Summary
- The European Commission has said ChatGPT and Roblox could potentially fall within the DSA’s largest platform regime.
- Designation would bring duties around systemic risk, transparency, audit, and regulatory data access.
- The debate shows how large AI services are being assessed not only as models, but as digital intermediaries.
OpenAI could face a more platform-style regulatory regime in Europe if ChatGPT is designated under the Digital Services Act’s rules for very large online platforms or search engines.
The European Commission has said ChatGPT and Roblox could potentially be included in the DSA designation system after both services announced user numbers above the regime’s threshold. Under the DSA, platforms and search engines with more than 45 million monthly users in the EU can be brought under additional obligations.
Commission spokesperson Thomas Regnier said designation was “definitely possible” and could “come sooner or later”. A designation would not be a finding of breach, but it would move ChatGPT into a regulatory structure originally built around large online intermediaries rather than general software tools.
The DSA’s largest service category carries duties around systemic risk assessment, mitigation, transparency, independent audits, and access to data for regulators and vetted researchers. Those duties were designed for services whose scale can affect information flows, consumer protection, public security, fundamental rights, and democratic processes.
Generative AI complicates those categories. ChatGPT is not a social network in the usual sense, but it is a high-volume interface through which users search, draft, summarise, code, ask for advice, generate media, and interact with automated systems. Once a service shapes access to information and produces content at platform scale, the regulatory boundary between tool and intermediary becomes harder to hold.
The debate sits alongside the EU AI Act, which already introduces obligations for general purpose AI models and high risk uses. The DSA would not replace those obligations, although it could add a layer focused on distribution, systemic risk, service design, transparency, and user-facing governance. Providers would then need to manage both the model-risk regime and a platform-risk regime.
That would affect more than public policy teams inside AI vendors. Product features, logging, data access processes, moderation systems, researcher access, and audit arrangements could all be shaped by designation. Enterprise customers using AI systems in regulated sectors would also need to understand how supplier obligations affect reliability, safety controls, documentation, and contractual assurance.
European technology regulation has often moved through adjacent laws before AI-specific rules mature. Data protection, consumer protection, competition law, online safety, and platform regulation are all now being applied to AI services whose business models and technical architectures are still changing. ChatGPT’s possible DSA treatment is one more sign that scale, not just model capability, will define the next regulatory perimeter.










