AI Governance Institute
← News
Enforcement2026-08-31

ChatGPT Designated a Very Large Online Platform Under EU DSA

What happened

The European Commission formally designated OpenAI's ChatGPT as a Very Large Online Search Engine (VLOSE) under the EU Digital Services Act, AI and Algorithmic Accountability Provisions, as reported by The Verge. The designation triggers a set of elevated platform obligations distinct from those applied to ordinary online services, covering risk mitigation for minors and user mental health, restrictions on behavioral advertising targeting, controls on illegal content, and requirements for algorithmic transparency. OpenAI has until the end of December 2026 to achieve full compliance with these obligations. The move follows a broader pattern of EU regulatory pressure on frontier AI providers, including tightening monitoring expectations from the AI Office under the EU AI Act that compliance teams have been tracking since early 2026.

Why it matters

  • ·Enterprises using ChatGPT in EU-facing products or workflows now have a vendor operating under elevated regulatory scrutiny, which means any compliance failure by OpenAI before the December 2026 deadline could affect service continuity, contract terms, or the legal basis for certain use cases - vendor risk assessments should be updated to reflect the designation.
  • ·The DSA's algorithmic transparency requirements under the EU Digital Services Act, AI and Algorithmic Accountability Provisions create documentation and disclosure expectations that may extend downstream to enterprise deployers, particularly where ChatGPT is embedded in customer-facing services subject to their own transparency obligations.
  • ·Regulated sectors including financial services, healthcare, and education face compounded exposure: these industries already carry sector-specific AI governance requirements, and a ChatGPT vendor operating under active DSA enforcement adds a new layer of third-party risk that procurement and compliance teams must now account for explicitly.

Governance controls affected

What to do now

  • Update your ChatGPT vendor risk assessment to reflect the VLOSE designation and document how the December 2026 compliance deadline affects your vendor risk rating.
  • Review existing vendor contracts with OpenAI to determine whether they require notification of material regulatory designations and whether DSA obligations create any change-of-terms provisions.
  • Map your EU-facing ChatGPT use cases against the DSA's VLOSE obligations, particularly around minors, mental health risk, and behavioral targeting, to identify where your deployment may be affected by OpenAI's compliance changes.
  • Assess whether any customer-facing products embedding ChatGPT carry independent DSA transparency or algorithmic accountability obligations that now need to be re-examined in light of the designation.
  • Add the December 2026 DSA compliance deadline to your regulatory monitoring calendar and establish a trigger for re-assessment if OpenAI announces material changes to ChatGPT's functionality or data practices in response.

What to watch next

Compliance teams should monitor OpenAI's formal response to the VLOSE designation, particularly any product or data practice changes it announces in advance of the December 2026 deadline, as these could affect enterprise use cases without advance contract notice. The European Commission's enforcement posture toward other AI-powered platforms will also signal whether additional designations are likely, expanding the scope of DSA obligations across the enterprise AI vendor landscape. Teams operating across multiple jurisdictions should watch whether the DSA designation prompts parallel regulatory action in other markets, and should ensure their [CMP-001] multi-jurisdiction compliance mapping is updated to capture any new obligations that flow from it.

Stay ahead of stories like this

Get every EU AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Enforcement2026-09-19

Internal Emails Confirm OpenAI and Microsoft Knew Scraping Was Legally Indefensible

Unsealed documents in the New York Times lawsuit against OpenAI and Microsoft reveal that company executives internally described their AI training practices as the 'largest theft of labor in human history.' Internal Microsoft communications warned of a web 'doom loop' that would erode the economic foundations of content publishers. The disclosures are directly relevant to enterprise copyright compliance, training data governance, and AI vendor due diligence programs.

Research2026-09-18

OpenAI Infrastructure Breach Exposes SSO and Dependency Risk in AI Platforms

Security researchers at Hacktron AI chained a heap buffer overflow in the libheif image library with an SSO misconfiguration in OpenAI's identity infrastructure to gain remote code execution on community.openai.com. The exploit gave access to multiple OpenAI employee ChatGPT and Codex accounts and potentially to the internal monorepo and connected services including GitHub, Slack, and email. The incident was disclosed in September 2026 and carries direct implications for enterprises that rely on OpenAI's platform controls to protect their data and integrated workflows.

Enforcement2026-09-17

Internal Emails Confirm Microsoft and OpenAI Knew Scraping Was Legally Indefensible

Unsealed court filings in the New York Times copyright lawsuit against OpenAI and Microsoft reveal that executives at both companies privately acknowledged that scraping news content for AI training violated fair use principles. A Microsoft director described the practice as potentially the largest theft of labor in human history. The disclosures expose a governance gap between internal risk assessments and continued commercial conduct.