On August 31, 2026, the European Commission officially designated ChatGPT as a “Very Large Online Search Engine” (VLOSE) under the Digital Services Act (DSA), alongside Reddit and Roblox as Very Large Online Platforms. This marks the first time an AI-powered conversational interface has been classified as a search engine for regulatory purposes, setting a precedent that will reshape how frontier AI models are governed across the 27-member bloc.
The designation was triggered after OpenAI reported over 159 million monthly active users in the EU—far exceeding the 45 million user threshold that triggers VLOSE classification. Unlike the voluntary AI Act commitments OpenAI signed earlier in 2026, the DSA designation carries legally enforceable obligations with fines up to 6% of global annual revenue for non-compliance.
This regulatory move crystallizes a fundamental tension: ChatGPT is a chatbot, not a traditional search engine like Google. Yet the EU’s classification treats it as infrastructure with systemic societal impact, requiring OpenAI to implement risk assessments, independent audits, and transparency measures typically reserved for social media giants and search monopolies. The decision signals that conversational AI has crossed from experimental technology into critical digital infrastructure subject to public oversight.
Designation Date: August 31, 2026 (effective immediately, four-month compliance clock)
User Threshold Trigger: 159 million monthly EU users (reported by OpenAI), far above the 45 million VLOSE threshold
Compliance Deadline: End of December 2026 (four months from designation)
Maximum Fine: Up to 6% of global annual revenue for DSA violations
First AI Chatbot Designated: ChatGPT is the first conversational AI to receive VLOSE classification under the DSA
Parallel Designations: Reddit and Roblox designated as Very Large Online Platforms (VLOPs) on the same day
DSA Compliance Obligations Timeline
+--------------------------------------------------------------------------+
| ChatGPT DSA Compliance Timeline & Obligations |
+--------------------------------------------------------------------------+
[August 31, 2026: Official Designation]
│
┌────────┴──────────────────────────────────────────┐
▼ ▼
[Four-Month Clock Starts] [December 2026 Deadline]
- Conduct systemic risk assessment - Publish first annual audit
- Implement ad transparency repository - Deploy non-profiling feed option
- Establish researcher data access - Complete independent compliance audit
- Build content moderation appeals - RESULT: Full DSA Compliance or 6% Fine
+--------------------------------------------------------------------------+
DSA Obligations Matrix for VLOSE Designation
The table below outlines the specific compliance requirements ChatGPT must implement by December 2026:
Compliance Area
Specific Obligation
Implementation Requirement
Enforcement Mechanism
Systemic Risk Assessment
Annual evaluation of illegal content, electoral interference, minor safety, mental health
Must cover all EU languages and use cases
Independent auditor certification required
Ad Transparency
Public searchable repository of all ads shown in EU
Must include targeting parameters, impression counts, advertiser identity
Real-time API access for regulators
Researcher Access
Provide vetted researchers access to platform data
Must enable study of systemic risks without exposing user PII
EU Digital Services Coordinator approval
Non-Profiling Option
At least one feed not based on user profiling
Must be prominently offered to all EU users
User choice architecture audit
Content Moderation
Notice-and-action mechanism for illegal content
Must respond within specific timeframes based on severity
Penalty for delayed takedowns
Crisis Response
Emergency protocols for electoral periods, public health crises
Must activate enhanced monitoring during designated crisis periods
European Commission directive
Systemic Risk Assessment
Specific Obligation Annual evaluation of illegal content, electoral interference, minor safety, mental health
Implementation Requirement Must cover all EU languages and use cases
Enforcement Mechanism Independent auditor certification required
Ad Transparency
Specific Obligation Public searchable repository of all ads shown in EU
Implementation Requirement Must include targeting parameters, impression counts, advertiser identity
Enforcement Mechanism Real-time API access for regulators
Researcher Access
Specific Obligation Provide vetted researchers access to platform data
Implementation Requirement Must enable study of systemic risks without exposing user PII
Enforcement Mechanism EU Digital Services Coordinator approval
Non-Profiling Option
Specific Obligation At least one feed not based on user profiling
Implementation Requirement Must be prominently offered to all EU users
Enforcement Mechanism User choice architecture audit
Content Moderation
Specific Obligation Notice-and-action mechanism for illegal content
Implementation Requirement Must respond within specific timeframes based on severity
Enforcement Mechanism Penalty for delayed takedowns
Crisis Response
Specific Obligation Emergency protocols for electoral periods, public health crises
Implementation Requirement Must activate enhanced monitoring during designated crisis periods
Enforcement Mechanism European Commission directive
Real-World Utility & Policy Implementation
The 4-Step DSA Compliance Playbook for AI Companies
Conduct Baseline Systemic Risk Assessment: Within 30 days of designation, map all potential harm vectors including disinformation amplification, minor exposure to harmful content, mental health impacts from prolonged usage, and electoral manipulation risks. Engage third-party auditors to validate methodology.
