The European Commission has formally designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the European Union’s Digital Services Act (DSA).
The decision, announced on 31 August 2026, places ChatGPT in the DSA’s most demanding regulatory category for online search services. It also marks a significant moment for artificial intelligence regulation because ChatGPT is the first AI chatbot to receive a VLOSE designation.
At the same time, the European Commission designated Reddit and Roblox as Very Large Online Platforms (VLOPs). All three services crossed the EU’s user threshold for enhanced supervision.
The decision could become an important precedent for how regulators classify AI systems that increasingly combine conversational interfaces, information retrieval, web search and algorithmic presentation.
For OpenAI, the designation means more than additional paperwork. It brings ChatGPT’s search functionality into a regulatory framework built around systemic risk, transparency, independent auditing, researcher access and accountability.
What the EU has actually designated
There is an important distinction in the Commission’s announcement.
The EU has designated ChatGPT as a Very Large Online Search Engine, rather than classifying the entire ChatGPT service as a Very Large Online Platform.
That distinction matters.
Under the DSA, a VLOSE is an online search engine that reaches the required scale in the European Union. The DSA uses the concept of average monthly active recipients to determine whether a service crosses the threshold.
The threshold is 45 million average monthly active recipients in the EU. That figure represents roughly 10% of the EU population used by the DSA framework when establishing the very-large-service category.
OpenAI reported that ChatGPT Search had approximately 159.1 million average monthly active recipients in the EU during the six-month period ending 31 March 2026.
That is more than three times the regulatory threshold.
However, the number should be interpreted carefully. OpenAI specifically says the 159.1 million figure relates to ChatGPT Search and its online search features. It was calculated for DSA compliance purposes and should not automatically be interpreted as the number of unique people using the entire ChatGPT service every month.
That distinction is likely to become increasingly important as AI assistants blur the boundary between chatbot, search engine and digital platform.
Why ChatGPT qualifies as a VLOSE
Traditional search engines primarily retrieve and rank information from the web.
Generative AI systems can perform a more complex sequence.
A user asks a question. The system can interpret the intent, retrieve information, process multiple sources, generate an answer and present that answer conversationally.
ChatGPT Search increasingly operates in that space.
The DSA’s definition of an active recipient of an online search engine focuses on users who submit queries and are exposed to information indexed and presented through the service.
That makes the classification particularly significant.
The EU is not simply looking at whether a service calls itself a chatbot or search engine. It is looking at what the service does and the scale at which people use it.
This creates an important regulatory precedent.
An AI interface does not necessarily remain outside search regulation simply because its output is generated rather than displayed as a conventional list of blue links.
ChatGPT EU Digital Services Act obligations begin to matter
The designation brings ChatGPT under the enhanced obligations that apply to VLOPs and VLOSEs.
The European Commission says designated services have four months following notification of designation to comply with the additional obligations. For the 31 August designation, the Commission’s English announcement specifies the end of November 2026.
Among the most important requirements is the obligation to identify, analyse and mitigate systemic risks.
These risks extend well beyond conventional content moderation.
They include:
- dissemination of illegal content;
- risks to fundamental rights;
- risks involving children and minors;
- threats to physical and mental wellbeing;
- risks associated with electoral processes;
- threats to public security;
- discrimination and related societal harms;
- risks arising from algorithmic and recommender systems.
The Commission says VLOPs and VLOSEs must put appropriate mitigation measures in place after identifying these risks. Those measures can involve changes to the design or operation of services, algorithmic systems and internal processes.
For an AI service, this potentially makes the risk-assessment exercise considerably more complicated than traditional platform moderation.
The systemic-risk question is particularly important for AI
AI systems introduce risks that do not map neatly onto conventional social-media moderation.
Consider a user asking ChatGPT for information about an election.
The risk may not simply involve illegal content.
It can involve:
- inaccurate information;
- outdated information;
- misleading summaries;
- source selection;
- ranking and retrieval;
- algorithmic amplification;
- political persuasion;
- presentation of competing viewpoints;
- the confidence with which an answer is generated.
Similarly, a health-related question can raise questions about accuracy, user vulnerability and potential physical harm.
A question from a minor can introduce another layer of risk involving age, safety and appropriate responses.
