X: DSA enforcement

Every formal proceeding the European Commission has opened against X under the Digital Services Act, with a step-by-step timeline of each case and any fines issued.

Proceedings
2
Platforms
1
Fines issued
1
Total fined
€120M
XPartially resolvedFined €120M

Illegal content, transparency & deceptive design

Notice-and-action, systemic-risk management, the "Blue check" deceptive design, the ad repository, and researcher data access. First-ever DSA formal proceedings.

  • Art. 16
  • Art. 25(1)
  • Art. 34
  • Art. 35
  • Art. 39
  • Art. 40(12)
  1. Request for information

    RFI on the spread of illegal content and disinformation around the Hamas attacks on Israel, and on the crisis-response protocol. Source ↗

  2. Formal proceedings opened

    The first-ever DSA formal proceedings — covering notice-and-action, risk management, deceptive design, ad transparency and data access. Source ↗

  3. Preliminary findings

    First-ever DSA preliminary findings: the Blue-checkmark design deceives users (Art. 25), the ad repository is not searchable/reliable (Art. 39) and researcher data access is obstructed (Art. 40). Source ↗

  4. Additional investigatory measures

    RFI on X’s recommender systems plus a retention order preserving documents on algorithm changes, and a request for access to X’s commercial API. Source ↗

  5. €120M fine

    First DSA non-compliance decision and fine, for the Art. 25(1), 39 and 40(12) breaches. X given 60/90 working days to remedy; further non-compliance can trigger periodic penalty payments. Source ↗

  6. X appeals to the EU General Court

    X challenged the €120M decision (X v Commission) — the first court challenge to a DSA fine. The 90-working-day remedy deadline for the ad repository and data access passed without a public outcome. Source ↗

  7. Commission accepts X’s action plan

    The Commission accepted X’s action plan to remedy the Art. 39 ad-repository and Art. 40(12) data-access breaches: X commits to add API access and more ad data to the repository and cut its response times, to give eligible researchers data free of charge with a streamlined application process, and to stop contractually barring the scraping of public data — with six months to implement and an independent audit to follow. The Board for Digital Services called the plan only “partially adequate” and the audit measures “insufficient to address the infringements.” Source ↗

First DSA non-compliance decision. Confirmed breaches of Art. 25(1) (Blue checkmark), Art. 39 (ad repository) and Art. 40(12) (researcher data access). The illegal-content and information-manipulation (Community Notes) strands remain open.

XOpen

Grok & recommender systems

A new investigation into risks from deploying the Grok AI into X (incl. manipulated sexual imagery / possible CSAM, gender-based violence) and an extension of the 2023 case to X’s recommender systems.

  • Art. 34
  • Art. 35
  • Art. 42(2)
  1. Request for information (Grok)

    RFI on Grok, including the antisemitic content generated by @grok in mid-2025. Source ↗

  2. New proceeding opened + 2023 case extended

    A new investigation into Grok’s deployment risks, and an extension of the December 2023 proceeding to X’s recommender systems (incl. the planned switch to a Grok-based recommender). Source ↗

Source: European Commission press releases (DSA enforcement). Preliminary findings are not a final decision. Last reviewed 8 July 2026.

Social Media Transparency