In December 2025, the European Union fined platform X €120 million under the Digital Services Act. The fine was for advertising transparency — the platform’s failure to maintain a searchable, accurate repository of who was paying for what political and commercial advertising. It was a real violation, and the fine was justified.

It was also the wrong fine, in the sense that it addressed the least serious of X’s problems under the Act. The far more consequential violation — the one with a documented evidentiary record, a billion-plus-view amplification event, and a direct line to two of the most damaging anti-Muslim narrative episodes in recent European history — has not been charged by any regulator. This article sets out why it should be, on what legal grounds, and by whom.

Part I: What Actually Happened

Two episodes anchor this analysis.

January 2025. The majority shareholder and chief executive of X published fifty-one posts over several days reframing historical UK child sexual exploitation cases — a subject with genuine victims and a genuine record of institutional failure — as a collective religious and ethnic indictment of British Pakistani Muslim men. Independent research subsequently measured approximately 1.2 billion engagements with this content, with total reach across the resulting discourse at 1.53 billion views. Researchers sampling posts from the peak period found that over half promoted hatred against Muslims as a collective group, rather than addressing the specific criminal conduct of specific individuals.

August 2024, and its aftermath. Following the Southport murders, false claims that the perpetrator was a Muslim asylum seeker spread through the platform at speed. A single far-right account tied to the ensuing wave of disinformation and subsequent unrest received over five hundred and eighty million views.

Neither episode is disputed as a factual matter. What is contested — because no regulator has yet formally alleged it — is whether this pattern amounts to a regulatory failure, as distinct from a moral or political one. That is a legal question, and it has a legal answer.

Part II: The Law X Has Not Yet Been Charged Under

The Digital Services Act does not only police illegal content and advertising disclosure. For “very large online platforms” (VLOPs) — a category X occupies by virtue of its EU user base exceeding 45 million monthly users — Articles 34 and 35 impose a freestanding, structural obligation that exists independently of any single post being illegal.

Article 34 requires VLOPs to identify, analyse, and assess systemic risks stemming from the design, functioning, and use of their service, at least once a year. The Article specifies four categories of risk platforms must assess, two of which are directly engaged here: the dissemination of illegal content through the service; actual or foreseeable negative effects on the exercise of fundamental rights, including the rights to non-discrimination and human dignity protected under the EU Charter of Fundamental Rights; actual or foreseeable negative effects on civic discourse and electoral processes, and on public security; and actual or foreseeable negative effects related to gender-based violence, protection of minors, and serious negative consequences for a person’s physical and mental wellbeing.

Article 35 requires platforms to put in place “reasonable, proportionate, and effective” mitigation measures tailored to the risks identified under Article 34 — adapting recommender systems, adjusting content moderation resourcing, applying visibility restrictions to demonstrably harmful viral content, and similar structural interventions. Critically, the obligation is not to prevent all harmful content — that would collide with free expression protections — but to have a functioning process that identifies foreseeable harms of this kind and takes proportionate structural steps to reduce them.

This is what separates Articles 34 and 35 from ordinary content moderation. A platform can comply perfectly with every individual takedown request — the subject of the Article 20 investigation Ireland’s regulator opened into X in November 2025 — and still fail Articles 34 and 35, because the obligation is systemic. It asks whether the platform’s design and governance, taken as a whole, foreseeably produced this outcome, and whether the platform did anything about it.

Part III: Applying the Law to the Facts

Three elements need to be established for an Article 34/35 case, and the public record already speaks to each.

1. Foreseeability. The risk of religious-minority targeting reaching billions of views was not a surprise event. The August 2024 Southport episode preceded the January 2025 posts by five months. A platform that had genuinely conducted its Article 34 risk assessment in good faith after Southport would have had a documented basis to anticipate that unmoderated, algorithmically amplified content from its own chief executive reframing a criminal matter along religious-ethnic lines carried a foreseeable risk of the same kind of harm, at greater scale, given his reach.

2. Scale and source. The identity of the poster matters legally, not just rhetorically. Content from a platform’s own controlling shareholder and CEO is not an edge case the platform’s systems failed to catch — it is content the platform’s own leadership had every institutional means to review, contextualize, or restrict, and did not. This goes to whether X’s mitigation measures under Article 35 were applied evenly, or selectively withheld from the one account structurally positioned to cause the most damage.

