
EU Executive Vice-President for Tech Sovereignty, Security and Democracy Henna Virkkunen gives a press conference on the Defense Readiness roadmap at the EU headquarters in Brussels on October 16, 2025. NICOLAS TUCAT/AFP via Getty Images
The European Commission's decision to designate ChatGPT as a Very Large Online Search Engine did not just hand OpenAI a compliance deadline — it handed every AI search product in the world a regulatory mirror. The mechanism Brussels used to pull ChatGPT into the Digital Services Act's strictest accountability tier turns on capability, not category, and it scales automatically to any AI assistant that crosses 45 million monthly users in the EU and retrieves live web content. That threshold has already been crossed — almost certainly by Google Gemini, and possibly by others — and Germany's media regulator began applying parallel national law to AI search outputs in July without any user threshold at all.
The August 31 VLOSE designation is the starting gun, not the finish line. For the AI search industry, the more consequential signal is that Brussels has now written the legal template — and it will travel.
When the European Commission designated ChatGPT a VLOSE on August 31, 2026, it placed OpenAI's product in a tier previously occupied by only two services: Google Search and Microsoft Bing. Reddit and Roblox were simultaneously named Very Large Online Platforms, bringing the total of designated services to 28.
The legal trigger was scale: under DSA Article 33(1), any online service reaching at least 45 million average monthly users in the EU — roughly one in ten of the bloc's population — qualifies for designation. ChatGPT shattered that threshold. OpenAI's own disclosure, prepared for DSA compliance purposes and covering the six months ending March 31, 2026, put ChatGPT's EU user count at approximately 159.1 million monthly average users — more than three and a half times the designation threshold, and still less than half of Google Search's declared 364 million EU users, according to the Commission's designation registry.
Reddit reported approximately 57.2 million monthly EU users and Roblox approximately 46.6 million for the same period. All three services cleared 45 million before Brussels acted.
"ChatGPT, Reddit and Roblox will now be held to a higher standard of scrutiny and accountability in the European Union, in line with their large impact on our citizens and society," said Henna Virkkunen, the Commission's executive vice-president for tech sovereignty, security and democracy. "We continue to watch the digital landscape closely and will not hesitate to designate any platform that meets the threshold for enhanced supervision under the Digital Services Act."
That last sentence is the more significant one.
The Commission described ChatGPT as a "hybrid service": it operates as a conversational assistant, but because it responds to user queries by actively searching the web and synthesizing results, it functionally behaves like a search engine. Brussels applied the VLOSE label, not the VLOP label, because the product retrieves and presents information from the live web in response to user queries — the defining characteristic of a search intermediary.
What the Commission did not say — but what every AI company's legal team will have noted — is that the classification is architecture-agnostic. It is not about whether a product calls itself a chatbot, an assistant, or a search engine. It is about whether the product has a web-retrieval function and whether enough European users use it. The same logic reaches Gemini, Perplexity's core product, and Anthropic's Claude when web browsing is enabled.
"The VLOSE classification turns on ChatGPT's live web-search function, not its AI product category, giving regulators a capability-based template to extend to Gemini, Claude, and Perplexity as they scale," AI Weekly analyst Alexis Dufresne wrote in analysis of the designation.
The relevant user base numbers are instructive. Google Gemini's standalone app reached 900 million monthly users globally at Google I/O 2026 in May, up from approximately 400 million a year earlier — and separately, Google's AI Mode surpassed 1 billion monthly users worldwide. Europe accounts for a substantial portion of Google's user base; even a conservative 15 percent EU share of Gemini's app users would put it above 100 million — well past the 45 million VLOSE threshold. Gemini is already a designated VLOSE via Google Search, but the standalone Gemini app has not yet received its own designation.
