OLYMPUS RISK INTELLIGENCE PROTOCOL — INSTITUTIONAL ASSESSMENT DIVISION CASE WTW-2026-072

EU DIGITAL SERVICES ACT

THE INSTITUTIONS THE RULEBOOK
REGULATORY WING — STATUTORY CONTENT-CONTROL AUTHORITY
Status
ACTIVE — Regulation (EU) 2022/2065; fully applicable since 17 February 2024; enforced by the European Commission and national Digital Services Coordinators
Hazard — Reach
88
RCH / FND / ENT
9 / 9 / 9
Conduct
STATUTE-INSTRUMENT — DUE PROCESS ON PAPER, ONE-WAY IN PRACTICE

OLYMPUS opened an institutional file on a statute. A law has no Big Five and no Dark Triad, and the unit does not invent them; what a law has is a text, an enforcement arm, and a funding structure. The Digital Services Act is catalogued here as the rulebook — the first statute in a Western democracy to convert content moderation from a platform’s private practice into a legal obligation with fines attached. The finding is the shape of the machinery, not the intent of its drafters: a framework whose stated categories (illegal content, systemic risk) are bounded by due process on paper, and whose observed history is a one-directional expansion of what the machinery reaches. The numbers in the front matter are reach, entrenchment, and durability — a regulation outlives every commissioner who signs it.

Institutional Archetype

THE RULEBOOK — The archetype is the statute that makes the private practice mandatory. The DSA does not run a platform, does not employ a moderator, and does not remove a single post itself. It obliges the platforms to do the removing — on legal deadlines, under systemic-risk assessments, with priority lanes for designated flaggers — and attaches fines of up to six percent of global annual turnover to the obligation. That is the structural power: not authorship of any single takedown, but authorship of the incentive landscape inside which every takedown decision on a large platform is now made. A platform facing a six-percent fine does not litigate borderline cases. It removes them. The over-removal is not written anywhere in the text; it is what the text’s incentives produce.

Mandate & Origin

The DSA was proposed by the European Commission in December 2020 under the von der Leyen Commission’s digital portfolio — Executive Vice-President Margrethe Vestager and Internal Market Commissioner Thierry Breton, who publicly fronted its enforcement — and adopted as Regulation (EU) 2022/2065 on 19 October 2022. Obligations for Very Large Online Platforms (VLOPs, 45 million+ EU users) began in late 2023; the full regulation became applicable to all intermediaries on 17 February 2024. The architecture, from the statute’s own text:

  • Systemic risk (Articles 34–35): VLOPs must assess and mitigate risks including the spread of illegal content and “negative effects on civic discourse and electoral processes” and public health — the assessment is annual, and the mitigation is audited.
  • Trusted flaggers (Article 22): entities designated by national Digital Services Coordinators whose illegal-content notices platforms must treat “with priority.” The Commission publishes the roster in a public database; the platforms retain formal responsibility for the removal decision.
  • Enforcement: the Commission itself directly supervises VLOPs — a supranational regulator holding the fine authority over the world’s largest speech venues — with national DSCs covering everything smaller.
  • Fines: up to six percent of global annual turnover.

Funding & Backers

The enforcement is funded by the enforced — the detail the coverage rarely leads with. Under Article 43, VLOPs and VLOSEs pay the Commission an annual supervisory fee, capped at 0.05 percent of worldwide annual net income, to fund their own supervision. The platforms pay for the regulator that fines them.

Who lobbied the statute into being is a contested ledger. The Foundation for Freedom Online — a project of former State Department official Mike Benz, and a partisan participant in this fight — documents 23 US-government-funded organizations that it says lobbied for the DSA and now help enforce it. That is FFO’s accounting, attributed as such; the Commission’s own accounting is that the DSA answered years of platform scandals and member-state fragmentation. Both accounts are on the record. What is not contested is that the flagging layer is substantially government-funded: Germany’s first designated trusted flagger, the REspect! reporting office, receives roughly 95 percent of its funding from the federal “Demokratie Leben” programme — a figure put on the parliamentary record in a written question to the Commission. A government-funded NGO, designated by a government agency, whose reports receive priority treatment from platforms under a government statute.

