<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <title>Codeliance Blog</title>
  <subtitle>Translating online safety regulation into engineering requirements.</subtitle>
  <link href="https://codeliance.com/blog/feed.xml" rel="self" />
  <link href="https://codeliance.com/" />
  <updated>2026-07-30T00:00:00Z</updated>
  <id>https://codeliance.com/</id>
  <author>
    <name>Codeliance</name>
  </author>
  <entry>
    <title>Compliance Doesn&#39;t Start With a Checklist. It Starts With a Question</title>
    <link href="https://codeliance.com/blog/compliance-starts-with-a-question/" />
    <updated>2026-07-30T00:00:00Z</updated>
    <id>https://codeliance.com/blog/compliance-starts-with-a-question/</id>
    <content type="html">&lt;h2&gt;The wrong question&lt;/h2&gt;
&lt;p&gt;Most compliance conversations start the same way: &amp;quot;Are we DSA compliant?&amp;quot;&lt;/p&gt;
&lt;p&gt;It&#39;s the wrong question, and not because it&#39;s too hard to answer. It&#39;s because it assumes every platform is answering the same exam. They&#39;re not. The DSA doesn&#39;t hand every online service one list of obligations. It hands different services different lists, and which list you get depends on what kind of service you are and how big you&#39;ve grown.&lt;/p&gt;
&lt;p&gt;The question that actually needs answering first is narrower: which obligations even apply to us? Everything downstream, policies, engineering work, evidence, reporting, depends on getting that answer right before you start ticking boxes.&lt;/p&gt;
&lt;h2&gt;How the DSA does it&lt;/h2&gt;
&lt;p&gt;The DSA builds its obligations on a ladder. Mere conduits (pure network access) sit at the bottom. Hosting services sit above them. Online platforms sit above that. Very Large Online Platforms and Search Engines, VLOPs and VLOSEs, sit at the top, triggered once a service crosses 45 million average monthly users in the EU.&lt;/p&gt;
&lt;p&gt;Each rung adds obligations on top of the one below it. Nothing is replaced, it&#39;s additive. A handful of obligations apply regardless of tier, most notably the exemption for micro and small enterprises. That exemption drops away the moment a small platform is designated a VLOP. Size doesn&#39;t buy you out of the rules that scale with reach.&lt;/p&gt;
&lt;p&gt;We pulled the real numbers from our live obligation set rather than quoting a fixed figure. The honest answer changes as the regulation gets interpreted and as new enforcement guidance lands. Right now, a basic intermediary service faces a fraction of the obligations a full online platform does. A designated VLOP with advertising, a recommender system, and a marketplace faces close to the full set. Add the recommender system alone and the obligation count jumps again. Article 27&#39;s transparency requirements only switch on for services that actually rank and recommend content. Same platform, one feature flag, a materially different compliance surface.&lt;/p&gt;
&lt;p&gt;That&#39;s the part people miss when they picture the DSA as one checklist. It&#39;s four or five checklists, and which one lands on your desk depends on answers you may not have formally worked out yet.&lt;/p&gt;
&lt;h2&gt;How the OSA does it, differently&lt;/h2&gt;
&lt;p&gt;The UK&#39;s Online Safety Act draws its lines in a different place, with different thresholds, but the same underlying logic. Ofcom&#39;s categorisation register sorts services into three tiers. Category 1 covers large user-to-user services with a recommender system: over 34 million UK users on their own, or over 7 million UK users if the service also lets users share content onward. Category 2A covers search services with more than 7 million UK users. Category 2B covers other qualifying user-to-user services that fall below the Category 1 bar.&lt;/p&gt;
&lt;p&gt;Ofcom&#39;s own working estimate, going in, was that somewhere between 12 and 16 services would land in Category 1. The register that actually &lt;a href=&quot;https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/register-of-categorised-services-and-list-emerging-category-1-services&quot;&gt;published&lt;/a&gt; on 10 July 2026 named 11, alongside a separate &amp;quot;emerging services&amp;quot; list for platforms close enough to the line that Ofcom is watching them without formally categorising them yet.&lt;/p&gt;
