Table of Contents
The European Union just did to ChatGPT what it once did to Google — and the consequences will reach every website, publisher and professional who depends on AI answers, including the Filipino content economy. On Monday, the European Commission officially designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the Digital Services Act, after OpenAI reported that ChatGPT search averaged 159.1 million monthly active users in the EU during the six months ending March 2026 — more than triple the 45-million-user threshold that triggers the bloc’s strictest regulatory tier. Reddit and Roblox were designated Very Large Online Platforms the same day, as SecurityOnline detailed. But it is the ChatGPT decision that makes history: for the first time, an AI assistant has been pulled into the same regulatory category as the world’s biggest search engines, on the argument that when an AI searches the web for you, it is a search engine.
Key Takeaway
- ⚖️ ChatGPT search is now regulated like a search engine: the European Commission designated it a Very Large Online Search Engine under the DSA on the basis that it “can engage with and respond to users’ prompts and queries, including by searching the web.”
- 📊 The numbers forced the issue: 159.1 million average monthly EU users of ChatGPT search — 3.5 times the 45-million DSA threshold — measured across the six months ending March 2026.
- ⏱️ A four-month compliance clock is running: OpenAI must complete independent risk assessments and systemic-risk mitigation, with full adherence to the new obligations due by January 2027.
- 🔎 Regulators get investigative teeth: the Commission, working with Ireland’s Coimisiún na Meán, can scrutinise how ChatGPT’s search and recommendation systems actually work.
- 🌍 Why Filipinos should care: when AI answers are regulated, AI-cited publishers gain or lose visibility by rule — and the DSA template tends to travel far beyond Brussels.
The thesis of this analysis is that the designation is bigger than a compliance story. Classifying ChatGPT search as a search engine settles, in regulatory practice, the argument that academics had been making on paper: an AI assistant that retrieves, synthesises and presents web content performs the core function of search — and must therefore carry the accountability of one. Everything downstream changes shape: how OpenAI designs its product for Europe, how other AI labs position their own chatbots against the same threshold, and how publishers like us understand our place in the AI-answer supply chain. The DSA did not amend itself to cover AI. AI grew until the DSA could not avoid it.
What Brussels Decided on ChatGPT Search and the DSA

The mechanics first. The Digital Services Act establishes a hard threshold: any platform averaging more than 45 million monthly active users in the EU falls into the Very Large tier — VLOSE for search engines, VLOP for platforms — and inherits direct European Commission oversight. OpenAI’s own transparency disclosures made the case unavoidable: ChatGPT search averaged 159.1 million active monthly users within the EU over the six months ending March 2026. Reddit reported 57.2 million and Roblox roughly 48 million, both crossing into the Very Large Online Platform category in the same announcement.
The Commission’s reasoning, quoted in the designation coverage, is deceptively simple: “ChatGPT is an AI system that can engage with and respond to users’ prompts and queries, including by searching the web. Hence, ChatGPT is a hybrid service that qualifies as an online search engine under the DSA.” That sentence does something legally novel — it treats a generative AI product as a search engine because of what it does, not what it is called. The category follows the function. ChatGPT was already subject to the DSA’s general obligations; the new designation attaches the enhanced tier: systemic risk assessment, independent audits, transparency reporting, and regulator access to the internals.
Timing matters in the story too. The designation follows months in which the regulator had reportedly been uncertain how to classify ChatGPT — the DSA’s definitions were written for search bars and social feeds, not conversational agents. The debate inside European policy circles played out publicly: researchers at the Internet Policy Review published a formal analysis arguing ChatGPT was a hybrid of search engine and hosting platform, meeting the definitions of both. The Commission’s decision effectively adopted that view. When definitions lag technology, regulators eventually choose the interpretation that preserves their jurisdiction — and they did.
Why the Search Engine Label Is the Right — and Consequential — Call
Consider what ChatGPT search actually does. A user asks a question; the system retrieves live web results, synthesises them into an answer, cites a handful of sources, and presents a finished page. The user’s attention lands on the AI answer — not ten blue links. Whatever we call that experience, its economic function is search: it is the moment of discovery, the allocation of attention, the decision about which sources deserve the click. If a service performs search’s function at 159 million users a month, regulating it as a chat toy while regulating Google as search would be a jurisdictional loophole the size of the internet.
