On 31 August 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act. The acronym is VLOSE. The threshold is at least 45 million average monthly users in the European Union. ChatGPT declared that it meets that threshold. Following notification, the Commission says the service has four months to comply with the additional obligations that apply to the largest platforms and search engines.
The legal consequence matters. The category shift may matter even more.
ChatGPT entered the market as a conversational model interface. People now use it to research products, compare options, interpret documents, navigate unfamiliar subjects and decide what to do next. Europe is beginning to regulate that behavior not only as the output of an AI system, but as large-scale search and information infrastructure.
That does not make ChatGPT identical to a conventional search engine. It does mean the interface has crossed a threshold where its systems can create risks at societal scale. For product teams, the useful question is no longer whether chat will replace a search box. It is what changes when a conversational answer becomes an important route to information, discovery and action.
What changed?
The Commission designated ChatGPT as a VLOSE under the DSA. In the same announcement, Reddit and Roblox were designated Very Large Online Platforms, or VLOPs. The distinction is deliberate: the Commission placed ChatGPT in the search-engine category, not the platform category used for the other two services.
The designation is based on reach. The services declared at least 45 million average monthly users in the EU, the DSA threshold for very large services. It is not a finding that ChatGPT has violated the law. It is a formal classification that activates an additional layer of obligations and direct Commission supervision.
The Commission’s notice says the additional obligations include assessing and mitigating systemic risks arising from the service and its algorithmic systems. It identifies risks connected to illegal content, negative effects on minors, physical and mental wellbeing, fundamental rights, electoral processes and public security.
The clock now matters. The Commission says the services have four months following notification to comply with those additional obligations. The official English notice describes that as “by the end of November 2026”; a French Commission representation page describes the endpoint as the end of December. That inconsistency should not be hidden. The operative notification and any formal decision should be treated as authoritative before publishing an exact deadline beyond “four months after notification.”
Why now?
FIG. 01
From AI product to information infrastructure
Methodology · Zerionia synthesis from the European Commission designation and Regulation (EU) 2022/2065
Scale is the immediate answer. A service above the DSA threshold does not become important because regulators call it important. The designation follows the audience.
The product answer is more revealing. ChatGPT is increasingly used before a user reaches another destination. It can summarize a market, explain a regulation, compare products, recommend a process and generate a plan inside one interface. OpenAI is also building an advertising system around moments when people research, compare and decide. Those developments do not prove that conversational systems replace web search, but they show why the boundary is becoming harder to maintain.
Traditional search exposes a list of sources and lets the user assemble an answer. A conversational interface often assembles the answer first and makes source inspection a secondary action. That changes where trust is placed. It changes which mistakes become visible. It changes the role of ranking, citation, provenance, commercial placement and user control.
The DSA designation is therefore not only about model output. It concerns the whole service: the algorithms that select and present information, the mechanisms that identify and mitigate risk, and the product controls through which users understand and challenge what the system does.
What does VLOSE actually mean?
FIG. 02
ChatGPT at the intersection of two legal layers
01
AI Act
Focus: AI systems and models. Product concern: model/system requirements, transparency and AI-specific obligations.
02
Digital Services Act
Focus: online services and information distribution. Product concern: service governance, systemic risks, mitigation and supervision at scale.
Methodology · Zerionia synthesis from EU primary legal and designation material
VLOSE means “Very Large Online Search Engine.” It is a DSA category, not an AI Act category and not a Digital Markets Act gatekeeper designation. The terms cannot be used interchangeably.
The DSA creates baseline duties for intermediary services and additional duties for designated VLOPs and VLOSEs. At the very-large-service layer, the Commission highlights systemic-risk assessment and mitigation. The broader DSA framework also covers independent auditing, transparency, access to data for vetted researchers under defined conditions, and crisis-response mechanisms. The precise application to ChatGPT should be described from the designation decision and subsequent compliance material rather than inferred from another service’s implementation.
The designation does not mean every answer becomes legally certified. It does not mean the Commission approves or ranks individual responses. It does not transform the DSA into a truth regulator. It establishes obligations around how a service of this scale identifies, evaluates and mitigates systemic risks.
