On August 31, the European Commission formally classified OpenAI's ChatGPT as a Very Large Online Search Engine (VLOSE), subjecting the platform to the Digital Services Act's (DSA) most demanding regulatory framework. The move represents the culmination of a lengthy deliberative process, with policy experts having examined pathways for such a designation years in advance.

The classification carries substantial consequences for both AI developers and European digital governance. Many of the practical implications will emerge only as the Commission exercises its supervisory authority in the months ahead.

This decision underscores the DSA's technological flexibility—its capacity to encompass services that emerged after the regulation's drafting. The classification hinges on Article 3(j) of the DSA, which characterizes a search engine as enabling users to search "in principle, all websites." ChatGPT's integrated web search capability, which can even serve as a browser default, satisfies this definition. Both the Commission and OpenAI's own transparency filings have already treated ChatGPT's search functionality as subject to general search engine obligations since 2024.

ChatGPT's search feature now faces the DSA's full due diligence regime: mandatory risk assessments, risk mitigation strategies, third-party audits, researcher data access, and public transparency disclosures.

However, the 159.1 million search users represent only one dimension of ChatGPT's European footprint. The conversational interface through which most users engage the model does not necessarily activate web search, making ChatGPT what regulators term a "hybrid service." The designation decision does not appear to isolate ChatGPT's distinct functions—an approach mirroring how other VLOP designations have proceeded, with Snapchat, for example, classified for social networking rather than messaging.

The question of whether the chat function itself might eventually warrant separate designation remains unresolved. Article 34(1) requires OpenAI to evaluate risks inherent in its service design and connected systems, potentially positioning the chat interface as a distinct "related system" subject to scrutiny.

Even absent such a separate designation, Article 34 creates an opening to examine ChatGPT's architecture comprehensively. The way a general-purpose AI model is constructed and deployed—spanning training data through output ranking—directly shapes the accuracy, diversity, and dependability of information reaching millions. Recital 84 of the DSA identifies algorithmic amplification and curation as systemic risk drivers, directly paralleling how ChatGPT determines, orders, and attributes sources. This framework becomes critical for assessing threats to democratic participation, public discourse, electoral integrity, security, health, child protection, and psychological welfare.

Media pluralism receives explicit recognition as a distinct systemic risk category under Article 34(1)(b). Risk assessments must therefore examine how ChatGPT's source attribution and citation practices influence publisher reach—a concern extending beyond OpenAI alone. AlgorithmWatch is already leveraging Article 40(4) researcher credentials to examine whether Google's AI Overviews diminish media pluralism by redirecting traffic away from news publishers.

The VLOSE designation grants OpenAI entry into the Article 40 data access framework, equipping external researchers with comparable investigative capabilities. Credentialed researchers may request data under Article 40(4) to study systemic risks as defined in Article 34(1) and evaluate OpenAI's risk mitigation effectiveness under Article 35. Article 40(12) extends further, granting non-credentialed researchers, including those at nonprofits, access to data publicly visible through ChatGPT's interface.

The timing carries additional significance: the designation arrives mere weeks after OpenAI announced that advertisers could purchase placements within ChatGPT throughout Europe. OpenAI must now incorporate its advertising operations into risk assessments and maintain an ad repository under Article 39.

These requirements take effect in January 2027, yet the forward trajectory warrants consideration. The Digital Markets Act does not classify generative AI as a core platform service, though it does regulate online search engines. With the Commission now recognizing ChatGPT as a very large online search engine under the DSA, a gatekeeper designation under the DMA becomes plausible should OpenAI satisfy the relevant qualitative and quantitative criteria. Such a determination would represent a substantially more stringent test than the one just completed.

Source: Tech Policy Press