The European Commission did not ban ChatGPT, fine OpenAI, or declare its answers illegal today. It changed ChatGPT's regulatory status.
On August 31, 2026, the Commission formally designated ChatGPT a Very Large Online Search Engine (VLOSE) under the EU Digital Services Act (DSA). The reason is unusually important: the Commission describes ChatGPT as a hybrid AI service that answers prompts and can search the web, so it qualifies as an online search engine under the DSA.
That designation puts ChatGPT into the DSA's highest-supervision category for search services. OpenAI now has a four-month compliance window for the additional VLOSE obligations; the Commission says those duties must be met by January 2027.
For users, the practical takeaway is less dramatic than the headline. There is no required overnight redesign on September 1. The important changes are behind the service: systemic-risk assessments, mitigation measures, independent audits, regulator access, researcher access and additional transparency. Some of those obligations may later produce visible product changes, but the designation itself does not prescribe a specific ChatGPT interface.
Status check — August 31, 2026: This article uses the Commission's updated August 31 press release and current DSA guidance. The Commission says ChatGPT, Reddit and Roblox each declared at least 45 million average monthly users in the EU, the threshold for designation. ChatGPT is the VLOSE; Reddit and Roblox were designated Very Large Online Platforms (VLOPs).
Why is ChatGPT legally a search engine?
This is the most interesting part of the decision.
The Commission's press release says ChatGPT is an AI system that responds to prompts and queries, including by searching the web, and therefore qualifies as a hybrid service that is an online search engine for DSA purposes.
That does not mean every language-model response has suddenly become equivalent to a Google search result. It means the service, as offered in the EU, contains information-retrieval functionality that brings it inside the DSA's search-engine category.
A useful way to separate the layers is:
| Layer | What it does | Main regulatory question here |
|---|---|---|
| Underlying AI model | Generates or reasons over content | Primarily addressed by AI-specific rules such as the EU AI Act |
| ChatGPT service | Gives users an interface to ask questions, use tools and receive answers | Already subject to general DSA obligations applicable to the service |
| Web-search functionality inside ChatGPT | Retrieves current information from the web as part of answering queries | Why the Commission classifies ChatGPT as an online search engine under the DSA |
| VLOSE designation | Adds enhanced duties because the service has reached very large EU scale | Systemic-risk governance, audits, transparency and supervision |
This distinction matters because two regulations can apply to different parts of the same product without being duplicates.
Why did the designation happen now?
The DSA uses a scale threshold rather than a subjective test of whether a service is "important enough."
A platform or online search engine can be designated a VLOP or VLOSE once it reaches 45 million average monthly users in the EU, roughly 10% of the EU population under the DSA framework.
The Commission says ChatGPT, Reddit and Roblox each declared that they meet that threshold.
Designation is therefore a size-and-service classification, not a finding that the company violated the law.
That is the first thing to keep straight:
large enough + covered service
↓
VLOSE designation
↓
additional legal duties
↓
possible investigation if compliance is questioned
↓
possible enforcement only if a breach is established
The first box happened today. The later boxes are separate steps.
What does OpenAI have to do within four months?
The Commission says the new designation gives ChatGPT four months to comply with the additional DSA duties for very large services. Its current VLOP/VLOSE guidance highlights several categories.
1. Assess systemic risks
A VLOSE has to identify and analyse systemic risks connected to its service and algorithmic systems.
The Commission specifically points to risks involving:
- dissemination of illegal content;
- fundamental rights;
- public security and electoral processes;
- protection of minors;
- physical and mental wellbeing.
For ChatGPT, the interesting question is how those categories are translated from traditional search and social-platform regulation into a conversational AI product.
The Commission has not published a ChatGPT-specific risk-assessment template in today's announcement. So it would be premature to claim that one particular model behavior, safety filter or answer format must change.
2. Put mitigation measures behind the assessment
A risk report is not enough on its own. The DSA requires very large services to put reasonable mitigation measures in place for risks they identify.
