1

The European Commission has placed the ChatGPT, Reddit, and Roblox platforms under the EU’s strictest internet rules (the DSA). For the first time, a program based on artificial intelligence has been included in this most stringent category.

2

For these companies, this entails a range of costly obligations (among them an annual risk assessment, independent audits, and advertising transparency), and failure to meet them carries a fine of up to 6% of worldwide annual turnover.

3

The Commission’s earlier actions—fines imposed on the X platform and the Temu marketplace, and demands that TikTok and Meta redesign their apps—show that it interprets the notion of “risk” very broadly, not merely as combating illegal content.

4

This raises concerns for freedom of speech: companies may restrict even lawful content “just in case,” the criteria for privileged “flaggers” are vague, and the Commission concentrates decision-making in its own hands.

5

 It remains an open question whether applying these rules to the first AI chatbot will be measured, or whether it will mark the beginning of broader control over the responses of artificial intelligence.


The European Commission has decided to place three further digital services under the strictest supervisory regime provided for in the Digital Services Act (DSA). Under the decision in question, the ChatGPT platform was classified as a VLOSE—a very large online search engine—while the Reddit website and the game Roblox were classified as VLOPs—very large online platforms. This step follows from the fact that the operators of all three services declared that they had exceeded the threshold of 45 million average monthly users in the European Union, which, under Article 33 of the DSA, entails the imposition on providers of the stringent obligations set out in that regulation.

Formally, the Commission’s recent decision fits into the policy that this EU body has consistently pursued of bringing ever more services and their providers within the DSA regulatory net. On the merits, however, the Commission’s latest move deserves attention for at least two reasons. First, for the first time in the history of the regulation’s application, VLOSE status has been granted to a system based on generative artificial intelligence—one that is not merely an ordinary search engine indexing web pages, but that formulates answers to the questions posed to it (ChatGPT). Second, the decision in question concerning the classification of these services fits into broader controversies, long present in public debate, surrounding the Digital Services Act itself—including questions about the limits of this regulation’s interference with freedom of expression and about the scope of the supervisory powers conferred on the Commission.

The Digital Services Act, very large online platforms, and very large online search engines

Regulation (EU) 2022/2065 of the European Parliament and of the Council of October 19, 2022 on a Single Market for Digital Services and amending Directive 2000/31/EC, more widely known as the Digital Services Act, is an act of secondary EU law intended to ensure a safe, predictable, and trustworthy online environment in which the fundamental rights enshrined in the Charter of Fundamental Rights of the European Union are effectively protected. The DSA’s provisions introduce solutions that, among other things, make it possible to combat illegal content online—including illegal goods, services, and information—to counter societal risks online, to identify traders on online marketplaces, and to strengthen oversight.

Not all entities within the scope of this act of secondary EU law are, however, subject to the same requirements. The regulation differentiates the type and intensity of the obligations imposed on them depending on the type of service provided and its scale, subjecting services with a particularly large number of users to the strictest supervisory regime. This follows from the tiered structure of obligations adopted in the DSA, under which the regulation distinguishes, in turn:

  1. intermediary services in the broad sense, comprising mere conduit, caching, and hosting (Article 3(g));
  2. hosting services, on which additional obligations have been imposed relative to intermediary services generally (Article 3(g)(iii) and Articles 16–18 of the DSA);
  3. online platforms—a subcategory of hosting services that make it possible to disseminate content to the public (Article 3(i) and Articles 19–28 of the DSA);
  4. platforms allowing distance contracts to be concluded, subject to additional obligations concerning the traceability of traders (Article 30 of the DSA);
  5. services designated as very large online platforms (VLOPs) and very large online search engines (VLOSEs). This is the highest, most stringent tier of that structure.

The legal basis for this distinction is Article 33 of the DSA, under which online platforms and online search engines reaching at least 45 million average monthly active recipients in the European Union are subject to additional, considerably broader obligations than the other services covered by the regulation. This regime, in principle the same for both of the categories indicated above, includes, among other things:

  • an annual assessment of the systemic risk posed by the service, including risks related to the dissemination of illegal content, adverse effects on minors, users’ physical and mental well-being, fundamental rights, electoral processes, and public security;
  • an obligation to implement proportionate measures to mitigate the risks identified;
  • submission to independent external audits and the maintenance of an internal compliance function (which consists in ensuring that the organization’s activity conforms to applicable law, ethical standards, and internal regulations);
  • maintaining a publicly accessible advertising repository;
  • providing access to data for supervisory authorities and vetted researchers.

