ChatGPT enters the EU’s highest online-safety tier
The European Commission said on Monday that OpenAI’s ChatGPT, Reddit, and Roblox will now be treated as very large online platforms under the European Union’s Digital Services Act, a move that extends the bloc’s toughest online-safety obligations to one of the world’s most widely used AI services.
The decision matters because the Digital Services Act, or DSA, imposes an extra layer of accountability once a service crosses the EU threshold of 45 million monthly users. According to the Commission, all three companies have now passed that mark, putting them into a category reserved for platforms considered large enough to have broad social impact inside the bloc.
For ChatGPT, the designation is especially notable because it shows how existing platform regulation is being applied to fast-growing generative AI products, not just conventional social networks or marketplaces. Brussels has already been testing how older digital rules fit newer AI systems, and Monday’s announcement makes that effort more concrete. Instead of waiting for entirely new AI-specific enforcement structures to mature, the Commission is using the DSA to require more immediate controls around risk, safety, and governance.
What the new designation changes
Under the Commission’s decision, ChatGPT, Reddit, and Roblox will face added obligations that go beyond baseline platform compliance. The source text says these include requirements related to removing illegal content and protecting the privacy and security of minors. Companies that fail to comply can face penalties of as much as 6 percent of global revenue.
The services have until the end of December 2026 to meet those extra obligations. That creates a short but meaningful compliance window for companies that have been growing quickly, particularly in categories where product behavior, moderation, and user interactions are changing faster than traditional rulemaking cycles.
For OpenAI, the announcement means ChatGPT is no longer being treated simply as an innovative AI assistant attracting extraordinary consumer demand. In regulatory terms, it is now being treated as a large-scale public-facing digital platform whose reach creates systemic responsibilities. That shift is one of the clearest signals yet that mainstream AI products are moving out of a lighter-touch experimental phase and into the same accountability debates that have shaped social media regulation for years.
Brussels expands the DSA into generative AI
The Commission’s move also signals that the EU does not view generative AI as existing outside the scope of its major digital laws. The source text describes this as a further expansion of the DSA into generative AI, with X’s AI chatbot Grok already under investigation under the same law.
That is an important policy direction. The DSA was designed as an online-safety regime, not as a bespoke AI statute. Yet regulators increasingly appear willing to use it where AI services distribute information, interact with users at scale, and may shape exposure to harmful or illegal material. In practical terms, that means a chatbot can be regulated not only for how it is built, but also for how it functions as a mass consumer service inside a digital ecosystem.
Henna Virkkunen, the EU’s tech chief, framed the decision in terms of impact and accountability, saying ChatGPT, Reddit, and Roblox would now face a higher level of scrutiny in line with their effect on citizens and society. That framing is consistent with the DSA’s structure, which scales obligations according to platform size and public reach rather than treating all online services the same.
The message from Brussels is that growth changes regulatory expectations. Once a service becomes large enough, the Commission expects more formal risk management, more robust protections, and faster responses when harms emerge.
OpenAI and the broader compliance picture
An OpenAI spokesperson said the company was preparing to meet the additional compliance requirements. That response is concise, but it suggests the company is already treating the designation as an operational reality rather than a symbolic warning.
For OpenAI, the practical challenge is likely to be broader than content removal alone. ChatGPT is not organized exactly like a social feed or discussion forum, and that makes compliance questions more complex. The service can generate text on demand, summarize user prompts, and support a wide range of interactions that do not map neatly onto traditional moderation systems. Even so, the Commission’s action shows that the EU believes the DSA framework can still attach to those interactions when the product’s audience becomes large enough.
The decision also lands as the EU begins enforcing its AI Act, which the source text describes as the world’s first regime regulating the development of the fast-developing technology. The coexistence of the DSA and the AI Act points to a layered European strategy: one set of rules aimed at online platform behavior and systemic public risk, and another aimed more directly at AI development and deployment.
That layered approach could become a defining feature of how advanced AI is governed in Europe. Companies may not be dealing with one single AI law, but with overlapping obligations drawn from competition rules, platform safety laws, privacy frameworks, and AI-specific statutes.
A transatlantic pressure point
The expansion comes at a politically sensitive time. The source text notes that Brussels is facing pressure from Washington over its regulation of US technology companies, including criticism tied to enforcement against companies such as X. Washington argues that the EU is unfairly targeting American groups and colliding with speech norms favored by the MAGA movement. The Commission, by contrast, maintains that its digital laws apply regardless of where a company is based.
That disagreement matters because nearly every major generative AI platform with large global reach is now part of a broader geopolitical argument over who sets the rules for digital services. The ChatGPT designation is therefore both a compliance event and a policy signal. It shows that the EU is prepared to incorporate AI interfaces into its existing enforcement architecture even while international debate about fairness, innovation, and speech remains unresolved.
For the tech industry, Monday’s announcement marks another stage in the normalization of AI regulation. ChatGPT’s explosive growth helped turn generative AI into a mass-market product. The Commission’s decision reflects the next phase: once those products reach platform scale, regulators expect them to operate with platform-grade safeguards.
That does not answer every open question about how AI assistants should be supervised. It does, however, establish a clear near-term fact. In the European Union, ChatGPT is no longer just an AI tool under observation. It is now a very large online platform with a legal deadline and a far stricter compliance standard.
This article is based on reporting by Ars Technica. Read the original article.
Originally published on arstechnica.com