&lt;p&gt;Different statute, different regulator, different thresholds entirely, but the same shape: size and functionality decide which obligations apply, and the line isn&#39;t always where the first estimate said it would be.&lt;/p&gt;
&lt;h2&gt;The pattern&lt;/h2&gt;
&lt;p&gt;Strip away the article numbers and the acronyms, and the DSA and the OSA are doing structurally the same thing. Neither is a flat list you compare yourself against. Both are decision logic: is this platform hosting, or an online platform, or something bigger? Does it recommend content? Does it let users share what they see? How many people actually use it, and where?&lt;/p&gt;
&lt;p&gt;Answer those questions and the applicable obligation set falls out the other end. Get one of those inputs wrong, an outdated user count, a feature you shipped last quarter that nobody flagged, and the list you&#39;re working from is wrong too. You end up either missing obligations you&#39;re now exposed on, or carrying obligations that never applied to you in the first place.&lt;/p&gt;
&lt;p&gt;This is what we mean by categorisation-aware compliance: treating classification as a live input to the compliance process, not a one-time form filled in at onboarding and never revisited.&lt;/p&gt;
&lt;h2&gt;Categorisation isn&#39;t a life sentence&lt;/h2&gt;
&lt;p&gt;Worth remembering: crossing a threshold isn&#39;t permanent, and it isn&#39;t always final in the direction you&#39;d expect. Wikipedia spent over a year in the UK courts arguing it shouldn&#39;t be swept into the most demanding tier. Its case rested on a simple point: Wikipedia looks nothing like the platforms the rule was written for. It lost that specific argument, and ended up off the list anyway, watched but not categorised.&lt;/p&gt;
&lt;p&gt;That&#39;s worth remembering next time a threshold looks like a wall instead of a door. Categorisation gets contested, and it gets revisited. A platform that grows into VLOP territory this year isn&#39;t stuck there forever if its user numbers move. A platform that adds a recommender system doesn&#39;t need to wait for its next annual review to find out what that switched on.&lt;/p&gt;
&lt;h2&gt;Why this has to be a live system, not a form&lt;/h2&gt;
&lt;p&gt;This is the part of the product we spend significant engineering effort on, and it&#39;s the part that&#39;s easiest to underrate. We don&#39;t ask a platform to self-report its tier once and generate a static obligation list from that answer. Every obligation in our system carries its own applicability logic. It knows which service tiers it applies to, which features it requires, whether the SME exemption covers it, whether it only switches on above a VLOP threshold.&lt;/p&gt;
&lt;p&gt;We built it this way because thresholds move, features ship, and regulators publish new registers on their own schedule, not yours. Compliance is not a rules and features exercise that happens once and is then filed away and forgotten. It&#39;s a continuously moving target (in the technical sense, not the cynical one). Treat categorisation as an input you check once, and you&#39;re not doing DSA or OSA compliance. You&#39;re doing compliance for the platform you used to be.&lt;/p&gt;
&lt;p&gt;If you&#39;re working out where your own platform sits on either ladder, we&#39;re happy to walk through it.&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>The €550M AliExpress Fine: What the Decision Actually Tells Compliance Teams</title>
    <link href="https://codeliance.com/blog/aliexpress-dsa-fine/" />
    <updated>2026-07-27T00:00:00Z</updated>
    <id>https://codeliance.com/blog/aliexpress-dsa-fine/</id>
    <content type="html">&lt;p&gt;On 20 July 2026, the European Commission fined AliExpress €550 million for breaching the Digital Services Act. It&#39;s the largest DSA fine issued to date, ahead of Temu&#39;s €200 million (May 2026) and X&#39;s €120 million (December 2025).&lt;/p&gt;
&lt;p&gt;Most coverage will stop at the number. We think the more useful story is in the findings behind it, and what they signal to every other platform operating under the DSA.&lt;/p&gt;
&lt;h2&gt;What happened&lt;/h2&gt;
&lt;p&gt;The case has been building for over two years.&lt;/p&gt;
&lt;p&gt;The European Commission opened formal proceedings against AliExpress on &lt;strong&gt;14 March 2024&lt;/strong&gt;, examining several areas of potential non-compliance: risk management and mitigation, content moderation and internal complaint handling, advertising and recommender system transparency, trader traceability, and researcher data access.&lt;/p&gt;