Build Ad Transparency Infrastructure: Deploy a public-facing ad library API that logs every ad impression shown to EU users, including targeting criteria (demographics, interests, behavioral signals), advertiser verification status, and spend data. This requires engineering investment to retrofit ChatGPT’s ad system (if applicable) or partner ad networks.
Establish Researcher Data Access Program: Create a formal application process for academic and civil society researchers to request aggregated, anonymized data about platform operations. Implement technical safeguards to prevent re-identification of users while enabling meaningful systemic risk research.
Implement User Choice Architecture: Redesign onboarding flows and settings pages to prominently offer EU users a non-profiling-based feed option (e.g., chronological, topic-based, or randomized content). This may require A/B testing to ensure the option is genuinely accessible and not buried in settings.
Expect Gemini and Perplexity Next: Once Google’s Gemini AI Search and Perplexity’s AI answer engine hit 45 million EU monthly users, they will face identical VLOSE designation. AI companies should proactively build DSA compliance into product roadmaps rather than retrofitting under deadline pressure.
Classification Ambiguity Creates Loopholes: Critics note that the “search engine” designation may actually limit the EU’s ability to regulate ChatGPT’s chat-based risks (like teen mental health or election misinformation) compared to a “platform” designation, which would impose stricter content moderation duties. This regulatory gap may be closed in future DSA amendments.
Global Compliance Spillover: DSA obligations will effectively become global standards, as it’s operationally impractical to maintain separate product versions for EU vs. non-EU users. Expect ChatGPT’s ad transparency, researcher access, and risk assessment features to roll out worldwide, raising the compliance floor for the entire AI industry.
Everyday Applications & Digital Rights for Global Consumers
The European Union’s designation of ChatGPT as a Very Large Online Search Engine (VLOSE) under the Digital Services Act (DSA) introduces sweeping new transparency requirements and consumer protections that directly impact how everyday people search the web.
What VLOSE Designation Means for Your Everyday Privacy
Under the DSA, search engines with more than 45 million monthly active European users must give individuals greater control over their personal data and algorithmic feeds. Everyday users should take advantage of these new protections:
Exercise Your Right to Non-Profiling Search: Look for platform settings that allow you to conduct search queries without behavioral profiling, preventing past chats from biasing news and product results.
Inspect Commercial and Sponsored Transparency: The DSA mandates that search platforms clearly label paid links, commercial partnerships, and sponsored ranking factors. Scrutinize AI-recommended products for disclosure markers.
Utilize Formal Redress Mechanisms: If ChatGPT Search generates defamatory, inaccurate, or copyrighted personal information about you or your business, you can utilize standardized dispute resolution channels mandated by EU regulations.
Compliance Checklist for Businesses Serving European Users
If your enterprise deploys conversational search or AI tools to European employees or customers, take note of these operational guidelines:
Document Automated Search Integrations: Maintain an internal registry of AI search tools used across departments, ensuring alignment with GDPR and DSA transparency standards.
Review Data Processing Addenda (DPAs): Verify that your commercial AI vendor agreements include enforceable EU Standard Contractual Clauses governing cross-border data transfers.
Consumer Privacy Audit: 5-Minute Checklist
Everyday consumers using ChatGPT Search or other frontier conversational engines can safeguard their personal digital footprint in five minutes:
Disable Training on Personal Chats: Navigate to account Data Controls and toggle off “Improve the model for everyone” to prevent personal queries from being used in future training runs.
Clear Stale Query History: Delete temporary search sessions containing home addresses, family health details, or tax inquiries.
Use Temporary Chat Sessions: For one-off research tasks, launch temporary or incognito chat sessions that leave zero persistent memory footprint.
Export Your Data Annually: Request a complete GDPR/DSA data export to inspect what user profile metadata and search telemetry has been logged.