ChatGPT classified as a "search engine" by Brussels: the EU locks generative AI into the DSA's strictest regime
🔎 A chatbot is not a search engine — except for the European Commission
On August 31, 2026, Brussels crossed a legal Rubicon. By officially designating ChatGPT as a VLOSE (Very Large Online Search Engine) under the Digital Services Act, the European Commission did something no regulator in the world had dared to do: equate a generative AI assistant with a search engine.
The announcement, published simultaneously by Reuters and the European Commission, is a triple blow. Reddit (57.2 million monthly users in the EU) and Roblox (48 million) are classified as VLOPs (Very Large Online Platforms). ChatGPT, with 120.4 million monthly active users in the EU — and up to 159 million according to data compiled by Bloomberg — becomes the first consumer-facing frontier model subject to mandatory systemic risk audits.
Bloomberg had sensed the move as early as July 29, 2026. A month later, the decision came down. And it raises a question that the entire tech ecosystem had been asking since the arrival of GPT-4 in late 2022: where does a chatbot end, and where does a search engine begin?
Brussels' answer is unambiguous: when a chatbot responds to open-ended queries by drawing from a massive corpus of information, it falls within the scope of the DSA. This precedent potentially concerns all consumer-facing AI assistants — Gemini, Claude, Grok — as soon as they cross the threshold of 45 million monthly users in the EU.
The key points
- The European Commission designates ChatGPT as a VLOSE, and Reddit and Roblox as VLOPs under the DSA (August 31, 2026).
- ChatGPT far exceeds the threshold with 120.4M MAU in the EU (VLOSE threshold: 45M), Reddit at 57.2M, and Roblox at 48M.
- OpenAI has 4 months (deadline end of December 2026) to comply: systemic risk assessment, annual independent audits, enhanced transparency.
- Fines can reach up to 6% of global revenue in case of non-compliance.
- This is the first frontier AI model subject to the strictest DSA regime — a major legal precedent for the entire generative AI industry.
Tools and platforms concerned
| Platform | DSA Status | MAU in the EU | Main AI Model | Compliance Deadline |
|---|---|---|---|---|
| ChatGPT | VLOSE | 120.4M | GPT-5.5 | Dec. 2026 |
| VLOP | 57.2M | N/A | Dec. 2026 | |
| Roblox | VLOP | 48M | N/A | Dec. 2026 |
| Google Gemini | Not designated (for now) | Not published | Gemini 3.1 Pro | — |
| Claude (Anthropic) | Not designated (for now) | Not published | Claude Opus 4.7 (Adaptive) | — |
Sources: Commission européenne, Xinhua News — figures as of August 2026.
VLOSE, VLOP : what exactly are we talking about?
The DSA (Digital Services Act), which came into full application in February 2024, creates two categories of regulation for very large digital platforms. VLOP for Very Large Online Platform (more than 45 million monthly users in the EU), VLOSE for Very Large Online Search Engine (same threshold).
Until now, the designated VLOSEs were Google Search, Bing and Ecosia. Traditional search engines: you type a query, you get a list of links. The parallel with ChatGPT is not obvious at first glance.
But the Commission ruled based on a functional, rather than formal, criterion. ChatGPT receives open-ended textual queries and answers them by drawing on a massive index of information. For the European regulator, this ability to "search and provide results in response to a query" is enough to qualify it as a search engine within the meaning of the DSA.
According to EU Law Live, this interpretation considerably expands the scope of the DSA. Any AI assistant capable of answering factual questions could theoretically fall under this regime.
This reading is not purely theoretical. Tech Policy Press points out that "classifying ChatGPT as a VLOSE under the DSA will intensify regulatory scrutiny and broaden the scope of examination to a wider set of issues."
Why did the Commission classify ChatGPT as a search engine?
The legal question is at the heart of the debate. The DSA defines a search engine as a service that allows users to perform searches on all or part of the web. ChatGPT does not return links. It generates text.
But OpenAI has blurred the boundaries. The progressive integration of web search into ChatGPT — through partnerships and browsing capabilities — has transformed a simple chatbot into an AI-search hybrid. This gradual shift made classification inevitable in the eyes of Brussels.
