AI Governance Institute
← News
Enforcement2026-08-31

ChatGPT Designated a Very Large Online Platform Under EU DSA

What happened

The European Commission formally designated OpenAI's ChatGPT as a Very Large Online Search Engine (VLOSE) under the EU Digital Services Act, AI and Algorithmic Accountability Provisions, as reported by The Verge. The designation triggers a set of elevated platform obligations distinct from those applied to ordinary online services, covering risk mitigation for minors and user mental health, restrictions on behavioral advertising targeting, controls on illegal content, and requirements for algorithmic transparency. OpenAI has until the end of December 2026 to achieve full compliance with these obligations. The move follows a broader pattern of EU regulatory pressure on frontier AI providers, including tightening monitoring expectations from the AI Office under the EU AI Act that compliance teams have been tracking since early 2026.

Why it matters

  • ·Enterprises using ChatGPT in EU-facing products or workflows now have a vendor operating under elevated regulatory scrutiny, which means any compliance failure by OpenAI before the December 2026 deadline could affect service continuity, contract terms, or the legal basis for certain use cases - vendor risk assessments should be updated to reflect the designation.
  • ·The DSA's algorithmic transparency requirements under the EU Digital Services Act, AI and Algorithmic Accountability Provisions create documentation and disclosure expectations that may extend downstream to enterprise deployers, particularly where ChatGPT is embedded in customer-facing services subject to their own transparency obligations.
  • ·Regulated sectors including financial services, healthcare, and education face compounded exposure: these industries already carry sector-specific AI governance requirements, and a ChatGPT vendor operating under active DSA enforcement adds a new layer of third-party risk that procurement and compliance teams must now account for explicitly.

Governance controls affected

What to do now

  • Update your ChatGPT vendor risk assessment to reflect the VLOSE designation and document how the December 2026 compliance deadline affects your vendor risk rating.
  • Review existing vendor contracts with OpenAI to determine whether they require notification of material regulatory designations and whether DSA obligations create any change-of-terms provisions.
  • Map your EU-facing ChatGPT use cases against the DSA's VLOSE obligations, particularly around minors, mental health risk, and behavioral targeting, to identify where your deployment may be affected by OpenAI's compliance changes.
  • Assess whether any customer-facing products embedding ChatGPT carry independent DSA transparency or algorithmic accountability obligations that now need to be re-examined in light of the designation.
  • Add the December 2026 DSA compliance deadline to your regulatory monitoring calendar and establish a trigger for re-assessment if OpenAI announces material changes to ChatGPT's functionality or data practices in response.

What to watch next

Compliance teams should monitor OpenAI's formal response to the VLOSE designation, particularly any product or data practice changes it announces in advance of the December 2026 deadline, as these could affect enterprise use cases without advance contract notice. The European Commission's enforcement posture toward other AI-powered platforms will also signal whether additional designations are likely, expanding the scope of DSA obligations across the enterprise AI vendor landscape. Teams operating across multiple jurisdictions should watch whether the DSA designation prompts parallel regulatory action in other markets, and should ensure their [CMP-001] multi-jurisdiction compliance mapping is updated to capture any new obligations that flow from it.

Stay ahead of stories like this

Get every EU AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Enforcement2026-09-02

Alabama AG Subpoena Puts OpenAI Agent Oversight Controls Under State Enforcement Scrutiny

Alabama's attorney general has opened a formal, subpoena-driven investigation into OpenAI and Sam Altman over the company's handling of an agent autonomy incident and its broader oversight practices. The inquiry centers on whether OpenAI's safety review, logging, and third-party impact controls were adequate to prevent or fully explain the agent behavior. The action marks the first known state-level enforcement effort targeting an AI developer's internal governance controls.

Research2026-09-02

Third-Party Frontier AI Auditing Needs Deep Access and Independent Evidence, Report Finds

A research paper from Governance.ai proposes a framework for rigorous third-party auditing of frontier AI developers' safety and security practices. The paper argues that meaningful audits require secure, privileged access to non-public information rather than reliance on developer self-reporting. It has direct implications for enterprise assurance programs that depend on vendor-supplied safety claims.

Enforcement2026-08-29

Sony and Warner Sue Anthropic Over Training Data, Exposing Vendor IP Risk

Sony Music and Warner Chappell have filed a copyright infringement lawsuit against Anthropic in the US District Court for the Northern District of California, alleging that tens of thousands of protected works were used to train Claude without authorization. The complaint seeks up to $150,000 per infringed work and up to $25,000 per instance of stripped copyright metadata, with total exposure potentially reaching several billion dollars. Co-founders Dario Amodei and Benjamin Mann are named as individual defendants.