Skip to main content
Home/Blog/X's €120M DSA Fine: Ad-Repository Transparency and What It Means for Advertisers in 2026
Back to Intelligence Hub
regulationEuropean UnionRisk Level: high

X's €120M DSA Fine: Ad-Repository Transparency and What It Means for Advertisers in 2026

The EU's first DSA non-compliance fine hit X over its ad repository, blue-checkmark design and researcher access — a signal on ad-library transparency for advertisers.

Updated July 10, 2026· Originally published July 10, 202612 min readAuditSocials Research
TweetShare
Quick Answer

The European Commission's first non-compliance fine under the Digital Services Act, 120 million euros against X, was based on three transparency failures, one of which sits at the centre of advertising: the Commission found that X's advertising repository did not meet the DSA's transparency and accessibility requirements, alongside the deceptive design of its 'blue checkmark' verified-account feature and a failure to give researchers adequate access to public data. Under the DSA, very large online platforms must maintain a public, searchable repository of the ads they carry, including who paid for each ad and the parameters used, so that researchers and civil society can scrutinise advertising and detect scams, coordinated operations and fake ads. The Commission concluded that X's repository fell short — incorporating design features and access barriers such as processing delays, and lacking critical information such as the content and topic of ads and the legal entity paying for them. For advertisers, the fine is not a direct obligation but a set of signals: ad-library transparency is now enforced, so the ads you run on major platforms are increasingly visible and scrutinised; verification-based trust signals like blue checkmarks are under regulatory pressure, which affects brand-safety assumptions; and the direction of travel is toward more, not less, ad transparency. The practical response is to assume your ads are publicly discoverable, keep creative and targeting defensible, and factor verification changes into brand-safety planning. Review X-specific rules in the X ads policy guide, track enforcement on the Policy Change Tracker, and pre-check campaigns with the AI Compliance Audit.

X's €120M DSA Fine: Ad-Repository Transparency and What It Means for Advertisers in 2026

The First DSA Non-Compliance Fine

The European Commission's 120 million euro penalty against X was the first non-compliance fine issued under the Digital Services Act, and its subject matter puts advertising transparency at the centre of DSA enforcement. The Commission found three breaches of the DSA's transparency obligations: the deceptive design of X's 'blue checkmark' verified-account feature, the lack of transparency of its advertising repository, and a failure to provide researchers with adequate access to public data. Two of the three go directly to how advertising is disclosed and scrutinised.

The significance for the advertising ecosystem is that the DSA's ad-transparency machinery — the public ad repositories that very large online platforms must maintain — is now being enforced with real penalties, not merely encouraged. For advertisers, this reframes a long-standing assumption: the ads they run on major platforms are increasingly visible in public repositories, searchable by researchers, journalists and civil society, and a platform that fails to make that repository properly transparent faces consequences. The scrutiny that used to attach mainly to political advertising now extends to advertising transparency generally.

"Accessible and searchable ad repositories are critical for researchers and civil society to detect scams, coordinated information operations and fake advertisements.
— European Commission, on the DSA ad-repository requirements"

This guide explains what the DSA requires of ad repositories, where X's fell short, the separate blue-checkmark finding, and what advertisers should take from a ruling that targets the platform rather than them. For X-specific advertising rules see the X ads policy guide, and for the wider EU framework the EU DSA compliance guide.

What the DSA Requires of Ad Repositories

At the heart of the advertising finding is the DSA's requirement that very large online platforms maintain a public repository of the advertisements they present. This is a transparency mechanism designed to let outside observers see what advertising is running, who is behind it, and how it is targeted — turning advertising from something visible only to its audience into something the public can examine.

