Assessing Compliance for Generative AI Systems under the Digital Services Act

Journal Article (2026)
Author(s)

Marie Therese Sekwenz (TU Delft - Technology, Policy and Management)

Rita Hermann-Gsenger (Weizenbaum Institut)

Shreyan Biswas (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Ujwal Gadiraju (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Research Group
Organisation & Governance
More Info
expand_more
Publication Year
2026
Language
English
Research Group
Organisation & Governance
Journal title
CEUR Workshop Proceedings
Volume number
4266
Event
2026 ACM IUI Workshops, IUI-WS 2026 (2026-03-23 - 2026-03-26), Paphos, Cyprus
Page Views
1
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

Generative AI systems such as ChatGPT are increasingly embedded into online services that shape information access, content creation, and user decision-making at scale. This raises a timely governance question for European digital regulation: how should large language model (LLM) services be assessed under the Digital Services Act (DSA), and what would compliance auditing require if such services qualify as Very Large Online Platforms or Search Engines (VLOPs/VLOSEs)? While the DSA’s oversight regime was designed around platform-era risks—such as user-generated content, recommender systems, and notice-and-action pipelines—LLM services express many compliance-relevant decisions through interactive safeguards, including refusals, safety warnings, and guardrail-driven output constraints. These features create new auditing challenges around reproducibility, transparency of enforcement logic, and the evaluation of model-generated content pathways. In this position paper, we analyse different forms of generative AI including ChatGPT-style services within DSA compliance structures and how generative AI reshapes assessment and, mitigation practices particularly in interaction with the AI Act. We outline a DSA-anchored testing perspective that maps core legal obligations to LLM-tailored audit considerations and structured prompt-based evaluation strategies. Finally, we clarify key intersections between the DSA and the AI Act, showing how service-level systemic risk assessment (Art. 34 DSA) and model-level governance obligations under the AI Act (e.g., Art. 3(66)) interact in practice. We argue that effective oversight of generative AI-infused services requires prompt- and risk-based systemic assessment and independent audit designs that draw on multiple compliance signals rather than solely traditional moderation metrics.