friday, september 18, 2026 · the day's ai, attributed published by trilot llc · wyoming
guide · running the business

Building on ChatGPT in the EU: what the DSA asks of you

Work out in an afternoon whether the Digital Services Act binds your product, which duties survive the small-business carve-out, and what ChatGPT's designation changes downstream for you.

Published 2026-09-04 · Updated 2026-09-04 · Read 10 min · Reviewed by Rami Steitieh

Verified 2026-09-04 · Rami
on this page · 0 / 0 checked

You built something on ChatGPT. Someone forwarded you a headline about the European Commission designating it under the Digital Services Act, with fines up to 6% of worldwide turnover attached [3], and now you are trying to work out whether that is your problem or someone else’s. For most solo operators and small teams the answer is that it is not your problem directly. That phrasing hides two things worth an afternoon, though: a short list of duties that may already apply to you and have nothing to do with AI, and a set of changes to the platform underneath you that will arrive on a regulator’s schedule rather than yours.

This is scoping, not legal advice. It is not for you if you already have counsel on retainer, and it is not for you if you are running anything near 45 million monthly users in the EU, because at that size the guide you need is a law firm. It is for the freelancer selling a ChatGPT-backed tool, the two-person team whose SaaS calls an API, the operator whose customers are in Berlin and Madrid. The durable skill is reading a regulation to find the one sentence that decides whether it is about you, then ignoring the other 300 pages with a clear conscience.

ChatGPT was designated a search engine, and the label decides the duties

On 31 August 2026 the Commission designated ChatGPT as a very large online search engine, and Reddit and Roblox as very large online platforms, under the DSA [1]. The public list records ChatGPT at 159.1 million average monthly active users in the EU, Reddit at 57.2 million and Roblox at 46.6 million [2]. The threshold is a single number: 45 million average monthly active recipients of the service in the Union [3]. A service clears it or it does not. There is no judgment call about how important you are.

The category is worth noticing, because most coverage collapsed it. The Commission’s reasoning is two sentences long. ChatGPT “can engage with and respond to users’ prompts and queries, including by searching the web”, and so “is a hybrid service that qualifies as an online search engine under the DSA” [1]. Reddit and Roblox landed in the other tier because they “enable users to disseminate third-party content to the public” [1]. The two tiers overlap heavily but they are not identical, and the difference tells you how the Commission read each product. Either way the obligations are substantial: an annual systemic risk assessment, mitigation measures, an internal compliance function, independent annual audits, data sharing with the Commission and national authorities, access for vetted researchers, and a public repository of advertisements [4]. Designation starts a clock rather than a fine. The obligations apply four months after the provider is notified [3][4], which the Commission puts at January 2027 for all three services [1].

The penalties are the part that travels in headlines. The DSA caps fines at 6% of worldwide annual turnover for failing to comply with an obligation, with a separate 1% ceiling for supplying incorrect, incomplete or misleading information to a regulator [3]. Both ceilings sit in the regulation for national enforcement too, not only for Commission action against the largest services [3]. And the list keeps growing: WhatsApp was added on 26 January 2026, months before the AI services [2], and the Commission now counts 28 designated platforms and search engines in total [1]. Treat designation as a recurring event rather than a one-off.

The DSA follows what your service does with other people’s content

The most common mistake is reading the DSA as AI regulation. It is not. It regulates intermediary services, which the text defines as mere conduit, caching and hosting [3]. Hosting means the storage of information provided by, and at the request of, a recipient of the service. An online platform is a hosting service that, at the request of a recipient, stores and disseminates information to the public. Dissemination to the public means making information available to a potentially unlimited number of third parties. An online search engine is an intermediary service that lets users search, in principle, all websites [3].