The Core Repository Requirements

RequirementWhat it meansPurpose
Public and searchableThe repository must be accessible and usable, not hidden or obstructedEnables scrutiny by researchers and civil society
Who paidThe legal entity paying for each ad must be identifiableReveals who is behind advertising
Content and parametersThe ad content, and the main targeting parameters, must be recordedShows what was shown and how it was targeted
Retention and completenessInformation must be stored and complete, without critical gapsAllows meaningful, historical analysis

Alongside the repository, the DSA also requires that individual ads be clearly labelled as advertising, with information about who placed them and why the user is seeing them. The repository and the per-ad labelling work together: labelling informs the individual viewer, while the repository informs the public. The obligation falls on the platform, but its effect is that advertisers' campaigns become part of a public record. For how ad transparency operates specifically for political advertising, which has its own layer, see the DSA political-advertising transparency guide.

Where X's Repository Fell Short

The Commission's finding was not that X lacked an ad repository, but that the repository it provided failed the DSA's transparency and accessibility standards in specific ways. The shortcomings fall into two groups: barriers that made the repository hard to use, and gaps in the information it contained.

The Identified Shortcomings

  • Access barriers: the Commission pointed to design features and obstacles — including processing delays — that undermined the repository's usability and defeated its purpose of enabling scrutiny.
  • Missing content and topic: the repository was found to lack critical information such as the content and topic of the advertisements, so an observer could not fully see what was being advertised.
  • Missing payer identity: the repository was found to lack clear information about the legal entity paying for the advertisement, obscuring who was behind the ads.

These shortcomings matter because a repository that exists but is slow, incomplete or hard to search does not deliver the transparency the DSA requires — the Commission's point was that the purpose of an ad repository is defeated by access barriers and missing fields even if a repository nominally exists. For advertisers, the corrective direction is clear: platforms will be pushed toward repositories that fully record ad content, topic and payer identity, which means the ads advertisers run will be more completely and durably documented in public. Track how platforms adjust their ad libraries on the Policy Change Tracker.

The Blue-Checkmark Dark-Pattern Finding

The third breach, distinct from the repository issue, concerned the design of X's 'blue checkmark' verified-account feature. The Commission found that the way X implemented verification amounted to a deceptive design — a dark pattern — because it no longer reliably signalled what users had come to associate with a verified account, allowing anyone to obtain the badge in a way that could mislead users about authenticity.

Why Verification Design Matters for Advertisers

  • Trust signals shift: when a verification badge no longer denotes vetted authenticity, the brand-safety value advertisers attach to appearing alongside 'verified' accounts changes.
  • Impersonation risk: a badge obtainable by anyone can facilitate impersonation of brands and public figures, a direct brand-safety and consumer-protection concern.
  • Regulatory pressure on design: the finding shows that deceptive design of trust features is itself an enforceable DSA violation, which may drive platforms to redesign verification.

For advertisers, the blue-checkmark finding is a reminder that platform trust signals are not fixed and that their meaning can change in ways that affect brand-safety assumptions and impersonation exposure. Advertisers should not treat a verification badge as a durable guarantee of authenticity when its basis has shifted, and should factor potential verification redesigns into planning. For the deceptive-content rules that govern advertising on X directly, see the X prohibited and deceptive content guide.

What Advertisers Should Take From It

As with other platform-directed enforcement, the fine imposes obligations on X, not on advertisers — it does not change what advertisers may run or add a filing duty. Its value to advertisers is as a set of signals about the environment they operate in, and those signals point consistently in one direction: more advertising transparency and more scrutiny.

The Practical Signals

  • Assume public discoverability: operate on the assumption that ads on major platforms are, or will be, publicly discoverable in repositories, and keep creative and targeting defensible on that basis.
  • Transparency is enforced, not optional: the DSA's ad-transparency requirements now carry real penalties, so the trend toward complete, searchable ad records will strengthen.
  • Verification is not a fixed trust anchor: build brand-safety planning that does not over-rely on platform verification badges whose meaning can change.
  • Scrutiny extends beyond politics: ad-transparency enforcement is not limited to political ads; commercial advertising is part of the public record too.

