How the EU DSA Affects ChatGPT, and What It Means for Californians

Written by
Last updated on:
September 9, 2026
Written by
Last updated on:
September 9, 2026

The EU’s designation of ChatGPT could give California a new model for regulating high-reach AI services—and prompt US enterprises to strengthen their AI governance.

On August 31st, 2026, the European Commission designated ChatGPT a Very Large Online Search Engine (VLOSE) under the Digital Services Act (DSA). ChatGPT had reported at least 45 million average monthly users in the EU, making it the first AI chatbot subject to the DSA’s strictest oversight requirements.

The designation applies in Europe, not the US. However, California businesses and organizations that serve California residents should take notice. The state has a history of turning global technology-policy momentum into US requirements, and it is already building rules for AI transparency, chatbot safety, privacy risk, and automated decision-making.

California currently doesn’t have a DSA-style designation process for AI services, and it may not adopt one. Even so, Europe’s decision raises questions California policymakers could ask next: When does an AI product become a major gateway to information? What risks emerge at scale? And what safeguards should be in place before those risks become widespread?

What Happened in Europe?

The DSA gives the European Commission additional oversight authority over online platforms and search engines with at least 45 million average monthly recipients in the EU. The Commission designated ChatGPT as a search engine and designated Reddit and Roblox as very large online platforms.

ChatGPT has become a common way for people to look for information online. Users can ask questions, compare options, and search the web through a conversational interface. By designating it as a VLOSE, the Commission is acknowledging the influence that role can have when a service reaches enough people.

OpenAI now has four months to meet the DSA’s added VLOSE requirements. These requirements include:

  • Assessing systemic risks: OpenAI must identify, analyze, and assess risks connected to ChatGPT, including illegal content, harm to minors, mental and physical well-being, fundamental rights, public security, and elections.
  • Taking steps to reduce those risks: If OpenAI identifies material risks, it must implement appropriate measures. That could mean changing the service’s design or functionality, adjusting recommender systems, or increasing internal resources dedicated to risk management.
  • Providing more transparency: VLOSEs must be transparent about advertising, content moderation decisions, and recommender systems. They must also maintain user-friendly terms and conditions and provide points of contact for users and authorities.
  • Undergoing independent audits: OpenAI must be audited by an independent auditor at least once a year and respond to audit recommendations.
  • Supporting regulatory and research oversight: OpenAI must share relevant data with the European Commission and national authorities. It must also provide access to vetted researchers studying systemic risks in the EU.
  • Maintaining an ad repository: VLOSEs must maintain a public repository of advertisements and offer at least one recommender-system option that is not based on profiling, as outlined by the European Commission.

Europe hasn’t created a new legal category for chatbots. It has, however, applied an existing framework for the largest online services to ChatGPT because of the product’s reach and role in information discovery.

Why the GDPR Matters

The DSA and GDPR are related parts of the EU’s technology-regulation landscape, though they address different risks.

The GDPR governs personal data: how companies collect, use, share, protect, and retain it. The DSA focuses on online-service accountability, including how large platforms and search engines manage illegal content, provide user safeguards, and reduce systemic risks associated with distributing and amplifying information.

For an AI provider, the distinction is practical. GDPR asks whether personal data is handled lawfully and responsibly. The DSA asks how a high-reach service could affect users, public information, and fundamental rights—and what the provider is doing to reduce those risks.

The EU AI Act adds a third layer focused more directly on AI systems and general-purpose models. Together, these laws show why responsible AI can’t be treated as a one-time legal review. It requires ongoing attention to data, model behavior, product design, security, human oversight, and vendor management.

GDPR, CCPA, and California Privacy Law

The GDPR didn’t create the California Consumer Privacy Act (CCPA). California privacy law has its own history, including constitutional privacy protections, existing state statutes, and consumer concerns that intensified after the Cambridge Analytica scandal.

However, the GDPR was an important international reference point as California’s privacy debate accelerated. The GDPR became applicable on May 25th, 2018; California enacted the CCPA just over a month later, on June 28th, 2018. The two laws share a broad focus on transparency, individual control, and organizational accountability, even though they use different legal structures and requirements.

The CCPA and its amendment, the California Privacy Rights Act (CPRA), reinforced several business practices that companies were already developing for a changing privacy environment: mapping personal data, updating privacy notices, creating consumer-request workflows, and strengthening vendor oversight.

The CCPA/CPRA gives Californians the right to know about their personal information, request deletion, correct inaccurate data, opt out of the sale or sharing of personal information, and limit certain uses of sensitive personal information. Covered businesses must provide notices and respond to eligible consumer requests, according to the California Department of Justice.

The GDPR and CCPA/CPRA aren’t interchangeable. A GDPR program won’t automatically meet California requirements, and California compliance won’t automatically satisfy the GDPR. Still, Europe’s policies often offer an early signal of the technology-governance issues California may address in its own way.

California’s Approach to AI Governance

California already regulates several AI-related issues, even without a single comprehensive AI law.

  • Training-data transparency: California’s Generative Artificial Intelligence: Training Data Transparency Act requires developers of generative AI systems or services intended for use by Californians to publish high-level summaries of the datasets used to develop them. The law took effect January 1th, 2026.
  • AI content provenance: California’s AI Transparency Act requires certain large generative AI providers to offer a free detection tool and disclosure capabilities for AI-generated image, video, and audio content. The law became operative August 2nd, 2026.
  • Companion chatbot safety: The Companion Chatbots Act requires covered operators to disclose when users are interacting with AI in specified circumstances and to maintain safeguards related to suicidal ideation, self-harm, and other risks. Some requirements take effect on a phased schedule, including reporting obligations beginning in 2027.
  • Privacy risk and automated decisions: The California Privacy Protection Agency has finalized CCPA regulations covering risk assessments, annual cybersecurity audits, and automated decision-making technology. Businesses must conduct risk assessments before beginning covered processing that presents a significant risk to consumer privacy, while certain automated-decision-making requirements begin in 2027.

