Magnifying glass inspecting an AI chat bubble against a European Union blue-and-gold backdrop, representing ChatGPT's VLOSE classification under the Digital Services Act
Briefing Industry News

EU Designates ChatGPT as Its Third VLOSE Under DSA

The European Commission designated ChatGPT a Very Large Online Search Engine (VLOSE) under the Digital Services Act on August 31, making it only the third service worldwide—after Google Search and Bing—to carry that classification. Following designation, OpenAI has four months—until approximately January 2027—to comply with the additional DSA obligations that apply to services at this scale. For operators running ChatGPT in EU markets, the headline is what the product may look like after compliance changes take hold.

Key Takeaways

  • ChatGPT is now the EU’s third designated Very Large Online Search Engine, joining only Google Search and Bing.
  • OpenAI has four months—until approximately January 2027—to comply with additional DSA obligations for VLOSEs, per the Commission’s designation notice.
  • Non-compliance risks fines up to 6% of global annual revenue; X paid €120M in December 2025 under the same law.
  • The 45 million EU monthly user threshold creates the basis for Commission designation—web-search capability alone is not sufficient.
  • Operators with EU-facing ChatGPT workflows should ask OpenAI now what product changes are planned before January.

What Does the VLOSE Designation Actually Require OpenAI to Do?

The Commission’s designation notice states that OpenAI must comply with “the additional DSA obligations for VLOSEs”—describing the core obligation as assessing and mitigating systemic risks across six categories: illegal content, harm to minors, physical and mental wellbeing, fundamental rights, electoral processes, and public security. DSA’s VLOSE framework also covers independent auditing, data sharing with the Commission and vetted researchers, and recommender-system transparency; each obligation is defined by DSA’s compliance chapters, and the Commission’s designation notice does not publish a separate per-obligation deadline schedule.

The Commission classified ChatGPT as a “hybrid service” qualifying as a search engine because it can search the web in response to user prompts. ChatGPT, Reddit, and Roblox were designated the same day after each declared reaching at least 45 million average monthly EU users—the threshold that provides the basis for Commission designation.

What Should EU-Operating Businesses Watch Before January?

Most DSA compliance work happens at OpenAI’s level. Three areas are worth tracking.

Product changes for EU users. Platforms that previously received VLOSE or VLOP status often modified products for EU compliance—adjusting recommendation logic, adding transparency overlays, or restricting features. If OpenAI changes how ChatGPT behaves for EU-located users, workflows that depend on ChatGPT surfacing and synthesizing external information may produce different outputs in the EU than elsewhere. This mirrors the compliance dynamic that produced Claude’s mandatory AI-content watermark for EU outputs—a separate EU AI Act obligation already live.

Enterprise data scope. DSA data-sharing obligations apply to systemic-level information shared with the Commission and vetted researchers; the Commission’s designation notice does not define what this means for enterprise customer data. Ask your account team two specific questions: how OpenAI separates enterprise conversation data from processes triggered by DSA regulatory access, and how it handles legally compelled disclosure. Your enterprise agreement governs normal operations—but do not assume the enterprise tier is categorically exempt from all regulatory access obligations.

The designation template. Gemini, Perplexity, and Claude.ai all offer web search with growing EU user bases—but the basis for Commission designation is the 45 million EU monthly user threshold, not web-search capability alone. None has declared reaching that threshold. Watch for public threshold declarations or Commission investigations; those are the concrete signals that designation is approaching for any other vendor. Operators building EU workflows on web-search-capable AI tools should ask vendors directly whether they approach designation thresholds and what compliance processes they have in place.

For operators, the near-term move is not a platform migration. It is a vendor conversation: ask what compliance changes OpenAI is planning for EU users, and whether any features will change before January. Posture: keep watching; ask sharper vendor questions if you have EU-facing ChatGPT workflows.

Frequently Asked Questions

Does the VLOSE designation change ChatGPT Business or Enterprise contract terms for EU customers?

The designation does not modify existing enterprise contracts. OpenAI’s DSA obligations run to the Commission, not enterprise customers. Your data governance terms remain under your enterprise agreement. Operators should verify with OpenAI whether any eventual compliance changes apply geography-wide or are tier-specific; OpenAI has not announced an implementation plan.

Which AI services might receive a VLOSE designation next?

The basis for Commission designation is the 45 million EU monthly user threshold. Gemini, Perplexity, and Claude.ai offer web search and have growing EU user bases, but none has declared reaching that threshold. A public threshold declaration or Commission investigation would be the concrete signal to watch—not web-search capability alone.

Can operators review OpenAI’s DSA risk assessments?

Eventually, yes — but through a defined process, not at operator discretion. The DSA’s risk-assessment reporting obligations and its vetted-researcher data-access regime are distinct. Under Article 34, OpenAI must conduct risk assessments and transmit them to the Commission. Vetted researchers under Article 40 can apply to access platform data — such as exposure logs and recommendation records — to study systemic risks; they do not automatically receive OpenAI’s risk-assessment documents. For public reporting, DSA Article 42 mandates that VLOSEs publish their risk assessment report, audit report, and audit implementation report within three months of receiving each audit report — a required disclosure, not a voluntary one. Redactions are permitted under Article 42(5) for confidential business information and security concerns, but unjustified redactions are themselves a compliance infringement. The Commission may approve timing flexibility for first-year compliance cycles; OpenAI’s first VLOSE audit cycle has not yet begun. In the interim, contractual audit rights and data-processing agreements remain the most reliable operator transparency mechanism.


Sources: European Commission designation notice (Tier 1, HTTP 200 ✓) · European Commission press release IP/26/1772 (Tier 1) · EU Commission Article 42 Q&A (Tier 1) · Gizmodo (Tier 2, HTTP 200 ✓) · Euronews (Tier 2) · Business Standard (Tier 2)