Commission designates ChatGPT, Reddit, Roblox under the Digital Services Act (31 August 2026)
Tag: S-2026-08-31-ec-dsa-chatgpt-vlose-designation Type: article (European Commission press release / news item, DG CONNECT digital-strategy site; presscorner reference IP/26/1772) Author(s): European Commission Date of source: 2026-08-31 (news item “Last update” 4 September 2026) Date ingested: 2026-09-08 (catch-up capture for the 29 Aug–7 Sep 2026 scan outage) Authority weight: high — primary Commission publication retrieved in full from the official digital-strategy site; but narrow in scope (a short designation notice), and the fuller presscorner text was not retrieved (JS shell). Raw file: S-2026-08-31-ec-dsa-chatgpt-vlose-designation.md. News item: digital-strategy.ec.europa.eu/en/news/commission-designates-chatgpt-reddit-roblox-under-digital-services-act.
What it claims
On 31 August 2026 the European Commission designated ChatGPT as a Very Large Online Search Engine (VLOSE), and Reddit and Roblox as Very Large Online Platforms (VLOPs), under the Digital Services Act (DSA). The basis stated is that these services “declared that they reach at least 45 million average monthly users in the EU and thus meet the threshold for designation.”
Following notification of the designations, the services have four months — i.e. by January 2027 — to comply with the additional DSA obligations that apply to VLOPs and VLOSEs. The notice gives as its example of those obligations “assessing and mitigating the systemic risks stemming from their service and algorithmic systems” related to the dissemination of illegal content, negative effects on minors, users’ physical and mental well-being, fundamental rights, electoral processes and public security. The item links to the Commission’s list of designated VLOPs/VLOSEs and to the DSA policy page.
The notice does not discuss the AI Act, general-purpose AI, or any sectoral (including financial-services) implications. It is a DSA action published in the same Commission news stream as the AI Office / AI Act items the wiki tracks.
Notable quotes
- “The Commission has designated ChatGPT as a Very Large Online Search Engine (VLOSE), as well as Reddit and Roblox as Very Large Online Platforms (VLOPs), under the Digital Services Act (DSA).” (news item, para. 1)
- “These services declared that they reach at least 45 million average monthly users in the EU and thus meet the threshold for designation.” (para. 2)
- “…these services have four months, i.e. by January 2027, to comply with the additional DSA obligations for VLOPs and VLOSEs, such as assessing and mitigating the systemic risks stemming from their service and algorithmic systems…” (para. 3)
What’s speculative vs. asserted
- Asserted (as fact): the 31 Aug 2026 designations and their classes; the ≥45 million average monthly EU users threshold as the basis (self-declared by the services); the four-month compliance window ending January 2027; the illustrative systemic-risk categories.
- Not stated by the source (not retrieved this run): the full obligation set (the DSA’s VLOP/VLOSE package generally includes annual systemic-risk assessments, mitigation measures, independent audits, data access for vetted researchers and transparency reporting — but the notice itemises only risk assessment/mitigation, and the fuller presscorner text was not retrieved); which OpenAI entity or ChatGPT service scope is designated.
- Ingesting-agent inference (not the source’s claim): that ChatGPT now sits under two overlapping EU governance layers — AI Act GPAI obligations enforced by the EU AI Office since 2 August 2026 and DSA VLOSE systemic-risk obligations supervised by the Commission — and that for financial-services deployers the practical read-across is to third-party / DORA due-diligence evidence (what systemic-risk assessments and mitigations the provider must now produce), not a new obligation on the firm. The source says nothing about financial services.
Topics this feeds
- EU AI Act — added as a Detail note on regulatory layering: a GPAI-based service subject to both the AI Office’s GPAI regime and the DSA VLOSE regime; the two regimes are distinct instruments with distinct supervisors and timelines (DSA compliance by January 2027).
- Operational Resilience and Third Party Risk — related only (not edited this run): a third-party GPAI provider’s new DSA systemic-risk obligations are a potential due-diligence evidence source for FS deployers [inference].
Open questions raised
- What is the full set of DSA VLOSE obligations ChatGPT must meet by January 2027 (independent audit, data access, transparency reporting, crisis response), and will the resulting systemic-risk assessments be public or usable by enterprise customers as third-party-risk evidence?
- How will the Commission coordinate DSA VLOSE supervision of ChatGPT with the AI Office’s GPAI supervision of the underlying models under the AI Act — one provider, two regimes?
- Is the designation scoped to the consumer ChatGPT service only, or does it reach enterprise/API deployments that FS firms actually use?