O
OOMeta
← Back to Insights

September 2026 · 9 min read

EU designates ChatGPT a 'very large' search engine

EU designates ChatGPT a 'very large' search engine

Key Definitions

VLOSE (Very Large Online Search Engine) One of the strictest accountability tiers under the EU Digital Services Act: any online service with at least 45 million average monthly EU users that retrieves live web content qualifies for designation under DSA Article 33(1). On August 31, 2026, ChatGPT became the first AI chatbot designated, joining Google Search and Bing.

Capability-based designation The Commission classified ChatGPT as a 'hybrid service': a conversational assistant that functionally behaves like a search engine because it searches the web and synthesizes results in response to queries. Classification turns on capability — web retrieval plus scale — not on what a product calls itself, so the same logic automatically extends to Gemini, Perplexity and Claude.

On August 31, 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the Digital Services Act — the first AI chatbot ever placed in the DSA's strictest accountability tier. The decision did not hand OpenAI a single fine; it handed the entire AI search industry a compliance mirror. Any AI product with live web retrieval that crosses 45 million average monthly EU users — whatever it calls itself, chatbot, assistant or search engine — now runs on the same clock.

The trigger is capability, not category

The designation rests on DSA Article 33(1): any online service reaching at least 45 million average monthly users in the EU — roughly one in ten of the bloc's population — qualifies. ChatGPT shattered the threshold. OpenAI's own disclosure, prepared for DSA compliance and covering the six months ending March 31, 2026, put ChatGPT's EU user count at approximately 159.1 million — more than three and a half times the threshold, yet still less than half of Google Search's declared 364 million. The same day, Reddit (≈57.2 million) and Roblox (≈46.6 million) were named Very Large Online Platforms, bringing the total of designated services to 28.

The Commission described ChatGPT as a 'hybrid service': a conversational assistant that functionally behaves like a search engine because it retrieves and synthesizes live web information in response to queries. The classification is capability-based and architecture-agnostic. Google Gemini's standalone app reached 900 million global monthly users at I/O 2026; even a conservative EU share estimate puts it above 100 million. Perplexity's global count is contested (45M–230M, with roughly 24% of traffic from Europe), so its EU numbers sit uncertainly around the line. Claude holds about 8.2% of global chatbot web traffic and has published no EU figures. Designations are not announced in advance — Brussels monitors platform-reported data and acts once the threshold is clearly exceeded.

The compliance infrastructure OpenAI must build by January 2027

VLOSE obligations are not paperwork; they are a set of engineering, legal and organizational infrastructure requirements. The heaviest is the systemic risk assessment: under DSA Articles 34 and 35, OpenAI must annually document systemic risks from ChatGPT's service and algorithmic systems, and what it has done to reduce those harms. The six named categories — illegal content, harms to minors, damage to mental and physical health, violations of fundamental rights, threats to electoral processes, public security risks — are not aspirational checklists. They are the basis for the independent third-party audit that must follow each assessment, and for the researcher data-access program available to vetted academics.

Then comes the technical problem. DSA Article 27 requires VLOSEs to disclose the 'main parameters' of their recommender and ranking systems. For Google Search this is demanding but conceptually coherent: traditional ranking factors are identifiable and describable. For ChatGPT it runs into an architectural wall — a transformer model does not retrieve through a ranking algorithm with auditable parameters; it generates answers through attention mechanisms and probabilistic next-token sampling, billions of learned weights interacting with no interpretable 'ranking' of sources. Freshfields' analysis flags this obligation's applicability to LLMs as genuinely unsettled, and the Commission has not issued guidance. OpenAI must either build documentation at a specificity AI product teams have never shipped, or negotiate a workable interpretation with Ireland's Coimisiún na Meán — ChatGPT's national supervisory authority under the DSA. That interpretation will set the standard for every AI search product that follows. OpenAI's response was measured: a spokesperson said ChatGPT 'operates as a DSA search service' and the company was 'preparing to meet the additional compliance requirements'. It did not contest the classification.

