DTWdailytechwire
Tech Intelligence, Wired Daily
Policy

ChatGPT Now Faces High-Risk Designation Under Europe's Digital Services Act

OpenAI's flagship product joins Reddit and Roblox under stricter EU oversight, triggering obligations around minors, mental health, and illegal content moderation.

MT
Mei-Lin Tan
Asia Tech Correspondent · Singapore
Sep 1, 2026
5 min read
ChatGPT Now Faces High-Risk Designation Under Europe's Digital Services Act
ChatGPT Now Faces High-Risk Designation Under Europe's Digital Services ActCredit: Cath Virginia / The Verge

A New Tier of Accountability

OpenAI now operates under a different regulatory regime in Europe. The European Commission has classified ChatGPT as a Very Large Online Search Engine under the Digital Services Act, placing it in the same compliance bracket as major search platforms that serve hundreds of millions of users. The designation carries binding obligations around content moderation, algorithmic transparency, and systemic risk assessment.

The move reflects Brussels' growing concern that conversational AI systems function as de facto gateways to information, not merely productivity tools. At DailyTechWire, we've tracked the evolution of the DSA since its draft phase in 2022, and this marks the first time a generative AI product has been swept into the "Very Large" threshold typically reserved for search engines and social networks. The classification is automatic once a platform exceeds 45 million monthly active users in the EU; OpenAI crossed that line earlier this year.

What the Designation Means in Practice

Under the DSA framework, OpenAI must now conduct annual audits of ChatGPT's systemic risks, covering three specific areas: harm to minors, impact on user mental health, and the amplification or generation of illegal content. These audits must be performed by independent third parties and submitted to the Commission, with findings made partially public. Failure to comply can trigger fines of up to six percent of global annual revenue.

The legislation also prohibits targeted advertising based on sensitive attributes. Platforms cannot use data related to sexual orientation, religious belief, ethnicity, or political affiliation to personalize ads. For ChatGPT, which does not currently run display advertising, the restriction applies to any future monetization model that might involve user profiling for commercial purposes. OpenAI has been testing subscription tiers and enterprise licensing, but any ad-supported variant would need to operate within these boundaries.

Transparency obligations extend to algorithmic decision-making. OpenAI must disclose, in accessible language, how ChatGPT ranks, filters, or prioritizes information in responses. This is a technically complex requirement: unlike a search engine that surfaces links, ChatGPT synthesizes answers, making it harder to trace the provenance of a given output. The Commission has signaled it will issue supplementary guidance on how generative models should meet this standard.

Reddit and Roblox Join the List

The same announcement brought Reddit and Roblox into the Very Large Online Platform category, a parallel designation for user-generated content services. Both companies will face similar auditing and transparency requirements, with additional obligations around content moderation at scale. Reddit, which went public in early 2024, has been expanding its European user base rapidly; Roblox, meanwhile, has long operated in a regulatory gray zone given its hybrid status as a gaming platform, social network, and creator marketplace.

For Reddit, the DSA's content moderation rules intersect with ongoing debates about subreddit governance and the platform's reliance on volunteer moderators. The law requires platforms to provide users with clear pathways to appeal content removal decisions and to respond within strict timelines. Roblox faces scrutiny over its younger demographic; the DSA mandates that platforms frequented by minors implement default privacy settings and restrict data processing.

The timing of these designations is deliberate. The Commission is under pressure to demonstrate enforcement capacity as the DSA enters its second year. Several member states have criticized Brussels for slow implementation and insufficient technical expertise. By adding three high-profile services in a single batch, the Commission signals it is moving beyond symbolic gestures.

Asia's Regulatory Divergence

Europe's approach stands in contrast to regulatory trends across Asia. In Seoul, the government is piloting a voluntary AI labeling scheme that emphasizes industry self-regulation rather than binding audits. Singapore's Infocomm Media Development Authority has focused on sector-specific guidelines, issuing separate frameworks for AI in finance, healthcare, and public services, but no overarching "Very Large" threshold. Beijing's Cyberspace Administration has imposed strict content controls on generative AI, but these are administered through pre-launch approval processes rather than post-deployment audits.

The divergence creates operational complexity for companies scaling AI products globally. OpenAI must now maintain separate compliance workflows for Europe, align with content filtering mandates in China, and navigate a patchwork of state-level proposals in the United States. This fragmentation is precisely what the DSA was designed to avoid within the EU's single market, but it amplifies friction at the international level.

Enforcement Questions Remain

The DSA's teeth depend on enforcement capacity. The Commission has hired additional staff for its new Directorate-General for Digital Services, but the unit remains small relative to the number of platforms now under its jurisdiction. Audits are expensive and time-consuming; independent assessors must have access to proprietary data and model weights, raising confidentiality and security concerns.

OpenAI has not yet commented publicly on how it will structure its compliance program. The company is already navigating parallel regulatory processes under the EU AI Act, which classifies certain uses of generative models as high-risk and imposes separate documentation and testing requirements. The overlap between the two frameworks is substantial but not identical, creating potential for duplication or conflict.

Industry observers expect the first round of DSA audits to surface methodological challenges. Unlike traditional platforms, where content moderation can be measured in takedown rates and response times, generative AI systems require evaluation of probabilistic outputs and latent risks. How do you audit a model's tendency to produce harmful content when that tendency is context-dependent and emergent? The Commission has signaled it will lean on academic researchers and civil society organizations to develop assessment methodologies, but this work is still in early stages.

A Template for Other Jurisdictions

Europe's move is already influencing policy discussions elsewhere. Australia's eSafety Commissioner has cited the DSA as a model for its own Online Safety Act amendments. Brazil's draft AI legislation includes a "high-impact system" designation that closely mirrors the Very Large threshold. Even in jurisdictions skeptical of European-style regulation, the DSA provides a reference architecture that policymakers can adapt or contest.

For OpenAI, the immediate challenge is operational: building audit trails, hiring compliance staff, and negotiating the boundaries of transparency without exposing competitive advantages. The longer-term question is strategic. If every major market imposes its own version of systemic risk oversight, does that reshape product development itself? Do models get fine-tuned differently for different regions, or do companies converge on a lowest-common-denominator approach that satisfies the strictest regulator?

The DSA designation does not answer those questions, but it makes them unavoidable. OpenAI is no longer operating in a regulatory frontier; it is now part of the infrastructure that governments believe requires active supervision. How that supervision unfolds will set precedents far beyond Europe.

Read next
Policy

Washington's Robot Tariffs Won't Slow China's Manufacturing Edge

Arjun S. Mehta · 6 min
Policy

Two Arrests in Western Australia Crack Open TeamPCP Supply-Chain Campaign

Arjun S. Mehta · 5 min
Policy

Two Music Giants Accuse Anthropic of Mass Copyright Infringement

Arjun S. Mehta · 5 min
Spot something wrong? Email corrections@dailytechwire.com. We log every correction publicly.