The European Commission fined AliExpress €550 million ($629 million) on Monday for what investigators described as a wholesale failure to manage the risk of illegal, unsafe, and counterfeit products circulating on its platform — the largest penalty ever issued under the EU's Digital Services Act and the clearest signal yet that Brussels holds marketplaces accountable for the goods their algorithms push to buyers.
The finding at the heart of the case goes beyond what most platform fines address. The Commission did not simply find that AliExpress failed to remove dangerous listings fast enough. It found that the platform's own recommendation system and advertising tools were actively routing European shoppers toward those listings — toys that failed safety standards, cosmetics with banned ingredients, counterfeit clothing — before the products were pulled. That distinction matters: it makes this the first DSA enforcement action in which a marketplace's algorithmic amplification mechanism is itself identified as a structural cause of consumer harm, not merely an incidental feature.
Scale Is Not an Excuse: What the Commission Found
The investigation, opened in March 2024 and spanning two years of evidence-gathering, identified five overlapping failures in how AliExpress managed product risk.
First, AliExpress significantly underestimated how many human moderators it needed to review potentially illegal product listings. Investigators found that reviewers were sometimes given only tens of seconds to determine whether a listing met EU standards — a throughput failure at the core of the platform's compliance architecture.
Second, and most consequential, the company failed to assess how its recommendation algorithms and advertising tools were amplifying the reach of dangerous goods. Products that had been flagged for review — and were therefore known to be suspect — were simultaneously being served to additional buyers through AliExpress's ranking and paid-promotion systems. The platform's algorithmic infrastructure had no effective integration with the flagging pipeline that would have suppressed suspect listings before they were reviewed.
Third, AliExpress used a single quantitative metric to gauge the effectiveness of its moderation system — a measure investigators found too narrow to capture re-listing behavior, in which sellers penalized for violations continued operating on the platform under different accounts or in different product categories.
Fourth, sellers could deliberately miscategorize items into product classes with lighter pre-listing scrutiny, bypassing the checks that existed. Fifth, AliExpress's brand-authorization system, designed to prevent counterfeit sales, was understaffed and circumvented easily by sellers offering fake merchandise.
The result, according to the Commission's findings, was that products including counterfeit clothing, unsafe toys, and dangerous cosmetics remained listed and actively promoted to European consumers for multiple weeks after being flagged as problematic.
European Commission Executive Vice President Henna Virkkunen, who leads the bloc's tech sovereignty portfolio, addressed the scale defense directly at Monday's briefing.
"The spread of counterfeit clothing, unsafe toys, dangerous cosmetics and other illegal and harmful products is not an unavoidable cost of shopping online — it is a failure by AliExpress to comply with its obligations under the Digital Services Act," Virkkunen said. "Scale is not an excuse; risks must be identified and addressed systematically to ensure consumers can safely shop online."
Algorithms as the Mechanism of Harm — a New Legal Frontier
The Commission's characterization of AliExpress's recommendation engine as a mechanism of harm — not just a neutral sorting tool — represents a meaningful expansion of how DSA enforcement applies to e-commerce platforms.
Under EU law, Very Large Online Platforms are required by Articles 34 and 35 of the DSA to assess and mitigate systemic risks, including risks posed by their own technical systems. The legal theory underlying Monday's fine is that a recommendation algorithm which uses engagement signals — views, clicks, purchase history — to surface and promote products does not become exempt from that obligation simply because the algorithm optimizes for commercial relevance rather than harm. When those engagement signals direct more buyers to listings that the platform's own moderation system has flagged, the algorithm is a vector of harm, and the platform bears responsibility for managing it.
The DSA's full applicability to all platforms took effect in February 2024. AliExpress was formally designated a Very Large Online Platform in 2023, meaning it was subject to the strictest compliance tier from the moment those rules came into force. The Commission opened its investigation in March 2024 — less than two months after the DSA became fully applicable.
AliExpress Pushes Back
AliExpress said it disagrees with the Commission's assessment and called the fine disproportionate. "We do not agree with today's decision or this disproportionate fine, which reflects neither our long-standing principles nor the significant and proactive measures we have implemented," the company said in a statement. The company said it is reviewing all available legal options.
The Commission acknowledged that the relative novelty of the DSA framework served as a mitigating factor — the fine could have been higher. Under the DSA, penalties for non-compliance can reach up to 6% of a company's total global annual turnover. Alibaba's annual revenue is approximately €120 billion, placing the theoretical ceiling at around €7.2 billion. Monday's €550 million penalty amounts to less than 1% of that figure.
In June 2025, the Commission accepted a package of commitments from AliExpress covering seller identity verification, advertising transparency, and data access for researchers — and made those commitments legally binding. The July 20 fine is the conclusion of a separate investigation track that those commitments did not resolve: the systemic risk of dangerous product circulation, which the Commission determined had not been adequately addressed.
A Pattern Emerges: Chinese Platforms Under Coordinated Scrutiny
Monday's decision is the third fine issued under the DSA, and all three have targeted major platforms — with two of three landing on Chinese-owned e-commerce operations. Temu received a €200 million fine in May 2026 for comparable failures to curb illegal product sales, a penalty it also contested. Shein is the subject of a separate DSA formal investigation opened in February 2026. X was fined €120 million in December 2025 for DSA violations related to content moderation and recommender system transparency.
Virkkunen pointed to the scale of Chinese platform penetration in Europe to explain the enforcement priority: AliExpress had 193 million monthly users in Europe last year, more than Shein's 156 million and Temu's 130 million. One in five Europeans shops from AliExpress, Shein, or Temu at least once a month.
