On August 31, the European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act. Reddit and Roblox were designated Very Large Online Platforms on the same day. It is the first time an AI assistant has been placed in the DSA's top enforcement tier, and OpenAI has roughly four months — until the end of December — to comply.
The threshold that triggered it is a number OpenAI disclosed itself: approximately 159.1 million average monthly active recipients in the EU for ChatGPT's search functionality over the six months ending March 31, 2026. The DSA's bar is 45 million. ChatGPT cleared it more than three times over.
Most coverage led with the penalty exposure — fines up to 6% of global annual revenue. That is the least interesting part of the story.
"The fine is the enforcement mechanism, not the substance," says Hassan Taher, an AI analyst and author who advises organizations on enterprise AI strategy. "The substance is that a regulator looked at a conversational AI product and concluded that what it functionally is, for legal purposes, is a search engine — an intermediary that stands between hundreds of millions of Europeans and the information they act on. That classification carries a set of duties that were written for a different technology and now apply to this one, and the interesting question is which of those duties an AI assistant can actually discharge."
What ChatGPT Now Has to Do
The VLOSE obligations are specific. OpenAI must identify, assess, and mitigate systemic risks arising from the service and its algorithmic systems, covering illegal content, effects on minors, physical and mental well-being, fundamental rights, electoral processes, and public security. It must submit to independent annual audits and respond to auditor recommendations. It must share data with the Commission and national authorities. It must give vetted researchers access to platform data for systemic-risk research. Where applicable, it must offer a recommender option not based on profiling, and maintain a public advertising repository if it displays ads.
Two of those are straightforward for a company of OpenAI's size. Auditing and regulator data-sharing are expensive but well-trodden. The others are harder in ways that are specific to how generative systems work.
Vetted researcher access is the clearest example. When the DSA drafters wrote that provision, they were imagining researchers querying a recommendation system — what content was amplified, to whom, how often. A feed has an inventory of items and a ranking over them, both of which can be sampled and studied. A generative model has no inventory. The output is produced at request time and never existed before. Giving a researcher meaningful access to study systemic risk in that system means giving them something closer to model access, evaluation infrastructure, and logs of real interactions — and the last of those collides directly with the privacy obligations OpenAI holds under other European law.
The non-profiling recommender option raises a subtler version of the same problem. In a feed, personalization is a layer you can switch off, and underneath it sits a chronological alternative. In a conversational assistant, personalization is increasingly woven into memory, context, and prior interactions. "Turn off profiling" does not have an obvious chronological fallback. It has to be designed.
The Two-Regulator Problem
The designation does not replace or overlap with the EU AI Act. They are separate instruments, with separate obligations, separate enforcement bodies, and separate timelines. OpenAI's position under the AI Act as a provider of a general-purpose model with systemic risk is unchanged by what happened on August 31. It now runs two parallel compliance programs against two regulators applying two different theories of what the product is.
Under the AI Act, ChatGPT is a model — governed at the level of training, documentation, evaluation, and systemic capability. Under the DSA, ChatGPT is an intermediary — governed at the level of what reaches users, how it is ranked, and what harms flow from distribution. Those are not contradictory framings, but they are genuinely different, and they generate obligations that can pull in opposite directions. Model-level transparency argues for disclosure; intermediary-level risk mitigation sometimes argues for restriction.
"This is the shape of AI regulation for the next several years, and I think it is underappreciated," Taher notes. "The debate has been framed as whether to regulate AI, as though a single instrument would arrive and settle the question. What is actually happening is that AI products are being absorbed into every existing regulatory regime they touch — platform law, consumer protection, medical devices, financial services, employment law — while AI-specific law develops alongside. A company shipping one product ends up defending it under four bodies of law that were never reconciled with each other." Taher has examined a narrower version of that problem in the AI-WISE Act and the small-business knowledge gap it tries to close, where the burden of overlapping rules falls hardest on the organizations least equipped to interpret them.
Why "Search Engine" Is the Right Call, Uncomfortably
There is an argument that the classification is a category error — that a chatbot is not a search engine and the Commission stretched the definition to reach a target it wanted to regulate.
The stronger argument runs the other way. A meaningful share of what people use ChatGPT for is what they previously used search for: finding out what is true, what happened, what to buy, what to do. That substitution has been visible for a while — Hassan Taher was writing about SearchGPT's role in transforming online search well before regulators reached for a classification. The distinction that matters legally is not the interface but the function — whether the service stands between a population and its information supply, and whether the way it selects and presents information can systematically shape what that population believes and does. On that test, the designation is not a stretch. If anything, it is overdue.
What makes it uncomfortable is the accountability asymmetry. A search engine returns links to sources that exist independently and can be inspected, challenged, and corrected at the source. A generative assistant returns a synthesis with no author, no publication date, and often no traceable provenance. When a search engine ranks a bad source highly, the harm is attributable and the remedy is legible. When a model produces a confident wrong answer, there is nothing to demote. The discipline growing up around this shift has its own name and its own emerging practice, which Hassan Taher has explained in his account of GEO and the new era of search.
That gap is the systemic risk the DSA is now going to force someone to quantify — and nobody, including the labs, currently has a good methodology for it.
What It Means for Everyone Else
Three implications extend well beyond OpenAI.
First, the 45-million threshold is not high. Any AI assistant that achieves consumer scale in Europe will cross it. The designation is a template, and the next several companies to reach it will be designated faster because the analysis has now been done once.
Second, the obligations are functional, not sectoral. They attach to what a service does — intermediating information at scale — rather than to what industry it claims to be in. Enterprises embedding AI assistants into consumer-facing products should not assume that being "an AI company" or "not a platform" is a defense. The question a regulator will ask is how many people receive information through the system and what happens when that information is wrong.
Third, the auditability requirement is going to become a procurement question. Independent annual audits of algorithmic systems require that the systems produce evidence an auditor can examine: logged decisions, versioned models, documented evaluations, records of what changed and why. Most AI deployments in production today cannot produce that record, because it was never built. Organizations that treat observability as an engineering nicety will find it reclassified as a legal prerequisite.
"The compliance clock here is four months, which for a company like OpenAI is aggressive but survivable," Taher says. "The deeper cost is architectural. You cannot bolt auditability onto a system that was not instrumented for it, and you cannot answer a regulator's question about systemic risk with a system that keeps no record of what it did. The organizations that come through this era intact will be the ones that decided, before anyone required it, that they wanted to be able to explain their own systems."
This article discusses regulatory developments for informational purposes. It is general commentary, not legal advice; organizations assessing their own obligations should consult qualified counsel.
Sources:
- Commission designates ChatGPT, Reddit, Roblox under Digital Services Act — European Commission
- ChatGPT Is Now A "Very Large Online Search Engine" In The EU — Search Engine Journal
- EU Designates ChatGPT as First AI Chatbot "Very Large Online Search Engine" Under DSA — TechJack Solutions
- EU Now Regulates ChatGPT as a Very Large Online Search Engine — WinBuzzer
