From regulating models to monitoring uses
The European Union is preparing to subject ChatGPT to a more demanding level of oversight. According to The Verge, OpenAI's conversational service is to be treated under the enhanced regime provided for by the Digital Services Act, or DSA, the European regulation on digital services. The change is significant: Brussels is no longer looking at artificial intelligence solely through the lens of model design, training data or performance. It is also taking an increasingly direct interest in the social consequences of an assistant used by a very large number of people.
The issue therefore extends beyond OpenAI alone. ChatGPT has become one of the symbols of the mainstream spread of generative AI since its launch at the end of 2022. Its conversational format has accelerated the adoption of these tools in education, office work, software development, information seeking, content creation and personal use. This proximity to users also brings risks that cannot be reduced to a model's factual errors: exposure of minors, inappropriate recommendations, illegal content, manipulation, harm to dignity, emotional dependence or potential effects on mental health.
Under the framework described by The Verge, ChatGPT would thus be covered by the obligations applicable to very large online platforms. The DSA provides for this status for services reaching a threshold of 45 million average monthly active recipients in the European Union, or around 10% of the European population. OpenAI indicated that ChatGPT had 120 million average monthly active recipients in the EU over a recent reference period. This level places the service well above the regulatory threshold.
This figure is important for two reasons. First, it shows that the assistant is no longer a specialized technology product reserved for a population of insiders. Second, it gives the European Commission a quantitative criterion for considering systemic oversight. The DSA was designed to address the influence of mass digital services, such as social networks, marketplaces and search engines. Its application to an AI-based conversational assistant illustrates the gradual adaptation of the European framework to new gateways to online information.
The question raised by Brussels is therefore not merely: “is an AI model sufficiently safe?” It becomes: “what risks does a very widely used conversational service create in everyday life, and what measures must its provider take to reduce them?” This shift in perspective may have lasting consequences for all general-purpose assistants offered to the European public.
What the DSA requires of very large-scale services
The Digital Services Act entered into force in November 2022 and has been fully applicable since February 2024. It is not a law specific to artificial intelligence models. Rather, it organizes the responsibilities of online intermediaries, with requirements graduated according to the nature and size of the service. Very large online platforms and very large online search engines are subject to the most extensive obligations, because their reach enables them to strongly influence the circulation of information, behavior and access to content.
The central mechanism is the assessment of systemic risks. A designated entity must identify, analyze and document the risks associated with its service. It must then put in place appropriate mitigation measures, verify their effectiveness and adjust them where necessary. The point is not to promise the complete absence of danger, an unrealistic objective for a large-scale communication or search tool. It is to demonstrate that known risks are taken seriously, that design choices are documented and that protection mechanisms are not merely declarative.
For ChatGPT, the issues highlighted by The Verge include potential effects on minors and mental health, as well as the dissemination of illegal content. These themes reflect the evolution of the debate around conversational AI. A general-purpose chatbot can answer ordinary questions, generate text or help organize a task. But it can also take part in intimate exchanges, respond to a person in a vulnerable situation, confidently rephrase inaccurate information or facilitate the production of problematic content. Its conversational form can strengthen the impression of personalization and trust, even when the response results from a statistical prediction of text rather than human understanding.
The DSA also targets transparency and accountability. The actors concerned must produce reports, cooperate with the competent authorities, provide approved researchers with access to certain information and accept independent audits. They must also provide mechanisms for reporting illegal content or activities, then handle them in accordance with the applicable obligations. The regulation does not turn companies into universal judges of legality, but it requires procedures, resources and traceability proportionate to their weight in the digital space.
In the case of an assistant such as ChatGPT, the practical application of these principles raises more complex questions than for a traditional post on a social network. A response may be generated instantly, vary from one user to another and not be publicly visible. It may combine an ambiguous query, conversational context and possible external tools. Detecting illegal or dangerous content therefore cannot rely on the same methods as moderating a public feed. This is precisely one of the reasons why the possible designation of the service is being closely watched: it will require clarification of how DSA obligations apply to a conversational interface.
European legislation provides for deadlines and specific supervision after designation. The European Commission has a direct role for very large services, alongside national digital services coordinators. Penalties may be imposed in the event of non-compliance with the obligations. The ceiling provided for by the DSA can reach 6% of the provider's annual worldwide turnover. Beyond the financial penalty, the risk for a company is also operational: having to revise its assessment systems, reporting pathways, internal controls and deployment choices in the European market.
Minors, mental health and illegal content: risks at the heart of the case
The protection of minors has become one of the most sensitive themes in the regulation of platforms and AI services. Young users may turn to a conversational assistant for homework, entertainment, personal relationships, sexuality, health or situations of distress. In these contexts, a tool that appears available, patient and personalized can take on a particular role. European regulators are therefore seeking to determine whether safety mechanisms, warnings, access restrictions and response arrangements are suited to this reality.