The counterargument — that ChatGPT merely displays links when asked, like any browser — fails on the synthesis point. Search engines rank; they do not rewrite the web’s content into a single authoritative voice. ChatGPT search does, which concentrates both power and risk: hallucination risk, source-selection bias, and the quiet editorial authority to decide which publishers exist in the AI answer layer. Those are precisely the “systemic risks” the DSA’s enhanced regime was designed to reach — misinformation, manipulation, and disproportionate influence over public opinion and elections. The designation brings the AI answer layer inside the accountability perimeter at the moment it became the front door to information for over a hundred million Europeans.
The regulatory symmetry also matters commercially. Google’s search results operate under obligations about how results are formed and disclosed. Now the AI answer that increasingly precedes — or replaces — those results operates under its own. The two layers of discovery are converging in regulation as they already converged in user behaviour. For an analysis of how the commercial layer beneath this converged — the capital flows behind AI search — see our coverage of the Nvidia-Perplexity talks and the $30 billion signal about AI search.
The Four-Month Clock for ChatGPT Search Compliance
The designation starts a compliance sprint with a January 2027 deadline. Within four months, ChatGPT must fully satisfy the enhanced DSA obligations, which include conducting and submitting comprehensive, independent risk assessments; actively evaluating and mitigating the systemic risks its algorithms and services generate; and providing the transparency that lets regulators — and researchers — examine how the system works. The Commission stated it will possess investigative powers to scrutinise ChatGPT’s functionalities, and it will oversee compliance in collaboration with Coimisiún na Meán, Ireland’s digital services coordinator, reflecting OpenAI’s EU establishment in Dublin.
What those risk assessments examine is where the product decisions get interesting. Systemic risk under the DSA includes misinformation and disinformation, negative effects on civic discourse and electoral processes, and risks to fundamental rights. Translated to an AI search product: how does the model handle contested topics during election season? How does it decide source authority? What happens when synthesis merges unreliable sources into confident prose? These are not hypothetical checkboxes — they are the exact questions newsrooms, educators and platforms have been debating informally since 2023, now moving into formal, auditable, potentially fine-bearing territory. DSA penalties scale to 6 percent of global turnover, which for OpenAI’s revenue trajectory is not an rounding error.
The operational burden is real but OpenAI is not walking in blind. The company already faces the DSA’s general obligations, operates transparency mechanisms, and has been through the EU AI Act’s grooming of the sector. But the VLOSE tier brings the audit intensity that has previously been reserved for Google, Meta and TikTok. The era in which AI labs could describe themselves as research organisations touched lightly by platform law is formally over in Europe. For a sense of how fast the product surface underneath all this is moving, our OpenAI Astra coverage tracks the assistant-era roadmap that regulators are now chasing.
The Precedent: Every AI Assistant Now Has a Regulatory Line to Cross
The immediate question about ChatGPT search precedent that every AI lab is asking is arithmetic: what is my EU user count, and how close am I to 45 million? The designation sets a template that applies by category, not by company. Any assistant with web-search capability that crosses the threshold — and several are within reach given ChatGPT’s growth curve — faces the same designation. The Commission has effectively announced that the VLOSE category is AI-ready, and the criteria are public: search function plus user scale. Gemini’s European numbers, Copilot’s, Perplexity’s — every lab’s compliance team ran the same query this week.
The deeper precedent is conceptual. The EU has now articulated, in an enforceable designation, that AI assistants which search the web inherit search-engine accountability. That doctrine will not stay in Brussels. Regulators in the UK, and in Asian jurisdictions watching the EU template — including the Philippines, where AI regulation bills are actively moving through Congress — now have a worked example of how to classify AI services without writing new law. The Brussels effect, the pattern by which EU regulation becomes the global default because companies build to the strictest standard, now has an AI chapter. Products built for 159 million European users will be designed to DSA specifications; everyone else inherits the design.
There is also a competitive reading. Compliance cost is a moat: a four-month audit-and-mitigation sprint is trivial for OpenAI’s scale and genuinely punishing for smaller AI search entrants. Regulation of this kind tends to consolidate the leaders it targets, by raising the floor cost of competing with them. The DSA’s AI era may therefore produce a paradox its drafters did not intend — the rules meant to discipline the giants may entrench them, unless enforcement genuinely opens the systemic-risk examination to competitors’ complaints.
What ChatGPT Search Regulation Means for Publishers and Creators
For the publishing economy — including every Filipino creator, newsroom and content business building an audience in the AI era — the designation changes the incentives in three concrete ways. First, transparency pressure flows downstream: when regulators examine how ChatGPT search selects and presents sources, the criteria that determine which publishers get cited move from opaque to examinable. Structured, authoritative, well-sourced content — the craft this publication invests in daily — becomes not just best practice but regulated infrastructure.
