ChatGPT and Roblox Expected to Face the EU's Strictest Platform Rules

The European Commission is expected to add ChatGPT and Roblox to its "very large online platform" (VLOP) list under the Digital Services Act, with the designation anticipated in August. Bloomberg, reported via Engadget, broke the news on July 29, 2026.
Under the DSA, a VLOP designation applies to platforms and search engines that exceed 45 million monthly active users in the EU. Think of it as a regulatory threshold: cross it, and you enter the regime's most demanding tier of obligations. Existing VLOPs include Google Maps, Google Play, Facebook, Instagram, Snapchat, TikTok, WhatsApp, X, and YouTube.
Within four months of designation, platforms must set up a contact point for both authorities and users, publish user-friendly terms and conditions, and be transparent about advertising, recommendation systems (the algorithms that decide what content you see), and content moderation decisions. VLOPs must also report criminal offenses, assess systemic risks tied to illegal content, electoral processes, gender-based violence, freedom of expression, media freedom, and discrimination, and take steps to mitigate those risks.
The designation of ChatGPT would bring an AI-powered conversational service under the DSA's VLOP framework for the first time. The DSA's transparency rules around recommendation systems and content moderation were written primarily with social media and marketplace platforms in mind. A generative AI chatbot does not run a content feed in the usual sense, but it does shape what information users see through model outputs influenced by training data, fine-tuning, and safety guardrails that functionally resemble content moderation. How the Commission maps those mechanisms onto DSA reporting categories will signal how other foundation-model services (large AI systems trained on broad data that can be adapted to many tasks) are treated downstream.
Roblox raises a different set of questions. The platform combines user-generated content, a virtual economy, and a mostly young user base. The DSA's risk assessment obligations cover gender-based violence, discrimination, and effects on minors, categories that line up directly with longstanding scrutiny of gaming and social platforms used by children. Roblox already operates trust and safety systems, but VLOP designation would require formalized, auditable risk assessments and mitigation reporting on an EU regulatory schedule.
The broader context is that the EU has been steadily expanding the perimeter of its digital regulation. The DSA, the AI Act, and the Digital Markets Act now form a three-pillar framework that collectively subjects large technology operators to layered obligations across content governance, AI system risk management, and market competition. ChatGPT's expected VLOP designation sits at the intersection of the DSA and the AI Act, and the compliance architecture a provider builds for one regime will almost certainly inform the other.
For technology teams at affected companies, the practical implications are concrete. Four months is a narrow window to stand up or adapt regulatory contact points, rewrite terms and conditions for EU users in plain language, and produce transparency reports covering recommendation logic and moderation decisions. For an LLM-based service (a chatbot powered by a large language model), "recommendation systems" may need to be interpreted to cover retrieval-augmented generation pipelines (systems that pull in outside documents to supplement answers), ranked output selection, and safety filters. The Commission has not yet published guidance on how DSA obligations apply specifically to generative AI interfaces, and the designation itself, while expected in August, has not been formally announced.
The EU's approach has consistently been to regulate at scale: the 45-million-user threshold is deliberately set high enough to capture only the largest operators while leaving smaller services under lighter-touch obligations. That ChatGPT has crossed that threshold in roughly three and a half years of public availability tracks an adoption curve steeper than most consumer internet services that took far longer to reach comparable reach. Whether that pace of adoption should change the regulatory calculus is a policy question, not a factual one.
What this does clarify is that the EU intends to apply its existing platform regulatory toolkit to AI services, rather than waiting for the AI Act alone to define obligations. Companies operating large-scale generative AI products in Europe will need to treat DSA compliance as a near-term operational requirement, not a distant possibility.
On balance, there is a useful convergence at work here. The compliance investments required, transparent content-moderation reporting, formalized risk assessments, and user-facing accountability mechanisms, are also the kinds of artifacts that build user trust in systems whose outputs are notoriously difficult to audit. That alignment between regulatory mandate and product maturity is, in this author's view, one of the more constructive aspects of an otherwise demanding process.


