Mariana Olaizola Rosenblat /Sep 3, 2026Republish
On August 31, the European Commission designated OpenAI’s ChatGPT as a Very Large Online Search Engine (VLOSE) and named Roblox and Reddit Very Large Online Platforms (VLOPs) under the Digital Services Act (DSA). Four months from now, these services will have to comply with additional obligations, including that they must:
- assess and mitigate the systemic risks their services generate
- submit to annual independent audits
- open their internal data to vetted researchers
- give users at least one content recommendation system not based on profiling
- publish a repository of the advertisements they run
- release biannual public reports on their content moderation
These new requirements kick in anytime an online platform or search engine becomes “very large,” meaning that it reaches at least 45 million average monthly users in the EU. The implications are substantial, particularly for transparency. As very large online services, ChatGPT and Roblox now have to open their hoods to outside inspection — not only by third-party auditors (granted, ones that they themselves select) but also by independent researchers and members of the public.
The first round of designations was straightforward, capturing mainly traditional social media platforms like Facebook and search engines like Google. More recent designations, including those of WhatsApp, Roblox, and ChatGPT, involved the Commission applying fixed statutory definitions to services that have changed considerably since those definitions were drafted. And it applied them correctly — considering what these services actually let users do today, not what they were originally built or marketed to be.
But, while the new obligations make sense from the standpoint of increasing transparency and accountability, they also raise new and thorny implementation questions.
Why Roblox and ChatGPT both qualify
Roblox is a game-creation engine. Users build experiences and publish them for tens of millions of other users to play, which makes it an online platform under the DSA’s definition. But much of the games industry has assumed the law doesn’t concern them, based on the theory that their business is interactive entertainment rather than user-to-user communication and user-generated content publication.
Our Working Group on Gaming and Regulation — a multi-stakeholder group convened by the NYU Stern Center for Business and Human Rights to help steer gaming regulation toward proportionate and evidence-based requirements —addressed this directly in its December 2024 submission to the Commission. We argued that gaming platforms already fall within the DSA’s scope as hosting services, that some qualify as online platforms, and that some, like Roblox, would eventually qualify as VLOPs. The social dimension of online games — user-generated experiences, matchmaking, in-game voice and text chat — blurs the line between gaming and social media. Whether a service carries “game” on its label should be less relevant than the type and scale of social functionalities it provides. Roblox’s designation is exactly what our argument anticipated.
ChatGPT began as a large language model with a consumer chatbot attached to it that answered queries with predictions based on data the model had absorbed during training. This setup made the chatbot unreliable on current events and prone to “hallucinations,” leading OpenAI to build search and other tools into the product. But a user no longer has to select a “search” mode. ChatGPT decides on its own when a query calls for the live web and returns an answer with links to sources. The Commission described the result as a “hybrid service” that qualifies as an online search engine, and OpenAI did not contest the characterization.
Why further guidance is needed for effective implementation
Recommender systems
Article 38 of the DSA requires VLOPs and VLOSEs that use recommender systems to provide at least one recommender option that is not based on profiling. Applied to Roblox, which ranks user-created experiences in its Recommended for You page, this provision is relatively straightforward. For ChatGPT, it is less so.
When ChatGPT conducts a search in order to respond to a query, an algorithm selects which sources to fetch, draw on, and cite. But the result is a synthesized answer rather than a ranked list, where it is less obvious what information the system prioritized or the “relative order or prominence” of that information. Moreover, what counts as a non-profiling-based option is debatable. ChatGPT’s use of persistent “memory” across sessions to shape answers should count as profiling, a definition set out in the EU’s General Data Protection Regulation (GDPR). Thus, allowing users to toggle off memory and turn on “temporary chat” could satisfy the requirement to provide a non-profiling option.
Yet, even when a user turns on these options in the privacy settings, the system returns answers based on the accumulated conversation rather than a query in isolation. In a single session, a user may reveal their occupation, health concerns, location, political leanings, or emotions, and the chatbot uses that information to return answers within that session. Thus, it is not clear how a non-profiling-based recommendation option, as contemplated in article 38, would apply to conversational systems.
Advertisement transparency
The ad repository requirement is especially significant for ChatGPT as OpenAI moves into advertising. On August 24, one week before the designation, OpenAI began showing ads in ChatGPT across 31 markets. The ads appear as “sponsored” cards beneath the chatbot’s answers, are shown only to users on the free and low-cost Go tiers, and are tailored to the topic of the conversation the user is having. Under article 39, the ad repository has to disclose “whether the advertisement was intended to be presented specifically to one or more particular groups of recipients of the service and if so, the main parameters used for that purpose.”
Applied to chatbots, what would make this provision meaningful would be to require OpenAI to disclose the “context hints” that determine where ads are placed within conversations. OpenAI’s documentation explains that advertisers supply hints describing “the conversations, topics, or keywords where their products may be relevant,” and that these guide which conversations an ad appears beside. Publishing them per advertisement would show whether a company can ask to appear beside a user describing sensitive personal information, such as health symptoms and interpersonal issues.
This information is very relevant to the public interest, but OpenAI may contest having to disclose it. The company might argue that the parameter disclosure requirement applies to ads that target “one or more particular groups of recipients of the service,” whereas context hints describe conversations rather than people. To ensure effective implementation, the European Commission should issue guidelines, as it is empowered to do under Article 39, making clear that OpenAI’s context hints count as parameters that should be disclosed.
Data access
The data access regime also poses unresolved questions, especially for gaming platforms that process ephemeral data.
Data access for traditional social media is relatively straightforward because in most cases posts are static and public. But applied to gaming platforms, the data access provision is less obvious. Games do not store their most revealing data the way social media platforms do. Much of what a researcher would need to study grooming, harassment, or radicalization on Roblox, for example, is ephemeral — real-time voice and text, gameplay behavior, interactions that are never retained long-term.
In our December 2024 submission, the Working Group set out what a workable regime would look like for gaming platforms like Roblox, balancing researchers’ valid interests in examining ephemeral communications with the privacy, technical, and financial constraints that make ephemeral data genuinely hard to share.
The Commission’s August 31 designations were the right call. It should now clarify what implementation means for services the DSA’s drafters did not have in mind, ensuring that compliance actually translates into better transparency and accountability. Other services, meanwhile, should stop assuming they fall out of scope because of their industry name or service label, and start examining feature by feature what service they actually operate.
Support Tech Policy Press
If you’ve found our work helpful, consider supporting us.
Donate
Authors

Mariana Olaizola RosenblatMariana Olaizola Rosenblat is a policy advisor on technology and law at the NYU Stern Center for Business and Human Rights. Previously, she served as a Lecturer-in-Law at the University of Chicago Law School. Mariana received her JD from Yale Law School and her BA in Political Theory from Princeton….
