Background: What VLOP Means and Why This Time Is Different
The EU's Digital Services Act (DSA) defines any service with more than 45 million monthly users in the EU as a Very Large Online Platform (VLOP). Once a service gets the VLOP label, it must comply with a long list of additional obligations — content moderation, minor protection, ad library disclosure, systemic risk assessment, and more. Non-compliance can trigger fines of up to 6% of global annual revenue, which for a company like OpenAI, with revenue in the multi-billion range, would translate into potential penalties of billions of dollars.
The VLOP list until now has been populated mostly by social media platforms (such as X and the Meta family) and marketplaces (AliExpress). Of the three new entries this round, only Reddit and Roblox fit the conventional platform mold. ChatGPT is the first generative AI conversational product ever placed on the VLOP list. This is the first time the DSA has treated an LLM application under the full platform-regulator lens, rather than as a model or tool.
Core of the Decision: How Brussels Got There
The European Commission made the designation public on Monday, with tech chief Henna Virkkunen stating: "ChatGPT, Reddit, and Roblox will now be held to a higher standard of scrutiny and accountability in the European Union, in line with their large impact on our citizens and society."
The trigger was the 45 million EU monthly user threshold, which all three services have now crossed. An OpenAI spokesperson confirmed the company is preparing to meet the additional compliance requirements. Roblox called itself "the first gaming platform to reach this milestone in the EU." Reddit did not respond to media inquiries by the time of publication.
The compliance deadline is the end of December this year. In other words, OpenAI has under four months to reshape its internal content moderation, advertising, and risk assessment systems to DSA standards.
Why This Cut Cuts OpenAI Especially Deep
The DSA was originally designed around social media feeds and comment sections. For a product whose primary interface is "user prompts, model answers," each obligation has to be remapped. For example:
- Content moderation obligation: Is a model's output "illegal content published by the platform"? If a user uses ChatGPT to generate child sexual abuse material, does OpenAI bear the same responsibility as X hosting terrorist videos?
- Ad library disclosure: ChatGPT has already started inserting ads in the free tier. How must the targeting logic and user profiles be made transparent?
- Risk assessment: OpenAI must now file annual systemic risk assessment reports covering illegal content, minor protection, and impact on civic discourse — a system originally built for social networks.
Brussels has already opened a DSA investigation into X's AI chatbot Grok, but Grok sits inside the X platform as a sub-product. This designation treats ChatGPT directly as a platform, in a way that is broader and more complete.
Relationship with the AI Act: DSA Is the Immediate Blade, AI Act the Long Arc
Brussels is currently wielding two knives against AI: the AI Act, which has been phasing in and governs model development and deployment; and the DSA, which this time reaches into the user-facing interface. OpenAI cannot satisfy the AI Act's transparency obligations alone — it must also meet DSA's platform-level requirements.
More complexity is coming. The EU is investigating Google's use of AI Overviews under competition rules, and is enforcing the AI Act in parallel. Two legal regimes stacked together mean any AI company operating in the EU now has to satisfy both the model layer and the application layer of regulation.
My Take: This Is Not Just a Fine Threat — It Is a Rewrite of Compliance Shape
In the short term, OpenAI won't make radical product changes because of this designation — the main task is documentation and process transformation. In the medium to long term, however, this event will rewrite several default assumptions of generative AI products:
- Model output is no longer "user behavior" but "platform content." This means OpenAI needs a traceable accountability chain for every model output, not just refusal rate and RLHF optimization.
- The ad monetization path is being tightened. The DSA requires VLOPs to disclose ad libraries and prohibit targeting based on sensitive attributes — a heavy blow to ChatGPT's strategy of placing ads inside answers.
- Spillover effects outside the EU. Similar to the earlier case of AI Act Article 50 text watermarks, once OpenAI rebuilds its product for the EU alone, that compliance capability will eventually sink into a "global default."
In short, this designation does not have OpenAI worried about the next fine — it is the first time generative AI has been governed as a "platform." Models belong to models, platforms belong to platforms — that line, the EU has now drawn clearly.