On 31 August 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act, placing its provider under additional obligations, including systemic risk assessment, risk mitigation and independent audits, after the prescribed transition period. On 1 September 2026, the European Commission confirmed that it had sent requests for information to more than 30 AI companies to assess compliance with model safety, copyright and transparency requirements. Relevant providers need to prepare evidence in response to those requests, which do not in themselves constitute findings of non-compliance. On 1 September 2026, the US Department of Justice filed a government submission in the OpenAI copyright litigation supporting the fair-use argument for the training stage. The submission is not a judicial ruling, and enterprises still need to assess copyright risks associated with data acquisition, storage and outputs separately. On 1 September 2026, an expert from the US General Services Administration presented research on multi-agent security at the Federal Cybersecurity and Privacy Professionals Forum hosted by NIST, recommending that agent interactions be incorporated into threat modelling. The presentation provides a reference for enterprises designing cross-agent authentication, workflow authorisation and log correlation, without creating new mandatory obligations.
On 31 August 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the Digital Services Act (DSA), which is already in force.
The designation brings ChatGPT within the DSA’s additional tier of oversight. It is based on the service’s hybrid nature, which includes web search, and its reaching the threshold of 45 million average monthly users in the EU. Additional obligations apply four months after notification and include assessing systemic risks at least annually, taking mitigation measures and undergoing independent audits. New features likely to have a significant impact on risks must be assessed before deployment, and supporting assessment documents must be retained for at least three years. Sources differ on the deadline month: the updated English press release gives January 2027, while end-December 2026 is still cited elsewhere. The precise date should be determined by the formal notification.
The provider needs to integrate risk assessment into its product release process. For example, when changing web-enabled retrieval, answer presentation or features for interactions with minors, it should record risk-testing samples, the languages covered, mitigation measures and validation results, enabling audits to trace the relationship between feature changes and risk responses. Tests involving election information, illegal content or physical and mental well-being should also cover realistic interaction scenarios. These additional obligations directly bind the provider of the designated service; ordinary enterprises do not automatically become VLOSEs simply by using ChatGPT or integrating OpenAI APIs. Procurement and integration teams can ask suppliers to clarify the regulatory coverage of the services actually used, feature-change notifications and issue-escalation channels, while continuing to establish source verification and human review for their own customer use cases. The official list currently identifies ChatGPT as the designated service and OpenAI Ireland Limited as its provider. The full designation decision has not yet been published, so the coverage of all APIs and products should not be inferred independently.
There is precedent for scrutiny of generative AI risks under the DSA. On 17 May 2024, the European Commission sent Microsoft a legally binding request for information, requiring additional internal documents and data on Bing’s generative AI features, with a focus on hallucinations, the spread of deepfakes and automated manipulation that could mislead voters. The current action places ChatGPT, a conversational service with search capabilities, directly on the designation list, continuing an approach to oversight based on service functionality and dissemination effects. For enterprise product design, this suggests that chat interfaces, web-enabled retrieval and content distribution may need to be assessed together in a service-level risk analysis. Subsequent monitoring should focus on how the formal decision defines the service’s boundaries and on risk assessments, mitigation measures and audit materials published as required by law, to understand how these requirements apply to specific features.
On 1 September 2026, European Commission spokesperson Thomas Regnier confirmed at the midday press briefing that the Commission had sent its first requests for information to more than 30 AI companies under the enforcement framework of the Artificial Intelligence Act (AI Act), covering model safety, copyright and transparency.
The action constitutes information gathering at an early stage of enforcement, with two lines of inquiry: model safety and cybersecurity, covering general-purpose and state-of-the-art AI models; and copyright and transparency compliance. Receiving a request for information does not mean that a company has been found non-compliant or that it has been penalised. The Commission did not publish the list of recipients. Although it confirmed recent exchanges with OpenAI and Anthropic on cybersecurity risks, it did not confirm whether either company had received a request. The public confirmation was made on 1 September; the briefing did not disclose when requests were sent to individual companies, the specific questions asked or the response deadlines.
Model providers need the ability to retrieve compliance evidence for specific model versions. Article 91 of the AI Act allows the Commission to request technical documentation and other necessary information, and requires requests to state their legal basis, purpose, the information sought and the deadline. Enterprises can establish processes for registering incoming requests, assigning evidence owners and reviewing responses accordingly. When preparing materials, providers should link summaries of training content, copyright policies and records of how rights reservations are handled to the corresponding model version. Providers subject to statutory systemic risk obligations should also link model evaluations, adversarial testing, serious incidents and remediation records. These recommendations correspond to existing obligations under Articles 53 and 55; they must not be presented as a published checklist from this batch of requests. For enterprises integrating external models, procurement assessments should focus on whether suppliers can provide documentation on model capabilities, limitations and integration requirements, alongside contractual arrangements for security incident notification and version changes. Whether a supplier has received an inquiry cannot, on its own, substitute for an assessment of its model risks.
