The regulatory perimeter for AI builders has fundamentally expanded, shifting from a focus on model-level safety to a platform-centric accountability model. By designating ChatGPT as a Very Large Online Search Engine (VLOSE) on August 31, 2026, the European Commission has effectively pulled generative AI interfaces into the systemic risk framework of the Digital Services Act (DSA). This designation, confirmed in European Commission press release IP_26_1772, marks the first time an AI chatbot has been subjected to these platform-wide obligations. OpenAI Ireland Limited, serving 159.1 million average monthly EU users, now faces a four-month window to align its operations with these requirements by approximately January 2027.
This development introduces a dual compliance burden that distinguishes the European regulatory environment from other global frameworks. While the AI Act focuses on the technical safety and transparency of general-purpose AI systems, the DSA imposes a broader, systemic obligation on the platform itself. Under Article 33 of the DSA, the designation requires OpenAI to manage risks that extend far beyond the model’s internal architecture, treating large-scale generative interfaces as critical infrastructure for information access.
The most significant structural implication for builders lies in the scope of the DSA’s systemic risk assessments. Article 34 mandates that VLOSEs assess risks related to illegal content, fundamental rights, civic discourse, and algorithmic design. Crucially, these assessments must now account for downstream agent features, including generative outputs and autonomous assistants that act on user inputs. This is the first regulatory framework that requires an AI platform to actively monitor and mitigate risks arising from third-party usage and integrated agentic workflows. For developers building on ChatGPT APIs, this means their deployments are effectively pulled into the platform’s regulatory perimeter, as the platform is now legally responsible for the systemic impacts of the agents it hosts.
This expansion of the regulatory perimeter creates a complex interplay with the AI Act. Recital 118 of the AI Act provides a presumption of compliance: if an AI system is integrated into a VLOSE, meeting the DSA’s risk management requirements is generally considered sufficient to satisfy the AI Act’s corresponding obligations. However, this presumption holds only if no additional risks outside the DSA’s scope emerge. Furthermore, builders must still navigate Article 50(2) of the AI Act, which requires the clear marking of synthetic content. The result is a layered governance structure where the platform acts as a gatekeeper for agent compliance, forcing builders to adhere to platform-level safety standards to maintain access.
This shift adds a fourth, platform-specific layer to the Three Gov Models framework. It sits alongside the G20 Carolina Principles, which favor a deregulatory, sector-specific approach, and the existing EU AI Act and China’s CAC Implementation Opinions. While the US continues to avoid AI-specific regulation, the EU is aggressively expanding its enforcement capacity, evidenced by the hiring of 40 new enforcement staff for the EU AI Office. This suggests that the January 2027 deadline will be met with rigorous oversight, as the Commission seeks to harmonize the DSA’s platform-wide requirements with the AI Act’s model-specific mandates.
For those navigating this landscape, the practical stakes are high. The DSA allows for fines of up to 6% of global annual turnover, and the requirement for independent annual audits under Article 37 ensures that these systemic risks are subject to external verification. Builders should anticipate that OpenAI will likely implement more stringent content moderation, stricter API usage policies, and enhanced transparency requirements for agentic behaviors to satisfy these DSA obligations. The era of treating AI platforms as neutral infrastructure is ending, replaced by a model where the platform is held accountable for the entire ecosystem of agents and outputs it enables.