The difficulty lies in the fact that the same system serves very different audiences. A response useful to an adult may be poorly suited to an adolescent or a child. Likewise, a tool designed for general interaction may receive messages revealing a crisis, self-harm, an eating disorder, harassment or a request for explicitly dangerous information. The assessment required under the DSA is not limited to the existence of internal policies. It concerns the actual risks created by the operation and dissemination of the service, as well as concrete mitigation measures.
Mental health is playing an increasing role in this reflection. It would be excessive to automatically equate an AI assistant with a healthcare professional, and providers of these services generally stress that their tools do not replace medical or psychological help. But real-world use does not always follow the categories envisioned by companies. Users may seek emotional advice, look for comfort or interpret machine responses as a form of authority. The regulatory question is therefore less whether ChatGPT “does therapy” than assessing situations in which its conversational behavior may worsen a vulnerability or provide inappropriate advice.
Authorities are also concerned about the possibility that generative systems may facilitate the production or circulation of illegal content. The risk depends on the nature of the requests, the model's safeguards, connected services and how responses are shared. It may concern violent content, abuse, scams, rights violations, dangerous instructions or other categories prohibited by European and national law. The DSA does not create all these prohibitions: it primarily requires very large platforms to take their dissemination into account and put proportionate responses in place.
This approach is broader than simple keyword moderation. Generative systems can bypass filters through rewording, language, fictional context or a sequence of requests. Conversely, excessively blunt moderation can block legitimate requests for information, particularly in the fields of health, education or prevention. The balance is delicate: protecting people without preventing access to lawful and useful information. European regulation does not provide a single technical recipe, but it requires operators to demonstrate that they examine these trade-offs in a structured manner.
The issue also concerns the quality of information. A conversational assistant can generate convincing but inaccurate answers, a phenomenon often referred to as a “hallucination” in the industry. The DSA notably addresses risks related to negative effects on civic discourse, electoral processes and public health. Even if the precise obligations will depend on the qualification and designation of the service, the logic is clear: at very large scale, reliability is no longer solely a matter of product experience. It becomes a matter of systemic risk, especially when a tool serves as an interface for accessing knowledge.
The European tipping point is not solely about a model's power: it is about the number of people who receive its answers, the nature of their requests and the possible effects of those answers in the real world.
A framework that complements, rather than replaces, the AI Act
The DSA's growing role for ChatGPT should not be confused with the AI Act, the European regulation dedicated to artificial intelligence. The AI Act entered into force on August 1, 2024, and is being applied progressively. It is based on a risk-classification logic: certain practices are prohibited, certain high-risk systems must meet enhanced requirements, while general-purpose AI models are subject to specific rules, particularly regarding transparency, documentation and, for models presenting systemic risks, assessment and security.
The DSA and the AI Act therefore pursue similar objectives in some respects, but they do not address AI at the same level. The AI Act notably concerns the AI system, its provider, its uses and its obligations for placing it on the market. The DSA concerns the digital service that organizes access to and dissemination of content on a very large scale. A company may thus have to comply simultaneously with several bodies of European rules: the AI Act, DSA, General Data Protection Regulation, consumer law, rules on illegal content and relevant national legislation.
This overlap is sometimes presented as a regulatory burden. It also reflects the diversity of the issues. The question of protecting personal data is not identical to that of a model's biases. The question of cybersecurity is not identical to that of a minor's exposure to a harmful exchange. The question of a provider's documentation obligations is not identical to that of the response from a mass-market product used every day by tens of millions of people. Europe is thus building layered regulation, with the risk of complexity this entails, but also with the ability to target distinct situations.
OpenAI is at the center of this development because ChatGPT has embedded generative AI in mass use. The company was founded in 2015 and made ChatGPT available to the public in November 2022. The service very quickly popularized the idea that a user could converse directly with a language model. Microsoft, for its part, has integrated OpenAI technologies into its products and developed the Copilot offering. Google offers Gemini. Anthropic develops Claude. Meta has deployed Meta AI in some of its applications and regions. All these actors face, to varying degrees, the same challenge: the more the assistant becomes a general layer for interacting with digital technology, the more its social effects attract the attention of authorities.
The comparison must nevertheless remain cautious. The products do not all offer the same functions, are not available in the same way in every European country and do not necessarily reach the same number of average monthly active recipients. Designation under the DSA depends on legal factors and audience data specific to each service. It would therefore not be accurate to state that all chatbots already fall under the same regime. But the ChatGPT case creates a practical precedent: it requires defining measurement, audit and mitigation methods suited to generative assistants.
The precedent is also institutional. The first major designations under the DSA primarily concerned social platforms, marketplaces and search engines. With ChatGPT, the debate is shifting toward a hybrid category. A chatbot does not fully resemble a social network: it does not necessarily organize a public space for posts between users. Nor does it exactly resemble a search engine: it synthesizes and generates an answer rather than only providing a list of links. Yet it can become a major gateway to information, advice and content. It is this functional role, more than the technical label, that explains European interest.
