PageIndex

Table the VLOP/VLOSE additional obligations — article, obligation, key constraints — plus the compli

Shared chat

Table the VLOP/VLOSE additional obligations — article, obligation, key constraints — plus the compliance timeline, then analyse the impact on ChatGPT, Reddit, and Roblox separately.

I'll start by mapping the document structure to locate the VLOP/VLOSE section.

Now reading the VLOP/VLOSE obligations section and the final provisions on timing.

Now the remaining articles (40-43) covering data access, compliance function, transparency reporting, and supervisory fees.

Section 5, Chapter III — Additional VLOP/VLOSE obligations

ArticleObligationKey constraints
33Designation as VLOP/VLOSEThreshold: ≥45 million average monthly active recipients in the Union, plus a Commission designation decision . Commission may adjust the threshold by delegated act if EU population moves ±5% vs. 2020 . Provider gets 10 working days to submit views where the Commission relies on other information; silence does not block designation . De-designation only after an uninterrupted year below threshold .
34Systemic risk assessmentFour mandatory risk categories: illegal content; fundamental rights (dignity, privacy, data protection, expression/media pluralism, non-discrimination, rights of the child, consumer protection); civic discourse, electoral processes and public security; gender-based violence, public health, protection of minors, physical and mental well-being . Must analyse recommender/algorithmic design, content moderation systems, T&Cs and enforcement, ad selection systems, data practices , plus intentional manipulation, inauthentic/automated use and rapid amplification , and regional/linguistic specifics . Timing: by the date of application, at least annually, and before deploying functionalities likely to have a critical impact on identified risks . Documents retained ≥3 years .
35Risk mitigationMeasures must be reasonable, proportionate, effective, tailored to identified risks, with particular regard to fundamental rights impacts . Illustrative menu: redesign of service/interfaces, T&C changes, content moderation adaptation, testing/adapting algorithms, ad system changes, internal process reinforcement, trusted flagger and codes-of-conduct cooperation, awareness measures, child-protection measures including age verification and parental controls, and prominent marking of deepfakes with a user flagging function .
36Crisis response mechanismTriggered only where extraordinary circumstances cause a serious threat to public security or public health in the Union or significant parts of it . Commission acts on Board recommendation; can require assessment, specific measures, and periodic reporting . Actions capped at three months, extendable once by up to three months . Choice of specific measures stays with the provider .
37Independent auditAt least annually, at the provider's own expense, covering all Chapter III obligations plus code-of-conduct and crisis-protocol commitments . Full cooperation including access to data and premises; no hampering or unduly influencing the audit . Auditor independence: no related non-audit services in the 12 months before or after, max 10 consecutive years, no success-contingent fees . Opinion must be positive / positive with comments / negative; a non-positive opinion triggers an audit implementation report within one month, with justification for any recommendation not implemented .
38Recommender systemsAt least one non-profiling option for each recommender system, on top of Article 27 transparency .
39Ad transparency repositoryPublic, searchable, multicriteria-queryable repository plus API access, retained until one year after last display; no personal data of recipients; reasonable efforts on accuracy . Fields include ad content, beneficiary, payer, display period, targeting/exclusion parameters, and reach broken down by Member State . Removed/illegal ads: substitute Article 17(3) or 9(2) information instead .
40Data access and scrutinyRegulator access on reasoned request, including explanation of the design, logic, functioning and testing of algorithmic and recommender systems . Vetted-researcher access for systemic-risk research ; only escape route is a request to amend within 15 days on grounds of no access to data or security/trade-secret vulnerability, and it must propose alternatives . Publicly accessible interface data must be shared without undue delay, in real time where technically possible, with qualifying researchers .
41Compliance functionIndependent from operational functions, one or more compliance officers, sufficient authority, stature, resources and board access . Head must be an independent senior manager reporting directly to the management body and cannot be removed without that body's prior approval . Management body is accountable for independence, conflict-of-interest prevention and systemic risk management, and must approve risk strategies at least annually .
42Transparency reportingArticle 15 reports within two months of the date of application, then at least every six months . VLOPs additionally report content-moderation headcount broken down by each official EU language, moderator qualifications, linguistic expertise and training, and accuracy indicators per language . Average monthly recipients per Member State . Risk assessment results, mitigation measures, audit report and audit implementation report published at the latest three months after receipt of each audit report ; confidential/security-sensitive parts may be redacted publicly but must be sent in full to the regulator with reasons .
43Supervisory feeAnnual fee per designated service, charged from designation, proportionate to average monthly active recipients in the Union, capped at 0.05% of worldwide annual net income in the preceding financial year .

Enforcement backstop: Commission fines up to 6% of total worldwide annual turnover for infringement, and up to 1% for procedural failures such as misleading information or refusing inspection ; periodic penalties up to 5% of average daily worldwide turnover per day . Section 5 breaches trigger the enhanced supervision regime: a mandatory action plan including a committed independent audit, reviewed by the Board within one month .

Compliance timeline

Date / triggerEvent
16 November 2022Early application of Article 24(2)–(3) and (6), Article 33(3)–(6), Article 37(7), Article 40(13), Article 43 and Sections 4–6 of Chapter IV — i.e. the user-number reporting and designation machinery, plus the fee regime, ran ahead of the main regulation .
Designation notificationCommission notifies provider, Board and DSC of establishment without undue delay; list published in the Official Journal .
Notification + 4 monthsSection 5 obligations start to apply (or cease to apply) ; anticipated application where that date falls before 17 February 2024 .
Same dateFirst systemic risk assessment must be completed .
Date of application + 2 monthsFirst Article 15 transparency report published, then at least every six months .
Annually thereafterRisk assessment refresh , independent audit , management-body review of risk strategies , supervisory fee .
Ad hocRisk assessment before deploying functionalities with critical impact on identified risks .
Audit + 1 monthAudit implementation report if opinion is not positive .
Audit report + 3 monthsPublic disclosure of risk assessment report, mitigation measures, audit report and implementation report .
17 February 2024General application of the Regulation to everyone else .
17 November 2025Commission report on Article 33 application, including the scope of Section 5 .
18 February 2027Reports on SME impact and on the Board's functioning and Article 43 .
17 November 2027, then every 5 yearsGeneral evaluation of the Regulation .
12-month lapse below thresholdDesignation terminated; obligations cease four months after notification .

