Systemic risk is a legal term of art in European platform regulation. Under Articles 34 and 35 of the Digital Services Act, Regulation (EU) 2022/2065, the largest online platforms and search engines must identify, analyse and assess the risks that arise from how their services are built and used, then put measures in place to reduce them. The obligation attaches to the machinery, not to individual posts. A single piece of illegal content is a moderation question. Whether the recommender system, the advertising auction and the interface design combine to spread it at scale is a systemic risk question, and that second question is the one the regulation makes enforceable.

The category exists because the earlier European approach to platform liability, built on the e-Commerce Directive of 2000, only asked what a platform did once it learned of specific unlawful material. That framework had nothing to say about design. Engagement-optimised ranking, monetisation policies that reward volume and targeting systems that reach the vulnerable all sat outside its reach.

What Article 34 requires

The duty falls on providers of very large online platforms (VLOPs) and very large online search engines (VLOSEs): services averaging at least 45 million monthly active recipients in the Union, roughly 10% of the bloc's population. Seventeen VLOPs and two VLOSEs were designated in April 2023, among them the Amazon Store, Facebook, Instagram, LinkedIn, Snapchat, TikTok, Zalando, Bing and Google Search. Later rounds added Pornhub, Shein, Stripchat, Temu, XNXX and XVideos. WhatsApp joined on 26 January 2026 on the strength of its Channels feature, which recorded 51.7 million average monthly EU users in the first half of 2025.

Article 34(1) names four risk categories. The first is the dissemination of illegal content. The second covers negative effects on fundamental rights, naming human dignity, privacy, data protection, freedom of expression including media pluralism, non-discrimination, the rights of the child and consumer protection, each keyed to an article of the Charter. The third concerns civic discourse, electoral processes and public security. The fourth addresses gender-based violence, public health, the protection of minors and serious consequences for physical and mental well-being.

Article 34(2) lists five factors providers must weigh: recommender design, content moderation systems, terms and conditions and their enforcement, systems for selecting and presenting advertisements, and data-related practices. Assessments must also examine intentional manipulation, including bot networks and inauthentic accounts, and account for regional and linguistic specifics down to individual member states. Supporting documents are kept for three years and handed to the Commission or the national Digital Services Coordinator on request.

Timing is fixed. The first assessment falls due on the date designation applies, then annually, and again before deploying any functionality likely to have a critical impact on the identified risks. That last clause turns a product launch into a regulatory event.

From assessment to mitigation

Article 35 converts findings into duties. Measures must be reasonable, proportionate and effective, with explicit regard to their own impact on fundamental rights, a safeguard added because over-removal counts as a risk in its own right. The article offers a non-exhaustive menu: adapting design and interfaces, adapting terms and conditions, changing moderation processes, testing and adapting recommender systems, adapting advertising systems, reinforcing internal detection resources, working with trusted flaggers, joining codes of conduct, targeted child-protection measures such as age assurance, and marking synthetic media prominently.

Verification runs through three further provisions. Article 37 requires an annual independent audit. Article 42 requires the risk assessment, the audit report and an audit implementation report to be published. Article 43 funds supervision through a fee capped at 0.05% of the provider's worldwide annual net income in the preceding financial year.

Where advertising sits inside the framework

Advertising is not a footnote here. It appears twice, as a risk factor in Article 34(2)(d) and as a mitigation lever in Article 35(1)(e).

The first annual report under Article 35(2), published by the European Board for Digital Services and the Commission on 18 November 2025 and covering 17 February 2024 to 16 February 2025, sets out what platforms and civil society groups filed. Targeted advertising was cited as a factor in the spread of illegal content. Discriminatory delivery appeared under non-discrimination, with job advertisements shown along gender lines as the example; Bing's 2024 assessment recorded a risk that its advertisements are biased in targeting in ways that affect protected groups' access to critical services. Scams were tied to deceptive advertising and inauthentic reviews. Civil society submissions singled out monetisation policies as an aggravating factor, arguing they incentivise clickbait and the targeting of vulnerable groups such as older users. Influencer marketing was flagged under public health, on the reasoning that minors struggle to recognise a promotion as commercial even when a disclaimer is present.

The mitigation practices reported are equally concrete: advertiser vetting, restricting sensitive categories such as armed conflict to approved organisations, pre-screening creative for scams and medical disinformation, minimum audience sizes to stop targeting becoming too narrow, bans on AI-generated content in election advertising, and advertiser self-declaration of generative AI use. Most providers stated they do not run personally targeted advertising to minors. Delivery settings that were once commercial choices have become compliance artefacts, published annually and readable by competitors, regulators and journalists.

Enforcement so far

The first non-compliance decision, a €120 million fine against X on 5 December 2025, concerned transparency rather than risk assessment: deceptive verification design, an inadequate advertising repository and blocked researcher access. X responded by terminating the Commission's own advertising account two days later.

Risk assessment itself became the charge in 2026. The Commission fined Temu €200 million on 28 May for failing to assess the systemic risk of illegal products, faulting an assessment built on generic sector analysis rather than platform-specific evidence. On 20 July, AliExpress was fined €550 million on the same ground, with the Commission counting the novelty of the regulation as a mitigating circumstance.

Design cases ran on a parallel track. Preliminary findings against TikTok on 6 February 2026 targeted infinite scroll, autoplay and push notifications. Near-identical findings reached Meta on 10 July 2026 over Instagram and Facebook, alongside separate April 2026 findings on under-13 age assurance. Proceedings opened against Shein on 17 February 2026 cover 145 million EU shoppers. In January 2026 the Commission extended its X case to Grok, asking whether an ad hoc assessment preceded deployment of a feature that changed the platform's risk profile.