The Commission justified placing ChatGPT in the VLOSE category on the ground that this system—described in that body’s communication as a “hybrid service”—by engaging in answering users’ queries and searching the resources of the web for that purpose, meets the functional definition of an online search engine, even though it does not return a classic list of references but rather a synthesized answer. Reddit and Roblox, in turn, were classified as platforms because they make it possible to disseminate to recipients content created by third parties.

It is worth noting that some commentators point out that classifying ChatGPT as a search engine falls within the literal wording of Article 3(j) of the DSA, which covers the return of search results in any format, and that this interpretation is further reinforced by the principle of technological neutrality invoked in recital 119 of the AI Act. The very fact that a provision enacted in 2022—that is, before the mass deployment of generative artificial intelligence—turns out to be capacious enough to cover a service of this kind may suggest that its practical application extends beyond the categories of service that the EU legislature originally had in mind at the time of its adoption. On the other hand, it should be borne in mind that formulating provisions in a technologically neutral manner (that is, without reference to specific, currently existing technical solutions) may be a deliberate legislative device intended to bring within the regulation solutions that do not yet exist when the act is adopted, without the need to amend it each time in step with technological development.

Failure to comply with the obligations imposed carries a fine of up to 6 percent of the provider’s global annual turnover for the service in question, and the Commission thereby acquires direct investigative powers over the designated services that bypass national regulators. Supervision of the enforcement of the decision has been divided between the Commission, Ireland’s Coimisiún na Meán (competent for ChatGPT and Reddit), and the Dutch Authority for Consumers and Markets (competent for Roblox). The deadline for complying with the new obligations is four months from notification of the decision.

The list of entities designated as VLOP or VLOSE providers maintained by the Commission currently contains 24 companies, which together provide 28 services covered by this status, since some of them—such as Google or Meta—provide more than one designated service.

From designation to enforcement: the Digital Services Act in practice

Designation itself is merely a starting point. The practice of applying the DSA to date with respect to previously designated platforms makes it possible to predict, with a high degree of probability, how matters will further proceed in the cases of ChatGPT, Reddit, and Roblox.

The enforcement path usually follows a recurring pattern: the opening of formal proceedings, a request for information, the issuing of preliminary findings, and then a final decision resulting in a fine or an order to change practices—possibly replaced by a settlement in the form of binding commitments accepted by the platform before the final ruling is issued (Articles 66, 67, 79, 73–74, and 71 of the DSA).

The first and, so far, the highest fine imposed under the DSA was EUR 120 million on the X platform for misleading verified-account markings, restricting researchers’ access, and a non-transparent advertising repository, which took place in December 2025. A further precedent came with the EUR 200 million fine imposed in May of this year on the Chinese online store Temu, justified by an inadequate assessment of the risk associated with trade in dangerous products.

Particularly important from the standpoint of this analysis, however, is another strand of enforcement. In February 2026, the Commission issued preliminary findings according to which TikTok’s architecture—including the infinite-scroll mechanism, the automatic playback of content, and push notifications (short messages sent to devices)—may breach the obligations arising from Article 34 of the DSA, because it had not been subjected to an adequate assessment of the risk to users’ mental well-being. Five months later, in July 2026, analogous preliminary findings were issued with respect to Meta, in relation to Instagram and Facebook. The Commission indicated outright that it expects autoplay and infinite scroll to be disabled by default and recommender systems to be made less oriented toward maximizing user engagement.

These cases are important not because they concern obviously harmful matters, but because they show the Commission’s readiness to formulate, on the basis of the general notion of systemic risk, very specific demands concerning product architecture that go beyond the classic understanding of combating illegal content. If the same interpretive standard is applied to ChatGPT, the question arises as to which elements of the functioning of a conversational system—beyond the content of the answers themselves—might be deemed to require regulatory intervention. The manner in which answers are formulated, the length of interaction with the user, and mechanisms that sustain engagement in the conversation are phenomena just as real in chatbots as infinite scroll is in social media.

Freedom of speech under the Commission’s supervision: a range of risks arising from both the Commission’s decision and the Digital Services Act itself

A chilling effect?

The obligation to assess and mitigate (limit) systemic risks, provided for in Articles 34 and 35 of the DSA, is not confined to illegal content—and it is worth noting that this concept is defined very broadly in the regulation. The DSA’s legal glossary defines it as information that, in itself or by reference to an activity, is not in compliance with Union law or with the law of any Member State that is in compliance with Union law, irrespective of the precise subject matter or nature of that law. This means that content permitted under Polish law may be formally deemed “illegal” within the meaning of the DSA on the basis of the law of another Member State—for example, stricter rules on hate speech—although the effect of such an order is, in principle, territorially limited to the state issuing it. In practice, however, as shown below, platforms often standardize moderation standards across the entire Union, which may indirectly extend such more restrictive requirements to Polish users as well.