Service-by-service impact

The analysis below applies the text above to each service; designation status is a factual matter outside this document, so treat threshold judgments as conditional.

ChatGPT

The pressure point is classification. Section 5 attaches to online platforms and online search engines , so the question is whether the search-and-browse function constitutes an online search engine and whether shared-content features amount to dissemination to the public. If the search function crosses 45 million average monthly EU recipients, designation as a VLOSE follows and only the search service is captured, not the whole assistant.

Where the framework bites hardest:

  • Article 34 requires assessing risks from the design and functioning of the service and its algorithmic systems, expressly including negative effects on civic discourse and electoral processes and on mental well-being . Generative output does not map cleanly onto "dissemination of illegal content" by third parties, but the algorithmic-systems and fundamental-rights limbs apply directly. New model or feature launches likely to affect those risks require an assessment before deployment .
  • Article 40(3) obliges explanation of the design, logic, functioning and testing of algorithmic systems to the Commission or DSC on request . This is the most intrusive item for a frontier-model operator, and the only carve-out is a request to amend on security or trade-secret grounds, which still requires proposing alternatives .
  • Article 35(1)(k) synthetic-media marking sits awkwardly with a service whose entire output is generated; the obligation is framed as a possible mitigation measure rather than a hard rule, giving room to argue proportionality .
  • Article 38's non-profiling recommender option and Article 39's ad repository are largely inert if the service neither profiles for ranking nor serves advertising .
  • Article 42(2) language-by-language moderation headcount reporting is a poor fit for a model-safety organisation, since it presumes human moderator teams per official language .

Net: moderate obligation count, but high uncertainty and high algorithmic-disclosure exposure. Article 41's independent compliance function with a senior head reporting to the management body is a structural governance change .

Reddit

Reddit is a textbook VLOP-shaped service: third-party content disseminated to the public, algorithmic feeds, advertising, and volunteer moderation. The binding question is again the 45 million EU threshold, which Reddit has publicly reported below in its Article 24(2) disclosures; if it stays below for an uninterrupted year it remains outside Section 5 .

If designated:

  • Article 34 applies across all four risk limbs, and the assessment must explicitly cover T&Cs and their enforcement . Reddit's devolved model — subreddit rules enforced by unpaid moderators — sits uneasily with an obligation to demonstrate enforcement adequacy, and with regional and linguistic granularity .
  • Article 34(2) requires analysis of intentional manipulation, inauthentic use and automated exploitation . Vote manipulation, brigading and bot activity move from trust-and-safety metrics to auditable regulatory findings.
  • Article 42(2) is the most expensive single item: content-moderation headcount, qualifications, linguistic expertise, training and accuracy indicators broken down by each official EU language . A community-moderation model with thin per-language professional staffing is exposed here.
  • Article 38 requires a non-profiling feed option ; chronological or subscription-only views make this comparatively cheap for Reddit.
  • Articles 39 and 40 are directly costly: a full public, API-accessible ad repository , and vetted-researcher access to data — plus near-real-time access to publicly accessible interface data for qualifying researchers, which interacts badly with Reddit's paid-API monetisation strategy .
  • Article 36 crisis powers matter for a service that becomes a live information hub during breaking events, though measure choice stays with Reddit and orders are capped at three months .

Net: highest obligation density of the three, with per-language moderation reporting and researcher data access the principal cost and strategy conflicts.

Roblox

Roblox is a hosting/platform hybrid whose user base skews young, which places it squarely in the Article 34(1)(d) minors and well-being limb and the Article 34(1)(b) rights-of-the-child limb . Threshold status is the gating question; publicly reported EU figures have been below 45 million.

If designated:

  • Article 35(1)(j) child-protection mitigation — age verification, parental control tools, abuse-signalling and support tools for minors — becomes the central compliance workstream and drives product change, not just reporting .
  • Article 34's scope covers risks from the design or functioning of the service and from the use made of it , which pulls in grooming, in-experience chat, and the economics of user-generated experiences. The pre-deployment assessment duty applies to new social or monetisation features .
  • Article 34(2)(e) data-related practices plus the consumer-protection limb bear on the Robux economy and in-experience purchasing by minors .
  • Article 42(2) per-language moderation reporting is demanding because Roblox moderates voice, chat, images and 3D assets at very high volume across many EU languages .
  • Article 40 researcher access is technically hard: much of the relevant signal is ephemeral in-experience interaction rather than "publicly accessible in their online interface", which narrows the Article 40(12) real-time duty but not the Article 40(4) vetted-researcher duty .
  • Articles 38 and 39 are lighter: discovery ranking would need a non-profiling option , and the ad repository obligation scales with the size of the immersive-advertising business .

Net: fewer distinct obligations than Reddit, but the deepest product-engineering impact, concentrated in age assurance and minor-safety mitigation, with heightened regulatory salience because child-safety failures attract the Article 75 enhanced supervision route .

One caveat: designation decisions and current EU user counts are external facts not contained in this Regulation. I can check the live designation list if you want the analysis pinned to actual status.

  1. 1.
    112 references