ChatGPT Is Now Officially a 'Search Engine' Under EU Law
The EU has classified ChatGPT as a 'Very Large Online Search Engine,' triggering stricter DSA rules on risk assessments, audits and transparency.
Brussels has decided that a chatbot answering your questions is doing the same job as a search box, and it wants to regulate it that way. On August 31, the European Commission designated OpenAI's ChatGPT a "Very Large Online Search Engine" under its Digital Services Act, putting the world's most-used AI assistant under the same legal microscope as Google Search.
What "VLOSE" actually means
The Digital Services Act, or DSA, is the EU's rulebook for large online platforms, built after years of fights over disinformation, child safety and market power on the big US tech services. It already applies extra obligations to "Very Large Online Platforms" (VLOPs) like Facebook and Instagram, and "Very Large Online Search Engines" (VLOSEs), a category so far occupied mainly by Google Search and Bing. A service crosses into "very large" territory once it reports more than 45 million average monthly users in the EU. The Commission says ChatGPT cleared that bar with roughly 159 million average monthly users across the bloc.
What makes ChatGPT unusual is that it wasn't designated for being a chatbot. Regulators specifically pointed to its ability to search the live web and return answers to prompts, calling it a "hybrid service" that behaves like a search engine even though most people think of it as an AI assistant. That distinction matters, because it means the EU didn't need a new AI-specific law to bring ChatGPT under search-engine rules. It just applied an existing definition to a new kind of product.
"These new designations mean that ChatGPT, Reddit and Roblox will now be held to a higher standard of scrutiny and accountability in the European Union, in line with their large impact on our citizens and society." — Henna Virkkunen, European Commission executive vice-president for tech sovereignty, security and democracy
What changes for OpenAI now
Reddit and Roblox were designated alongside ChatGPT in the same announcement, as VLOPs rather than VLOSEs, but all three now face the DSA's toughest tier of obligations. OpenAI has four months, until January 2027, to bring ChatGPT into compliance. In practice that means:
- Running and publishing a "systemic risk assessment" — essentially a formal audit of how the service could spread illegal content, harm minors, or affect elections and public health
- Submitting to independent external audits of those risk controls, not just self-certification
- Giving EU regulators and vetted researchers access to internal data to check the company's own claims
- Building in extra transparency around how the AI ranks, moderates and surfaces information in response to queries
Miss the deadline or fall short, and the penalties aren't symbolic: the DSA allows fines up to 6% of a company's global annual turnover, a number large enough to get any board's attention.
Why this decision travels beyond ChatGPT
The interesting part isn't really the fine print — it's the precedent. By classifying ChatGPT on the basis of what it does (searching the web and answering queries) rather than what it's marketed as (an AI chatbot), the Commission has effectively written a template it can reuse. Google's Gemini, Anthropic's Claude and Perplexity all have similar live-search features bolted onto a conversational interface, and all of them are edging toward or past the 45-million-user threshold in Europe. None of them can now credibly argue that "we're an AI product, not a search engine" is a permanent shield.
The India angle nobody's talking about yet
India has no direct equivalent of the DSA, but it has been moving in a parallel direction. The IT Rules, 2021 already impose extra due-diligence duties on "significant social media intermediaries" once they cross a user threshold in India, and MeitY has been drafting AI-specific guidance on deepfakes, synthetic content labelling and algorithmic accountability rather than passing one big omnibus law. ChatGPT is genuinely huge here — India is consistently among OpenAI's largest markets by user count — so the compliance playbook OpenAI now has to build for Brussels (risk assessments, external audits, data access for regulators) is a preview of the kind of scrutiny Indian regulators could plausibly ask for next, especially as the DPDP Act's rules on data processing come into force and MeitY keeps a close eye on how AI services handle Indian users' data and content moderation at scale. Indian startups building on top of ChatGPT or similar AI-search hybrids should treat this less as a European curiosity and more as an early look at where the compliance bar is heading globally.
What it means going forward
The DSA was written with social feeds and marketplaces in mind, not AI chatbots that browse the web on your behalf. Applying it to ChatGPT anyway shows regulators are choosing to stretch existing law over waiting years for AI-specific legislation to catch up — a faster, messier approach, but one that puts real deadlines on the calendar starting now rather than in some hypothetical future AI Act. For OpenAI, the January 2027 deadline is the first real test of whether "move fast" and "pass a formal EU risk audit" can coexist in the same product roadmap.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0