Data And Regulation
Global Digital Policy Enters an "Enforcement Year": Platform Responsibility, AI Governance, and Competition Rules Tighten in Tandem
In January 2026, the European Union designated WhatsApp as a very large online platform and launched an investigation into X's deployment of Grok; France passed a social media ban for under-15s; and the European Union initiated specification proceedings against Google under the DMA. Digital regulation is shifting from a legislative race to an enforcement race, forcing platforms to restructure their product design, recommendation algorithms, and data use.
In January 2026, the focus of global digital policy shifted from "making rules" to "enforcing rules." The European Commission designated WhatsApp as a very large online platform (VLOP) under the Digital Services Act (DSA), launched a formal investigation into whether X fulfilled its risk assessment obligations before deploying the Grok feature, and expanded its existing investigation into X's recommendation system; the French National Assembly passed a bill banning minors under 15 from using social networks and classifying profile-based recommendations targeting minors as "editorial activity." On competition policy, the European Commission launched specification proceedings against Google under the Digital Markets Act (DMA), and the UK imposed behavioral requirements on Google. On data governance, the EU introduced a cybersecurity package, China amended its Cybersecurity Law, and the UK advanced implementation of the Data (Use and Access) Act. These moves appear disparate, but they point to the same thing: platforms' product design, algorithms, and data use are being brought into enforceable compliance frameworks.
Event Background: A Concentrated Regulatory Release Covering the G20
This assessment comes from a monthly roundup published by Digital Policy Alert via TechPolicy.Press on February 9, 2026. The organization conducts daily monitoring of policy changes in G20 countries, and each entry links to official government sources, covering four major areas: content moderation, artificial intelligence, competition policy, and data governance.
Content moderation was the area with the most intense activity this month. In addition to WhatsApp's VLOP designation, the European Commission also launched two investigations into X's compliance issues, while Ireland's High Court certified X's appeal against the Media Commission's Online Safety Code provisions. At the member state level, Poland's president vetoed a draft law to implement the DSA and designate a national competent authority; the Dutch Authority for Consumers and Markets (ACM) launched an investigation into Roblox to assess whether its protections for minors are adequate; Italy's communications regulator (AGCOM) approved a list of "services of general interest" that must be prominently displayed on connected devices and TV platforms.
On artificial intelligence, the EU advanced regulation related to AI "gigafactories," South Korea enacted the AI Framework Act, China released cybersecurity standards for AI chips, and a Brazilian court suspended an order concerning Meta's AI service integration. On competition policy, besides the DMA specification proceedings against Google, South Korea took enforcement action against Coupang. On data governance, the EU released a cybersecurity package, China amended its Cybersecurity Law, the UK implemented the Data (Use and Access) Act, and Canada took enforcement action against X.
Digital Economy Analysis: Compliance Costs Are Becoming Product Architecture
When these issues are viewed together, a structural shift emerges: the lever of digital regulation has moved from "punishing illegal content after the fact" to "prescribing in advance how products are designed."The French bill is the most representative. It does not merely set an age threshold; it also reclassifies profile-based recommendations to minors as editorial activity—meaning recommendation algorithms are redefined from “technologically neutral distribution tools” into “publishing conduct that must bear editorial responsibility.” The same logic appears in a bill submitted to Turkey’s Grand National Assembly: age verification, content moderation obligations, child safety by default, and bans on specific services are bundled together. In the UK, the interim guidance on “super-complaints” under the Online Safety Act and the age-verification guidance for pornographic websites likewise embed compliance requirements into the service entry point.
For platforms, this means compliance is no longer an outsourced legal expense, but a product constraint that directly changes user growth funnels, recommendation system architecture, and ad delivery logic. Age verification raises registration friction and changes conversion rates; restrictions on recommendation systems weaken ad inventory that depends on dwell time; and integrating AI features requires risk assessments before launch—the EU investigation into X’s deployment of Grok is a direct manifestation of this requirement.
Business model observation: Advertising, subscriptions, and AI features are being repriced simultaneously
First, the advertising model is under the most obvious pressure. The French bill explicitly bans targeted advertising aimed at minors and requires warnings to be attached to promotional content. For social platforms with advertising as their revenue mainstay, minor traffic shifts from “monetizable inventory” to “compliance burden,” and its commercial value will be reassessed; some platforms may choose to proactively raise age thresholds to reduce costs.
Second, the commercialization path for AI features is being lengthened. Grok’s deployment on X and Novi’s generative AI service were both called out by regulators for failing to fully implement age assurance or risk assessments. This means the marginal revenue of AI features must deduct an additional “upfront compliance cost,” and the release cadence of AI features will shift from product-driven to compliance-driven.
Third, a new services market is taking shape. Age verification, digital product passports, risk assessments, and transparency reports are shifting from ad hoc projects to recurring expenditure. The EU’s Toy Safety Regulation requires all toys placed on the EU market—including those sold online—to carry a digital product passport, and the potential for this infrastructure logic to extend to other product categories in the future is worth watching.
Fourth, AI infrastructure itself has become an object of industrial policy. The EU’s regulatory moves on AI “gigafactories” indicate that compute power and model training capacity are now viewed as strategic resources requiring a regulatory framework, rather than merely a matter of private-sector capital expenditure.
