OpenAI’s ChatGPT is set to face tougher oversight in the European Union after the European Commission designated it a Very Large Online Search Engine under the Digital Services Act (DSA).
The designation puts ChatGPT in a category of services subject to heightened obligations intended for online products with broad public reach and potential systemic effects. For OpenAI, the immediate regulatory focus includes mitigating risks connected to minors, user mental health and the spread of illegal content.
What changed
The DSA is the EU’s framework for regulating major online services and platforms. Its requirements go beyond removing individual pieces of prohibited content: covered services must assess and reduce wider risks associated with how their products operate.
The Commission’s announcement also designated Reddit and Roblox as Very Large Online Platforms. While those services operate differently from a conversational AI system, the grouping signals the EU’s willingness to apply its largest-service rules across social, gaming and AI-driven consumer products.
For ChatGPT, the classification creates a more formal accountability structure around risks that have become central to debates over consumer AI. That includes how young users interact with the service, whether use can affect mental health, and how the product may be used to find, create or distribute illegal material.
Why operators should care
The decision matters beyond OpenAI. It offers a practical signal to companies building AI products with significant EU usage: consumer-facing generative AI can be treated as a major online service, rather than as a separate regulatory category outside platform rules.
For product, trust-and-safety and legal teams, this means risk management is becoming a core operating requirement. Companies expanding conversational AI products in Europe will need to consider protections for younger users, mechanisms for handling illegal content, and evidence that their safeguards work in practice.
The DSA also limits certain advertising practices for covered platforms, including targeting ads to minors and targeting people based on sexual orientation, religion, ethnicity or political beliefs. Businesses whose AI products develop advertising models will need to account for those boundaries in their European product design.
A shift from voluntary safety work to regulatory accountability
AI providers have increasingly introduced their own safety policies and moderation systems. The DSA designation changes the context: OpenAI will be accountable to a defined EU regime for mitigating specified categories of systemic risk.
That distinction is important for executives. Safety features that were once positioned as product choices can become compliance controls, requiring clearer ownership, documentation and ongoing review. The issue is not simply whether a chatbot can refuse unsafe requests, but whether the service’s design and operation adequately address broader harms.
What to watch next
The key question is how the new obligations are applied to a conversational AI product. ChatGPT does not resemble a conventional social network or search engine in every respect, so its treatment may help establish how the DSA maps onto generative AI interfaces.
Operators should watch for the Commission’s expectations around risk assessment, safeguards for minors and mental-health-related risks, and enforcement approaches to illegal content. Those details could become a blueprint for other high-reach AI services operating in Europe.
For founders and builders, the message is straightforward: as AI products scale, governance is no longer only a policy discussion. In the EU, it is increasingly part of the product and operating model.