The ad business and the ad transparency infrastructure are now the same project

One collision deserves attention: the same week of the designation, OpenAI reported ChatGPT Ads passed a $1 billion annualized revenue run rate — 200 days after the February 2026 pilot — and expanded its self-serve ad-buying platform into Europe. The VLOSE designation requires OpenAI to maintain a searchable public repository of every advertisement shown to EU users. For a traditional search engine, that means an ad library indexed by advertiser, content, targeting and impressions. For a conversational AI that delivers sponsored content as labeled cards inside natural-language responses, the questions are harder: what counts as a distinct 'ad' in a dynamically generated conversation, how are successive impressions of the same sponsored message indexed, and how does a public library accommodate personalized, context-dependent conversational placement? None of this has been answered. OpenAI is simultaneously building its European advertising business and the EU-mandated transparency infrastructure for it — the two are effectively the same project now.

Enforcement has teeth: an €870 million precedent

The compliance window may feel distant, but the DSA enforcement record is not theoretical. Since its first enforcement action in December 2025, the Commission has issued approximately €870 million in fines across three designated services: a record €550 million against AliExpress in July 2026 for algorithms that promoted counterfeit products, ≈€200 million against Temu in May 2026, and €120 million against X in December 2025 for deceptive user verification and transparency failures. Fines are calibrated as a percentage of global annual revenue — up to 6 percent. OpenAI reported approximately $13.07 billion in recognized revenue in 2025, putting its maximum exposure near $784 million per violation. Legal challenge has also proven difficult: Amazon and Zalando both lost their earlier VLOP challenges before the EU's General Court, which accepted that the compliance burden is substantial but justified by regulatory aims — and contesting a designation does not suspend obligations.

Germany's ZAK: a parallel track with no user threshold

Alongside the EU-level designation, a more aggressive national track has been running since July. On July 14, 2026, Germany's Commission for Licensing and Supervision (ZAK) ruled against Google and Perplexity, finding AI-generated search outputs subject to the German State Media Treaty. ZAK chairman Dr. Thorsten Schmiege put it plainly: 'AI search engines and chatbots are content providers, and we are now consistently applying German media law to them.' Regulators found AI responses constitute content the providers create themselves — not neutral hosting of third-party material — so the EU's standard platform liability exemption, which has protected intermediaries for two decades, does not apply.

This track matters in two ways. First, AI search regulation does not require the DSA's 45 million user threshold — German media law applies to any service meeting the legal definition of a content provider, regardless of scale. Second, it shows the Commission's VLOSE logic — 'AI-generated answers are a form of editorial authority over information' — being adopted independently by national regulators. For AI search products that have not yet crossed the DSA threshold, this is an immediately enforceable reality.

Dual-track compliance is the real cost calculation

The VLOSE designation does not arrive in isolation. OpenAI already operates under the EU AI Act as a general-purpose AI model provider — obligations enforceable with financial penalties since August 2, 2026. The AI Act governs what OpenAI builds and discloses about its model; the DSA governs how OpenAI runs that model as a service for 159.1 million EU users. The frameworks are complementary but not redundant, and a DSA systemic risk assessment must account for risks from the underlying model as well as search and retrieval features — meaning AI Act documentation and DSA risk assessments inevitably overlap, potentially requiring the same research team to produce two differently formatted accountability reports for two regulatory authorities.

For every AI company watching, this dual-compliance reality is the actual cost calculation. DSA compliance for a VLOSE requires sustained investment in risk assessment capacity, independent audit relationships, researcher data-access infrastructure and public ad-library tooling. For AI search products that have not crossed 45 million EU users, ChatGPT's designation is a preview of the obligations they will inherit on arrival — a near-term engineering and legal planning horizon, not a distant concern. The January 2027 compliance deadline for OpenAI, Reddit and Roblox will be the first real-world test of whether the DSA's obligations can meaningfully apply to a generative AI system.

The bottom line

The capability-based logic that brought ChatGPT into the VLOSE tier will scale forward automatically. The question for every AI search product is not whether the same regulation will reach it, but whether it will be ready when it does. For enterprise decision-makers the actionable read is more direct: if you build any AI product with live web retrieval, calculate now when your EU user base crosses 45 million — DSA compliance infrastructure is not a four-month project. If you procure and operate these products, add DSA risk audits and AI Act documentation to the same vendor-assessment track — two frameworks, two reports, one team. That is the default cost structure of AI compliance in 2026.