Obligations for providers of general-purpose AI models have applied in phases since 2 August 2025, while the Commission’s relevant enforcement powers have applied since 2 August 2026. Models placed on the market before 2 August 2025 remain subject to transitional arrangements until 2 August 2027. This public confirmation shows that the regulator has begun gathering information in practice, but it does not establish that all existing models have been brought forward to the same compliance deadline. Compared with the designation of ChatGPT under the Digital Services Act (DSA) in the same week, the two actions concern model-provider compliance and risks associated with large online services, respectively. Enterprises need to identify the responsible entities and scope of evidence separately. Subsequent monitoring should track whether the Commission publishes the specific legal bases for requests, the models covered and the outcomes, avoiding any presentation of preliminary inquiries as findings of infringement.
On 1 September 2026, the US Department of Justice (DOJ) filed the “Statement of Interest of the United States” with the United States District Court for the Southern District of New York. In the consolidated OpenAI copyright litigation, the submission supports treating the use of copyrighted written works to train large language models as fair use.
The statement sets out the government’s legal position and creates no new copyright exemption. The DOJ argues that training serves a new purpose by learning linguistic patterns and is highly transformative. It also argues that assessments of market harm should distinguish substitution for protected works from general competition. Its reasoning explicitly focuses on the training stage; data acquisition, storage and specific outputs may still raise separate copyright questions. Support for fair use at the training stage does not amount to recognition that the entire data-processing chain is lawful. Fair use must be assessed in the context of the specific use. The statement itself is neither a court judgment nor a ruling absolving OpenAI of liability.
Enterprises using news, books or specialist materials to train or fine-tune models still need to assess separately how the materials were obtained, their training use and the use of outputs. They should link sources, licence scope and acquisition dates to training batches, distinguishing materials authorised for training from those authorised only for retrieval or display. When providing answers to customers, enterprises can establish tests for reproduction of lengthy verbatim passages, citation controls and procedures for handling disputed content. Section 107 of the current US Copyright Act requires consideration of the purpose of the use, the nature of the work, the amount and substantiality used, and market effects. Government support for a category of training use cannot replace assessment of those specific facts. When procuring external models, enterprises should check whether intellectual property indemnity provisions cover materials they upload themselves, fine-tuning activities and final outputs, and clarify arrangements for cooperation on evidence if a dispute arises. These are risk management recommendations; the statement introduces no uniform logging or audit obligations.
The New York Times sued Microsoft and OpenAI on 27 December 2023, alleging unauthorised copying and use of news content. The DOJ’s intervention adds the government’s views in support of fair use for training to the existing litigation. The key issue ahead is whether the court adopts its distinction between stages and its market-harm analysis. Deployments across jurisdictions also face differing requirements. Article 53 of the European Union’s Artificial Intelligence Act (AI Act), which is already in force, establishes an obligation for general-purpose AI model providers to put in place a copyright compliance policy. Recital 106 explains that the obligation applies to providers placing models on the EU market, regardless of whether training took place in another jurisdiction. Accordingly, US fair-use defences and EU copyright compliance policies require separate assessments and supporting evidence.
On 1 September 2026, Tam Nguyen, Data Scientist for Cybersecurity at the US General Services Administration (GSA), presented on risks in multi-agent AI systems, gaps in existing frameworks and security recommendations at the Federal Cybersecurity and Privacy Professionals Forum hosted by the National Institute of Standards and Technology (NIST).
“Security Considerations for Multi-Agent AI Systems” is a conference presentation. Its official page was created on 2 September 2026, and it establishes no new mandatory requirements. The material notes that malicious content in shared memory may propagate to other agents, identity and trust issues may spread along task-delegation chains, and fragmented logs make it difficult to reconstruct full causal relationships. The presentation recommends incorporating interactions between agents into threat modelling, identifying how attacks can move through collaboration pathways, and proposes measures such as cross-agent event correlation, authentication, workflow authorisation and continuous security testing.
When an enterprise assigns different agents to read customer information, propose a resolution and execute a refund, its security assessment needs to examine the combined outcome of those connected steps: whether instructions passed from upstream are trustworthy, whether permission to read information is incorrectly extended to permission to execute transactions, and whether the original task and authorising person can be identified after an incident. Drawing on the presentation’s recommendations on workflow authorisation and event correlation, enterprises can test cross-agent authorisation violations and error propagation before deployment, use a common task identifier to link delegation, tool calls and approval records during operation, and specify the conditions for stopping the workflow. When procuring multi-agent platforms, enterprises can also ask suppliers to explain their capabilities for identity isolation, revocation of authorisation and export of complete call records. These are deployment recommendations; the forum established no uniform log-retention periods or procurement eligibility requirements.
NIST previously launched the AI Agent Standards Initiative on 17 February 2026, identifying interoperable protocols and research on security and identity as areas of work. On 27 August 2026, its official technical blog further discussed shared credentials, long-lived tokens and overly broad permissions, warning that excessive reliance on human confirmation may lead to approval fatigue. This forum adds an analysis of multi-agent collaboration risks within that broader discussion, but does not establish a new federal regulatory standard. For enterprise architecture, the three developments point to a concrete question: can identity, permissions and accountability records be carried forward consistently as tasks are delegated? As collaboration capabilities expand, these controls also need to cover execution across systems so that each action can be assessed against the scope of the original authorisation.
Cite as · AI Governance Weekly · 11 September 2026
If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.