Regulation

The €550M AliExpress Fine: What the Decision Actually Tells Compliance Teams

On 20 July 2026, the European Commission fined AliExpress €550 million for breaching the Digital Services Act. It's the largest DSA fine issued to date, ahead of Temu's €200 million (May 2026) and X's €120 million (December 2025).

Most coverage will stop at the number. We think the more useful story is in the findings behind it, and what they signal to every other platform operating under the DSA.

What happened

The case has been building for over two years.

The European Commission opened formal proceedings against AliExpress on 14 March 2024, examining several areas of potential non-compliance: risk management and mitigation, content moderation and internal complaint handling, advertising and recommender system transparency, trader traceability, and researcher data access.

On 18 June 2025, the Commission resolved part of the case. AliExpress offered a set of binding commitments covering several of the articles under investigation:

  • Article 20 — internal complaint-handling system
  • Article 26 — advertising transparency
  • Article 27 — recommender system transparency
  • Article 30 — traceability of traders
  • Article 40 — researcher data access obligations

The Commission accepted these commitments and made them legally binding, with an independent Monitoring Trustee overseeing implementation over a five-year period.

But two issues weren't resolved by commitment. The Commission issued a preliminary finding of non-compliance on AliExpress's obligation to assess and mitigate the risk of illegal products being sold on its platform.

Thirteen months later, that preliminary finding became final. The Commission's non-compliance decision, issued 20 July 2026, concluded that AliExpress breached:

  • Article 34 DSA (Risk assessment): AliExpress failed to properly identify and assess the risks of illegal, unsafe, and counterfeit products being distributed through its recommender and advertising systems, and did not adequately assess whether it had sufficient staff to review those risks.
  • Article 35 DSA (Mitigation of risks): The measures AliExpress had in place, including its "brand authorisation" system meant to catch counterfeit sellers, were found ineffective, understaffed, and easy to circumvent. The Commission also found AliExpress overestimated how effective its detection systems actually were, and relied on a single quantitative indicator to measure whether its mitigation efforts were working.

AliExpress has until 20 October 2026 to submit an action plan addressing the breach. The Commission has said it will continue engaging with the platform, and non-compliance with the decision itself could trigger periodic penalty payments on top of the fine already issued.

Three things worth reading between the lines

The findings above are the official record. But for compliance and Trust & Safety teams navigating the DSA, three details in this decision matter more than the headline number.

1. Duration is now part of the compliance story, not just the substance.

The Commission didn't just say AliExpress had a risk. It said AliExpress knew about the risk for over a year and didn't fix it. That's a different kind of finding. It suggests regulators are watching trajectory, not just a snapshot. A platform that can show continuous, documented progress against a known risk is in a fundamentally different position than one that waits for the next audit cycle to demonstrate it did something. Compliance can't be a once-a-year event anymore. It has to be visible and ongoing.

2. The staffing question hasn't gone away, even in an AI-heavy compliance era.

The Commission's finding that AliExpress "did not properly evaluate whether it had enough people to review the risks" and "overestimated the effectiveness of its system" is notable. Across the industry, Trust & Safety headcount has been under pressure for several years, often justified by automation picking up the slack. This decision is a reminder that regulators expect platforms to know, and be able to show, that their human review capacity actually matches their risk exposure. Automation is part of the answer. It isn't the whole answer, and regulators are starting to say so directly.

3. A single metric doesn't make a risk assessment.

Perhaps the most interesting detail: the Commission found AliExpress relied on one quantitative indicator to measure the effectiveness of its risk mitigation. This points to a challenge the T&S field has wrestled with for years: what does "safe" actually look like in numbers? A removal count tells you volume. It doesn't tell you whether the products that got through caused harm, or whether your mitigation is actually reducing risk over time. Regulators are now signaling that a defensible risk assessment needs metrics that reflect effort and outcome, not just activity.

Why this matters beyond AliExpress

This decision reinforces something we've built Codeliance around: DSA compliance isn't a document you file once a year. It's an operational, ongoing obligation that has to be demonstrable at any point in time, across staffing, systems, and metrics.

Platforms that can show continuous evidence of risk assessment and mitigation, not just a report from twelve months ago, are in a stronger position with regulators. That's the gap Codeliance exists to close: turning DSA obligations into structured, testable requirements your team can validate on an ongoing basis, not just when the Commission asks.

If your team is thinking through how your compliance posture would hold up to this kind of scrutiny, we'd be glad to talk.

Ready to Simplify Compliance?

See how Codeliance translates regulation into action for your platform.

Book a Demo