The European Union is bringing OpenAI’s ChatGPT under its strictest online platform rules, signaling that Brussels increasingly views widely used artificial intelligence services not only as AI models but also as mass-market information platforms capable of creating systemic risks.
The European Commission on Monday (Aug. 31) designated ChatGPT as a Very Large Online Search Engine, or VLOSE, under the Digital Services Act (DSA). Reddit and Roblox were separately designated as Very Large Online Platforms, or VLOPs.
The designations place the three services under direct Commission supervision and give them until January 2027 to comply with additional risk-management, auditing and transparency requirements.
For ChatGPT, the decision creates a second major layer of EU oversight. OpenAI already faces obligations under the EU AI Act governing general-purpose AI models and AI-generated content. The DSA designation regulates ChatGPT as a service through which millions of Europeans seek and receive information.
That distinction could have broad implications for other large chatbots, AI answer engines and agentic assistants. The Commission is demonstrating that it can apply its platform-governance law to emerging AI services without waiting for legislation specifically addressing conversational interfaces.
The Commission described ChatGPT as a “hybrid service” qualifying as an online search engine. Unlike a conventional search engine, however, ChatGPT does not merely retrieve and rank links. It can synthesize information, generate original responses and combine retrieved material with model-produced content.
That model raises difficult compliance issues, including how DSA concepts involving illegal content, recommender systems and information ranking apply to dynamically generated answers. ChatGPT’s required systemic-risk assessment may need to address hallucinations, fabricated citations, election misinformation, harmful advice, mental health interactions and risks to minors, per German broadcaster DW.
Under the DSA, services qualify as VLOPs or VLOSEs when they reach at least 45 million average monthly users in the EU, equivalent to roughly 10% of the bloc’s population. OpenAI reported 159.1 million monthly ChatGPT users in the EU. Reddit reported 57.2 million, while Roblox reported 46.6 million.
The designation is not a finding that any of the companies violated the law. But it moves them into the DSA’s highest supervisory tier, where they must identify and mitigate systemic risks connected to illegal content, fundamental rights, consumer protection, public security, elections and users’ physical and mental well-being.
The services also must establish independent compliance functions, undergo annual outside audits and give regulators access to information needed to evaluate compliance.
For Reddit, the new obligations are likely to focus on illegal user-generated material, harassment, disinformation, recommender systems and the adequacy of moderation across its network of largely user-operated communities.
Roblox is likely to face particularly close scrutiny over child safety. Its risk assessment could encompass age assurance, interactions between adults and minors, inappropriate content, addictive design features and purchases involving virtual goods.
ChatGPT’s designation presents more novel questions because the DSA and AI Act regulate different dimensions of the same service. The AI Act governs matters such as model development, general-purpose AI risk management and transparency for AI-generated content. The DSA addresses how a service distributes information at scale and affects users and society.
A ChatGPT response involving public affairs, for example, could implicate AI Act transparency rules while also raising DSA concerns involving misinformation, electoral processes or fundamental rights. OpenAI may therefore need to coordinate model testing, product design, content safeguards and compliance documentation across both regimes.
Businesses deploying large chatbots will not automatically inherit OpenAI’s VLOSE status merely by using ChatGPT or its application programming interface. But the designation is likely to have downstream consequences, including revised contract provisions, additional logging and monitoring, stronger safeguards and restrictions on certain use cases.
Companies that deploy their own consumer-facing chatbots also should examine whether their services perform search, information-discovery or intermediary functions covered by the DSA. User numbers, functionality and the degree to which a service connects users with online information could become increasingly important jurisdictional factors.
Brussels is effectively treating the interface through which people obtain AI-generated answers as regulatory infrastructure in its own right. For companies building the next generation of conversational services, compliance may no longer stop at governing the model. It may also require governing the AI service as a platform.
The post ChatGPT Facing Dual Regulatory Regimes Under New EU Designation appeared first on PYMNTS.com.