We tested OpenAI’s reporting system in the European Union. This is what we found.
OpenAI has failed to take safety seriously – again. CCDH tested OpenAI’s reporting system for ChatGPT users in the European Union and found that the company ignored 19 out of 20 reports submitted by a simulated 13-year-old.
Content warning: Self-harm, suicide, and eating disorders.
CCDH researchers reported harmful outputs generated by ChatGPT related to self-harm and eating disorders, including instructions for maintaining dangerous low-calorie diets and fictional suicide notes.
Of the 20 reports submitted, only one received an email response – with an empty subject line. The email contained no evidence of content review, no explanation of actions taken, and no next steps.

The current reporting portal is but an empty promise of accountability and transparency. OpenAI has a responsibility to keep its users safe and, when it fails to do so, should provide meaningful avenues for complaints. OpenAI must design processes that demonstrate follow-up action, changes, or even genuine acknowledgement.
How is the DSA holding OpenAI accountable?
With more than 120 million monthly users in the EU, ChatGPT has entered a new regulatory phase. The European Commission has confirmed that it is evaluating whether to designate ChatGPT as a Very Large Online Search Engine (VLOSE) under the Digital Services Act (DSA). This is the designation used for large platforms like Meta’s Facebook and Instagram, X, TikTok, LinkedIn, and Google’s YouTube.
This move would subject OpenAI to enhanced obligations in the European Union, including the need for systemic risk assessment, transparency reporting, and data access for researchers. These obligations are designed for regulators to have visibility of opaque algorithmic systems and ensure that powerful companies meet the EU’s standards.
Yet, CCDH research raises concerns about OpenAI’s compliance with even the DSA’s baseline duties. Under Article 14, companies must enforce their own terms and conditions consistently, and under Article 16, they must maintain a “notice and action” mechanism including notifying users of decisions taken in response to their reports. OpenAI has failed on both fronts.
CCDH has shown that OpenAI’s safety measures are ineffective
This research follows recent CCDH study into harms to teenage users of ChatGPT and the ineffectiveness of new safety measures to reduce that harm.
But OpenAI is not only failing to protect users from harm. The company’s failure to meaningfully engage with people through reporting mechanisms poses serious questions about its ability to comply with the DSA.
As the European Commission evaluates changing OpenAI’s designation, the evidence points to a company still struggling to meet the most basic accountability standards that the law already requires.