Regulation explainerTechnology, Media & Telecommunications
DSA content moderation: duties by service tier and a pipeline that evidences them
DSA content moderation duties depend on what your service is: every hosting service needs notice and action and statements of reasons, online platforms add complaints, trusted flaggers and database submissions, and very large platforms add risk assessments and audits. The practical answer is a moderation pipeline whose decision records already contain what each duty asks for, so reports and redress come from logs rather than from a scramble.
On this page
- Which Digital Services Act tier your service falls into
- Moderation duties that stack from hosting service to very large platform
- Instruments that govern moderation decisions in the EU and UK
- A moderation pipeline whose records double as compliance evidence
- Turning DSA duties into engineering work
- A hypothetical marketplace handling counterfeit listings
- Where AI-assisted moderation programs fall short of the DSA
- Questions and answers
- Sources
Which Digital Services Act tier your service falls into
The Digital Services Act (Regulation (EU) 2022/2065) applies to intermediary services offered to recipients in the EU, wherever the provider is established1. Within that, obligations stack by tier. A hosting service stores information on behalf of users. An online platform is a hosting service that also disseminates that information to the public, such as a social network, video service or marketplace. A very large online platform (VLOP) or very large online search engine (VLOSE) is one designated by the Commission once it reaches 45 million average monthly active recipients in the Union1.
Micro and small enterprises are exempt from most additional online platform obligations unless designated as very large1. The exemption does not reach hosting-level duties, so even a small service storing user content needs a notice mechanism and statements of reasons.
Moderation duties that stack from hosting service to very large platform
| Duty | Hosting service | Online platform | VLOP or VLOSE |
|---|---|---|---|
| Notice and action (Article 16) | Required | Required, with trusted flagger priority | Required, with trusted flagger priority |
| Statement of reasons (Article 17) | Required for each restriction | Required for each restriction | Required for each restriction |
| Submission to the Transparency Database | Not required | Every decision and statement of reasons | Every decision and statement of reasons |
| Internal complaints and out-of-court settlement | Not required | Required (Article 20 and Article 21) | Required (Article 20 and Article 21) |
| Transparency report | Annual, unless micro or small | Annual, with extra platform data | At least every six months |
| Systemic risk assessment, mitigation and audit | Not required | Not required | Required yearly (Article 34, Article 35, Article 37) |
Summarized from Regulation (EU) 2022/2065, Articles 15 to 421. The micro and small enterprise exemption removes most online platform duties for qualifying providers that are not designated as very large.
Instruments that govern moderation decisions in the EU and UK
Cite the primary text in your own policy documents; guidance and codes change more often than the acts.
Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act)
European UnionApplies whenAn intermediary service is offered to recipients established or located in the EU, whatever the provider's place of establishment1.
- Process notices in a timely, diligent, non-arbitrary and objective manner and disclose any use of automated means in doing so (Article 16)1.
- Give a clear and specific statement of reasons for each restriction, stating the facts relied on, the legal or contractual ground, redress options and whether automated means were used (Article 17)1.
- Online platforms submit decisions and statements of reasons, without personal data, to the Commission's public database (Article 24)1.
Commission Implementing Regulation (EU) 2024/2835 (templates for DSA transparency reports)
European UnionApplies whenA provider publishes the transparency reports the Digital Services Act requires; the templates apply to reporting periods from 1 July 20252.
Online Safety Act
United KingdomApplies whenUnder the Online Safety Act 2023, a user-to-user or search service has links with the UK, such as a significant number of UK users or the UK as a target market4.
A moderation pipeline whose records double as compliance evidence
- Intake
User notices, trusted flagger notices, authority orders and proactive detections arrive with source tags.
- Classifier scoring
Models score each item against a named policy version and confidence threshold.
- Routing
High-confidence items are actioned automatically where policy allows; the rest go to trained reviewers.
- Decision record
One record holds the action, ground, policy version, reviewer or model, and whether automation detected or decided.
- Statement of reasons
Generated from the decision record and sent to the affected user, then submitted to the database.