The Commission's general guidance says mitigation can involve changing the design or functioning of a service, adjusting algorithmic systems, or adding internal resources and controls.
That means the eventual effect could appear in product design, safety systems, recommendation/search behavior, account protections, or operational processes—but which measures OpenAI chooses and which measures regulators consider sufficient are not yet established by today's designation.
3. Submit to independent audits
VLOPs and VLOSEs must undergo an independent audit at least annually and respond to the auditor's recommendations.
This is one of the biggest structural changes compared with ordinary consumer product review. The question is no longer only whether OpenAI says its controls work; there is a recurring external compliance process around the DSA obligations.
4. Give regulators access to relevant data
The Commission and national authorities can require access to data needed to monitor DSA compliance.
Today's press release also says the designation gives the Commission investigative powers to assess the functionalities behind ChatGPT and, where applicable, related systems. Supervision will be carried out with Ireland's Coimisiún na Meán, the relevant Digital Services Coordinator for ChatGPT's EU establishment.
5. Enable vetted research into systemic risks
The DSA creates a route for qualified researchers to request access to data needed to study systemic risks and the effectiveness of mitigation measures.
Researchers do not receive unrestricted access simply because they ask. The EU's data-access framework includes vetting requirements around research affiliation, independence, security, confidentiality and the necessity of the requested data.
For AI services, this could become one of the more consequential parts of the regime because independent researchers have historically had limited visibility into large commercial systems beyond public interfaces and voluntary disclosures.
6. Meet enhanced transparency requirements
The Commission's general VLOP/VLOSE guidance includes transparency around areas such as advertising, recommender systems and content-moderation decisions, plus a public advertisement repository and non-profiling recommendation options where those systems are relevant.
Not every traditional platform feature maps neatly onto a chatbot. That is exactly why the implementation details matter more than a generic checklist copied from social media.
The DSA sets the obligation. How a conversational AI search service satisfies the relevant parts is what to watch over the next four months.
What will an ordinary ChatGPT user notice?
Possibly very little immediately.
The designation date and the user-visible product-change date are not the same thing.
A sensible expectation is to look for changes in four areas over time:
| Area | What might become more visible | What is not guaranteed by today's decision |
|---|---|---|
| Transparency | Clearer explanations, reports, disclosures or DSA-specific documentation | A complete public description of every model or safety system |
| Safety and minors | Additional safeguards if OpenAI adopts them as part of risk mitigation | A specific age gate or feature removal announced today |
| Search / recommendation design | Changes where the DSA's algorithmic transparency or choice rules apply | A requirement that ChatGPT rank every answer in one prescribed way |
| Advertising | DSA transparency mechanisms where ads are served | Removal of advertising or a ban on ChatGPT's ad business |
The distinction is useful because regulation headlines often collapse obligation, implementation, and user-visible effect into one event. They are three different stages.
What does not happen because ChatGPT became a VLOSE?
ChatGPT is not automatically found in breach
Designation is not an enforcement judgment. The Commission is saying that ChatGPT meets the legal type and scale threshold for enhanced supervision.
A non-compliance decision would require a separate process.
The EU is not approving individual answers
The DSA creates obligations on the service provider. It does not turn the European Commission into an editor that pre-approves every response generated for an EU user.
ChatGPT does not have to disappear from Europe
There is no shutdown order in the August 31 designation. The Commission gives the service four months to meet the additional obligations.
The DSA does not replace the EU AI Act
This is an especially important distinction.
The DSA regulates online intermediary and platform/search services, with extra systemic-risk obligations at very large scale.
The AI Act separately sets rules for AI systems and general-purpose AI model providers, including transparency, copyright and—in the case of the most capable models with systemic risk—additional safety and security obligations.
ChatGPT can therefore sit under the DSA as a service while OpenAI also has AI Act responsibilities as an AI provider. One framework does not cancel the other.