The consequences for OpenAI and for the European market
For OpenAI, enhanced oversight first means an obligation of governance. The company will have to be able to explain how it assesses the risks associated with ChatGPT in the European Union, what measures it puts in place to reduce them and how it measures their results. This requires compliance teams, escalation processes, more detailed documentation, audits and a capacity for dialogue with authorities. These requirements do not mechanically guarantee a perfect response to every interaction, but they make an approach based only on general rules or safety promises more difficult.
The issue may also affect product design. When an obligation concerns minors or mental health, relevant decisions may concern default settings, the presentation of certain warnings, how signs of vulnerability are detected, restrictions on certain queries, avenues of redress or reporting tools. When it concerns illegal content, it may involve prevention, review and traceability systems. Each measure nevertheless raises questions of privacy, freedom of expression, technical accuracy and the risk of overblocking.
For European users, the most visible effect could be greater formalization of the protections and information provided by the service. French internet users, like those in other Member States, are directly concerned: the threshold used by the DSA is assessed at Union level, but the obligations target European recipients. France already has a dense regulatory environment for digital technology, with a role for the CNIL on personal data and Arcom on several issues relating to online services. The DSA adds a European dimension of oversight for very large platforms.
French companies and public administrations that use AI assistants must also follow this development. They do not automatically become responsible for all the obligations placed on OpenAI. However, they must understand the limits of the tools they deploy, the data-protection rules applicable to their own uses and the risks associated with responses provided to their employees, customers or users. In sensitive sectors, excessive reliance on an automatically generated answer can raise issues of quality, security and liability, regardless of the platform's DSA status.
The European AI market could experience a dual effect. On the one hand, compliance obligations represent a significant cost, especially for companies approaching a massive audience. Risk assessments, audits, reports and control mechanisms require legal, technical and operational expertise. On the other hand, a more predictable framework can foster the trust of European organizations, particularly when they hesitate to integrate generative assistants into their processes.
This tension is particularly strong for European players. They must compete with American groups that already have computing infrastructures, very well-known models and substantial budgets, while complying with a demanding legal framework in their domestic market. But Europe is specifically seeking to prevent innovation from taking place without accountability mechanisms when services reach a very large scale. The issue is not to treat every young company as a very large platform. The threshold of 45 million average monthly active recipients is intended to reserve the heaviest obligations for services whose reach can produce systemic effects.
Toward regulating assistants as information infrastructures
The ChatGPT case could mark a stage in how European authorities view AI assistants. For several years, public attention has focused on the models themselves: the size of datasets, computing power, test performance, copyright, energy consumption or bias. These issues remain essential. But a model does not exist in a vacuum. It becomes socially decisive when it is integrated into an interface used daily by millions of people, sometimes as their first reflex for asking a question, drafting a document or seeking advice.
From this perspective, the conversational assistant can be viewed as an information infrastructure. It does not decide on its own what is true or false, but it selects, rephrases and prioritizes answers. It does not necessarily replace the media, search engines, teachers, healthcare providers or public administrations, but it can position itself between them and the user. It does not always publish in a space visible to everyone, but its answers can shape individual behavior on a very large scale. This diffuse influence is precisely more difficult to monitor than the traditional virality of a social network.
The reference to the DSA provides the European Commission with an already existing tool for addressing this influence. Rather than waiting for a new law entirely dedicated to chatbots, Brussels can require a very popular service to analyze systemic risks and take mitigation measures. The method has limitations: applying rules designed for traditional platforms to private, real-time generated interactions will require new interpretations. It nevertheless opens a space for concrete oversight, based on the service's audience and effects.
The decisive question will be implementation. A reporting obligation can improve transparency, but it is not enough if indicators are too general or if audits do not make it possible to test genuinely problematic situations. A safety measure can reduce certain risks, but also shift uses to other tools or create new workarounds. A restriction intended to protect minors may be ineffective if age verification remains weak. A cautious response on mental health can avoid dangerous advice without, however, resolving the isolation or distress that led the user to consult the chatbot.
For regulators, the challenge is to maintain a high standard without reducing compliance to an administrative checklist. For companies, it will be to demonstrate that safety is built into the product rather than added afterward under the sole pressure of a designation. For European users, the issue is to retain the benefits of tools able to assist, translate, explain or create, while preventing them from becoming unguarded interlocutors in the most sensitive situations.
ChatGPT's trajectory in the European Union will therefore be watched far beyond OpenAI. If the enhanced scrutiny described by The Verge results in specific operational requirements, it could serve as a reference for future consumer-facing assistants that cross a comparable audience threshold. Europe would no longer seek only to regulate artificial intelligence as a technology: it would regulate conversational assistants as mass services whose answers, protections and failures can have direct effects on citizens.
Comments· 2 comments
What specific evidence would trigger these stricter obligations, and under which EU framework would they apply? The distinction between a service’s user numbers, its risk assessments, and documented harms matters here, especially for claims involving minors and mental health.
A useful place to look would be the European Commission’s formal designation or enforcement notice, if one is published, along with the relevant Digital Services Act provisions. Those documents should clarify the legal basis, the scope of any risk-assessment duties, and what the provider is expected to change or report.