Run your own product through those definitions and the answer usually falls out in a minute. A tool that takes one customer’s prompt, calls a model, and returns the answer to that same customer stores nothing for public dissemination. It is not an online platform, and the fact that a language model sits in the middle changes nothing. Now add a public gallery of user-submitted prompts, a shared workspace anyone can browse, a comment thread under each output, or a marketplace where customers publish agents they built. You have crossed into hosting, and probably into online platform territory, and you did it with a feature that had no AI in it at all. That is the same test the Commission applied to Reddit and Roblox, and it turned on third-party content reaching the public, not on what the software does [1]. A plain directory of user-written listings is more clearly in scope than a private AI writing assistant.

This is also why the API is a separate question from the consumer app. The designation decision names ChatGPT [1], and the Commission described it as a search engine because it answers queries, including by searching the web [1]. Neither the designation announcement nor the Commission’s page on what designation requires says anything about developer APIs [1][4]. Do not assume the question is settled in either direction, and be suspicious of anyone who tells you it is.

The small-enterprise carve-out is real and narrower than it reads

If you land on the wrong side of that test and you are an online platform, the regulation carves out micro and small enterprises from the platform-specific section of obligations [3]. Micro means fewer than 10 staff with turnover or balance sheet total at or below €2 million; small means fewer than 50 staff with turnover or balance sheet total at or below €10 million, and if you are part of a larger group you may have to include the group’s figures [5]. The carve-out removes a genuinely expensive block of work: internal complaint-handling systems, out-of-court dispute settlement, trusted flaggers, the platform transparency reports, and submitting each moderation decision to the Commission’s database [3]. Lose the status and you keep the exemption for 12 more months, unless you have been designated very large, in which case none of it helps [3].

What the carve-out does not touch is everything outside that one section, and that is where a small operator actually gets caught. If you host user content, your terms and conditions have to set out the restrictions you impose on it, including your content moderation policies, any algorithmic decision-making, and the rules of procedure of your internal complaint handling system, in clear, plain and unambiguous language [3]. You need a notice and action mechanism that lets any individual or entity tell you about illegal content on your service, easy to access and user-friendly [3]. You owe a statement of reasons to the user whose content you restrict [3]. You need a point of contact for authorities and a separate one for users, and if your business has no establishment in the EU you must designate a legal representative in writing in a member state where you offer the service, notify that country’s Digital Services Coordinator, and make the details public [3]. That last one catches a lot of people who assumed geography was a defence. Even inside the carve-out, you still have to hand the Commission or your Digital Services Coordinator your EU user numbers when they ask [3].

For a sense of the machine you would be joining: on the day this was checked, the Commission’s transparency database held 3.79 billion statements of reasons submitted over the previous 180 days by 368 active platforms, and 43% of those decisions were fully automated [6]. That is what content moderation at regulated scale looks like as a data problem. It is a good reason to design your product so it never needs to be an online platform in the first place.

Your provider’s compliance sprint arrives as product changes

Nothing in ChatGPT’s designation reaches your business as an obligation. It reaches you as behaviour. A service that has to identify and mitigate systemic risks running from illegal content and fundamental rights through civic discourse, electoral processes, public security and the protection of minors [3] does not do that in a policy document alone. The regulation lists what mitigation can look like, and most of it is product work: adapting the design, features or functioning of the service, adapting terms and conditions and their enforcement, adapting content moderation processes and the speed at which notices are handled, testing and adapting algorithmic systems, and targeted measures to protect the rights of the child including age verification and parental control tools [3]. A provider working to a January deadline picks from that list [1].

OpenAI already maintains EU terms separate from its global ones, last updated 16 January 2026. They require you to be at least 13, or the minimum age your country sets for consenting to use the services, and anyone under 18 needs a parent or guardian’s permission [7]. That document is the one to watch between now and January, not the news cycle. The changes that will cost you time are small and specific. If your onboarding assumes a 15-year-old can sign up unaided, or your core prompt depends on the model discussing a topic it may start declining for EU users, the change arrives as a support ticket and a broken flow, not as a legal notice addressed to you.

Dependency hygiene is the part of this you control

You cannot do OpenAI’s compliance work and you should not try to predict it. What you can do is make the eventual change cheap. Write down, in the repository rather than in your head, which provider policy version your product currently assumes and which behaviours would break if it moved: age floors, refusal boundaries, data retention, whether outputs can be republished, whether you can serve minors at all.

