ChatGPT enters EU’s toughest oversight tier

Europe’s largest platforms become part of the terrain regulators must inspect.
Image composition · tobriefIf you saw headlines saying Brussels put ChatGPT, Reddit and Roblox under its toughest online-safety rules, the easy mistake is to read that as a finding of wrongdoing. It is not. The European Commission added all three to a watchlist of services so large that their design choices affect society, not just their users. Think of it less like a safety citation and more like a building moving from self-reported maintenance to mandatory inspections.
The Size Rule
The Digital Services Act draws a line: any online service used by more than 45 million people per month in the EU enters the highest oversight tier (European Commission). That number is roughly a tenth of the EU's population, the point where Brussels considers a service's architecture capable of producing bloc-wide effects (Commission DSA overview).
All three cleared that bar. ChatGPT reported roughly 159 million EU users for its search function, Reddit 57.2 million, and Roblox about 47 million (Euronews, Yahoo News). The total number of designated services now stands at 28 (IEU Monitoring).
Reddit hosts user-generated content. Roblox hosts user-created games. Both fit the mould the DSA was written for. ChatGPT is more interesting. It synthesises answers from across the web into a single conversational response, and the Commission classified it as a search engine because it retrieves and ranks external information when you ask it something (Straits Times). A search engine shapes what users find. A chatbot that searches the web goes further, collapsing multiple sources into one answer, which makes it harder to see why you got that answer and not another.
This is the first time a mainstream AI chatbot has entered this tier. The AI Act, a separate law, imposes transparency duties on chatbots. The DSA designation does something different: it treats the service as information infrastructure large enough to create harms through its design at scale, not through any single post or answer (Les Echos, ZDNet France).
Annual Health Check, Outside Inspector, Open Books
The three services have four months from notification to comply. The obligations amount to a shift from "trust us, we moderate" to provable, auditable governance (DSA, Regulation 2022/2065). Three things change in practice.
First, an annual health check. The companies must identify risks created by their design, algorithms and use patterns, covering illegal content, harm to children, effects on public debate and security (EDAA explainer). Second, an outside inspector. Independent auditors, not the companies, evaluate whether the safeguards actually work (Prighter DSA text). Third, open books for researchers. The Commission and vetted academics can request explanations of how algorithms rank and recommend content, under a framework established by a 2025 delegated regulation.
None of this means an EU official sits between a ChatGPT prompt and its answer, or approves individual Reddit posts. The target is the system: ranking logic, moderation machinery, advertising architecture, child-safety design. When the Commission does find violations, it uses separate enforcement tools, as it has already done with a €120 million fine against X and preliminary findings against Meta over addictive design. Fines can reach 6% of worldwide annual turnover (Brussels Times).
Why Families Should Pay Attention
For parents, Roblox is the most tangible case. Around 70% of its users are under 18 (Biz Chosun). The DSA's guidelines on minors prohibit targeted advertising based on user profiles when a service knows a user is a child. The top-tier designation requires Roblox to assess whether its user-created games, chat systems and recommendation algorithms create risks for children at scale (Commission minors guidelines). Roblox has already introduced facial-recognition age checks, age-banded chat restrictions and AI moderation. The question is whether those tools work together, at scale, and now the Commission will be in a position to judge.
Executive Vice-President Henna Virkkunen framed the designations as holding these services to scrutiny matching their reach (UPI). The enforcement powers behind those words are real. By late December, the companies should be able to show completed risk assessments, audit arrangements and researcher-access processes. What matters now is not the designation itself but whether the Commission's auditing machinery proves sharp enough to distinguish genuine accountability from polished compliance paperwork.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 9/1/2026, 2:08:19 AM
- Pipeline run:
- eu_pipeline_20260901_005007
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication