For the past two years, global digital governance analysts have viewed the EU AI Act as the definitive blueprint for regulating artificial intelligence. However, a major regulatory step on 31 August 2026 showed that Brussels has other tools at hand. Using its Digital Services Act (DSA), the European Commission formally designated ChatGPT as a Very Large Online Search Engine (VLOSE), layering platform accountability on top of existing AI model rules. The designation binds OpenAI to strict new transparency and risk management obligations that must be in place by January 2027, and sets a global precedent for how states can govern hybrid AI services that act as gateways to knowledge. The practical consequence of this designation is that OpenAI faces a legally binding compliance checklist with a strict deadline of four months: While the AI Act and the DSA are both European digital laws, they regulate different objects and operate on different principles. The AI Act focuses on general purpose AI models: their training, technical documentation, and, for some providers, additional obligations linked to systemic risk. Those rules have applied to providers like OpenAI since 2025. The DSA, by contrast, regulates intermediary services that distribute information to the public. It classifies services based on their user reach rather than their underlying code, focusing squarely on societal impact and information distribution. By crossing the threshold of 45 million monthly active users in Europe, ChatGPT triggered the strictest tier of this framework. By deploying both frameworks simultaneously, Brussels establishes a comprehensive dual strategy. While the AI Act governs the backend training data, the DSA now governs the frontend output. When ChatGPT browses the web to synthesise live data for a user, it is legally operating as a search engine. Consequently, OpenAI must now answer for how it indexes, summarises, and presents that information. A point of confusion in tech policy is how a chatbot can be classified under search rules when it does not always browse the web. ChatGPT frequently relies entirely on its static training data to answer questions without looking up live information. The European Commission resolved this by focusing strictly on the functional capability of the tool. Under the DSA, a service first has to qualify as an online search engine (allowing users to search, in principle, all websites and receive results), and then exceed 45 million monthly active recipients in the EU to become a VLOSE. The VLOSE designation applies specifically to the interface with enabled search and capabilities to retrieve information from the web, not necessarily to every mode or deployment of the underlying model. For the wider AI market, this functional boundary introduces an important operational distinction. Purely offline models, or models that operate without search tools, still face basic DSA obligations if they are hosted online or distributed via app marketplaces. However, they remain exempt from the strict, expensive auditing burdens of the search engine tier. The European Commission only triggers these specific VLOSE rules when an AI interface begins acting as a real-time tool to index and summarise the live internet.
For digital diplomats, OpenAI’s isolated status raises an important question: why aren’t chatbots like Google Gemini and Microsoft Copilot on this new list, given that both have web search features and certainly exceed 45 million European users? The answer lies in how the DSA treats existing search infrastructures. Because Google Search and Microsoft Bing were already designated as Very Large Online Search Engines before Gemini and Copilot were integrated, their AI search features automatically fall under those existing VLOSE obligations. ChatGPT, by contrast, grew as a stand-alone consumer application outside a legacy search framework, so a distinct VLOSE label was needed to bring it into the same compliance tier. The selective focus of this enforcement shows how the DSA depends entirely on user metrics reported by the companies themselves. Rather than fighting the regulatory classification, OpenAI adopted a posture of cooperative compliance, voluntarily disclosing to regulators that ChatGPT’s search function averages 159.1 million monthly active users in Europe. By actively submitting these figures, the company chose to work directly with the European Commission to prepare for its upcoming obligations. While ChatGPT easily cleared this legal line, other prominent competitors such as Anthropic’s Claude, France’s Mistral AI, and China’s DeepSeek remain unaffected because they have not yet officially crossed the 45 million user threshold. As the market pioneer, OpenAI must absorb the immense operational costs of modifying its product, while rival firms gain a strategic window to observe OpenAI’s adjustments before their user bases grow large enough to trigger the same rules. However, any AI service with a live web search feature that reaches 45 million EU recipients will automatically face the same VLOSE obligations, turning this framework into a template determined by technical capabilities rather than an isolated sanction. This is not the final milestone for OpenAI. If ChatGPT continues to expand its feature set, it could face further classification. For example, if OpenAI develops its upcoming features into a major marketplace or an environment where users distribute applications created by outside developers to a massive audience, the EU could additionally designate it as a Very Large Online Platform (VLOP). A Gatekeeper designation under the Digital Markets Act (DMA) is also conceivable in the longer term, but would depend on meeting strict quantitative and qualitative criteria for core platform services and an entrenched market position. International policy will feel the implications of this regulatory shift in the months to come. For some time, lawmakers worldwide have faced a foundational question: do conversational interfaces require entirely new legal regimes that take years to draft? The European Commission has provided a practical answer. By categorising a generative AI tool as a hybrid search engine, the EU demonstrated that existing platform laws can be adapted to govern artificial intelligence. Developing nations looking to establish guardrails can look to platform accountability frameworks that are already on the books, bypassing the need to reinvent complex technical legislation. Furthermore, while triggering the ‘Brussels Effect’ remains a projection rather than an established fact, OpenAI is unlikely to maintain a completely different software architecture exclusively for European users due to the immense operational costs. The compliance mechanisms built to satisfy European regulators will likely be integrated into the global version of the product, setting a new baseline for AI search interfaces everywhere. The focus has moved beyond the safety of the static code to the integrity of the information delivered to millions of screens every day. For developing countries and smaller states, the lesson is practical rather than theoretical. Instead of drafting entirely new AI statutes, they can adapt existing platform or intermediary laws to cover AI services that function as information gateways, imposing obligations such as risk assessments, independent audits, ad transparency, and researcher access to data. This functional approach is easier to export and enforce than highly technical, model-centric legislation. Author: Slobodan Kovrlija
What OpenAI must do by January 2027
Dual regulatory pathway
When chatbots do not search
The corporate exceptions
The first-mover compliance burden
The precedent for global tech diplomacy