Policy
EU Designates ChatGPT a Very Large Search Engine Under the Digital Services Act
The European Commission has placed ChatGPT under the Digital Services Act's strictest tier as a very large online search engine. OpenAI now has four months to assess systemic risks, submit to oversight and meet expanded transparency duties.
By Michael C ·

The European Commission has designated ChatGPT a Very Large Online Search Engine under the Digital Services Act, placing OpenAI's consumer service within the law's highest tier of oversight. The Commission separately designated Reddit and Roblox as Very Large Online Platforms. Each service reported at least 45 million average monthly users in the European Union, the statutory threshold for enhanced obligations. The classification is a consequential answer to a question regulators have been avoiding: when a chatbot retrieves and synthesizes information for a mass audience, it can be governed as part of the search ecosystem rather than as ordinary software.
OpenAI has four months from formal notification to comply with additional duties. The Commission says those duties include identifying and mitigating systemic risks connected to illegal content, harm to minors, physical and mental well-being, fundamental rights, elections and public security. ChatGPT will also face stronger transparency, audit and data-access expectations. The designation does not declare that the service has violated the law. It recognizes that the scale and function of the product create consequences that require a more demanding governance process.
Calling ChatGPT a search engine is legally important because the product does more than host user posts. It answers questions by combining model knowledge, web retrieval and generated language. A user may never see the original ranking process or the complete set of sources considered. The service can therefore shape access to information in ways that resemble search while adding a new layer of synthesis. The DSA framework gives regulators a route to examine that layer without waiting for a chatbot-specific statute.
The classification also rejects a narrow view of generative AI as a private conversation between a user and a model. At ChatGPT's scale, answers can affect public understanding, commercial visibility and political discourse. A confident error about an election, health treatment or legal right can travel through screenshots and downstream tools even if it began in one session. Systemic-risk analysis asks the provider to look beyond one answer and study recurring patterns, distribution and foreseeable misuse across the service.
The DSA Turns Safety Claims Into Documented Obligations
Very large services must conduct regular risk assessments and adopt proportionate mitigations. For ChatGPT, that should mean evidence about how the company identifies harmful failure modes, tests changes, monitors abuse and measures whether a safeguard works. The law does not require a regulator to dictate every model response. It requires the provider to show that it has examined risks created by design choices and that mitigation is more than a policy statement.

Independent auditing will be difficult because a frontier model is not static. OpenAI can change prompts, retrieval systems, safety classifiers and model versions without producing a new consumer product name. An audit conducted against one configuration may age quickly. Regulators and auditors will need version records, access to representative testing and a method for deciding when a material change requires renewed review. The useful object of oversight is the operating system around ChatGPT, not only the weights of one model.
Researchers' access to data will be another test. The DSA contains mechanisms intended to support vetted research into systemic risks, but generative systems hold sensitive user conversations and security information. OpenAI will argue, with reason, that unrestricted disclosure could expose privacy or enable attacks. Regulators will have to create protected pathways that allow examination of aggregate behavior, recommendation and risk controls without turning user data or model vulnerabilities into public records.
The designation may force more clarity around source visibility. If ChatGPT is treated as a search service, publishers and users will ask how sources are selected, cited and excluded. The DSA is not a copyright law and does not guarantee referral traffic. It does create transparency pressure around ranking and recommender systems. For a generated answer, the equivalent questions include which retrieval results informed the response, how commercial relationships affect presentation and when the service chooses to answer without visible sources.
User appeals also take on a different form. Platforms traditionally moderate accounts or remove posts. A chatbot may refuse a request, restrict an account, suppress a source or generate a harmful answer. Each action raises different due-process questions. OpenAI will need to explain which decisions fall within DSA complaint mechanisms and how a user can contest them. A generic feedback button will not be enough if the service makes consequential choices about access or visibility.
ChatGPT, Reddit and Roblox Present Different Risk Profiles
The Commission announced the three designations together because they crossed the same audience threshold, not because their systems are interchangeable. Reddit organizes user communities and depends heavily on volunteer moderation. Roblox combines social interaction, payments and user-created experiences used by many children. ChatGPT generates responses and increasingly acts through tools. The DSA's value will depend on whether supervision adapts common principles to those distinct designs rather than applying one checklist to every service.

