ChatGPT DSA Designation Sweeps In Every AI Search Engine
The ChatGPT DSA designation reportedly makes it the EU's first AI-native very large online search engine. Here is the test deciding which AI tools follow.

In this article
- 1.What the ChatGPT DSA designation actually says
- 2.The DSA defines search engines by function
- 3.Does the DSA apply to AI chatbots with web search?
- 4.The three-question exposure test
- 5.Which AI products count as search engines under the DSA
- 6.The VLOSE obligation stack for search engines
- 7.What the stack costs an engineering org
- 8.What to watch and what to do now
The reported ChatGPT DSA designation makes OpenAI's chatbot the first AI-native very large online search engine in the European Union. Read as an OpenAI compliance story, it is a small one. Brussels classified by function, not label: regulators applied the Digital Services Act's definition of an online search engine to a chat interface that takes user queries and retrieves web content, and the definition fit. Every AI product doing the same thing now sits inside a perimeter drafted for Google and Bing, and for each team the only open variable is when, not whether, the 45 million EU-user threshold catches them.
Stay in the loop.
Get the latest posts and exclusive content delivered to your inbox.
Join 3 readers. No spam. Unsubscribe in one click, anytime.
This piece runs the test instead of summarizing OpenAI's to-do list. You get the functional definition as written in the regulation, a three-question version you can apply to your own roadmap, an exposure table scoring Perplexity, Gemini, Copilot, Grok, and Meta AI against that test, the very large online search engine (VLOSE) duty stack including the places where search engines carry a narrower set than platforms, and the engineering bill in sequencing terms. The dates, thresholds, and penalties here are the ones you can carry into a leadership briefing.
What the ChatGPT DSA designation actually says
Per the Commission's designation announcement, ChatGPT enters the VLOSE tier in the same batch that adds Reddit and Roblox as very large online platforms. Press reporting (The Decoder, The Verge) puts ChatGPT at least 45 million average monthly EU users, clearing the Act's numerical bar for the top tier. Google Search and Bing have been the only designated VLOSEs since April 2023, which makes this the first entry for a product that answers rather than links, and the template every later AI designation will copy.
The clock matters as much as the label. VLOSE obligations begin six months after the provider is notified of designation, and reporting places OpenAI's first heavy deliverables, the risk assessment and transparency reporting, around the end of 2026. Reports also mention an ad archive among the deliverables, an odd fit given that ad repositories are platform machinery under the DSA, so treat that detail as unconfirmed until the obligation list is published. One further open question is doing the rounds: whether a search engine designation lets Brussels reach training data as well as retrieved results. Legal experts are reportedly split, and nothing public settles it yet.
Two more facts frame the stakes for everyone else. First, being inside the DSA is not the news; every in-scope service already owes baseline duties. Designation moves ChatGPT into the tier where systemic-risk obligations, independent audits, and researcher data access attach. Second, the entry ticket was OpenAI's own number. Designations ride on self-declared user counts, which is why the counting question below is an engineering problem before it is a legal one.
The DSA defines search engines by function

The Article 3(12) definition of an online search engine has three moving parts: a service that lets users input queries to search, in principle, all websites; a basis in web crawling or indexing; and results returned "in any format" that can be ranked or prioritized. That last phrase is the load-bearing one. A page of ten blue links is a format. A synthesized paragraph with citations is also a format. When a model decides which sources to ground on, it is ranking and prioritizing, which is exactly what the article describes.
Two consequences follow, and both cut against how vendors describe themselves:
- The product label is irrelevant. "Answer engine," "copilot," and "assistant" are marketing terms. The regulation asks what the service does with a query, and ChatGPT's web search feature does precisely what Article 3(12) describes. That behavior, not the brand, is what pulled it into this lane.
- You do not need your own crawler. The text says results are produced on the basis of crawling or indexing, not that you must own the index. An assistant that retrieves through Bing, a partner feed, or a licensed index still matches the definition.
