The EU just regulated ChatGPT as a search engine — and the Commission's wording covers the answering, not the search box
TL;DR: On Monday 31 August 2026 the European Commission designated ChatGPT a Very Large Online Search Engine (VLOSE) under the Digital Services Act — the first generative AI assistant brought under the regime, and only the third designated search service after Google Search and Bing. Reddit and Roblox were designated as Very Large Online Platforms in the same decisions, taking the supervised total to 28. The trigger was OpenAI’s own disclosure of roughly 159 million average monthly EU users, far above the 45 million threshold. Obligations — annual systemic risk assessments, independent audits, researcher data access, ranking transparency, an ad repository — bite after four months, which the Commission puts at January 2027, with fines up to 6% of global annual turnover. The wording is the story. OpenAI says “ChatGPT search operates as a search service under the DSA.” The Commission’s reason is that ChatGPT answers prompts and queries, including by searching the web. One scopes a feature; the other scopes the product. For you: nothing changes this quarter, but from January a system you already depend on starts producing audited, published safety documentation — the first genuinely citable evidence most AI vendor files have ever had.
What the Commission actually did
The decision is short and its mechanics are unglamorous. ChatGPT “declared that it reaches at least 45 million average monthly users in the EU” — the DSA’s designation threshold — and the Commission designated it accordingly. Reddit and Roblox crossed the same line and were designated as Very Large Online Platforms. That brings the total number of designated very large platforms and search engines to 28.
The self-reported figure is much larger than the threshold. OpenAI’s DSA transparency disclosure put ChatGPT at roughly 159.1 million average monthly EU users for the six months ending 31 March 2026, up from about 120.4 million in the preceding period. This was not a marginal call.
Henna Virkkunen, the Commission’s executive vice-president for tech sovereignty, security and democracy, framed it plainly: the designations mean the three services “will now be held to a higher standard of scrutiny and accountability in the European Union, in line with their large impact on our citizens and society.”
OpenAI’s response was cooperative and carefully worded. A spokesperson said: “ChatGPT search operates as a search service under the DSA, and we are preparing to meet the additional compliance requirements that come with this Very Large Online Search Engine designation.”
The eleven words that decide the scope
Read those two statements next to each other and they are not describing the same object.
The Commission’s stated reason for treating ChatGPT as a search engine is that it answers prompts and queries, including by searching the web. The phrase “including by” is doing enormous work. It says web search is one of the ways ChatGPT does the regulated thing, not that web search is the regulated thing. The regulated act, on that reading, is answering.
OpenAI’s sentence draws the boundary somewhere else. “ChatGPT search operates as a search service” identifies a named feature — the mode where the assistant browses and cites — and locates the designation there. On that reading, a conversation that never touches the web is outside the perimeter.
This is not a semantic quibble, because the DSA’s obligations attach to the designated service and its “algorithmic systems”. If the perimeter is the search feature, OpenAI must assess systemic risk in a retrieval pipeline. If the perimeter is the assistant, it must assess systemic risk in a general-purpose model that hundreds of millions of Europeans use for legal questions, medical questions, political questions and their own mental health — the exact categories the DSA names as systemic risk areas, and the ones this site has watched OpenAI address through product policy rather than regulation until now.
Nobody will resolve this on 31 August. It gets resolved when the first risk assessment is filed and the Commission either accepts its scope or opens proceedings. That is the thing to watch in early 2027, and it is genuinely undecided.
What the obligations actually are
Stripped of acronyms, the VLOSE tier adds five things a normal service does not have to do:
| Obligation | What it means in practice |
|---|---|
| Annual systemic risk assessment | Document how the service could amplify illegal content, harm minors, damage physical and mental wellbeing, infringe fundamental rights, distort elections or threaten public security — and what mitigations are in place |
| Independent audit | A third party, not an internal review, tests those claims annually and publishes an opinion |
| Researcher data access | Vetted academic researchers can compel access to data needed to study systemic risk |
| Ranking and recommender transparency | Explain the main parameters determining what the service surfaces, and offer at least one option not based on profiling |
| Ad repository and crisis mechanism | A public archive of ads shown, plus a Commission-triggered crisis response protocol |
Enforcement sits with the Commission directly rather than a national regulator, with Ireland’s Coimisiún na Meán in a supporting role, and penalties reach 6% of global annual turnover. The compliance clock is four months from notification; the Commission’s announcement states this as January 2027.