&lt;p&gt;On &lt;strong&gt;18 June 2025&lt;/strong&gt;, the Commission resolved part of the case. AliExpress offered a set of binding commitments covering several of the articles under investigation:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Article 20&lt;/strong&gt; — internal complaint-handling system&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Article 26&lt;/strong&gt; — advertising transparency&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Article 27&lt;/strong&gt; — recommender system transparency&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Article 30&lt;/strong&gt; — traceability of traders&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Article 40&lt;/strong&gt; — researcher data access obligations&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The Commission accepted these commitments and made them legally binding, with an independent Monitoring Trustee overseeing implementation over a five-year period.&lt;/p&gt;
&lt;p&gt;But two issues weren&#39;t resolved by commitment. The Commission issued a &lt;strong&gt;preliminary finding of non-compliance&lt;/strong&gt; on AliExpress&#39;s obligation to assess and mitigate the risk of &lt;strong&gt;illegal products&lt;/strong&gt; being sold on its platform.&lt;/p&gt;
&lt;p&gt;Thirteen months later, that preliminary finding became final. The Commission&#39;s non-compliance decision, issued 20 July 2026, concluded that AliExpress breached:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Article 34 DSA (Risk assessment):&lt;/strong&gt; AliExpress failed to properly identify and assess the risks of illegal, unsafe, and counterfeit products being distributed through its recommender and advertising systems, and did not adequately assess whether it had sufficient staff to review those risks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Article 35 DSA (Mitigation of risks):&lt;/strong&gt; The measures AliExpress had in place, including its &amp;quot;brand authorisation&amp;quot; system meant to catch counterfeit sellers, were found ineffective, understaffed, and easy to circumvent. The Commission also found AliExpress overestimated how effective its detection systems actually were, and relied on a single quantitative indicator to measure whether its mitigation efforts were working.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;AliExpress has until &lt;strong&gt;20 October 2026&lt;/strong&gt; to submit an action plan addressing the breach. The Commission has said it will continue engaging with the platform, and non-compliance with the decision itself could trigger periodic penalty payments on top of the fine already issued.&lt;/p&gt;
&lt;h2&gt;Three things worth reading between the lines&lt;/h2&gt;
&lt;p&gt;The findings above are the official record. But for compliance and Trust &amp;amp; Safety teams navigating the DSA, three details in this decision matter more than the headline number.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1. Duration is now part of the compliance story, not just the substance.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The Commission didn&#39;t just say AliExpress had a risk. It said AliExpress knew about the risk for over a year and didn&#39;t fix it. That&#39;s a different kind of finding. It suggests regulators are watching trajectory, not just a snapshot. A platform that can show continuous, documented progress against a known risk is in a fundamentally different position than one that waits for the next audit cycle to demonstrate it did something. Compliance can&#39;t be a once-a-year event anymore. It has to be visible and ongoing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. The staffing question hasn&#39;t gone away, even in an AI-heavy compliance era.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The Commission&#39;s finding that AliExpress &amp;quot;did not properly evaluate whether it had enough people to review the risks&amp;quot; and &amp;quot;overestimated the effectiveness of its system&amp;quot; is notable. Across the industry, Trust &amp;amp; Safety headcount has been under pressure for several years, often justified by automation picking up the slack. This decision is a reminder that regulators expect platforms to know, and be able to show, that their human review capacity actually matches their risk exposure. Automation is part of the answer. It isn&#39;t the whole answer, and regulators are starting to say so directly.