On August 31, 2026, the European Commission officially designated ChatGPT as a “Very Large Online Search Engine” (VLOSE) under the Digital Services Act (DSA), alongside Reddit and Roblox as Very Large Online Platforms. This marks the first time an AI-powered conversational interface has been classified as a search engine for regulatory purposes, setting a precedent that will reshape how frontier AI models are governed across the 27-member bloc.

The designation was triggered after OpenAI reported over 159 million monthly active users in the EU—far exceeding the 45 million user threshold that triggers VLOSE classification. Unlike the voluntary AI Act commitments OpenAI signed earlier in 2026, the DSA designation carries legally enforceable obligations with fines up to 6% of global annual revenue for non-compliance.

This regulatory move crystallizes a fundamental tension: ChatGPT is a chatbot, not a traditional search engine like Google. Yet the EU’s classification treats it as infrastructure with systemic societal impact, requiring OpenAI to implement risk assessments, independent audits, and transparency measures typically reserved for social media giants and search monopolies. The decision signals that conversational AI has crossed from experimental technology into critical digital infrastructure subject to public oversight.

Fast Facts
  • Designation Date: August 31, 2026 (effective immediately, four-month compliance clock)
  • User Threshold Trigger: 159 million monthly EU users (reported by OpenAI), far above the 45 million VLOSE threshold
  • Compliance Deadline: End of December 2026 (four months from designation)
  • Maximum Fine: Up to 6% of global annual revenue for DSA violations
  • First AI Chatbot Designated: ChatGPT is the first conversational AI to receive VLOSE classification under the DSA
  • Parallel Designations: Reddit and Roblox designated as Very Large Online Platforms (VLOPs) on the same day

DSA Compliance Obligations Timeline

Terminal
+--------------------------------------------------------------------------+
|              ChatGPT DSA Compliance Timeline & Obligations               |
+--------------------------------------------------------------------------+
[August 31, 2026: Official Designation]
               │
      ┌────────┴──────────────────────────────────────────┐
      ▼                                                   ▼
[Four-Month Clock Starts]                           [December 2026 Deadline]
- Conduct systemic risk assessment                  - Publish first annual audit
- Implement ad transparency repository              - Deploy non-profiling feed option
- Establish researcher data access                  - Complete independent compliance audit
- Build content moderation appeals                  - RESULT: Full DSA Compliance or 6% Fine
+--------------------------------------------------------------------------+

DSA Obligations Matrix for VLOSE Designation

The table below outlines the specific compliance requirements ChatGPT must implement by December 2026:

Compliance Area Specific Obligation Implementation Requirement Enforcement Mechanism
Systemic Risk Assessment Annual evaluation of illegal content, electoral interference, minor safety, mental health Must cover all EU languages and use cases Independent auditor certification required
Ad Transparency Public searchable repository of all ads shown in EU Must include targeting parameters, impression counts, advertiser identity Real-time API access for regulators
Researcher Access Provide vetted researchers access to platform data Must enable study of systemic risks without exposing user PII EU Digital Services Coordinator approval
Non-Profiling Option At least one feed not based on user profiling Must be prominently offered to all EU users User choice architecture audit
Content Moderation Notice-and-action mechanism for illegal content Must respond within specific timeframes based on severity Penalty for delayed takedowns
Crisis Response Emergency protocols for electoral periods, public health crises Must activate enhanced monitoring during designated crisis periods European Commission directive
Systemic Risk Assessment
Specific ObligationAnnual evaluation of illegal content, electoral interference, minor safety, mental health
Implementation RequirementMust cover all EU languages and use cases
Enforcement MechanismIndependent auditor certification required
Ad Transparency
Specific ObligationPublic searchable repository of all ads shown in EU
Implementation RequirementMust include targeting parameters, impression counts, advertiser identity
Enforcement MechanismReal-time API access for regulators
Researcher Access
Specific ObligationProvide vetted researchers access to platform data
Implementation RequirementMust enable study of systemic risks without exposing user PII
Enforcement MechanismEU Digital Services Coordinator approval
Non-Profiling Option
Specific ObligationAt least one feed not based on user profiling
Implementation RequirementMust be prominently offered to all EU users
Enforcement MechanismUser choice architecture audit
Content Moderation
Specific ObligationNotice-and-action mechanism for illegal content
Implementation RequirementMust respond within specific timeframes based on severity
Enforcement MechanismPenalty for delayed takedowns
Crisis Response
Specific ObligationEmergency protocols for electoral periods, public health crises
Implementation RequirementMust activate enhanced monitoring during designated crisis periods
Enforcement MechanismEuropean Commission directive

