Weekly AI Governance Brief: 31 August–6 September 2026
European Commission brings ChatGPT under the DSA's enhanced supervision regime
On 31 August, the European Commission formally designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act. Reddit and Roblox were separately designated as Very Large Online Platforms. The designation followed declarations that each service reaches at least 45 million average monthly users in the European Union.
ChatGPT now has four months, until January 2027, to comply with the additional obligations applying to VLOSEs. These include requirements to assess and mitigate systemic risks arising from the service and its algorithmic systems.
The Commission identifies those risks as including the dissemination of illegal content, negative effects on minors and users' physical or mental well-being, effects on fundamental rights, electoral processes and public security. The designation also places ChatGPT within the Commission's enhanced supervisory framework under the DSA.
Why this matters
The designation extends an established EU systemic-risk regime directly to a major generative-AI service. For governance teams, this means ChatGPT's European regulatory framework is no longer defined only by AI-specific requirements. Its operation will also be subject to DSA processes for identifying, documenting and mitigating systemic risks associated with algorithmic services. The development therefore illustrates the growing interaction between the AI Act and adjacent EU digital legislation when the same service falls within multiple regulatory classifications.
Delaware links privacy rights to automated decision-making
On 2 September, Delaware Governor Matt Meyer signed House Bills 380 and 381, substantially expanding the state's personal-data framework. The legislation will take effect on 1 January 2027.
The package lowers the threshold for businesses falling within the framework to those handling data concerning at least 10,000 consumers. It also gives consumers the ability to opt out where protected data is used in automated decisions involving areas such as lending, housing and employment.
The legislation additionally narrows the existing exclusion for employee data. The Governor's announcement expressly identifies AI resume screeners, interview-scoring systems and tools used to influence hiring, promotion, disciplinary and termination decisions as relevant to this change.
The package expands the categories of data subject to opt-in requirements and treats certain inferences derived from other information as sensitive where they are used to identify or reveal a protected characteristic.
Why this matters
Delaware's approach demonstrates how significant AI-governance obligations can emerge through amendments to general privacy legislation rather than through a dedicated AI law. The automated-decision provisions are particularly relevant to organisations using AI in consequential processes. They connect system deployment with consumer control over personal-data processing, while the narrowing of the employee-data exemption increases the relevance of the framework for workplace AI. The treatment of inferred sensitive information is also significant for systems that generate classifications or predictions rather than merely processing information explicitly supplied by an individual.
California advances statutory controls on generative AI in legal practice
California's legislature completed passage of Senate Bill 574 on 31 August, with the enrolled version published on 4 September. The measure addresses the use of generative AI by attorneys and arbitrators.
The bill would prohibit attorneys from delegating the practice of law to generative AI. Lawyers using such systems would be required to prevent confidential, personally identifying, and other non-public information from being entered into systems where access is not appropriately restricted.
Attorneys would also need to take reasonable steps to verify AI-generated outputs and correct erroneous or hallucinated material. The bill specifically addresses verification of case and statutory citations and would require disclosure of generative-AI use to courts for documents submitted to them.
Separate provisions address arbitration. An arbitrator could not delegate any part of the decision-making process to a generative-AI tool and could not rely on AI-generated information outside the record without prior disclosure to the parties and an opportunity, where practical, to comment.
Why this matters
SB 574 provides a concrete example of AI governance being embedded into an existing professional accountability framework. Its controls address several recurring operational issues associated with generative-AI adoption: protection of confidential information, verification of outputs, and retention of human responsibility for consequential decisions. The bill also distinguishes between AI used to assist professional work and AI used as a substitute for professional judgment. For governance purposes, that distinction is material in environments where an AI-generated output can influence legal proceedings or individual rights.
G20 ministers agree common AI and emerging-technology principles
G20 Innovation Ministers concluded their meeting on 2 September with a consensus statement covering emerging technologies and AI. The meeting brought together G20 members, including the European Union, and produced several associated policy deliverables.
The statement addresses pro-innovation policy frameworks, intellectual-property policy for artificial intelligence and the relationship between AI and standards. Ministers also agreed on the Carolina Principles for Emerging Technologies.
Additional deliverables included the G20 AI Prosperity Objectives and AI Prosperity Compact, which concern technical workforce development and private-sector participation.
The statement does not create binding legal requirements. Its significance lies instead in the formal agreement reached among jurisdictions with substantially different domestic approaches to AI regulation.
Why this matters
International AI governance remains fragmented at the level of binding national and regional law. The G20 statement nevertheless identifies areas where governments were able to agree on common policy language. Standards are especially relevant because they can provide a practical interface between high-level governance principles and the technical processes used to evaluate AI systems. The inclusion of intellectual-property policy also places another major area of AI-related regulatory tension within a multilateral framework. The statement should therefore be understood as a governance-direction signal rather than a new compliance obligation.
Looking ahead
The developments of 31 August–6 September show AI governance continuing to expand through legal frameworks that were not originally designed as comprehensive AI regimes.
The Commission's designation of ChatGPT brings generative AI directly within the EU's systemic platform-risk architecture. Delaware uses privacy law to address automated decision-making and workplace AI, while California is developing AI-specific duties through professional regulation.
At the international level, the G20 agreement shows standards and intellectual-property policy becoming part of formal multilateral AI discussions. Across the period, the clearest observable pattern is therefore not convergence around a single AI-law model, but the incorporation of AI governance into existing regulatory and institutional systems.
Sources
European Commission designation of ChatGPT under the Digital Services Act: https://digital-strategy.ec.europa.eu/en/news/commission-designates-chatgpt-reddit-roblox-under-digital-services-act
Delaware Governor announcement on HB 380 and HB 381: https://news.delaware.gov/2026/09/02/governor-meyer-signed-historic-data-privacy-legislation-protecting-delaware-residents-and-businesses/
Delaware Legislative Advisory #57: https://governor.delaware.gov/legislative-advisories/legislative-advisories-57/
California Legislature enrolled text of SB 574: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB574
G20 Innovation Ministerial Statement: https://www.gov.uk/government/publications/g20-innovation-ministerial-statement-2-september-2026