← Back to Perspectives

EU Designates ChatGPT as a Very Large Online Search Engine Under the DSA

September 1, 2026 · 10 min read

AI chatbot interface on a smartphone in a modern European interior, illustrating ChatGPT’s Digital Services Act designation and the rise of regulated AI information systems.
ChatGPT, Reddit and Roblox have crossed the EU's 45 million-user threshold, bringing them under the strictest tier of the Digital Services Act and placing systemic AI risk under greater regulatory scrutiny.
The European Union has drawn a new regulatory line around artificial intelligence.
On 31 August 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the Digital Services Act, while designating Reddit and Roblox as Very Large Online Platforms (VLOPs).
All three services reported at least 45 million average monthly users in the European Union, crossing the threshold for the EU's most stringent DSA requirements.
For ChatGPT, the decision is particularly significant.
It is the first standalone AI chatbot to receive the VLOSE designation.
The classification reflects ChatGPT's ability to respond to queries and, where applicable, search and retrieve information from the web. In other words, the EU is recognising that an AI assistant can increasingly perform a role similar to a search intermediary.That changes the regulatory question.
ChatGPT is no longer simply a tool that generates answers.
At its current scale, it is becoming part of the information infrastructure through which millions of people discover, interpret and act on information.

Why the 45 million threshold matters

The DSA sets a threshold of more than 45 million monthly EU users for designation as a Very Large Online Platform or Very Large Online Search Engine.
The reasoning is straightforward.
Scale creates systemic consequences.
A problem affecting a small digital service may remain relatively contained.
A problem affecting a service used by tens of millions of people can spread across an entire information environment.

That is why the DSA imposes additional obligations on the largest services.
The regulation is not only concerned with whether individual pieces of content are legal.
It is increasingly concerned with what happens when the systems themselves create or amplify risk at scale.
That distinction is particularly important for AI.

ChatGPT is being treated differently from Reddit and Roblox

The three services have crossed the same user threshold, but they have not received the same classification.
Reddit and Roblox have been designated Very Large Online Platforms because they allow users to share and distribute content to the public.
ChatGPT has been designated a Very Large Online Search Engine.
The distinction reflects how the services function.
Reddit and Roblox are primarily platforms where users interact with and distribute content.
ChatGPT can act as an information intermediary, responding to queries and, through its search functionality, retrieving information from across the web.
The classification therefore says something important about how AI products are evolving.

A chatbot can increasingly occupy several roles at once.
It can be an assistant.
A research tool.
A search interface.
A coding environment.
A content generator.
And increasingly, an agent capable of taking actions.
Regulation is now beginning to catch up with that convergence.

Four months to address systemic risk

The designation immediately raises the pressure on the companies involved.
The European Commission says ChatGPT, Reddit and Roblox have four months, until January 2027, to comply with the additional obligations that apply to VLOPs and VLOSEs.
Those obligations include assessing and mitigating systemic risks arising from their services and algorithmic systems.
The areas specifically identified by the Commission include:
  • illegal content

  • risks to minors

  • physical and mental wellbeing

  • fundamental rights

  • electoral processes

  • public security

The companies will also face enhanced transparency and oversight requirements under the DSA framework.
This is where the regulation becomes more interesting than a simple content-moderation rule.
The EU is asking these services to look at how their systems behave at scale.

From content moderation to system monitoring

Traditional platform regulation often asks a relatively simple question:
Was this piece of content allowed?
The DSA's systemic-risk framework asks a much larger question:
What patterns does the platform create, amplify or enable?
That could mean examining how information is ranked.
How users are exposed to certain material.
How recommendation systems behave.
How vulnerable users interact with the service.
How harmful content spreads.
And how the platform itself can contribute to risks involving elections, public security or fundamental rights.
For AI, the challenge is even more complicated.
An AI model can generate an answer rather than simply display existing content.
That answer can then influence what a user believes, what they search for next and what action they take.
The system therefore sits somewhere between information retrieval and information production.

The new importance of continuous intelligence

This shift toward systemic monitoring has a strong connection with the way The Hedge Collective approaches intelligence.
Through its Perspectives platform, The Hedge Collective examines developments across AI, technology, infrastructure and strategic risk.
The DSA's approach points toward the same broader reality:
large-scale digital systems cannot be understood through isolated events alone.

They need to be monitored continuously.
Signals need to be connected.
Patterns need to be identified.
And emerging risks need to be understood before they become larger failures.
That is where intelligence infrastructure becomes important.

Varro: from isolated signals to an operational picture

This is also where Varro becomes relevant.
Varro is designed around bringing disparate signals together and turning them into a clearer intelligence picture.
The underlying principle is simple: individual events rarely tell the whole story.
A sudden change in online behaviour may not mean much on its own.
A spike in harmful content may not be significant by itself.
A change in search behaviour may look ordinary.
But when those signals begin moving together, they can reveal something much more important.

