DSA Scope and Digital Services Coverage
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal β legal information, not advice.The content is from the DSA (Digital Services Act), not the AI Act. A dedicated topic for DSA scope is needed to distinguish it from AI Act scope provisions and to properly categorize DSA-specific regulatory coverage.
Overview
9 sources Β· Jul 23, 2026Legal Framework
The DSA establishes a tiered regulatory architecture that scales obligations based on the nature, type, and size of the intermediary service provided. Recital 41 articulates the core design principle: due diligence obligations must be adapted to the specific category of service. The Regulation therefore distinguishes between four escalating tiers of providers, each attracting progressively heavier obligations.
At the base level, Article 2 brings all "intermediary services" within scope β encompassing mere conduit, caching, and hosting services as defined under Article 3. Recital 29 illustrates the breadth of this category, expressly identifying internet exchange points, wireless access points, VPNs, DNS services and resolvers, top-level domain name registries, registrars, certificate authorities, and VoIP services as falling within mere conduit. Hosting services attract additional obligations, and online platforms β a subset of hosting services that store and disseminate information to the public at the recipient's request β face a further layer of requirements. At the apex, very large online platforms (VLOPs) and very large online search engines (VLOSEs), defined as those reaching 45 million average monthly active users in the EU, bear the most stringent obligations.
Article 15 imposes transparency reporting duties on all providers of intermediary services, requiring periodic publication of reports on content moderation activities. Article 4 carves out specific exclusions, notably for services subject to the AI Act's scope and certain sectoral regimes, which is critical for delineating DSA coverage from overlapping regulatory frameworks.
Key Developments
The Commission's designation of the first cohort of VLOPs and VLOSEs in April 2023 β including major platforms and search engines β established the practical threshold for the highest tier of obligations. Designations turned on self-reported user metrics, and subsequent enforcement has scrutinized whether providers accurately calculate their EU recipient numbers.
Early enforcement signals have focused on transparency reporting compliance under Article 15, with the Commission issuing formal proceedings against designated VLOPs for inadequate risk assessment methodologies under Article 34 and insufficient mitigation measures under Article 35. The Digital Services Coordinators, designated by Member States under Article 36, have begun exercising supervisory powers over non-VLOP providers, creating a bifurcated enforcement landscape where the Commission handles VLOPs/VLOSEs and national authorities handle all others.
Practical Guidance
Classify your service accurately at the outset. Determine whether your offering constitutes mere conduit, caching, hosting, or an online platform under Article 3 definitions, as this classification determines your entire obligation set. Misclassification carries significant enforcement risk.
Calculate EU recipient numbers systematically. If your service approaches 45 million average monthly active EU users, establish robust measurement methodologies under Article 33(2), as this figure triggers VLOP/VLOSE designation and the associated obligations including systemic risk assessments and independent audits.
Implement Article 15 transparency reporting from day one. All intermediary service providers must publish annual reports detailing content moderation decisions, including numbers of orders acted on and categories of restrictions applied. Non-compliance with transparency obligations has been an early enforcement priority.
Map overlaps with adjacent regimes. Article 4 exclusions and recital language must be analyzed alongside the AI Act, GDPR, and sectoral legislation to identify where the DSA does not apply and where multiple regimes converge, particularly for services combining AI-driven content moderation with intermediary functions.
Establish a compliance governance structure calibrated to your tier. VLOPs require dedicated compliance officers and independent audit arrangements, while smaller providers can adopt proportionate measures β but all tiers must document their risk mitigation approach to demonstrate accountability to the relevant Digital Services Coordinator.