It also does not replace the AI Act. The AI Act addresses AI systems and models through a different legal structure. The DSA addresses the responsibilities of online intermediary services, including the largest platforms and search engines. ChatGPT can be relevant to both regimes for different reasons.
Why the search classification matters
Categories shape product expectations.
If a system is treated primarily as a chatbot, the product conversation tends to focus on conversational quality: whether responses are helpful, natural and accurate. If it is treated as search infrastructure, other questions move to the center. How does information enter the answer? Which sources are surfaced? Can users recognize uncertainty? How are commercial results separated? What happens when the system repeatedly directs attention toward or away from a class of information? How can an outside researcher study systemic behavior without receiving private conversation data?
These questions existed before the designation. The classification makes them harder to treat as optional polish.
Search infrastructure creates power by organizing access. Conversational search adds another layer because the system does not merely order links; it compresses them into a response. Compression is useful. It can also hide disagreement, remove context and make a synthetic conclusion feel more settled than the underlying material.
The product challenge is not to make every answer longer. It is to create legible trust surfaces: citations that are useful rather than decorative, uncertainty that appears where it changes a decision, commercial content that remains visibly separate, and controls that allow a user to inspect or correct the path.
What changes for product design?
First, provenance becomes interface infrastructure. A source link at the bottom is not enough if the user cannot tell which claim it supports. Product teams need a relationship between assertion, evidence and confidence that survives the conversational format.
Second, risk controls need to operate across sessions and systems, not only at the prompt boundary. A single answer can look harmless while a repeated pattern creates a societal effect. That is why systemic-risk language matters: it pushes evaluation beyond isolated failure examples.
Third, user agency must be visible before a crisis. Reporting, correction, personalization controls and explanations cannot remain buried in settings if they are part of the mitigation model.
Fourth, advertising separation becomes part of information quality. OpenAI says ads do not influence answers and are clearly labeled. As the ad platform gains targeting, optimization and new formats, maintaining that distinction is a continuing product task, not a one-time policy statement.
Finally, research access and privacy must coexist. Large-scale scrutiny is necessary, but conversational data can be deeply personal. The strongest implementation will make it possible to evaluate systemic effects without treating private dialogue as an unrestricted research dataset.
What is confirmed
The European Commission announced the designation on 31 August 2026.
ChatGPT was designated a VLOSE, while Reddit and Roblox were designated VLOPs.
The services declared at least 45 million average monthly users in the EU.
The Commission says the additional duties apply four months after notification.
The Commission explicitly names systemic risks involving illegal content, minors, wellbeing, fundamental rights, elections and public security.
What remains uncertain
The public announcement does not explain exactly how every DSA duty will be implemented in a conversational interface. It does not settle which evaluation methods will be considered sufficient, how research access will work for this service, or how the Commission will assess the separation between generated answers and an expanding advertising system.
The exact compliance date should be confirmed against the formal notification because Commission pages currently describe the end point inconsistently while agreeing on the four-month period.
It is also too early to claim that the designation legally defines every general-purpose assistant as a search engine. This is a designation of ChatGPT based on the service, its function and its scale.
What happens next?
The next useful evidence will not be another press release repeating the label. It will be implementation: OpenAI’s risk assessments and mitigation choices, the Commission’s explanation of scope, any audit or researcher-access framework, and visible changes to citations, reporting, controls or commercial separation.
Zerionia should track those changes in the AI Transparency Radar. A new article is justified only when the evidence reveals a durable product pattern. Smaller changes belong in the Radar and the Transparency Checker.
Zerionia view
The important development is not that Europe has discovered chatbots. It is that a conversational interface has become important enough to be treated as information infrastructure.
That transition changes the product brief. Helpfulness is no longer sufficient. The service must make provenance, uncertainty, commercial boundaries and recourse work at scale. The teams that solve this well will not bolt compliance labels onto an answer. They will design a search-quality system for an interface that no longer looks like search.