Perplexity presents a different picture. Its global monthly active user count is itself contested — estimates from mid-2026 range from approximately 45 million to as high as 230 million depending on methodology and whether agent products are included. Europe accounts for roughly 24 percent of Perplexity's traffic by some third-party estimates. At the lower end of the global range, Perplexity's EU user base likely falls below the 45 million VLOSE threshold today; at the upper end, it would already qualify. The uncertainty itself illustrates the transparency gap the DSA is designed to close: Perplexity has not published EU-specific user figures.
For Anthropic's Claude — which held 8.2 percent of chatbot web traffic globally as of mid-2026 — the path to 45 million EU monthly users is present but not yet clearly met.
Read more: Germany Strips AI Search of Its EU Liability Shield in World's First Media Ruling
While the European Commission's VLOSE designation is the EU-level story, a parallel and in some ways more aggressive track has been running at the national level since July. On July 14, 2026, Germany's Commission for Licensing and Supervision (ZAK), which coordinates the country's 14 state media authorities, ruled against Google and Perplexity — finding that AI-generated search outputs are subject to Germany's State Media Treaty.
ZAK Chairman Dr. Thorsten Schmiege put it plainly: "AI search engines and chatbots are content providers, and we are now consistently applying German media law to them." Regulators found AI responses constitute content created by providers themselves — not neutral hosting of third-party material. That matters legally because the EU's standard platform liability exemption, which has protected internet intermediaries from liability for third-party content for two decades, does not apply to content the provider itself generates.
The ZAK rulings were immediately enforceable. Germany's regulators concluded that Google's AI Overviews give Google's own synthesized content prime placement above traditional search results, effectively discriminating against third-party journalistic sources. For Perplexity, regulators found that its selection and presentation of sources alongside AI-generated answers makes it a media intermediary subject to plurality and transparency rules.
This track matters for the broader regulatory picture in two ways. First, it demonstrates that AI search regulation does not require the DSA's 45 million user threshold — German media law applies to any AI service meeting the legal definition of a content provider, regardless of scale. Second, it shows that the regulatory logic the Commission used for the VLOSE designation — "AI-generated answers are a form of editorial authority over information" — is being adopted independently by national regulators.
Read more: ChatGPT Becomes First AI Chatbot Designated as Search Engine Under EU Law
The compliance obligations that come with VLOSE designation are not paperwork. They are a set of engineering, legal, and organizational infrastructure requirements that OpenAI must build by January 2027.
The most demanding is the systemic risk assessment: under DSA Articles 34 and 35, OpenAI must annually document systemic risks from ChatGPT's service and its algorithmic systems, and what the company has done to reduce those harms. The six named categories — illegal content, harms to minors, damage to users' mental and physical health, violations of fundamental rights, threats to electoral processes, and public security risks — are not aspirational checklists. They are the basis for the independent third-party audit that must follow each risk assessment, and for the researcher data-access program available to vetted academics studying ChatGPT's EU-user impacts.
Then there is the technical problem. DSA Article 27 requires VLOSEs to disclose the "main parameters" of their recommender and ranking systems and explain why certain results are surfaced. For Google Search, this is a demanding but conceptually coherent obligation: traditional search ranking parameters are identifiable and describable, even if the full algorithm is proprietary.
For ChatGPT, the obligation runs into an architectural wall. A transformer-based large language model does not retrieve search results through a ranking algorithm with auditable parameters. It generates answers through attention mechanisms and probabilistic next-token sampling — a process in which billions of learned weights interact without any interpretable "ranking" of sources or claims. "Recommendation algorithm transparency means an AI provider needs an auditable account of why the model surfaces one response over another — a question that current transformer architectures answer poorly by default," as one technical legal analysis noted.
The Freshfields DSA analysis notes that the algorithmic transparency requirement for search engines focuses on "recommender systems" — but that this concept's applicability to LLMs is genuinely unsettled. The Commission has not yet published guidance on how to interpret VLOSE transparency obligations for LLM-based services. OpenAI will need to either produce documentation at a level of specificity current AI product teams have not built into their release pipelines, or negotiate a workable interpretation with Ireland's Coimisiún na Meán — ChatGPT's designated national supervisor under the DSA.
