The Digital Services Act
Goanta's territory, and the EU's first attempt to make algorithmic auditing a legal obligation. Also the home of the single best research project available to you: a public corpus of several hundred million statements of reasons.
1. The basics
Regulation (EU) 2022/2065. In force November 2022, obligations on the largest platforms from late August 2023, and full application from 17 February 2024. It replaced the liability regime of the e-Commerce Directive while keeping its core.
The DSA is asymmetric by design: obligations stack by actor type, so a small hosting provider carries a handful and a very large platform carries all of them.
| Tier | Who | Obligations |
|---|---|---|
| Intermediary services | Mere conduit, caching, hosting | Articles 11 to 15: points of contact, legal representative, terms, transparency reporting |
| Hosting services | Anyone storing user-provided content | Plus Articles 16 to 18: notice and action, statements of reasons, reporting criminal offences |
| Online platforms | Hosting that disseminates to the public | Plus Articles 19 to 28: complaints, dispute settlement, trusted flaggers, transparency, interface design, advertising and recommender transparency, minors |
| VLOPs and VLOSEs | At least 45 million average monthly active recipients in the EU | Plus Articles 33 to 43: systemic risk assessment and mitigation, independent audits, recommender choice, ad repository, data access, compliance function, supervisory fee |
2. The liability layer
- Articles 4 to 6 — conditional exemptions for mere conduit, caching and hosting. A hosting provider is not liable for user content unless it has actual knowledge and fails to act expeditiously.
- Article 8 — no general monitoring obligation. Member States cannot require platforms to proactively scan everything. This is the provision that keeps the DSA from becoming a surveillance mandate, and it is why the systemic-risk duties are framed as risk assessment rather than detection.
3. The due diligence obligations that matter to you
| Article | Obligation |
|---|---|
| 16 | Notice and action mechanisms for illegal content |
| 17 | Statement of reasons. Every content moderation decision affecting a user must be accompanied by a clear, specific statement of reasons — the facts relied on, the legal or contractual ground, whether automated means were used, and the redress available |
| 20 and 21 | Internal complaint handling, and certified out-of-court dispute settlement |
| 22 | Trusted flaggers, whose notices get priority |
| 24 | Transparency reporting |
| 25 | Interface design: no dark patterns that distort or impair free and informed decisions |
| 26 and 39 | Advertising transparency, and for very large platforms a public searchable ad repository |
| 27 and 38 | Recommender system transparency, and for very large platforms at least one option not based on profiling |
| 34 and 35 | Systemic risk assessment and mitigation for very large platforms, covering illegal content, fundamental rights, civic discourse and electoral processes, and harms to minors and to physical and mental wellbeing |
| 37 | Independent audits, annually, at the platform's own expense, with the report and the platform's response published |
| 40 | Data access for the Commission, for Digital Services Coordinators, and for vetted researchers |
4. Enforcement
Split supervision. The Commission has exclusive oversight of the very large platforms and search engines. Digital Services Coordinators in each Member State supervise everyone else and coordinate nationally. Penalties reach 6 percent of worldwide annual turnover.
Note the contrast with the DMA, which is entirely centralised, and with Articles 101 and 102, which are entirely decentralised post-2004. Three instruments, three different institutional designs, all operating on overlapping subject matter. That fragmentation is itself an ATLANTIS-shaped problem.
5. How this connects to ATLANTIS
Of the five instruments, the DSA is the furthest from the project's subject matter and the closest to its methodology. It is where the EU has already had to answer two questions ATLANTIS is about to face.
- How do you audit an algorithmic system you do not own? Article 37 is the answer the EU reached for platforms: annual independent audits at the auditee's expense, with the report published. Whether that produces real scrutiny is contested, and the answer determines whether a comparable duty on agency tools would be worth imposing.
- How does an outside researcher lawfully obtain data from an unwilling holder? Article 40 is the answer: a vetted researcher mechanism with a defined public-interest purpose. ATLANTIS needs exactly this for agency data, and currently has only fieldwork goodwill through the Stanford network.
6. What the panel brings to this chapter
| Panel member | Why the DSA is their territory |
|---|---|
| Catalina Goanta | This is her field. Principal investigator of the ERC Starting Grant HUMANads on content monetisation and platform governance. She has proposed a legal compliance API for enforcing the DSA on social media platforms. She has run large-scale empirical measurement of platform behaviour, including a multi-country longitudinal study of influencer disclosure across hundreds of creators and around a million posts. She founded the Maastricht Law and Tech Lab, which placed computer scientists in residence at a law school — meaning she has spent years on exactly the collaboration problem your position creates |
| Tijmen Wisman | Article 8's prohibition on general monitoring, and the systemic risk duties, are the point where platform governance meets his field. His work is on whether a system that observes people at scale can satisfy a proportionality test |
| Georgiana Mirza | Digital ecosystems and data spaces, where the DSA's data access provisions and the DMA's data obligations meet |
7. What is unexplored, and five projects — the first is your best
8. Your CV, mapped onto this chapter
| What you have | Where it lands | Why it fits |
|---|---|---|
| NLP at corpus scale — TF-IDF, GloVe, WordNet, POS tagging, entity extraction, and the hybrid legal summarisation and extraction paper | Project 1, the statements of reasons corpus | Hundreds of millions of short structured legal texts is the single best fit between your technical training and an open research question anywhere in this prep |
| Rubric-based evaluation at Outlier, across law, programming and linguistics | Project 2, coding the audit reports | You have professional practice at exactly this: applying a consistent rubric to documents and recording where they fail |
| Faithfulness measurement — the Mens Rea harness, and the finding that a true but incomplete account survives checking | Projects 1 and 5 | The question of whether a stated reason matches the real reason is the same question in both domains |
| Computer vision and image classification — OpenCV, Pillow | Project 4, dark patterns | Interface classification is a vision problem with a legal standard attached |
| Probability and model evaluation — calibration, interval estimation at small n, agreement reporting | Project 4's evidentiary weight question | A classifier output offered as evidence needs a defensible confidence statement, which is the chapter one calibration problem again |
| Legal training in evidence and procedure, plus published legal writing | Projects 1 and 3 | Project 1 is an evidence-law question asked with a dataset; Project 3 is institutional design and needs the doctrinal half done properly |
| Multilingual work across six Indian languages, in production | Project 1, which spans 24 EU languages | Cross-language consistency is the first thing that breaks on a pan-EU corpus, and you have shipped multilingual systems rather than only read about them |
9. If you remember eight things
- Regulation (EU) 2022/2065, fully applicable February 2024, asymmetric by actor type.
- Liability exemptions in Articles 4 to 6, and no general monitoring obligation under Article 8.
- Article 17 requires a statement of reasons for every moderation decision, including whether automated means were used.
- Articles 34 and 35 require systemic risk assessment and mitigation for very large platforms.
- Article 37 makes independent algorithmic auditing a legal obligation — the EU's first.
- Article 40 creates vetted researcher data access — the EU's first mechanism for forcing data out of an unwilling holder for independent scrutiny.
- Penalties to 6 percent of worldwide turnover. Commission supervises the very large platforms; Digital Services Coordinators supervise the rest.
- The move for ATLANTIS: Articles 37 and 40 are the accountability machinery the AI Act omits for public enforcement authorities. Ask whether they can be turned around and pointed at regulators.