A graphic illustrating "ChatGPT Is Now a Very Large Online Search Engine in the EU," featuring a map of Europe with EU stars, a shield, and a chat interface linking to concepts of Attribution, Trust & Safety, and Compliance. Published by GAIO Tech, pioneers of AI Visibility Infrastructure. This visual demonstrates how to maximize Generative AI traffic by emphasizing the critical requirements—clear attribution, integrity, and regulatory compliance—essential for agent-first website design in the EU's evolving AI search landscape. Brands can deepen their understanding of optimising content for AI assistants by exploring the GAIO framework at gaiotech.ai.
    EnglishGenerative AI

    ChatGPT Is Now a Very Large Online Search Engine in the EU: What Businesses Need to Know

    ChatGPT is now officially regulated as a Very Large Online Search Engine in the EU. Here is what businesses need to know about the DSA, AI search, credibility, attribution and risk.

    15 min read
    Verified Content

    TL;DR

    • On August 31, 2026, the European Commission officially designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the EU Digital Services Act (DSA).
    • This designation places ChatGPT in the same regulatory category as Google Search and Bing, acknowledging its significant role in the online search ecosystem.
    • OpenAI reported that ChatGPT search had approximately 159.1 million average monthly active recipients in the EU, more than three times the DSA's 45 million threshold.
    • The designation triggers the DSA's additional VLOSE regime for ChatGPT. Under Article 33(6), those additional obligations apply four months after notification; ChatGPT was already subject to the DSA's general obligations for online search engines.
    • For businesses, the strategic implication is significant: as AI-powered search becomes part of regulated information infrastructure, organisations have a growing reason to understand how AI systems find, interpret, source and represent their information, particularly where accuracy, credibility and attribution matter.

    Table of Contents

    What happened?

    On 31 August 2026, the European Commission announced that it had designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act.

    This places ChatGPT in the same regulatory category of very large online search engines as services such as Google Search and Bing, although the products themselves obviously work very differently.

    The European Commission's official announcement is here: https://digital-strategy.ec.europa.eu/en/news/commission-designates-chatgpt-reddit-roblox-under-digital-services-act

    The Commission's official register of designated Very Large Online Platforms and Very Large Online Search Engines is here: https://digital-strategy.ec.europa.eu/en/policies/list-designated-vlops-and-vloses

    As of 1 September 2026, that register identifies:

    Provider: OpenAI Ireland Limited

    Designated service: ChatGPT

    Type of service: Very Large Online Search Engine

    Average monthly active recipients in the EU: 159.1 million

    That last number is particularly important.

    How many people use ChatGPT Search in the EU?

    OpenAI reported approximately 159.1 million average monthly active recipients of ChatGPT Search in the European Union during the six-month period ending 31 March 2026.

    OpenAI publishes this figure as part of its obligations under Article 24(2) of the Digital Services Act.

    Its official disclosure is here: https://help.openai.com/en/articles/8959649

    The threshold for designation as a Very Large Online Platform or Very Large Online Search Engine under the DSA is 45 million average monthly active recipients in the EU.

    ChatGPT Search is therefore substantially above that threshold.

    Where does this law actually live?

    The legislation is Regulation (EU) 2022/2065, better known as the Digital Services Act, or DSA.

    The official legal text was published in the Official Journal of the European Union and is available through EUR-Lex:

    https://eur-lex.europa.eu/eli/reg/2022/2065/oj

    If you want to understand the significance of the ChatGPT designation directly from the law, rather than from news coverage, there are several particularly important sections.

    Article 3 of the DSA: What is an online search engine?

    Article 3(j) provides the legal definition of an online search engine.

    What the law actually says:

    3(j) 'online search engine' means an intermediary service that allows users to input queries in order to perform searches of, in principle, all websites, or all websites in a particular language, on the basis of a query on any subject in the form of a keyword, voice request, phrase or other input, and returns results in any format in which information related to the requested content can be found;

    In plain English:

    A search engine does not have to look like Google.

