Used Services and Cookies

Our website uses cookies to enhance your user experience. Some cookies are essential for the operation and management of the site, while others are used for anonymous statistics or personalized content. Please note that limiting cookie use may impair certain functions of the website.

More information: Imprint, Data protection

Essential cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website or, for example, saving your cookie settings. The website cannot function properly without these cookies. This category cannot be deactivated.
  • Name:
    ukie_a_cookie_consent_manager
  • Domain:
    blomstein.com
  • Purpose:
    Stores the cookie preferences of website visitors.
  • Name:
    blomstein_session
  • Domain:
    blomstein.com
  • Purpose:
    The session cookie is essential for the basic functioning of the website. It allows users to navigate through the site and use its basic features.
  • Name:
    XSRF-TOKEN
  • Domain:
    blomstein.com
  • Purpose:
    This cookie serves security purposes and aids in preventing Cross-Site Request Forgery (CSRF) attacks. It is a technical necessity.
These cookies collect information about how you use a website, e.g. which pages you have visited and which links you have clicked on.
  • Name:
    _ga
  • Domain:
    blomstein.com
  • Purpose:
    The Google Analytics cookie _ga is used to distinguish users by assigning a unique identification number to each visitor. This number is sent to Google Analytics each time a page is accessed in order to collect user, session and campaign data and to statistically evaluate the use of the website. The cookie helps website operators to understand how visitors interact with the website by collecting information anonymously and generating reports.
  • Name:
    _ga_*
  • Domain:
    blomstein.com
  • Purpose:
    The _ga_[container_id] cookie, specific to Google Analytics 4 (GA4), is used to distinguish website visitors by assigning a unique ID for each session and each user. It enables the collection and analysis of data on user behavior on the website in anonymized form. This includes tracking page views, interactions and the path users take on the website to give website operators deeper insights into the use of their site and improve the user experience.
  • Name:
    _gid
  • Domain:
    blomstein.com
  • Purpose:
    The _gid cookie is a cookie set by Google Analytics that is used to distinguish users. It assigns a unique identification number to each visitor to the website, which is sent to Google Analytics each time the page is accessed. This makes it possible to track and analyze user behavior on the website over a period of 24 hours.
  • Name:
    _gat_gtag_UA_77241503_1
  • Domain:
    blomstein.com
  • Purpose:
    The _gat_gtag_UA_77241503_1 cookie is part of Google Analytics and Google Tag Manager and is used to throttle the request rate, i.e. it limits data collection on high traffic websites. This cookie is linked to a specific Google Analytics property ID (in this case UA-77241503-1), which means that it is used for performance monitoring and control of data collection for that specific website property.

Search Me

Why LLM Providers Should Care About the DSA

7 September 2026

On the last day of August, the European Commission designated ChatGPT, Reddit and Roblox under the Digital Services Act (DSA). Reddit and Roblox were designated as Very Large Online Platforms (VLOPs) – notable, but business as usual for anyone tracking EU platform regulation. The designation worth pausing on is ChatGPT Search: The Commission classified it as a “Very Large Online Search Engine” (VLOSE) – the same regulatory category as Google Search. With that decision, the Commission has answered a lingering question: in its view, LLMs can qualify as search engines under the DSA framework. Indeed, this is the first time an AI chatbot has been formally treated as such. The signal to the industry is clear: if your LLM has a search function and enough users, the Commission’s view is that the DSA applies to you.

DSA and LLMs

The DSA is the EU’s main rulebook for online content and platform accountability. It gives intermediary services – whether they merely transmit, cache or host content – a conditional shield from liability. At the same time, it imposes due diligence obligations in a graduated system: A baseline for all intermediary services, additional rules for hosting services and online platforms, and the most demanding set for the biggest players – VLOPs and VLOSEs.

The DSA was not originally built with search engines – let alone AI chatbots – in mind. Search engines were only added during the legislative process, and the rulebook arguably was never fully adapted to fit them. Rather than reworking the DSA from end to end, a separate chapter with obligations for VLOSEs was bolted on, creating a patchwork regime. LLM providers now have to navigate the resulting uncertainty.