Second, the risk assessments create a documentation trail. If ChatGPT must mitigate systemic risk in its answers, it must define what makes a source reliable — and every definition it writes becomes a lever publishers can optimise toward, and regulators can contest. We have argued since our earliest coverage that AI search visibility is the new SEO; the DSA designation turns that thesis into supervised reality. The practical guidance for Filipino professionals building their own visibility — in careers, consulting or content — is the same as ever, but now with regulatory wind behind it: be the source the answer layer can defend citing. Our practical guide to working with AI agents covers the skill side of that equation.
Third, the enforcement lens on synthesis quality is, quietly, an anti-plagiarism instrument. AI answers that merge scraped content without meaningful attribution face exactly the “systemic risk” framing the DSA empowers regulators to police. Publishers who watched AI search collapse their traffic have, for the first time, a regulatory forum in which that grievance is legible — not as copyright alone, but as information-ecosystem risk. Whether that translates into bargaining power for publishers is now a question of enforcement politics, not law.
What Comes Next: January 2027 and the Enforcement Test
The calendar for ChatGPT search is short. Four months from designation — January 2027 — is OpenAI’s deadline for full adherence to the enhanced obligations: risk assessments complete, mitigation measures documented, transparency mechanisms operating. Between now and then, watch three things. The first formal risk assessment will reveal how OpenAI itself defines the systemic risks of AI-mediated search — the industry’s most consequential self-portrait yet. The Commission’s first enforcement posture will show whether the DSA’s AI chapter begins with dialogue or with fines. And the counter-reaction from other capitals — Washington above all — will determine whether the EU writes the global rulebook for AI search or sparks a regulatory competition instead.
The last word belongs to the pattern. Every major information technology eventually met the regulator: telegraph, radio, television, the web, social media, and now the answer layer. Each time, the defining fight was the same — who bears responsibility when the technology shapes what the public knows. The European Commission’s answer this week is that an AI which searches for the public is a search engine, and search engines answer for their results. The 159.1 million users did not ask for a designation. But they got one — and so did everyone who publishes into the AI era.
Frequently Asked Questions About the EU ChatGPT Designation
Why did the EU classify ChatGPT as a search engine?
Because ChatGPT performs search’s core function: it responds to user queries by searching the web, retrieving results and presenting them. The European Commission stated that “ChatGPT is a hybrid service that qualifies as an online search engine under the DSA.” The classification follows the function, not the product label — and at 159.1 million average monthly EU users of ChatGPT search, it was far past the DSA’s 45-million-user threshold.
What is a Very Large Online Search Engine (VLOSE)?
Under the EU Digital Services Act, a VLOSE is a search service averaging more than 45 million monthly users in the EU — 10 percent of the bloc’s population — which triggers the strictest oversight tier: independent risk assessments, systemic-risk mitigation, transparency reporting, audits, and direct European Commission supervision with investigative powers and fines up to 6 percent of global turnover.
When must ChatGPT search comply with the new DSA obligations?
OpenAI has a four-month window from the designation to fully adhere to the enhanced obligations, putting the deadline around January 2027. In that period it must conduct comprehensive independent risk assessments and implement measures mitigating the systemic risks of its service, with oversight shared between the European Commission and Ireland’s Coimisiún na Meán.
Which other services were designated alongside ChatGPT?
Reddit and Roblox were designated Very Large Online Platforms in the same announcement, reporting 57.2 million and roughly 48 million average monthly EU users respectively. Both cross the 45-million threshold and join the roster of services under direct Commission oversight, which already includes major search engines and social platforms.
Does the designation change how ChatGPT works for users?
Direct product changes in Europe are likely over time — more transparency about sources, documented handling of contested topics, and audited answer quality — but the immediate effect is organizational: risk assessments, compliance infrastructure and regulator engagement. Users outside the EU will benefit indirectly, since safety and transparency features built for DSA compliance usually roll out globally.
What does the ChatGPT designation mean for website owners and publishers?
It formalizes AI search as regulated infrastructure. Source-selection criteria that determine which publishers appear in AI answers will face transparency and risk-mitigation review, strengthening the case for authoritative, well-structured, verifiable content. Publishers also gain a regulatory forum for complaints about how AI answers use and present their work — a significant shift in bargaining power for the content economy.