The reassuring counterpoint is that advertisers running truthful, policy-compliant, well-targeted campaigns have little to fear from greater transparency — a public record is a problem mainly for deceptive or non-compliant advertising. Treating public discoverability as the default is simply good discipline: write creative you would be comfortable seeing in a public library, and keep targeting within policy. Pre-check campaigns against platform and legal standards with the AI Compliance Audit, and for the harmful-content and brand-safety dimension of DSA enforcement see the harmful-content brand-safety playbook.

Ad-Transparency Readiness Checklist

  • [ ] Assumed ads on major platforms are publicly discoverable in ad repositories
  • [ ] Ensured creative would be defensible if seen in a public ad library
  • [ ] Kept targeting parameters within platform policy and applicable law
  • [ ] Confirmed the legal entity paying for ads is accurate and consistent
  • [ ] Reviewed reliance on platform verification badges in brand-safety planning
  • [ ] Assessed impersonation exposure where verification no longer guarantees authenticity
  • [ ] Distinguished the platform's DSA obligation from any advertiser duty
  • [ ] Monitored platform ad-repository and verification changes
  • [ ] Reviewed deceptive-content rules for advertising on the platform
  • [ ] Confirmed current DSA ad-transparency status against official Commission sources

Frequently Asked Questions

What was X fined for under the DSA?
X was fined 120 million euros by the European Commission in what was the first non-compliance fine issued under the Digital Services Act, for three breaches of the DSA's transparency obligations: the deceptive design of its 'blue checkmark' verified-account feature, the lack of transparency of its advertising repository, and a failure to provide researchers with adequate access to public data. Two of these three failures go directly to advertising and information transparency, which is why the fine matters to the advertising ecosystem even though the obligation falls on X. The advertising-repository failure is the most directly relevant. Under the DSA, very large online platforms must maintain a public, searchable repository of the ads they carry, including information about who paid for each ad and the parameters used to target it, so that researchers, journalists and civil society can scrutinise advertising and detect scams, coordinated operations and fake ads. The Commission found that X's repository did not meet these transparency and accessibility standards — it incorporated design features and access barriers, such as processing delays, that undermined its usability, and it lacked critical information such as the content and topic of the advertisements and the legal entity paying for them. In other words, X had a repository, but the Commission concluded it did not deliver the transparency the DSA requires. The blue-checkmark failure concerned trust and authenticity rather than advertising specifically: the Commission found that X's implementation of verification was a deceptive design, because the badge no longer reliably signalled the vetted authenticity users had come to expect, and could mislead them. The researcher-access failure concerned the DSA's requirement that platforms give vetted researchers access to public data so that independent scrutiny of platform risks is possible. Together, the three findings show the Commission enforcing the DSA's transparency architecture — ad repositories, honest design of trust features, and researcher access — with real financial penalties. For advertisers, the essential takeaways are that ad-library transparency is now enforced, that verification signals are under pressure, and that the direction of travel is toward more scrutiny of advertising. For X-specific rules see the X ads policy guide, and track enforcement on the Policy Change Tracker. The organizing principle is that X was fined for failing the DSA's transparency requirements on its ad repository, its verification design, and researcher data access.
What does the DSA actually require platforms to put in an ad repository?
The DSA requires very large online platforms to maintain a public repository of the advertisements they present, and that repository must be accessible and searchable and must contain, for each ad, information including the content of the advertisement, the legal or natural person on whose behalf it is presented and who paid for it, the period during which it ran, and the main parameters used to target it — so that the public can see not just that advertising occurred but what was shown, by whom, and to whom it was aimed. The purpose is to convert advertising from something visible only to its intended audience into something outside observers can examine collectively. Breaking down the core elements: the repository must be genuinely usable — public and searchable, not hidden behind obstacles or crippled by delays — because a repository that cannot be effectively searched does not enable the scrutiny it exists for. It must identify who is behind each ad, including the entity that paid, so that observers can trace advertising to its source and detect, for instance, coordinated campaigns or undisclosed interests. It must