← Back to Insights

EU Designates ChatGPT as a VLOSE: Four Months After the 45 million User Threshold

Nils Liu
AI OpenAI ChatGPT European Union Digital Services Act Regulation News

TL;DR

The European Commission designated ChatGPT a Very Large Online Search Engine under the DSA, giving OpenAI until January 2027 to address systemic risks including illegal content, minors’ well-being, and public security.

EU Designates ChatGPT as a VLOSE: Four Months After the 45 million User Threshold

The decision leaves a testable gap for the next four months. The European Union requires ChatGPT to assess and mitigate systemic risks, but the material published on August 31, 2026 does not explain how generated answers, search results, and outbound links will be measured separately. If OpenAI publishes reproducible risk indicators and mitigation results by January 2027, the Very Large Online Search Engine rules will have an auditable implementation. If it publishes only general principles, outsiders still will not be able to determine whether the obligation changed how the product operates.

The European Commission designated ChatGPT as a Very Large Online Search Engine, or VLOSE, on that date. It simultaneously designated Reddit and Roblox as Very Large Online Platforms, or VLOPs. All three services declared at least 45 million average monthly users in the EU, meeting the Digital Services Act threshold. The Verge independently reported the classification and compliance timetable. ChatGPT falls into the search-engine category, while Reddit and Roblox are online platforms, a distinction that matters when regulators decide which functions and risks must be documented.

The four-month clock begins with notification

Designation does not mean that every remedial measure takes effect immediately. The Commission gave the three services four months, until January 2027, to comply with the additional obligations for VLOPs and VLOSEs. The official notice says they must assess and mitigate systemic risks arising from their services and algorithmic systems. It names the spread of illegal content, negative effects on minors, users’ physical and mental well-being, fundamental rights, electoral processes, and public security. The notice establishes a deadline and a scope, but it does not publish OpenAI’s assessment method, baseline data, or planned product changes.

The Verge adds product-level context about existing DSA requirements. Large services may not target advertising at minors or use sensitive traits such as sexual orientation, religion, ethnicity, or political beliefs for ad targeting. They must also provide greater transparency about recommendation algorithms. Those duties are relatively straightforward to locate in the interfaces of Reddit and Roblox. ChatGPT generates text, organizes web information, and supplies links within the same interaction, so the boundary among search, recommendation, and advertising will depend on OpenAI’s compliance design and subsequent EU supervision.

The category is settled; the measurement is not

The 45 million figure is an average monthly-user threshold, not an incident rate. Scale gives the Commission a basis for direct supervision, but it does not reveal the share of conversations that spread illegal material, negatively affect minors, or increase risks to elections and public security. A before-and-after comparison would require a fixed observation period, a defined denominator, consistent incident categories, and a measure of residual risk after mitigation. Neither of the two sources provides that data today.

The legal timetable defines what can be measured over the next three to six months. OpenAI can disclose whether it submitted a systemic-risk assessment by January 2027, identify the measurement boundary between generated answers and search functions, and show whether its interface or content-handling policies changed. The August 31, 2026 decision establishes that ChatGPT is now within DSA supervision as a VLOSE. It does not yet establish how much any particular risk will decline after four months of compliance work.

Sources:

Get the latest insights

Join the newsletter to receive my latest articles on GenAI, AI Agents, and architecture.

No spam. Unsubscribe anytime.