AI risks on platforms: the DSA puts evidence at the heart of scrutiny
Following the European roundtable of 23 September 2026, how can AI risks on large platforms be assessed? The role of researchers and the limits of regulatory scrutiny.

A discussion about enforcement, not a new law
The European Commission brought together around 60 organisations and researchers on 23 September 2026 for its fifth roundtable on the Digital Services Act (DSA). Its account was published on 25 September and updated on 1 October. It includes AI-related risks among the priorities discussed.
The discussion covered systemic risks, measures to reduce those risks and access to data. The statement does not establish an infringement by a platform or announce a penalty. It describes work on scrutiny and research.
An algorithm needs to be examined in context
Articles 34 and 35 of the DSA require designated very large online platforms and very large online search engines to assess their services’ systemic risks and take appropriate mitigation measures. Article 40 provides, among other things, for vetted researchers’ regulated access to certain data. These obligations do not apply indiscriminately to every website or chatbot.
Imagine a feed repeatedly recommending misleading AI-generated images. This is a fictional scenario. Analysis needs to distinguish how the images were created, how they spread and the role of recommendations. Finding that content is synthetic does not, on its own, demonstrate a DSA infringement.
Evidence that allows a before-and-after comparison
Our practical reading of this development is that a safety promise should be tested against observations. An organisation can record the service studied, dates, language, account settings and method used. Without those details, two screenshots may describe situations that cannot meaningfully be compared.
A platform may change its interface without reducing the problem observed. Evaluating a measure needs a precise question and a suitable indicator: is the same kind of content still recommended under the same conditions? This approach does not replace an official investigation or statistical expertise.
Individual harm and systemic risk remain distinct
A Belgian user who encounters misleading content can retain its URL, date and the response to a report to help explain the facts. Avoid republishing personal data or harmful images to collect evidence. An individual account can be useful, but does not automatically establish systemic behaviour.
The roundtable highlights the value of work outside platforms. It does not give every organisation unrestricted access to their databases: research must follow the applicable framework and protect the people concerned.
What to look for next
Watch for verifiable results: the research method, risks identified, measures adopted and effects observed. This article examines a September development using sources available on 4 October 2026. It does not present the meeting as an event that happened today.
Use our directory of legal sources to check the cited texts. Our editorial page explains AI use and the corrections process. This general analysis does not determine the rights or remedies available in an individual case.
Sources and references
General information. Application to a matter depends on its facts and the rules in force.