Why did the EU classify ChatGPT as a search engine?
ChatGPT was not classified as a search engine because it looks like Google. The EU treated it as one because the service can respond to users’ prompts and queries, including by searching the web.
That distinction matters. ChatGPT is a hybrid service: part conversational chatbot, part tool for finding information online. Under the Digital Services Act, that capability places it within the definition of an online search engine, even though users interact with it through a chat interface rather than a traditional list of links.
A second condition triggered the stricter classification: scale. Services with more than 45 million monthly EU users can be designated as Very Large Online Platforms or Very Large Online Search Engines. OpenAI reported that ChatGPT had 159.1 million average monthly EU users during the six-month period ending in March 2026. That is nearly four times the legal threshold.
The result is significant because ChatGPT became the first standalone AI service designated as a Very Large Online Search Engine under EU law. Reddit and Roblox crossed the same user threshold, but they were classified as Very Large Online Platforms instead.
The designation brings direct oversight from the European Commission and requires OpenAI to conduct an annual systemic risk assessment. That assessment must cover areas including illegal content and protection of minors. OpenAI has four months, until the end of November, to complete the first one. Ireland is the lead national regulator for OpenAI under the DSA.
The simple takeaway is that the EU classified ChatGPT by what it can do, not by what it is called. A chatbot that answers questions by searching the web can fall under search-engine rules when its reach becomes large enough.
What makes ChatGPT’s 159.1 million users significant?
ChatGPT’s 159.1 million users matter because user scale determines when the EU’s toughest platform rules apply. The European Commission set a threshold of 45 million monthly users for special oversight. ChatGPT crossed it, becoming the first AI service designated a “very large online search engine.”
That classification is significant because ChatGPT is not being treated only as a chatbot. The Commission classified it as a “hybrid service” because it can respond to prompts and queries, including by searching the web. In practical terms, the EU is regulating both the conversational system and the large-scale information service built around it.
The designation brings obligations that smaller services do not face. ChatGPT must conduct annual assessments of systemic risks, including illegal content, protection of minors, mental and physical wellbeing, fundamental rights, electoral processes, and public security. It must also submit to independent audits and share data with regulators and vetted researchers. The Commission gains investigative powers to examine how the service and its algorithms work.
The important point is that the user count is not just a measure of popularity. It is a legal trigger. Once a service reaches the relevant audience threshold, its design choices can become a matter of public oversight because failures may affect millions of people at once.
Reddit and Roblox also crossed the threshold, but they were designated as very large online platforms. ChatGPT’s separate classification reflects the way it combines AI-generated responses with web search. The takeaway is simple: scale changes the rules. For ChatGPT, reaching a massive audience now means accepting stronger duties to measure, explain, and reduce systemic risk.
How does the 45 million user threshold change oversight?
Crossing 45 million monthly users moves ChatGPT into the European Union’s strictest platform oversight category. The key change is not simply that OpenAI has more paperwork. The European Commission gains a direct role in examining how the service operates and how its algorithms affect people across the EU.
That includes possible harm to minors and the spread of illegal content. The Commission can investigate the way ChatGPT’s services and algorithms work, rather than relying only on the company’s own explanations or internal checks. This gives regulators a clearer route to examine how the system behaves at large scale and whether its design creates risks for users or society.
The designation also raises the standard for scrutiny and accountability. Henna Virkkunen, the Commission’s executive vice-president for tech sovereignty, security and democracy, said the Commission was watching the digital closely and would not hesitate to designate platforms that meet the threshold. Her statement signals that reaching the user level can trigger regulatory attention even when a service is not a traditional social network.
ChatGPT is the first standalone AI service to meet this threshold. Other platforms owned by AI hyperscalers, including Meta, Google, and Microsoft, were already designated under the Digital Services Act. The distinction matters because ChatGPT’s main product is an AI service, not a broader platform company with many consumer products.
The threshold does not make ChatGPT immune from problems below that line. SpaceX-owned Grok, despite not being classified as a “very large” platform, is facing a DSA investigation into alleged sexualised images of women and children.
The takeaway is simple: 45 million users turns scale into regulatory responsibility, with algorithms and social harms placed under closer examination.
What new risks must OpenAI assess?
ChatGPT’s new status changes the question regulators ask about it. OpenAI is no longer being viewed only as the operator of an AI chatbot. Because ChatGPT can pull live results from the internet, the European Commission has concluded that it functions, in regulatory terms, as a search engine.
