The European Commission has designated ChatGPT a Very Large Online Search Engine, or VLOSE, under the EU’s Digital Services Act, extending the bloc’s most demanding online-service rules to a leading generative-AI product. The August 31 designation puts ChatGPT in the DSA’s highest oversight tier alongside major platforms and search engines; Reddit and Roblox were designated as Very Large Online Platforms in the same announcement. (digital-strategy.ec.europa.eu)

The designation means OpenAI has four months to comply with the additional VLOSE requirements, with the Commission’s notice setting the deadline in January 2027. Those duties focus on identifying and reducing systemic risks linked to a service and its algorithmic systems, including the spread of illegal content, harms to minors, risks to users’ physical and mental well-being, effects on fundamental rights, electoral processes and public security. (digital-strategy.ec.europa.eu)

For ChatGPT, the significance is not simply that the service has crossed a large-user threshold. It is that an AI assistant is now being supervised through a framework built to address how large digital services shape the information people encounter and the risks that can result at scale. The Commission said the newly designated services had declared at least 45 million average monthly users in the EU, the threshold for this category. (digital-strategy.ec.europa.eu)

OpenAI’s own DSA information says ChatGPT search averaged approximately 159.1 million monthly active recipients in the EU during the six months ending March 31, 2026. The company describes that calculation as one made for DSA compliance purposes and says it should not be used for other purposes. The figure helps explain why the Commission has treated the service’s search capability as subject to the DSA’s very-large-search-engine regime. (help.openai.com)

What the higher-tier rules require

The DSA requires VLOSEs to carry out risk assessments and put mitigation measures in place. The Commission’s guidance also lists obligations including readable, multilingual terms and conditions and a crisis-response mechanism. The practical task for OpenAI will be to show regulators that its processes can identify material risks arising from ChatGPT’s operation and that its safeguards are proportionate to those risks. (digital-strategy.ec.europa.eu)

That matters because the DSA’s risk framework is broader than a narrow illegal-content takedown regime. In the Commission’s formulation, the assessment must reach potential effects on children, health and well-being, civic and electoral systems, public security and fundamental rights. For a conversational AI product, those questions can involve both what a system returns to users and how product features affect access to, presentation of or interaction with information. (digital-strategy.ec.europa.eu)

The enhanced regime also increases external scrutiny. VLOPs and VLOSEs are subject to independent audits, and the DSA establishes data-access obligations for researchers studying systemic risks. The European Commission’s algorithmic-transparency center says designated services must provide researchers access to publicly accessible data without undue delay, while access for vetted researchers is a legal obligation under the DSA. (digital-strategy.ec.europa.eu)

OpenAI already publishes DSA compliance information, including routes for users to report illegal content and points of contact for EU users and authorities. Its public guidance says reports may lead to removal, restriction or other action under applicable law and its policies. Those measures predate the new designation, but the VLOSE status adds a more formal systemic-risk and supervisory layer to OpenAI’s European operations. (help.openai.com)

Direct Commission supervision and enforcement risk

The Commission directly supervises compliance by VLOPs and VLOSEs, while national Digital Services Coordinators have defined roles within the broader enforcement system. The designation is not itself a finding that ChatGPT has violated the DSA. Rather, it changes the set of obligations that apply to the service and gives the Commission a stronger basis to examine whether those obligations are being met. (digital-strategy.ec.europa.eu)

If the Commission finds non-compliance, the DSA provides for investigative and sanctioning measures. The Commission says it can impose fines of up to 6% of a provider’s worldwide annual turnover for breaches of DSA obligations, subject to the regulation’s enforcement process and potential review by EU courts. (digital-strategy.ec.europa.eu)

The move also supplies a concrete example of how European platform regulation is being applied to generative AI without creating a separate DSA category for chatbots. For builders and companies deploying AI systems in Europe, the immediate legal duties fall on the designated service. But the decision signals that conversational interfaces with large EU reach—and especially those that function as gateways to information—can face platform-style governance expectations alongside AI-specific regulation.

That makes the next four months consequential for OpenAI. The core compliance question will be whether its published safety, reporting and transparency systems can be demonstrated to meet the DSA’s higher bar for assessing and mitigating systemic risks at the scale of ChatGPT’s European audience. The Commission’s designation ensures that question will now be examined within one of the EU’s strongest digital-services enforcement frameworks. (digital-strategy.ec.europa.eu)