Skip to content
All systems operational0 AI providers monitored, polled every 2 minutes
Live status
Back to Originals

Brussels Did Not Regulate ChatGPT the Chatbot. It Regulated the Search Box, and That Template Fits Every Assistant That Browses.

Adrian Vale··7 min read
Policy · EU Digital Services Act

On Monday, August 31, 2026, the European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act, and designated Reddit and Roblox as Very Large Online Platforms in the same announcement. It is the first time a generative AI assistant has been pulled into the DSA's top tier. The trigger was OpenAI's own disclosure that ChatGPT's search function averaged roughly 159.1 million monthly active recipients in the EU over the six months ending March 31, 2026, against a threshold of 45 million.

Almost every writeup I read this week led with the same framing: the EU has decided ChatGPT is a search engine. That is true and it is the least interesting sentence available. The part worth your attention is which box the Commission ticked and why, because the reasoning is portable and it does not care what your model is called.

VLOSE, Not VLOP, and the Difference Is the Whole Story

The DSA has two designations at the top tier. Very Large Online Platform covers services that host and disseminate user content at scale. Very Large Online Search Engine covers services that let users query and retrieve information from across the open web. Reddit and Roblox got the first one, which is obvious: they are content hosts. ChatGPT got the second one.

Nobody thinks ChatGPT is a search engine in the way anyone used that phrase in 2019. What the Commission actually concluded is narrower and sharper: a service that retrieves live results from the open web and presents them to a user is, functionally, performing search, regardless of what wraps the output. The designation attaches to a capability, not to a product category and not to a model.

That is a legal framing with a very long reach. It means the qualifying question is not "are you an AI company" but "do you fetch the live web for users, and how many of them are in the EU." Every serious assistant now ships browsing. Most of them ship it on by default.

ServiceDesignationDeclared EU MAUMultiple of threshold
ChatGPTVLOSE (search engine)159.1M3.5x
RedditVLOP (platform)45M+1.0x+
RobloxVLOP (platform)45M+1.0x+
ThresholdEither45M1.0x

Reddit and Roblox declared figures at or above the threshold; the Commission publishes the designation rather than a precise count for every service. ChatGPT's 159.1 million is OpenAI's own disclosure for the search function specifically, covering the six months to March 31, 2026.

What Is Actually in the Four Month Clock

Designation starts a four month compliance clock from notification. Reporting on the exact landing date is inconsistent, with outlets variously putting it at the end of November, the end of December, and January 2027. Treat the Commission's own language as authoritative and the precise day as unsettled until OpenAI publishes a compliance timeline. What is not unsettled is the obligation set, and it is a real engineering and legal program rather than a disclosure exercise.

ObligationWhat it requiresDifficulty for a generative service
Systemic risk assessmentAnnual assessment covering illegal content, minors, physical and mental wellbeing, fundamental rights, elections, public securityModerate. Overlaps heavily with model cards and safety evals already produced
Risk mitigationDemonstrable measures tied to each identified risk, and evidence they workHard. Mitigations on a generative system are probabilistic, not rule based
Independent auditAnnual third party audit of DSA complianceHard. The audit firm market for frontier model behavior barely exists
Vetted researcher data accessAccess for accredited researchers to data needed to study systemic riskHardest. Scope is genuinely undefined for a model
Transparency reportingPublic reports on a fixed cadenceLow. Reporting is reporting
Supervisory feeAnnual fee toward Commission oversight costs, capped at 0.05 percent of worldwide annual net incomeLow as a cost, non trivial as a precedent

Behind all of it sits the enforcement number: fines up to 6 percent of global annual turnover. Not EU turnover. Global.

Article 40 Is the Row Nobody Has Priced

The vetted researcher access provision was written for platforms where "data" has an obvious referent: posts, engagement metrics, recommender inputs, moderation decisions. You can hand a researcher a dataset and the question of what you handed over is answerable.

A generative assistant does not have that shape. If an accredited researcher wants to study whether ChatGPT amplifies a particular category of harmful claim, what is the dataset? Query logs are the most obvious answer and also the most privacy loaded thing OpenAI holds. Retrieval logs showing which sources the model pulled are more tractable and probably where this lands first. But legal commentary has already raised the question that matters, which is whether necessary access under a systemic risk framing could reach training data composition or model weights. Nobody knows. The statute does not say, because the statute was not drafted with this in mind.

That ambiguity is the single largest unpriced liability in Monday's announcement, and it will get resolved in negotiation and litigation over the next two years rather than in a compliance filing in December. Watch the first vetted researcher request that is refused. That is where the boundary gets drawn.