For ChatGPT, model behavior and retrieval are central. For Reddit, governance may focus more on illegal content, recommender systems and the relationship between the company and moderators. For Roblox, child safety, commercial design and communications are likely to receive particular scrutiny. The Commission will supervise compliance alongside national authorities in Ireland for ChatGPT and Reddit and the Netherlands for Roblox, reflecting where the companies' European operations are established.
The shared designation still creates a useful benchmark. OpenAI can no longer argue that its interface sits outside platform governance simply because the content is generated on demand. Conversely, regulators cannot treat every model error as proof of a DSA breach. The legal question is whether the company assessed foreseeable systemic risks, adopted proportionate controls, responded to evidence and met transparency duties. That standard is demanding without pretending that zero failure is possible.
The Commission can impose significant penalties for noncompliance, but enforcement should begin with specific information requests and testable expectations. A broad demand to make ChatGPT safe would produce documents rather than accountability. A request for evidence about election-query testing, minor protections, source attribution or incident response can reveal whether the process works. The regulator's technical capacity will matter as much as the law's maximum fine.
The Search Classification Will Travel Beyond Europe
OpenAI is unlikely to maintain completely separate governance systems for each jurisdiction. DSA risk assessments, change logs and audit controls can become internal standards used elsewhere, especially when enterprise customers ask for the same evidence. That spillover is one reason the designation matters globally. European law can shape product operations without requiring every feature to be identical across markets.
Other AI providers should assume that scale will bring similar scrutiny. The Commission says it will continue monitoring services that meet the statutory criteria. A competitor may avoid designation while small, but it cannot build a regulatory strategy around remaining below 45 million users forever. Product teams need logs, evaluation records and complaint processes before they become mandatory. Retrofitting them after a designation is slower and less credible.
Publishers and civil-society groups now have a formal channel for asking how ChatGPT affects information access. That does not guarantee agreement with OpenAI or the Commission, and the DSA cannot resolve every concern about training data or market power. It does move the debate from voluntary meetings into a process with deadlines, documents and supervisory authority. The next four months will show how the Commission translates a search-engine label into obligations suited to generated answers.
Advertising and commercial placement will require particular clarity as ChatGPT expands monetization. A generated response can blend recommendation, summary and action in one interface. Users need to know when payment affects what appears and whether sponsored material influenced the sources used to ground an answer. The DSA's transparency rules provide a starting point, but regulators may need guidance tailored to conversational formats where an advertisement is not confined to a familiar box beside organic results.
Minor protection is equally difficult because age assurance can conflict with privacy. OpenAI needs controls appropriate to younger users without collecting more identity data than necessary from everyone. Risk assessment should consider self-harm, sexual content, manipulation and the tendency to treat a responsive system as a trusted companion. Mitigation can include age-appropriate defaults, crisis escalation, parental tools and limits on persuasive behavior, but each measure should be tested for unintended exclusion and false alarms.
Election risk will test the difference between generated speech and distribution. ChatGPT does not have a conventional social feed, yet it can provide personalized explanations at enormous scale and can be integrated into tools that publish content elsewhere. OpenAI should measure factual reliability for current political information, disclose when retrieval is unavailable and monitor coordinated attempts to automate persuasion. Regulators should avoid demanding one official answer while insisting on clear sourcing and rapid correction of demonstrably false claims.
Fundamental-rights review should include language coverage. A safeguard that performs well in English may fail in smaller European languages or dialects, producing unequal access and risk. OpenAI will need evaluation sets, expert review and complaint analysis across the Union, not a translated policy page. The Commission should ask for evidence by language and use case so aggregate performance does not hide weak protection for communities with fewer training resources.
The designation may also clarify incident reporting. A model update that produces a sudden increase in harmful answers can affect millions before ordinary product metrics detect it. OpenAI should define which events trigger regulatory notification, how it preserves affected outputs and when it rolls back a change. Reports must protect user privacy while giving supervisors enough information to distinguish one-off errors from a systemic design failure. A mature process will treat model regressions with the same seriousness as security and availability incidents.
The most important consequence is institutional. ChatGPT has become large enough that European regulators no longer view it as an experimental layer attached to the web. They view it as infrastructure through which millions of people find and interpret information. OpenAI can challenge details of that analogy, but the burden has shifted. The company must now demonstrate, under law, how a system that answers at search-engine scale manages the risks that come with search-engine influence.
Topics: ChatGPT, European Union, Digital Services Act, OpenAI, platform regulation