Real-World Utility & Policy Implementation

The 4-Step DSA Compliance Playbook for AI Companies

  1. Conduct Baseline Systemic Risk Assessment: Within 30 days of designation, map all potential harm vectors including disinformation amplification, minor exposure to harmful content, mental health impacts from prolonged usage, and electoral manipulation risks. Engage third-party auditors to validate methodology.
  1. Build Ad Transparency Infrastructure: Deploy a public-facing ad library API that logs every ad impression shown to EU users, including targeting criteria (demographics, interests, behavioral signals), advertiser verification status, and spend data. This requires engineering investment to retrofit ChatGPT’s ad system (if applicable) or partner ad networks.
  1. Establish Researcher Data Access Program: Create a formal application process for academic and civil society researchers to request aggregated, anonymized data about platform operations. Implement technical safeguards to prevent re-identification of users while enabling meaningful systemic risk research.
  1. Implement User Choice Architecture: Redesign onboarding flows and settings pages to prominently offer EU users a non-profiling-based feed option (e.g., chronological, topic-based, or randomized content). This may require A/B testing to ensure the option is genuinely accessible and not buried in settings.
Strategic Implementation ChecklistPractitioner recommendations
  1. Expect Gemini and Perplexity Next: Once Google’s Gemini AI Search and Perplexity’s AI answer engine hit 45 million EU monthly users, they will face identical VLOSE designation. AI companies should proactively build DSA compliance into product roadmaps rather than retrofitting under deadline pressure.
  1. Classification Ambiguity Creates Loopholes: Critics note that the “search engine” designation may actually limit the EU’s ability to regulate ChatGPT’s chat-based risks (like teen mental health or election misinformation) compared to a “platform” designation, which would impose stricter content moderation duties. This regulatory gap may be closed in future DSA amendments.
  1. Global Compliance Spillover: DSA obligations will effectively become global standards, as it’s operationally impractical to maintain separate product versions for EU vs. non-EU users. Expect ChatGPT’s ad transparency, researcher access, and risk assessment features to roll out worldwide, raising the compliance floor for the entire AI industry.

Everyday Applications & Digital Rights for Global Consumers

The European Union’s designation of ChatGPT as a Very Large Online Search Engine (VLOSE) under the Digital Services Act (DSA) introduces sweeping new transparency requirements and consumer protections that directly impact how everyday people search the web.

What VLOSE Designation Means for Your Everyday Privacy

Under the DSA, search engines with more than 45 million monthly active European users must give individuals greater control over their personal data and algorithmic feeds. Everyday users should take advantage of these new protections:

  • Exercise Your Right to Non-Profiling Search: Look for platform settings that allow you to conduct search queries without behavioral profiling, preventing past chats from biasing news and product results.
  • Inspect Commercial and Sponsored Transparency: The DSA mandates that search platforms clearly label paid links, commercial partnerships, and sponsored ranking factors. Scrutinize AI-recommended products for disclosure markers.
  • Utilize Formal Redress Mechanisms: If ChatGPT Search generates defamatory, inaccurate, or copyrighted personal information about you or your business, you can utilize standardized dispute resolution channels mandated by EU regulations.

Compliance Checklist for Businesses Serving European Users

If your enterprise deploys conversational search or AI tools to European employees or customers, take note of these operational guidelines:

  • Document Automated Search Integrations: Maintain an internal registry of AI search tools used across departments, ensuring alignment with GDPR and DSA transparency standards.
  • Review Data Processing Addenda (DPAs): Verify that your commercial AI vendor agreements include enforceable EU Standard Contractual Clauses governing cross-border data transfers.

Consumer Privacy Audit: 5-Minute Checklist

Everyday consumers using ChatGPT Search or other frontier conversational engines can safeguard their personal digital footprint in five minutes:

  • Disable Training on Personal Chats: Navigate to account Data Controls and toggle off “Improve the model for everyone” to prevent personal queries from being used in future training runs.
  • Clear Stale Query History: Delete temporary search sessions containing home addresses, family health details, or tax inquiries.
  • Use Temporary Chat Sessions: For one-off research tasks, launch temporary or incognito chat sessions that leave zero persistent memory footprint.
  • Export Your Data Annually: Request a complete GDPR/DSA data export to inspect what user profile metadata and search telemetry has been logged.

The Tuesday Intelligence Dispatch

The definitive weekly briefing engineering leaders and technical founders read before deploying AI models to production. Unvarnished latency audits, real-world token unit economics, and architectural teardowns—zero vendor hype, zero sponsored reviews, and 100% empirical verification.

Every Tuesday at 6 AM ET Tested in Real Environments Verified by Experts
Strictly no spam. We never share your data. 1-click unsubscribe anytime.
✓ Added to Dispatch

You’re all set!

Stay tuned for the upcoming Tuesday Intelligence Dispatch delivered at 6 AM ET.