news / 2026 / chatgpt + openai A regulatory audit desk maps chatbot queries, source retrieval, generated answers, risk reports, and researcher-access requests around the EU's search-platform rules.

news

Europe Classified ChatGPT as Search Infrastructure

Europe has decided that a chatbot synthesizing the web performs a search function with public consequences, giving regulators access to the machinery behind the answer.

The European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act on August 31. It is the first standalone chatbot placed in the European Union’s heaviest search-platform tier. Reddit and Roblox joined the same announcement as Very Large Online Platforms, while ChatGPT received the classification that matters here: search infrastructure.[1][3]

OpenAI had already published the number that made designation hard to avoid. ChatGPT search recorded about 159.1 million average monthly active recipients in the EU during the six months ending March 31, far above the DSA threshold of 45 million.[5] The Commission has now attached an operating regime to that audience.

This is a specific new development in Europe’s attempt to govern AI through interfaces and infrastructure. The AI Act recently turned disclosure into a visible product obligation. The DSA also turned researcher access into a fight over platform data, quotas, and reproducibility. ChatGPT’s designation joins those systems at the point where a prompt becomes an answer. The new fact is formal classification: the Commission has decided that a service which searches the web and synthesizes a response qualifies as an online search engine.[6]

Search became an answer-shaped product

The useful part of the decision is its functional reading of search. ChatGPT can converse, draft, calculate, transform files, and answer from model knowledge. When it retrieves web material in response to a query, the Commission says the hybrid service qualifies as an online search engine under the DSA.[6]

That closes an increasingly absurd semantic escape hatch. Search stopped looking like ten blue links years ago. A ranked page, a map panel, a product carousel, a knowledge box, and a synthesized paragraph all mediate access to information. The interface changed before the power relationship did.

A February legal analysis in Verfassungsblog mapped the statutory route before the designation arrived. Article 3(j) covers an intermediary service that accepts queries and returns results in any format where information related to the requested content can be found. The analysis argued that synthesis fits the functional definition even when the interface does not present a traditional index of links.[2] The Commission’s decision now turns that interpretation into an enforcement position.

The classification also creates a cleaner account of what users are doing. A person asking ChatGPT about an election, a medical symptom, a protest, a product, or a war may experience the exchange as conversation. Operationally, the service retrieves, ranks, compresses, and presents information. Its prose can hide the seams that a conventional results page exposes. Source selection, omission, ordering, uncertainty, and personalization still shape the answer.

The answer now has an audit trail

Designation starts a four-month compliance clock. By the end of December 2026, OpenAI must meet the additional duties applied to VLOSEs. The Commission identifies systemic-risk assessment and mitigation across illegal content, fundamental rights, minors, physical and mental well-being, electoral processes, and public security.[6]

The standing VLOSE rules make that list concrete. Designated services need an internal compliance function, an independent annual audit, data sharing with regulators, access for vetted researchers studying systemic risks, transparency around advertising and recommendation systems, and a recommendation option that does not rely on user profiling.[4] These obligations reach beyond a content-policy page. They require evidence about how the service behaves.

That distinction matters because generated answers are hard to inspect from outside. A researcher can collect prompts and outputs, but the resulting sample says little about retrieval candidate sets, source ranking, model routing, safety interventions, personalization, session state, or experiments active at the time. The same prompt may travel through different paths. A clean screenshot can conceal a filthy decision chain.

Regulated data access offers a route into that chain. It could let qualified researchers connect observed outputs to system conditions, measure whether effects persist across languages and user classes, and distinguish a repeatable failure from stochastic debris. The DSA does not guarantee that the resulting access will be fast, broad, or pleasant. Existing platform fights show that application gates, privacy review, format decisions, quotas, and reproducibility can turn a legal right into procedural fog. Formal access still gives outsiders a stronger position than scraping a black box and hoping the sample means what it appears to mean.

A second law now reaches the same interface

The AI Act and DSA approach the product from different directions. The AI Act governs AI systems, providers, model transparency, disclosure, and risk categories. The DSA governs intermediary services and the societal effects produced by large distribution systems. ChatGPT now sits inside both frames.

That overlap is useful when it follows the actual system. A model card can describe a model while missing the production service wrapped around it. The live product adds retrieval, browsing, memory, ranking, account state, moderation, tools, experiments, and commercial incentives. VLOSE supervision can inspect the service layer where those parts meet users.

It also creates responsibility for the final arrangement. OpenAI cannot treat a harmful information pattern as somebody else’s search result, a raw model quirk, or an isolated prompt artifact when the production system selected, assembled, and delivered the answer. The Commission’s press release says designation gives it investigative powers over service functionality and any related system where applicable.[6] That phrase reaches toward the complete answer pipeline.

The hard work begins in the implementation. “Systemic risk” can become an expensive binder produced once a year, or it can become a continuous engineering discipline tied to incident reporting, launch gates, red-team evidence, language coverage, researcher findings, and public remediation. Independent audits can expose weak controls, or they can become compliance theater performed by firms that depend on the same companies for repeat business. Researcher access can reveal the mechanics of information power, or drown applicants in portals.

The designation settles the first argument. Europe has classified ChatGPT according to the function it performs in public life, rather than the friendly shape of its interface. A generated paragraph can route attention, compress disagreement, bury provenance, and become the terminal source for a user who never opens another page. Search power survived the disappearance of the search-results page. The law has finally followed it into the answer box.

Sources

[1] https://digital-strategy.ec.europa.eu/en/news/commission-designates-chatgpt-reddit-roblox-under-digital-services-act | European Commission designates ChatGPT under the DSA [2] https://verfassungsblog.de/searching-for-answers | Searching for Answers: ChatGPT under the DSA [3] https://www.lemonde.fr/en/pixels/article/2026/08/31/chatgpt-becomes-first-ai-chatbot-to-face-tougher-eu-rules_6757011_13.html | ChatGPT becomes first AI chatbot to face tougher EU rules [4] https://digital-strategy.ec.europa.eu/en/policies/dsa-vlops | DSA rules for very large platforms and search engines [5] https://help.openai.com/en/articles/8959649-eu-digital-services-act-dsa | OpenAI EU monthly active recipients for ChatGPT search [6] https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1772 | European Commission press release on ChatGPT DSA designation