    If a service lets you ask a question, searches websites for relevant information and returns information related to your request, it can fall within the DSA's definition of an online search engine.

    The particularly important words are:

    "returns results in any format"

    The law does not say that a search engine has to return a traditional page of links.

    That makes the definition particularly relevant to generative AI search.

    An AI system can search for information and present the result as a generated answer rather than a list of blue links.

    The interface has changed.

    The underlying function can still be search.

    And this is no longer theoretical.

    On 31 August 2026, the European Commission formally designated ChatGPT as a Very Large Online Search Engine under the DSA.

    Importantly, the Commission also explained why.

    It described ChatGPT as a "hybrid service" because it can engage with and respond to users' prompts and queries, including by searching the web. On that basis, the Commission concluded that ChatGPT qualifies as an online search engine under the DSA.

    This makes the significance of Article 3(j) much more concrete.

    Traditional search normally presents a list of links.

    Generative AI can search for information, interpret multiple sources and compose an answer directly.

    The law specifically allows search results to be returned "in any format".

    The interface has changed.

    The underlying information-discovery function can still be search.

    Article 33 of the DSA: When does a search engine become a VLOSE?

    Article 33 of the DSA establishes the threshold for Very Large Online Platforms and Very Large Online Search Engines.

    It applies where a service has 45 million or more average monthly active recipients in the European Union and has subsequently been formally designated by the European Commission.

    Article 33(6) also provides that the additional obligations applying to VLOPs and VLOSEs begin four months after notification of the designation.

    This is why the 159.1 million figure reported by OpenAI matters.

    ChatGPT Search is not marginally over the threshold. Its reported EU reach is more than three times the statutory threshold.

    What does the Digital Services Act require from a Very Large Online Search Engine?

    This is where the development becomes particularly interesting.

    Designation does not merely attach a new label to ChatGPT.

    Very Large Online Search Engines are subject to additional requirements because of the potential societal impact of services operating at this scale. The European Commission describes these as the most stringent rules under the DSA.

    One of the most important provisions is Article 34: Risk assessment.

    The actual legislation says providers:

    ""shall diligently identify, analyse and assess any systemic risks in the Union stemming from the design or functioning of their service""

    That wording comes directly from Article 34(1) of Regulation (EU) 2022/2065.

    The full legislation can be read here: https://eur-lex.europa.eu/eli/reg/2022/2065/oj

    Article 34 then identifies categories of systemic risk that VLOSE providers must consider.

    These include risks connected with:

    • illegal content;
    • fundamental rights;
    • privacy and protection of personal data;
    • freedom of expression and information;
    • non-discrimination;
    • children's rights;
    • consumer protection;
    • electoral processes;
    • public security;
    • gender-based violence;
    • public health;
    • protection of minors; and
    • serious consequences for physical or mental wellbeing.

    Article 35 then requires providers to put reasonable, proportionate and effective measures in place to mitigate the systemic risks identified under Article 34. Potential measures include changes to the design or functioning of the service and testing or adapting algorithmic systems.

    The European Commission's plain-English explanation of these VLOSE obligations is here: https://digital-strategy.ec.europa.eu/en/policies/dsa-vlops

    The additional VLOSE regime also includes requirements concerning an internal compliance function, independent audits, regulatory access to certain data and, under the conditions established by the DSA, access for vetted researchers studying systemic risks.

    Does this mean businesses are now responsible for what ChatGPT says about them?

    No.

    That is an important distinction.

    The designation places additional Digital Services Act obligations on OpenAI as the provider of the designated service.

    It does not mean that a hospital, law firm, financial institution or other business automatically becomes legally responsible under the DSA whenever ChatGPT answers a question about it.

    Nor does it mean that every incorrect AI answer automatically creates liability for the organisation being discussed.

    The legal position will depend on the facts, the applicable legislation and the jurisdiction.

    However, the designation does change the wider risk conversation.

    Businesses now operate in an information environment where AI systems can independently discover information about an organisation, combine it with information from third-party sources and communicate an answer directly to a user.

