ChatGPT and Reddit Now Face EU's Toughest Online Safety Rules
The European Union has formally designated ChatGPT and Reddit as Very Large Online Platforms (VLOPs) under the Digital Services Act, placing both services in the highest tier of regulatory scrutiny the bloc applies to online services. The designation triggers a set of obligations that go considerably beyond what standard platforms face, including mandatory risk assessments, independent audits, and enhanced transparency requirements.
The VLOP designation is threshold-based, applying to platforms with over 45 million monthly active users in the EU. ChatGPT's inclusion marks a meaningful shift in how European regulators are beginning to classify AI-facing consumer products — not as software tools, but as platforms with systemic reach and corresponding systemic responsibility.
This is the first time a generative AI application has been brought under the DSA's most demanding compliance tier, a distinction that carries significant operational weight for OpenAI and sets a precedent for how regulators may treat other AI services as they scale.
Under VLOP status, both companies must conduct regular assessments of systemic risks their platforms may generate — covering areas such as the spread of harmful content, manipulation of public discourse, and threats to fundamental rights. These assessments must be made available to regulators and verified by external auditors. Platforms must also provide data access to vetted researchers and implement mechanisms for users to flag problematic content or outputs.
For Reddit, the obligations are largely familiar territory. Content moderation at scale, user reporting infrastructure, and advertiser transparency are functions the platform has managed in some form for years. The compliance burden is real but mappable onto existing operations.
For OpenAI, the picture is more complex. ChatGPT's conversational architecture does not map cleanly onto the content moderation frameworks the DSA was originally built around. Risk assessments for a generative system must account for outputs that are dynamic, context-dependent, and not pre-published — a fundamentally different compliance challenge than moderating user-uploaded posts or links. OpenAI will need to develop or adapt methodologies for risk identification, incident reporting, and audit readiness that have no direct precedent in the DSA compliance playbook established by social media platforms.
The broader implication for AI companies operating in Europe is structural. If regulators treat large-scale AI applications as platforms rather than software products, the compliance surface area expands substantially. Consumer-facing AI services that cross the user threshold will face audit cycles, researcher data-sharing obligations, and algorithmic transparency requirements that are time-intensive and legally consequential if mishandled.
This also creates a compliance cost asymmetry. Established platforms like Meta, Google, and X have already built DSA compliance infrastructure. AI-native companies entering the VLOP tier for the first time must build that infrastructure while simultaneously scaling their core products — a dual burden that could influence how aggressively they pursue European user growth.
From an operational standpoint, the designation also raises questions about what constitutes a "risk" in the context of a generative AI system under DSA framing. The regulation was written with content hosting in mind, not content generation. Regulators and companies will likely spend considerable effort in the near term negotiating what meaningful compliance actually looks like for systems that produce rather than distribute content.
The EU has consistently used its regulatory surface area to shape global AI product development. GDPR forced data architecture changes worldwide. The AI Act introduced risk-tiering for AI systems. The DSA's VLOP expansion into generative AI is the next vector — one that shifts compliance from a legal checkbox into an ongoing operational discipline for any AI company serious about the European market.
Sources: — Ars Technica (https://arstechnica.com/tech-policy/2026/08/chatgtp-and-reddit-now-face-eus-toughest-online-safety-rules/)