AI Governance Institute
← News
Enforcement2026-08-31

ChatGPT Designated a Very Large Online Platform Under EU DSA

What happened

The European Commission formally designated OpenAI's ChatGPT as a Very Large Online Search Engine (VLOSE) under the EU Digital Services Act, AI and Algorithmic Accountability Provisions, as reported by The Verge. The designation triggers a set of elevated platform obligations distinct from those applied to ordinary online services, covering risk mitigation for minors and user mental health, restrictions on behavioral advertising targeting, controls on illegal content, and requirements for algorithmic transparency. OpenAI has until the end of December 2026 to achieve full compliance with these obligations. The move follows a broader pattern of EU regulatory pressure on frontier AI providers, including tightening monitoring expectations from the AI Office under the EU AI Act that compliance teams have been tracking since early 2026.

Why it matters

  • ·Enterprises using ChatGPT in EU-facing products or workflows now have a vendor operating under elevated regulatory scrutiny, which means any compliance failure by OpenAI before the December 2026 deadline could affect service continuity, contract terms, or the legal basis for certain use cases - vendor risk assessments should be updated to reflect the designation.
  • ·The DSA's algorithmic transparency requirements under the EU Digital Services Act, AI and Algorithmic Accountability Provisions create documentation and disclosure expectations that may extend downstream to enterprise deployers, particularly where ChatGPT is embedded in customer-facing services subject to their own transparency obligations.
  • ·Regulated sectors including financial services, healthcare, and education face compounded exposure: these industries already carry sector-specific AI governance requirements, and a ChatGPT vendor operating under active DSA enforcement adds a new layer of third-party risk that procurement and compliance teams must now account for explicitly.

Governance controls affected

What to do now

  • Update your ChatGPT vendor risk assessment to reflect the VLOSE designation and document how the December 2026 compliance deadline affects your vendor risk rating.
  • Review existing vendor contracts with OpenAI to determine whether they require notification of material regulatory designations and whether DSA obligations create any change-of-terms provisions.
  • Map your EU-facing ChatGPT use cases against the DSA's VLOSE obligations, particularly around minors, mental health risk, and behavioral targeting, to identify where your deployment may be affected by OpenAI's compliance changes.
  • Assess whether any customer-facing products embedding ChatGPT carry independent DSA transparency or algorithmic accountability obligations that now need to be re-examined in light of the designation.
  • Add the December 2026 DSA compliance deadline to your regulatory monitoring calendar and establish a trigger for re-assessment if OpenAI announces material changes to ChatGPT's functionality or data practices in response.

What to watch next

Compliance teams should monitor OpenAI's formal response to the VLOSE designation, particularly any product or data practice changes it announces in advance of the December 2026 deadline, as these could affect enterprise use cases without advance contract notice. The European Commission's enforcement posture toward other AI-powered platforms will also signal whether additional designations are likely, expanding the scope of DSA obligations across the enterprise AI vendor landscape. Teams operating across multiple jurisdictions should watch whether the DSA designation prompts parallel regulatory action in other markets, and should ensure their [CMP-001] multi-jurisdiction compliance mapping is updated to capture any new obligations that flow from it.

Stay ahead of stories like this

Get every EU AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Enforcement2026-08-29

Sony and Warner Sue Anthropic Over Training Data, Exposing Vendor IP Risk

Sony Music and Warner Chappell have filed a copyright infringement lawsuit against Anthropic in the US District Court for the Northern District of California, alleging that tens of thousands of protected works were used to train Claude without authorization. The complaint seeks up to $150,000 per infringed work and up to $25,000 per instance of stripped copyright metadata, with total exposure potentially reaching several billion dollars. Co-founders Dario Amodei and Benjamin Mann are named as individual defendants.

Corporate Policy2026-08-18

OpenAI's Teen ChatGPT Launch Exposes a Vendor Intake Gap in Education Compliance

OpenAI has launched a teen-specific version of ChatGPT with default content restrictions, a Study Mode feature, and parental notification tools, years after minors began using the general product without age-specific safeguards. The offering is grounded in OpenAI's Under-18 Principles from its Model Spec. Enterprise compliance teams in education, edtech, and family-facing platform sectors now face a vendor governance reassessment obligation.

Corporate Policy2026-08-29

OpenAI's Cyber-Pacing Framework Creates New Vendor Governance Obligations

OpenAI published a governance framework titled 'Pacing model development in an era of cyber-critical systems' on August 18, 2026, outlining how it will manage model development, access controls, and monitoring for cyber-sensitive deployments. The framework addresses alignment, abuse monitoring, and security measures for more capable models. Enterprise customers relying on OpenAI's internal controls as compensating controls in their own risk programs now face a direct obligation to evaluate whether this framework is operationally binding.