Brussels does not usually move this fast on anything involving a single company, but ChatGPT managed to trip a threshold nobody expected an AI chatbot to trip. On August 31, 2026, the European Commission formally designated OpenAI’s ChatGPT a Very Large Online Search Engine under the Digital Services Act, the same legal category that already covers Google Search and Microsoft Bing. It is the first time a conversational AI product has been placed in that bracket, and it comes with a rulebook OpenAI now has until the end of December to satisfy.
The number that triggered it is almost comically large. Services cross into “very large” territory once they report more than 45 million average monthly users in the EU. OpenAI’s own reporting put ChatGPT at roughly 159.1 million average monthly users across the bloc, more than three times the line, which made the designation less a judgment call than a formality the Commission was obligated to make.
The short version
- A new legal category, not a punishment. The Commission calls ChatGPT a “hybrid service” that answers prompts partly by searching the web, which under the DSA’s own definitions makes it a search engine, regardless of how odd that sounds
- The threshold was blown past, not nudged. 159.1 million average monthly EU users against a 45 million bar
- Reddit and Roblox were designated the same day, as Very Large Online Platforms rather than search engines, bringing the DSA’s list of very large services to 28
- December 2026 is the deadline. Systemic risk assessments, independent audits, algorithmic transparency and researcher data access all have to be in place by then
- Non-compliance is expensive. Fines under the DSA can reach 6% of a company’s global annual turnover, not just its EU revenue
- OpenAI is not fighting the label. Its statement to press accepted that “ChatGPT search operates as a search service under the DSA” and said it was preparing to meet the new requirements
How a chatbot became a search engine, legally
The Digital Services Act was written years before generative AI chat became a mainstream way to look things up, so it defines an online search engine functionally rather than by what a product calls itself: a service that lets users enter queries and returns results relevant to that query, typically by crawling or indexing web content. ChatGPT’s search mode does exactly that when it browses the web to answer a question, and the Commission’s position is that once a product does the thing the law describes, the label follows, whatever the marketing says.
That is a broader reading than most people would guess from the name “ChatGPT.” It is also consistent with how the EU has approached the DSA generally, treating the size and function of a service as the trigger for obligations rather than its category on an app store. The same designation round that caught ChatGPT also caught Reddit and Roblox, though as Very Large Online Platforms rather than search engines, since neither of those returns web search results in the same sense.
What OpenAI actually has to build before December
The obligations attached to a Very Large Online Search Engine are not paperwork so much as permanent infrastructure. OpenAI now has to run a systemic risk assessment covering how ChatGPT’s search function could contribute to the spread of illegal content, harm to minors, or manipulation of public discourse, and it has to publish the methodology, not just the conclusion. An independent auditor, not OpenAI itself, has to check that the assessment holds up. Vetted researchers get a formal channel to request data about how the system behaves at scale, a right that previously applied mainly to Google and the big social platforms.
On top of that sits algorithmic transparency: OpenAI has to be able to explain, in terms a regulator can evaluate, why ChatGPT surfaces the sources and answers it does for a given query. For a system built on a language model rather than a ranked index, that is a meaningfully harder engineering and documentation problem than it was for Bing, whose architecture already looked like the kind of thing the DSA was written to regulate.
| Obligation | What it actually requires | Deadline |
|---|---|---|
| Systemic risk assessment | Annual review of how the service could spread illegal content, harm minors or affect civic discourse | Dec 2026, then yearly |
| Independent audit | An outside auditor checks the risk assessment and mitigation steps, not OpenAI’s own team | Dec 2026 |
| Algorithmic transparency | Explain to regulators, in evaluable terms, how answers and sources are generated and ranked | Dec 2026 |
| Researcher data access | Vetted academic researchers can formally request behavioral data at scale | Dec 2026 |
| Content moderation and appeals | Documented moderation process with a user right to appeal decisions | Dec 2026 |
OpenAI’s public response leaned into acceptance rather than pushback. The company told reporters that “ChatGPT search operates as a search service under the DSA, and we are preparing to meet the additional compliance requirements that come with this Very Large Online Search Engine designation,” framing the moment as evidence of how quickly people have adopted a new way of searching rather than as a fight worth having. That is a notably calmer tone than the one Brussels and Silicon Valley have taken with each other over most of the last two years, and it fits a pattern: fighting a DSA designation in court is slow and rarely successful, while building the compliance program at least keeps a company’s own engineers in charge of how it gets built.
The number that makes this hard to shrug off
None of this is symbolic. Companies that fail to meet DSA obligations for a Very Large Online Platform or Search Engine can be fined up to 6% of their total worldwide annual turnover, not just revenue generated in the EU. For a company the size OpenAI has become, now past a billion weekly users globally, that is not a rounding-error penalty, and it is the kind of number that gets a compliance program funded and staffed properly rather than treated as a side project.
It also lands on top of an already crowded regulatory calendar for AI companies operating in Europe. The EU AI Act became enforceable earlier this year, bringing its own separate set of transparency and risk obligations that apply specifically to AI systems rather than to search engines or platforms as categories. ChatGPT’s operators are now threading both frameworks at once: one built for AI specifically, one built for big internet services generally, arriving at the same product from two different directions.
Why this is not really about search results
The more interesting long-term question is what a formal researcher-access requirement and an audited risk assessment reveal about a chatbot that people increasingly ask about things far more sensitive than search queries used to be. A ranked list of web links carries a certain kind of risk. A conversational answer that a user treats as a confidant carries a different one, and regulators clearly plan to look at that gap. The overlap is not hypothetical: courts have already started pulling chatbot transcripts into evidence in unrelated cases, a reminder that what people say to a chatbot carries none of the legal protection a conversation with a lawyer or doctor would. A systemic risk assessment sits on top of that same underlying tension: a product designed to feel like a private exchange, being audited like a piece of public infrastructure, because at 159 million EU users a month, that is closer to what it actually is.
The honest read
Nothing about this designation says OpenAI has done anything wrong. The Commission has been explicit that crossing the 45 million user threshold triggers the obligation automatically, regardless of a company’s conduct, in the same mechanical way Google Search and Bing were designated years earlier. What changes is that ChatGPT now has to prove, on a fixed public schedule and to an outside auditor, that the thing hundreds of millions of Europeans use every month behaves the way it claims to.
That is a genuinely new kind of scrutiny for a conversational AI product, and it will not be the last one. If a chatbot can trip a search engine threshold by doing what search engines do, the next products likely to get pulled into the same bracket are the AI features quietly folding search behavior into browsers, phones and office software everywhere else. Brussels just drew the first line. It will not be drawing the only one.