Two regimes, one product
Twenty-nine days before this designation, Article 50 of the EU AI Act became applicable, requiring machine-readable marking of synthetic output and disclosure when AI-written text is published to inform the public. That is why Anthropic shipped a text watermark and why every page on this site carries an AI-generated disclosure.
Now a second European regime lands on the same product, and it classifies it as something else entirely. Under the AI Act, ChatGPT is a general-purpose AI system with transparency duties. Under the DSA, it is a search engine with systemic-risk duties. Add the GDPR question already live around ChatGPT’s advertising rollout in the EEA and its consent-or-pay design — and note that a VLOSE must now publish an ad repository, which is about to make that rollout considerably more legible — and one product is answerable to three frameworks with three theories of what it is.
That is not obviously bad, but it has a cost buyers should price in. Compliance capacity is finite, and the Apple approach of delaying an EU launch rather than resolving the regulatory position is a live option for vendors with less at stake in Europe than OpenAI. Expect more feature delays in EU tenants, and treat “available in the EU” as a real differentiator when you compare ChatGPT, Gemini and Perplexity rather than assuming parity.
The contrast with the United States remains stark. Where the White House framework was completed but never published, the EU’s method is to publish the obligation, name the service and start a clock. It is slower and noisier. It also produces documents.
The part that is genuinely useful to you
Most regulatory news for AI buyers is overhead. This one has an unusual property: it manufactures evidence.
From January 2027, one of the assistants on your shortlist will be producing an annual systemic risk assessment and an independently audited opinion on it, on a published schedule, enforceable at 6% of turnover. Nothing comparable exists for any other AI vendor. Today, the honest answer to “how do we know this model is safe enough for our customer-facing use case?” is a vendor blog post and a benchmark card — the same evidentiary problem behind how thin AI security assurances have proven under adversarial testing.
So the practical move is not to change tools. It is to change what you ask for:
- Put the DSA artefacts on your renewal checklist now. Ask OpenAI’s account team, in writing, for the systemic risk assessment and audit report when published, and note the January 2027 date in your vendor review calendar.
- Ask the scoping question directly. “Does your DSA risk assessment cover the assistant as a whole or only ChatGPT search?” The answer tells you what the audit will actually have examined — and a vendor that cannot answer has not finished deciding.
- Do not conflate the regimes. AI Act transparency and DSA systemic risk are separate asks with separate documents. Request both by name.
- Re-check EU availability on your shortlist. Compliance load falls unevenly; Perplexity against ChatGPT and the best AI chatbots guide are the places to sanity-check whether your second choice is actually shippable in your jurisdiction.
- If you are consumer-facing in the EU, check your own numbers. DSA designation is triggered by your published user counts, not by anyone’s opinion of your risk profile.
Honest caveats
The compliance deadline is reported inconsistently. The Commission’s own announcement says four months, “i.e. by January 2027”. Secondary coverage has variously rendered this as 31 December 2026 and 31 January 2027, which reflects uncertainty about the notification date rather than the rule. Use the Commission’s wording and confirm the exact date from the designation decision when it publishes.
The scoping argument set out above is this site’s reading, not a Commission finding. The Commission has not said the designation covers the assistant in full, and OpenAI has not said it does not. Both statements are consistent with either outcome. Treat the question as open.
Designation is not a finding of wrongdoing. It is a size threshold. Nothing in Monday’s decision alleges that ChatGPT has caused any of the harms the DSA lists.
Obligations on paper are not obligations in practice. The DSA’s audit and researcher-access provisions have a mixed record on the platforms designated in 2023, and there is no reason to assume the first year of a novel service type will go more smoothly.
Frequently asked questions
Does this change anything about how I use ChatGPT today?
Nothing changes this week, and probably nothing changes visibly this year. The DSA gives a newly designated service four months from notification to come into compliance, which the Commission's own announcement puts at January 2027. What arrives after that is mostly paperwork and plumbing rather than product change: an annual systemic risk assessment, an independent third-party audit of that assessment, a mechanism for vetted researchers to request data, transparency about how results are ranked, and a repository of advertisements shown on the service. If you are an ordinary user, the most likely visible consequences are more granular controls somewhere in settings and clearer labelling around sponsored content. The reason to care now is not user experience. It is that the compliance artefacts this produces are documents you can cite in your own vendor file, and they will exist on a published schedule for the first time.
