Digital Services Act (DSA)
DSA applies to your AI system if it touches user-generated content, recommender logic, or platform distribution. Most product teams haven’t mapped it.

How DSA works for AI products
The Digital Services Act has fully applied since 17 February 2024. It covers every provider of intermediary services offering services to recipients in the EU — hosting providers, online platforms, online marketplaces, search engines, and app stores — and reaches designated Very Large Online Platforms and Very Large Online Search Engines (VLOPs/VLOSEs) under a stricter tier of obligations from the point of their Commission designation.
If your AI system powers a recommender feed, moderates or ranks user content, screens listings on a marketplace, or is embedded in a platform’s public-facing product, DSA reaches you — whether or not you are established in the EU and whether or not you consider yourself a “platform.”
DSA’s core demand is accountability for how a service shapes what users see and who they can reach. For AI systems this creates specific obligations around recommender system transparency, automated content moderation reporting, and — for VLOPs/VLOSEs — systemic risk assessment of algorithmic amplification.
These obligations sit alongside and increasingly overlap with EU AI Act transparency rules, particularly since the Digital Omnibus brought AI systems embedded in VLOPs/VLOSEs under direct AI Office oversight.
DSA Compliance Assessment for Your AI System
Fixed price · Named lawyer · AI and platform specific · Delivered in 5 working days
DSA and Your AI Product

DSA organises its obligations in tiers, each layered on top of the last. Each tier creates specific obligations for AI systems used in or supplied to in-scope services.
Baseline due diligence
Every intermediary service — mere conduit, caching, or hosting — must maintain a single point of contact, publish clear terms and conditions, and report annually on content moderation activity.
Where AI performs any part of that moderation, the reporting obligation extends to it: the service must state that automated means were used and describe them in general terms.
Notice-and-action and hosting obligations
Hosting services, including platforms built on AI-driven storage and distribution, must run a notice-and-action mechanism for illegal content and give a statement of reasons for removals or restrictions. Where an AI system makes or materially informs that removal decision, the statement of reasons must say so.
Online platform obligations
Platforms that store and disseminate information to the public — most consumer-facing AI products with a public feed or output stream fall here — carry additional duties: an internal complaint-handling system, access to out-of-court dispute settlement, priority handling for trusted flaggers, measures against abusive notices, a ban on dark patterns, protections for minors, and, critically, recommender system transparency.
Where an AI-driven recommender selects or ranks content, the platform must explain the main parameters in plain language and offer at least one option not based on profiling.
Online marketplace obligations
Marketplaces using AI to screen, rank, or recommend third-party listings carry trader traceability duties on top of the platform tier — know-your-business-customer checks, random compliance sampling, and design that lets the marketplace flag illegal products before an AI recommender surfaces them to consumers.
VLOP and VLOSE obligations
Platforms and search engines designated by the Commission at 45 million or more average monthly active recipients in the EU face the heaviest tier: annual systemic risk assessments covering algorithmic amplification and recommender design, independent third-party audits, a crisis response mechanism, vetted-researcher access to data including about the AI systems involved, and an advertising repository.
Since the Digital Omnibus entered into force on 27 July 2026, AI systems that constitute or are embedded in a VLOP or VLOSE also fall under direct AI Office supervision, layered on top of DSA’s own enforcement.
Who DSA Applies to
DSA applies directly to intermediary service providers offering services to recipients in the EU, regardless of where they are established. AI companies frequently find themselves in scope as the provider of the platform itself, or indirectly bound through a platform client’s DSA obligations, without having identified either.
| Entity type | In scope? | Key obligation |
|---|---|---|
| Social media or content-sharing platform | Yes — as online platform | Recommender transparency, notice-and-action, trusted flaggers, minor protection |
| Online marketplace | Yes — as online platform + marketplace | All platform obligations plus trader traceability |
| Search engine (general use) | Yes — as intermediary/platform tier depending on function | Notice-and-action, transparency reporting |
| Cloud or hosting provider with no public dissemination function | Yes — baseline hosting tier only | Notice-and-action mechanism, statement of reasons |
| Interpersonal communication service (email, private messaging) | No — excluded from the online platform definition | Not applicable |
| AI chatbot or assistant offered directly to the public | Contested — depends on whether it stores and disseminates information to the public at a recipient’s request | Case-by-case. Treat as in scope until assessed. |
| AI company supplying a recommender or moderation system to a platform | Indirectly — not a direct DSA obligee unless it is itself the platform | Contractual and technical support for the platform client’s DSA compliance |
| VLOP or VLOSE designated by the Commission (45M+ EU users) | Yes — full VLOP/VLOSE tier | Systemic risk assessment, independent audit, researcher data access, AI Office oversight of embedded AI |
| Company with no EU users and no service offered to the EU | No | Document the determination |
Recommender and Moderation Supply Chains: the DSA Obligation AI Suppliers Miss
DSA’s transparency obligations attach to the platform, not automatically to the AI vendor behind the recommender or moderation system. That does not remove the AI supplier from the picture — it shifts the exposure into the contract.
