On July 19, 2026, the European Commission fined AliExpress EUR 550 million for breaching its obligations under the Digital Services Act (DSA) to diligently assess and mitigate systemic risks linked to the sale of illegal, unsafe and counterfeit products on its marketplace. The Commission also ordered the platform, a designated Very Large Online Platform (VLOP), to submit a compliance action plan by October 20, 2026.

The decision, published as press release IP/26/1654, is the first final non-compliance ruling against AliExpress under the DSA and one of the largest DSA penalties to date. It targets two obligations every VLOP owes under Article 35 (risk assessment) and Article 36 (mitigation of systemic risks): the Commission found that AliExpress overestimated its moderation capacity, failed to test how its recommender and advertising systems amplified illegal goods, and relied on a single quantitative metric that did not measure whether illegal products reappeared on the platform.

Who has to act, and by when?

AliExpress must deliver its action plan to the Commission by October 20, 2026. The European Board for Digital Services then has one month to issue an opinion, and the Commission has a further month to adopt its final decision and set a reasonable implementation period. Failure to comply with the non-compliance decision can trigger periodic penalty payments.

The deadline is not only AliExpress's problem. Trust and safety, legal compliance and EU regulatory affairs teams at every other VLOP and large online marketplace, including Meta, TikTok, X, Amazon, Shein, Temu, Zalando, Booking and Google, should read the ruling as the template for the Commission's next enforcement wave. The same Article 35 and Article 36 obligations bind all of them, and the reasoning in this decision maps directly onto their own risk-assessment files.

What the Commission found wrong with AliExpress's risk assessment

The decision, based on AliExpress's 2023 and 2024 risk-assessment reports plus testing by the Commission's services, identifies three assessment failures:

  • Staffing realism. AliExpress did not properly evaluate whether it had enough human moderators to review potentially illegal products, and it overstated how effectively its system detected and removed them.
  • Recommender amplification. Commission testing showed that many illegal products were recommended or advertised to consumers before they were effectively removed, meaning the platform's own algorithms spread the very risks it was supposed to contain.
  • Metrics. AliExpress relied on only one quantitative indicator, which did not measure whether its moderation system prevented illegal products from appearing or reappearing in similar forms.

What the Commission found wrong with AliExpress's mitigation

Four mitigation shortcomings drove the fine. The Commission found that AliExpress's system to detect illegal products did not work properly: counterfeit goods, unsafe toys and dangerous cosmetics circulated for multiple weeks even after being detected. AliExpress did not properly enforce its penalty policy for traders selling illegal products, so penalised stores stayed active. Product compliance checks could be circumvented through mis-categorisation, because AliExpress allocated insufficient staff to verify whether products were correctly categorised before publication, letting malicious traders place goods in the wrong category to benefit from more flexible requirements. Finally, the mandatory brand authorisation system intended to prevent counterfeit sales proved ineffective and understaffed, so traders bypassed it and published counterfeit products that were only removed later.

The Commission calculated the fine taking into account the nature of the infringements, their gravity in terms of affected EU users, and their duration, which ran at least until June 2025 when it issued preliminary findings against AliExpress. Failing to conduct proper risk assessments and to effectively mitigate systemic risks constitutes a particularly serious infringement of the DSA. The Commission also applied mitigating circumstances in AliExpress's favour, notably the novelty of the Digital Services Act.

How this fits the DSA enforcement ladder

DateStep
March 14, 2024Commission opened formal proceedings against AliExpress
June 18, 2025Commitments made binding; preliminary findings of non-compliance on risk assessment and mitigation
July 19, 2026Final EUR 550 million fine and action-plan order issued
October 20, 2026Action plan due from AliExpress

The DSA has applied to VLOPs since August 2023. The AliExpress decision marks the Commission's shift from opening proceedings and accepting commitments to imposing final fines with concrete remedial deadlines, and it signals that risk-assessment quality, not just content takedown volume, is now the enforcement frontier. Continuous, per-jurisdiction real-time monitoring surfaces this kind of change the moment it publishes.

Take advantage of this real-time watch

DMA cloud gatekeeper decisionsLive
Monitor the EU Digital Markets Act cloud investigations for the AI, data and digital governance industry.
Hourly Email 5 news
This live monitoring job detected the news you are reading.
Activate this watch free now

What to do next

Compliance teams at VLOPs and large marketplaces should treat the decision as an audit checklist. Confirm that your Article 35 risk assessment quantifies moderator workload against listing volume, that it tests recommender and advertising amplification of illegal goods, and that it tracks reappearance rates rather than single-removal counts. Verify that trader penalty enforcement actually disables offending stores, that categorisation controls cannot be gamed, and that brand authorisation is staffed to demand. Brief trust and safety, legal and EU regulatory affairs ahead of the October 20, 2026 action-plan deadline, and watch for the European Board for Digital Services opinion that follows.