How to Make Your Platform DSA Compliant in the EU

If you’re only now asking how to make your platform DSA compliant, ChatGPT’s regulators just gave everyone a very public deadline reminder. On August 31, 2026, the European Commission designated ChatGPT, alongside Reddit and Roblox, a Very Large Online Platform under the Digital Services Act after it crossed 45 million monthly EU users. That designation brings a much stricter set of duties: systemic-risk assessment, illegal-content handling procedures, transparency obligations, and specific protections for minors, with non-compliance penalties reaching up to 6% of global annual revenue.

What makes this designation notable isn’t just the size of the fine. It’s the first clear signal that Europe is applying rules originally built for social platforms directly to generative AI products. OpenAI is already navigating the separate EU AI Act, and competition authorities are examining the broader AI market on top of that. Because the DSA has extraterritorial reach, it applies to any platform serving enough EU users regardless of where the company is based, this also affects non-EU firms, including Pakistani and other South Asian IT exporters, that serve European customers through AI-powered products or platforms.

For a company that has spent the last few years thinking of AI regulation purely through the lens of the EU AI Act, the ChatGPT designation is a reminder that Brussels has more than one regulatory tool aimed at large digital platforms, and they can apply at the same time. A generative AI product that reaches enough EU users can find itself subject to DSA transparency and risk-assessment duties on top of whatever AI Act obligations apply to the underlying model, which means compliance planning that only accounts for one of these frameworks is planning against half the picture.

What You Need Before You Start

Before you assess your own DSA exposure, get three numbers and one document ready: your monthly active EU user count (the VLOP threshold sits at 45 million, but smaller platforms face baseline DSA obligations regardless), your current content moderation and takedown process if you operate anything with user-generated content, your existing risk assessment documentation if you have any, and a clear picture of who inside your organization currently owns compliance for EU regulations. If nobody owns that today, that’s the first gap to close, not the last.

Step 1: Determine Your DSA Exposure Tier

The DSA doesn’t apply the same way to every company. Very Large Online Platforms and Search Engines, those crossing 45 million monthly EU users, face the strictest tier: systemic risk assessments, independent audits, and detailed transparency reporting. Smaller platforms and intermediary services still have baseline obligations around content moderation transparency and user redress mechanisms, just without the VLOP-level audit requirements. Map your actual EU user numbers and service type against these tiers honestly before assuming you’re too small to matter, since baseline DSA obligations apply well below the VLOP threshold.

If you’re genuinely unsure which tier applies, get a written legal opinion rather than guessing from general summaries of the regulation, DSA case law and Commission guidance are both still developing, and the cost of a wrong assumption at this stage is far higher than the cost of a proper legal review now. This is doubly true if your EU user numbers are growing quickly, since a platform can cross into VLOP territory well before its own leadership realizes the threshold has been passed.

Step 2: Build Your Risk Assessment and Content Handling Process

If your AI product generates content, moderates content, or serves as an intermediary for user interactions in the EU, you need a documented process for identifying illegal content, handling user complaints, and assessing systemic risks like the spread of misinformation or harm to minors. For an AI platform specifically, this means thinking through what happens when your system generates something harmful or is used in a way that creates the kinds of systemic risks the DSA is designed to catch, not just traditional user-generated content moderation. Document this process even if you’re below the VLOP threshold, since regulators and enterprise customers alike increasingly expect to see it regardless of your exact designation.

Step 3: Set Up Ongoing Monitoring, Not a One-Time Fix

DSA compliance isn’t a project you finish once. User numbers change, which means your VLOP status can change too, and ChatGPT’s own crossing of the 45-million threshold shows how quickly a fast-growing product can move into a stricter compliance tier. Set up a recurring review, quarterly is reasonable for most companies, that checks your current EU user numbers against the thresholds, revisits your risk assessment for anything that’s changed in your product, and confirms your transparency reporting is current. Assign this to a specific person or team, not a rotating responsibility that nobody actually owns.

Build a simple dashboard or even a shared spreadsheet that tracks monthly EU active users against the VLOP threshold, updated every reporting cycle. That one artifact, reviewed on a fixed schedule by a named owner, is often the difference between a company that sees a regulatory shift coming and adjusts its roadmap accordingly, and one that finds out from a Commission designation letter the same way the rest of the industry read about ChatGPT’s.

Common Mistakes to Avoid

The first mistake is assuming DSA rules only apply to traditional social media and marketplace platforms. ChatGPT’s designation makes clear that a generative AI product with a large enough EU user base gets treated the same way. The second is confusing DSA obligations with EU AI Act obligations, they’re separate regulations with separate requirements, and a company can be in scope for one, both, or neither depending on what it does. The third is waiting for a formal designation letter from the European Commission before starting compliance work. By the time that letter arrives, as OpenAI has now learned, you’re already expected to be building toward the stricter obligations, not starting from zero.

Key Takeaways

  • Generative AI isn’t exempt: ChatGPT’s VLOP designation confirms the DSA applies to AI platforms that hit the user threshold.
  • Fines are steep: Non-compliance penalties can reach 6% of global annual revenue.
  • Reach is extraterritorial: Non-EU companies serving enough EU users face the same obligations as EU-based ones.
  • Compliance is ongoing: User growth can push you into a stricter tier faster than you expect, so review your exposure regularly.

Need Expert Help?

If this feels like a lot to manage alone, TecniForge can handle the heavy lifting. Our team specializes in custom software development and helping platforms prepare for evolving EU technology regulation. Get in touch with our experts if you serve EU users and need to assess your DSA exposure.

Also read: ChatGPT EU Rules: 6 Things Businesses Must Know as the DSA Bites, our earlier coverage on the VLOP designation and what triggered it.

Regulators are applying old rules to new technology faster than most companies expect. Map your exposure now, before a growth milestone maps it for you.

Sources

Reporting drawn from TechStartups.