The Commission opted for a pragmatic approach. Rather than debating for years about the ontological nature of a chatbot, it looked at actual usage: millions of Europeans use ChatGPT to get information, just like Google Search. The threshold of 45 million MAUs is largely exceeded. The logic of the DSA — proportioning obligations to size and impact — therefore applies.
This reasoning opens a Pandora's box. If ChatGPT is a search engine, what about Google Gemini, natively integrated into the Google search ecosystem? What about Perplexity, which explicitly presents itself as an "AI search engine"? The designation of ChatGPT creates a precedent that makes these future classifications almost inevitable.
To understand the stakes, you have to look at how AI models have become de facto search tools. Many users already compare the best LLMs for search to replace or complement Google. The Commission is simply legally recognizing a reality of usage.
What this designation concretely changes for OpenAI
Being classified as a VLOSE is not symbolic. It triggers an arsenal of heavy obligations.
Systemic risk assessment. OpenAI must identify and assess the risks that ChatGPT poses to society: disinformation, electoral manipulation, the spread of illegal content, effects on mental health, discriminatory bias. These assessments must be published and regularly updated.
Annual independent audits. An independent third party must audit ChatGPT's compliance with the DSA every year. Not a disguised internal audit — a genuine external examination, the results of which are communicated to the Commission and the public.
Enhanced transparency. OpenAI must publish detailed reports on content moderation, algorithmic recommendations, and how ChatGPT ranks and presents information. The "black box" approach is no longer legally tenable.
Crisis management. In the event of a major event (election, health crisis, armed conflict), OpenAI must activate specific mitigation measures and report on them.
The timeline is tight: four months, meaning a deadline at the end of December 2026. For a tool that fundamentally relies on a probabilistic model whose exact behavior is unpredictable, this is a considerable technical and organizational challenge.
This timeline comes as OpenAI is already under pressure on other fronts. The accelerated monetization of ChatGPT — notably with the rollout of ChatGPT Ads en Inde involving 50 brands and agencies like WPP and Omnicom — complicates compliance with transparency obligations. How to reconcile the advertising logic with the DSA's requirements on algorithmic recommendation?
6% of global revenue: the financial stick
The fines provided for by the DSA are not symbolic. Up to 6% of the company's global revenue in case of non-compliance. For OpenAI, whose annual revenues are estimated in the billions of dollars, we are talking about potential nine-figure fines.
But the real lever is not financial. It's reputational. A DSA fine is a strong signal sent to users, investors, and regulators around the world. Apple, Meta and TikTok learned this the hard way with the first VLOP designations in 2023-2024.
The DSA also provides for the possibility of corrective measures: obligation to change an algorithm, modify a feature, or even restrict access to the service in the EU in case of persistent non-compliance. This is the catastrophic scenario for OpenAI — a service blocked in its first major regulated market.
AI Weekly summarizes the situation: VLOP/VLOSE status triggers systemic risk assessments, annual independent audits, transparency obligations and fines of up to 6% of global revenue. The full package, without exception.
Reddit and Roblox: why they are in the same boat
The designation of Reddit and Roblox as VLOPs is less surprising but just as significant. Both platforms exceed the threshold of 45 million monthly users in the EU — 57.2 million for Reddit, 48 million for Roblox according to the Commission's figures.
Reddit is an interesting case in the context of AI. The platform has become one of the most sought-after sources of training data for language models. The licensing agreements signed with Google and OpenAI illustrate this symbiosis. At the same time, Reddit hosts communities where disinformation thrives. The VLOP status imposes moderation and transparency obligations that Reddit did not have to shoulder at this scale.
Roblox, for its part, raises the question of regulating immersive environments. The platform is primarily frequented by minors. The DSA imposes enhanced protections for vulnerable users — a central issue for Roblox.
The fact that these three designations were announced simultaneously is not insignificant. The Commission is sending a clear message: the DSA applies to all types of large-scale digital services, whether they are social networks, gaming platforms, or AI assistants. The underlying technology matters less than the impact on users.
A precedent that threatens all AI assistants
This is the most defining point of this decision. By classifying ChatGPT as a VLOSE, the Commission did not merely regulate OpenAI. It created a framework that potentially applies to all consumer-facing AI assistants.
