Wire
11:34ZEPOCHTIMESUS Treasury Reports Disagreement Over Sovereign Debt, Global Imbalances11:31ZINSIDERPAPXi Tells Sisi External Interference in Middle East Should Be Opposed11:27ZTHECRADLEM12 Israeli prison guards charged in 2023 beating death of Palestinian detainee11:27ZDAILYNATIOKenyan entrepreneur launches platform connecting women in business after job search struggles11:24ZSTANDARDKEPolice constable, 3 others detained 30 days over murder of Dr. Victoria in Kenya11:24ZTWOMAJORSRail freight to Poland rises amid Odesa port blockade, 1.7 million tons moved in August11:23ZINTELSLAVAVideo shows Russian drone brigade intercepting Ukrainian drones over Khers11:23ZWFWITNESSChevron to expand Venezuela operations with U.S. Energy Secretary Wright and oil executives
  • S&P 500 ETF 0.11%
  • Nasdaq 1.03%
  • Nasdaq 100 1.29%
  • Dow ETF 0.06%
Terminal ↗
← The MonexusEurope

EU flags ChatGPT under the Digital Services Act: what the threshold actually triggers

Brussels has formally brought OpenAI's ChatGPT inside its most demanding tier of platform oversight. The 45-million-user threshold is the trigger, and it converts a chatbot into regulated infrastructure.

A black placeholder graphic displays "MONEXUS NEWS" and "DESK" headers above the word "EUROPE," with a note stating "No photograph on file."
A black placeholder graphic displays "MONEXUS NEWS" and "DESK" headers above the word "EUROPE," with a note stating "No photograph on file." Monexus News

Brussels has formally placed OpenAI's ChatGPT inside the European Union's most demanding tier of platform oversight, after the chatbot crossed a population-scale threshold that converts a private product decision into a public-law compliance load. The trigger was arithmetic, not political: roughly 45 million monthly users inside the EU, the figure the Digital Services Act sets as the line above which a service is treated as systemically consequential.

The designation matters less for the label than for what the label switches on. From the moment a service is named a Very Large Online Search Engine (VLOSE) under the DSA, a separate chapter of obligations comes due. None of that disappears if OpenAI appeals. The compliance clock starts when the Commission publishes the designation.

The number that runs the rule

The DSA does not give the European Commission discretion to designate a service based on its fame or its product category. It gives the Commission discretion to designate a service that meets two measurable conditions: more than 45 million monthly active users in the EU, and designation as a VLOSE on the grounds that the service poses a systemic risk to fundamental rights, civic discourse, public health, or minors. Once both are satisfied, the service is treated as if it were infrastructure, not a consumer app.

Reporting from market-data outlet Unusual Whales, posted on 2 September 2026 at 02:58 UTC, records the user-count trigger as the immediate cause of the Commission's action, describing the 45-million-user figure as "about one in ten people in the EU." That figure is not a guideline. Per Unusual Whales' framing, it is the statutory line. The same post ties the designation explicitly to the DSA framework rather than to the parallel EU AI Act, which regulates model training, transparency, and high-risk uses but does not hinge on user counts in this way.

Two consequences follow, as the post describes them. First, OpenAI now sits in the same Brussels-internal risk category as X, Meta's Facebook and Instagram, TikTok, and Alphabet's Google Search, each of which has already been designated and is operating under DSA obligations. Second, the user-count rule is a moving threshold tied to actual usage, not to corporate self-description. A service that crosses 45 million monthly EU users cannot opt out by arguing that it is technically a chatbot rather than a search engine.

What the framework now requires of OpenAI

Monexus analysis: the specific operational obligations of a VLOSE designation under the DSA are spelled out in the regulation itself rather than in the cited posts. The cited Unusual Whales coverage confirms that the DSA framework applies, not the AI Act; the detailed compliance workstreams below are read off the standard VLOSE chapter of the regulation as this is what the designation switches on, with that scope flagged here as analysis rather than as a quotation of the supplied source.

Under that standard VLOSE chapter, the obligations cluster around four workstreams. First, an independent audit of the systemic risks the service creates in the EU, with the audit report submitted to the Commission. The audit is an assessment of harms to civic discourse, electoral integrity, public health, and minors' wellbeing that the service may amplify, not a security review of the model. Second, a researcher access programme granting vetted academic researchers a statutory right to query non-personally-identifying data about how the service ranks, surfaces, and suppresses content. Third, a crisis-response protocol requiring the service to demonstrate it can modulate surfacing in hours when the Commission signals an active crisis. Fourth, advertising-transparency obligations, including the publication of a repository of ads served in the EU.

Monexus assessment: the heaviest of these in practice is the audit, because an adverse finding gives the Commission a documented basis for opening a formal non-compliance procedure that can lead to penalties tied to global annual turnover. The specific penalty ceiling for this action is not stated in the supplied source material; this article has not independently established the precise figure applicable to this particular designation, and readers should treat any percentage cited elsewhere as requiring its own confirmation.

The asymmetry the framework is built for

The DSA was designed on a structural premise that has aged well. Large platforms monetise attention at scale; their harms scale with them; and a national regulator cannot, by definition, police a service that has more users than the country has citizens. The response is a Commission-level enforcement layer that runs on user-count thresholds rather than on industry self-certification.

The premise has uncomfortable implications. A European challenger to OpenAI with eight million monthly EU users faces a fraction of the compliance overhead of the designated incumbent, even if its product is functionally identical. That is the price of regulation calibrated to scale, and it is also the policy: the law deliberately tilts the cost curve against the largest actors on the theory that they impose the largest externalities. Whether that tilt entrenches incumbents or disciplines them is the open empirical question. Brussels has, in effect, bet that the answer is the latter.

The counter-read is straightforward and worth naming. Critics argue that user-count thresholds reward incumbents that crossed the line first, raise the cost of operating a frontier service inside the EU, and push the next generation of European AI startups toward either US acquisition or jurisdiction-shopping to Singapore and the Gulf. That is a serious critique. The defenders of the framework answer that the alternative is a patchwork of national rules that none of the largest platforms would have to obey either.

What remains genuinely uncertain

The available source material does not specify how OpenAI intends to structure the required audit, which audit firm it will retain, or whether the company will pursue a judicial challenge to the designation in the General Court of the EU. The Commission has not, in the cited coverage, named a compliance deadline for the first researcher-access submission. The cited posts do not specify how the DSA interacts with ChatGPT's enterprise product, which is sold under separate contracts to companies and governments, and the public record does not yet show whether enterprise deployments count toward the 45-million-user line.

What is not contested is the underlying trigger. The user count is the threshold, and per the cited coverage the threshold has been crossed.

How Monexus framed this: the wire coverage flagged the user-count mechanic; Monexus structured the piece around what the threshold unlocks, the asymmetry the framework is built to produce, and the open compliance questions OpenAI now faces. Operational details beyond the trigger were read off the standard VLOSE chapter of the DSA and flagged as analysis rather than as a quotation of the supplied source.

Wire provenance

This editorial synthesis draws on the following public wire/social posts:

  • https://unusualwhales.com/news/eu-designates-chatgpt-vlose-dsa
  • https://x.com/unusual_whales/status/2094983148673114430
  • https://t.me/NikkeiAsia/21564
  • https://t.me/nikkeiasia/21564
© 2026 Monexus Media · AI-native reporting from public-source material