The strongest signal is not the 45-million threshold—it is the "hybrid service" reasoning
The user threshold explains when ChatGPT entered the highest DSA tier. The Commission's service classification explains something more durable: how an AI assistant can enter the search-engine regulatory perimeter at all.
The logic can be reduced to two questions:
Does the AI service perform online-search functionality?
↓ yes
Can it qualify as an online search engine under the DSA?
↓ yes, according to today's ChatGPT designation
Has it reached the VLOSE scale threshold?
↓ yes
Enhanced DSA duties apply after the compliance window
That creates a useful framework for watching other AI assistants.
It does not mean every chatbot is automatically a VLOSE. A service still has to fall within the relevant DSA category and reach the scale threshold before the Commission can designate it at this level.
But the decision makes clear that "it's an AI chatbot" is not, by itself, a reason the search component sits outside the DSA.
What can happen if a VLOSE does not comply?
The Commission is the primary supervisor for VLOPs and VLOSEs and has investigative and sanctioning powers under the DSA.
Its current enforcement guidance says a confirmed non-compliance decision can lead to fines of up to 6% of the provider's global annual turnover, with the amount depending on factors such as the nature, gravity, recurrence and duration of the infringement.
That is a statutory maximum, not a fine imposed on OpenAI today.
The difference matters enough to repeat: August 31 is a designation and the start of an enhanced-compliance period, not an announcement that OpenAI owes a percentage of revenue.
A four-month watchlist
Instead of guessing which feature will change, watch for evidence in this order.
1. OpenAI's DSA compliance documentation
Look for an updated transparency or regulatory page explaining how the company interprets the VLOSE obligations for ChatGPT specifically.
2. The first VLOSE risk-assessment disclosures
The Commission says the four-month compliance period includes the additional systemic-risk duties. The scope OpenAI gives to risks involving search, generated answers, minors, wellbeing, fundamental rights and elections will show how the company translates traditional DSA concepts into conversational AI.
3. Independent-audit information
An audit provides a stronger signal than a product announcement because it asks whether the required systems and processes actually satisfy the legal framework.
4. Researcher-access implementation
Watch how researchers can request data relevant to ChatGPT's systemic risks, what data types are considered necessary, and what confidentiality or security constraints apply.
5. Any user-interface changes tied explicitly to DSA compliance
If search controls, transparency labels, ad information, safety features or account protections change, look for a direct explanation from OpenAI or the Commission before assuming the DSA caused the change.
That last rule is worth keeping: correlation with the four-month window is not proof of regulatory causation.
Conclusion
ChatGPT's August 31 designation is important, but not because the EU suddenly decided to regulate every AI answer as a search result.
The more precise development is this:
The European Commission has decided that ChatGPT's hybrid prompt-and-web-search service qualifies as an online search engine under the DSA, and its EU scale is now large enough for VLOSE status.
That starts a four-month compliance clock for enhanced systemic-risk, audit, transparency and data-access duties. It also gives the Commission stronger direct supervisory and investigative powers over the service.
For users, there is no single switch to look for tomorrow. The meaningful evidence will arrive in the implementation: what risks OpenAI identifies, what mitigation it adopts, what independent audits reveal, how researcher access works, and which product changes OpenAI explicitly ties to DSA compliance.
The bigger long-term lesson is that conversational AI and search are no longer cleanly separate regulatory categories in Europe. Once an AI assistant becomes a web-search interface at very large scale, the EU has now shown which rulebook it is prepared to use.
Sources
Checked August 31, 2026:
- European Commission — Commission designates ChatGPT, Reddit, Roblox under Digital Services Act
- European Commission — Full August 31 designation press release (PDF)
- European Commission — DSA: Very large online platforms and search engines
- European Commission — Digital Services Act questions and answers
- European Commission — DSA enforcement framework
- European Commission — DSA transparency and researcher data access
- European Commission — EU AI Act overview
- Reuters — ChatGPT, Reddit, Roblox to adhere to EU's "very large" rules