The Digital Services Act's AI-Generated Content Duties
10 min read · updated August 11, 2026
The DSA is usually described as a content moderation regulation, which is true and unhelpful. Only a handful of its provisions name generated or manipulated content, they apply to a specific and short list of services, and they do something different from the AI Act’s labelling rules. Those are the provisions worth knowing precisely.
Who the AI-specific duties apply to
Regulation (EU) 2022/2065 entered into force on 16 November 2022 and has applied in full since 17 February 2024; the text is on EUR-Lex at ELI reg/2022/2065. Its obligations are tiered. Everything in Chapter III Section 5 — the systemic risk provisions, and with them every duty that mentions synthetic content — applies only to very large online platforms and very large online search engines, designated by the Commission on the basis of at least 45 million average monthly active recipients in the Union. Designations began on 25 April 2023.
So a mid-sized platform hosting AI-generated images has no DSA marking duty at all. It has the notice-and-action, statement-of-reasons and trader-traceability duties that apply to hosting services and online platforms generally, and nothing synthetic-media-specific. Getting this tier boundary wrong in either direction is the most common error in compliance summaries of the DSA.
The Article 35 marking duty
Article 35(1) requires designated services to put in place reasonable, proportionate and effective mitigation measures against the systemic risks identified under Article 34, and gives a non-exhaustive list. One item on that list — Article 35(1)(k) — is the synthetic media provision.
It concerns an item of information that constitutes a generated or manipulated image, audio or video, appreciably resembling existing persons, objects, places, entities or events, and falsely appearing to a person to be authentic or truthful. Where such an item is presented on the service’s online interfaces, the measure is to ensure it is distinguishable through prominent markings, and in addition to provide an easy-to-use functionality allowing recipients to indicate that information is of that kind.
Three features of that drafting are load-bearing. It is not a flat prohibition and it is not an unconditional obligation: it is an item in a list of possible mitigation measures, applied where appropriate to the risks the service identified. It reaches image, audio and video — not text, which is a deliberate limit. And it imposes a user-reporting route as well as a marking route, which means the compliance artefact is partly a product feature rather than only a detection model.
AI features trigger a fresh risk assessment
Article 34 requires designated services to diligently identify, analyse and assess systemic risks stemming from the design, functioning and use of their services, including the dissemination of illegal content, negative effects on fundamental rights, on civic discourse and electoral processes, and on public health and minors. Article 34(2) directs attention to the algorithmic systems involved, naming recommender and content moderation systems.
The clause integrators miss is the timing one: the assessment must be carried out before deploying functionalities likely to have a critical impact on the risks identified. Adding a generative image tool, an AI assistant or a synthetic-voice feature to a designated platform is such a deployment, and the assessment is due before launch rather than in the next annual cycle.
The Commission has also issued guidelines under Article 35(3) on mitigating systemic risks to electoral processes, adopted 26 March 2024, which set out generative-AI-specific expectations including labelling of synthetic political content and coordination during election periods. Guidelines are not binding rules; departing from them is permitted but must be justified, and in an enforcement conversation the burden of that justification sits with the platform.
Moderating with AI is separately regulated
The second AI dimension of the DSA points the other way: the platform’s own use of models to moderate. These duties apply far more widely than the VLOP tier.
- Statements of reasons must disclose automation. Article 17 requires a provider restricting content to give the affected recipient a statement of reasons that includes whether the decision was taken using automated means, and these statements are published in the DSA Transparency Database.
- Transparency reports must quantify it. Article 15 requires reporting on content moderation carried out at the provider’s own initiative, including use of automated tools, with indicators of accuracy and the possible rate of error, broken down by type of illegal content or breach of terms.
- Complaints cannot be resolved solely by machine. Article 20 requires internal complaint-handling decisions to be taken under the supervision of appropriately qualified staff and not solely on the basis of automated means.
The accuracy-and-error-rate requirement in Article 15 is the sharpest of these, because it obliges a platform to publish a number about its own classifier. A provider that cannot say what its moderation model’s error rate is has a reporting problem before it has a moderation problem.
What the DSA does not do
It does not regulate the generator. The duty to mark synthetic output at the point of creation, in a machine-readable form, comes from Article 50 of the AI Act and falls on providers and deployers of the generating system — the deepfake labelling duty and the machine-readable marking duty cover that side. The DSA duty is a platform display duty, and the two are designed to interlock: a marking embedded at generation is what makes a platform’s display marking feasible at scale.
It also does not change the liability position for hosted content. The conditional exemptions for mere conduit, caching and hosting in Articles 4 to 6 carry over from the e-Commerce Directive and are untouched by the synthetic-media provisions; there is no general monitoring obligation, under Article 8, and a marking duty is not a duty to detect everything. And it creates no individual right to have a specific piece of AI-generated content removed. Enforcement runs through the Commission and the national Digital Services Coordinators, not through a private claim.