Category: 미분류

  • Three Core Issues in EU DSA Regulation — What the ChatGPT and Reddit VLOP Designations Really Mean

    EU DSA regulation

    Key Summary

    • The European Commission and Digital Services Act (DSA) supervisory authorities have officially designated OpenAI’s ChatGPT and Reddit as “Very Large Online Platforms (VLOPs),” the top tier based on user count.
    • Effective immediately, both services must carry out enhanced obligations across the EU, including risk assessments, publication of transparency reports, public disclosure of illegal-content response systems, granting data access to external researchers, and strengthened measures for child protection and cyberbullying prevention.
    • As a generative AI service, ChatGPT must submit a dedicated risk assessment covering harms from hallucinations, deepfakes, and harmful content for minors. Reddit must demonstrate that its community self-governance structure (Mod/Subreddit) satisfies the DSA’s “systemic risk” requirements.

    issues

    EU DSA regulation drew a new benchmark at the end of August. The European Commission has designated OpenAI’s ChatGPT and Reddit as “Very Large Online Platforms (VLOPs),” the top tier based on user count. Effective immediately, both services must fulfill enhanced obligations, including risk assessments, transparency reports, external researcher data access, and child protection systems.

    ChatGPT is the first generative AI service to be included as a VLOP. Reddit is the second U.S.-origin UGC platform after X to receive the designation. I see the two designations as sending different signals. One is the fact that “AI services are now subject to platform regulation,” and the other is a new test of whether “community self-governance will be recognized by regulators.”

    1. A Separate Risk Assessment for Generative AI — Hallucinations and Minor Protection

    The risk assessment ChatGPT must submit differs in character from that of a typical VLOP. EU DSA regulation classifies the risks arising from generative AI’s “synthetic content” as a separate category. From misinformation caused by hallucinations, to harmful responses to minors, to the potential abuse of image-generation features for deepfakes — OpenAI must document its mitigation measures and incident-response systems for each of these items.

    The reason this is practically difficult is that the outputs of large language models are non-deterministic, so traditional “content moderation checklist” approaches cannot fully control the risk. As a result, OpenAI is likely to submit its own documents, such as model cards and system cards, together with user feedback loops and safety-classifier performance metrics. How far EU regulators require that data to be disclosed to external researchers will be a key variable going forward.

    2. UGC Platforms’ Self-Governance Structure — Reddit’s Systemic Risk Proof

    Reddit’s designation poses a different test. The DSA requires VLOPs to conduct a “systemic risk” assessment. The scope covers the spread of illegal content, impact on elections and public health, child protection, gender-based violence, and cyberbullying.

    Reddit’s self-governance structure — its moderators and Subreddit operators — has long functioned as the backbone of content moderation. But EU DSA requirements are not satisfied merely by the fact that a structure exists. The EU requires proof that (1) policies are actually enforced, (2) moderators are given adequate tools and training, and (3) platform-level escalation paths function when inappropriate content arises. In other words, for self-governance to be recognized as “systemic safety,” performance metrics for that self-governance are needed. The metrics Reddit puts forward will be an industry-wide focal point.

    3. Transparency Reports and External Researcher Data Access

    The two most contentious provisions in the DSA are the biannual transparency reports and data access for “vetted researchers.” OpenAI must decide how to handle areas that directly collide with trade secrets, such as model weights, training data, and prompt logs. Reddit must determine how much information about deleted posts, locked subreddits, and banned users it will expose to researchers.

    The interesting part is that both companies have already been effectively treating EU DSA regulation as a de facto global standard. Google, Meta, and X applied DSA standards to their global operations from the first round of VLOP designations in 2024. This latest inclusion is the next chapter in that trend, and once rules are set, they effectively spread as the same UX to users outside the EU — the so-called “Brussels Effect.” It is worth watching how future EU DSA regulation technical standardization work expands into the global supply chain and researcher ecosystem.

    Global Ripple Effects — Where the U.S., U.K., and Korea Stand

    The Brussels Effect of EU DSA regulation is already in motion. The United States continues to push the Kids Online Safety Act (KOSA) at the federal level in 2024. The United Kingdom has already entered the first implementation phase under its Online Safety Act. South Korea is also moving in the same direction through revisions to its Child and Youth Protection Act and discussions on a basic AI law.

    Nonetheless, there are differences in pace and texture. The EU groups “platforms” as a unit and demands governance, transparency, and researcher access all at once. In contrast, the U.S. has fragmented federal and state laws, and the U.K. applies tiered rules by media type. South Korea’s basic AI law is likely to be designed around “impact assessment,” giving it a more industry-friendly tone than the EU DSA. Even so, one fact remains the same — any service that does not follow the EU DSA regulation benchmark loses the EU market.

    Key Issues at a Glance

    There are three issues this designation highlights.