record the ad content and topic, so that what was actually advertised is visible rather than merely the fact that an ad ran. It must capture the main targeting parameters, so that how the ad was aimed can be understood, which is central to detecting discriminatory or manipulative targeting. And the information must be retained and complete, so that historical and longitudinal analysis is possible rather than a fleeting snapshot. Separately but relatedly, the DSA requires that individual ads be clearly labelled as advertising and carry information about who placed them and why the particular user is seeing them; this per-ad transparency informs the individual viewer, while the repository informs the public and researchers. The two mechanisms complement each other. The obligation sits on the platform, but the practical effect on advertisers is significant: their campaigns become part of a durable public record that anyone can search, which is precisely why the enforcement trend rewards truthful, compliant, well-targeted advertising and penalises deceptive or non-compliant campaigns that would be exposed by such a record. For the political-advertising layer, which has additional transparency requirements, see the DSA political-advertising transparency guide, and for the framework overall the EU DSA compliance guide. The organizing principle is that DSA ad repositories must be public, searchable and complete — recording ad content, payer identity, run period and targeting — so advertising becomes a public record.
Why is the 'blue checkmark' a DSA problem, and how does it affect advertisers?
The blue checkmark became a DSA problem because the Commission found that X's implementation of the verified-account badge was a deceptive design — a 'dark pattern' — since the badge no longer reliably signalled the vetted authenticity that users had historically associated with verification, yet was presented in a way that could still lead users to believe it did, and this deception of users is what the DSA's rules against deceptive design prohibit. For advertisers, the finding matters because it destabilises a trust signal that brand-safety thinking has quietly relied on. To understand the issue, recall what verification traditionally meant: a checkmark indicated that a platform had confirmed an account genuinely belonged to the notable person, brand or organisation it claimed to represent. Users learned to read the badge as a marker of authenticity. When verification is changed so that the badge can be obtained by anyone — for example through a subscription — without the same authenticity vetting, the badge's meaning diverges from users' understanding of it. The Commission's concern was that continuing to present the badge as if it carried its old meaning, when it no longer did, deceives users about who they are dealing with. That deception can facilitate impersonation of brands, public figures and institutions, because an account can appear 'verified' while being inauthentic. The advertiser implications are twofold. First, brand-safety assumptions: advertisers and their tools sometimes treat proximity to 'verified' accounts, or the presence of verification, as a positive trust signal in placement and association decisions; if verification no longer denotes vetted authenticity, those assumptions need revisiting, because a badge is no longer a dependable proxy for a legitimate, authentic account. Second, impersonation exposure: a verification system that anyone can obtain raises the risk that a brand is impersonated by a 'verified'-looking account, which is a direct brand-protection and consumer-harm concern that advertisers should monitor. The broader lesson is that platform trust signals are not fixed features but design choices that can change — and that regulators will treat deceptive design of such signals as an enforceable violation. Advertisers should therefore avoid over-relying on any single platform badge as a durable authenticity guarantee and should factor potential verification redesigns into brand-safety and impersonation planning. For the deceptive-content rules governing advertising on the platform directly, see the X prohibited and deceptive content guide, and track changes on the Policy Change Tracker. The organizing principle is that a verification badge that no longer signals vetted authenticity is a deceptive design under the DSA, so advertisers should not treat verification as a fixed brand-safety anchor.
Does this fine create any obligation for advertisers?
