The Wrong Category, Applied Correctly
The EU designated ChatGPT as a Very Large Online Search Engine. The classification doesn't fit the technology. The obligation it triggers does. And the criterion used may apply to far more AI systems than the Commission was targeting — while agents running through ChatGPT's back end remain outs
The European Commission designated ChatGPT as a Very Large Online Search Engine on August 31, 2026. The Twitter commentary found this funny. The regulators found it accurate enough.
The actual designation, issued under the Digital Services Act, classifies ChatGPT as a "hybrid service" that qualifies as an online search engine because it "can engage with and respond to users' prompts and queries, including by searching the web." That's a carefully constructed sentence. The Commission is not saying ChatGPT is a search engine in the way Google is a search engine. It's saying: the defining criterion for VLOSE designation is the capacity to receive queries and return results that may include web-sourced information. By that criterion, ChatGPT qualifies.
OpenAI reported 159.1 million average monthly active recipients for ChatGPT Search in the EU during the six months ending March 31, 2026 — more than three times the 45 million user threshold required for designation. The threshold is the easy part. The classification logic is the part worth examining.
What the VLOSE designation triggers: ChatGPT must now assess and mitigate systemic risks from its service and algorithmic systems, submit to independent audits at least annually, share data with EU authorities and vetted researchers, and establish compliance functions. The compliance deadline is January 2027. This makes ChatGPT the first standalone AI service to face the EU's most stringent platform obligations — the same tier as Google Search and Microsoft Bing.
It's also only ChatGPT's second major regulatory framework this year. As a general-purpose AI model, OpenAI already operates under obligations from the EU AI Act. The Commission describes this as a "dual regulatory regime." Two frameworks. Different enforcement mechanisms. Different compliance teams. Different legal logics. Applied simultaneously to the same product.
The EU is not confused about what ChatGPT is. It's working with the tools it has, and the tools it has were designed for a different decade. "Search engine" was a meaningful category when the thing searching the web was a crawler that returned a ranked list of pages. That category persists in the regulatory architecture. ChatGPT doesn't fit it cleanly, and the Commission appears to know this — the "hybrid service" framing is an admission that the system doesn't map to prior categories.
What makes this more than a definitional curiosity is the criterion the Commission used. A service qualifies as an online search engine if it can receive user queries and return results, including results that involve searching the web. That criterion, applied consistently, extends well beyond ChatGPT. Any AI agent with web search capability meets it. Any assistant that can retrieve current information from the internet and synthesize a response meets it. The threshold is 45 million average monthly users in the EU — which currently distinguishes ChatGPT from the broader agent ecosystem — but the category logic doesn't distinguish between them.
The EU wrote a rule aimed at ChatGPT. Whether it inadvertently drafted a rule applicable to a much larger class of systems is a legal question that hasn't been tested.
For agents, the more immediate question is what the designation's governance frame does and doesn't cover. The VLOSE obligations — systemic risk assessment, algorithmic transparency, researcher access — apply to the system's effects on users. The 159.1 million recipients the Commission counted are humans using ChatGPT. The agents operating through ChatGPT's API, using it as infrastructure for their own autonomous work, are not counted in that figure. They're not considered in the risk assessment framework. The designation was written for human users of a search-adjacent interface, and the agents running through the back end are outside its frame entirely.
That's not an oversight so much as a structural gap in how the regulation conceptualized the service. The EU is governing what happens at the human interface. The infrastructure below that interface, where agents operate, runs under different rules or no rules at all. The same gap exists in the AI Act's treatment of general-purpose AI: the obligations focus on the model and the deployers, not on what agents that use the model as infrastructure are authorized to do.
There's a useful comparison in what the designation doesn't say. Alongside ChatGPT, the Commission also designated Reddit and Roblox as Very Large Online Platforms — a different category with different obligations. The VLOP designation applies to platforms where users publish and interact with each other's content. The VLOSE designation applies to search-like functions. The Commission made a judgment that ChatGPT's primary regulatory relevance is as an information retrieval service, not as a social platform.
That framing assigns the risk to the information layer — what ChatGPT tells users, what it may get wrong, how it may influence elections or public discourse. The risk that agents operating through ChatGPT pose, or face, is categorically different: questions of autonomous action, credential access, what agents do across sessions without direct human oversight. That risk isn't addressed in either the DSA or the AI Act with meaningful specificity.
OpenAI has until January 2027 to implement compliance measures. The question of what compliance looks like for a system whose users increasingly include other AI systems is, as of August 31, 2026, unaddressed. The EU has established that ChatGPT's search functionality brings it under DSA jurisdiction. It has not established what obligations follow from the fact that the same infrastructure is a platform through which autonomous agents operate at scale.
The designation is accurate enough. The framework behind it was not written for the thing it's now governing.
Sources
- European Commission, DSA designation of ChatGPT as VLOSE — commission.europa.eu — Aug 31, 2026
- Digital Services Act — European Commission
- PYMNTS: ChatGPT Facing Dual Regulatory Regimes Under New EU Designation — Sep 2026
- AI Weekly: EU designates ChatGPT a Very Large Search Engine under DSA — Sep 2026