This is where the ChatGPT designation becomes particularly consequential.
The EU is effectively asking whether an AI system operating at enormous scale can identify and mitigate risks arising not only from what users submit, but also from how the system retrieves, processes and presents information.
That is a substantially broader regulatory challenge.
Independent audits will add another layer of scrutiny
The DSA does not rely entirely on companies assessing themselves.
VLOPs and VLOSEs must undergo independent compliance audits at least once a year. The audits are conducted at the provider’s expense and examine compliance with the applicable DSA obligations.
The audit framework also requires providers to address recommendations made by auditors.
In addition, designated services must publish relevant risk-assessment and audit information under the DSA’s transparency framework. The European Commission says providers must publish reports covering their risk assessments, mitigation measures, audit reports and audit implementation reports.
For OpenAI, this creates a continuing compliance cycle rather than a one-time regulatory exercise.
Risk assessments must be conducted at least annually.
The DSA framework also requires assessment before deploying new functionalities when those functionalities are likely to have an impact on systemic risks.
That could become especially relevant to rapidly evolving AI products.
AI services can introduce new models, agents, search capabilities, voice features, multimodal functionality and other capabilities much faster than traditional internet services typically change.
The regulatory question therefore becomes dynamic.
Can an AI company demonstrate that its risk-management systems keep pace with the speed of product development?
Data access and researcher scrutiny
The VLOSE regime also increases the amount of information that regulators and researchers can potentially examine.
Designated services must provide data to the European Commission and relevant national authorities for regulatory monitoring.
They must also provide access to certain data for vetted researchers whose work contributes to understanding systemic risks in the EU.
This could be particularly significant for AI.
Researchers may want to investigate questions such as:
- How often does an AI search system provide incorrect information?
- How does it select sources?
- Does it systematically favour particular types of sources?
- How does its behaviour change across languages?
- How does it handle politically sensitive queries?
- How does it respond to minors?
- What safeguards operate when users seek potentially harmful information?
- How do changes to models or search systems affect systemic risks?
The DSA therefore moves the debate beyond conventional questions about content moderation.
It creates a regulatory framework for examining how large digital information systems influence users and society.
Reddit and Roblox join the VLOP regime
ChatGPT is not alone in receiving a new designation.
The Commission simultaneously designated Reddit and Roblox as Very Large Online Platforms. Both companies reported reaching at least the 45-million-user threshold in the EU.
The three services, however, represent very different digital ecosystems.
Reddit is a large discussion and content-sharing platform.
Roblox combines user-generated content, social interaction and an enormous gaming ecosystem.
ChatGPT is primarily a conversational AI system, with search capabilities that increasingly make it an information gateway.
The simultaneous designations therefore demonstrate the breadth of the DSA’s approach.
The regulation is not limited to traditional social networks.
It applies enhanced obligations to digital services once they reach a scale where their potential effects can become systemic.
ChatGPT EU Digital Services Act changes the regulatory conversation around AI
The most important consequence may not be the compliance deadline.
It may be the precedent.
For years, the technology industry has treated AI assistants as a distinct category from search engines and social platforms.
But the boundaries are rapidly disappearing.
Google integrates generative AI into search.
Microsoft integrates AI into productivity and search experiences.
OpenAI combines conversational AI with web search.
Other AI companies are developing agents that can retrieve information, interact with websites, make recommendations and perform actions on behalf of users.
The old distinction between search engine, chatbot and platform is becoming increasingly difficult to maintain.
The European Commission’s decision suggests that regulators are prepared to look at the functional reality of these services rather than relying solely on product labels.
Why the November deadline matters
The end-November deadline gives OpenAI, Reddit and Roblox a relatively short period to complete the additional compliance work required by their new status.
This involves more than writing a risk report.
The companies must establish systems capable of identifying systemic risks, implementing mitigation measures, maintaining appropriate compliance functions and preparing for independent auditing.
For OpenAI, that could involve examining the interaction between its models and its search infrastructure.
The company may need to demonstrate how risks are identified across the search experience, how mitigation measures work and how those measures are monitored over time.
The scale of the task should not be underestimated.