Take the case of Claude (Anthropic). Claude Opus 4.7 (Adaptive) is one of the most high-performing models in the world, with a score of 90 on reference benchmarks. If Anthropic develops a consumer interface that exceeds 45 million MAU in the EU — or integrates web search capabilities similar to ChatGPT — the VLOSE designation becomes likely. The precedent is set.
The same logic applies to Google Gemini. Gemini 3.1 Pro, with a score of 92, is already integrated into the Google ecosystem. If the Commission considered ChatGPT to be a search engine, what can be said about Gemini, which is literally connected to Google Search? The question is not whether Gemini will be designated, but when.
For users who already compare Claude and ChatGPT, this regulation could create tangible differences in the experience. Models subject to the DSA could be more cautious, more transparent, but also more restricted in their responses.
The analysis by EU Law Live is categorical: this is a major precedent for any consumer-facing AI assistant under the DSA. The classification as a "search engine" no longer depends on the technology, but on the usage.
The EU, the first regulator to audit a frontier model
This designation makes the European Union the first legal jurisdiction in the world to impose mandatory systemic risk audits on a general-purpose frontier AI model.
The European AI Act, which comes into force in stages starting in August 2025, classifies frontier models in the "systemic risk" category. But the AI Act and the DSA follow different logics. The AI Act regulates the model itself (training data, evaluation, documentation). The DSA regulates the service as it is used by the public (moderation, transparency, recommendation).
ChatGPT now falls under a dual regime. OpenAI must comply with both the AI Act for GPT-5.5 and the DSA for the ChatGPT service. This is an unprecedented regulatory burden for an AI company.
This dual constraint could favor the meilleurs LLM gratuits that remain below the regulatory thresholds, or incentivize providers to segment their offerings to avoid the VLOSE designation.
The technical challenges of compliance
Assessing the systemic risks of an LLM is an open problem. Unlike a video recommendation algorithm — which can be audited in a relatively deterministic way — a language model generates probabilistic responses. The same prompt can produce different responses with each execution.
How do you audit this? How do you reliably assess the disinformation risks of a model that can be queried on any topic, in any language, at any time?
OpenAI will have to invent audit methodologies. Independent auditors will need to develop specific skills in LLM evaluation — a field that is still in its infancy. The annual risk reports will be unprecedented technical documents, potentially a source of new controversies.
The transparency requirement also poses concrete problems. Will OpenAI have to publish details about GPT-5.5's safety mechanisms? Down to what level of granularity? Too much transparency could help adversaries bypass the guardrails. Not enough could be considered non-compliance. It is a delicate balance.
The tech ecosystem's reaction
The August 31 announcement drew mixed reactions. On the regulators' side, it is a strong signal of European execution capacity. The DSA is not a dead letter — it is producing concrete effects on the world's largest platforms.
On the AI companies' side, the concern is palpable. Classifying ChatGPT as a search engine is seen by many as a legal stretch. A chatbot that generates text does not have the same mechanisms as a web page indexer. The boundary between "answering a question" and "providing search results" is now legally blurred.
Some players, however, see a competitive advantage. Companies investing in DSA compliance right now — transparency, auditability, security — could use this label as a commercial argument. In an increasingly competitive AI market, regulatory trust becomes a differentiator.
This is particularly true in the context of enterprise adoption. When Salesforce adopts Claude as the default reasoning engine, the regulatory compliance of the underlying model becomes a purchasing criterion. Client companies want to know that the AI they integrate complies with legal frameworks.
What this changes for the end user
For the European ChatGPT user, the effects will not be immediate or visible at first glance. But in the medium term, several concrete changes are likely.
Potentially more conservative responses. Risk management obligations could lead OpenAI to strengthen its safety filters. Responses on sensitive subjects (politics, health, sexuality) could become more cautious and more regulated.
More transparency about what ChatGPT knows about you. The DSA imposes transparency obligations regarding data collection and personalization. Users should have clearer access to their data and how it is used.
Better handling of reports. VLOSEs must establish effective reporting mechanisms. If a user reports a problematic response, OpenAI will have to process this report within specific timeframes and account for its decision.
Information about the recommendation logic. The DSA requires users to understand why they see certain content. For ChatGPT, this could translate into explanations about how responses are generated and ranked.