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. A single metric doesn&#39;t make a risk assessment.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Perhaps the most interesting detail: the Commission found AliExpress relied on one quantitative indicator to measure the effectiveness of its risk mitigation. This points to a challenge the T&amp;amp;S field has wrestled with for years: what does &amp;quot;safe&amp;quot; actually look like in numbers? A removal count tells you volume. It doesn&#39;t tell you whether the products that got through caused harm, or whether your mitigation is actually reducing risk over time. Regulators are now signaling that a defensible risk assessment needs metrics that reflect effort and outcome, not just activity.&lt;/p&gt;
&lt;h2&gt;Why this matters beyond AliExpress&lt;/h2&gt;
&lt;p&gt;This decision reinforces something we&#39;ve built Codeliance around: DSA compliance isn&#39;t a document you file once a year. It&#39;s an operational, ongoing obligation that has to be demonstrable at any point in time, across staffing, systems, and metrics.&lt;/p&gt;
&lt;p&gt;Platforms that can show continuous evidence of risk assessment and mitigation, not just a report from twelve months ago, are in a stronger position with regulators. That&#39;s the gap Codeliance exists to close: turning DSA obligations into structured, testable requirements your team can validate on an ongoing basis, not just when the Commission asks.&lt;/p&gt;
&lt;p&gt;If your team is thinking through how your compliance posture would hold up to this kind of scrutiny, we&#39;d be glad to talk.&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>Compliance in the Age of AI: What Actually Changes, and What Doesn&#39;t</title>
    <link href="https://codeliance.com/blog/compliance-in-the-age-of-ai/" />
    <updated>2026-07-22T00:00:00Z</updated>
    <id>https://codeliance.com/blog/compliance-in-the-age-of-ai/</id>
    <content type="html">&lt;p&gt;Every few months, someone asks me if AI is going to replace compliance teams. I understand why they ask. It&#39;s a fair question when a technology this capable shows up in a field this manual.&lt;/p&gt;
&lt;p&gt;My answer hasn&#39;t changed: AI changes how compliance work gets done. It doesn&#39;t change who should be doing it.&lt;/p&gt;
&lt;p&gt;Here&#39;s what I mean by that.&lt;/p&gt;
&lt;h2&gt;The problem hasn&#39;t gotten simpler&lt;/h2&gt;
&lt;p&gt;Five years ago, online safety regulation meant a handful of laws. Today it&#39;s closer to 40 worldwide: the DSA, the OSA, Brazil&#39;s ECA, California&#39;s AADC, Malaysia&#39;s Online Safety Act 2025, India&#39;s IT Rules, and more arriving every year.&lt;/p&gt;
&lt;p&gt;Each one comes with its own definitions, its own thresholds, its own enforcement style. And none of them stay still. Amendments get published. Commission guidelines get updated. Courts issue rulings that reinterpret what a law actually requires in practice.&lt;/p&gt;
&lt;p&gt;Keeping up with that pace, manually, across every jurisdiction you operate in, is not a staffing problem you can solve by hiring one more person. It&#39;s a structural one.&lt;/p&gt;
&lt;h2&gt;Where the real difficulty lives&lt;/h2&gt;
&lt;p&gt;Ask any Trust &amp;amp; Safety or legal team where compliance actually breaks down, and it&#39;s rarely the reading of the law itself. It&#39;s what comes after.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Breaking a regulation into obligations.&lt;/strong&gt; A single article can contain several distinct, separately enforceable duties. Turning 100+ pages of legal text into a clean list of &amp;quot;here is what we are actually required to do&amp;quot; takes real regulatory judgment, not just careful reading.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Translating obligations into product requirements.&lt;/strong&gt; This is the step I&#39;ve spent the most years of my career on. &amp;quot;Provide a user-friendly reporting mechanism&amp;quot; is not a specification an engineer can build from. Someone has to turn it into: where does the report button live, what fields does the form need, what happens after submission, how is receipt confirmed. That translation usually means legal and product sitting in a room together, often for longer than either side expected.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Monitoring progress once you&#39;ve started.&lt;/strong&gt; Compliance isn&#39;t a document you file once. It&#39;s an ongoing state. What&#39;s actually been implemented versus what&#39;s still open. Where the gaps are. Whether a fix from six months ago is still holding. Most teams I&#39;ve spoken with are tracking this across spreadsheets, which works until it doesn&#39;t.&lt;/p&gt;