This obligation also covers the broadly understood impact of a service on public debate, electoral processes, and users’ well-being—that is, categories relating, to a significant extent, to fully lawful content. Critics of this mechanism, including analysts at American think tanks dealing with technology policy, point to the risk of a so-called chilling effect. Because the penalty for an incorrect risk assessment can reach 6 percent of global turnover, platforms have a strong incentive to over-zealously and preemptively restrict content that formally breaches no provision, solely in order to avoid the risk of a dispute with the Commission. This phenomenon is sometimes described as excessive compliance with regulatory requirements—in practice going further than the letter of the law itself requires.

This takes on added significance in the context of the acknowledgment that EU content-moderation standards, given the scale of the European market, are sometimes implemented uniformly by global platforms, including beyond the Union’s borders—something that some commentators describe as the Brussels effect with respect to content regulation.

The specific tool by which providers fulfill the obligation to mitigate systemic risk is the catalog of measures listed in the DSA, which includes, among other things, adapting content-moderation processes—particularly with respect to hate speech—as well as testing and adjusting the algorithmic systems responsible for which content is displayed to the user and which is omitted, including mechanisms analogous to recommender systems, though formally defined separately for platforms and search engines. The provision does not, however, specify what precisely these adjustments are to consist in, leaving this to the discretion of the provider itself, acting under the pressure of a deadline and the threat of a fine. In practice, this means that the decision as to which sources of information the system will regard as reliable and which as risky from the standpoint of “disinformation” or “hate speech” within the meaning of the law of the most restrictive Member State is taken inside the platform itself, without external, transparent oversight of the criteria for that selection. In the case of a conversational system such as ChatGPT, this mechanism translates directly into which sources and arguments the model will take into account in the answer it formulates and which it will omit as “risky,” making it far more sensitive than the classic adjustment of a search engine’s ranking algorithm.

ChatGPT as a precedent in the development of generative artificial intelligence

Placing ChatGPT under the VLOSE regime constitutes the first instance of imposing the obligation to assess systemic risk on a platform that does not distribute the content of others but independently generates answers to a user’s queries. This raises the question of the very measurability of the concept of systemic risk in relation to a service in which there is no clear division between user-created content and the mechanism for its distribution, but in which each answer is the result of a generative process dependent on the way the system has been trained and configured by the provider. The requirement to assess the impact of such a service on matters as sensitive as hallucinations, fabricated citations, electoral disinformation, or mental-health advice may in practice translate into pressure regarding the way the system is to formulate answers on socially controversial topics—not merely into eliminating content that is outright unlawful.

It is worth noting, in this context, that the model behind ChatGPT was already previously subject to the obligations arising from the EU’s AI Act as a general-purpose model. Designation under the DSA does not, therefore, create a new, separate regime, but rather imposes an additional, stricter layer of supervision on top of the obligations existing under the AI Act. OpenAI is thus currently subject cumulatively to two EU supervisory systems, based on partly divergent definitions and criteria for assessing the same service.

The role of trusted flaggers

The DSA provides for the institution of trusted flaggers, to whose reports concerning illegal content platforms are required to give priority. The criteria for granting this status, although formally neutral, rest to a significant extent on vague and discretionary notions, which gives rise to the risk that among the entities obtaining the status of an effectively privileged flagger there will be mainly organizations with a particular worldview profile, not necessarily representative of the full spectrum of views present in public debate. Since Reddit and ChatGPT, as services now covered by the VLOP and VLOSE regime, will also have to take reports from such entities into account in their procedures, this mechanism acquires, in practice, a far broader reach than before.

An analogous mechanism of external risk-signaling is also provided for by the AI Act. Under the provisions of that regulation, a scientific panel of independent experts may alert the AI Office to a systemic risk posed by a given general-purpose AI model, thereby initiating a possible regulatory intervention. As in the case of trusted flaggers under the DSA, an analogous gap becomes apparent here as well. The AI Act requires candidates for membership of the scientific panel to meet three conditions:

  • possession of particular expertise and competence, together with scientific or technical expertise in the field of AI;
  • independence from providers of AI systems or general-purpose AI models;
  • the ability to carry out tasks diligently, accurately, and objectively.

None of these conditions relates to independence from political parties or to experts’ possible ties to the government or EU institutions. Moreover, the experts themselves are selected directly by the European Commission—so the same body that subsequently relies on their findings as a basis for taking supervisory action decides in advance on the composition of the panel meant to initiate that action.