The boundary cuts the other way too. A chatbot with no web retrieval is not a search engine under this definition, whatever its marketing says. It may still be an online platform if it hosts user content publicly, or nothing in particular under the DSA. Classification attaches to behavior, and retrieval is the behavior nearly every roadmap plans to add.
Does the DSA apply to AI chatbots with web search?
If the service is offered to people in the EU and it takes open-ended queries and retrieves web content in response, the functional answer is yes: it can be a search engine under the DSA. Scale then decides the tier. Below 45 million average monthly recipients you owe baseline duties as an in-scope search engine; above it, you are a VLOSE candidate. ChatGPT web search regulation is now a live category, and the same logic reaches any chat interface with a retrieval step.
The three-question exposure test
The regulation collapses into three questions you can ask about your own product, including features still on the drawing board.
- Do you offer the service to recipients in the EU? The DSA covers services offered to recipients in the Union irrespective of the provider's place of establishment, and providers outside the EU must designate a legal representative under Article 12. Geography is not an exit.
- Does the product take open-ended queries and retrieve web content in response? This is the Article 3(12) function test above. Search boxes, chat boxes, and agentic browsing all qualify if web content comes back.
- Do you average 45 million monthly EU recipients? That is the DSA Article 33 threshold, measured on the Act's six-month self-declaration cycle, and designation follows the declared number.
Three yeses put you in the VLOSE lane with the full duty stack below. Yes, yes, and no means you are an in-scope search engine owing baseline duties today, with counting discipline as your early-warning system, because the only thing between you and the top tier is growth. A no on the second question means the search engine chapter does not reach you, though platform duties might if you host public user content.
Which AI products count as search engines under the DSA
Applying the test to named products, using public product behavior as of writing. These are our functional assessments against the DSA text, not Commission positions or legal advice.
| Product | Takes open-ended queries | Retrieves web content | Functional verdict | Open variable |
|---|---|---|---|---|
| ChatGPT | Yes | Yes, via web search | Meets the test; designated VLOSE | None, clock is running |
| Perplexity | Yes | Yes, own and partner indexes | Meets the test | EU recipient count |
| Gemini | Yes | Yes, grounding via Google Search | Meets the test | EU recipient count |
| Copilot | Yes | Yes, via Bing | Meets the test | EU recipient count |
| Grok | Yes | Yes, web plus X data | Meets the test | EU recipient count |
| Meta AI | Yes | Yes, via search partners | Meets the test | Count, and EU rollout scope |
Read the table as one claim: the only genuinely open variable in every row is the recipient count. Designations attach to services, not corporate groups, so Gemini's numbers are Gemini's even though Google Search is already designated, and Copilot's are Copilot's even though Bing sits in the tier. None of the five has been designated as of writing, and each is one growth quarter, or one self-declaration, away from the conversation OpenAI is now having. The ChatGPT DSA designation is unlikely to stay the tier's only AI-native entry, because the functional test above reaches every row in this table.
The VLOSE obligation stack for search engines

What actually attaches at the top tier, in the order a compliance team will sequence it:
| Duty | Anchor | What it means operationally |
|---|---|---|
| Self-declared EU user numbers | Article 33 | Count average monthly recipients on a six-month cycle; your number drives designation |
| Annual risk assessment | Article 34 | Assess named systemic risks, explicitly including minors, electoral processes, and mental wellbeing |
| Risk mitigation | Article 35 | Measures proportionate to findings, tested and documented |
| Independent audit | Article 37 and Delegated Regulation 2023/2917 | Annual external audit with a public summary |
| Researcher data access | Article 40 plus the delegated act on data access | Vetted researchers get real access, through APIs where feasible |
| Transparency reporting | Recurring reports | Orders received and measures taken, on a published cycle |
| Supervisory fee | The DSA supervisory fee rules | Up to 0.05% of worldwide annual net income |
| Enforcement ceiling | Article 52 fines | Up to 6% of global annual turnover |
Search engines do catch a break that most explainer coverage skips. The DSA's heaviest platform machinery, the notice-and-action takedown regime and the ad repository requirements, attaches to online platforms, and search engines carry a narrower baseline duty set as a result. The asymmetry ends at the VLOSE tier. The systemic-risk chapter applies to very large search engines in full, and it names the protection of minors and the integrity of electoral processes among the risks to assess. An answer engine with no takedown duty still has to assess how its outputs surface illegal content, deceive voters, or harm teenagers, then mitigate what it finds.