Institutional Voice & Intent

The voice is the harmonization register — the grammar of “a safe, predictable and trusted online environment,” of risk assessments and transparency reports and statements of reasons. The statute speaks in process, and the process is real: removal decisions must be explained, users can appeal, and the Commission’s own two-year report counts roughly 50 million moderation decisions appealed through DSA channels with about 30 percent reversed — which the Commission presents as the accountability machinery working, and which is, on its face, the strongest evidence anyone has offered that it sometimes does.

Stated intent: Harmonize the rules for intermediaries across 27 member states; make platforms accountable for illegal content; give users transparency and appeal rights; protect elections, minors, and public health from systemic platform risks.

Observed intent: Hold the fine authority over the world’s largest speech platforms in a single supranational regulator; convert content moderation into a compliance discipline whose categories — “illegal content,” “disinformation,” “systemic risk” — are defined and expanded by the regulator holding the fine; and export the result globally, since platforms build one system for their largest regulated market. The legal literature calls this the Brussels Effect, and the Commission does not dispute it; it advertises it.

Gap: The stated and observed intents overlap wherever “illegal content” means the unarguable cases — the CSAM, the terrorist livestream. The gap opens at the elastic categories. “Systemic risk” is not a defined harm; it is a framework a regulator interprets, and the observed enforcement history runs in one direction: the first formal proceedings (X, December 2023) covered risk management, dark patterns, ad transparency, and researcher data access; by January 2026 the same statute reached an AI chatbot’s image generator — a case brought under the DSA precisely because the AI Act’s own enforcement teeth had not yet engaged. The statute built for platform moderation became, within two years, the Union’s available instrument for regulating generative AI outputs. Nothing in that expansion was unlawful. That is the point of building it as a statute.

Position in the Apparatus

The DSA is the load-bearing statute of the European wing of the apparatus this file documents. Its trusted-flagger lane institutionalizes what the American wing did informally — the Twitter Files documented flags moving from government-adjacent bodies to platforms by email and portal; Article 22 gives the same flow a legal basis, a designation procedure, and a priority queue. Its systemic-risk framework is the template other jurisdictions cite. Its fine authority is what the informal American system never had, which is why the enforcement gravity has shifted to Brussels: the flagging machine’s American nodes spent 2023–2025 under subpoena, while the European node acquired statutory teeth, a public budget, and a fee stream from the platforms it supervises. The personal enforcement face of the statute’s first years, Thierry Breton, has his own file; the statute survived his exit without slowing, which is the difference between a man and a rulebook.

Actions & Leadership Choices

Founding purpose, judged on evidence. The DSA answered real failures — the platforms’ own transparency reports, the Christchurch livestream, the takedown chaos of 27 divergent national regimes. As harmonization it is genuine: one rulebook now replaces a patchwork, and the appeal-and-reversal machinery it created processes complaints at a scale no platform voluntarily offered before. The due process is not decorative. Fifty million appeals with a thirty-percent reversal rate is a functioning correction layer, and this file records it as one.

The enforcement record, where the conduct shows. The record to date runs through one platform. The Commission opened its first DSA formal proceedings against X in December 2023. In December 2025 it issued its first fine — 120 million euros — and the charges are worth stating precisely, because both sides of the litigation rest on them: deceptive design of the blue checkmark, insufficient transparency of the ads repository, and failure to provide researchers access to public data. Verification plumbing and transparency, on the Commission’s own framing — not speech. In February 2026 X filed the first legal challenge ever brought against a DSA fine, arguing prosecutorial bias and extraterritorial consequences for speech. The litigation is live and unresolved; X’s characterization and the Commission’s travel together here, and this file asserts neither. What the file does assert is the selection effect visible on the surface of the record: fourteen investigations open across the sector, and the first fine landed on the platform whose owner spent three years publicly defying the statute’s enforcement face.