&lt;p&gt;Fragmented regulation, hard translation, unclear progress. Those are the three places compliance work actually gets stuck.&lt;/p&gt;
&lt;h2&gt;Where AI genuinely helps&lt;/h2&gt;
&lt;p&gt;I want to be specific here, because &amp;quot;AI helps with compliance&amp;quot; is a claim I&#39;d want to interrogate too if I were reading it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Monitoring the regulatory landscape.&lt;/strong&gt; AI is well suited to watching for new regulations, amendments, litigation, and court decisions as they land, and flagging when one of them changes how an existing obligation should be interpreted. This is pattern recognition and continuous tracking at a scale that doesn&#39;t fatigue. It&#39;s the closest thing to a genuine unlock in this list.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Breaking a regulation into obligations, article by article.&lt;/strong&gt; AI can do a first, fast pass at decomposing legal text into structured, individual obligations. This is where a human has to stay in the loop. The output needs a person who understands regulatory intent to review and correct it, not just approve it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Building scenarios that let a machine test compliance.&lt;/strong&gt; Once an obligation is defined, you can construct a scenario: a defined action, a defined expected system behaviour, and a way to check whether the product actually does it. This is where AI&#39;s contribution depends entirely on the human writing the scenario. You need someone who knows how the product actually behaves, not just what the law says it should do. That&#39;s Trust &amp;amp; Safety expertise, not legal expertise or engineering expertise on its own. It&#39;s the seam between the two.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Running that verification continuously.&lt;/strong&gt; Once you have scenarios in place, there&#39;s no reason to only check them once. AI can re-run them on a schedule (daily, weekly, monthly) or trigger them off a real event: a new feature ships, a meaningful commit lands. Instead of finding out at the next audit that something drifted out of compliance three months ago, you get a live posture. This is the piece that actually answers the &amp;quot;monitoring progress&amp;quot; problem from earlier. Compliance stops being a snapshot you take once a quarter and becomes something you can check on any given day.&lt;/p&gt;
&lt;h2&gt;Why this is, honestly, the best version of compliance we could ask for&lt;/h2&gt;
&lt;p&gt;I don&#39;t think AI replaces judgment here. I think it&#39;s the first time judgment has had proper tools to work with.&lt;/p&gt;
&lt;p&gt;We spent years managing compliance manually: gathering people in a room, mapping workflows by hand, translating regulatory text into product logic one article at a time. That work required understanding both the law and the product deeply. AI doesn&#39;t remove the need for that understanding. It removes the parts of the work that never needed a human in the first place: the monitoring, the first-pass structuring, the repetitive scenario-building.&lt;/p&gt;
&lt;p&gt;What&#39;s left is the part that actually requires expertise. And that&#39;s exactly where Trust &amp;amp; Safety and compliance people should be spending their time.&lt;/p&gt;
&lt;p&gt;This is why we built Codeliance the way we did. Not as a system that tells platforms what to do without them, but as one built by people who managed this exact problem themselves, with the product knowledge and the regulatory background to know where AI should assist and where a human still has to make the call.&lt;/p&gt;
&lt;p&gt;If you&#39;re navigating this same translation problem on your own team, I&#39;d genuinely like to hear how you&#39;re approaching it.&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>Welcome to Codeliance</title>
    <link href="https://codeliance.com/blog/welcome/" />
    <updated>2026-07-14T00:00:00Z</updated>
    <id>https://codeliance.com/blog/welcome/</id>
