ChatGPT Is Now an EU “Search Engine”: What the DSA’s VLOSE Rules Mean for AI Tools
📑 Table of Contents
- Introduction: A Chatbot Walks Into a Search-Engine Rulebook
- What Actually Happened on August 31
- VLOSE 101: The DSA’s Toughest Tier, Explained
- The Obligations ChatGPT Now Inherits
- The AI Act Interplay: Why This Echoes Beyond the DSA
- What It Means for Every AI Tool With Web Access
- The Timeline: What to Watch Through January 2027
- Frequently Asked Questions
Introduction: A Chatbot Walks Into a Search-Rulebook
For two years, the AI industry’s regulatory anxiety has focused on the EU AI Act — a framework written, debated, and refined with frontier models in mind. Then, on August 31, 2026, the European Commission quietly did something arguably more consequential than anything in the AI Act’s first wave: it designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the Digital Services Act.
The classification hit like a riddle. ChatGPT is a chatbot, not a search box — right? Not under Brussels’ reading. Because ChatGPT “can engage with and respond to users’ prompts and queries, including by searching the web,” the Commission classified it as a hybrid service that qualifies as an online search engine. Once OpenAI’s own declarations confirmed it serves at least 45 million average monthly EU users (by some counts, 159.1 million), the designation became automatic under the DSA’s thresholds.
The upshot: the world’s most widely used AI chatbot is now subject to the same systemic-risk regime that governs Google Search and Bing — annual risk assessments, independent audits, data-sharing with researchers and regulators, and a compliance clock that runs out in roughly four months. If you build, deploy, or just choose AI tools for your company, this decision redraws the compliance map well beyond OpenAI.
What Actually Happened on August 31
The Commission’s designation notice (press release IP/26/1772) named three services in one stroke: ChatGPT as a VLOSE, and Reddit and Roblox as Very Large Online Platforms. All three had declared EU user numbers crossing the 45-million threshold that triggers the DSA’s highest tier of obligations.
Each service gets four months from notification to comply. The Commission’s own calendar references have been inconsistently reported — some pages say “by January 2027,” others hint at end of November — a discrepancy legal commentators were quick to flag. The operative rule is unambiguous, though: four months after notification, the full VLOSE duty set applies.
National regulator assignments landed alongside the designations: Ireland’s Coimisiún na Meán oversees OpenAI and Reddit, while the Netherlands handles Roblox. Ireland has become, in effect, the EU’s AI company regulator — a familiar pattern for anyone who watched GDPR enforcement cluster around the Irish DPC.
VLOSE 101: The DSA’s Toughest Tier, Explained
The Digital Services Act, fully in force since 2024, scales obligations with size and societal risk. The categories most relevant here:
- Online search engine: a service that allows general searches based on queries on keywords, returning results ranked by relevance or other criteria.
- VLOSE: a search engine averaging 45+ million monthly EU users — subject to the DSA’s systemic-risk chapter.
- VLOP: the platform equivalent — Reddit and Roblox’s new designation.
ChatGPT’s “hybrid” nature was the crux. It is conversational, yes — but its web-browsing capability means it retrieves, synthesizes, and effectively ranks information in response to user queries. To the Commission, that functional reality matters more than the product category label. It’s a precedent with teeth: any AI assistant with meaningful web access and EU scale can plausibly be swept into the same bucket. Perplexity, Gemini, Copilot — none were named this time, but none are obviously out of scope next time.
The Obligations ChatGPT Now Inherits
VLOSE status isn’t a label; it’s a work program. Within the compliance window, OpenAI must stand up:
- Annual systemic-risk assessments covering illegal content dissemination, protection of minors, users’ physical and mental well-being, fundamental rights, electoral processes, and public security — specifically as these relate to ChatGPT’s algorithmic systems, including recommender behavior and content moderation.
- Independent audits: at least yearly, by auditors empowered to examine data and systems, with audit reports made available to the Commission and member-state authorities.
- Transparency measures: clear notice about recommender system main parameters, and data access for vetted researchers.
- Risk mitigation duties: identifying and implementing mitigations for risks surfaced — think hallucinated legal or medical guidance, minors’ exposure, or election-related misinformation surfacing through AI answers.
The penalties for missing the bar are steep: the DSA allows fines up to 6% of global annual turnover.
