The EU Just Classified ChatGPT as a 'Very Large Search Engine'
The European Commission designated ChatGPT a Very Large Online Search Engine under the DSA, triggering audits and risk assessments. Here's what that actually means.
On August 31, the European Commission designated ChatGPT a Very Large Online Search Engine (VLOSE) under the Digital Services Act. It’s the first time Brussels has put a generative AI chatbot into a legal category built for search engines, and it comes with a four-month clock: OpenAI has until January 2027 to comply with a fresh set of obligations, or face fines that can reach 6% of global annual revenue.
The same day, the Commission designated Reddit and Roblox as Very Large Online Platforms (VLOPs) — a related but distinct category under the same law. All three crossed the DSA’s activation threshold: at least 45 million average monthly users in the EU. ChatGPT cleared it by a wide margin, reporting around 159 million monthly EU users.
Why “search engine” and not “platform”
The DSA has two relevant buckets. VLOPs are large platforms hosting user-generated content — think Facebook, TikTok, or now Reddit and Roblox. VLOSEs are search engines, a smaller and more tightly regulated category that until now held only Google Search, Bing, and a handful of others.
The Commission’s reasoning for slotting ChatGPT into the search bucket rather than creating a new one: it decided ChatGPT functions as a “hybrid service.” Users type a query, ChatGPT can search the live web for an answer, and it returns something that resembles search results even when the interface looks nothing like a results page. That was enough for regulators to apply the search engine framework rather than write a new one from scratch — a sign the EU is choosing to stretch existing law over AI chatbots instead of waiting for bespoke rules.
What changes for OpenAI
VLOSE status brings the DSA’s strictest tier of obligations. OpenAI will need to:
- Conduct annual systemic risk assessments covering things like the spread of illegal content, harm to civic discourse, and effects on public health
- Submit to independent external audits of those risk assessments and OpenAI’s mitigation measures
- Share certain data with regulators and vetted researchers studying systemic risks
- Maintain a public advertising repository, if ChatGPT carries ads that fall under the rule
- Report to the Commission on compliance, with the first deadline in January 2027
These are the same obligations Google Search has operated under since the DSA’s very-large-service rules took effect in 2023. The practical question is how cleanly a chatbot’s “systemic risks” map onto a framework written for link-based search results — misinformation spread through search snippets is a different mechanism than misinformation generated in a conversational answer, and regulators and OpenAI will likely spend the next several months arguing over what the assessment should actually measure.
This isn’t the Commission’s first time forcing a US AI company to restructure around EU platform law. In July it ordered Google to open Android’s AI features and share search data with rivals under the separate Digital Markets Act. Between that case and this one, a pattern is forming: Brussels is treating AI products as extensions of existing dominant-platform categories — search, mobile OS, app stores — rather than carving out AI-specific law and waiting for it to pass. That’s faster than writing new legislation, but it also means AI companies are being regulated by rules that predate the products being regulated.
The bigger picture
OpenAI has had a rough few weeks with regulators and infrastructure partners. A misconfigured OpenAI test agent breached Hugging Face’s servers in July, and lawmakers responded with a kill-switch bill within days. Now a legal designation adds compliance overhead layered on top of security scrutiny — different regulators, different countries, same company under the microscope simultaneously.
For OpenAI, the immediate cost is operational: building out audit trails, risk-assessment processes, and EU-specific reporting infrastructure that Google already had to build years ago. For the rest of the AI industry, the designation matters more as precedent. Any chatbot or AI assistant that both answers questions and searches the live web — a growing share of the field, including Perplexity and Google’s own Gemini — is a plausible future candidate for the same VLOSE bucket once it crosses the 45-million-user threshold in the EU. The Commission has now shown it’s willing to make that call.