ChatGPT Designated a Very Large Online Platform Under EU DSA
What happened
The European Commission formally designated OpenAI's ChatGPT as a Very Large Online Search Engine (VLOSE) under the EU Digital Services Act, AI and Algorithmic Accountability Provisions, as reported by The Verge. The designation triggers a set of elevated platform obligations distinct from those applied to ordinary online services, covering risk mitigation for minors and user mental health, restrictions on behavioral advertising targeting, controls on illegal content, and requirements for algorithmic transparency. OpenAI has until the end of December 2026 to achieve full compliance with these obligations. The move follows a broader pattern of EU regulatory pressure on frontier AI providers, including tightening monitoring expectations from the AI Office under the EU AI Act that compliance teams have been tracking since early 2026.
Why it matters
- ·Enterprises using ChatGPT in EU-facing products or workflows now have a vendor operating under elevated regulatory scrutiny, which means any compliance failure by OpenAI before the December 2026 deadline could affect service continuity, contract terms, or the legal basis for certain use cases - vendor risk assessments should be updated to reflect the designation.
- ·The DSA's algorithmic transparency requirements under the EU Digital Services Act, AI and Algorithmic Accountability Provisions create documentation and disclosure expectations that may extend downstream to enterprise deployers, particularly where ChatGPT is embedded in customer-facing services subject to their own transparency obligations.
- ·Regulated sectors including financial services, healthcare, and education face compounded exposure: these industries already carry sector-specific AI governance requirements, and a ChatGPT vendor operating under active DSA enforcement adds a new layer of third-party risk that procurement and compliance teams must now account for explicitly.
Governance controls affected
What to do now
- ☐Update your ChatGPT vendor risk assessment to reflect the VLOSE designation and document how the December 2026 compliance deadline affects your vendor risk rating.
- ☐Review existing vendor contracts with OpenAI to determine whether they require notification of material regulatory designations and whether DSA obligations create any change-of-terms provisions.
- ☐Map your EU-facing ChatGPT use cases against the DSA's VLOSE obligations, particularly around minors, mental health risk, and behavioral targeting, to identify where your deployment may be affected by OpenAI's compliance changes.
- ☐Assess whether any customer-facing products embedding ChatGPT carry independent DSA transparency or algorithmic accountability obligations that now need to be re-examined in light of the designation.
- ☐Add the December 2026 DSA compliance deadline to your regulatory monitoring calendar and establish a trigger for re-assessment if OpenAI announces material changes to ChatGPT's functionality or data practices in response.
What to watch next
Compliance teams should monitor OpenAI's formal response to the VLOSE designation, particularly any product or data practice changes it announces in advance of the December 2026 deadline, as these could affect enterprise use cases without advance contract notice. The European Commission's enforcement posture toward other AI-powered platforms will also signal whether additional designations are likely, expanding the scope of DSA obligations across the enterprise AI vendor landscape. Teams operating across multiple jurisdictions should watch whether the DSA designation prompts parallel regulatory action in other markets, and should ensure their [CMP-001] multi-jurisdiction compliance mapping is updated to capture any new obligations that flow from it.
Stay ahead of stories like this
Get every EU AI governance development like this one, plus the rest of the week's developments. Every Thursday.
