Assessing Compliance for Generative AI Systems under the Digital Services Act
Marie Therese Sekwenz (TU Delft - Technology, Policy and Management)
Rita Hermann-Gsenger (Weizenbaum Institut)
Shreyan Biswas (TU Delft - Electrical Engineering, Mathematics and Computer Science)
Ujwal Gadiraju (TU Delft - Electrical Engineering, Mathematics and Computer Science)
More Info
expand_more
Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.
Abstract
Generative AI systems such as ChatGPT are increasingly embedded into online services that shape information access, content creation, and user decision-making at scale. This raises a timely governance question for European digital regulation: how should large language model (LLM) services be assessed under the Digital Services Act (DSA), and what would compliance auditing require if such services qualify as Very Large Online Platforms or Search Engines (VLOPs/VLOSEs)? While the DSA’s oversight regime was designed around platform-era risks—such as user-generated content, recommender systems, and notice-and-action pipelines—LLM services express many compliance-relevant decisions through interactive safeguards, including refusals, safety warnings, and guardrail-driven output constraints. These features create new auditing challenges around reproducibility, transparency of enforcement logic, and the evaluation of model-generated content pathways. In this position paper, we analyse different forms of generative AI including ChatGPT-style services within DSA compliance structures and how generative AI reshapes assessment and, mitigation practices particularly in interaction with the AI Act. We outline a DSA-anchored testing perspective that maps core legal obligations to LLM-tailored audit considerations and structured prompt-based evaluation strategies. Finally, we clarify key intersections between the DSA and the AI Act, showing how service-level systemic risk assessment (Art. 34 DSA) and model-level governance obligations under the AI Act (e.g., Art. 3(66)) interact in practice. We argue that effective oversight of generative AI-infused services requires prompt- and risk-based systemic assessment and independent audit designs that draw on multiple compliance signals rather than solely traditional moderation metrics.