These changes could also create regional differences. A European ChatGPT user might have a different experience than an American or Asian user — a "regulatory fragmentation" that the industry dreads.
OpenAI's 4 months: an impossible timeline?
Late December 2026. That is the deadline. Four months to deeply transform OpenAI's internal processes and comply with the strictest regime of the DSA.
The initial assessment of systemic risks is the most urgent step. OpenAI must map all the risks that ChatGPT poses to European society — a colossal exercise for a service used by over 120 million people in dozens of languages.
The appointment of an independent auditor is also a challenge. Few organizations currently have the technical expertise to audit a model as complex as GPT-5.5. The AI audit market will have to structure itself urgently.
OpenAI's legal and technical teams must work in parallel on the AI Act and the DSA — two texts with different logics, timelines, and requirements. The workload is considerable.
If OpenAI requests an additional delay, the Commission will have a choice between firmness (no exemption) and pragmatism (granting a few extra months to avoid premature litigation). The first scenario is more likely: Brussels has an interest in showing that deadlines are enforced.
❌ Common mistakes
Mistake 1: Confusing DSA and AI Act
Many commentators treat this designation as an application of the AI Act. This is wrong. The DSA regulates the ChatGPT service as a platform accessible to the public. The AI Act regulates the GPT-5.5 model as a systemic-risk AI system. These are two distinct regimes, with different obligations, that accumulate.
Mistake 2: Thinking that only ChatGPT is affected
The designation applies to ChatGPT today. But the legal precedent applies to any AI assistant that exceeds 45 million MAU in the EU and offers information search capabilities. Gemini, Claude, Perplexity, Grok: they are all in the crosshairs.
Mistake 3: Believing that fines are the real risk
6% of global revenue is a lot. But the main risk is structural: the obligation to modify how the service operates, to reduce certain features, and to publish sensitive information about safety mechanisms. The fine is the tree that hides the forest of operational constraints.
Mistake 4: Downplaying the impact on innovation
A model subject to mandatory annual audits, systemic risk assessments, and transparency obligations evolves differently from a model free of these constraints. Regulatory pressure could slow down the deployment of new features, or steer innovation toward smaller, less regulated models.
❓ Frequently Asked Questions
Is an AI chatbot really a search engine?
Legally, the European Commission has ruled: yes, provided it receives open queries and answers them by drawing on a massive corpus of information. This interpretation is debatable but is now authoritative under the DSA.
Which other AI assistants could be designated as VLOSEs?
Google Gemini is the most obvious candidate, as it is natively connected to Google Search. Claude (Anthropic), Perplexity and Grok could be if they exceed the threshold of 45 million MAUs in the EU. The best AIs for research are all potentially affected.
Will European users see changes quickly?
Not immediately. The compliance deadline is 4 months. Visible changes (increased transparency, reporting mechanisms) should appear in early 2027. The effects on the model's behavior (more cautious answers) could be more gradual.
Could OpenAI simply block ChatGPT in the EU?
Theoretically yes, but it is extremely unlikely. The EU is the world's first major regulated market. Withdrawing from it would send a catastrophic signal to investors and other regulators (United States, China, United Kingdom) who are waiting to see how OpenAI handles regulatory constraints.
Does this designation affect the free versions of ChatGPT?
Yes. The DSA applies to the service as a whole, without distinction between free and paid offers. The 120.4 million MAUs include all users, regardless of their subscription. Free alternatives to ChatGPT could also become more attractive if they escape the VLOSE regime.
Does the AI Act also apply to ChatGPT?
Yes, in parallel. The AI Act imposes specific obligations on AI models with systemic risk (capability evaluations, technical documentation, serious incident reports). The DSA adds a user-oriented layer of regulation (transparency, moderation, reporting). The two are cumulative.
✅ Conclusion
August 31, 2026, will go down as the date Europe decided a chatbot is no longer just a chatbot. By designating ChatGPT as a VLOSE, the Commission has brought generative AI into the strictest digital platform regulatory regime — a precedent that reconfigures the landscape for all AI players. OpenAI has four months to adapt. Other AI assistants have a clear signal: regulation is no longer a possibility, it is a trajectory. To follow the evolution of this case and its consequences for the AI ecosystem, check out our comparison Google Gemini vs ChatGPT vs Claude: which one for which use?.
```