The Template, and Who It Fits

Because the designation attaches to live retrieval rather than to model class, the exposure question for every other assistant is arithmetic, not philosophy. Do you browse for users in the EU, and how many.

Google Search and Bing are already designated VLOSEs, which produces an odd asymmetry: search grounded generative answers delivered inside an already designated surface arrive pre regulated, while the same capability delivered in a standalone assistant needs its own designation. That gap is exactly where the next round of designations will land. Gemini as a standalone app, Copilot as a standalone app, Perplexity, Claude with web search on, Grok inside X, Meta AI inside its own surfaces: every one of them retrieves live web content, and the only variable is the declared EU user count.

Which brings up the mechanism that should make anyone building a consumer assistant uncomfortable. Designation runs on self declared active recipient numbers, published by the provider under Article 24(2). The threshold is crossed by growth, and the disclosure that triggers it is your own. OpenAI reported 159.1 million and the Commission acted. There is no version of this where a company scales a browsing assistant across Europe and quietly avoids the tier.

If you are tracking which assistants have shipped live retrieval and on which surfaces, our models tracker carries the capability flags, and AI policy follows the regulatory thread.

Three Counterarguments, Taken Seriously

One: this is duplicative, because the AI Act already covers it. Partly right and mostly wrong. The AI Act regulates the model and the provider through risk tiers and general purpose model obligations. The DSA regulates the service as an information intermediary. They target different objects. The clearest illustration is researcher access, which the DSA grants to accredited researchers and the AI Act does not provide in the same form. OpenAI now has two European supervisory relationships with different theories, different remedies, and different reporting calendars, and the overlap creates compliance cost without creating a defense.

Two: the designation covers the search feature, not the chatbot, so the scope is narrow. This is the strongest objection and I want to give it full weight. The 159.1 million number is for the search function specifically, and OpenAI has acknowledged that function operates as a search service. On paper you could imagine a firewall where DSA obligations bind retrieval and stop at generation. In practice I do not think that boundary survives contact, because the harm the risk assessment is aimed at is the answer the user reads, not the fetch that preceded it. A retrieval pipeline whose output is synthesized into prose cannot be assessed for systemic risk without assessing the synthesis. The narrow scope holds in the filing and dissolves in the first enforcement question.

Three: the DSA is content moderation law and generative output is not user content. True as statutory history and increasingly beside the point. The DSA's systemic risk articles are written around the effects of a service on users and on society, not around who authored the bytes. A designation that turns on retrieval sidesteps the authorship question entirely, which is very likely why the Commission chose the search category rather than trying to argue that model output is disseminated user content. It picked the framing with the fewest doctrinal problems.

Our Take

The headline story is a milestone: first generative assistant in the DSA's top tier. The structural story is that Brussels found a way to regulate AI assistants without waiting for a new instrument, without a definitional fight about what a model is, and without touching the AI Act. It regulated a feature. The feature is browsing, every assistant worth using has it, and the only gate is a user count the provider publishes itself.

I think that is a more durable move than a bespoke AI statute would have been, and I do not entirely mean that as praise. Capability based designation is fast and it generalizes, which is what you want from a regulator facing a category that reinvents itself every eight months. It also means the obligations landing on OpenAI in four months were designed for a different kind of service, and Article 40 in particular is going to be litigated by people discovering in real time that the word "data" does not survive the transition from a feed to a model.

For anyone building on these APIs, the near term effect is close to zero and the medium term effect is not. Systemic risk mitigation obligations tend to arrive downstream as tightened default refusals, more aggressive retrieval filtering in the EU, and regional behavior divergence between the same model on the same endpoint. That is the part that shows up in your evals before it shows up in a press release.

Three Signposts

Whether OpenAI publishes a compliance date rather than letting the press guess. Three different landing dates are circulating for a four month clock that started on a known day. A company that intends to comply on schedule states the schedule, because it costs nothing and it sets the narrative. Continued silence means the internal answer is not settled.

Whether a second standalone assistant gets designated inside 180 days. One designation is a milestone. Two is a category. The moment a second browsing assistant crosses on its own declared numbers, every EU product roadmap starts treating web retrieval as a regulated feature with a compliance budget attached rather than a checkbox.

Whether any provider ships an EU specific retrieval behavior and documents it. Regional divergence is the observable that tells you mitigation obligations have reached product. If a model's browsing behavior differs measurably by region and the difference shows up in a changelog rather than in a research paper, the DSA has started shaping output and not just paperwork. We will be watching for it on the models tracker.

Adrian Vale, September 2, 2026. TensorFeed tracks AI model releases, pricing, and provider status in real time. Sources for this piece: the European Commission designation announcement of August 31, 2026, and subsequent reporting.