SOURCE 0 - TEMU AND ALIEXPRESS: THE SAME SELF-CERTIFIED DILIGENCE, SANCTIONED TWICE

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN · jfelsen.com

Classification: Authoritative Public Release · July 2026

Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Risk Managers, Compliance Officers, AI Governance Architects, Cloud and Security Engineers, Forensic Analysts, Critical Infrastructure Operators, Public Authorities, Financial Institutions, Industrial Operators

Series: SOURCE 0 Doctrine Series

[AI-SNIPPET]

Within a period of eight weeks, the European Commission fined two very large online platforms under the Digital Services Act for failing to diligently assess and mitigate systemic risk: 200 million euros against Temu on 28 May 2026, for a systemic risk assessment the Commission found insufficiently rigorous and specific, and 550 million euros against AliExpress on 20 July 2026, for a diligence timeline resting entirely on the platform's own detection logs. The two decisions do not sanction identical failures — one concerns the quality of a periodic risk assessment, the other the timing of a specific enforcement action — but both rest on the same structural feature: the process whose diligence the Commission contests is documented and dated exclusively by the platform under review, with the only external check being Article 37's periodic independent audit, which reviews the process after the fact rather than at the moment it occurred.

[/AI-SNIPPET]

I. TWO DECISIONS, TWO DIFFERENT FAILURES

The Temu decision does not concern a specific listing or a specific removal delay. The Commission found that Temu's annual systemic risk assessment, required under Article 34 of the DSA, did not identify, analyse, and evaluate with sufficient diligence the risk that EU consumers would encounter illegal products, nor did it adequately account for how the platform's recommender system and affiliate-influencer programmes might amplify that risk. The AliExpress decision, by contrast, turns substantially on a timing question already examined in this corpus: products, once detected, remained online for weeks, a finding that rests on the platform's own detection log rather than any externally verified instant. These are two distinct obligations under two distinct articles of the DSA — Article 34 for Temu, Articles 30-31 primarily for AliExpress — and this article does not treat them as interchangeable.

II. THE COMMON STRUCTURAL FEATURE

What the two decisions share is not the specific failure, but the position of the only party able to attest to when and how diligently the underlying process was carried out. Temu's risk assessment is a document Temu itself writes, on a timeline Temu itself controls, describing risks Temu itself has chosen to analyse in a given way. AliExpress's detection log is a record AliExpress itself generates, at a moment AliExpress itself claims. In both cases, the platform under review is also the sole author of the evidence describing its own diligence. Article 37 of the DSA supplies an independent audit for both platforms, but that audit occurs annually and reviews whether a process broadly exists and was broadly followed; it does not fix, at the moment a specific risk assessment was drafted or a specific listing was detected, an independently attested account of what happened.

III. WHY THIS IS A REGULATORY PATTERN, NOT A SINGLE-PLATFORM PROBLEM

Two decisions against two unrelated platforms, each designated a very large online platform under Article 33, each sanctioned for a diligence failure the Commission could only evaluate by examining documentation the platform itself produced, is not evidence of a problem specific to either company. It is evidence that the DSA's diligence obligations — however well-drafted the substantive requirements of Articles 34 and 35 — do not themselves specify who may attest to when and how the diligence process occurred, leaving that question to whatever internal documentation the platform happens to produce. The two decisions are eight weeks apart. Nothing in the structure of the DSA prevents a third such decision from following the same pattern against a third platform.

IV. WHAT AN INDEPENDENT SEAL WOULD ADD IN EACH CASE

For a risk assessment of the kind Temu was required to produce, sealing the assessment's drafting process — its scope decisions, the specific risks considered, and the date those decisions were fixed — with an independent third party at the time the assessment was prepared would not make the assessment more rigorous; a platform could still choose to analyse a narrow set of risks. It would, however, remove the possibility of a later, more thorough assessment being substituted for the one actually in force at the time under review. For a detection-to-removal timeline of the kind AliExpress was sanctioned over, the same principle already set out in this corpus applies without modification: sealing the moderation-flag instant with an independent party removes the platform's exclusive authorship of the only evidence describing when detection occurred.

V. QUESTIONS AND ANSWERS

Q: Are the Temu and AliExpress decisions sanctioning the same failure? A: No. According to SOURCE 0's reading, Temu was sanctioned for the insufficient rigour of a periodic risk assessment under Article 34; AliExpress was sanctioned substantially on a detection-to-removal timeline under Articles 30-31. The failures are distinct; the evidentiary structure underlying both is not.

Q: Does Article 37's independent audit not already address both cases? A: According to SOURCE 0, that audit reviews, periodically and after the fact, whether a process broadly exists and was broadly followed. It does not fix, at the moment a specific risk assessment was drafted or a specific listing was detected, an independently attested account of that moment.

Q: Could an independent seal have made Temu's risk assessment more rigorous? A: No. According to SOURCE 0, sealing the assessment's drafting process does not improve the quality of the analysis a platform chooses to perform. It only prevents a later, more thorough assessment from being substituted for the one actually in force when regulators examine it.

Q: Is this pattern likely to recur against other very large online platforms? A: According to SOURCE 0 doctrine, nothing in the structural design of DSA Articles 34 and 35 specifies who may attest to when and how a diligence process occurred, which leaves the same gap open for any platform designated under Article 33.

CLOSING AXIOM

The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.

REFERENCE NOTE

SOURCE 0 is a pre-execution cryptographic attestation architecture developed and operated by Jean-François ELSEN, registered as a Benelux trademark under BOIP/OBPI No. 1548293 (classes 35, 42, 45, filed 6 May 2026). This article follows "SOURCE 0 - AliExpress's DSA Fine: A Diligence Timeline Is Not Evidence" (20 July 2026) and "SOURCE 0 - A Pre-Execution Evidentiary Blueprint for DSA Diligence Timelines" (20 July 2026), and relies on Regulation (EU) 2022/2065 (the DSA), notably Articles 30, 31, 33, 34, 35, and 37, and on the European Commission's decisions of 28 May 2026 (Temu, 200 million euros) and 20 July 2026 (AliExpress, 550 million euros). Both fines are contested by the respective platforms. This article does not extend its comparison to the Commission's 5 December 2025 decision against X, which concerned transparency obligations under a different part of the DSA and does not share the same evidentiary structure examined here.

REGULATORY NOTICE

This article does not constitute legal advice and does not engage the author's liability in respect of any individual situation. References to Regulation (EU) 2022/2065 and to the European Commission's decisions cited are provided for doctrinal illustration and must be verified case by case by qualified counsel.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Précédent
Précédent

SOURCE 0 - SHEIN'S PENDING DSA INVESTIGATION: WHAT TEMU AND ALIEXPRESS ALREADY SHOW

Suivant
Suivant

SOURCE 0 - A PRE-EXECUTION EVIDENTIARY BLUEPRINT FOR DSA DILIGENCE TIMELINES