Laws & Guides

ChatGPT Is Now a VLOSE Under the DSA: What Changes?

ChatGPT Is Now a VLOSE Under the DSA: What Changes?

On 31 August 2026, the European Commission designated ChatGPT as a very large online search engine (VLOSE) under the Digital Services Act (DSA). It also designated Reddit and Roblox as very large online platforms (VLOPs). According to the Commission’s published list, ChatGPT has 159.1 million average monthly active recipients of the service in the EU.

The designation is a classification based on the scale criteria set by the DSA. The announcement does not find that ChatGPT has violated the law. OpenAI will become subject to the additional VLOSE obligations four months after it receives notice of the designation decision.

1. VLOPs and VLOSEs

Article 33 of the DSA provides that an online platform or online search engine with at least 45 million average monthly active recipients of the service in the EU may be designated by the European Commission as a VLOP or VLOSE.

Before making a designation, the Commission must consult the Member State in which the service provider is established or take into account information supplied by that Member State’s Digital Services Coordinator. A designation may be based on user figures reported by the provider, information requested by regulators and other information available to the Commission. According to the Commission’s published list, OpenAI Ireland Limited is the provider of ChatGPT in the EU and has its main establishment in Ireland.

The Commission has not yet published the designation decision. At present, the confirmed information covers ChatGPT’s service classification, user scale and designation date. The Commission’s specific reasons for classifying ChatGPT as an online search engine will remain unclear until the full decision is published.

Article 33(6) requires the additional obligations in Section 5 of Chapter III of the DSA to apply four months after the provider is notified of the designation decision. ChatGPT, Reddit and Roblox must comply with these obligations by January 2027.

2. Additional Obligations

Following the designation, OpenAI Ireland Limited will principally be subject to six categories of additional obligations.

(1) Systemic Risk Assessment and Mitigation

Article 34 requires providers to identify, analyse and assess systemic risks in the EU arising from the design and operation of their services, their algorithmic systems and the ways users engage with them. These risks include the dissemination of illegal content; negative effects on fundamental rights, civic discourse, electoral processes and public security; and risks relating to gender-based violence, public health, the protection of minors and physical and mental well-being.

The first risk assessment must be completed no later than the date on which the additional obligations begin to apply, and assessments must then be conducted at least annually. A provider must also assess a planned feature before launch if it is likely to have a critical impact on the relevant risks. Supporting documents must be retained for at least three years.

Article 35 requires providers to adopt reasonable, proportionate and effective mitigation measures for identified risks. These may include changes to service interfaces, enforcement of terms and conditions, content moderation, algorithmic and advertising systems, internal testing and safeguards for minors. If a crisis poses a serious threat to public security or public health in the EU, the Commission may also require a designated service to conduct a specific assessment, take response measures and report on their effectiveness under Article 36.

(2) Independent Audits

Article 37 provides that a VLOSE must undergo an independent audit at its own expense at least once a year. The audit covers the obligations in Chapter III of the DSA as well as commitments made by the provider under codes of conduct or crisis protocols.

The provider must give the auditor the cooperation needed to perform the audit, including access to relevant data and premises and answers to written or oral questions. If the audit report contains operational recommendations, the provider must issue an audit implementation report within one month of receiving them. The report must explain the measures already taken or planned. If a recommendation is not adopted, the provider must explain its reasons and any alternative measures.

(3) Recommender Systems and Advertising Transparency

A VLOSE that uses recommender systems must offer at least one option for each recommender system that is not based on user profiling.

A VLOSE that displays advertising on its interface must maintain a public, searchable advertising repository and make it accessible through an application programming interface. The repository must include information such as the content of the advertisement, its funder, the period during which it was displayed, targeting parameters and the number of recipients reached. The information must be retained for one year after the advertisement was last displayed.

(4) Data Access for Regulators and Researchers

The European Commission or the Digital Services Coordinator of the Member State of establishment may issue a reasoned request for data access. The provider must supply the data needed for regulatory purposes within the specified period. Regulators may also require an explanation of the design, logic, operation and testing of algorithmic systems.

Researchers who have passed the statutory vetting process may also obtain data needed to study systemic risks through the procedures set out in law. Requirements protecting personal data, trade secrets and service security also apply to these forms of data access.

(5) Compliance Function

A VLOSE must establish a compliance function independent from its operational functions, appoint one or more compliance officers with the necessary qualifications and designate a head of the compliance function. The function must have sufficient authority and resources, and its head must be able to report directly to the management body. The management body is responsible for establishing and overseeing governance arrangements, reviewing systemic risk management strategies at least once a year and ensuring that the relevant work receives adequate resources.

(6) Transparency Reporting

Article 42 provides that a VLOSE must publish a transparency report at least once every six months. Risk assessment results, specific mitigation measures, audit reports and audit implementation reports must also be made public as required by law.

References

European Commission, “Commission designates ChatGPT, Reddit, Roblox under Digital Services Act”: https://digital-strategy.ec.europa.eu/en/news/commission-designates-chatgpt-reddit-roblox-under-digital-services-act; European Commission list of designated VLOPs and VLOSEs and related oversight information: https://digital-strategy.ec.europa.eu/en/policies/list-designated-vlops-and-vloses; Regulation (EU) 2022/2065 of the European Parliament and of the Council: https://eur-lex.europa.eu/eli/reg/2022/2065/oj

Related reading

Laws & Guides

California DROP Starts August 1 with Ongoing Deletion Duties

California data brokers must process DROP requests from August 1, 2026. The rules cover 45-day cycles, ongoing deletion, matching, and vendor instructions.

·8 min
Laws & Guides

Privacy Alert | Vietnam’s Personal Data Protection Law (PDPL) Officially Enacted

Vietnam’s Personal Data Protection Law (PDPL), enacted in June 2025 and effective from January 1, 2026, establishes a comprehensive national framework for personal data protection, replacing the 2023 Decree No. 13/2023/NĐ-CP. Applicable to both domestic and foreign entities processing Vietnamese citizens’ or residents’ data, the PDPL introduces strict penalties (up to 10 times illegal proceeds for data trading or 5% of annual revenue for cross-border violations), a narrow “legitimate rights and interests” processing basis, and exemptions for micro-enterprises. It mandates explicit consent, data processing and transfer impact assessments (DPIA and TIA), and robust data subject rights, including access, correction, and deletion. Enterprises must implement consent mechanisms, data security measures, and compliance with data localization under the Cybersecurity Law, with specific rules for sensitive data like children’s or health information, and a 72-hour breach reporting requirement.

·6 min
Laws & Guides

FTC Enforces New "Click to Cancel" Rule for Subscription Cancellations

The FTC's new “Click to Cancel” rule mandates businesses to simplify subscription cancellations, making them as straightforward as the sign-up process.

·4 min
Kaamel
info@kaamel.com
340 E Middlefield Rd, Mountain View, CA 94043
AICPA Drata
© 2026 Kaamel Inc. All rights reserved.