All stories
AI

EU Designates ChatGPT as 'Very Large Online Search Engine' Under DSA

The European Commission's classification of ChatGPT as a VLOSE under the Digital Services Act marks a critical regulatory precedent for standalone AI services, imposing stringent new obligations on OpenAI.

By TECH NEWS Editorial·Source:The Verge AI·4 min read·34m ago

This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more

Share

Listen to this story

0:00 / 0:00
EU Designates ChatGPT as 'Very Large Online Search Engine' Under DSA

The European Commission officially designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the Digital Services Act (DSA) on August 31, 2026, marking a significant regulatory milestone as the first standalone AI service to be subjected to the bloc's most stringent online rules. This classification, alongside Reddit and Roblox being designated Very Large Online Platforms (VLOPs) on the same day, stems from ChatGPT reporting 159.1 million monthly active users in the EU over the six months ending March 2026, far exceeding the DSA's 45 million user threshold for enhanced oversight. The Commission categorized ChatGPT as a "hybrid service" because its web search functionality can engage with and respond to user queries by searching the web, thus qualifying it as an online search engine. This designation means OpenAI now has a four-month deadline, until January 2027, to comply with a comprehensive set of additional obligations aimed at mitigating systemic risks inherent in its service.

This designation fundamentally alters the operational landscape for OpenAI within the EU and sets a critical precedent for the burgeoning generative AI industry. The core of these new obligations centers on assessing and mitigating systemic risks related to the dissemination of illegal content, negative effects on minors, users' physical and mental well-being, fundamental rights, electoral processes, and public security. Unlike traditional search engines that primarily index and link to existing content, ChatGPT generates its own responses, presenting unique challenges for risk assessment and moderation. For instance, OpenAI will need to adapt ChatGPT's systems, design, features, and functioning based on assessed risks, and conduct annual systemic risk assessments, with additional assessments triggered by new functionalities likely to have a "critical impact" on these risks. This could involve more stringent content moderation, age verification mechanisms, and enhanced transparency regarding how its algorithms generate and moderate outputs, aspects not explicitly covered by the separate AI Act. Furthermore, OpenAI will be required to submit to independent audits and provide data access to regulators and vetted researchers, a particularly contentious area given the commercial sensitivity of AI training data and model weights.

The impact on users will likely manifest as a more curated and potentially safer online experience, particularly for vulnerable groups like minors. Stricter content moderation could reduce exposure to illegal or harmful content, though it also raises questions about potential over-censorship or limitations on freedom of expression. For the industry, this move by the EU sends a clear signal that large-scale AI models, especially those with search functionalities, will not operate in a regulatory vacuum. The DSA’s enforcement, which can levy fines up to 6% of a company's global annual turnover for serious infringements, underscores the gravity of these obligations. This financial penalty, potentially running into billions for major tech companies, serves as a powerful incentive for compliance. The DSA has already resulted in significant fines, including €550 million against AliExpress and €200 million against Temu, demonstrating the Commission's resolve.

Historically, the DSA, which became generally applicable in 2024, was primarily envisioned for traditional social media platforms and online marketplaces. Its application to a generative AI model like ChatGPT, classified as a VLOSE alongside Google's Chrome and Microsoft's Bing, highlights the evolving nature of digital services and the EU's proactive approach to regulating emerging technologies. While other major AI models like Google's Gemini or Anthropic's Claude have not yet received this specific designation, the Commission's explicit statement that it will "not hesitate to designate any platform that meets the threshold for enhanced supervision" suggests that similar designations are likely as these services grow in user base. This creates a competitive dynamic where AI developers must now factor robust risk mitigation and transparency into their core product development, particularly for services targeting the EU market.

Looking ahead, the interplay between the DSA and the EU's Artificial Intelligence Act (AI Act) will be crucial. While the DSA governs the intermediary services through which information circulates, the AI Act, which became applicable for most rules on August 2, 2026, regulates the AI systems themselves. The AI Act introduces a risk-based approach, with stricter obligations for "high-risk" AI systems and specific transparency and copyright rules for General-Purpose AI (GPAI) models, which became applicable in August 2025. For instance, providers of generative AI under the AI Act must ensure AI-generated content is identifiable and clearly labeled, especially deepfakes and public interest texts. The DSA's systemic risk assessments are now expected to integrate any AI systems or models deployed on or as part of the platform, requiring a coordinated approach to compliance. This dual regulatory framework, while complex, aims to create a comprehensive safety net for AI within the EU, potentially influencing global AI governance standards. The next few months will reveal how OpenAI operationalizes these new DSA obligations and how the Commission enforces them, setting a critical precedent for the future of AI development and deployment worldwide.