Decoding the world of cybersecurity

ChatGPT enters EU’s toughest DSA tier

The European Commission has designated ChatGPT as a Very Large Online Search Engine, bringing the service into the Digital Services Act’s enhanced systemic-risk and oversight regime.

ChatGPT enters EU’s toughest DSA tier
Summary
  • ChatGPT has been designated a Very Large Online Search Engine after reporting at least 45 million average monthly EU users.
  • Reddit and Roblox were separately designated as Very Large Online Platforms.
  • The services have four months to meet enhanced obligations covering systemic risk, audits, transparency, research access, and public security.

The European Commission has designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act, placing the generative AI service inside the EU’s enhanced platform-risk regime.

Reddit and Roblox were designated as Very Large Online Platforms in the same decision. The Commission said all three services had declared at least 45 million average monthly users in the European Union, meeting the threshold at which additional DSA requirements apply.

The services have four months following notification of their designations to comply with the enhanced rules, placing the deadline at the end of November 2026.

For ChatGPT, the classification brings a generative AI service into a regulatory structure originally organised around intermediary services, online platforms, and search engines rather than generative AI as a separate category.

The additional obligations require the largest services to identify, assess, and mitigate systemic risks created by their services and algorithmic systems. The Commission specifically lists risks involving illegal content, minors, physical and mental wellbeing, fundamental rights, electoral processes, and public security.

Those requirements go beyond handling individual pieces of content. Very Large Online Platforms and Very Large Online Search Engines are subject to risk assessments, independent audits, stronger transparency duties, and mechanisms through which vetted researchers and regulators can obtain certain data.

The designation therefore adds another regulatory layer around ChatGPT alongside the EU AI Act. The two laws address different relationships. The AI Act governs artificial-intelligence systems through rules tied to their function and risk, while the DSA governs responsibilities attached to large digital intermediary services and their systemic effects.

ChatGPT now sits across both regimes. Its DSA designation is not a finding that OpenAI has breached the law, nor does it establish that a specific systemic risk has occurred. The designation follows from the service’s scale and brings additional duties to assess and mitigate categories of risk set out in the legislation.

Public security is expressly included. In the context of a conversational AI service, that can bring questions about misuse, information integrity, coordinated manipulation, harmful content, and the behaviour of algorithmic systems into a formal risk-management process overseen by the Commission.

The DSA also requires a greater degree of outside scrutiny than most AI services have historically faced. Independent auditing and vetted-researcher access are established parts of the enhanced regime, although applying those requirements to conversational AI presents different technical questions from applying them to a conventional social network or search index.

Outputs in a generative AI system are assembled dynamically in response to prompts rather than simply ranked from a fixed set of stored webpages or posts. Demonstrating how risk mitigations operate, what information can be provided to researchers, and how meaningful transparency is achieved may therefore require different technical arrangements.

The Commission directly supervises designated VLOPs and VLOSEs for the enhanced obligations. Under the DSA, serious infringements can ultimately attract fines of up to 6% of worldwide annual turnover, although designation itself is an administrative classification rather than a penalty.

The decision also reflects the increasing movement of European technology regulation from legislation into supervision. AI services are no longer being considered solely through future rulemaking or voluntary principles; major platforms are increasingly being placed inside existing enforcement structures as their scale reaches statutory thresholds.

OpenAI will now have to translate the DSA’s established systemic-risk requirements into the operation of ChatGPT. The immediate milestone is the end-November compliance deadline, after which the service will be expected to operate under the same enhanced DSA framework already applied to other very large digital services.

×