That distinction matters. A chatbot response is not limited to what the model learned during training. When it retrieves current information, it can also shape how people find, interpret, and use material from the wider internet. The service therefore has a broader effect than a private conversation between a user and an AI system.
Under the EU’s strictest online safety regime, OpenAI must face a higher standard of scrutiny and accountability. The central risk assessment is consequently tied to ChatGPT’s large impact on EU citizens and society. The Commission’s statement does not provide a detailed list of every risk OpenAI must examine, so it would be inaccurate to name specific required categories not included in the available material. What is clear is that the assessment must reflect ChatGPT’s role as a large-scale information service, not just its role as a text generator.
This also explains why the designation is consequential. The regulatory lens follows what the product does in practice. If a service supplies live internet results, its effects resemble those of a search engine, even when users access those results through a conversational interface.
The takeaway is simple: OpenAI must now account for the wider social impact of ChatGPT’s answers and web-connected behavior. Its responsibility is being measured by the information role the product performs, not merely by the label attached to it.
Why do minors, elections, and public security enter the review?
A platform with more than 45 million monthly users in the EU reaches roughly one in 10 people in the bloc. That size is the reason the review expands beyond ordinary product checks. Under the Digital Services Act, services above the threshold become Very Large Online Platforms or Very Large Online Search Engines, with enhanced supervision.
The surprising part is that ChatGPT did not need to operate like a traditional social network to qualify. The European Commission classified it as a “hybrid service” and an online search engine because it responds to user prompts and queries, including by searching the web. Reddit and Roblox reached the same regulatory threshold as platforms where users create and share content publicly.
That scale makes certain questions unavoidable. How might minors encounter or use the service? Could its responses affect how people understand elections? Could failures or misuse create wider public security concerns? These questions matter because a service used by tens of millions can distribute information far beyond a single conversation or account.
The designation does not mean the Commission has declared ChatGPT unsafe, nor does the provided decision say that a specific violation occurred. It means the service now falls into a category that receives enhanced supervision. The Commission has also said it will continue monitoring the digital and designate platforms that meet the threshold.
For users, the practical takeaway is simple: size changes the standard. Once a service becomes large enough, regulators examine not only whether it works, but also how its reach can affect vulnerable users, public information, and society-wide risks.
What will independent audits and regulator investigations examine?
The designation does not simply add a label to ChatGPT. It creates a deadline and a set of questions that regulators can examine. The Commission says ChatGPT declared at least 45 million average monthly users in the EU, meeting the threshold for designation as a Very Large Online Search Engine, or VLOSE, under the Digital Services Act.
The central issue will be systemic risk. ChatGPT must assess how its service and algorithmic systems may contribute to the spread of illegal content, harm to minors, and negative effects on users’ physical and mental well-being. Reviews will also examine possible effects on fundamental rights, electoral processes, and public security.
That scope matters because the concern is not limited to whether one answer is accurate or one user violates a rule. The DSA obligations focus on patterns created by the service and its algorithms. Regulators will therefore be looking at the risks produced at scale, across the EU user base.
The Commission’s announcement does not list the exact tests an independent audit will use, or describe a specific investigation into ChatGPT. It does establish what the company must address. Following the designation on 31 August 2026, ChatGPT has four months, until January 2027, to comply with the additional obligations for VLOPs and VLOSEs.
For users and operators, the practical takeaway is clear: oversight will focus on the service’s broader effects, not only individual outputs. ChatGPT will need to show that it has identified and worked to reduce risks tied to content, algorithms, rights, safety, and democratic processes.
How will Ireland become OpenAI’s lead DSA regulator?
Ireland’s role depends on a legal and administrative step that has not yet been confirmed in the available record. The European Commission is currently assessing whether ChatGPT’s search feature qualifies as a Very Large Online Search Engine, or VLOSE, under the Digital Services Act. That assessment matters because ChatGPT reported an average of 120.4 million monthly users in the EU in October 2025, almost three times the statutory threshold.
The surprising part is that user numbers alone do not settle the question. The Commission must first decide whether ChatGPT fits Article 3(j) of the DSA, which defines an online search engine. ChatGPT does not simply return indexed links. It synthesises answers. The legal issue is whether the DSA should interpret the service by its function, rather than by the format of its results.
If the Commission classifies ChatGPT as a VLOSE, the service would enter the DSA’s supervision system for designated very large platforms and search engines. That would bring stronger scrutiny of risks affecting minors, physical and mental well-being, fundamental rights, electoral processes, and public security. It would also require risk assessments, creating new demand for systems that can demonstrate trustworthy AI practices.