A platform cannot discharge its Article 27 recommender transparency duty or its Article 15 moderation reporting duty without technical detail the AI vendor holds. Every AI supplier to a platform, marketplace, or VLOP/VLOSE inherits a de facto DSA obligation through that contract, whether or not the vendor is itself regulated.
Three things AI suppliers to platforms consistently misunderstand:
DSA requires platforms to explain the main parameters of any AI-driven recommender system in plain, non-technical language, and to offer a non-profiling alternative. If your recommender system doesn’t expose those parameters or support a non-profiling mode, your platform client cannot comply, and the commercial relationship is under pressure at the next regulator review.
VLOPs and VLOSEs face mandatory independent audits covering the design and function of the algorithmic systems they deploy, including AI recommenders and moderation tools supplied by third parties. Auditors will ask the AI vendor for documentation directly. AI companies that cannot produce it on request become the reason their client’s audit fails.
Vetted researcher access is mandatory for VLOPs and VLOSEs under Article 40, and it reaches data generated by the AI systems embedded in the platform. AI suppliers that build systems without any capacity for structured data export create compliance problems for their clients and commercial risk for themselves.
What DORA compliance requires for AI products
These are the DSA requirements that apply most directly to AI products used in or supplied to platforms, marketplaces, and search engines in scope:
Recommender transparency documentation — a plain-language explanation of the main parameters your AI recommender uses to rank or select content, plus a working non-profiling alternative, satisfying Article 27 of the Digital Services Act.
Automated moderation transparency — disclosure of the automated means used in content moderation decisions, including indicative accuracy and error rate information, satisfying Articles 15 and 24 reporting duties.
Notice-and-action integration — your AI system’s outputs and decisions must be traceable into the platform’s notice-and-action mechanism, so a statement of reasons can name the automated system that acted.
Dark pattern review — your interface and any AI-personalised design elements must be assessed against DSA’s prohibition on manipulative design that materially distorts user decision-making.
Minor protection measures — where the AI system is accessible to minors, default settings and design choices must meet DSA’s heightened protection standard, distinct from and additional to GDPR’s own rules on children’s data.
Ad repository support — where the AI system serves or personalises advertising on a platform, the underlying targeting parameters must be exportable into the platform’s public advertising repository.
Systemic risk input — for AI systems embedded in a VLOP or VLOSE, a documented contribution to the platform’s annual systemic risk assessment covering algorithmic amplification, and readiness for independent audit and AI Office review.
Sub-processor and AI supply chain mapping — identification and documentation of every AI component your product depends on that feeds into a platform’s recommender, moderation, or ranking function, with clarity on which party holds which Digital Services Act obligation.
One engagement. Every DSA obligation mapped for your AI system.
A lawyer-built assessment of your AI system’s DSA obligations — recommender transparency documentation, automated moderation reporting framework, notice-and-action integration review, dark pattern and minor protection audit, VLOP/VLOSE systemic risk input where relevant, and a documented compliance record your platform clients and their regulators can rely on.
Frequently Asked Questions About DSA Compliance
What is DSA and who does it apply to?
The Digital Services Act is an EU regulation that has fully applied since 17 February 2024. It applies to providers of intermediary services offering services to recipients in the EU, regardless of where the provider is established.
In-scope services include hosting providers, online platforms, online marketplaces, and search engines, with an additional tier of obligations for Very Large Online Platforms and Very Large Online Search Engines designated by the Commission at 45 million or more average monthly active EU recipients.
Does the DSA apply to AI companies that are not platforms themselves?
