Evidence note. Last checked 1 September 2026 at 02:16 BST. The immediate effect is a compliance timetable rather than a service restriction, but the governance consequence is material: ChatGPT is now within the Digital Services Act’s strictest supervision tier as a very large online search engine. The designation does not establish that ChatGPT is unsafe, and it is separate from the EU AI Act.
The European Commission designated ChatGPT a Very Large Online Search Engine, or VLOSE, on 31 August 2026. OpenAI now has four months, by January 2027, to meet the additional duties that apply to services used by at least 45 million people a month in the European Union.
The decision matters because it moves AI-mediated search into the same systemic-risk framework used for the EU’s largest digital intermediaries. The Commission will expect evidence about risks to fundamental rights, minors, elections, public security, health and well-being—not only evidence that individual answers are accurate or that a model passed a pre-release evaluation.
OpenAI reported approximately 159.1 million average monthly active recipients of ChatGPT search in the EU during the six months ending 31 March 2026. That figure is specifically a Digital Services Act measurement for the search service; it should not be read as a complete count of every ChatGPT user or every conversational feature.
Independent coverage by Search Engine Journal corroborated the designation, the recipient figure and the four-month compliance window. It also described ChatGPT as the first AI chatbot to receive this designation, illustrating why the decision is more than a routine threshold update.
What the designation establishes
The DSA applies its most demanding obligations to platforms and search engines above the 45-million-recipient threshold. The Commission’s guidance for very large platforms and search engines requires them to identify, analyse and assess systemic risks arising from the design and operation of their services. They must take proportionate measures to mitigate those risks, maintain an internal compliance function and submit to an independent annual audit.
Other duties include giving regulators access to relevant data, enabling vetted researchers to study systemic risks, maintaining transparency around moderation and recommender systems, and providing a recommendation option that is not based on profiling. The practical interpretation of some of these duties for generative search is not yet settled, but the regulatory direction is clear: a service that selects sources, ranks information and synthesises an answer at this scale cannot be governed only as a sequence of private conversations.
The designation is not a finding that OpenAI has breached the law. Nor does it classify ChatGPT as a high-risk system under the EU AI Act. Artificially Confident’s earlier analysis described how the AI Act is becoming an operational-readiness test; this is a different legal route. The DSA focuses on the systemic effects of intermediary services, including how information is distributed and how service design affects people and society.
The regulatory perimeter has moved
Traditional search governance can inspect an index, a ranking process and the results shown to users. Generative search adds another layer. It may retrieve multiple sources, select among them, combine their claims, omit qualifications and present a fluent synthesis that users experience as a single answer. The path from source to conclusion is therefore both a search process and a model-mediated editorial process.
An academic analysis published before the designation described ChatGPT as a hybrid between search and platform. That characterisation is analysis rather than the Commission’s legal reasoning, but it explains the governance problem well. Risks can arise from which sources are retrieved, how they are ranked, what the model infers from them, which citations are displayed and how confidently uncertainty is communicated.
This creates a broader evidence requirement than a conventional accuracy benchmark. OpenAI will need to show how service changes affect systemic risks and how mitigations work in practice. That may include changes to source selection, ranking, synthesis, citations, personalisation, safety routing, election-related responses and protections for minors. A model or interface update that appears modest at product level could materially alter the information environment experienced by millions of people.
The operational and governance consequence
The useful lesson extends beyond OpenAI. Organisations building or procuring AI search should treat the answer-generation chain as a governed service, not a hidden implementation detail. At minimum, accountable teams should be able to trace:
- which sources were eligible, retrieved and excluded;
- how ranking, personalisation and safety rules shaped the evidence presented to the model;
- which model and prompt configuration produced the answer;
- how citations, uncertainty and conflicting evidence were displayed;
- how users can report illegal or harmful content and obtain a review; and
- which changes require a new risk assessment, independent testing or executive approval.
This is the same operating principle behind Artificially Confident’s argument that AI transparency is a workflow, not a label. A disclosure that an answer was AI-generated is not enough. Meaningful assurance depends on preserving the decision route from source retrieval to generated output, recording interventions and demonstrating that review and appeal mechanisms can change an outcome.
The DSA’s audit and researcher-access requirements also make data architecture a governance issue. Evidence cannot be reconstructed reliably after the fact if source selection, ranking decisions, model versions and moderation interventions were never recorded. Teams need retention rules that preserve useful accountability evidence while respecting privacy, security and data-minimisation duties.
What remains unresolved
The Commission’s announcement does not yet answer every scope question. The public designation concerns ChatGPT as a very large online search engine, while OpenAI’s published recipient figure is specifically for ChatGPT search. Further legal and technical detail will be needed to show how the obligations apply across the search experience and its interaction with broader conversational functions.
There are also open implementation questions. A non-profiled recommendation option has an established meaning for feeds and marketplaces, but its application to a generated answer is less obvious. Vetted researcher access may need to cover retrieved sources, ranking signals and outputs without exposing personal prompts, security controls or proprietary data. Independent auditors will need methods that can evaluate a changing model-and-search system rather than a static algorithm.
These uncertainties are reasons for disciplined preparation, not for inflated conclusions. The designation does not mean every inaccurate answer is a DSA breach, and the four-month timetable does not guarantee that all systemic risks can be eliminated. It does mean that risk identification, mitigation evidence and independent scrutiny must become recurring operating processes.
What to watch and do next
The next important evidence will be the detailed designation decision, Commission guidance on generative search, OpenAI’s first systemic-risk assessment and the audit and transparency material that follows. It will also be worth watching how the Commission distinguishes the search service from other ChatGPT functions and how it interprets researcher access and non-profiled recommendations.
AI product leaders do not need to wait for enforcement. They can map the full source-to-answer route now, assign ownership for each control, preserve version and change evidence, test reporting and appeal routes, and require a documented risk review before changes that affect reach, ranking or synthesis. The Commission’s decision is not an emergency. It is a clear signal that AI search at population scale is becoming regulated information infrastructure—and that fluent answers must be backed by inspectable governance.