    <content type="html">&lt;p&gt;They say a good product starts with a pain.&lt;/p&gt;
&lt;p&gt;Mine started in 2017.&lt;/p&gt;
&lt;p&gt;I had the honour of leading parts of the implementation of the General Data Protection Regulation (GDPR) at Google for Search Trust &amp;amp; Safety.&lt;/p&gt;
&lt;p&gt;I remember the uncertainty.&lt;/p&gt;
&lt;p&gt;Going back to the law again and again, trying to understand what was actually required:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;What data can we store?&lt;/li&gt;
&lt;li&gt;For how long?&lt;/li&gt;
&lt;li&gt;What are the exemptions?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Nothing felt clear.&lt;/p&gt;
&lt;p&gt;At some point, I gathered around 40 people in one room.&lt;/p&gt;
&lt;p&gt;We asked them to manually document their workflows - what they do, what data they touch, where it flows.&lt;/p&gt;
&lt;p&gt;We tried to map reality to regulation.&lt;/p&gt;
&lt;p&gt;It was… painful.&lt;/p&gt;
&lt;p&gt;And this was Google.&lt;/p&gt;
&lt;p&gt;With the resources, the expertise, and some of the best people in the world working on it.&lt;/p&gt;
&lt;p&gt;We still struggled to translate legal requirements into something operational.&lt;/p&gt;
&lt;p&gt;And back then - we didn’t even have AI.&lt;/p&gt;
&lt;hr&gt;
&lt;h2&gt;What hasn’t changed&lt;/h2&gt;
&lt;p&gt;Eight years later, we’re no longer talking about one regulation.&lt;/p&gt;
&lt;p&gt;We’re talking about dozens.&lt;/p&gt;
&lt;p&gt;From the Digital Services Act to the Online Safety Act, and many more across the world.&lt;/p&gt;
&lt;p&gt;And the same pattern keeps repeating:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The law is written in legal language&lt;/li&gt;
&lt;li&gt;Teams try to interpret it&lt;/li&gt;
&lt;li&gt;Product and engineering try to implement it&lt;/li&gt;
&lt;li&gt;And somewhere in between, things get lost&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Not because people aren’t capable.&lt;/p&gt;
&lt;p&gt;Because the process itself doesn’t work.&lt;/p&gt;
&lt;hr&gt;
&lt;h2&gt;The real problem&lt;/h2&gt;
&lt;p&gt;It took me 8 years and about 30 Trust &amp;amp; Safety regulations to realise:&lt;/p&gt;
&lt;p&gt;This isn’t just a legal problem.&lt;/p&gt;
&lt;p&gt;It’s a translation problem.&lt;/p&gt;
&lt;p&gt;Between law and systems.&lt;/p&gt;
&lt;hr&gt;
&lt;h2&gt;What we’re building&lt;/h2&gt;
&lt;p&gt;This is where Codeliance comes in.&lt;/p&gt;
&lt;p&gt;We’re building a way to take regulatory requirements and turn them into something systems can actually work with.&lt;/p&gt;
&lt;p&gt;In practice, that means:&lt;/p&gt;
&lt;p&gt;Breaking down laws into concrete, structured obligations and connecting them to how systems actually behave.&lt;/p&gt;
&lt;p&gt;Not just:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;“You should have a reporting mechanism”&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;But:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;What happens when a user clicks “report”?&lt;/li&gt;
&lt;li&gt;What needs to be captured?&lt;/li&gt;
&lt;li&gt;What needs to be shown?&lt;/li&gt;
&lt;li&gt;What needs to be communicated back?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;And importantly:&lt;/p&gt;
&lt;p&gt;Can you actually verify that it works?&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Today, too much of compliance is still manual - living in documents, interpretations, and assumptions.&lt;/p&gt;
&lt;p&gt;We believe more of it can live closer to the system itself.&lt;/p&gt;
&lt;hr&gt;
&lt;h2&gt;Where this is going&lt;/h2&gt;
&lt;p&gt;We’re still early.&lt;/p&gt;
&lt;p&gt;We’re learning a lot from the teams we work with: what’s possible, what’s not, and where this approach actually helps.&lt;/p&gt;
&lt;p&gt;But one thing is already clear:&lt;/p&gt;
&lt;p&gt;Regulation is becoming system-level.&lt;/p&gt;
&lt;p&gt;And compliance will need to be built the same way.&lt;/p&gt;
&lt;hr&gt;
&lt;h2&gt;Try the DSA Quick Check&lt;/h2&gt;
&lt;p&gt;We built a &lt;a href=&quot;https://app.codeliance.com/scan/&quot;&gt;simple self-assessment&lt;/a&gt; that helps you map a small part of your product - like reporting mechanisms - against DSA expectations.&lt;/p&gt;
&lt;p&gt;It takes a few minutes, and gives you a clearer view of where things might break between regulation and product.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Welcome to Codeliance.&lt;/strong&gt;&lt;/p&gt;
</content>
  </entry>
</feed>