The EU is now taking a new step in its efforts to gain control over the digital information environment. Starting this autumn, ChatGPT will be subject to the EU’s strictest regulations for large digital services via the Digital Services Act (DSA). The decision means that OpenAI’s AI service is, for the first time, placed in the same top regulatory tier as the largest search engines and online platforms.
The European Commission has classified ChatGPT as a so-called “Very Large Online Search Engine” (VLOSE). The background is that the service has surpassed the threshold of 45 million average monthly users within the EU. As a result, Brussels will have significantly greater opportunities to scrutinize how the service operates and what societal risks it is considered to create.
On paper, the rules concern safety, transparency, and user protection. ChatGPT must, among other things, assess and limit risks associated with illegal content, minors, elections, public safety, and fundamental rights. At the same time, the Commission receives a considerably stronger supervisory role over the biggest services.
But behind the wording about “security” and “risk management” lies a bigger political question: who should decide in the future what answers an AI may provide?
READ ALSO: EU Official: Implement Mandatory ID Verification for Social Media
This is where the EU’s new oversight of ChatGPT becomes controversial. An AI service is not like a traditional newspaper editorial team. It responds directly to users’ questions about politics, history, religion, crime, migration, and social debate.
If the company is simultaneously required to adapt its systems to European demands for identifying and reducing “systemic risks,” there may be a strong incentive to limit a controversial answer rather than risk conflict with regulators.
This does not have to mean that an EU official sits and approves every response ChatGPT generates. The real risk is more indirect: when the state imposes extensive requirements on how a digital service should handle information, the company itself may begin to over-moderate to avoid fines and legal issues.
Risk Management and Freedom of Expression
Legal analyses of the DSA have precisely pointed out the risk that regulation could impose limitations on freedom of expression, partly because legal content may be affected by the platforms’ risk management strategies.
At the same time, the European Commission highlights that, on the contrary, the DSA is intended to strengthen users’ fundamental rights and explicitly protect, among other things, freedom of expression and freedom of information. The problem is that these goals can come into conflict. The same regulations designed to combat illegal content and disinformation also give authorities greater powers to supervise the largest digital services.

For AI, the question becomes particularly sensitive because the line between information, opinion, and “risk” is much more complicated than on a traditional platform. A post on Reddit can be removed or left up. An AI response, however, can be formulated in hundreds of different ways and is influenced by the system’s instructions, safety filters, and how the model was trained.
This opens the door for a development where the EU’s rules do not need to contain an explicit censorship law to still affect what Europeans hear from their AI systems. If a company risks fines of up to six percent of its global annual turnover for serious breaches, there are strong financial incentives to play it safe.
Control Over Information
And this is no longer just a theoretical discussion about the future. The EU has already established an extensive supervisory system over the largest digital platforms. With ChatGPT, the same model is now being applied to the generative AI world. In total, the European Commission has designated 28 major platforms and search engines under the DSA system.
Critics may therefore argue that Europe is creating a model where the digital public sphere is increasingly shaped by regulation from Brussels. Proponents see it as necessary protection against powerful tech companies. The conflict is ultimately about something bigger than ChatGPT: should the state set the frameworks for the digital information environment, or should the individual decide what ideas and perspectives she wants to encounter?
For OpenAI, time is now short. ChatGPT must meet the new requirements within four months. After that, the EU stands ready to use its supervisory powers against the service.
READ ALSO: Europol erroneously stored large amounts of personal and sensitive information
