2026 in the sources checked for this tracker [9][10] | Expected proposal; not binding | Potential future consumer-interface and deceptive-design obligations adjacent to DSA Article 25 platform design issues; no current DSA amendment to apply | Q4 2026 proposal check. Source-status note: timing references are not fully uniform across public trackers, so this page uses Q4 2026 as the supported planning assumption, not as enacted law. | Digital Fairness Act tracker; Taylor Wessing [9][10] | Medium, if AI-driven interfaces or personalization are within scope of the eventual proposal |
Track 2 — Commission implementation instruments and evaluation records
| Record | Date | Status as of 3 Aug 2026 | Affected DSA/platform obligation | Next milestone to re-check | Primary source | AI relevance |
|---|---|---|---|---|---|---|
| Article 40 researcher-data delegated act | In force 29 Oct 2025 [11] | In force | Researcher access to VLOP/VLOSE data under Article 40; turns a statutory access obligation into a more operational request, vetting, and access process | Operational implementation and any Commission updates to researcher-access procedure | eucrim overview, with Commission record to be re-checked before publication [11] | Medium, especially where requested data concerns recommender systems, ranking, search, advertising delivery, or AI-enabled moderation |
| Guidelines on protection of minors | Guidelines dated 14 Jul 2025; revision announced 10 Feb 2026 [11] | Guidance in place; revision pending | Platform duties concerning minors’ safety, privacy, security, and risk mitigation; operationally relevant to age-appropriate design, recommender exposure, and interface controls | Publication of the revised guidelines announced on 10 Feb 2026 | eucrim overview, with Commission record to be re-checked before publication [11] | Medium to high where AI ranking, profiling, recommender systems, or generative features affect minors’ exposure |
| Trusted-flagger guidance | Announced 10 Feb 2026 [11] | Announced / pending publication in the sources checked for this tracker | Notice-handling and prioritization workflows for trusted flaggers; relevant to platform escalation queues and evidence logs | Publication of the guidance | eucrim overview [11] | Low to medium; higher if AI triage tools rank or route trusted-flagger notices |
| Incidents and crisis protocol under the European Democracy Shield | Announced 12 Nov 2025 [11] | Announced / pending operational detail in the sources checked for this tracker | Crisis-response and incident-handling expectations for platform services; relevant to governance, escalation, and documentation during systemic-risk events | Commission protocol text and any platform-specific implementation instructions | eucrim overview [11] | Medium, particularly if generative AI or recommender amplification is implicated in crisis scenarios |
| Article 91(1) evaluation report | 17 Nov 2025; COM(2025) 708 [3] | Published evaluation report | Confirms the Commission’s view that the 45 million-user threshold remains fit for purpose and maps interaction with 54 other EU legal acts [3] | Use as baseline when checking future designation-threshold proposals or cross-regime conflicts | European Commission Article 91(1) evaluation news [3] | Medium; important for AI Act/DSA interface mapping but not itself an AI Act explainer |
Track 3 — enforcement decisions and proceedings functioning as rule-setting signals
| Record | Date | Status as of 3 Aug 2026 | Affected DSA/platform obligation | Next milestone to re-check | Primary source | AI relevance |
|---|---|---|---|---|---|---|
| X €120 million non-compliance decision | 5 Dec 2025 [12] | First Commission non-compliance decision under the DSA, with €120 million fine [12] | Articles 25(1), 39, and 40(12): deceptive design, advertising transparency/repository obligations, and data-access-related obligations as identified in the Commission record [12] | Remediation monitoring and connection to the later accepted action plan | Commission news release [12] | High for deceptive-design analysis where AI-driven interface design, recommender prompts, or product affordances affect user choice |
| X action plan accepted | 15 Jul 2026 [2] | Action plan accepted; not the same thing as saying every underlying issue is finally closed | Remediation path following Commission supervision of X under the DSA | Commission confirmation of implementation, closure, or further measures | Commission VLOP/VLOSE supervision tracker [2] | Medium to high, depending on which remediation items involve automated systems, ranking, or transparency tooling |
| Temu €200 million decision | 28 May 2026 [2] | Commission-recorded fine of €200 million [2] | Risk-assessment failures concerning illegal, unsafe, or counterfeit products, as reflected in the Commission supervision record [2] | Any appeal, compliance plan, or follow-on supervisory step recorded by the Commission | Commission VLOP/VLOSE supervision tracker [2] | Medium; marketplace risk systems may rely on automated detection, ranking, seller scoring, or recommendation tools |
| AliExpress €550 million decision | 20 Jul 2026 [2] | Commission-recorded fine of €550 million [2] | Risk-assessment failures concerning illegal, unsafe, or counterfeit products, as reflected in the Commission supervision record [2] | Any appeal, compliance plan, or follow-on supervisory step recorded by the Commission | Commission VLOP/VLOSE supervision tracker [2] | Medium; similar marketplace-AI relevance where automated product, seller, or recommender systems form part of the risk-control stack |
