The day ChatGPT became regulated as a search engine.
On August 31, 2026, the European Commission formally designated ChatGPT as a "Very Large Online Search Engine" (VLOSE) under the Digital Services Act. The trigger was a reported 159.1 million average monthly users in the EU, far above the 45 million designation threshold. For the first time, an AI chatbot now carries the same heavyweight obligations that previously applied only to Google Search and Microsoft Bing.
How the definition of
"search engine" swallowed ChatGPT
The Digital Services Act, in force since 2022, imposes heavier obligations on companies designated as "Very Large Online Platforms" (VLOPs) or "Very Large Online Search Engines" (VLOSEs). The bar is simple: an average of 45 million monthly users in the EU. Until now, only two services had ever crossed it as search engines: Google Search and Microsoft Bing.
What tipped ChatGPT over the line was its built-in web search capability. According to the European Commission's announcement, the classification rests on ChatGPT's ability to search the web and return results, not on how the product is marketed — a functional test rather than a category label. OpenAI itself reported roughly 159.1 million average monthly users in the EU, more than three times the threshold.
| A typical online service | ChatGPT, post-VLOSE |
|---|---|
| Systemic risk assessment: optional | Annual systemic risk assessment required |
| Ad practices can stay private | Must publish a public ad repository |
| No data access for outside researchers | Must give vetted researchers data access |
| No transparency reporting duty | Must file reports twice a year |
"These new designations mean that ChatGPT, Reddit and Roblox will now be held to a higher standard of scrutiny and accountability in the European Union, in line with their large impact on our citizens and society."
Four months of grace,
then the real obligations begin
From the date of notification, OpenAI gets a grace period to build the compliance machinery the DSA demands of its heaviest-regulated services.
Full compliance is expected by around January 2027, after which OpenAI must run annual systemic risk assessments, stand up a crisis-response mechanism, and formalize notice-and-action procedures. Non-compliance carries fines of up to 6% of global annual turnover — in the same league as other major tech regulations.
Who actually feels this
The weight of the rule falls mostly on the service provider. Day-to-day usage won't look different for a while.
Legal & compliance teams
Enterprises running ChatGPT Enterprise should watch OpenAI's compliance rollout — transparency reports and risk assessments in particular — and check it against their own data-governance policies.
Everyday users
Nothing changes visibly in a chat window. But the public ad repository and formalized notice-and-action rules feed back over time into clearer terms and more visible feature disclosures.
Competing AI services
Gemini, Claude, and Perplexity are all growing their EU user bases, and any that crosses 45 million faces the same test. This designation looks like the dry run for what comes next.
An era where "search" keeps getting redefined
Until now, VLOSE status belonged only to services that explicitly called themselves search engines. This designation establishes a precedent: a chat-first AI product can be treated as a search engine under EU law the moment it adds web search. The European Commission's press release frames this as the third-ever VLOSE designation, after Google Search and Bing — meaning AI vendors now have a new variable to plan around: search functionality itself can trigger heavyweight regulation.
For anyone deciding which AI tools to adopt at work, three practical takeaways follow. First, build a habit of checking the transparency reports and risk assessments that ChatGPT Enterprise and similar vendors will start publishing. Second, factor into vendor selection the likelihood that other AI services with integrated web search will eventually cross the same threshold. Third, don't over-read this as a quality signal — heavier regulation doesn't by itself mean a worse product.
Risks and open questions remain, though. DSA obligations are a real operational burden, and it's plausible that EU-facing features ship later, or in a more restricted form, as a result. It's also worth noting that the designation rests on OpenAI's own self-reported user figures — how that number is calculated, and whether it can be contested, is still worth watching.