3. Absence of a demonstrated mitigation response. To date, no public transparency report, risk assessment summary, or regulatory filing by X has documented a specific mitigation response to either episode. The €120 million fine addressed advertising registries. It did not purport to, and did not, address whether X’s recommender systems were adjusted, whether the content was down-ranked, or whether any structural governance response occurred at all following either event.

None of this proves a violation in the way a court finding would. It establishes what a serious regulatory complaint requires: a documented, foreseeable, large-scale pattern, and a visible absence of the structural response Articles 34 and 35 require. That is a legally serious case, not a moral one dressed up in legal language.

Part IV: Anticipated Defenses, and Why They Don’t Resolve the Case

Any fair legal analysis has to state the other side’s strongest arguments.

“This is protected speech, and platforms aren’t liable for user content.” Correct, and irrelevant to this specific claim. Articles 34 and 35 do not ask whether the CEO’s posts should have been removed — a much harder free-expression question. They ask whether the platform’s systemic design and mitigation processes functioned as required once the foreseeable, mass-scale effect of that content became apparent. A platform can leave content up and still fail its systemic risk obligations by declining to apply the same visibility, labeling, or friction measures it applies to comparable viral content from other sources.

“Causation between any single post and the eventual harm is impossible to prove.” This is true and is precisely why Article 34 does not require proof of a specific downstream harm caused by a specific post. It requires an assessment of foreseeable risk and a proportionate mitigation response to that risk — a lower and more institutionally realistic bar than tort-style causation, deliberately designed because platform-scale harms are diffuse by nature.

“Regulators already fined X — this is double jeopardy.” It is not. The December 2025 fine addressed a distinct, narrower obligation (advertising transparency, under different DSA provisions). Nothing in the DSA’s structure treats a fine under one obligation as satisfying a separate one; VLOPs commonly face parallel investigations under different Articles simultaneously, as the ongoing Article 20 probe into X’s appeals process by Ireland’s Coimisiún na Meán already demonstrates.

Part V: Who Has Jurisdiction, and What Should Happen Next

This is the part most advocacy pieces get wrong, so it is worth being precise.

Under the DSA’s enforcement architecture, jurisdiction over Article 34 and 35 obligations for VLOPs sits with the European Commission, not with national Digital Services Coordinators. Ireland’s Coimisiún na Meán — X’s DSC of establishment — retains competence over other DSA obligations (its current investigation concerns Article 20 appeal rights), but once the Commission has opened or could open proceedings on a VLOP’s systemic risk obligations, that authority is reserved to the Commission alone under the Article 56 division of powers. This matters practically: a complaint aimed at the wrong body will be redirected or shelved, wasting the time of everyone who filed it.

Concrete steps, and who should take them: civil society organisations and researcher coalitions should compile a formal Article 34/35 complaint dossier directly to the European Commission’s DSA enforcement unit, built on the documented engagement data and the absence of any published mitigation record. Vetted researchers, who under Article 40 of the DSA have a statutory right to request data access from VLOPs, should formally request X’s internal risk assessment documentation and recommender-system adjustment logs. The European Parliament should be asked directly why systemic risk obligations have not been part of any public X enforcement action to date. Individual complainants can file a normal DSA notice-and-complaint through the Commission’s complaint portal referencing Articles 34 and 35 specifically. Any resulting Commission investigation, if opened, could result in a finding requiring structural mitigation measures — not merely a fine — with penalties of up to 6% of X’s global annual turnover for confirmed breaches.

Conclusion

The €120 million fine already imposed on X proves the Digital Services Act works as designed for the violation it was built to catch. It says nothing about whether the Act works for the violation described in this article, because that violation has not yet been charged.

The legal architecture to charge it already exists in force. The evidentiary record — engagement figures, timeline, source, and absence of any documented mitigation — is already public. What is missing is not law. It is a regulator, or a coalition serious enough to make one act.

This analysis is offered as a legal argument for consideration by regulators, researchers, and civil society organisations. It does not constitute a finding of liability, which only the European Commission or a competent court could make.