OpenAI's response was measured. A company spokesperson said ChatGPT "operates as a DSA search service" and that the company was "preparing to meet the additional compliance requirements" that come with the designation. The company did not contest the search engine classification.
The VLOSE designation does not arrive in isolation. OpenAI already operates under the EU AI Act as a general-purpose AI model provider — obligations enforceable with financial penalties from August 2, 2026, three weeks before the ChatGPT Ads European rollout and four weeks before the VLOSE designation. The AI Act imposes documentation requirements, transparency obligations, and copyright compliance duties on the model itself; the DSA imposes platform-accountability obligations on the service OpenAI runs on top of that model.
The two frameworks are complementary but not redundant. The AI Act governs what OpenAI builds; the DSA governs what OpenAI runs at scale for 159.1 million EU users. An OpenAI systemic risk assessment produced for DSA compliance will need to account for risks arising from the underlying model as well as from the search and retrieval features — meaning AI Act documentation and DSA risk assessments will inevitably overlap, potentially requiring the same research team to produce two differently-formatted accountability reports for two different regulatory authorities.
For every AI company watching the ChatGPT designation, this dual-compliance reality is the actual cost calculation. DSA compliance for a VLOSE is estimated to require sustained investment in risk assessment capacity, independent audit relationships, researcher data-access infrastructure, and public ad-library tooling. For AI search products that have not yet crossed the 45 million EU user threshold, the designation of ChatGPT functions as a preview of the compliance obligations they will inherit on arrival — not a distant concern but a near-term engineering and legal planning horizon.
One collision in the VLOSE designation deserves specific attention. The same week the European Commission designated ChatGPT, OpenAI reported that ChatGPT Ads reached $1 billion in annualized revenue run rate — 200 days after the ad pilot launched in February 2026 — and had expanded the self-serve ad-buying platform into Europe.
VLOSE designation requires OpenAI to maintain a searchable public repository of every advertisement shown on ChatGPT to EU users. For a traditional search engine, this means maintaining an ad library indexed by advertiser, ad content, targeting parameters, and impression volume. For a conversational AI that delivers sponsored content as labeled cards in natural language responses, the technical requirements are more complex: what constitutes a distinct "ad" in a dynamically generated conversation, how are successive impressions of the same sponsored message indexed, and how does a public library accommodate the personalized and context-dependent nature of conversational ad placement?
These questions have not been answered. OpenAI is simultaneously building its European advertising business and building the EU-mandated transparency infrastructure for that business. The two are now, effectively, the same project.
The compliance window may feel distant, but the DSA enforcement track record is not theoretical. Since the regulation's first enforcement action in December 2025, the Commission has issued approximately €870 million (approximately $1.009 billion at September 3, 2026 rates) in fines across three designated services: a record €550 million (approximately $638 million) against AliExpress in July 2026 for failing to address algorithms that promoted counterfeit products; approximately €200 million (approximately $232 million) against Temu in May 2026 for comparable failings; and €120 million (approximately $139 million) against X (formerly Twitter) in December 2025 for deceptive user verification practices and transparency failures.
Fines are calibrated as a percentage of global annual revenue — up to 6 percent for violations. For context, OpenAI reported approximately $13.07 billion in recognized revenue in 2025, meaning its maximum exposure approaches $784 million per violation. The non-compliance risk is specific and sized: it is not hypothetical.
Legal challenge has also proven difficult. Amazon and Zalando both challenged their earlier VLOP designations before the EU's General Court and lost — the court accepted that the compliance burden is substantial but found it justified by the regulatory aims. Zalando has indicated it will appeal to the Court of Justice. The pattern: contesting designation doesn't suspend obligations in the interim.
For the global AI search industry, the practical implications of the ChatGPT VLOSE designation are immediate in two senses. First, every AI company with a live-web-search feature must now calculate when its EU user base will cross 45 million, because that calculation determines when compliance infrastructure must be ready — and DSA compliance infrastructure is not a four-month project. Second, Germany's ZAK rulings are a reminder that the EU-level designation is not the only regulatory track: national media authorities can apply their own frameworks to AI search products regardless of VLOSE status, and those rulings are immediately enforceable.
