Brussels Brings ChatGPT, Reddit, and Roblox Under Digital Services Act
Three platforms now face the EU's strictest content moderation and safety obligations, with penalties reaching 6 percent of global revenue for non-compliance.

A New Regulatory Threshold
The European Commission announced Monday that OpenAI's ChatGPT, social discussion platform Reddit, and gaming service Roblox will now be classified as very large online platforms under the Digital Services Act. The designation marks the first time an AI chatbot has been swept into the EU's most stringent online safety framework, a regime originally crafted with social networks and e-commerce giants in mind.
At DailyTechWire, we've tracked the DSA's implementation since it took effect in 2023, watching Brussels steadily expand the perimeter of platforms subject to heightened scrutiny. The inclusion of ChatGPT signals that European regulators view conversational AI as functionally equivalent to content distribution networks when it comes to systemic risk.
The classification triggers a suite of obligations that go well beyond baseline compliance. Platforms must now implement systems to identify and remove illegal material, conduct regular risk assessments of their recommendation algorithms, and provide transparency reports detailing content moderation decisions. For ChatGPT specifically, the implications are thorny: how does an AI model "remove" content when its knowledge is baked into weights rather than stored in a traditional content database?
What Very Large Platform Status Means
Under the DSA, any online service reaching more than 45 million monthly active users in the EU crosses into very large online platform territory. According to the European Commission, all three newly designated services have surpassed that threshold. OpenAI has not publicly disclosed ChatGPT's European user base, but third-party analytics firms estimate the chatbot serves tens of millions of users across the bloc each month.
The regulatory burden is not trivial. Very large platforms must submit to annual independent audits, appoint compliance officers who report directly to the Commission, and maintain direct channels for researchers and civil society organizations to access anonymized data. They also face heightened liability for systemic risks, from the spread of disinformation to harms affecting minors.
Penalties for non-compliance can reach up to 6 percent of global annual revenue. For OpenAI, which is reportedly targeting several billion dollars in annualized revenue as it scales enterprise subscriptions, that ceiling translates into potential fines in the hundreds of millions. Reddit and Roblox, both publicly traded companies with revenues in the multi-billion-dollar range, face similar exposure.
The AI Enforcement Challenge
Brussels has been wrestling with how to fit generative AI into a regulatory apparatus designed for platforms that host user-generated text, images, and video. The DSA's content moderation provisions assume a clear distinction between platform and user, but ChatGPT blurs that line. When the model generates a response that contains false medical advice or instructions for synthesizing hazardous substances, is that "content" in the traditional sense, or is it algorithmic output?
European policymakers are increasingly adopting a functional approach: if a service can disseminate information at scale and poses comparable risks to social media, it should face comparable rules. That logic underpins the Commission's decision to bring ChatGPT into the DSA fold, even as the bloc finalizes separate legislation, the AI Act, that will impose additional requirements on high-risk AI systems.
The overlap between the two regimes is intentional. The AI Act focuses on model development, data governance, and transparency around training datasets. The DSA, by contrast, targets deployment and the interface between AI systems and end users. OpenAI will need to navigate both frameworks simultaneously, a compliance challenge that few companies have faced at this scale.
Reddit and Roblox in the Crosshairs
Reddit's inclusion is less surprising. The platform has long operated in a grey zone, hosting millions of semi-autonomous communities that range from hobbyist forums to hotbeds of coordinated harassment. European regulators have watched with concern as Reddit's user base in the EU has grown, particularly among younger demographics. The DSA's child safety provisions will require Reddit to implement age verification mechanisms and restrict minors' exposure to communities flagged for adult content or coordinated abuse.
Roblox presents a different set of risks. The platform is effectively a universe of user-generated games, many of them created by and for children. Brussels has signaled that it views Roblox's in-game chat systems and virtual economy as vectors for exploitation, from grooming to financial scams targeting minors. Very large platform status will compel Roblox to deploy more aggressive content filtering and to share data with regulators about moderation decisions and user complaints.
Both platforms have invested heavily in trust and safety infrastructure over the past two years, anticipating regulatory pressure. But the DSA's audit requirements and the prospect of six-figure fines create a fundamentally different incentive structure than voluntary self-regulation.
Regional Divergence and Global Friction
The Commission's move widens the gap between European and American approaches to online platform governance. In the United States, Section 230 of the Communications Decency Act continues to shield platforms from liability for user-generated content, and there is no federal equivalent to the DSA. That divergence is forcing companies to build region-specific compliance architectures, with separate content policies, moderation queues, and transparency mechanisms for European users.
For OpenAI, the compliance burden is compounded by the fact that ChatGPT is a single global model. Unlike a social network that can geo-fence features or apply jurisdiction-specific filters to a content database, OpenAI must decide whether to fine-tune ChatGPT's behavior for European users or to implement post-generation filtering layers. Neither option is straightforward: fine-tuning risks degrading model performance, while filtering adds latency and can be circumvented through prompt engineering.
We've observed similar tensions in Southeast Asia, where governments in Singapore, Indonesia, and Vietnam have rolled out online safety legislation that borrows elements from the DSA but imposes even tighter timelines for content takedowns. The result is a fragmented regulatory landscape in which platforms must navigate overlapping and sometimes conflicting obligations.
What Comes Next
The three platforms now have four months to demonstrate compliance with DSA obligations. The Commission will assign dedicated supervision teams to each service, and the first transparency reports are expected by early 2027. OpenAI, Reddit, and Roblox will also be required to participate in the Commission's crisis response mechanism, which can compel platforms to take emergency measures during events such as terrorist attacks or public health emergencies.
For the broader tech industry, the designation is a signal that Brussels views scale, not sector, as the primary determinant of regulatory treatment. If a service reaches tens of millions of European users, it will be brought under the DSA umbrella, regardless of whether it is a social network, a gaming platform, or an AI assistant.
The open question is how effectively the DSA's framework, built for content platforms, can be adapted to generative AI. Over the next year, OpenAI's compliance efforts will serve as a live experiment in whether existing online safety rules can govern a fundamentally new category of technology, or whether entirely new regulatory instruments will be needed.


