ChatGPT did not receive a fine on August 31. It received a classification: the European Union now treats its search function as large enough to carry the Digital Services Act’s heaviest platform duties.
The European Commission designated ChatGPT a VLOSE, short for Very Large Online Search Engine. OpenAI reported at least 45 million average monthly users in the EU, which meets the legal threshold. The company now has four months, through the end of November 2026, to meet the additional DSA obligations attached to that status.
This is not a finding that ChatGPT broke the law. It is the point where scale creates a stronger compliance job. That distinction matters because regulation stories often get flattened into either “Europe banned AI” or “nothing changes.” Neither reading is useful.
Why ChatGPT is being treated as search
People increasingly use ChatGPT to find sources, compare products, summarize current events, and choose what to do next. The Commission’s designation focuses on that online-search function under the Digital Services Act.
The threshold is not a subjective judgment about influence. ChatGPT declared at least 45 million average monthly EU users. Once a service reaches that scale and falls within the covered category, the Commission can designate it for the additional VLOSE regime.
| Question | Verified position | Responsible reading |
|---|---|---|
| Was ChatGPT designated? | Yes, as a Very Large Online Search Engine | The DSA’s additional obligations now apply after the compliance window |
| Why did it qualify? | ChatGPT declared at least 45 million average monthly EU users | This is the statutory scale threshold reported by the service |
| When is the deadline? | Four months, through the end of November 2026 | OpenAI must build and document the required controls during that window |
| Was a violation proven? | No violation finding appears in the designation notice | Designation creates duties and supervision; it is not a penalty |
The DSA and AI Act ask different questions
Europe now has two rulebooks that can touch the same product. The AI Act focuses on AI systems and models: what they are, how particular uses are classified, and what providers or deployers must disclose or control. The DSA focuses on online intermediary services and the systemic risks created when those services reach very large audiences.
| Regime | Primary object | Question for ChatGPT |
|---|---|---|
| Digital Services Act | The large online service and its algorithmic systems | What systemic risks arise when search, recommendations, ads, and distribution operate at EU scale? |
| AI Act | The AI system, model, provider, and covered deployment | What transparency, safety, documentation, or use-specific duties apply to the AI? |
That separation is more than legal housekeeping. A model card cannot answer every question about search ranking, advertising, citations, user reporting, or the distribution of harmful material. Conversely, a platform transparency report does not replace model evaluation.
Four control surfaces now matter
1. Systemic-risk assessment
The Commission specifically names risks involving illegal content, minors, physical and mental wellbeing, fundamental rights, elections, and public security. OpenAI will need to identify how ChatGPT’s service and algorithmic systems can create or amplify those risks, then document mitigation.
2. Independent scrutiny
The VLOSE regime adds outside accountability, including independent auditing under the DSA framework and Commission supervision. The useful artifact is not a broad safety promise. It is evidence that names the risk, control, test, failure rate, owner, and remediation deadline.
3. Search and recommender transparency
ChatGPT can decide which sources to cite, which products to surface, and how to order an answer. Those choices are not identical to a classic ranked list, but they still shape discovery. Builders should expect more attention on ranking parameters, user controls, advertising separation, and the evidence behind citations.
4. Access for oversight
The DSA gives regulators and vetted researchers routes to examine very large services. The hard part for a conversational search product will be providing useful access without exposing private conversations, security-sensitive systems, or personal data. Those tensions should appear in the access design rather than being buried in a policy page.
What changes for builders using ChatGPT
The designation is directed at OpenAI’s service, not every developer who calls an API. A small SaaS product does not become a VLOSE because it uses a ChatGPT model. Still, downstream teams should expect product and documentation changes that can affect integrations.
- Search and citation behavior may gain clearer controls or disclosures.
- Reporting, appeals, and user-notice flows may become more visible.
- Advertising and recommendation surfaces may carry stronger separation and transparency requirements.
- Logs and research-access processes may change to support audits without exposing private data.
- Country-specific availability or defaults may shift while OpenAI implements the EU controls.
If your product depends on ChatGPT’s connected accounts, preserve the user identity and source behind every action. Our analysis of multiple Google accounts in one ChatGPT conversation explains why source attribution cannot be reconstructed reliably after the fact.
Build your own evidence pack before November
- Inventory the dependency. Record whether you rely on ChatGPT Search, citations, recommendations, ads, connected accounts, or API models.
- Capture the current behavior. Save representative prompts, cited sources, ranking outcomes, refusal behavior, and user controls.
- Define a regression set. Include sensitive queries, multilingual searches, commercial recommendations, and requests involving minors or elections where appropriate.
- Preserve provenance. Store the source URL, retrieval date, model or product mode, account context, and any user-selected setting.
- Watch the contract and documentation. The four-month implementation window may change terms, logs, data access, or product defaults.
- Keep a fallback. If a required search or citation behavior changes, know which alternative can meet the same acceptance test.
This is also relevant to commercial discovery. OpenAI’s same-day ChatGPT Ads update says ad selection may use the current conversation and, where settings and country rules permit, broader ChatGPT context. Search oversight and ad oversight now meet in the same interface.
What the designation does not prove
It does not prove ChatGPT has violated the DSA. It does not classify the underlying model as high risk under the AI Act. It does not require every ChatGPT answer to expose a traditional ranking formula. It does not automatically make an API customer responsible for OpenAI’s VLOSE duties.
The Commission will supervise ChatGPT with Ireland’s Coimisiún na Meán. Enforcement conclusions should come from that process, not from guesses based on the designation headline.
My verdict: watch the evidence, not the label
The useful part of the ChatGPT VLOSE designation is the deadline. By the end of November, the public should be able to inspect more than a promise that risks are taken seriously. We should see a traceable map from risk to control to test.
For builders, the immediate job is smaller: document which ChatGPT behavior your product depends on and how you will notice when it changes. Regulation may force better evidence from the platform. It cannot write your acceptance test for you.
Read the primary sources
- Read the European Commission’s ChatGPT VLOSE designation notice.
- Review the Commission’s register and supervision information for designated services.
- Compare the Commission’s AI Act enforcement and transparency notice.
Checked August 31, 2026. The designation, user threshold, compliance window, risk areas, and supervisory arrangement come from the European Commission. This article does not allege a DSA violation.