That is the challenge facing regulators and platforms as AI systems scale.
The question is no longer only whether a single answer or piece of content is problematic.
It is whether patterns across millions of interactions reveal a systemic risk.
This is exactly the kind of shift that makes continuous intelligence increasingly important.

Domains: understanding the wider environment

The same logic extends into The Hedge Collective's Domains framework.
Complex risks rarely exist in isolation.
Technology, information, infrastructure, human behaviour and geopolitical developments can interact with each other. The DSA's systemic-risk requirements reflect a similar understanding.
A platform's impact on an election may involve information distribution.
The same system may affect minors differently.
A separate vulnerability could have implications for public security.
A change in algorithmic behaviour could affect all of them simultaneously.
This makes risk assessment less like checking a list of individual incidents and more like mapping an interconnected environment.
The challenge is not simply detecting events.
It is understanding relationships between them.

AI governance is becoming infrastructure governance

This is why the ChatGPT designation matters beyond OpenAI.
AI systems are becoming infrastructure.
People use them to search for information, make decisions, write software, conduct research and interact with other digital services.
As adoption increases, their behaviour can have consequences beyond individual users.
That creates a new governance problem.
Who is responsible when an AI system produces a harmful result?
Who monitors systemic effects?
Who decides what constitutes an acceptable level of risk?
Who has access to the data needed to identify those risks?And perhaps most importantly:
Who controls the infrastructure through which the intelligence operates?
These questions sit closely alongside The Hedge Collective's work on sovereign infrastructure.
Regulation can establish boundaries around a technology.
But regulation does not necessarily give a country or organisation control over the technology itself.

Regulation is not the same as sovereignty

The EU can regulate ChatGPT.
That does not mean it owns the underlying model.
It does not control every component of the infrastructure required to operate it.
And it does not automatically eliminate Europe's dependence on external AI providers.
This distinction matters. A state can have regulatory authority over a system while still depending on another actor for the underlying capability. That creates an important strategic tension.
The rules may be sovereign while the infrastructure is not.
For organisations building critical AI capabilities, understanding that dependency becomes increasingly important.

The financial risk is significant

The DSA also gives the European Commission meaningful enforcement powers.
For serious non-compliance, the maximum fine can reach 6% of a provider's total worldwide annual turnover.
For a company operating at global scale, that is not a symbolic penalty.
It creates a significant incentive to build compliance into the architecture of the service itself.
The larger implication is that regulatory requirements may increasingly influence how AI systems are designed.
Risk assessment can no longer be something added after deployment.
It becomes part of the product.

Why mental wellbeing and minors are part of the same framework

The DSA's focus on minors and users' physical and mental wellbeing is also notable.
AI services are increasingly used by people for personal advice, education, research and everyday decision-making.
That means the consequences of poor system behaviour are not always technical.
They can be social and psychological.
A system that is technically functioning as designed may still create undesirable effects when used by millions of people.
The EU is therefore looking beyond individual outputs and toward the relationship between digital systems and human behaviour.
That is a significant evolution in platform regulation.
The election problem is bigger than misinformationThe inclusion of electoral processes is another important element.
AI can influence elections without directly creating false political content.
It can affect what information people find.
It can summarise political claims.
It can determine which sources are surfaced.
It can influence what users choose to investigate next.
At large scale, those seemingly small interactions can accumulate.
That is why systemic risk matters.
The impact of AI may not come from one dramatic event.
It can emerge from millions of ordinary interactions.

What this means for the future of AI

The ChatGPT designation could become a precedent for other AI systems.
As AI assistants gain users and expand their search capabilities, more services may eventually approach the DSA's threshold. That means AI companies will need to think about regulation alongside scale.
Growth brings more than commercial opportunity.
It brings greater systemic responsibility.
The EU is effectively saying that once an information system becomes large enough, its internal risks become a matter of public interest.
That is a significant principle.

The bigger picture

The EU's decision is not simply about putting ChatGPT under another set of rules.
It reflects a deeper shift in how governments view AI.
AI is no longer being treated solely as software. It is becoming part of the infrastructure through which information moves, decisions are made and societies operate. That makes visibility, monitoring and control increasingly important. The DSA addresses one part of that problem through regulation.
Tools such as Varro approach another part through continuous intelligence and signal analysis.
Frameworks such as Domains help place individual developments inside a wider strategic environment.
And The Hedge Collective's work on sovereignty asks the deeper question of who ultimately controls the infrastructure behind emerging capabilities.
The three perspectives point toward the same conclusion.

As AI becomes infrastructure, understanding it is no longer enough. Organisations need to understand what surrounds it, what it depends on and how its risks evolve over time. The EU has now placed ChatGPT inside its strictest digital regulatory framework. The next phase will be watching what happens when the rules meet the system. Because the real test of AI governance is not whether a regulation exists.
It is whether we can see systemic risk early enough to do something about it.