| Grok formal proceedings | 26 Jan 2026 [13] | Proceedings opened; no final non-compliance decision identified in the records checked for this tracker as of 3 Aug 2026 | Systemic-risk supervision where an AI system is embedded in or connected to a platform environment; the record should be read as a proceeding, not as a proven violation | Commission outcome: closure, commitments, preliminary findings, or non-compliance decision | Commission press release IP/26/203 [13] | High; this is the clearest DSA enforcement bridge to generative AI in the current tracker |
| TikTok preliminary findings | 24 Jul 2026 [2] | Preliminary findings; not a final decision | Platform-specific obligations as stated in the Commission supervision record; do not generalize without checking the underlying record | Response period, commitments, closure, or final decision | Commission VLOP/VLOSE supervision tracker [2] | Medium; depends on whether the underlying finding concerns recommender, advertising, minors, transparency, or risk systems |
| Meta, porn platforms, Shein, Snapchat and other supervision pipeline items | Proceeding dates vary by record on the Commission tracker [2] | Open or pending items as recorded by the Commission; status must be checked individually | Record-specific platform obligations; this row is a pointer to the live pipeline, not a single consolidated allegation | Next Commission step for each listed service: preliminary findings, commitments, closure, or decision | Commission VLOP/VLOSE supervision tracker [2] | Varies; higher where recommender systems, advertising delivery, minors’ exposure, or AI-mediated moderation are central to the record |
The three recorded fines in this tracker add to €870 million if one simply adds the Commission-recorded amounts for X, Temu, and AliExpress: €120 million + €200 million + €550 million.[12][2] That is a derived arithmetic note, not a Commission-stated aggregate headline. It is useful for scale, but less useful than the provision-by-provision and obligation-by-obligation mapping.
Why the three-track structure changes the compliance read
A platform counsel checking only the DSA regulation text will see the stable statutory architecture. That does not show whether a delegated act has converted an access right into a live operational process, whether a guideline revision is pending, whether the Commission has treated a design pattern as non-compliant, or whether an AI system embedded in a VLOP/VLOSE is now being supervised through an amended interface between the DSA and AI rules.
The legislative track is the formal-obligation track. The Digital Omnibus on AI is the record in this set that most directly changes the DSA-AI interface. The Digital Omnibus on Data and the expected Digital Fairness Act are weaker, for DSA purposes, because their relevant items are proposed or expected rather than binding. They still belong in the tracker because a procurement or product briefing written in Q3 2026 needs to distinguish “currently binding” from “expected to become reviewable soon.”
The implementation track is where a great deal of false certainty enters internal summaries. An Article 40 researcher-data obligation is not operationally complete until the delegated act and access process are checked. A minors-protection paragraph in a policy memo should not be treated as stable if a revision has been announced. A trusted-flagger workflow may be legally described in the regulation, but the queue design, evidence retention, and escalation model can be affected by Commission guidance once published.
The enforcement track is not legislation, but it is not merely news. The X decision gives concrete Commission treatment to Articles 25(1), 39, and 40(12).[12] The Temu and AliExpress records show the Commission using risk-assessment obligations in marketplace product-safety and counterfeit-risk settings.[2] The Grok proceeding shows why embedded AI features cannot be kept in a separate “AI Act only” folder when the distribution environment is a DSA-supervised platform.[13]

The AI-relevance layer
The AI flag in the tracker is not a claim that every DSA item is an AI Act item. It marks the records that a platform-dependent AI product team, legal-AI procurement lead, or counsel reviewing embedded systems should not skip. The highest-priority records are the Digital Omnibus on AI, Grok proceedings, X deceptive-design decision, and marketplace risk-assessment decisions where automated detection, recommender systems, ranking, seller scoring, or advertising systems may be part of the compliance evidence.
The Digital Omnibus on AI is the formal bridge. In the sources used here, it extends AI Office supervision to AI systems constituting or embedded in DSA VLOPs/VLOSEs and to deployers within the same undertaking.[5] It also affects timing for Article 50 transparency marking, with applicability on 2 Aug 2026 and a grace period running to 2 Dec 2026, and it includes new AI-related prohibitions such as CSAM and nudifier-related prohibitions with safeguards due by 2 Dec 2026.[5] Those dates are not background color; they are calendar entries.

Grok should be handled with the same discipline. The Commission opened formal proceedings on 26 Jan 2026.[13] That is a live supervisory record, not a final finding. It is still unusually important for legal-AI readers because it places a generative AI system inside the DSA supervisory frame rather than treating the AI layer as a separate product-compliance silo.
The X decision is the deceptive-design anchor. It should not be inflated into a universal rule for every AI interface. It does, however, make Article 25(1) a live procurement and product-review issue where AI systems are used to shape choices, rank options, prompt users, personalize paths, or generate interface text. The practical question for an internal record is not “does this use AI?” but “which platform design decision would we have to evidence if the Commission asked how the user choice was presented?”
