ChatGPT regulation under the EU Digital Services Act

EU puts ChatGPT under stricter DSA oversight as platform risk rules expand

ChatGPT regulation is tightening in the EU as the DSA designates OpenAI’s chatbot a very large service with new compliance duties.

In short

The EU has classified ChatGPT as a very large online service under the Digital Services Act, subjecting OpenAI to stricter rules on safety, transparency, and risk mitigation. Reddit and Roblox received the same designation and must comply by the end of 2026.

  • ChatGPT is now subject to tougher EU oversight under the Digital Services Act.
  • The designation focuses on risks to minors, mental health, illegal content, and ad targeting.
  • Reddit and Roblox were also labeled very large platforms by the European Commission.
  • The companies have until the end of December 2026 to meet the new obligations.

The European Union will subject ChatGPT to tougher oversight under its Digital Services Act, placing OpenAI’s chatbot in the same high-scrutiny category as major online platforms that must do more to protect users from harmful content and other risks. The move matters because it expands Brussels’ regulatory reach into one of the world’s most widely used AI products, with direct implications for minors, mental health, advertising practices, and transparency.

Alongside ChatGPT, the European Commission also designated Reddit and Roblox as “Very Large Online Platforms” or “Very Large Online Search Engines,” triggering stricter obligations tied to their scale and influence across the bloc. The companies now have until the end of December 2026 to comply with the added requirements.

What the EU decision means for ChatGPT

ChatGPT’s new status under the Digital Services Act means OpenAI will have to meet a higher compliance bar in the European Union because regulators now view the service as a large enough online platform or search service to create meaningful public risk. The designation is not a fine or a ban, but it does create a more demanding legal framework around how the service operates, is audited, and is monitored.

At the heart of the DSA is the idea that services with very large audiences can shape what users see, how they interact, and what harms spread online. For ChatGPT, that includes concerns about how the system may affect younger users, whether it could worsen mental health issues, and how it handles potentially illegal material.

Although ChatGPT is best known as a conversational assistant, European regulators are treating its scale and influence as comparable to other major digital intermediaries. That is a significant signal for the broader AI industry: once a chatbot reaches mass adoption, policymakers may increasingly judge it not just as software, but as a platform with social responsibilities.

Why the DSA classification matters

The Digital Services Act was designed to rein in the risks posed by dominant internet services, especially those with large user bases across Europe. The law applies enhanced obligations once a platform or search engine crosses the threshold of 45 million average monthly users in the EU. That benchmark is intended to capture services whose decisions can have outsized effects on public discourse, safety, and consumer protection.

For companies that fall into the “Very Large” category, the DSA imposes stricter expectations around risk management, transparency, and accountability. It also gives European regulators more leverage to scrutinize how algorithms and recommendation systems work, particularly if they are influencing what people encounter online.

In practical terms, the designation means ChatGPT, Reddit, and Roblox will need to demonstrate that they understand and are actively mitigating the dangers linked to their scale. Those dangers can differ by product, but the legal principle is the same: if a service becomes big enough, it must do more to show that its systems are not exposing users to preventable harm.

How the law applies to AI platforms

The DSA was originally built with social networks, marketplaces, and search engines in mind, but its structure is broad enough to reach AI services that operate at internet scale. ChatGPT’s inclusion suggests regulators are willing to treat generative AI tools as part of the same digital ecosystem as traditional platforms when those tools direct, filter, or surface information to large numbers of people.

That is important because AI chatbots increasingly serve as entry points to information, advice, and recommendations. Even when they do not function exactly like social networks or search engines, they can still shape user behavior and public exposure to content. Brussels appears to be saying that those effects matter as much as the product label.

EU executive vice-president Henna Virkkunen said the new designations place ChatGPT, Reddit, and Roblox under a higher level of scrutiny and accountability because of their size and impact on European citizens and society.

What rules will ChatGPT have to follow?

ChatGPT will have to comply with the DSA’s stricter obligations for very large services, including controls related to advertising and algorithmic transparency. The law restricts platforms from targeting minors with ads and from using sensitive personal characteristics such as sexual orientation, religion, ethnicity, or political beliefs in ad targeting.

