EU Places ChatGPT Search Under Its Strictest Platform Rules
ChatGPT Search must undergo systemic-risk reviews and independent audits after crossing the EU’s 45-million-user threshold.
ChatGPT enters the DSA’s highest tier
The European Commission has designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act, extending the bloc’s most demanding online-platform regime to a general-purpose AI assistant for the first time. Reddit and Roblox were separately classified as Very Large Online Platforms.
The decision follows usage disclosures showing that ChatGPT’s search function averaged about 159 million monthly active recipients in the European Union during the six months ending in March 2026. That comfortably exceeds the DSA threshold of 45 million, equivalent to roughly 10% of the EU population. The classification applies to ChatGPT’s search service rather than treating every model or API interaction identically.
OpenAI now has four months, through the end of November, to meet the additional obligations. These include assessing and mitigating systemic risks involving illegal content, fundamental rights, elections, public security, physical and mental wellbeing, and protections for minors. The regime also requires greater transparency, independent auditing and access for vetted researchers. Serious violations can expose a provider to fines of up to 6% of worldwide annual turnover.
Why it matters
The designation formally recognizes conversational AI as part of Europe’s information-discovery infrastructure, not merely a software tool. Search answers synthesized by a model can shape what users see without exposing the ranking process or source list associated with a conventional search engine. European supervisors will therefore have to translate platform-era concepts—including recommender transparency and systemic-risk mitigation—into rules suitable for generated answers.
How that translation works could influence AI search well beyond Europe. OpenAI may implement some compliance systems globally rather than maintain separate product architectures, while rivals approaching the same user threshold will gain a practical template for audits and risk reporting. The unresolved question is whether regulators can inspect an adaptive answer engine without encouraging superficial documentation or forcing disclosure of security-sensitive model details.