However, the supplied material does not state that Ireland has already been appointed OpenAI’s lead regulator, identify the Irish authority involved, or explain the exact route by which that appointment would happen. The immediate decision therefore belongs to the Commission: first determine whether ChatGPT’s search function falls within the VLOSE definition, then apply the relevant supervision framework.
The takeaway is simple: Ireland’s role cannot be treated as settled until ChatGPT receives a formal DSA designation and the responsible national regulator is identified.
What does this mean for AI product and compliance teams?
For AI product and compliance teams, a possible VLOSE designation would make web-scale information retrieval a governance problem, not only a product problem. ChatGPT can retrieve and synthesise web information at scale even when it does not return a traditional list of links. Under Article 3(j) of the Digital Services Act, that function can matter more than the interface used to deliver it.
The practical change is that teams would need to connect product decisions with formal risk work. Required risk assessments would examine how the service operates at scale and what systemic risks it creates. Transparency requirements would also place more pressure on teams to explain how information is presented and how the service affects users, publishers, and advertising models.
This work will be expensive. Estimates for a single large platform range from $150 million, according to the CCIA Research Center, to €260 million annually, according to Bertelsmann Stiftung. Those figures make compliance planning a budget issue for executives, not a final review before launch.
There is also a less obvious commercial effect. Strong compliance may help firms compete in a digital trust market projected to reach $130 billion to $470 billion by 2035. But regulation can also strengthen the position of large incumbents. After GDPR implementation, market concentration increased by 17%, while an Oxford Martin School study found that small IT firms saw profits drop.
The lesson for product teams is clear: build evidence, risk controls, and transparency into the service early. The lesson for compliance teams is equally important: regulation can create trust and market opportunity, but its cost and effect on smaller rivals must be measured alongside legal compliance.
Why is ChatGPT’s designation different from Reddit and Roblox?
ChatGPT, Reddit, and Roblox all crossed the same EU user threshold, but they were not placed in the same regulatory category. Each service reported at least 45 million average monthly users in the European Union. That number triggers the strictest tier of the Digital Services Act, with the European Commission taking over direct oversight.
The difference comes from how the services are classified. ChatGPT has been designated a Very Large Online Search Engine, or VLOSE. Reddit and Roblox have been designated Very Large Online Platforms, or VLOPs. The labels reflect the services’ different functions, rather than a difference in their reported reach.
That distinction matters because ChatGPT is being regulated in the same broad category as Google as a search engine. Reddit and Roblox, by contrast, are treated as online platforms. The available designation does not suggest that one service is considered more important than another. Instead, it places each under the framework that matches the role it plays for users.
The practical result is shared scrutiny, but through different regulatory classifications. The European Commission says these designations bring a higher level of scrutiny and accountability because of the services’ significant impact on citizens and society. It also says it will continue monitoring the digital and may designate additional services.
The key takeaway is simple: crossing the 45 million user threshold determines the intensity of oversight, while the service’s function determines the category. ChatGPT’s designation is different from Reddit’s and Roblox’s because the EU treats it as a search engine, not because it crossed a different threshold.
What should companies learn before their AI service reaches this scale?
The most important lesson is simple: user growth can change a company’s regulatory position. ChatGPT was designated by the European Commission as a very large online search engine after reaching at least 45 million average monthly users in the European Union. Reddit and Roblox received comparable treatment as very large online platforms.
That threshold is not just a growth milestone. It signals that a service has a significant effect on millions of people, so its risks and algorithmic systems receive closer attention. The European Union’s Digital Services Act is designed to apply a higher standard of scrutiny to services at this scale, including ChatGPT.
Companies should prepare before they cross the line, not after. The practical work is to understand how the service operates for users in the EU, identify where its algorithms may create risks, and maintain clear evidence about those systems. The research does not describe every duty that follows designation, but it makes the direction clear: large services should expect stronger oversight.
There is also a warning for fast-growing companies that have not yet reached the threshold. The European Commission said it continues to monitor the digital and will not hesitate to designate any platform that meets the requirement. Waiting for a formal notice may leave little time to organize the necessary people, processes, and records.
The takeaway is that scale brings accountability with it. A company should treat the 45 million average monthly user threshold as a planning deadline, not a surprise event. Growth teams, product leaders, and legal teams need to watch usage in the EU together, because reaching more users can also mean entering a more demanding form of supervision.