- Complaint review
Appeals reopen the record for a human decision; reversals feed threshold tuning and report metrics.
Turning DSA duties into engineering work
Version every policy and threshold
Give each community guideline and classifier threshold an identifier and an effective date, so every decision record can cite the exact clause in force at the time.
Tag the source and the automation level
Record whether the item came from a user notice, a trusted flagger, an authority order or proactive detection, and whether a model detected it, decided it, or both. Article 17 and the transparency templates ask for that distinction.
Set automation boundaries per harm type
Allow automatic action only where precision on a recently labelled, held-out set meets the bar your policy team sets for that harm. Satire and hate speech need more human judgment than known counterfeit listings.
Generate statements of reasons from the record
Build the statement from structured fields: restriction and its scope, facts relied on, ground, automation used and redress routes. Free-text reviewer notes should add detail, not replace the fields.
Submit to the database and strip personal data
Online platforms send each decision to the DSA Transparency Database3. Pseudonymize or drop personal data before submission and keep the mapping internal for complaints.
Staff the complaint queue with qualified reviewers
Complaints must be decided under the supervision of qualified staff, not solely by automated means1. Track reversal rates by policy and model version, since a high reversal rate is evidence a threshold is wrong.
Build the transparency report as a query
Map each field in the harmonized templates to a column in your decision store, including precision and recall estimates for each automated tool, and run a draft report well before the deadline.
A hypothetical marketplace handling counterfeit listings
Where AI-assisted moderation programs fall short of the DSA
Automation not recorded per decision
Early signalThe team can say a model is used but not which decisions it made.
MitigationMake detection and decision automation flags mandatory fields in the decision schema.
Accuracy measured once, at launch
Early signalPrecision and recall figures in reports come from the original validation set.
MitigationRe-label a fresh sample each reporting period and report against that.
Appeals handled by the same model
Early signalComplaint outcomes match the original decision almost every time.
MitigationRoute complaints to qualified reviewers who can see, but are not bound by, the model score.
UK and EU handled as one regime
Early signalOne risk assessment document is reused for both without mapping to Ofcom's codes.
MitigationKeep a shared evidence base but produce separate assessments for each act.
Questions and answers
Does every content removal under the DSA need a statement of reasons?
Hosting providers must give one for restrictions imposed because content is illegal or incompatible with their terms, including visibility limits, demonetization, suspensions and account closures. Article 17 applies only where the provider knows the user's electronic contact details, does not apply to deceptive high-volume commercial content, and does not cover action taken under an authority order issued under Article 91.
How should a platform report the accuracy of automated moderation?
The harmonized templates in Implementing Regulation (EU) 2024/2835 ask for accuracy indicators for automated tools, including precision and recall, together with a qualitative description of the tools and their possible error rate2. The defensible way to produce them is to label a fresh random sample of automated decisions each period and calculate the indicators per tool and harm type.
Does the DSA apply to companies outside the EU?
Yes, if they offer services to recipients in the EU. The regulation applies irrespective of where the provider is established, and a provider without an EU establishment must appoint a legal representative in a Member State1. Mere technical accessibility of a website from the EU is not enough on its own; a substantial connection, such as a significant number of EU users or targeting EU countries, is.
Can AI make moderation decisions without any human involvement?
For initial decisions, the DSA permits automated means but requires the provider to disclose their use in notice handling and in each statement of reasons. Complaints are different: the internal complaint system must decide under the supervision of qualified staff and not solely by automated means1. Most teams therefore automate high-precision, low-ambiguity cases and keep humans on contested and context-heavy ones.
Sources
- Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act) — EUR-Lex · checked 10 October 2026
- Commission Implementing Regulation (EU) 2024/2835 laying down templates concerning the transparency reporting obligations under Regulation (EU) 2022/2065 — EUR-Lex · checked 10 October 2026
- DSA Transparency Database — European Commission · checked 10 October 2026
- Online Safety Act 2023 — legislation.gov.uk · checked 10 October 2026
- Important dates for Online Safety compliance — Ofcom · checked 10 October 2026