Public rules, funding and supervision of private compliance
European Commission
The European Commission combines digital rulemaking, enforcement and research funding. It appears here through child-safety policy engagement, AI4TRUST funding, platform-data access procedures and binding AliExpress commitments overseen by a Commission-approved monitor paid by the company.
The European Commission occupies several different positions in this investigation. It participates in policy forums, funds research and exercises enforcement powers over major online services. These roles let it influence both the ideas available to policymakers and the practical conditions under which companies operate. Its WeProtect board participation is one route into child-safety discussion; its digital-service decisions carry a different, legally binding kind of authority.
The AliExpress case provides a particularly clear view of that authority. In June 2025 the Commission made commitments binding on named Dutch and Singapore entities. The arrangement included a monitoring trustee nominated and paid by the company, whose mandate required Commission approval. The Commission approved Ankura Consulting (Europe) in September 2025 and retained powers to give instructions or require replacement. A private consultancy thus performs work within a publicly supervised compliance structure.
The Commission also adopted procedures for project-specific researcher access under the Digital Services Act and was assigned responsibility for the data-access portal. Those arrangements define a route through which qualified researchers may obtain information from major platforms. Eligibility, the requested project and the access conditions matter because the resulting power is permission to inspect data that companies otherwise control.
Research funding is another channel. The Commission's records list approximately €5.95 million for the AI4TRUST project, including €385,275 for its German GDI participant. Separately, it announced a €550 million AliExpress fine in July 2026 concerning illegal-product risks. Together these examples show an institution able to finance knowledge production, establish obligations and demand changes in company conduct. Its importance lies in that combination of resources and public authority.
Reuters reports age-tiered access checks and supervisory fees in an unpublished Commission draft. The Commission declined comment; its actual text was not obtained. These reported design choices are neither adopted duties nor an exercised enforcement power.
Ankura Consulting (Europe), Limited → European Commission
must submit monitoring reports and promptly flag concluded failure
C.9 prints impossible31November2027;recital16730November/C.12 two months.2026cycle not yet ended9September2026; no silent correction.
First cycle ends30September2025, first report due within2months; later cycles endSeptember2026/2027. Company copy may remove third-party confidential material. No actual receipt/report/response acquired.
European Commission → 2025/2050: project-specific access procedure
adopted the project-specific research-access procedures
Published adopted regulation assigns prerequisites, request formulation, access modalities and amendment/delivery records. No named project approval or60-day GDI proposal adoption inferred.
July 2022 minutes record a Commission briefing to the WeProtect board and possible requests for assistance. Particular requests and resulting outputs are not established by this record.
European Commission → Ankura Consulting (Europe), Limited
approves mandate and may instruct or replace the trustee
Commission may reject/modify mandate and issue compliance instructions; replacement/discharge/hand-over governedC.7–8. No exercised instruction/replacement acquired.
The dated route reaches back before either 2024 report previously traced. A July2022 paper by Ian Levy and Crispin Robinson identifies their posts at the UK National Cyber Security Centre and GCHQ. The European Commission cited it in a public defence of its child-sexual-abuse proposal on 7August2022. eSafety cited it in an encryption position dated 13October2023. These are actual citations by public authorities, not merely institutional proximity.
At paragraph76, PDF17 , Full Fact argues that the proposed definition is too narrowly directed at public safety. It asks to include public health and national security, aligning the definition with section 175 and comparing the EU Digital Services Act's crisis definition. It describes the existing Secretary of State route to Ofcom's media-literacy priorities or public statement notices. This is a scope-alignment argument using an existing power as a benchmark, not a newly drafted executive activation power.
The proposal is sponsored by Safe Online and delivered by the Belgian nonprofit euCONSENT ASBL (cover and1.9, PDF3). It builds on an earlier European Commission-funded consortium project; do not backdate ASBL as the original 2021 grant recipient. The reported project-level funding purpose is established. The executed grant agreement, amount, subproject/vendor allocation, ultimate donor allocation and clearance/acceptance rights remain unacquired; a separately encountered $2million figure belongs to a ten-project portfolio and is not assigned here.
July 2022 minutes record a Commission briefing to the WeProtect board and possible requests for assistance. Particular requests and resulting outputs are not established by this record.
Project interval; EC signature6December2022, registry last updated17June2026; not disbursement dates.
Reported by the cited source
CORDIS records EUR5950682.50 project contribution and cost. This is an aggregate project field, not GDI income or a dated payout. The separately displayed German participant contribution is included within this project, not extra funding to add.
Financial details: value: 5,950,682.5; currency: EUR; kind: published net EU project contribution; period: project1January2023-28February2026
Project1January2023-28February2026; exact participant accession/payment dates not obtained.
Reported by the cited source
CORDIS German GDI participant entry lists net EU contribution and total cost each EUR385275. The recipient is the German legal participant, not proven UK receipt, subaward or a bank transfer.
Financial details: value: 385,275; currency: EUR; kind: published net EU participant contribution; period: AI4TRUST project interval; payout dates unknown
CORDIS updated17June2026 labels the project closed with28February2026 end. This is project administrative status, not a declaration every resulting tool stopped or all final deliverables were accepted.
Published adopted regulation assigns prerequisites, request formulation, access modalities and amendment/delivery records. No named project approval or60-day GDI proposal adoption inferred.
Commission may reject/modify mandate and issue compliance instructions; replacement/discharge/hand-over governedC.7–8. No exercised instruction/replacement acquired.