Recent debate over whether a conversational AI product can also be regulated like search highlights a durable lesson: online services are judged by what they do, not only by what they call themselves. The Digital Services Act is one lens for that judgment, focused on platform behavior, user safety, transparency, and systemic risk.

Why this matters now

The Digital Services Act, or DSA, is a European framework for governing online intermediary services such as hosting providers, platforms, marketplaces, social networks, and search services. Its core idea is simple: services that connect people to information, goods, or other users can create public harms at scale, so they need accountable systems for managing those harms.

For AI and tech teams, the important shift is from policy as paperwork to policy as product architecture. A service may have multiple regulated behaviors inside one interface. A chatbot might generate text, retrieve web information, rank sources, host user content, or recommend content. Each behavior can trigger a different compliance question.

That is why the DSA matters alongside AI specific regulation. AI rules often focus on model risk, intended use, training, outputs, and human oversight. The DSA focuses on online service functions: content moderation, recommender systems, advertising transparency, trader traceability, complaint handling, and systemic risk. One product can need both maps.

How it works

The DSA starts by classifying the service function. A simple hosting service has fewer obligations than a large platform or search service with broad public reach. As scale and societal impact increase, obligations become more demanding, especially around risk assessment, mitigation, independent review, data access for oversight, and transparency reporting.

@title DSA risk cycle
  Service behavior ·························
     │
     ▼
  Service classification ··················
     │
     ▼
  Systemic risk assessment ················
     │
     ▼
  Mitigation and transparency ·············
     │
     ▼
  Audit and oversight ·····················
@caption Service behavior drives scope risk assessment mitigation and audit

The mechanism is risk based. First, identify what the product does: host content, surface recommendations, enable search, sell goods, display ads, or moderate user posts. Second, determine the service category and applicable duties. Third, assess foreseeable risks, such as illegal content, manipulation, harm to minors, discrimination, public security threats, or integrity risks around civic processes. Fourth, implement controls and explain them clearly to users and regulators.

Controls are not only legal notices. They can include reporting channels, appeal processes, moderation workflows, recommender system settings, ad libraries, age appropriate design, incident response, internal escalation, logging, and governance signoff before high impact launches.

The transferable skill is feature based scoping. Do not ask only, “Is this an AI product?” Ask, “Which regulated functions are present, who is affected, what can go wrong at scale, and how would we prove we managed it?”

Real-world applications

A product manager launching web connected answers should map where retrieval, ranking, source presentation, and generated explanation happen. The search like layer may need transparency and systemic risk controls even if the conversational layer is assessed under AI governance.

A marketplace team should connect product design to seller verification, illegal product reporting, user appeals, and risk monitoring. A recommender team should document how ranking choices affect users, whether users can understand or influence those choices, and how harmful amplification is detected.

A trust and safety leader should treat the DSA as an operating model: policies, tools, metrics, audits, escalation paths, and product change reviews. The goal is not merely to avoid penalties. It is to make high scale digital services legible, contestable, and safer to operate.

Where to go deeper

Build a DSA inventory by feature, not by org chart. List hosting, search, recommendation, advertising, marketplace, and moderation functions. For each, record user impact, risk owners, controls, evidence, and open questions.

Then compare that inventory with your AI governance map. Where AI generates, predicts, personalizes, ranks, or automates decisions, examine both the model risk and the platform risk. The strongest teams maintain separate but connected risk maps, because the same product can create different legal and operational duties through different behaviors.