Brussels spent Monday putting a chatbot in the search engine box. Since 31 August 2026 ChatGPT is a Very Large Online Search Engine under the Digital Services Act, the first conversational AI service any regulator has classified that way, and the Commission's reasoning runs to about one sentence: it answers prompts and queries, including by searching the web. Reddit and Roblox were designated the same day, both as platforms rather than engines. If you publish for a living, the tempting read is that the EU just forced OpenAI to explain how it picks your pages. It didn't. Not this week, anyway.
The short answer
The European Commission designated ChatGPT a Very Large Online Search Engine on 31 August 2026, a first for a chatbot. The obligations land on OpenAI: systemic risk assessment, an annual external audit, data access for vetted researchers. Nothing lands on your stack. And nobody has to publish how the thing picks its sources.
What the Commission actually decided
Three designations went out on 31 August. ChatGPT as a Very Large Online Search Engine. Reddit and Roblox as Very Large Online Platforms. That takes the count of services in the strictest DSA tier to 28, the tier that already holds Google Search and Bing.
The interesting one is obviously ChatGPT, because the search category was written for something that returns a page of links. The Commission’s line is that it’s “a hybrid service that qualifies as an online search engine because it responds to users’ prompts and queries, including by searching the web”. Read that twice. The trigger isn’t the chat window. It’s the web-searching behaviour underneath it, which means the same logic would reach any assistant that browses on your behalf at EU scale.
Honestly I expected this to land as a platform designation, or as an AI Act matter, and it went the other way. Worth updating your priors on how Brussels is going to treat answer engines.
The number OpenAI put on the form
159.1 million average monthly active recipients in the EU, over the six months ending 31 March 2026.
That figure is worth pulling apart, because a lot of the coverage rounded it to “ChatGPT has 159 million European users” and that’s not what was declared. It covers ChatGPT search specifically. So OpenAI’s own filing says the web-searching part of the product reaches roughly a third of a billion people’s worth of EU population monthly, which is a bigger admission about how much of ChatGPT is now a retrieval product than anything in the company’s marketing.
Reddit declared 57.2 million and Roblox roughly 48 million, both close enough to the 45 million line that a soft quarter might have kept them out. ChatGPT wasn’t close to the line at all.
What lands on OpenAI, and what doesn’t
Here’s where the enthusiasm usually outruns the text.
The obligations are a systemic risk assessment every year, covering illegal content, protection of minors, effects on wellbeing and fundamental rights, electoral processes and public security. Then mitigation of whatever the assessment finds. Then an independent external audit of the whole thing. Plus data access for the Commission, for national authorities, and for vetted researchers studying systemic risk. Where applicable, a public advertisement repository and at least one recommender option that isn’t built on profiling. Non-compliance carries fines up to 6 percent of global annual turnover.
What isn’t in there: any duty to publish model weights, ranking code, or the criteria by which ChatGPT decides your article is the one worth citing.
Two clarifications that keep getting muddled. First, this is the Digital Services Act, not the AI Act. Different instrument, different obligations, different timetable, and if you’re tracking compliance work then the Article 50 labelling rules we covered are a separate pile of homework. Second, designation is not a finding that OpenAI did anything wrong. It’s a status that switches obligations on.
The ad repository line, arriving at an awkward moment
One clause deserves more attention than it’s getting.
VLOPs and VLOSEs owe a public, searchable advertisement repository showing who paid and how the ad was targeted. It applies where the service carries ads. Until recently ChatGPT didn’t. Now it does: OpenAI’s self-serve Ads Manager went live and the ads business reportedly crossed a billion dollars annualised in under 200 days, with the self-serve tool rolling out across Europe.
So the designation catches the ad product in its first year rather than a decade in. If that repository obligation applies in full, an EU ad archive for ChatGPT would be the first public window into how anybody targets advertising inside an answer engine. I might be reading too much into a “where applicable”, and OpenAI hasn’t said what it thinks applies. But that’s the clause I’d watch, not the risk assessment.
If you publish, what actually changes for you
Short version: nothing, this quarter.
No new crawler shows up. Your robots.txt doesn’t need a line, though that file is having a busy year anyway if you’ve been following Cloudflare’s Bot Preference Sync. The API is unchanged. Nobody owes you an explanation for why ChatGPT quoted a competitor’s page instead of yours.
What you might get, eventually, is second hand. Audit reports become public documents. The vetted-researcher channel means academics get a legal route to data about how a designated answer engine behaves at scale, which is the first structured visibility anyone outside OpenAI has had into that. First deliverables land in 2027 at the earliest, and audit reports are famously written to be survivable rather than informative.
The deadline itself is worth nailing down, because the reporting split. Four months from notification, which the Commission’s page puts in January 2027. Several outlets printed 31 December 2026, which is what you get if you count four months from the announcement. Go with the Commission’s own number.
We’ll pick this back up when the first risk assessment is filed, or sooner if OpenAI says anything public about the ad repository.
Sources
The designation, the reasoning and the obligations come from the European Commission’s own announcement, Commission designates ChatGPT, Reddit, Roblox under Digital Services Act, dated 31 August 2026, and the accompanying press release. The 159.1 million figure for ChatGPT search over the six months ending 31 March 2026, and the breakdown of obligations, are reported by Search Engine Journal. The Reddit and Roblox declarations, the 28 designated services and the 6 percent penalty ceiling are from Euronews. Our earlier coverage of the ads product is ChatGPT ads are live.
Frequently asked questions
What does VLOSE mean under the DSA?
Very Large Online Search Engine. It is the designation the European Commission applies to a search service that declares at least 45 million average monthly users in the EU. Designation pulls the service into the strictest tier of the Digital Services Act, alongside the Very Large Online Platform category that covers Reddit and Roblox. There are 28 designated services in total now.
Why is ChatGPT a search engine and not a platform?
The Commission called it a hybrid service that qualifies as an online search engine because it responds to users' prompts and queries, including by searching the web. So the web-searching behaviour is what pulled it into the search category rather than the chat interface. It is the first time a chatbot has been designated on that basis.
When does OpenAI have to comply?
Four months from notification. The Commission's own page puts that in January 2027. Some coverage printed 31 December 2026, which is what you get counting four months from the announcement date, so use the Commission figure. Designation itself took effect on 31 August 2026.
Does this mean OpenAI has to publish how ChatGPT ranks sources?
No. The DSA obliges risk assessment, external audit and data access for vetted researchers, not publication of ranking code or model weights. The audit reports and the researcher channel are the closest thing to visibility here, and neither produces anything public before 2027.
Does anything change on my own site or in the API?
Nothing. The obligations sit on OpenAI as the designated provider. No API surface changes, no new crawler, no robots.txt directive to add. If you were hoping for a legal lever over how ChatGPT cites you, this is not it.
Is designation the same as being found in breach?
No. The Commission is explicit that designation is not a finding of wrongdoing. It sets obligations going forward. Enforcement proceedings are a separate track, and penalties for non-compliance run up to 6 percent of global annual turnover.