Marketplace fines belong in the AI layer for a different reason. The Commission-recorded Temu and AliExpress decisions concern risk-assessment failures around illegal, unsafe, or counterfeit products.[2] The public tracker does not, on its own, prove that a particular automated system caused those failures. It does justify asking whether automated product review, seller scoring, ranking, recommendation, or ad-delivery systems are part of the evidence file for the platform’s DSA risk assessment.
Milestones to re-check before relying on this page
| Milestone | Why it matters | Current status in this tracker | Re-check source |
|---|---|---|---|
| 2 Dec 2026 Digital Omnibus on AI grace-period and safeguards milestone | May affect AI transparency marking and safeguards around new AI-related prohibitions | Future implementation date after Article 50 marking applicability on 2 Aug 2026 [5] | Freshfields and Commission proposal/update pages [4][5] |
| Q4 2026 Digital Fairness Act proposal expectation | Potentially relevant to deceptive design and consumer-interface obligations adjacent to DSA platform design duties | Expected proposal; not binding [9][10] | Digital Fairness Act tracker and Commission planning materials when published [9][10] |
| H1 2027 Digital Omnibus on Data agreement expectation | May affect the surrounding digital-rule environment but should not be treated as a current DSA amendment | Expected agreement window in secondary verification sources [7][8] | Skadden, Kliemt/Ius Laboris, and EU legislative records when available [7][8] |
| Revised minors-protection guidelines | Could affect platform safety, privacy, security, recommender, and design controls for minors | Revision announced 10 Feb 2026 [11] | Commission publication page and eucrim update trail [11] |
| Trusted-flagger guidance | Could affect notice-routing, prioritization, escalation, and evidence-retention workflows | Announced 10 Feb 2026 [11] | Commission publication page and eucrim update trail [11] |
| Incidents and crisis protocol | Could affect crisis escalation and systemic-risk documentation | Announced 12 Nov 2025 [11] | Commission and European Democracy Shield materials; eucrim update trail [11] |
| X remediation after accepted action plan | Determines whether the non-compliance record remains open, is closed, or generates further measures | Action plan accepted 15 Jul 2026 [2] | Commission VLOP/VLOSE supervision tracker [2] |
| Grok proceeding outcome | May become the clearest Commission statement on DSA treatment of generative AI embedded in a platform environment | Proceedings opened 26 Jan 2026; no final decision identified in the records checked for this tracker [13] | Commission press release and VLOP/VLOSE supervision tracker [13][2] |
| TikTok, Meta, porn platforms, Shein, Snapchat pipeline updates | Preliminary findings and open proceedings can mature into commitments, closures, or decisions that clarify platform obligations | Status varies by service; check individually [2] | Commission VLOP/VLOSE supervision tracker [2] |
One source-management note is worth keeping visible: several enforcement amounts, dates, and proceeding statuses should be re-verified against the Commission’s linked record immediately before publication or client use, especially where a supervision tracker entry points to a press release that was not separately crawled during verification. The narrower record is the safer record.
Next re-verification date for this page: 3 Sep 2026, or earlier if the Commission publishes a Digital Fairness Act proposal, revised minors guidance, trusted-flagger guidance, crisis-protocol text, or a new decision in the Grok, X, TikTok, Meta, Shein, Snapchat, or marketplace supervision files.
Cross-link slots for future records: Regulation & Ethics — EU AI Act implementation dates; Regulation & Ethics — Digital Fairness Act proposal tracker; Verification Workflows — EU primary-source status checks for platform obligations.
As of Q3 2026, DSA compliance review for platforms and platform-dependent AI tools requires record-by-record tracking across amendments, implementation instruments, and enforcement decisions. A clean single-track summary is usually the document most likely to be obsolete.
References
- Digital Services Act — European Commission, 18 May 2026.
- List of designated VLOPs and VLOSEs — European Commission.
- Commission evaluates Digital Services Act's interaction with other EU laws and its designation threshold — European Commission, 17 Nov 2025.
- Digital Omnibus Regulation Proposal — European Commission.
- EU AI Act unpacked #34: the final Digital Omnibus on AI – key amendments to the AI Act — Freshfields.
- EU Policy Update - April 2026 — CENTR, April 2026.
- Commission Proposes Significant Changes to EU Digital Rules — Skadden, Nov 2025.
- The EU’s Digital Omnibus – everything you need to know — Kliemt / Ius Laboris, 2 Jan 2026.
- Digital Fairness Act — DigitalFairnessAct.com.
- Enhancement and enforcement — Taylor Wessing, 2025.
- Overview of the Latest Developments under the Digital Services Act (November 2025-February 2026) — eucrim.
- Commission fines X €120 million under the Digital Services Act — European Commission, 5 Dec 2025.
- Commission Grok press release IP/26/203 — European Commission, 26 Jan 2026.
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →