IA · 31 August 2026 · 4 min read

ChatGPT Faces Stricter EU Scrutiny: Brussels Designates OpenAI Under the Digital Services Act

In brief: The European Commission has officially designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act after the service surpassed 45 million monthly active users in the EU. This classification subjects OpenAI to strict algorithmic transparency rules, systemic risk audits, and enhanced child protection measures by the end of 2026, aligning generative AI platforms with Europe's toughest platform governance standards.

by Team Mocchi's

ChatGPT Faces Stricter EU Scrutiny: Brussels Designates OpenAI Under the Digital Services Act

The European Union has taken a major step in the regulatory governance of consumer-facing generative artificial intelligence. The European Commission has officially brought ChatGPT under the strictest tier of the Digital Services Act (DSA), classifying OpenAI's conversational tool as a Very Large Online Search Engine (VLOSE).

As reported by The Verge, the decision was triggered by ChatGPT crossing the regulatory threshold of 45 million average monthly active users across the European Union. In the same batch of designations, Brussels also classified Reddit and gaming platform Roblox as Very Large Online Platforms (VLOPs), placing all three under enhanced European oversight.

What the Digital Services Act Requires from OpenAI

By entering the VLOSE category, OpenAI is no longer treated merely as an independent software vendor or generic tech provider, but as systemic digital infrastructure. This designation introduces stringent compliance obligations that OpenAI must fully meet by the end of December 2026.

Key requirements include:

  • Systemic risk assessment and mitigation: OpenAI will be required to conduct independent annual audits evaluating ChatGPT's potential negative impacts, including the spread of illegal content, algorithmic disinformation, and effects on user mental health.
  • Enhanced protection for minors: Stringent bans will apply to targeted profiling or advertising directed at underage users, alongside mandatory mechanisms to prevent access to harmful or age-inappropriate outputs.
  • Algorithmic and recommendation transparency: The company must provide clear explanations regarding how answers, recommendations, and source materials are selected and surfaced, while granting qualified researchers access to platform data for systemic risk evaluations.
  • Restrictions on sensitive profiling: Strict prohibitions against leveraging sensitive personal attributes—such as political beliefs, religious convictions, or biometric markers—for behavioral targeting or customized content delivery.

Henna Virkkunen, the EU executive vice-president for tech sovereignty, security, and democracy, emphasized that these designations reflect the substantial influence these platforms wield over citizens and society, justifying a higher standard of scrutiny and accountability.

The Intersection of the DSA and the EU AI Act

This ruling marks the beginning of an unprecedented regulatory convergence for generative AI in Europe. While the EU AI Act focuses primarily on underlying model architectures, compute thresholds, training dataset provenance, and technical risk classifications, the Digital Services Act regulates the distribution interface and the real-world impact of the service on public discourse.

By framing ChatGPT as a search engine of systemic proportions, EU regulators formally acknowledge that conversational AI has evolved into a primary gateway for knowledge retrieval. Consequently, OpenAI will need to harden its retrieval pipelines, source attribution mechanisms, and hallucination safeguards to prevent systemic misinformation across millions of daily European queries.

Mocchi's take

ChatGPT's designation under the DSA is not merely an administrative hurdle for Silicon Valley giants; it is a clear operational signal for European digital builders. For companies developing consumer-facing software powered by frontier models, data traceability, output auditing, and algorithmic accountability are rapidly becoming non-negotiable architectural requirements. Moving forward, stricter platform compliance will accelerate the demand for verifiable guardrails and transparent data handling, rewarding development teams that prioritize robust AI governance over unchecked black-box integrations.

Further reading

All articles on the Mocchi's blog