The DSA also requires more clarity about recommendation systems. For a chatbot, that could raise questions about how responses are ranked, filtered, personalized, or shaped by user history and platform design. Regulators want companies to be able to explain the mechanisms that influence what users receive and why.

The rules are especially relevant because AI systems can produce highly tailored interactions. If a model is used by a teenager, for example, the company must be able to show that it has considered the risks associated with that user group. That includes how the service may present harmful content, how it handles vulnerable users, and whether safeguards are strong enough to limit abuse.

What does ‘higher scrutiny’ mean in practice?

It means the company will face deeper oversight, more documentation, and greater accountability for systemic risk management. In the DSA context, that can involve transparency reporting, independent review expectations, and obligations to assess whether the platform’s design contributes to harm.

For a company like OpenAI, that likely translates into more formal processes for evaluating how ChatGPT behaves at scale, what kinds of content it may surface, and where gaps remain in preventing misuse. The core regulatory idea is not that every harmful outcome can be eliminated, but that a very large service should be able to prove it is taking the issue seriously.

Why minors and mental health are central to the debate

The EU’s concern about minors and mental health reflects a broader shift in how governments view AI products. Chatbots are no longer seen only as productivity tools or novelty applications. They are also social and psychological interfaces that can influence behavior, reinforce beliefs, and become part of a user’s daily routine.

That makes protections for younger users especially important. Children and teenagers may be more likely to rely on an AI assistant for emotional support, homework, companionship, or general advice. Regulators worry that a system optimized for engagement or responsiveness could expose those users to manipulative content, unhealthy dependency, or misleading guidance.

Mental health is similarly sensitive because conversational systems can encourage prolonged interaction and may appear authoritative even when they are wrong. European lawmakers have increasingly signaled that digital products should not be evaluated solely on convenience or growth, but also on the ways they may affect wellbeing.

How ChatGPT compares with Reddit and Roblox

ChatGPT, Reddit, and Roblox are very different services, but they now share the same broad regulatory designation because of scale. That comparison is useful because it shows how the EU is applying the DSA across multiple kinds of online environments rather than targeting only one sector.

Reddit is a massive discussion platform where user-generated content can spread quickly across communities. Roblox is a large gaming and creation platform with substantial youth engagement. ChatGPT is an AI assistant that can generate content in real time and increasingly acts as an information interface. Each raises distinct risks, but all are now considered influential enough to warrant the same baseline of heightened scrutiny.

Service EU designation Why it matters Compliance deadline
ChatGPT Very Large Online Search Engine Faces stricter oversight on risk mitigation, transparency, and user safety End of December 2026
Reddit Very Large Online Platform Subject to heightened duties for content and recommendation risks End of December 2026
Roblox Very Large Online Platform Must address platform-scale risks affecting users, including minors End of December 2026

What the EU’s timing tells us about AI regulation

The designation comes at a moment when governments are trying to catch up with the speed of AI adoption. ChatGPT has become one of the defining consumer technologies of the decade, and regulators are no longer content to treat such products as experimental tools operating outside the framework applied to other major digital platforms.

By setting a compliance deadline at the end of December 2026, the Commission is giving companies time to adjust. That suggests Brussels wants measurable implementation rather than symbolic compliance. The message is that large AI services must prepare now for a regulatory environment in which user impact, safety, and transparency are central requirements, not afterthoughts.

This is also part of a wider European pattern. The EU has repeatedly taken the lead on tech governance, often moving faster than the United States or other regions on formal rules for online services. The ChatGPT decision fits that tradition by placing a fast-growing AI product inside an established accountability regime rather than creating a separate carveout for generative AI.

How companies may respond

Companies are likely to respond by strengthening internal auditing, expanding safety testing, and documenting how they handle high-risk use cases. They may also invest in clearer user controls, better age-related protections, and more detailed explanations of how their systems work.

For OpenAI in particular, the challenge will be to balance product usefulness with compliance. A chatbot is expected to be conversational and flexible, but the DSA pushes companies toward more structure, documentation, and guardrails. That can create tension between user experience and regulatory control, especially for products built around rapid iteration.