Taken together, these measures show that California is developing AI governance through targeted laws, privacy rules, and consumer protections. The state has focused on specific aspects of AI development and use, including training data, synthetic content, companion chatbots, consumer privacy, and high-impact automated decisions.

Golden Gate Bridge in San Francisco, California, representing the state’s evolving approach to AI governance and regulation.

What Could Come Next

California hasn’t proposed a direct equivalent to the EU’s VLOSE designation for ChatGPT. However, the EU’s decision could shape how California approaches AI products with a large reach and a growing role in how people find information, make decisions, or complete tasks.

Potential directions include:

  • Obligations based on scale and function: California could establish added responsibilities for AI services that serve a large number of users or become major gateways to information, recommendations, or transactions. 
  • Service-wide risk management: Policymakers could require major AI services to evaluate how their full product experience—not only an individual automated decision—affects public information, consumer safety, minors, fundamental rights, or access to essential services. This would extend beyond California’s current privacy-focused risk-assessment framework.
  • Transparency for AI search and recommendations: A future framework could focus on how AI services retrieve, rank, and present information. For example, it could require disclosures about paid placements, commercial relationships, personalization, web retrieval, or the sources that influence a recommendation or answer.
  • Accountability for AI agents: California could set more explicit requirements for AI systems that take actions, rather than only generate content. Potential requirements could address permissioning, action confirmation, logging, incident response, human escalation, and limits on autonomous actions in high-risk contexts.
  • Enforcement through several channels: California may pursue these issues through CPPA rulemaking, consumer-protection enforcement, public procurement, sector-specific rules, or targeted bills rather than a single DSA-style law.

What US Enterprises Should Do

Waiting for a California version of the DSA isn’t a practical strategy. California is already advancing AI-related requirements through privacy risk assessments, cybersecurity audits, and rules for certain automated decision-making uses. Meanwhile, AI products can change faster than legislation. A chatbot may quickly gain web retrieval, access to internal data, third-party tool connections, or agentic capabilities that change its risk profile.

Waiting until those systems are widespread can force organizations to retrofit permissions, monitoring, audit trails, disclosures, and human approvals into workflows that weren’t designed for them. A better approach is to build AI governance into the operating model from the start.

That starts with a current inventory of AI use cases and vendors, risk tiers that match controls to each use case, and clear ownership for approval, monitoring, and incident response. For higher-risk systems, teams should document data sources, model versions, retrieval sources, tool calls, permissions, human approvals, and system actions. They should also use least-privilege access and require confirmation or human review for consequential actions.

Don’t assess a model in isolation. A model that performs well in testing can behave differently once it is connected to customer data, internal systems, third-party tools, or autonomous workflows. Governance needs to cover the complete system: data flows, prompts, retrieval, permissions, interfaces, business rules, monitoring, and human oversight.

Not sure where to start with AI governance? Read our guide to building ethical, scalable AI systems.

The Bottom Line

Europe’s designation of ChatGPT as a VLOSE shows that regulators can treat a high-reach AI chatbot as an information service with broader responsibilities, not simply as a model inside a consumer app.

California may not adopt the EU’s terminology or create a DSA-style category for AI search engines. However, the state is already expanding AI and privacy requirements through targeted laws, risk-assessment rules, and automated decision-making regulations. That makes it one of the most important US jurisdictions for enterprise leaders to watch.

Companies don’t need to wait for a single, comprehensive AI law to prepare. As AI becomes more connected to customer experiences, internal data, and business-critical workflows, teams need clear ownership, sensible access controls, reliable records of how systems are used, and ways to identify and address problems early. Building those practices in now is far easier than adding them after AI is embedded across the organization.

Ready to build the operating model, workflows, and software foundation needed to scale AI? FullStack helps organizations move from AI experimentation to AI maturity and turn promising use cases into practical, repeatable business value.

Talk with our AI transformation experts today.

Learn more

Frequently Asked Questions

The European Commission has designated ChatGPT a Very Large Online Search Engine (VLOSE) under the Digital Services Act (DSA). The designation places ChatGPT in the DSA’s strictest oversight tier for services with at least 45 million average monthly recipients in the EU.

The EU classified ChatGPT as a VLOSE because the service helps people find and evaluate information through conversational responses and web search. The designation shows that regulators can assess an AI product by its function and reach, not only by whether it resembles a traditional search engine.

As a VLOSE, ChatGPT must assess and mitigate systemic risks tied to illegal content, minors’ safety, fundamental rights, public security, and elections. OpenAI must also meet additional transparency, independent-audit, advertising-repository, regulatory-data-access, and vetted-researcher-access requirements.

California has not proposed a direct equivalent to the EU’s VLOSE designation for ChatGPT. However, California already regulates AI-related issues through laws and rules covering generative AI training-data transparency, AI-generated-content disclosures, companion chatbot safety, privacy risk assessments, cybersecurity audits, and automated decision-making. That existing framework could inform future rules for high-reach AI services.

US enterprises should build AI governance into products and workflows before systems become deeply connected to customer data, internal tools, and business-critical processes. Start with an AI use-case inventory, clear owners, risk-based reviews, least-privilege access, system logs, human approval for consequential actions, and processes for monitoring and responding to incidents.