What the stack costs an engineering org
DSA VLOSE obligations for AI assistants read as law but ship as engineering workstreams. Sequence them like this.
- Recipient counting. Average monthly active recipients in the EU, deduplicated per the Commission's methodology, reported on the six-month cycle. Build this first, because designation rides on your own declared number, and the number exists whether or not you measure it.
- Risk evidence pipelines. The Article 34 risk assessment requirements demand data: eval runs on illegal-content surfacing, red-team logs, and incident registers covering minors and elections. Teams already running safety evals are halfway to an auditable evidence base.
- Mitigation features. Source-quality controls, citation and provenance surfaces, and age-aware design are the product-side artifacts an auditor will look for under Article 35.
- Audit readiness. Delegated Regulation 2023/2917 defines the audit methodology: documentation, sampling, an external auditor, and a public summary, repeated annually.
- Data access for researchers. The delegated act under Article 40 pushes toward API access for vetted researchers, which is a real platform build with rate limits, scopes, and a vetting workflow.
- Reporting operations. Orders-received logging and recurring transparency reports are lighter builds, but they sit on a fixed clock forever.
The honest picture of AI search compliance cost under the DSA is not a one-off audit fee; it is a standing cross-functional program touching platform, data, safety, and legal, plausibly a multi-quarter build to reach first audit readiness. Google Search and Bing have run this loop since 2023, and their published risk assessments and audit summaries are the best public image of what done looks like. No dollar estimate is needed to make the case: the fee of up to 0.05% of net income and the 6% fine ceiling do that work on their own.
What to watch and what to do now
Watch three things. The Commission's designation list is now the center of gravity for AI search engine regulation in the EU, and it will move in both directions as self-declared counts shift. The training-data question will resurface, because a designation that reaches model training would be a far bigger deal than one that reaches results. And the AI Act is a separate machine entirely; GPAI obligations and DSA systemic-risk duties run on different clocks, and neither substitutes for the other.
Do four things now. Run the three-question test on every product and roadmap item that retrieves web content, including agentic features that browse. Stand up EU recipient counting before any threshold conversation starts. Confirm your legal representative arrangement if you are not established in the EU. And read OpenAI's DSA page alongside the published risk assessments of the designated search engines, because that material is the disclosure template your team will eventually be filling in.
The ChatGPT DSA designation settled the classification question for every retrieval-heavy product shipping to the EU. What remains, per team, is the arithmetic of 45 million monthly recipients and a six-month clock.
Stay in the loop.
Get the latest posts and exclusive content delivered to your inbox.
Join 3 readers. No spam. Unsubscribe in one click, anytime.
About the author
Rachel Brennan
AI Research Editor
Rachel tracks AI research so the rest of us don't have to. With a background in NLP and a habit of reproducing papers, she turns new models and methods into ideas you can actually use.
Related Posts
NVIDIA Hugging Face Acquisition Ends the Neutral Hub
The NVIDIA Hugging Face acquisition turns the Hub into vendor infrastructure. Here is how builders mirror weights, pin revisions, and cut lock-in.
AI Agent Token Usage Overtook Humans on OpenRouter
OpenRouter data shows AI agent token usage passed human traffic on February 6, 2025, with 14x growth and ~70 percent cached. Here is how to audit your mix.
ChatGPT Business Premium Pricing Decodes Agent Token Math
ChatGPT Business Premium pricing at $125 reveals the real cost of agentic AI. Reverse-engineer the token math to set your own agent price floor.


