The European Board for Digital Services (EBDS), in co-operation with the European Commission, has published its second annual report on systemic risks and mitigation measures under the EU Digital Services Act (DSA). The report examines systemic risks across very large online platforms (VLOPs) and very large online search engines (VLOSEs), with a particular focus on risks affecting children and young people. These include the dissemination of illegal content and the impact of platform design choices, such as interface features, recommender systems, infinite scroll and autoplay, which may contribute to addiction-like behaviour. The report also highlights minors’ exposure to harmful or age-inappropriate content, including dangerous viral challenges and adult material, as well as harmful conduct such as cyberbullying, grooming, sextortion and the dissemination of child sexual abuse material (CSAM). It additionally notes that generative artificial intelligence (AI) tools may aggravate risks to minors, including through sexualised deepfakes, AI-generated CSAM and harmful chatbot interactions. It outlines mitigation measures reported by VLOPs and VLOSEs, including targeted child-protection measures such as age assurance, safer default settings for minors, parental controls, limits on certain features, CSAM detection tools, content warnings, easier reporting mechanisms and tools giving users greater control over their online experience. The report further notes that the EU DSA risk-management framework remains at an early stage, and that the EBDS does not yet identify any measures as ‘best practice’. The Commission stated that it will continue monitoring EU DSA implementation.