Skip to main content
Abstract illustration of platform regulation, AI governance, vendor review and controlled data flows.
Back to all Insights

Insights · Compliance

DSA designation for ChatGPT: why companies should treat platform and AI governance as one issue

Published
9 September 2026
Reading time
4 min read

Share this article

On 31 August 2026 the European Commission designated ChatGPT, Reddit and Roblox as very large services under the Digital Services Act. Platform regulation and generative AI are moving even closer to everyday business.

The distinction matters: the immediate DSA duties arising from this designation primarily apply to the designated providers. Companies that use these services do not automatically become platforms themselves. Even so, the decision is a clear prompt to review internal AI and platform governance.

What the designation means

In its press release on the designation of 31 August 2026 the Commission classifies ChatGPT as a very large online search engine, and Reddit and Roblox as very large online platforms. All three services reach at least 45 million monthly users in the EU and therefore cross the threshold for this category. The additional duties apply four months after the decision is notified, that is from January 2027.

What those requirements are is set out in the Digital Services Act itself, the full text of Regulation (EU) 2022/2065 on EUR-Lex: above all risk management, transparency, audits and closer supervision. The Commission keeps every affected service in a continuously updated overview of designated platforms and search engines.

When a service such as ChatGPT falls within this regulatory framework, it shows that generative AI is no longer treated merely as a software tool. It is part of a digital infrastructure that can influence content, information and user interactions at scale.

For corporate customers, the relevance therefore lies less in a new direct reporting duty. It lies in how such services are procured, approved and used under control internally.

Why companies should still act

In many organisations, AI and platform services are introduced faster than governance processes can keep up. Business units trial tools, teams use browser applications, data is entered and results are processed further.

That can be reasonable. It does, however, require clear rules:

  • Which platform and AI services may be used for business purposes?
  • Which data may be entered there?
  • Who reviews providers, contract terms and data-protection roles?
  • Which use cases require a separate approval?
  • How is content checked before it is used externally?
  • Who documents risks, controls and responsibilities?

Without such rules, governance flies blind. The risk then sits not only in a single tool, but in unclear accountability.

Platform law, AI regulation and data protection overlap

Companies should not treat the DSA designation in isolation. In practice several layers overlap:

  • Platform law: what requirements apply to the service, and how transparent is its use?
  • AI governance: which use cases are permitted, high-risk or subject to approval? The EU AI Act already sets its own duties here.
  • Data protection: which personal or confidential data is processed?
  • Contract review: which assurances, liability rules and subcontractors apply?
  • Compliance: how are internal policies, training and controls documented?

These interfaces are decisive in day-to-day work. A tool may be technically available and still be unsuitable for particular data, content or processes.

A pragmatic review path

Companies do not now need to stop every AI tool. A structured check is the useful next step:

  1. Inventory: which AI and platform services are actually in use?
  2. Data classification: which data may be entered, and which may not?
  3. Use cases: which cases are standard, and which need approval?
  4. Vendor review: which contract, data-protection and security information is on file?
  5. Accountability: who decides on introduction, use and control?
  6. Documentation: how are policies, exceptions and reviews recorded in a way that can be evidenced?

This path is not an end in itself. It creates speed, because teams know what is permitted and where they need to ask.

No reason for haste, but for structure

The DSA designation of ChatGPT is no reason for operational haste. It is, however, a clear indication that generative AI and large platform services belong in robust corporate governance.

Anyone using AI in business should document providers, data flows, use cases and responsibilities cleanly. That creates a framework that enables innovation without ignoring legal and organisational risk.

We help companies set up AI and platform governance in a pragmatic way: from the policy and vendor review through to legally sound process documentation – as part of our Managed Legal Services.

Do you have questions about this topic?

We can assess what the development means for your organisation and advise you directly.

Discuss AI and platform governance

Would you like to stay up to date with the latest developments?

Sign up for our newsletter

From EU directives and AI to the industrialisation of different service areas, the market is undergoing significant change, and so is Clarius.

Our newsletter provides regular updates on developments that may be relevant to you.

Form loading …

Your personal contact

Matthias Schulz

Matthias Schulz

Director Sales

Get in touch by email