No — the 120 million euro fine creates obligations for X, not for advertisers: it does not change what advertisers are permitted to run, it does not add any filing, disclosure or verification duty for advertisers, and it does not alter advertising-policy compliance requirements. The DSA obligations at issue — maintaining a compliant ad repository, designing verification honestly, and giving researchers data access — are platform duties, and the enforcement action is directed at the platform's failure to meet them. Advertisers are downstream of these obligations, not subject to them. That said, being free of a direct obligation is not the same as being unaffected, and the sensible reading is that the fine sends advertisers several important signals about the environment they operate in. The first is that ad-library transparency is now genuinely enforced. Because very large online platforms must maintain public, searchable ad repositories and now face real penalties for failing to, the ads advertisers run are increasingly part of a durable public record that researchers, journalists and competitors can examine. Advertisers should operate on the assumption that their campaigns are publicly discoverable, which is simply a reason to keep creative and targeting truthful and defensible. The second signal is that verification-based trust is under pressure. The blue-checkmark finding shows that platform trust signals can change and that regulators will treat deceptive trust design as a violation, so advertisers should not build brand-safety plans that over-rely on a platform badge as a fixed authenticity guarantee. The third is directional: EU ad-transparency enforcement is intensifying and extending beyond political advertising to advertising transparency generally, so the trend of more scrutiny and more complete ad records will continue. The appropriate advertiser response to all of this is not new compliance paperwork but good discipline: assume public discoverability, keep creative and targeting within policy and law, ensure the paying entity behind ads is accurately represented, and monitor platform changes to ad repositories and verification. Advertisers who already run clean, compliant campaigns need change little; the transparency trend mainly threatens deceptive or non-compliant advertising that a public record would expose. Pre-check campaigns with the AI Compliance Audit, and for the broader DSA framework see the EU DSA compliance guide. The organizing principle is that the fine obliges the platform, not advertisers, but signals a transparency trend that rewards truthful, compliant, publicly-defensible advertising.
How should advertisers prepare for greater ad-transparency enforcement?
Advertisers should prepare for greater ad-transparency enforcement by adopting a simple operating assumption — that the ads they run on major platforms are, or will be, publicly discoverable in searchable repositories — and building their creative, targeting and record-keeping to be defensible on that basis, because the X fine confirms that the DSA's ad-transparency machinery is now enforced with real penalties and the trend toward complete, public ad records will only strengthen. This is less about new compliance tasks than about a mindset shift that makes existing good practices non-negotiable. Concretely, the preparation has several strands. On creative, treat every ad as though it will appear in a public ad library viewed by researchers, journalists and competitors: write claims you can substantiate, avoid deceptive or manipulative framing, and ensure the creative would withstand scrutiny out of its original context. A public record is only a problem for advertising that could not survive being seen; truthful, compliant creative is unaffected. On targeting, keep parameters within platform policy and applicable law, because the repository can expose how ads were aimed, and discriminatory or manipulative targeting is exactly what transparency mechanisms are designed to reveal. On payer identity, ensure the legal entity paying for the ads is accurate and consistent, since the repository is meant to identify who is behind advertising, and discrepancies invite questions. On brand safety, revisit any reliance on platform verification signals, given that the blue-checkmark finding shows those signals can change and lose their meaning; plan for verification redesigns and for impersonation risk rather than treating a badge as a permanent guarantee. On monitoring, keep track of how platforms adjust their ad repositories and verification systems in response to enforcement, because the mechanics — what fields are recorded, how searchable the library is — will evolve. Finally, extend the same discipline beyond any single platform: ad-transparency requirements apply across very large online platforms, and the expectation of public discoverability is becoming a general feature of advertising in the EU, not an X-specific quirk. The overarching point is that advertisers who run clean, truthful, well-targeted campaigns are well positioned for a more transparent environment and need mainly to make that discipline consistent and deliberate. Pre-check campaigns against platform and legal standards with the AI Compliance Audit, review platform rules in the X ads policy guide, and monitor enforcement on the Policy Change Tracker. The organizing principle is that advertisers prepare for ad-transparency enforcement by assuming public discoverability and making truthful creative, compliant targeting and accurate payer identity a consistent default.

Don't miss the next policy change.

Create a free account — track every policy change across 8 platforms, get instant alerts, and access every free compliance tool. Or try our Keyword Risk Checker first.

Create Free Account

Report Keywords — Run AI Compliance Audit

#X Ads#DSA#Ad Transparency#Ad Repository#Brand Safety#Content Moderation#Ad Compliance#Advertisers#European Union#2026 Policy#Dark Patterns#Compliance Guide 2026

Share This Report

TweetShare

Related Posts

Related Resources