Indirectly, yes, if they supply recommender systems, moderation tools, or ranking logic to a platform. The platform carries the direct DSA obligation, but it cannot discharge that obligation — recommender transparency, moderation reporting, audit readiness — without technical detail only the AI vendor holds.
This dependency creates a contractual DSA obligation for the vendor even where the vendor is not itself a regulated intermediary service.
What is the difference between the DSA and the EU AI Act for platform AI?
The DSA governs how a service’s design and algorithms affect users — content moderation, recommender transparency, systemic risk from amplification, and platform accountability. The EU AI Act governs the AI system itself — risk classification, technical documentation, and conformity assessment.
For AI embedded in a VLOP or VLOSE, both now apply simultaneously and under overlapping enforcement: the Digital Omnibus, in force since 27 July 2026, brought AI systems constituting or embedded in a VLOP or VLOSE under direct AI Office supervision on top of DSA’s own enforcement route. A cross-framework assessment maps both against the same product.
What is a Very Large Online Platform or Very Large Online Search Engine under the DSA?
A VLOP or VLOSE is a platform or search engine formally designated by the European Commission once it reaches an average of 45 million or more monthly active recipients in the EU, roughly 10% of the EU population.
Designation triggers the DSA’s heaviest tier: annual systemic risk assessments, independent third-party audits, vetted-researcher data access, an advertising repository, and a crisis response mechanism.
AI systems that become central to a platform’s growth may push it toward that threshold without the platform having planned for the obligations that follow.
What happens when an AI vendor supplies a recommender or moderation system to a platform?
The platform remains the direct DSA obligee, but it typically pushes technical and documentary requirements down into the vendor contract: parameter transparency for recommenders, accuracy and error-rate data for moderation tools, and audit cooperation for VLOPs and VLOSEs. Vendors that cannot produce this on request become the reason their client fails a regulatory review, which is a commercial risk even without direct DSA liability.
What are the DSA’s transparency and reporting requirements relevant to AI?
Article 15 and Article 24 require annual transparency reports disclosing the use of automated means in content moderation, including indicative information on accuracy and error rates. Article 27 requires platforms using AI-driven recommender systems to set out the main parameters in plain language and to offer at least one non-profiling option.
VLOPs and VLOSEs face additional systemic risk reporting under Article 34 covering algorithmic amplification specifically.
Does the DSA apply to non-EU AI companies whose products are used on EU platforms?
Yes. The DSA applies to intermediary services offered to recipients in the EU regardless of where the provider is established. A non-EU AI company supplying a recommender or moderation system that feeds an EU-facing platform is inside the same practical exposure as an EU-established supplier, through the platform’s own DSA obligations and the contract that follows from them.
How does the DSA interact with the AI Act for platform AI specifically?
Where an AI system is embedded in or constitutes a VLOP or VLOSE, both regimes apply and, since the Digital Omnibus, both are enforced with AI Office involvement alongside the DSA’s Digital Services Coordinators and the Commission. Recommender transparency under DSA Article 27 and transparency obligations under AI Act Article 50 frequently address the same system from different angles — one from a platform-accountability lens, one from an AI-system lens — and a cross-framework assessment identifies where one satisfies the other and where they don’t.
What are the penalties for DSA non-compliance?
Penalties can reach up to 6% of a provider’s total worldwide annual turnover for the preceding financial year, with lower caps for supplying incorrect or misleading information to regulators. For VLOPs and VLOSEs, the Commission enforces directly; for other providers, enforcement runs through the national Digital Services Coordinator.
The commercial consequence for AI suppliers — a platform client that cannot integrate a vendor’s system without breaching its own DSA obligations — often forces the issue before any fine does.
How do I start DSA compliance for my AI system?
Four steps in order. First, determine whether your AI system functions as, or is embedded in, a service offered to EU recipients — hosting, platform, marketplace, or search engine — and whether that service is VLOP/VLOSE designated.
Second, map every recommender, ranking, or moderation function your AI system performs against Articles 15, 24, and 27.
Third, assess your interface and default settings against the dark pattern and minor protection rules.
Fourth, if you supply a platform client rather than operate one, review your contract for the DSA-driven transparency and audit-cooperation terms your client needs from you.
A lawyer-built assessment covers all four steps and delivers a documented compliance position specific to your system and your platform relationship.