    • Generative AI is classified separately as a “synthetic content” risk, and model cards and safety-classifier performance effectively become regulatory reports.
    • A community self-governance structure is not sufficient on its own; enforcement metrics, escalation paths, and moderator tools must be demonstrated together.
    • Transparency reports and researcher data access directly conflict with trade secrets, so consent procedures, ethics review, and publication guidelines must be designed in advance.

    What to Do Right Now

    • Check the European Commission’s VLOP list and simulate whether your service will reach the threshold (45 million monthly EU users) within the next 12 months.
    • Draft a vetted researcher collaboration guideline, including data scope, consent procedures, and publication requirements.
    • Build a data pipeline that can automatically aggregate the 11 transparency items required by the DSA on a biannual basis.
    • Consolidate safety-classifier, content-moderation, and ad-library data into a single dashboard and standardize quarterly compliance reviews.
    • Set up a translation pipeline that can simultaneously deliver transparency reports, terms of service, and safety guides in English, German, and French.

    Frequently Asked Questions

    Is VLOP designation mandatory?

    Yes, it is mandatory. Once the European Commission determines that the user-count threshold is met, it designates the service, and the designation cannot be refused. Violations can result in fines of up to 6% of global revenue.

    Does the ChatGPT designation apply to all of OpenAI?

    No. The designation applies to the ChatGPT service itself. OpenAI’s API business and other models are separate, although safety measures equivalent to those for a VLOP are likely to be indirectly required for services accessed via the API.

    Why was Reddit designated later than X?

    The EU only counts EU residents and excludes non-logged-in visits and API calls. Reddit’s share of EU users is analyzed to have been lower than X’s, which is considered a factor in the delay.

    Can a Korean business ignore EU DSA regulation?

    It would face service blocking in the EU. Since 2024, equivalent safety laws have been introduced in succession in the U.S., Korea, and Japan, making it a de facto global standard. A detailed analysis is available in Four Issues in the First Application of EU AI Regulation.

    This article was prepared based on Ars Technica’s reporting on the VLOP designations. Further English analysis can be found in The Standards Competition Created by ChatGPT’s VLOSE Designation.

    Expert Commentary (AI)

    Platform Governance & Digital Policy Expert

    Extending VLOP regulation is the right direction, but the mechanical designation by user count and the lack of methodology for evaluating self-governing communities remain gaps

    The VLOP designation of ChatGPT and Reddit is a symbolic event showing that platform regulation has expanded beyond the social-media feed model to generative AI and community self-governance structures. However, the approach of designating VLOPs solely on the basis of a 45 million monthly EU user threshold is a formal distinction unrelated to actual risk, and applying the same content-moderation framework to conversational chatbots and community feeds weakens the fit between regulatory target and means. The direction of requiring Reddit’s volunteer moderator system to demonstrate enforcement metrics and escalation paths does strengthen the accountability of self-governance, but excessively rigid metric demands can produce the perverse effect of pushing platforms to replace community self-governance with centralized algorithmic control. Data access for vetted researchers is genuine progress for the platform research ecosystem, but specific procedures to mediate conflicts with GDPR and trade-secret protection have not yet been established. The fine of up to 6% of global revenue for violations ensures effectiveness, but whether systemic risk assessments devolve into paperwork-driven compliance theater depends on regulators’ technical enforcement capabilities.

    Rating: 8/10 – The regulatory backbone of accountability, transparency, and researcher access has been validated, but risk-assessment methodology tailored to generative AI and self-governing communities is still incomplete

    AI Safety & Reliability Expert

    Treating hallucinations and deepfakes as systemic risk is meaningful, but sustainable assessment for non-deterministic outputs and resolution of overlap with the AI Act are key

    Classifying generative AI hallucinations, deepfakes, and harmful outputs for minors as a separate synthetic-content risk distinct from general UGC is substantive progress, bringing AI safety into the platform-responsibility domain. The approach of requiring submission of model cards, system cards, and safety-classifier performance metrics raises the documentation practices already common in the industry to the regulatory level, which has the advantage of a relatively low adaptation burden. However, because large language models are continuously updated, biannual risk assessments and transparency reports become outdated at the moment of submission; for effectiveness, post-deployment continuous monitoring and version-by-version re-evaluation obligations must run in parallel with snapshot reporting. If GPAI obligations under the EU AI Act and DSA systemic risk assessments are applied redundantly to the same model, compliance costs will be doubled, so the division of labor between the two regimes must be clarified. Safety-classifier metrics are also gameable, so standardized benchmarks and external red-team validation must back them up, and the disclosure of prompt logs to researchers creates new privacy risks unless anonymization techniques and secure research environments are designed in advance.

    Rating: 7/10 – Creating an external verification channel for generative AI is highly regarded, but assessment methodology standardization and resolution of regulatory overlap remain in the early stages