Technology

What the EU's Toughest Online Rules Mean for ChatGPT and Roblox

Martin HollowayPublished 23h ago4 min readBased on 2 sources
Reading level
What the EU's Toughest Online Rules Mean for ChatGPT and Roblox

The European Commission is expected to add ChatGPT and Roblox to its list of "very large online platforms" under a law called the Digital Services Act, or DSA. The designation is anticipated in August. Bloomberg, reported via Engadget, broke the news on July 29, 2026.

Under the DSA, the very large platform label applies to services with more than 45 million monthly active users in the EU. Once a platform crosses that line, it faces the law's strictest set of rules. Platforms already on the list include Google Maps, Google Play, Facebook, Instagram, Snapchat, TikTok, WhatsApp, X, and YouTube.

Within four months of being designated, these platforms must set up a contact point for both authorities and users, publish terms and conditions in plain language, and be open about how they handle advertising, recommendation systems (the algorithms that decide what content you see), and content moderation. They must also report criminal offenses, assess risks related to illegal content, elections, gender-based violence, freedom of expression, media freedom, and discrimination, and take steps to reduce those risks.

Bringing ChatGPT under these rules would be a first for an AI chatbot. The DSA's transparency requirements were written with social media and online marketplaces in mind. A chatbot does not show you a feed of content the way Facebook or TikTok does, but it does shape what information you receive through its answers, which are influenced by its training data and built-in safety filters that work much like content moderation. How regulators decide to treat those filters under the DSA will be a signal for how other AI services are handled in the future.

Roblox raises different concerns. The platform lets users create their own games and content, runs a virtual economy, and has a mostly young user base. The DSA's risk assessment rules cover minors, discrimination, and gender-based violence, categories that fit directly with long-running concerns about online platforms popular with children. Roblox already has trust and safety systems, but the VLOP designation would require formal risk assessments and mitigation reports on a regulatory schedule.

The broader context is that the EU has been steadily expanding its digital regulation. Three laws now work together: the DSA covers content governance, the AI Act covers AI system risk management, and the Digital Markets Act covers market competition. ChatGPT's expected designation sits at the intersection of the DSA and the AI Act, and the compliance work a company does for one law will likely help with the other.

For technology teams at these companies, the timeline is tight. Four months is not much time to set up regulatory contact points, rewrite user terms in plain language, and produce transparency reports on how recommendation and moderation systems work. For an AI chatbot, regulators may interpret "recommendation systems" to include the way the model selects and filters its answers. The Commission has not yet published specific guidance on how DSA rules apply to AI chatbot interfaces, and the designation, while expected in August, has not been formally announced.

The EU has consistently chosen to regulate at scale. The 45-million-user threshold is set high on purpose, so that only the biggest platforms face the strictest rules while smaller services have lighter obligations. That ChatGPT has crossed that threshold in about three and a half years of public availability is faster than most consumer internet services, which took far longer to reach similar numbers of users. Whether that speed of adoption should change how regulators think is a policy question, not a factual one.

What this does clarify is that the EU intends to apply its existing platform rules to AI services now, rather than waiting for the AI Act to do the job alone. Companies running large-scale AI products in Europe will need to treat DSA compliance as a near-term requirement, not a distant possibility.

In this author's view, there is a silver lining. The work required to meet these rules, transparent moderation reporting, formal risk assessments, and user-facing accountability, is also the kind of work that builds trust in AI systems whose outputs are hard for outsiders to verify. That alignment between what regulators demand and what makes a better product is a useful convergence.