Skip to content

Regulatory Pulse

Commission designates ChatGPT, Reddit and Roblox under the DSA

The Commission’s 31 August 2026 DSA designations trigger additional systemic-risk, audit, compliance and transparency duties within four months.

European Union
Digital Services Act, platform governance and AI governance
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Binding DSA designation decisions — additional duties follow within four months · Reviewed 3 September 2026 · 7 min read

The 60-second summary

On 31 August 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine (VLOSE), and Reddit and Roblox as Very Large Online Platforms (VLOPs), under the Digital Services Act. Each service reported at least 45 million average monthly users in the EU. The designation activates the DSA’s additional obligations for the largest services four months after notification; the Commission says compliance is required by January 2027. These duties include systemic-risk assessment and mitigation, independent annual audits, an internal compliance function, regulator and vetted-researcher data access, and enhanced transparency. Designation is not a finding that any service breached the DSA.

Timeline that matters

  1. 31 August 2026

    Designation announced

    The Commission designated ChatGPT as a VLOSE and Reddit and Roblox as VLOPs.

  2. 31 August 2026

    Commission register updated

    The official register recorded reported average monthly users of 159.1 million, 57.2 million and 46.6 million respectively, and said the designation decisions were not yet publicly available.

  3. By January 2027

    Additional duties apply

    The Commission states the services have four months after notification to comply. Confirm the exact day from each notified decision.

  4. 3 September 2026

    PrivacyBuilt review

    Official announcement, designation register, DSA overview, enforcement framework and binding regulation checked.

  5. 10 September 2026

    Next editorial review

    Check whether the designation decisions have been published and whether they provide a more precise notified date or scope detail.

What changed

The named services move into the DSA’s most intensive supervisory tier. The Commission lists ChatGPT as a VLOSE with 159.1 million average monthly users, Reddit as a VLOP with 57.2 million, and Roblox as a VLOP with 46.6 million. The additional duties attach to the designated services after the statutory four-month period. The Commission’s public register notes that the designation decisions themselves were not yet available when the register was updated, so teams should retain the notified decision and calculate the exact deadline from that notice rather than infer a day from the press release alone.

Who should pay attention?

Named service providers

Confirm the notified deadline, accountable owners, risk-assessment scope, audit readiness and evidence for every additional duty.

Product, trust and safety teams

Connect risk findings to testable mitigations across ranking, discovery, moderation, reporting, minors’ experiences and recommender controls.

Privacy, legal and compliance teams

Coordinate DSA work with data-protection, consumer-protection and AI-governance obligations without treating one assessment as a substitute for another.

Vendors and business customers

Track changes to controls, data access, terms and assurance packages, and request evidence proportionate to the dependency.

What the guidance clarifies

Designation is not an infringement finding
The Commission designated the services because their reported reach met the statutory threshold. It did not announce a breach, fine or enforcement proceeding against them in this release.
The service classification differs
ChatGPT is designated as a Very Large Online Search Engine. Reddit and Roblox are designated as Very Large Online Platforms. Teams should map the duties to the designated service and its role rather than treat all three as identical products.
The deadline runs from notification
The DSA applies four months after notification of the designation decision. The Commission summarises the deadline as January 2027; the provider’s notified decision is the authoritative record for the exact day.
Additional governance duties are triggered
The largest services must assess and mitigate systemic risks, maintain an internal compliance function, undergo independent annual audits and support supervisory and vetted-researcher access to data.
Business customers do not inherit the designation
Organisations using the services should monitor contractual, product and assurance changes, but the designation does not by itself make every customer a VLOP or VLOSE.

Largest-service governance is becoming operational evidence

Why this matters for global organisations

A designation at this scale can change product controls, contractual assurances, audit materials and access arrangements throughout a service ecosystem. Organisations that depend on a designated service should identify the workflows involved, request proportionate evidence and avoid assuming that a provider’s regulatory programme resolves their own responsibilities.

  • Map which critical workflows depend on each designated service.
  • Record product, policy and contractual changes that affect risk or data handling.
  • Request current assurance for high-impact uses rather than relying on generic statements.
  • Keep local accountability for configuration, content, access and downstream decisions.

12 actions to start now

  1. Obtain and retain the notified designation decision; record the exact four-month compliance date and service boundary.
  2. Create an obligation map separating baseline DSA duties from the additional VLOP or VLOSE requirements.
  3. Assign accountable owners for systemic-risk assessment, mitigation, audit, compliance, data access, advertising and recommender transparency.
  4. Define the assessment perimeter across algorithms, interfaces, moderation, search or discovery, advertising, minors’ experiences and third-party integrations.
  5. Build a risk register covering illegal content, fundamental rights, public security, electoral processes, minors, wellbeing and other relevant systemic risks.
  6. Link every material risk to a measurable mitigation, owner, test method, residual-risk decision and review date.
  7. Commission an independent audit with sufficient scope, access and remediation tracking; preserve independence and competence evidence.
  8. Test the non-profiling recommender option where applicable and document how users can find and use it.
  9. Validate advertising transparency and repository controls where the service carries advertising.
  10. Establish procedures for Commission, Digital Services Coordinator and vetted-researcher data requests, including privacy and security review.
  11. Update vendor and subprocessor oversight for moderation, age assurance, audit, analytics and safety services.
  12. Run a readiness exercise covering an information request, preservation of evidence, executive escalation and remediation governance.

Suggested next steps

  • Confirm the exact compliance day from the notified designation decision when available. Validate applicability and implementation choices with qualified specialists. The checklist is PrivacyBuilt’s operational analysis, not an official Commission checklist.

Evidence worth retaining

  • Notification and designation decision, with deadline calculation and service-scope memorandum.
  • Board or executive-approved governance map and internal compliance-function mandate.
  • Systemic-risk assessment methodology, inventory, evidence inputs and approved results.
  • Mitigation designs, test results, effectiveness metrics and residual-risk decisions.
  • Independent auditor engagement, competence and independence records, audit report and remediation log.
  • Recommender-system documentation and non-profiling-option test evidence where applicable.
  • Advertising-repository and transparency-control test results where applicable.
  • Regulator and vetted-researcher request procedures, access logs and privacy/security assessments.
  • Vendor due-diligence files, contracts, service changes and assurance reports.
  • Training, incident exercises, escalation records and management review minutes.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • What is the exact notification date and legal scope stated in the designation decision?
  • Which systems, features and interfaces form part of the designated service?
  • How should systemic risks be assessed where DSA, data-protection, consumer-protection and AI-governance duties overlap?
  • Does the proposed audit scope meet the DSA requirements for independence, coverage and follow-up?
  • What data can be provided to authorities or vetted researchers, and what safeguards remain necessary?
  • Which recommender, advertising and minors’ protection duties apply to this service design?
  • Which product or contractual changes require notice to business customers or a renewed vendor-risk assessment?
  • What evidence should management review before signing off readiness?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.