We build on the OpenAI API, not ChatGPT. Are we affected?
Not directly, and that distinction is worth holding onto because it is where most confusion about this story will come from. The DSA regulates intermediary services offered to recipients in the EU — the ChatGPT product with its EU user base — not the model weights or the developer API underneath it. Designation does not impose DSA obligations on your application because you call GPT-5.6 over HTTPS. Where it reaches you is indirect and mostly favourable: OpenAI's risk assessments, audit reports and transparency reporting become public artefacts about the safety properties of a system you depend on, which is materially better evidence than a marketing page. If your own product is a consumer-facing service in the EU, your DSA exposure is assessed on your own user numbers and your own service, not inherited from your model vendor. Your AI Act obligations are a separate question with a separate answer.
Why a search engine? ChatGPT does not look like Google.
Because the DSA defines an online search engine by what it does rather than by what it resembles: a service that allows users to input queries and returns results in any format on any subject. The Commission's reasoning for ChatGPT is that it answers prompts and queries, including by searching the web, which fits that functional definition even though the interface is a conversation. The classification also has a practical logic. The alternative category, Very Large Online Platform, applies to services that store and disseminate information at the request of users to the public — which describes Reddit and Roblox, both designated as VLOPs in the same decisions, and does not describe a private chat session. A generative assistant is genuinely awkward under a regime written in 2022 for content intermediaries, and search engine is the least-bad fit rather than a natural one. That awkwardness is why the scoping question in this article is live rather than pedantic.
Will Claude, Gemini and Perplexity be designated next?
Some of them almost certainly will, and the mechanism is worth understanding because it is self-reported. Under the DSA, services publish their average monthly active recipients in the EU at least every six months; the Commission designates once that published figure crosses 45 million. So the question is not whether a regulator notices you but whether your own disclosure crosses the line. Gemini's exposure is complicated by its distribution inside Google products, several of which are already designated. Perplexity is functionally the closest thing to a search engine in the field and the most obviously in scope on the merits, but it is the user count that decides, not the resemblance. Claude's consumer footprint in the EU is smaller and is the least likely of the three to cross soon. The strategic reading for a buyer is that designation status will become an uneven patchwork across your vendor list for reasons that have little to do with product risk — so do not read a designation as a warning label, or its absence as a clean bill of health.
How does this interact with the EU AI Act obligations that went live in August?
They are separate regimes with separate regulators, separate triggers and separate penalties, and they now both apply to the same product. Article 50 of the AI Act became applicable on 2 August 2026 and governs transparency: machine-readable marking of synthetic output and disclosure when AI-generated text is published to inform the public. The DSA governs systemic risk in how a large service is designed and operated, and is enforced by the Commission directly with fines up to 6% of global annual turnover. Nothing in one satisfies the other. For a compliance team the practical consequence is that the AI feature you approved once now sits under two frameworks whose obligations were drafted by different people for different harms, and the vendor documentation that answers one will not answer the other. Ask for both explicitly. A vendor that offers a DSA transparency report when you asked about Article 50 marking is not being evasive — the two really are unrelated, and that is the problem.
Sources
- European Commission — Commission designates ChatGPT, Reddit, Roblox under Digital Services Act (31 August 2026)
- European Commission press corner — IP/26/1772, Commission designates ChatGPT, Reddit, Roblox under the Digital Services Act
- European Commission — Supervision of the designated very large online platforms and search engines under the DSA (current list)
- PYMNTS — ChatGPT faces greater regulatory oversight by EU (Virkkunen and OpenAI statements, 31 August 2026)
- Gizmodo — The EU has officially decided ChatGPT is a search engine (31 August 2026)
- Crypto Briefing — ChatGPT faces tougher rules under EU online safety regime (obligations, EU user figures)
- Cybersecurity News — EU designates ChatGPT as Very Large Online Search Engine after crossing 45 million users
- Crowdfund Insider — EU says ChatGPT, Reddit and Roblox now fall under DSA regulation (31 August 2026)
Related tool reviews
Questions or corrections? Email Pick Right. Want the full list? See all news.