The 60-second summary
On 31 August 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine (VLOSE), and Reddit and Roblox as Very Large Online Platforms (VLOPs), under the Digital Services Act. Each service reported at least 45 million average monthly users in the EU. The designation activates the DSA’s additional obligations for the largest services four months after notification; the Commission says compliance is required by January 2027. These duties include systemic-risk assessment and mitigation, independent annual audits, an internal compliance function, regulator and vetted-researcher data access, and enhanced transparency. Designation is not a finding that any service breached the DSA.
Timeline that matters
31 August 2026
Designation announced
The Commission designated ChatGPT as a VLOSE and Reddit and Roblox as VLOPs.
31 August 2026
Commission register updated
The official register recorded reported average monthly users of 159.1 million, 57.2 million and 46.6 million respectively, and said the designation decisions were not yet publicly available.
By January 2027
Additional duties apply
The Commission states the services have four months after notification to comply. Confirm the exact day from each notified decision.
3 September 2026
PrivacyBuilt review
Official announcement, designation register, DSA overview, enforcement framework and binding regulation checked.
10 September 2026
Next editorial review
Check whether the designation decisions have been published and whether they provide a more precise notified date or scope detail.
What changed
The named services move into the DSA’s most intensive supervisory tier. The Commission lists ChatGPT as a VLOSE with 159.1 million average monthly users, Reddit as a VLOP with 57.2 million, and Roblox as a VLOP with 46.6 million. The additional duties attach to the designated services after the statutory four-month period. The Commission’s public register notes that the designation decisions themselves were not yet available when the register was updated, so teams should retain the notified decision and calculate the exact deadline from that notice rather than infer a day from the press release alone.
Who should pay attention?
Named service providers
Confirm the notified deadline, accountable owners, risk-assessment scope, audit readiness and evidence for every additional duty.
Product, trust and safety teams
Connect risk findings to testable mitigations across ranking, discovery, moderation, reporting, minors’ experiences and recommender controls.
Privacy, legal and compliance teams
Coordinate DSA work with data-protection, consumer-protection and AI-governance obligations without treating one assessment as a substitute for another.
Vendors and business customers
Track changes to controls, data access, terms and assurance packages, and request evidence proportionate to the dependency.
What the guidance clarifies
- Designation is not an infringement finding
- The Commission designated the services because their reported reach met the statutory threshold. It did not announce a breach, fine or enforcement proceeding against them in this release.
- The service classification differs
- ChatGPT is designated as a Very Large Online Search Engine. Reddit and Roblox are designated as Very Large Online Platforms. Teams should map the duties to the designated service and its role rather than treat all three as identical products.
- The deadline runs from notification
- The DSA applies four months after notification of the designation decision. The Commission summarises the deadline as January 2027; the provider’s notified decision is the authoritative record for the exact day.
- Additional governance duties are triggered
- The largest services must assess and mitigate systemic risks, maintain an internal compliance function, undergo independent annual audits and support supervisory and vetted-researcher access to data.
- Business customers do not inherit the designation
- Organisations using the services should monitor contractual, product and assurance changes, but the designation does not by itself make every customer a VLOP or VLOSE.
Largest-service governance is becoming operational evidence
Why this matters for global organisations
A designation at this scale can change product controls, contractual assurances, audit materials and access arrangements throughout a service ecosystem. Organisations that depend on a designated service should identify the workflows involved, request proportionate evidence and avoid assuming that a provider’s regulatory programme resolves their own responsibilities.
- Map which critical workflows depend on each designated service.
- Record product, policy and contractual changes that affect risk or data handling.
- Request current assurance for high-impact uses rather than relying on generic statements.
- Keep local accountability for configuration, content, access and downstream decisions.
12 actions to start now
- Obtain and retain the notified designation decision; record the exact four-month compliance date and service boundary.
- Create an obligation map separating baseline DSA duties from the additional VLOP or VLOSE requirements.
- Assign accountable owners for systemic-risk assessment, mitigation, audit, compliance, data access, advertising and recommender transparency.
- Define the assessment perimeter across algorithms, interfaces, moderation, search or discovery, advertising, minors’ experiences and third-party integrations.
- Build a risk register covering illegal content, fundamental rights, public security, electoral processes, minors, wellbeing and other relevant systemic risks.
- Link every material risk to a measurable mitigation, owner, test method, residual-risk decision and review date.
- Commission an independent audit with sufficient scope, access and remediation tracking; preserve independence and competence evidence.
- Test the non-profiling recommender option where applicable and document how users can find and use it.
- Validate advertising transparency and repository controls where the service carries advertising.
- Establish procedures for Commission, Digital Services Coordinator and vetted-researcher data requests, including privacy and security review.
- Update vendor and subprocessor oversight for moderation, age assurance, audit, analytics and safety services.
- Run a readiness exercise covering an information request, preservation of evidence, executive escalation and remediation governance.
Suggested next steps
- Confirm the exact compliance day from the notified designation decision when available. Validate applicability and implementation choices with qualified specialists. The checklist is PrivacyBuilt’s operational analysis, not an official Commission checklist.
Evidence worth retaining
- Notification and designation decision, with deadline calculation and service-scope memorandum.
- Board or executive-approved governance map and internal compliance-function mandate.
- Systemic-risk assessment methodology, inventory, evidence inputs and approved results.
- Mitigation designs, test results, effectiveness metrics and residual-risk decisions.
- Independent auditor engagement, competence and independence records, audit report and remediation log.
- Recommender-system documentation and non-profiling-option test evidence where applicable.
- Advertising-repository and transparency-control test results where applicable.
- Regulator and vetted-researcher request procedures, access logs and privacy/security assessments.
- Vendor due-diligence files, contracts, service changes and assurance reports.
- Training, incident exercises, escalation records and management review minutes.
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- What is the exact notification date and legal scope stated in the designation decision?
- Which systems, features and interfaces form part of the designated service?
- How should systemic risks be assessed where DSA, data-protection, consumer-protection and AI-governance duties overlap?
- Does the proposed audit scope meet the DSA requirements for independence, coverage and follow-up?
- What data can be provided to authorities or vetted researchers, and what safeguards remain necessary?
- Which recommender, advertising and minors’ protection duties apply to this service design?
- Which product or contractual changes require notice to business customers or a renewed vendor-risk assessment?
- What evidence should management review before signing off readiness?
Official sources
- European Commission — designation announcement, 31 August 2026
- European Commission — register of designated VLOPs and VLOSEs, updated 31 August 2026
- European Commission — obligations for VLOPs and VLOSEs
- European Commission — DSA enforcement framework
- EUR-Lex — Regulation (EU) 2022/2065 (Digital Services Act)
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.