The January 2027 compliance deadline for OpenAI, Reddit, and Roblox will be the first real-world test of whether the DSA's obligations — risk assessments, audits, researcher access, ad repositories, algorithmic transparency — can be meaningfully applied to a generative AI system. If OpenAI's first systemic risk assessment produces reproducible risk indicators and documented mitigation measures, it will establish a template for what VLOSE compliance looks like for AI products. If it produces general principles without specific product changes, the Commission has indicated it will not hesitate to respond.
"These are not boxes to check," as one Brussels-area compliance analyst put it. "The audit mechanism is designed to distinguish between an honest accounting of what a system does at scale and a presentation designed to satisfy the form of the obligation without the substance."
The capability-based logic that brought ChatGPT into the VLOSE tier will scale forward automatically. The question for every AI search product is not whether the same regulation will reach them. It is whether they will be ready when it does.
Currency conversions are approximate, calculated at September 3, 2026 rates.
Any AI service with a live web-search feature that reaches 45 million average monthly users in the EU qualifies for VLOSE designation under DSA Article 33(1) — automatically, without a separate determination of category. Google Gemini crossed 900 million users globally at Google I/O 2026; even a conservative estimate of its EU user base would put it well above the 45 million threshold. Perplexity's global user count is contested — estimates range from 45 million to over 100 million globally — but its EU-specific figure has not been published; the Wytlabs third-party tracker puts European traffic at roughly 24 percent of global, which at the lower end of global estimates would place EU users below the threshold today. Anthropic's Claude holds roughly 8 percent of AI chatbot web traffic globally and has not published EU-specific user data. Critically, the designation trigger is not announced in advance — Brussels monitors platform-reported user data and acts when the threshold is clearly exceeded. For any of these products, the compliance planning horizon for a VLOSE designation is now, not when the designation arrives.
No. The VLOSE designation does not give the European Commission authority over ChatGPT's specific outputs or the right to require particular answers be changed. What it requires is that OpenAI systematically study the harms its product creates at scale — including illegal content, risks to minors, mental health harms, and election integrity risks — document those findings honestly, take documented action to reduce identified risks, and submit those assessments to independent review annually. A separate but related instrument, the EU AI Act (enforced as of August 2, 2026), governs transparency obligations for the underlying AI model. The two frameworks create overlapping but distinct compliance obligations: the AI Act governs what OpenAI builds and discloses about its model; the DSA governs how OpenAI runs that model as a service for 159.1 million EU users, as explained in TechTimes' EU AI Act coverage.
DSA Article 27 requires VLOSEs to explain the "main parameters" of their recommender and ranking systems. For Google Search, this is demanding but coherent: traditional search engines use algorithmic ranking systems with identifiable factors such as authority scores, recency, and query match that can be described in plain language. ChatGPT's answers are generated through a transformer architecture that uses attention mechanisms and probabilistic token sampling across billions of learned weights — there is no ranking list, no identifiable parameter set, and no auditable decision path in the same sense. The Freshfields analysis flags this unsettled question of how the Article 27 obligation translates to LLM-based services. OpenAI will need to work with Ireland's Coimisiún na Meán — ChatGPT's national supervisory authority under the DSA — to determine what "main parameters" means for a generative AI system. That interpretation will set the standard for every AI search product that follows.
Germany's Commission for Licensing and Supervision ruled in July 2026 that AI-generated search outputs from both Google and Perplexity are subject to the German State Media Treaty — treating them as content the providers create themselves, not as neutral hosting of third-party information. This matters for smaller AI search products because it applies regardless of user count. A service does not need to reach 45 million EU users to fall under German national media law; it only needs to generate its own content and distribute it to German users. ZAK's rulings are immediately enforceable. The DSA is a floor for the largest services; national media law can reach smaller ones through a completely different legal mechanism.