What risks are regulators trying to reduce?

Regulators are trying to reduce systemic harms that can spread when a service reaches mass scale. In ChatGPT’s case, those include exposure to illegal content, misleading guidance, harmful interactions for minors, and possible negative effects on mental health. The DSA framework assumes that once a service becomes large enough, its design choices can affect society in ways that go beyond ordinary consumer risk.

The EU is also trying to limit opaque decision-making. If a platform or AI service shapes what users see, lawmakers want the company to be able to explain the logic behind those systems. That does not necessarily mean disclosing trade secrets in full, but it does mean giving regulators and users more visibility into how the service functions.

Another concern is ad targeting. The DSA places explicit limits on how personal data can be used for advertising, particularly when minors are involved. That rule matters because platforms often monetize attention in ways that may be invisible to users, and lawmakers want to curb the exploitation of sensitive attributes.

How this could affect the broader AI industry

ChatGPT’s designation may serve as a precedent for other AI products that achieve similar scale in the European market. If regulators are prepared to classify a chatbot as a very large service, other generative AI tools could eventually face the same scrutiny once their user numbers and influence grow enough.

That could push AI companies to think about compliance earlier in the product lifecycle. Safety controls, transparency reporting, and youth protections may become standard development priorities instead of legal add-ons. In that sense, the EU decision is about more than OpenAI; it is a signal about the regulatory path of consumer AI in general.

It also underscores a changing reality for the industry. As AI tools become embedded in everyday search, productivity, education, and entertainment, they will increasingly be judged not just on model quality, but on their societal footprint. The larger and more influential the product, the more likely governments are to ask what risks it creates and how those risks are being addressed.

Key facts at a glance

Item Detail
Regulator European Commission
Law Digital Services Act
Newly designated services ChatGPT, Reddit, Roblox
ChatGPT classification Very Large Online Search Engine
Reddit and Roblox classification Very Large Online Platforms
Threshold for designation At least 45 million average monthly users in the EU
Compliance deadline End of December 2026

What happens next?

ChatGPT and the other designated services now have a runway to bring their practices in line with the DSA’s enhanced requirements. The real test will be whether they can document meaningful safeguards, not just announce them. For regulators, the next phase will be about monitoring whether companies are actually reducing the kinds of risks the law was designed to address.

For users, the immediate change may not be visible in the interface, but the framework around the product is becoming much more demanding. The EU has made clear that when a digital service becomes influential enough, it must also become more accountable. ChatGPT’s new status is the latest proof that generative AI is now squarely inside that regulatory logic.

As Europe tightens the rules, the message to major AI platforms is straightforward: scale brings responsibility, and responsibility now includes the risks created by machine-generated conversation, recommendation systems, and the way digital products shape public life.

Frequently asked questions

Why did the EU classify ChatGPT under the Digital Services Act?

The EU classified ChatGPT under the Digital Services Act because it now reaches the scale and influence that Brussels considers large enough to create systemic risk. Regulators want stronger accountability for harms involving minors, mental health, illegal content, and platform transparency.

What does Very Large Online Search Engine mean for ChatGPT?

It means ChatGPT is now subject to stricter DSA obligations because it has surpassed the EU’s user threshold for major online services. OpenAI must take additional steps to assess risks, improve transparency, and comply with rules on advertising and recommendation systems.

How many users trigger the EU’s very large platform rules?

The EU’s very large platform rules apply once a service reaches at least 45 million average monthly users in the European Union. That threshold is meant to capture services whose decisions can have broad effects on users and society.

When must ChatGPT comply with the new EU rules?

ChatGPT must comply by the end of December 2026. The deadline gives OpenAI time to adapt its systems, reporting, and safety measures to meet the higher standards required under the Digital Services Act.

Are Reddit and Roblox affected by the same decision?

Yes. Reddit and Roblox were also designated as very large online platforms, which means they will face similar heightened oversight under the same EU law. Like ChatGPT, they must address risk management, transparency, and other DSA obligations.

Share this 🚀