On August 31, 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the Digital Services Act, the first time a generative-AI chatbot has been pulled into the DSA's tier for the largest platforms and search engines. Reddit and Roblox were designated at the same time as Very Large Online Platforms (VLOPs). The designation does not treat ChatGPT as an AI chatbot for regulatory purposes; it treats ChatGPT's live web-search function as a search engine, and that distinction is doing most of the legal work in this story.
What the Digital Services Act actually does
The Digital Services Act is the EU's core rulebook for online intermediaries, in force since 2024 and applying to everything from small forums to the largest platforms operating in the bloc. Every covered service carries baseline obligations around illegal content takedown, transparency and user redress. A second, heavier tier sits on top of that baseline: any online platform or search engine that reaches an average of 45 million monthly active recipients in the EU, roughly 10% of the EU population, over a six-month period is designated a Very Large Online Platform or Very Large Online Search Engine. That threshold, not the nature of the service, is what triggers the extra obligations.
The Commission's own numbers show why ChatGPT crossed that line by a wide margin. Its search function reached an average of about 159.1 million monthly active recipients in the EU over the six months ending March 31, 2026, more than three times the 45 million threshold.
ChatGPT search cleared the DSA threshold more than 3x over
Average monthly active EU recipients, six months ending March 31, 2026, versus the Digital Services Act’s 45 million-user designation threshold. Source: European Commission.
At 159.1 million average monthly EU users, ChatGPT’s search function sits well above the 45 million threshold that triggers VLOSE/VLOP obligations under the DSA.
Why a chatbot became a "search engine"
The legally interesting part of this designation is not the user count, it is the classification itself. ChatGPT is not being regulated as a chatbot. The Commission describes it as a "hybrid service" that qualifies as an online search engine specifically "because it can engage with and respond to users' prompts and queries, including by searching the web." In other words, the trigger is ChatGPT's live web-browsing and search capability, layered on top of its core conversational function, not the chatbot interface itself.
The Commission is regulating what ChatGPT does when it searches the live web, not what it is when it answers from a static model. That distinction sets the template for every AI assistant with a browse feature.
Metir AI analysis
That reasoning matters well beyond OpenAI. Any AI assistant that fetches live web results and cites them back to a user, rather than answering purely from its trained weights, now has a plausible path into the same "hybrid service" category the Commission has applied here. The relevant fact for regulators is not how a product markets itself but what function it performs for users at scale.

What compliance actually requires
VLOSE and VLOP status is not a fine or a ban. It adds a specific set of recurring obligations on top of the DSA's baseline rules, and the Commission gave the three newly designated services a four-month window, by January 2027, to meet them.
What VLOSE/VLOP status adds on top of ordinary DSA rules
Designation as a Very Large Online Search Engine or Platform layers extra obligations on top of the baseline DSA rules every online service already follows.
Designation applies to ChatGPT’s search function specifically, not the assistant as a whole, but the compliance obligations attach to OpenAI as the service provider.
The core requirements are an annual systemic risk assessment covering illegal content, protection of minors, mental and physical well-being, fundamental rights, electoral processes and public security; an independent audit of DSA compliance; and data-sharing obligations toward the Commission and vetted independent researchers studying those systemic risks. For OpenAI specifically, this means documenting and assessing how ChatGPT's search function could contribute to each of those risk categories at EU scale, submitting to third-party audit of that assessment, and opening data access to researchers the Commission approves, a materially higher compliance burden than operating under the DSA's baseline rules alone.
A second EU law is already in play
The DSA designation lands on top of, not instead of, the EU AI Act, a separate law with its own overlapping scope. The AI Act regulates AI systems by risk category and imposes its own transparency, documentation and, for general-purpose models above certain compute thresholds, systemic-risk obligations. ChatGPT was already subject to AI Act requirements as a general-purpose AI system before this DSA designation. The two regimes ask related but distinct questions: the AI Act is largely about the model and how it is built and disclosed; the DSA's VLOSE tier is about the scale and function of a specific service, in this case ChatGPT's search capability, and its effects on users and public discourse at platform scale. OpenAI, and any AI company crossing similar thresholds, now has to satisfy both frameworks in parallel rather than treating either as a complete compliance answer.
Who else could be next
The Commission's reasoning creates a legible test that other AI assistants with live search or browsing features could also meet if their EU user base grows past 45 million monthly active recipients: Google's Gemini, Anthropic's Claude, Perplexity, and Microsoft's Copilot all ship some form of live web search or grounding today. None of them has been designated VLOSE as of this writing, and the Commission has not published EU user figures for these services in this announcement, so any claim about who crosses the threshold next would be speculative. What is established is the legal template: a service search-enables itself and hits 45 million EU users, the Commission has now shown it will apply search-engine obligations regardless of whether the product is branded a chatbot, an assistant, or something else.
The compliance-burden argument, stated fairly
Critics of the DSA's very-large-platform tier argue the annual audit and risk-assessment requirements are a heavy fixed cost that scales poorly for AI products iterating faster than platforms the DSA was originally written to regulate, and that applying search-engine rules to a conversational product is an awkward fit that will produce compliance documentation without necessarily reducing the risks the DSA targets. The Commission's counter-argument is the one embedded in the law itself: obligations attach at 45 million users specifically because a service at that scale has outsized influence on what EU citizens see and believe, and the DSA's audit and transparency requirements exist to make that influence externally checkable rather than opaque. Both positions describe the same set of facts from different premises about what regulatory scrutiny should cost and when it is warranted.
What this means for teams deploying AI tools
For enterprises building on AI assistants, this designation is a preview of a broader pattern: as AI products cross regulatory thresholds market by market, the compliance posture of a single vendor's tool can shift with little warning, and a company that has standardized its workflows on one assistant inherits whatever compliance changes, feature restrictions or data-sharing obligations that vendor takes on. Teams that route work across multiple models rather than committing to one vendor have more room to adjust as individual providers' regulatory exposure changes. Metir AI is built as a model-agnostic platform for exactly that reason, giving teams access to models from OpenAI, Google, Anthropic and others side by side so a regulatory shift affecting one provider does not require rebuilding a workflow from scratch.
The takeaway
The Commission's August 31, 2026 decision is narrow in its immediate reach, ChatGPT's search function, Reddit and Roblox, but broad in its legal logic. It confirms that DSA obligations for the largest online services attach to what a product does at scale, not to how it is categorized by its maker, and it puts a live-web-search feature squarely inside the same regulatory tier as Google Search. OpenAI now has until the Commission's January 2027 deadline to stand up annual risk assessments, independent audits and researcher data access for ChatGPT's search function, in parallel with its existing EU AI Act obligations. Whether other AI assistants with browse features follow ChatGPT into this tier will depend on their own EU user growth, but the legal path for getting there is no longer hypothetical.
Sources:
- Commission designates ChatGPT, Reddit and Roblox under the Digital Services Act | European Commission
- DSA: EU Commission classifies ChatGPT as very large search engine | Heise
- What does the EU 'very large search engine' tag mean for ChatGPT? | Business Standard
Image credits
Header image: the Berlaymont building, headquarters of the European Commission in Brussels, Belgium, with EU flags flying in front of it, photographed by Vaido Otsar via Wikimedia Commons, released under a CC0 public domain dedication. In-body photograph: a close-up upward view of the Berlaymont building's curved facade, photographed by acediscovery via Wikimedia Commons, licensed under CC BY 4.0. Both photos show the European Commission's headquarters building; neither depicts the ChatGPT VLOSE announcement itself, which was a written Commission decision with no accompanying event photography.

Anthropic
Perplexity