References

  • TechTimes: EU Sets AI Search Compliance Template — https://www.techtimes.com/articles/326510/20260903/eu-sets-ai-search-compliance-template-gemini-perplexity-face-same-clock-chatgpt.htm
  • European Commission: Commission designates ChatGPT, Reddit and Roblox under the Digital Services Act — https://digital-strategy.ec.europa.eu/en/news/commission-designates-chatgpt-reddit-roblox-under-digital-services-act
  • POLITICO: Hey EU, your new rules for ChatGPT don't cover chat — https://www.politico.eu/article/new-eu-rules-for-chatgpt-dont-cover-chat/
  • Freshfields: DSA decoded — algorithmic transparency under the DSA — https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/dsa-decoded-10-algorithmic-transparency-under-the-dsa-102mgg8
  • TechTimes: Germany Strips AI Search of Its EU Liability Shield — https://www.techtimes.com/articles/320790/20260716/germany-strips-ai-search-its-eu-liability-shield-worlds-first-media-ruling.htm
  • TechTimes: ChatGPT Ads Reach $1 Billion — https://www.techtimes.com/articles/326128/20260901/chatgpt-ads-reach-1-billion-advertisers-report-clicks-that-analytics-cannot-find.htm

Frequently Asked Questions

Does the VLOSE designation let the EU control what ChatGPT says?+

No. The designation does not give the Commission authority over ChatGPT's specific outputs or the right to require particular answers. It requires OpenAI to systematically study the harms the product creates at scale — illegal content, harms to minors, mental and physical health damage, fundamental rights violations, threats to electoral processes and public security — document findings honestly, take documented mitigation action, submit to independent third-party audits annually, and provide vetted researchers with data access. The deadline is January 2027.

Why was ChatGPT classified as a search engine and not a platform?+

The Commission called it a 'hybrid service': a conversational assistant that retrieves and presents information from the live web in response to user queries — the defining characteristic of a search intermediary. That is why the VLOSE label applied rather than VLOP. The classification is capability-based and architecture-agnostic: any AI product with a web-retrieval function and enough European users inherits the same logic.

Which AI search products are next?+

Google Gemini's standalone app reached 900 million monthly users globally at Google I/O 2026; even a conservative EU share estimate exceeds 100 million. Perplexity's global user count is contested (45M–230M), with roughly 24% of traffic from Europe — whether it qualifies depends on methodology. Claude holds about 8.2% of global chatbot web traffic and has not published EU figures. Designations are not announced in advance: Brussels monitors platform-reported data and acts when the threshold is clearly crossed.

Why is algorithm transparency harder for ChatGPT than Google Search?+

DSA Article 27 requires VLOSEs to disclose the 'main parameters' of their recommender and ranking systems. For Google Search, factors like authority scores, recency and query match are identifiable and describable. ChatGPT generates answers through attention mechanisms and probabilistic token sampling across billions of weights — there is no ranking list, no identifiable parameter set, no auditable decision path. Freshfields flags the obligation's applicability to LLMs as genuinely unsettled; OpenAI must negotiate the meaning of 'main parameters' for a generative system with Ireland's Coimisiún na Meán, ChatGPT's national supervisory authority under the DSA.

What does Germany's ZAK ruling mean for products below the DSA threshold?+

On July 14, 2026, Germany's Commission for Licensing and Supervision (ZAK) ruled that AI-generated search outputs from Google and Perplexity fall under the German State Media Treaty — AI responses are content providers create themselves, not neutral hosting of third-party material, so the standard platform liability exemption does not apply. There is no user threshold: any service distributing AI-generated content to German users can be covered, and the rulings are immediately enforceable. The DSA is a floor for the largest services; national media law reaches smaller ones through a separate mechanism.

How do the DSA and the AI Act relate?+

They are complementary but not redundant. The AI Act governs what OpenAI builds and discloses about its model (penalties enforceable since August 2, 2026); the DSA governs how OpenAI runs that model as a service for 159.1 million EU users (compliance due January 2027). AI Act documentation and DSA risk assessments inevitably overlap — potentially requiring the same research team to produce two differently formatted accountability reports for two regulators. For any AI company watching, that dual-compliance reality is the actual cost calculation.