ChatGPT Is Now Regulated as a Search Engine in the EU: What That Means for AI-Enabled Software

On 31st August 2026 it was announced that the European Commission designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act.

What Does This Actually Mean?

The DSA is the EU's general rulebook for online services, covering platforms, marketplaces and search engines. It was drafted before the current generation of AI products and is concerned with content, safety and transparency rather than with artificial intelligence. It applies to services on a tiered basis, so that the obligations become progressively heavier as a service grows, and the heaviest tier is reserved for services with at least 45 million average monthly users in the EU. That tier is divided between Very Large Online Platforms, which covers services such as social networks and marketplaces, and Very Large Online Search Engines, which until now has covered conventional web search.

A "designation" is a formal decision placing a named service within one of those categories. It is not a fine, a finding of wrongdoing or a criticism of how the service operates. What it does is switch on a defined set of obligations, together with direct supervision by the European Commission and the prospect of penalties of up to 6% of global annual turnover if those obligations are not met.

Rather than treating an AI assistant as something requiring a new classification, it looked at what the service does when a user asks it a question, concluded that retrieving and summarising live web results is functionally search, and applied the existing search engine rules accordingly.

The Commission concluded that an AI assistant which retrieves live results from the web performs the function of a search engine, and applied an existing regulation on that basis. That approach to classification is relevant to a great many businesses that would not describe themselves as platforms, and it gives a useful indication of how European regulators intend to handle AI products that do not fit neatly into the categories the law was drafted around.

What The Commission Decided

On 31st August 2026, the Commission designated ChatGPT as a Very Large Online Search Engine, and Reddit and Roblox as Very Large Online Platforms, under the Digital Services Act. Each service had declared that it reaches at least 45 million average monthly users in the EU, which is the threshold in Article 33 of the DSA that triggers designation. OpenAI reported approximately 159 million average monthly active recipients of ChatGPT search in the EU for the six months ending March 2026, which is more than three times the threshold.

The three services have four months from notification, so until January 2027, to meet the additional obligations that apply at this tier. Supervision sits with the Commission itself rather than with a national regulator alone, working alongside Ireland's Coimisiún na Meán as digital services coordinator for ChatGPT and Reddit, and the Netherlands' Authority for Consumers and Markets for Roblox.

What Does VLOSE Status Actually Require?

The obligations at this tier are considerably more demanding than the DSA's baseline rules, and most of them require operational change rather than documentation alone.

Designated services must carry out an annual systemic risk assessment addressing a defined group of harms. These include illegal material circulating on the service, harm to children, damage to the physical and mental health of users, interference with fundamental rights, distortion of public debate and elections, and threats to public security. They must assess how their content moderation, recommender and advertising systems contribute to each of those risks, put mitigation measures in place, and be able to demonstrate that those measures work. They then have to undergo an independent audit at least once a year and publish the audit report, together with an implementation report where the outcome is not positive.

The tier also requires at least one recommender option not based on profiling, a public repository of advertisements, data access for the Commission and national coordinators to assess compliance, data access for vetted researchers studying systemic risks, an internal compliance function staffed by designated compliance officers, transparency reporting on a more frequent cycle than smaller services, and payment of an annual supervisory fee towards the cost of Commission oversight. Non-compliance can attract fines of up to 6% of global annual turnover.

Why The Commission's Reasoning Matters Beyond OpenAI

In its reasoning, the Commission treated ChatGPT as a service with more than one character, and found that it meets the definition of an online search engine because part of what it does is take a user's query and go looking for material on the open web in order to answer it. The assessment turned on function rather than form. The product's own description of itself, and the novelty of the underlying technology, did not determine the outcome. What determined it was the role the service performs for the user.

The reasoning is therefore relevant well beyond this particular designation. European regulators are not waiting for AI-specific rules to mature before applying the rules that already exist, and if part of your product performs a function that EU law already regulates, whether that is search, hosting content your users provide, intermediating transactions between third parties or processing personal data, you should expect the existing regime to be applied to that function. How the product is described commercially is unlikely to be the deciding factor, and neither is the fact that the function is delivered through a model rather than through conventional software.

The designation also establishes a threshold that other providers will cross in the ordinary course of growth. Any consumer-facing assistant reaching 45 million monthly EU users enters this regime by default, which means that European launches for large AI products now involve DSA obligations as a design consideration rather than as a question to be addressed later.

How Seriously Is The DSA Being Enforced?

The DSA has now produced roughly €890 million in penalties, which suggests that designation carries practical consequences rather than reputational ones alone. X was fined €120 million in December 2025, the first penalty issued under the regulation, over deceptive interface design, gaps in its advertising repository and blocked researcher access. Temu was fined €200 million in May 2026 over systemic risk failures in its handling of illegal products. AliExpress received a €550 million penalty in July 2026 relating to illegal and counterfeit goods.