National enforcement lags: Germany's coordinator acted on 1.3% of complaints in its first full year and issued no fines.

Criticisms and disputes

The sharpest technical objection is that the DSA never defines systemic risk. It supplies an open-ended list instead, which academic critics argue leaves interpretation exposed to political pressure and to negotiation with the platforms being regulated. A related question stays unresolved: which system is being assessed, the whole service, one recommender, or the advertising stack.

The political objection is louder. A US House Judiciary Committee report argued the framework pressures platforms into removing lawful speech, since global terms of service make European standards travel. Commission spokesperson Thomas Regnier called censorship allegations "complete nonsense", citing a 35% rate of successful user challenges to moderation decisions. Former commissioners defending the regulation stressed that the duty addresses structural design, not individual content, while Mueller, quoted in the same coverage, argued that mitigation duties amount to removing lawful content on top of what was already unlawful.

Courts have trimmed the machinery too. In September 2025 the General Court annulled the Commission's supervisory fee decisions in T-55/24 and T-58/24, holding the calculation method should have appeared in a delegated act rather than the fee notices. Overlap is a further complaint: the same conduct can attract assessment duties under the DSA, the AI Act and the GDPR, and the European Data Protection Board confirmed in Guidelines 3/2025 that systemic risk identification will often trigger a separate data protection impact assessment.

Scope gaps show up in practice. Maldita.es documented 5,600 posts in Facebook groups organising irregular Ceuta crossings before planning moved to encrypted WhatsApp groups, beyond the framework's reach.

Terms it is confused with

AI Act systemic risk is a different regime sharing the name. Article 51 of Regulation (EU) 2024/1689 classifies a general-purpose AI model as carrying systemic risk when training compute exceeds 10^25 floating point operations, or when the Commission decides capabilities are equivalent. That designation attaches to a model rather than a service, and the wider classification threshold for general-purpose models sits at 10^23 FLOPs. The AI Office became exclusively competent for AI systems embedded in designated VLOPs under amendments to Article 75, which places the two regimes in direct contact.

Financial systemic risk is the older usage, describing contagion through interconnected institutions. The DSA borrowed the vocabulary, not the modelling.

Digital Markets Act obligations get confused with DSA duties because both instruments were proposed on 15 December 2020. The DMA regulates competitive conduct by designated gatekeepers and contains no risk assessment duty.

Brand safety risk is a commercial judgement about where an advertisement appears. Adjacency problems belong to the advertiser; systemic risk belongs to the platform.

Recent developments

Enforcement volume has risen while the surrounding rulebook is reopened. The Digital Omnibus of 19 November 2025 would simplify the GDPR, the ePrivacy Directive and the AI Act; the Council stripped a machine-readable consent signal from it in June 2026. The DSA itself has not been amended. The first designated cohort has filed three rounds of assessments and audits, a longitudinal record regulators lacked when the earliest cases opened.

Timeline

  • 15 December 2020: Commission proposes the Digital Services Act alongside the Digital Markets Act
  • 19 October 2022: European Parliament adopts Regulation (EU) 2022/2065
  • 16 November 2022: DSA enters into force
  • 25 April 2023: First 17 VLOPs and two VLOSEs designated
  • Late August 2023: First cohort compliance deadline, four months after designation
  • 17 February 2024: DSA becomes fully applicable to all intermediary services
  • 19 February 2024: Formal proceedings opened against TikTok
  • April 2024: Commission issues Article 35(3) guidelines on electoral process risks
  • 16 May 2024: Formal proceedings opened against Meta
  • 31 May 2024: Temu designated as a VLOP
  • July 2025: Commission issues Article 28(4) guidelines on protection of minors
  • 11 September 2025: EDPB adopts Guidelines 3/2025 on the DSA and GDPR interplay
  • September 2025: General Court annuls supervisory fee decisions in T-55/24 and T-58/24
  • 29 October 2025: Delegated act on researcher data access under Article 40 enters into force
  • 18 November 2025: First annual Article 35(2) report on systemic risks published
  • 5 December 2025: X fined €120 million, first DSA non-compliance decision
  • 26 January 2026: WhatsApp designated as a VLOP
  • 6 February 2026: Preliminary findings against TikTok on addictive design
  • 17 February 2026: Formal proceedings opened against Shein
  • 29 April 2026: Preliminary findings against Meta on under-13 age assurance
  • 28 May 2026: Temu fined €200 million for inadequate risk assessment
  • 10 July 2026: Preliminary findings against Meta on addictive design
  • 20 July 2026: AliExpress fined €550 million for risk assessment and mitigation failures

Summary

Who: Providers of very large online platforms and very large online search engines carry the obligation. The European Commission supervises them directly, working with national Digital Services Coordinators through the European Board for Digital Services. Independent audit organisations verify compliance, and vetted researchers and civil society groups supply outside scrutiny.

What: A duty under Articles 34 and 35 of Regulation (EU) 2022/2065 to identify, analyse and assess four categories of risk stemming from service design, then to implement proportionate mitigation measures. Recommender systems, content moderation, terms and conditions, advertising systems and data practices are the five factors that must be weighed. Assessments are audited annually and published. Fines reach 6% of worldwide annual turnover.

When: The regulation entered into force on 16 November 2022 and became fully applicable on 17 February 2024. The first designated services assessed their risks from 2023 and have now filed three annual rounds. Risk assessment became the basis of penalties in 2026, with fines against Temu in May and AliExpress in July.

Where: The European Union and the European Economic Area. Obligations attach to services with at least 45 million average monthly recipients in the Union, regardless of where the provider is established.

Why: Liability rules written for the early web addressed individual pieces of content and said nothing about the systems that distribute them. Systemic risk shifts the regulatory question from what a platform removes to how a platform is built.