The concentration of supervisory powers in the Commission’s hands

Designation as a VLOP or VLOSE means not only the imposition of additional obligations on the service provider, but also the shift of supervisory powers from national Digital Services Coordinators to the European Commission itself, which, with respect to the obligations provided for in Section 5 of the regulation, has exclusive competence. The Commission has at its disposal, moreover, a broad arsenal of investigative measures, including the power to request information, carry out on-site inspections, and impose interim measures before a case is decided on the merits. Such centralization of supervision over entities of global reach in the hands of a single administrative body, bypassing the courts and national regulators at the earliest stage of proceedings, raises doubts from the standpoint of the principle of the separation of powers and the principle of subsidiarity underlying the legal order of the European Union.

A similar direction can also be discerned in the Commission’s subsequent initiatives. The European Democracy Shield, announced on November 12, 2025, envisages, among other things, the implementation of a “DSA crisis protocol” coordinating the response of authorities to phenomena described as disinformation or foreign information manipulation—something that critics call a tool for centralizing control over the public narrative in Brussels.

The risk of national over-regulation when implementing the DSA

The experience of the Member States shows that the DSA is sometimes used by national legislatures as a pretext for introducing solutions that go beyond what the regulation actually requires. One example is the Polish government’s bill implementing the DSA, which provided for the addition of an administrative mechanism for blocking content online, even though no provision of the DSA imposes such an obligation, and recital 31 of the regulation expressly stipulates that it does not constitute a legal basis for issuing orders of this kind. The scale of controversy surrounding this solution proved serious enough that the President of the Republic of Poland vetoed the act on January 9, 2026 (invoking, among other things, its over-regulatory character), which in itself illustrates how far a national implementation can go beyond what the EU act itself requires. This phenomenon, known as “gold-plating,” shows that the real risk to freedom of expression may stem not so much from the content of the DSA itself as from the manner of its implementation by individual Member States, which makes the assessment of the regulation’s impact on freedom of expression dependent on the national context—especially since, in the view of some authors, the over-regulation of EU law is essentially a chronic phenomenon in Poland.

Delayed judicial review: effects that precede verification

A characteristic feature of the DSA enforcement mechanism is that the measures most burdensome for a provider—such as orders to cease or to remedy an alleged infringement, or interim measures—may be applied by the Commission even before a final, appealable decision is issued, and all the more so before its verification by a court. Only the final decision is subject to review by the General Court of the European Union and, subsequently, by the Court of Justice—which may take years, as shown by the still-unfinished proceedings concerning Amazon’s designation as a VLOP. During that time, the measures imposed by the Commission produce their full factual and financial effects on the designated entity.

What arguments do the DSA’s supporters raise?

For the sake of fairness, it is worth noting that the DSA does not formally impose an obligation to remove lawful content, but merely requires a risk assessment and the implementation of proportionate mitigating measures. The regulation also introduced mechanisms previously unknown in platform practice, such as the obligation to publish statements of reasons for moderation decisions in a publicly accessible database (Article 17 of the DSA) and the possibility of appealing against such decisions through out-of-court dispute resolution. The legitimacy of the VLOP mechanism itself was also the subject of direct judicial review. In its judgment of November 19, 2025 in Case T-367/23, the General Court of the European Union dismissed the action brought by Amazon, which had challenged the compatibility of the entire VLOP regime with the Charter of Fundamental Rights, including the freedom to conduct a business and freedom of expression. The Court did acknowledge that this regime interferes with those freedoms, but held the interference to be proportionate. That judgment is not final, because Amazon has lodged an appeal with the Court of Justice, and the Commission has lodged a cross-appeal, so the case remains pending.

The European Commission’s decision of August 31, 2026 is formally a further, routine procedural step, resulting from three services having exceeded the statutory user threshold. Its practical consequences, however, will genuinely shape the way these services function in the European Union, through annual risk assessments, independent audits, and the constant financial pressure arising from the threat of fines reaching 6 percent of global turnover—both for the entities operating in this area and for hundreds of millions of users in the 27 Member States of the European Union (and beyond). Importantly, these are obligations imposed cumulatively on a model that was already previously subject to a separate supervisory regime under the AI Act.

Of particular significance here is the fact that, for the first time, the DSA’s strictest supervisory regime covers a generative artificial intelligence system, rather than a service based solely on the distribution of content created by third parties. The DSA enforcement practice to date—including the demands to change the very architecture of the product formulated with respect to TikTok and Meta—shows that the Commission is inclined to interpret the notion of systemic risk broadly, going beyond the classic combating of unlawful content. It remains an open question whether enforcing this standard against the first AI chatbot to hold VLOSE status will stay within the bounds of proportionality, or whether it will become the starting point for far broader control over the way artificial intelligence systems formulate answers on topics important from the standpoint of public debate.

Patryk Ignaszczak – analyst at the Ordo Iuris Center for International Law

See also:

Source of cover photo: iStock

Support us