Then keep the provider swappable. If your prompt only works against one model’s exact refusal behaviour, you have taken on a dependency you cannot price and cannot hedge. Claude and Gemini are worth keeping wired up behind a thin interface for the same reason you keep a second payment processor, which is not that the first one is bad. Regional policy divergence is now a normal operating condition rather than an edge case, and the cost of switching is much lower before you need to than during the week you need to.

The AI Act is likelier to bind you than the DSA

If you only have room for one regulation this quarter, it is probably not this one. The AI Act entered into force on 1 August 2024 and became applicable on 2 August 2026 [8]. Its prohibited practices and AI literacy obligations applied from 2 February 2025, and the obligations for general-purpose AI models from 2 August 2025 [8]. Its transparency rules came into effect in August 2026 [8]. The AI Omnibus amendments, in force since 27 July 2026, pushed the high-risk obligations back to 2 December 2027 for use cases in certain sensitive areas and to 2 August 2028 for systems embedded in regulated products [8].

The transparency layer is the one that catches ordinary builders. The Commission’s own worked example is a chatbot: when people use one, they should be made aware that they are interacting with a machine [8]. The same layer reaches disclosure of the artificial nature of generated images, audio and text [8], and its date has already passed. It applies whether or not you host anything for anyone, which is precisely the gap the DSA leaves open. A private AI assistant that is comfortably outside the DSA can sit squarely inside the AI Act’s transparency rules, and most builders have the two the wrong way round.

checklist
Scoping the DSA against your product
0 of 8 · saved in this browser only
calculator
Statutory ceiling on a DSA penalty
EUR maximum

The DSA caps penalties at 6% of annual worldwide turnover [3]. This is the statutory ceiling for a serious infringement, not a forecast of any actual fine. Computed in the page; nothing is sent anywhere.

What still goes wrong

The honest limit is that nobody knows how the DSA lands on a one-person AI product, because it has not happened in public. Enforcement attention and enforcement resources both point at the designated services. A guide can tell you which sentence in the regulation decides your category, and this one has. It cannot tell you your legal position, and if the answer to the hosting question is genuinely close for your product, an hour with a lawyer is cheaper than a year of guessing.

The second limit is that the ChatGPT designation is new and its edges are unresolved. The Commission called it a hybrid service and put it in the search-engine tier [1]; how that heading applies to an assistant’s non-search behaviour is not something the designation or the obligations page addresses [1][4]. Neither is the status of model APIs. The additional obligations only start biting in January 2027 [1], so the visible consequences have mostly not arrived, and anyone describing them in detail today is extrapolating.

The third is ordinary decay. Every date, threshold and policy statement here was checked against the source on the day this was published, and terms of use in particular change without announcement. OpenAI’s EU terms were last updated in January 2026 [7]; that date will be wrong before this guide feels old. The transparency database counter moves every hour. Treat the sources as the thing to re-read and this page as a map of where to look, not as a substitute for looking.

sources
  1. 01European Commission — Commission designates ChatGPT, Reddit, Roblox under Digital Services Actec.europa.eu
  2. 02European Commission — List of designated VLOPs and VLOSEsdigital-strategy.ec.europa.eu
  3. 03Regulation (EU) 2022/2065 (Digital Services Act), consolidated texteur-lex.europa.eu
  4. 04European Commission — The impact of the DSA on very large online platforms and search enginesdigital-strategy.ec.europa.eu
  5. 05European Commission — SME definition (Recommendation 2003/361/EC)single-market-economy.ec.europa.eu
  6. 06European Commission — DSA Transparency Databasetransparency.dsa.ec.europa.eu
  7. 07OpenAI — EU Terms of Useopenai.com
  8. 08European Commission — Regulatory framework for AI (AI Act application dates)digital-strategy.ec.europa.eu
next guide
When to buy the pipeline around your coding agents
10 min · verified 2026-09-04
related guides