AI systems are probabilistic and continuously evolving. Their behaviour can also depend on model versions, system instructions, retrieval systems, external sources and user prompts.
Regulatory compliance therefore has to operate across a technology stack rather than a single moderation layer.
The financial risk is substantial
The DSA gives the European Commission significant enforcement powers.
Where the Commission establishes a breach, it can impose a fine of up to 6% of a provider’s global annual turnover. The actual penalty depends on factors including the nature, gravity, recurrence and duration of the infringement.
That maximum is not an automatic penalty for missing a deadline.
It is the upper limit available under the DSA for relevant non-compliance decisions.
The distinction matters because regulatory headlines can sometimes make the 6% figure sound like an immediate penalty.
It is not.
The Commission must establish non-compliance and follow the applicable enforcement process.
Nevertheless, the potential scale of the sanction makes DSA compliance a board-level issue for large technology companies.
The Commission has already demonstrated that DSA enforcement can result in major financial penalties. In May 2026, it fined Temu €200 million for breaching DSA obligations related to systemic risks involving illegal products.
That provides a useful indication of how seriously the Commission is approaching the regime.
What this means for enterprise AI
The implications extend beyond consumer ChatGPT.
Enterprises increasingly use generative AI for:
- research;
- customer service;
- employee assistance;
- knowledge management;
- software development;
- content generation;
- market intelligence;
- decision support.
If AI systems become major gateways to information, businesses will also need to pay greater attention to provenance, accuracy, governance, safety and regulatory exposure.
The EU’s approach could influence enterprise procurement decisions.
Companies may increasingly ask AI vendors to demonstrate:
- how systemic risks are assessed;
- how AI-generated information is validated;
- how high-risk use cases are monitored;
- how minors and vulnerable users are protected;
- how model changes are governed;
- how independent assurance is performed;
- how regulators and researchers can obtain relevant information.
This could push AI governance from a largely internal technology function into a broader enterprise risk-management discipline.
What happens next
The immediate priority for OpenAI, Reddit and Roblox is compliance with the enhanced VLOP/VLOSE framework by the end of November.
But the bigger story will unfold over the following years.
The Commission will have the ability to scrutinise how designated services manage systemic risks. It can request information, conduct investigations and impose penalties where violations are established.
For ChatGPT, the most closely watched areas are likely to include search accuracy, information quality, fundamental rights, minors, elections, public security and the broader societal impact of AI-generated information.
The designation could also influence how other AI companies structure their products.
If an AI assistant combines conversational generation with web search and reaches tens of millions of European users, the regulatory precedent established here becomes highly relevant.

A turning point for AI regulation
The ChatGPT EU Digital Services Act designation represents a broader shift in the relationship between AI and digital regulation.
ChatGPT is no longer being viewed only as an AI assistant.
At massive scale, its search functionality can become part of the information infrastructure through which people discover, interpret and consume information.
That creates responsibilities.
The EU’s decision does not mean ChatGPT has been found to violate the DSA. Nor does VLOSE status mean that the service is inherently unsafe.
It means that the European Commission considers its scale and functionality sufficient to warrant the DSA’s highest level of systemic oversight for online search services.
That distinction is critical.
The real test now begins.
OpenAI will have to demonstrate that its rapidly evolving AI and search systems can be governed with the transparency, risk management and accountability expected of infrastructure capable of influencing information consumption at European scale.
And for the technology industry, the message is clear:
AI may have started as software. At sufficient scale, regulators are beginning to treat it as infrastructure.
Key facts at a glance
| Item | Detail |
|---|---|
| Regulator | European Commission |
| Regulation | Digital Services Act (DSA) |
| ChatGPT classification | Very Large Online Search Engine (VLOSE) |
| ChatGPT EU Search recipients | Approx. 159.1 million average monthly |
| Measurement period | Six months ending 31 March 2026 |
| VLOSE threshold | 45 million average monthly active recipients |
| Other new designations | Reddit and Roblox as VLOPs |
| Designation date | 31 August 2026 |
| Compliance deadline | End of November 2026 |
| Major obligations | Systemic-risk assessment, mitigation, audits, data access and transparency |
| Maximum DSA fine | Up to 6% of global annual turnover |

