cyberivy
ChatGPTOpenAIDigital Services ActAI RegulationEuropean UnionVLOSEPlatform Safety

EU places ChatGPT under its strictest platform oversight

August 31, 2026

Mehrere blaue Flaggen der Europäischen Kommission wehen vor einem modernen Glasgebäude.

The EU now treats ChatGPT as a very large online search engine. OpenAI must assess risks, undergo independent audits and provide vetted researchers with data access.

What this is about

The European Commission designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act (DSA) on August 31, 2026. This is the first time a standalone AI chatbot has entered the law's strictest supervision tier. OpenAI reported about 159 million average monthly active EU users for ChatGPT's search function. The threshold is 45 million.

For people in Europe, this is more than a new legal label. The Commission can now require systematic risk assessments, independent audits and access for vetted researchers. OpenAI has four months to implement the additional obligations.

What the designation actually does

The Commission considers ChatGPT a “hybrid service.” The decisive point is that the chatbot does not merely generate answers; it can also search the web in response to user queries. In regulatory terms, that gives it the characteristics of an online search engine.

OpenAI will have to assess systemic risks every year. These include illegal content, protection of minors, effects on physical and mental wellbeing, fundamental rights, elections and public security. The rules also require independent audits, transparency measures and access to certain data for authorities and vetted researchers. DSA violations can lead to fines of up to six percent of worldwide annual turnover.

The designation is not a finding that ChatGPT has already broken the law. It determines which duties and supervisory powers apply from now on.

Why it matters

Chatbots are increasingly used like search engines, although their answers are produced differently. A conventional search engine presents a list of sources; a language model turns information into a fluent response. Errors, skewed sources or misleading wording may therefore be less visible.

The EU is setting a precedent: a provider's technical description does not decide the category; the service's real function for users does. In the longer term, that logic may affect other assistants combining web search, recommendations and actions.

OpenAI also faces two overlapping rulebooks. The DSA targets risks created by the service and its reach. The AI Act separately sets requirements for certain AI systems and general-purpose AI models. Companies, researchers and civil society therefore gain several routes for requesting evidence.

In plain language

Imagine ChatGPT as a large railway station that used to be treated as an unusually modern information desk. The EU now says that because huge numbers of people arrive, receive information and are directed onward, the safety rules for the whole station apply. The operator must run the desk, document risks, allow inspections and explain how problems are fixed.

A practical example

Suppose ten million people ask ChatGPT about candidates, polling stations and disputed claims before a European election. If its answers repeatedly provide incorrect opening times or systematically favour particular political sources, that would be more than a collection of isolated mistakes.

As part of its risk assessment, OpenAI would need to examine how those patterns arise, which mitigations work and whether corrections measurably improve results. An independent audit could test whether the process is credible. Vetted researchers could use supplied data to study whether particular groups or languages are affected more heavily.

Scope and limits

  • The designation does not prove a specific legal violation and says nothing about whether an individual ChatGPT answer is correct.
  • Its practical effect depends on audits, data access and consistent enforcement; written obligations do not automatically prevent errors.
  • Many details will only become visible during implementation. Trade secrets, privacy and research transparency can conflict.
  • The DSA does not replace personal source checking for medical, legal, financial or political decisions.

SEO & GEO keywords

ChatGPT, OpenAI, Digital Services Act, DSA, European Commission, Very Large Online Search Engine, VLOSE, AI regulation, platform oversight, risk assessment, independent audit

💡 In plain English

ChatGPT is now legally treated as a very large online search engine in the EU. OpenAI must regularly assess risks, allow external audits and provide certain data to vetted researchers.

Key Takeaways

  • ChatGPT exceeds the DSA threshold of 45 million with about 159 million monthly active EU users.
  • OpenAI has four months to implement the additional DSA obligations.
  • The duties include systemic risk assessments, independent audits and data access for vetted researchers.
  • The designation is not a finding of a past legal violation.
  • DSA violations can lead to fines of up to six percent of worldwide annual turnover.

FAQ

Why is ChatGPT treated as a search engine?

Because it can answer user queries while searching the web. The Commission therefore describes it as a hybrid service with a search-engine function.

What must OpenAI do now?

OpenAI must assess systemic risks, undergo independent audits and provide data access to certain authorities and vetted researchers.

Is ChatGPT banned in the EU?

No. The designation increases oversight and obligations; it does not ban the service.

When do the additional duties apply?

OpenAI has four months after the designation to implement them.

Sources & Context