The enforcement pattern runs parallel to a broader EU customs reform. The bloc replaced its €150 per-item duty-free exemption for small parcel imports with a flat €3 fee on July 1, 2026 — a measure targeting the logistics economics of direct-from-China shipping that the DSA fines cannot address.
Alibaba, AliExpress's parent company, had also agreed just 18 days before Monday's ruling to pay $600 million to resolve a US Department of Justice investigation — the department's finding that between 2016 and 2024, approximately 80,000 transactions on Alibaba.com and AliExpress.com involved illegal pharmaceuticals, controlled substances, precursor chemicals, and pill-making equipment.
What AliExpress Is Required to Do by October
The October 20, 2026 deadline is not a formality. AliExpress must submit a detailed action plan specifying exactly how it intends to remedy each of the Commission's identified failures under the DSA's non-compliance process. The European Board for Digital Services will then have one month to issue an opinion on the plan, after which the Commission will have a further month to set a final compliance deadline. Inadequate remediation could trigger ongoing periodic penalty payments with no fixed ceiling.
What regulators will look for is not simply a higher count of removed listings. Based on the Commission's findings, AliExpress will need to demonstrate measurable improvements across staffing levels for human review, algorithmic controls on recommendation and advertising systems, enforcement against re-listing sellers, category verification, and the brand-authorization process. The October plan will function as a compliance blueprint that every major marketplace operating in Europe will study closely.
For the broader platform industry, the message from Monday's ruling is precise: in the EU, a marketplace's algorithmic infrastructure is now part of its legal compliance obligation. The DSA is no longer primarily a content moderation law. It is becoming the legal foundation for a new accountability regime that extends to the full architecture of online commerce — including the systems that decide what a buyer sees next.
What Shoppers Should Know About AliExpress and Data Under Chinese Law
AliExpress's parent company Alibaba is headquartered in Hangzhou, China. That jurisdiction creates legal obligations that apply regardless of where user data is stored, what the company's privacy policy states, or where subsidiaries may be incorporated. Readers who use AliExpress should be aware of the following fixed legal conditions.
China's National Intelligence Law (2017), Article 7, requires any organization or citizen to "support, assist and cooperate with the state intelligence work in accordance with the law." Under this law, Alibaba cannot refuse a request from Chinese intelligence authorities, and is legally prohibited from disclosing that any such request has been made.
China's Cybersecurity Law (2017) requires companies to cooperate with government network inspections and may authorize government access to stored data. China's Data Security Law (2021) imposes data localization requirements and includes government-access provisions.
The categories of data AliExpress collects from European users — shopping history, search queries, device identifiers, browsing behavior on-platform, and payment-linked records — are in principle subject to these legal demands. The EU's GDPR creates partial protections for European users, but no European court has fully resolved the conflict between GDPR obligations and Chinese intelligence law in the context of a Chinese company operating in Europe. No independent security audit of AliExpress's data transmission practices was publicly available as of this article's publication. Readers who wish to limit their exposure can use a dedicated browser profile for AliExpress sessions, avoid linking payment details to an AliExpress account where possible, and review their data access and deletion rights under the GDPR via AliExpress's EU-facing privacy portal. None of these steps eliminates the structural risk created by Chinese jurisdiction law; they reduce the footprint of data available to be compelled.
Frequently Asked Questions
What specifically did AliExpress do wrong under EU law?
The European Commission found three core failures, the most significant of which was that AliExpress's recommendation algorithm and paid advertising tools were actively promoting flagged, unsafe, and counterfeit products to more buyers — not merely failing to remove them. The platform also failed to maintain enough human moderators to review suspect listings, and used a single inadequate metric to measure moderation effectiveness, meaning the system consistently underreported the scale of risk. The Commission found that counterfeit clothing, unsafe toys, and dangerous cosmetics remained listed and algorithmically promoted for multiple weeks after being identified.
Is AliExpress safe to use after this fine?
The fine does not constitute a ban, and AliExpress remains operational in the EU. However, the Commission's findings document that the platform's own recommendation system was steering European shoppers toward unsafe and counterfeit products as recently as June 2025. AliExpress has until October 20, 2026 to submit a remediation plan; whether its systems have materially improved before that deadline is not independently verifiable. Shoppers should exercise extra caution when purchasing toys, children's products, cosmetics, and electrical goods from the platform until independent compliance confirmation is available.
What does this mean for all online marketplaces, not just AliExpress?
Monday's ruling establishes that under the DSA, a marketplace's recommendation algorithm and advertising placement systems are part of its legal compliance obligation — not neutral technical tools. Any Very Large Online Platform operating in Europe whose systems promote listings that the platform's own moderation identifies as risky faces the same legal exposure AliExpress did. This applies to Amazon, eBay, and any other marketplace meeting the 45-million-user VLOP threshold. The ruling is the strongest signal yet that Brussels intends the DSA's risk-assessment obligations to govern not just what platforms take down but what their algorithms push up, as Digital Watch Observatory noted.
Who is operating AliExpress, and what are the data-privacy implications for European shoppers?
AliExpress is owned by Alibaba Group, which is headquartered in China and subject to China's National Intelligence Law (2017), Cybersecurity Law (2017), and Data Security Law (2021). These laws legally compel Chinese companies to cooperate with government intelligence requests and prohibit them from disclosing that any request has been made. This means that the shopping data, device identifiers, and browsing behavior European users generate on AliExpress are, in principle, accessible to Chinese authorities on demand — a condition that exists independently of AliExpress's privacy policy, its EU GDPR compliance, or the physical location of its servers.
Related Articles