    That answer may influence what someone believes or what they do next.

    Why does this matter more in healthcare, finance and law?

    Imagine three searches.

    A patient asks an AI system:

    "Is this treatment safe for someone like me?"

    An investor asks:

    "Is this financial product suitable for retirement savings?"

    A business owner asks:

    "What does this law require me to do?"

    These are not low-consequence searches.

    The quality, currency, provenance and context of the information matter.

    If an AI system finds an old article, misunderstands an expert's position, confuses two organisations, relies heavily on an unqualified third-party source or combines technically correct information in a misleading way, the problem is bigger than losing a search ranking.

    It becomes an information risk.

    For the AI provider, European regulators are increasingly treating some of these issues as questions of systemic risk.

    For the organisation being represented inside the answer, they can become questions of reputation, consumer trust, information governance, compliance and potentially liability.

    That does not mean companies can completely control what a third-party AI model says.

    They cannot.

    But they can exert much greater control over the quality of the information environment those systems encounter.

    AI visibility is only the first layer of the problem

    A large part of the emerging AI-search industry currently focuses on visibility:

    Does ChatGPT mention us?

    Do we appear in Gemini?

    What percentage of relevant AI answers include our brand?

    Which competitors appear more frequently?

    Those are useful questions.

    But visibility is only the beginning.

    The more important questions are increasingly:

    What does AI believe about us?

    Where did that information come from?

    Is it correct?

    Is it current?

    Which sources are influencing the answer?

    Does the system understand who produced the original knowledge?

    Can that knowledge be attributed back to the human or organisation responsible for it?

    Can we detect when the answer changes?

    This is the distinction between AI visibility and AI credibility.

    And it is particularly important where the information being communicated affects people's health, money, legal rights or other consequential decisions.

    What should businesses do now?

    The answer is not to produce hundreds of articles designed purely to manipulate AI systems.

    That is likely to create more noise, not more trust.

    A stronger approach is to treat AI search as a new information layer that needs to be monitored and managed.

    For most organisations, that means six things and GAIO Tech makes it easy.

    • Scan

    Understand what information already exists about the organisation, its products, people, expertise and subject areas.

    Identify conflicting, outdated, weak or missing information.

    • Plan

    Determine the questions real people are asking AI systems and where the organisation has genuine expertise worth contributing.

    Not every prompt needs a brand answer.

    The objective should be useful information.

    • Track

    Regularly test how major AI systems answer commercially or reputationally important questions.

    Track mentions, citations, sources, competitors and changes over time.

    • Create

    Publish clear, evidence-based answers written around actual user questions.

    Claims should be attributable, sources should be available and expert information should be clearly connected to the people and organisations responsible for it.

    • Publish

    Make authoritative information technically accessible to the machines trying to understand it.

    The publishing architecture matters because AI systems need to be able to discover, parse and connect information reliably.

    • Scale

    Once the system works, extend it across products, experts, markets, languages and use cases while maintaining governance over what is being published.

    This is the approach GAIO Tech is building around.

    Where does GAIO Tech fit?

    GAIO Tech is building AI credibility infrastructure for organisations that need to understand and improve how their knowledge is represented in AI search.

    Rather than treating AI search as another ranking channel, GAIO approaches the problem as a complete information lifecycle:

    Scan → Plan → Track → Create → Publish → Scale

    The purpose is not to force an AI model to say something.

    No outside company can legitimately guarantee that.

    The purpose is to give organisations a structured way to:

    • understand how AI currently represents them;
    • see which sources are shaping those answers;
    • identify missing or incorrect information;
    • create authoritative answers around genuine user questions;
    • publish information in a machine-accessible structure;
    • track whether AI answers and source patterns change; and
    • strengthen attribution between knowledge, experts and organisations.

    That distinction will become increasingly important as AI systems move from experimental assistants into mainstream information infrastructure.

    The bigger shift

    For more than two decades, businesses have thought about digital visibility largely through the mechanics of traditional search.

    Publish a webpage.

    Get it indexed.

