The European Commission recently published an official announcement. Based strictly upon established criteria within the Digital Services Act (DSA), the European Union now officially designates ChatGPT as a Very Large Online Search Engine. Consequently, ChatGPT must rigorously adhere to all relevant DSA stipulations. This pivotal decision indicates that ChatGPT will face significantly harsher regulatory scrutiny operating within the European Union.
Massive Active User Base Triggers Regulation
The EU Digital Services Act establishes a clear, undeniable regulatory threshold. If a platform averages 45 million monthly active users within the EU, it immediately falls under DSA jurisdiction. OpenAI previously disclosed critical user data. During the six months leading up to the end of March 2026, the ChatGPT search function averaged a staggering 159.1 million active monthly users within the EU. Naturally, this massive user base easily surpasses the established DSA regulatory threshold.
Comparing Platforms and Categorizations
Simultaneously, the European Union also officially incorporated both Roblox and the massive online forum Reddit into this strict regulatory framework. Roblox currently boasts 48 million monthly active EU users, while Reddit maintains 57.2 million. However, a crucial distinction separates ChatGPT from platforms like Reddit. Reddit functions primarily as a platform hosting third-party content. Conversely, regulators specifically categorized ChatGPT as a search engine.
This critical classification carries profound implications. It signifies that the European Union successfully integrated a generative AI system directly into a preexisting regulatory framework. Legislators originally designed this specific framework primarily to govern traditional search services like Google.
Mandatory Risk Assessments and Compliance
Following this official EU designation, the affected companies face a strict deadline. They must fully satisfy all additional DSA obligations within a tight four-month window. This demanding process requires conducting comprehensive, independent risk assessments. They must actively evaluate and subsequently mitigate any systemic risks generated by their algorithms and services.
Focus Areas for Scrutiny
These mandatory assessments must focus intently upon several critical areas. These include preventing the rapid dissemination of illegal content and ensuring robust protection for minors. Furthermore, companies must safeguard users’ physical and mental well-being, protect fundamental human rights, secure electoral integrity, and maintain overall public security.
The Burden of Transparency and Auditing
Whether classified as a Very Large Online Search Engine or a Very Large Online Platform, these services now face immense pressure. They must submit to significantly harsher transparency requirements and rigorous, independent auditing. Furthermore, they must provide regulatory authorities with unprecedented access to intricate algorithmic mechanisms and detailed risk management data.
For ChatGPT, this translates into severe operational changes. OpenAI must not only swiftly eliminate demonstrably illegal content. They may also face intense scrutiny regarding exactly how their model generates and subsequently presents information. Furthermore, regulators will likely investigate whether generated responses potentially inflict any latent, systemic harm upon vulnerable user demographics.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!