Competitive market analysis: The DMA specification proceedings and the battle over recommendation algorithms
Competition policy in January showed characteristics of “proceduralized enforcement.” The European Commission launched DMA specification proceedings against Google, while the UK imposed behavioral requirements on Google. The two paths differ, but point in the same direction: shifting the definition of market dominance from market share to concrete behavioral indicators such as user choice and data portability.For Google, the real cost is not fines, but the fact that its products must simultaneously satisfy different behavioral constraints across multiple jurisdictions, creating complex coordination challenges among search, app distribution, and advertising technology. For X, pressure comes from two directions: content moderation compliance and AI feature deployment compliance, and its announced shift to a Grok-based recommendation system falls squarely within regulators’ focus on recommendation algorithm risks.
On the beneficiary side, providers of compliance technology, age assurance, digital identity, and audit services will see structural demand; vendors deploying computing power and model capabilities locally in Europe may benefit relatively from “gigafactory”-oriented industrial policy. Those facing challenges are platforms heavily dependent on traffic from minors, targeted advertising, and rapid AI feature iteration, including some social platforms, gaming platforms, and short-video services. South Korea’s enforcement action against Coupang also signals that enforcement risks for e-commerce and platform-based companies at the consumer protection level are rising in tandem.
Data and Regulatory Impact: Protection of Minors Becomes the World’s Broadest Common Ground
The January policy list shows that protection of minors has transcended ideological divides and become the area where national regulators can most easily form consensus.
On the European side, France’s ban on social media for under-15s, Turkey’s age verification and child-safety-by-default settings, the Dutch ACM’s investigation into Roblox, and the Australian eSafety Commissioner’s inquiry notice to X regarding Grok’s potential to generate sexualized content form a clear thread: platforms must prove that they “can identify children and limit their exposure.”
On the China side, the Ministry of Public Security has solicited public comments on the Anti-Cybercrime Law, requiring service providers, search engines, and AI platforms to monitor and block illegal or false information, requiring AI-generated content to be clearly labeled, and restricting improper use of website and app names; the Cyberspace Administration of China has adopted measures for classifying online information that may affect the physical and mental health of minors, requiring platforms to implement corresponding access restrictions. Indonesia’s Criminal Code came into effect, establishing categories of crimes committed using information technology.
Notably, regulatory paths are diverging: Europe emphasizes platform risk assessments and transparency reports, China emphasizes content labeling and classification management, while the UK gradually refines obligations through Ofcom guidance and enforcement lists. The fifth commencement regulations under the UK’s Data (Use and Access) Act even criminalize creating or soliciting intimate images of another person without consent. For multinational companies, this divergence means: a unified global content and data strategy is becoming ineffective, and the cost of localized compliance teams will continue to rise.
Global Trend Observation: From a “Legislative Race” to an “Enforcement Race”
Over the past five years, the main thread of global digital policy has been legislation—the DSA, DMA, AI Act, and national data protection laws have been introduced one after another. The signal sent in January 2026 is that the main thread has switched to enforcement: designating VLOPs, initiating specification proceedings, issuing information notices, launching investigations, and issuing guidance. These actions determine how legal provisions actually become real costs for companies.
This is a long-term trend, not a short-term event. Three medium-term paths can be anticipated: First, age verification will spread from content platforms to gaming, e-commerce, and AI services, giving rise to digital identity infrastructure. Second, recommendation algorithms will continue to be incorporated into editorial responsibility and risk assessment frameworks, and algorithmic transparency will become a core compliance asset for platforms. Third, the boundary between AI features and platform responsibility will further blur, and “compliance assessment before product launch” will become a standard process.
DigitalEcoNews Insight
The most important economic significance of January’s policy list does not lie in any single penalty, but in the fact that the digital economy is undergoing a “capitalization of compliance.” In the past, compliance was an operating cost for platforms; today, compliance capability is becoming a precondition for whether a product can be launched, whether a feature can be released, and whether a market can be entered. This means compliance has shifted from a cost item to a competitive variable.
The impact on corporate business models is direct. Revenue structures that rely on minors’ traffic and targeted advertising will be weakened; the pace of AI feature iteration will be constrained by the rhythm of risk assessment, and tension between short-term growth and compliance cadence will persist; by contrast, age assurance, digital identity, auditing, and compliance tools will grow into an industry with long-term demand. If platforms can internalize compliance capability as product capability—for example, by making age verification a low-friction experience and making recommendation system transparency an asset of user trust—they will have an opportunity to turn regulatory pressure into differentiated advantage.
There are three implications for the future landscape. First, the global digital market is moving from “one product serving the globe” to “multiple compliance architectures operating in parallel,” and the value of localization capability is being repriced. Second, the regulatory focus is shifting from content itself to distribution mechanisms: whoever controls recommendation bears more responsibility. Third, the combination of minor protection and AI governance will become the most certain regulatory increment over the next two years, and companies should incorporate it into product roadmaps rather than crisis response lists.
Short-term enforcement cases will pass, but the logic of “compliance by design” has been established. For managers in the digital economy, the key question in 2026 is no longer “will regulation come,” but “can our product architecture withstand the normalization of regulation.”
Use note · digitalecononews
digitalecononews frames this note through Digital Markets / AI Economy / Platforms & Apps (Source URLs should be opened before the summary is reused). Digital Markets / AI Economy / Platforms & Apps explains the local editorial angle; dates, names and status changes still need checking.