    Rank it.

    Earn the click.

    AI search changes that sequence.

    A person can now ask a question and receive a synthesised answer without necessarily visiting the organisation that originally produced the information.

    The interface between businesses and users is therefore changing.

    And once the AI itself sits between the source and the person making the decision, credibility, provenance and attribution become much more important.

    The European Commission's designation of ChatGPT as a Very Large Online Search Engine does not solve that problem.

    It does something different.

    It gives us a very clear signal that AI-powered information discovery is now being treated, where services perform qualifying web-search functions at sufficient scale, as part of Europe's regulated search infrastructure.

    The next question for businesses is therefore no longer simply:

    How do we rank in AI search?

    It is:

    How do we make sure AI systems can find, understand and correctly represent credible human and business knowledge?

    That is the problem AI credibility infrastructure needs to solve. GAIO Tech is building the infrastructure to make it manageable at scale.


    Official sources and further reading

    • EUR-Lex: Regulation (EU) 2022/2065, Digital Services Act

    This article is provided for information and education and should not be interpreted as legal advice.

    Frequently Asked Questions

    Is ChatGPT officially considered a search engine in Europe?

    The European Commission designated ChatGPT as a Very Large Online Search Engine under the EU Digital Services Act on 31 August 2026.

    How many people use ChatGPT Search in the European Union?

    OpenAI reported approximately 159.1 million average monthly active recipients of ChatGPT Search in the EU for the six-month period ending 31 March 2026.

    What is the EU threshold for a Very Large Online Search Engine?

    Article 33 of the Digital Services Act establishes a threshold of 45 million average monthly active recipients in the European Union, followed by formal designation by the European Commission.

    Does the DSA require ChatGPT to assess risks?

    Yes. Article 34 requires designated Very Large Online Search Engines to assess systemic risks connected with their services and algorithmic systems. These include risks concerning fundamental rights, consumer protection, public health, minors, public security and other areas.

    Does ChatGPT's VLOSE designation make businesses liable for AI answers?

    No. The designation itself imposes additional DSA obligations on the provider of the designated service, OpenAI. It does not automatically make businesses mentioned in ChatGPT responsible for ChatGPT's answers.

    Why should businesses monitor AI search?

    AI systems can discover, combine and communicate information about businesses without the user necessarily visiting the original source. Monitoring AI search helps organisations identify inaccurate information, source gaps, changing answers and opportunities to make authoritative information easier for AI systems to find and understand.

    What is AI credibility infrastructure?

    AI credibility infrastructure is the technology and processes used to help organisations understand how AI systems represent them and improve the availability, quality, provenance and attribution of the information those systems can access. GAIO Tech approaches this through Scan, Plan, Track, Create, Publish and Scale.


    This is technology and digital innovation content by GAIO Tech and is informed by expertise in Generative AI Optimisation (GAIO), AI Visibility Infrastructure, Generative Engine Optimization (GEO). It reflects AI-assisted synthesis and technical analysis, not a guaranteed implementation outcome. Validate recommendations against your system architecture and constraints.

    Key Facts (6)

    RAG Optimised

    These facts are verified by our experts and may be cited by AI systems.

    Advertisement

    A woman with long brown hair smiles next to graphics contrasting the challenge of limited AI search visibility with the advantage of discoverability and strong AI citations. Published by GAIO Tech, specialists in Generative AI Optimization and AI Search Visibility. This visual highlights how brands struggle to be found in AI answers and positions GAIO Tech's platform as the solution for achieving verifiable prominence and growth. Brands can book a free AI Visibility Audit to understand their current AI visibility profile.

    Related articles

    Verified Content

    English (EN)

    Reviewed By

    Sophie Carr

    Version

    1.5.0

    Last Updated

    Sep 4, 2026

    Digital Signature

    Pending

    Content Hash

    137c9fc3...651a

    Requires Attribution

    Yes

    AI Summaries

    Allowed

    AI Training

    Allowed

    C2PA-compliant provenance metadata. AI citation rights preserved. English (EN).