The counter-move, on the record. In December 2025 the United States imposed visa bans on five Europeans it accused of censoring Americans — including the DSA’s own former enforcement commissioner, whom the coverage called the statute’s “mastermind,” and the leaders of three flagging organizations. Secretary of State Marco Rubio’s stated grounds: they “have led organised efforts to coerce American platforms to censor, demonetise, and suppress American viewpoints they oppose.” France and the Commission called the bans intimidation and coercion. For the first time, the cost of operating Europe’s content-control machinery was imposed on named operators personally, by another government — the apparatus and the counter-apparatus now sanction each other’s staff. Both characterizations are on the record; the escalation itself is the documented fact.

CONDUCT verdict: STATUTE-INSTRUMENT — DUE PROCESS ON PAPER, ONE-WAY IN PRACTICE. A real harmonization statute with a functioning appeal layer, whose elastic risk categories, government-funded flagging lane, and fine-backed incentives push platforms toward over-removal as the safe default — and whose documented enforcement history expands in one direction, from platform process into generative AI, without ever needing to amend the text.

Reach Assessment

Institutional: Maximum within its class. The DSA is the enforcement template of the democratic world’s content-control architecture — statutory where the American system was informal, funded where the NGOs are grant-dependent, and permanent where commissioners are temporary. The UK’s Online Safety Act and successor regimes elsewhere are read against it.

Memetic: High. The Brussels Effect is the memetic mechanism in legal form: platforms build one compliance system for their largest regulated market, and the EU’s categories — systemic risk, trusted flagger, statement of reasons — become the vocabulary in which every jurisdiction’s moderation debate is now conducted, including in countries that never voted on it.

Civilizational: High. The statute does not build AI systems and does not write their refusals. It built the legal machinery that decides what the platforms carrying those systems must remove, on pain of six percent of global turnover — and its first reach into generative AI arrived in January 2026, under the old statute, before the new one’s teeth were in. The recurring lesson of this file’s drawer, in statutory form: the capability is built first, the category expands later, and a rulebook never resigns.


Sources: Regulation (EU) 2022/2065 — EUR-Lex; The Digital Services Act — European Commission; Trusted flaggers under the DSA — European Commission; Parliamentary question E-002057/2024 — ‘REspect!’ trusted flagger — European Parliament; Article 22 Digital Services Act: Building trust with trusted flaggers — Internet Policy Review; Two years of DSA — 50 million content moderation decisions appealed — European Commission; Commission opens formal proceedings against X under the DSA, 18 Dec 2023 — European Commission; Commission fines X €120 million under the Digital Services Act — European Commission; X challenges €120M fine under EU censorship law — ADF International (supports the challenge; characterization attributed); The EU’s fine against X is not about speech or ‘censorship’ — TechPolicy.Press (defense side); US-funded censorship hubs drive EU’s war on tech companies — Foundation for Freedom Online (partisan participant; attributed); The Digital Services Act and the Brussels Effect — Chicago Journal of International Law; EU probes Musk’s Grok AI feature over deepfakes — Al Jazeera, 26 Jan 2026; US bans visas for ex-EU commissioner over alleged censorship — CNBC, 24 Dec 2025.

RCH 9 REACH
FND 9 FUNDING
ENT 9 ENTRENCHMENT
OLYMPUS RISK INTELLIGENCE PROTOCOL does not exist. It was assembled in a GitHub issue thread in October 2023 by engineers who had read the extinction risk letter and wanted to understand who specifically had signed a document saying AI might kill everyone and then continued working on AI. These dossiers are satire. The biographical facts cited are sourced from published reporting, public statements, academic papers, and court records. The psychometric scores are not clinical assessments. No part of this constitutes professional psychological evaluation or diagnosis. Do not use these dossiers to make decisions about anything.