Two of those three penalties concerned failures of transparency infrastructure, meaning the advertising repository and researcher data access, rather than failures to remove harmful content. Those are the obligations that tend to look administrative and are most easily deprioritised by a company scaling quickly, and so far they are the ones the Commission has been most willing to penalise.

Does This Reach You If You Are Nowhere Near 45 Million Users?

The DSA has never been only a large platform regime. Its baseline obligations apply to intermediary services offered to users in the EU regardless of where the provider is established and regardless of size. If your product stores or transmits information provided by your customers or their end users, you may be a hosting service or an online platform under the DSA even though you would not describe yourself in those terms. Collaboration tools, marketplaces, community features, review functionality, file sharing and user-generated content of any kind can all bring a service within scope.

A provider established outside the EU that offers services to users there has to appoint a legal representative in a Member State and publish a single point of contact for authorities and for users. Hosting services need a notice and action mechanism and must give statements of reasons when they remove or restrict content. Micro and small enterprises are exempt from several of the online platform obligations but not from the intermediary and hosting layer, and that exemption falls away as a business grows. These requirements are relatively inexpensive to put in place early and considerably more awkward to retrofit under regulatory pressure.

It is worth mentioning that using ChatGPT or its API does not make you a VLOSE, and designation attaches to OpenAI rather than to its customers. You should nonetheless expect downstream consequences over the coming months, including revised contract terms, additional logging and monitoring requirements passed on to you, stronger safeguards around particular categories of use, and possibly restrictions on use cases that are currently available. A US SaaS provider that has built a customer-facing feature on a third-party assistant may find the behaviour of that feature changing in Europe for reasons that sit entirely outside its own control.

Where Does The DSA Now Overlap With The AI Act?

The designation came a month after the AI Act's transparency rules started to apply. From 2 August 2026, chatbots and other interactive AI systems have to tell users they are dealing with AI rather than a person, deepfakes have to be labelled, and AI-generated or altered content has to carry machine-readable marks so that it can be detected as synthetic. The Commission's AI Office and national authorities began enforcing the AI Act on the same date, including the obligations that apply to providers of general-purpose AI models.

The practical result is that a single feature can give rise to two separate compliance conversations with two different regulators. The AI Act asks whether users know they are dealing with AI and whether synthetic content is marked. The DSA asks what systemic risks the service creates at scale and what is being done to reduce them. A single answer touching on an election could engage AI Act transparency obligations and DSA risk mitigation obligations at the same time, through entirely separate legal routes.

This has organisational consequences as well as legal ones. Where AI transparency work sits with the product team and content risk work sits with trust and safety, the two functions will need to coordinate, because the same feature now falls within both regimes.

It is also worth keeping EU-level and national supervision separate in your planning. Both the DSA and the AI Act are regulations that apply directly across the EU without national transposition, but enforcement is shared with national authorities. In France, Arcom is the Digital Services Coordinator, with the CNIL holding competence over provisions concerning advertising and profiling and the DGCCRF over marketplace and trader traceability provisions. Selling into several Member States can therefore involve dealing with several regulators even where the underlying rules are identical, and the practical experience of being supervised in France will not be the same as in Ireland or the Netherlands.

What To Check Now

The first question is whether any part of your service is an intermediary or hosting service under the DSA, because the answer determines everything that follows and a considerable number of software businesses have never examined it. If the answer is yes, or possibly yes, the next questions are whether you have appointed a legal representative in a Member State, published a point of contact, and built a workable notice and action mechanism.

The second is how your AI features sit against the transparency rules that took effect on 2nd August 2026, particularly anything that generates text, images, audio or video that a reasonable user might take to be human-produced. Machine-readable marking is a technical requirement that has to be built into the product rather than described in your terms of use.

The third concerns your suppliers. It is worth asking your AI vendors directly what their EU regulatory status is, what changes they anticipate before January 2027, and whether your contract permits them to alter model behaviour, restrict use cases or change output filtering without notifying you. A vendor's compliance programme can change what your product does in front of your own customers, and it is more manageable to plan for that in advance than to respond to it after the fact.

Where a service sits near any of these boundaries, and particularly where it combines user-generated content with an AI layer, it is worth taking advice on classification before building a compliance programme around an assumption. Classification is carrying a great deal of weight under both regimes, and the Commission has now applied these categories to a service that its own developers would have described differently.

How Can Gerrish Legal Help?

Gerrish Legal is a dynamic digital law firm. We pride ourselves on giving high-quality and expert legal advice to our valued clients. We specialise in many aspects of digital law such as GDPR, data privacy, digital and technology law, commercial law, and intellectual property. 

We give companies the support they need to successfully and confidently run their businesses whilst complying with legal regulations without the burdens of keeping up with ever-changing digital requirements. 

We are here to help you, get in contact with us today for more information.


Next
Next

GDPR vs the EU AI Act: Why Compliance With One Doesn't Mean Compliance With the Other