Verwendete Dienste und Cookies

Unsere Website nutzt Cookies, um Ihre Nutzungserfahrung zu verbessern. Einige Cookies sind essentiell für das Funktionieren und Managen der Seite, während andere für anonyme Statistiken oder personalisierte Inhalte verwendet werden. Bitte beachten Sie, dass bei eingeschränkter Cookie-Nutzung bestimmte Webseitenfunktionen beeinträchtigt sein können.

Weitere Informationen: Impressum, Datenschutz

Notwendige Cookies helfen dabei, eine Webseite nutzbar zu machen, indem sie Grundfunktionen wie Seitennavigation und Zugriff auf sichere Bereiche der Webseite ermöglichen oder z.B. Ihre Cookie-Einstellungen speichern. Die Webseite kann ohne diese Cookies nicht richtig funktionieren. Diese Kategorie kann nicht deaktiviert werden.
  • Name:
    ukie_a_cookie_consent_manager
  • Domain:
    blomstein.com
  • Zweck:
    Speichert die Cookie-Einstellungen der Website-Besucher.
  • Name:
    blomstein_session
  • Domain:
    blomstein.com
  • Zweck:
    Der Session-Cookie ist für das grundlegende Funktionieren der Website unerlässlich. Er ermöglicht es den Nutzern, durch die Website zu navigieren und ihre grundlegenden Funktionen zu nutzen.
  • Name:
    XSRF-TOKEN
  • Domain:
    blomstein.com
  • Zweck:
    Dieser Cookie dient der Sicherheit und hilft, Cross-Site Request Forgery (CSRF)-Angriffe zu verhindern. Er ist technisch notwendig.
Diese Cookies sammeln Informationen darüber, wie Sie eine Website nutzen, z. B. welche Seiten Sie besucht und auf welche Links Sie geklickt haben.
  • Name:
    _ga
  • Domain:
    blomstein.com
  • Zweck:
    Das Google Analytics Cookie _ga wird verwendet, um Benutzer zu unterscheiden, indem es eine eindeutige Identifikationsnummer für jeden Besucher vergibt. Diese Nummer wird bei jedem Seitenaufruf an Google Analytics gesendet, um Nutzer-, Sitzungs- und Kampagnendaten zu sammeln und die Nutzung der Website statistisch auszuwerten. Das Cookie hilft Website-Betreibern zu verstehen, wie Besucher mit der Website interagieren, indem es Informationen anonym sammelt und Berichte generiert.
  • Name:
    _ga_*
  • Domain:
    blomstein.com
  • Zweck:
    Das Cookie _ga_[container_id], spezifisch für Google Analytics 4 (GA4), dient der Unterscheidung von Website-Besuchern durch Zuweisung einer einzigartigen ID für jede Sitzung und jeden Nutzer. Es ermöglicht die Sammlung und Analyse von Daten über das Nutzerverhalten auf der Website in anonymisierter Form. Dies umfasst das Tracking von Seitenaufrufen, Interaktionen und dem Weg, den Nutzer auf der Website zurücklegen, um Website-Betreibern tiefere Einblicke in die Nutzung ihrer Seite zu geben und die Benutzererfahrung zu verbessern.
  • Name:
    _gid
  • Domain:
    blomstein.com
  • Zweck:
    Das Cookie _gid ist ein von Google Analytics gesetztes Cookie, das dazu dient, Benutzer zu unterscheiden. Es weist jedem Besucher der Website eine einzigartige Identifikationsnummer zu, die bei jedem Seitenaufruf an Google Analytics gesendet wird. Dies ermöglicht es, das Nutzerverhalten auf der Website über einen Zeitraum von 24 Stunden zu verfolgen und zu analysieren.
  • Name:
    _gat_gtag_UA_77241503_1
  • Domain:
    blomstein.com
  • Zweck:
    Das Cookie _gat_gtag_UA_77241503_1 ist Teil von Google Analytics und Google Tag Manager und wird verwendet, um die Anfragerate zu drosseln, d.h., es begrenzt die Datensammlung auf Websites mit hohem Verkehrsaufkommen. Dieses Cookie ist mit einer spezifischen Google Analytics-Property-ID (in diesem Fall UA-77241503-1) verknüpft, was bedeutet, dass es für die Leistungsüberwachung und -steuerung der Datenerfassung für diese spezielle Website-Property eingesetzt wird.

Search Me

Why LLM Providers Should Care About the DSA

On the last day of August, the European Commission designated ChatGPT, Reddit and Roblox under the Digital Services Act (DSA). Reddit and Roblox were designated as Very Large Online Platforms (VLOPs) – notable, but business as usual for anyone tracking EU platform regulation. The designation worth pausing on is ChatGPT Search: The Commission classified it as a “Very Large Online Search Engine” (VLOSE) – the same regulatory category as Google Search. With that decision, the Commission has answered a lingering question: in its view, LLMs can qualify as search engines under the DSA framework. Indeed, this is the first time an AI chatbot has been formally treated as such. The signal to the industry is clear: if your LLM has a search function and enough users, the Commission’s view is that the DSA applies to you.

