The EU designated ChatGPT a very large online platform, with 159.1 million monthly users
The Digital Services Act designation gives the Commission power to demand systemic risk audits, force remedies and open ChatGPT's data to vetted researchers. OpenAI has four months to comply.
The European Commission has designated ChatGPT a very large online platform under the Digital Services Act, on the basis that it has 159.1 million monthly users in the European Union. OpenAI has four months to comply with the obligations that follow.
The designation is a bigger regulatory event for OpenAI than anything in the AI Act, and it has attracted a fraction of the attention.
What the obligations actually require
VLOP status brings duties that are structural rather than procedural. OpenAI must assess the systemic risks its service creates in the EU — to fundamental rights, civic discourse, public health, minors — and take measures to reduce them. It must submit to independent audits of whether those measures work. And it must give vetted researchers access to platform data to study those risks.
That third obligation is the one with teeth. Researcher data access under Article 40 has been the most contested provision of the DSA for social platforms, because it makes external parties able to check the company's own risk assessments. Applied to a conversational AI service, it means academics with a legal right of access to data about how 159.1 million Europeans use ChatGPT and what it tells them.
Penalties for non-compliance run to 6 percent of global annual turnover.
Why designation rather than the AI Act
The AI Act is the instrument everyone expects to bind frontier models, and its general-purpose AI provisions became enforceable on 2 August, when the Commission's supervision and enforcement powers over GPAI providers came into force alongside new transparency rules requiring systems to disclose that content is AI-generated.
But the AI Act largely regulates the model — documentation, copyright policy, systemic-risk evaluation, adherence to a code of practice. The DSA regulates the service, and its obligations are about what happens to users at scale.
For a company whose consumer product is now among the largest destinations on the European internet, the DSA is the closer fit and the sharper instrument. It also arrives with an enforcement apparatus that has been operating against platforms for two years, rather than an AI Office that is still building capacity.
The compliance problem underneath
Systemic risk mitigation assumes the operator can characterise how its system behaves. That is materially harder for a model than for a recommender feed. A platform can describe its ranking signals; OpenAI cannot fully describe why a model produces a given output, and its newest model makes this worse rather than better.
Astra, released three days after the designation, uses opaque recurrence — internal computation reused across steps rather than expressed as language tokens — which reduces exactly the interpretability that chain-of-thought monitoring provided. OpenAI's chief scientist has framed the opacity as an unavoidable consequence of capability.
An auditor asking how OpenAI mitigates a systemic risk in a model whose reasoning is partly unreadable is asking a question the company has publicly said it cannot fully answer.
What is not yet known
The Commission has not said which risks it will prioritise, whether the assessment must cover ChatGPT's agentic features, or how researcher access will work for conversational data that is more personally revealing than public posts. OpenAI has not commented on the designation or said whether it will contest it.
Four months puts the deadline around the end of December.
Runs the newsroom. Rename this profile in the studio to your own byline.
Related
Every weekday, the AI stories that moved money or shipped code.
No cross-posting, unsubscribe anytime. See all newsletters