Certain obligations generally apply following a VLOSE designation:

  • Identify and mitigate systemic risks connected with how the service is designed and used – at least once a year and before rolling out any feature that could change those risks

  • Submit to independent audits once a year

  • Give vetted researchers access to certain data so they can study the risks and verify that mitigation measures work

  • Establish an independent compliance function with a dedicated compliance officer reporting to senior management

  • Publish enhanced transparency reports at least every six months, including per-Member-State user figures

  • Pay an annual supervisory fee to the Commission

The application of other obligations is less certain, leaving providers in the dark about which additional compliance measures are now required. Obligations that may apply include:

  • The full set of rules for traditional hosting services, such as structured complaint-handling systems

  • Platform-style obligations such as extra protection for minors

  • Depending on whether chatbots count as “recommender systems” – a need to offer a version that does not rely on personal profiling

A rather open question for LLM providers is whether the DSA’s liability shields – which exempt intermediaries from responsibility for content they transmit, cache or store – apply to them at all. Those shields only protect services that handle information provided by a user and that do so in a neutral, purely technical manner. An AI-generated answer, however, reshapes, recombines and sometimes fabricates source material, which may take it well beyond neutral intermediation. Germany’s Federal Court of Justice (BGH) reached a similar conclusion for Google’s Autocomplete function, holding that algorithmically generated suggestions are the search engine operator’s own content because the provider – not a third party – creates the link between the user’s query and the output. That reasoning might be broadly transferable to LLMs. Even where a chatbot clearly cites its source, the shield may not apply if the answer has been reworked or summarised. Of course, the BGH’s judgment came well before the DSA and only the European Court of Justice may rule definitively on the subject. The question is therefore genuinely open. A risk-averse reading, however, points towards assuming that the liability shields do not apply – meaning LLM providers should build their compliance framework on the basis that they bear full responsibility for their output.

What this means for the broader LLM market

While it remains to be seen whether the ChatGPT designation will be challenged, and which obligations under the DSA will ultimately apply, the Commission has made one thing clear: In its view, AI chatbots qualify as online search engines. As a result, LLM providers with a search function must at the very least designate a point of contact for authorities and publish their monthly active user numbers, and those exceeding 45 million EU users may face designation as a VLOSE – with the full set of enhanced compliance obligations that comes with it.

Given the remaining legal uncertainty and the relatively short compliance period following designation, providers whose user base is at or approaching the threshold should already be assessing the extent to which their compliance framework requires adaption. Regardless of any legal challenge, the designation has immediate practical consequences: OpenAI’s compliance clock is already running, and other chatbot providers should expect higher scrutiny. This is exactly the type of situation in which proactive preparation is critical.

Not just the DSA: the AI Act is already live

The DSA is not the only EU rulebook catching up with LLM providers. Since 2 August 2025, the obligations for providers of general-purpose AI models under the AI Act are fully applicable. That means LLM providers already have to maintain technical documentation on their models, put in place a copyright compliance policy, and publish a summary of the training data they used. Models classified as posing systemic risk face additional duties, including adversarial testing, incident reporting, and cybersecurity measures.

Taken together, the DSA designation and the AI Act create a compliance landscape that is both fast-moving and legally uncertain. The Commission’s willingness to treat LLMs as search engines signals that further designations are only a matter of time. Providers that wait for a Commission decision before acting risk being caught unprepared. The prudent course is to map both regimes against existing operations now, identify the gaps, and begin building the structures that will be required regardless of how the remaining open questions are resolved.

BLOMSTEIN will closely monitor further developments and keep you informed. If you have any questions on EU Digital Law and specifically the DSA, Anna Blume Huttenlauch, Mattis Leson and the entire team is ready to assist you.

BLOMSTEIN | We provide legal support to our international client base on competition, international trade, public procurement, State aid and ESG in Germany, Europe, and – through our global network – worldwide.