DSA and LLMs

The DSA is the EU’s main rulebook for online content and platform accountability. It gives intermediary services – whether they merely transmit, cache or host content – a conditional shield from liability. At the same time, it imposes due diligence obligations in a graduated system: A baseline for all intermediary services, additional rules for hosting services and online platforms, and the most demanding set for the biggest players – VLOPs and VLOSEs.

The DSA was not originally built with search engines – let alone AI chatbots – in mind. Search engines were only added during the legislative process, and the rulebook arguably was never fully adapted to fit them. Rather than reworking the DSA from end to end, a separate chapter with obligations for VLOSEs was bolted on, creating a patchwork regime. LLM providers now have to navigate the resulting uncertainty.

Certain obligations generally apply following a VLOSE designation:

  • Identify and mitigate systemic risks connected with how the service is designed and used – at least once a year and before rolling out any feature that could change those risks

  • Submit to independent audits once a year

  • Give vetted researchers access to certain data so they can study the risks and verify that mitigation measures work

  • Establish an independent compliance function with a dedicated compliance officer reporting to senior management

  • Publish enhanced transparency reports at least every six months, including per-Member-State user figures

  • Pay an annual supervisory fee to the Commission

The application of other obligations is less certain, leaving providers in the dark about which additional compliance measures are now required. Obligations that may apply include:

  • The full set of rules for traditional hosting services, such as structured complaint-handling systems

  • Platform-style obligations such as extra protection for minors

  • Depending on whether chatbots count as “recommender systems” – a need to offer a version that does not rely on personal profiling

A rather open question for LLM providers is whether the DSA’s liability shields – which exempt intermediaries from responsibility for content they transmit, cache or store – apply to them at all. Those shields only protect services that handle information provided by a user and that do so in a neutral, purely technical manner. An AI-generated answer, however, reshapes, recombines and sometimes fabricates source material, which may take it well beyond neutral intermediation. Germany’s Federal Court of Justice (BGH) reached a similar conclusion for Google’s Autocomplete function, holding that algorithmically generated suggestions are the search engine operator’s own content because the provider – not a third party – creates the link between the user’s query and the output. That reasoning might be broadly transferable to LLMs. Even where a chatbot clearly cites its source, the shield may not apply if the answer has been reworked or summarised. Of course, the BGH’s judgment came well before the DSA and only the European Court of Justice may rule definitively on the subject. The question is therefore genuinely open. A risk-averse reading, however, points towards assuming that the liability shields do not apply – meaning LLM providers should build their compliance framework on the basis that they bear full responsibility for their output.

What this means for the broader LLM market

While it remains to be seen whether the ChatGPT designation will be challenged, and which obligations under the DSA will ultimately apply, the Commission has made one thing clear: In its view, AI chatbots qualify as online search engines. As a result, LLM providers with a search function must at the very least designate a point of contact for authorities and publish their monthly active user numbers, and those exceeding 45 million EU users may face designation as a VLOSE – with the full set of enhanced compliance obligations that comes with it.

Given the remaining legal uncertainty and the relatively short compliance period following designation, providers whose user base is at or approaching the threshold should already be assessing the extent to which their compliance framework requires adaption. Regardless of any legal challenge, the designation has immediate practical consequences: OpenAI’s compliance clock is already running, and other chatbot providers should expect higher scrutiny. This is exactly the type of situation in which proactive preparation is critical.

Not just the DSA: the AI Act is already live

The DSA is not the only EU rulebook catching up with LLM providers. Since 2 August 2025, the obligations for providers of general-purpose AI models under the AI Act are fully applicable. That means LLM providers already have to maintain technical documentation on their models, put in place a copyright compliance policy, and publish a summary of the training data they used. Models classified as posing systemic risk face additional duties, including adversarial testing, incident reporting, and cybersecurity measures.

Taken together, the DSA designation and the AI Act create a compliance landscape that is both fast-moving and legally uncertain. The Commission’s willingness to treat LLMs as search engines signals that further designations are only a matter of time. Providers that wait for a Commission decision before acting risk being caught unprepared. The prudent course is to map both regimes against existing operations now, identify the gaps, and begin building the structures that will be required regardless of how the remaining open questions are resolved.

BLOMSTEIN will closely monitor further developments and keep you informed. If you have any questions on EU Digital Law and specifically the DSA, Anna Blume Huttenlauch, Mattis Leson and the entire team is ready to assist you.

BLOMSTEIN | We provide legal support to our international client base on competition, international trade, public procurement, State aid and ESG in Germany, Europe, and – through our global network – worldwide.