The number landed on a Monday morning
The European Commission announced on 20 July 2026 that it had fined AliExpress EUR 550 million for breaching the Digital Services Act. The Commission's finding is that the marketplace fell short of its obligation to diligently assess the risk of dissemination of illegal, unsafe or counterfeit products, and failed to take effective measures to reduce that risk.
Henna Virkkunen, the Commission's tech chief, framed the harm in two directions at once. The situation is "very dangerous for consumers, unfair for companies which are complying", she said. That second clause is the one most coverage skipped, and it is the one that matters to anyone who has spent money building the controls a competitor did not.
AliExpress called the fine disproportionate and said it was carefully reviewing the decision. That response sets up months of argument. It does not pause the clock the decision started.
The finding is about headcount, not takedowns
Read the findings closely and a pattern emerges that is not really about counterfeit phone chargers. The Commission found that AliExpress had not properly evaluated whether it had enough people to review the risks, and that it had overestimated the effectiveness of its own system for detecting and removing illegal products. Those are findings about a company's description of itself.
The DSA requires very large platforms to produce a risk assessment. It is easy to read that obligation as a document exercise, and easy to write the document in the confident register that internal reporting tends to reward. The Commission has now treated that document as a testable claim. If the assessment says the detection system works and the detection system does not, the gap is not a communications problem. It is the infringement.
The same logic runs through the rest of the decision. The mandatory brand authorisation system, designed to stop counterfeit sales, was found to be ineffective and understaffed, and easily circumvented by traders selling fakes. The penalty policy was ineffective, so sellers who had been penalised carried on selling illegal goods. Illegal items remained online for many weeks. Each of those is a control that existed on paper and was not resourced to work.
One hundred twenty, two hundred, five hundred fifty
Three DSA fines have now been issued. X was fined EUR 120 million. Temu was fined EUR 200 million. AliExpress has been fined EUR 550 million. The third number is larger than the first two combined by a wide margin.
It is tempting to read that curve as a measure of how much worse each case was. A more useful reading is that the Commission is calibrating upward until the fine exceeds what compliance would have cost. A penalty that lands below the price of hiring the moderation staff and building the enforcement tooling is simply a licence fee, and every platform finance team knows how to model a licence fee. A penalty that lands above it changes the build-or-pay calculation.
For operators well below the very-large-platform threshold, the direct exposure is limited. The signal is not. Enforcement priorities set at the top of the market become the template for what national regulators look for further down it, and the questions being asked here translate cleanly to any business that hosts third-party listings, reviews or user submissions.
October is the deadline that actually bites
The fine is the visible part of the decision and the least consequential. AliExpress must propose remedial measures by 20 October. The Commission will assess in December whether those measures bring it into compliance. Failure to comply with the non-compliance decision may lead to periodic penalty payments, which accrue continuously rather than arriving as a single number.
That structure is the point. A one-off fine can be absorbed, disclosed and moved past. Periodic penalty payments cannot, because they do not stop until the underlying problem is fixed, which means the company has to actually resource the fix rather than argue about the assessment of it.
The Commission also said it would continue engaging with the company to ensure compliance with the decision and with the DSA more generally. Read plainly, that means this file stays open. The EUR 550 million is the entry price for a supervisory relationship, not an exit from one.
What to change before your next risk assessment
The first change is to stop writing risk assessments in marketing voice. If your document says a detection system is effective, someone should be able to produce the measurement that supports it, including the false-negative rate. Where you do not have the measurement, write that you do not have it. An honest gap is defensible. An overstatement is now an infringement finding.
The second is to tie every named control to a number of people. The brand authorisation failure here was not a design failure, it was a staffing failure attached to a well-designed control. For each control in your compliance documentation, record who runs it, how many of them there are, and what volume they can actually process. If that arithmetic does not work, the control does not work, and writing it down is what makes the gap visible before a regulator finds it.
The third is to check what happens after you penalise someone. The Commission found that penalised sellers continued to sell illegal products, which means the sanction existed but the follow-through did not. Whatever your equivalent is, whether a suspended account, a delisted supplier or a warned user, test whether the sanction actually holds a week later. Most organisations have never checked.
Read next: Brussels Just Put a Price on Google's Search Data | The EU Says Addictive Design Can Cost 6% of Revenue