The AI Act Interplay: Why This Echoes Beyond the DSA
Here’s the part AI tool builders should underline. Recital 118 of the AI Act provides a presumption of compliance: where an AI system is integrated into a VLOSE, meeting the DSA’s risk-management requirements is generally considered sufficient to satisfy the AI Act’s corresponding obligations — provided no additional risks outside the DSA’s scope emerge.
In practice, the VLOSE designation converts the DSA into OpenAI’s primary compliance surface for ChatGPT in the EU — effectively substituting for chunks of the AI Act’s transparency regime for this product. That is a genuinely novel regulatory architecture: platform law absorbing AI law, category by category. Legal teams across the industry are now re-reading their AI Act gap analyses with the DSA open beside them.
There’s a catch, though. Article 50(2) of the AI Act still independently requires disclosure that users are interacting with an AI system. The DSA presumption doesn’t extinguish obligations that fall outside its scope — it just narrows the overlap.
What It Means for Every AI Tool With Web Access
The designation’s ripple effects reach far further than one company. Four practical takeaways:
- The 45-million line is now a compliance tripwire. Any AI assistant with EU reach and web-grounded answers should be tracking monthly active EU users against the DSA threshold, not just the AI Act’s risk tiers.
- Hybrid services can’t pick their category. Brussels classified by function, not form. If your tool searches, synthesizes, and ranks — even conversationally — the search-engine frame is live.
- Systemic-risk language is becoming product language. Expect “risk assessment,” “audit trail,” and “researcher access” to appear in enterprise procurement checklists for AI tools, the way SOC 2 did for SaaS.
- It’s a layering game, not a substitution. The DSA, AI Act, and (soon) GPAI obligations stack. Tools that figure out the interplay early will win enterprise deals; those that don’t will discover it during due diligence.
If you’re weighing which AI assistant or search tool to standardize on, transparency practices are worth scoring now. Compare how Perplexity, Google Gemini, Microsoft Copilot, Grok, and Kagi handle source attribution, web-grounding, and editorial accountability — the same dimensions EU auditors will now be probing at OpenAI.
The Timeline: What to Watch Through January 2027
Mark three checkpoints. First, the compliance deadline itself — four months from notification, landing somewhere between end of November 2026 and January 2027 depending on which Commission calendar wins. Second, the first systemic-risk assessment: its scope and candor will set the template for every AI VLOSE that follows. Third, copycat designations: watch whether other web-grounded AI assistants get designated once their own user declarations cross the line — a signal Brussels intends to treat this as doctrine, not a one-off.
And keep one eye on how this interacts with the parallel AI regulatory drama of the season — the US pushing a hands-off approach while its own frontier models trigger “Critical” cybersecurity ratings. The EU just showed there’s a third way: skip the model-level debate entirely, and regulate the interface.
Frequently Asked Questions
Why is ChatGPT considered a search engine under the DSA?
The European Commission classified ChatGPT as a “hybrid service” that qualifies as an online search engine because it can respond to user queries by searching the web and returning synthesized, effectively ranked information. Functional capability — not the chatbot interface — drove the classification.
What does VLOSE status require OpenAI to do?
Annual systemic-risk assessments covering illegal content, minors, well-being, fundamental rights, elections, and public security; independent audits; transparency about recommender parameters; researcher data access; and mitigation of identified risks — all under threat of fines up to 6% of global turnover.
When is the compliance deadline?
Four months from notification of the August 31, 2026 designation. The Commission has inconsistently referenced “end of November 2026” and “January 2027” in public materials; the legal rule is the four-month interval, with January 2027 as the outer bound.
Could other AI chatbots get the same designation?
Yes. Any AI assistant with web-search capability and 45+ million average monthly EU users meets the designation threshold. The ChatGPT decision establishes the functional “search engine” reading that would apply to similar hybrid assistants.
How does the DSA designation interact with the EU AI Act?
AI Act Recital 118 creates a presumption of compliance: meeting the DSA’s risk-management requirements is generally deemed sufficient for the AI Act’s corresponding obligations when an AI system is integrated into a VLOSE — though duties outside the DSA’s scope, like Article 50(2) AI-disclosure, still apply independently.
Explore All AI Tools
Discover and compare 300+ AI tools on aitrove.ai — your trusted AI tool directory.
Browse All Tools →