i
DATAIST
News · 2026-08-31

EU designates ChatGPT a very large search engine under the DSA

@neuronium_ai @neuronium_ai

The European Commission announced in Brussels on Monday that ChatGPT will be supervised as a very large search engine under the Digital Services Act. The reasoning is narrow and worth reading closely: the service was classified this way because it searches the internet and answers user queries, and because it clears the threshold of at least 45 million monthly users in the EU. Reddit and Roblox were reclassified in the same decision as very large online platforms, on the grounds that users can publish material there created by other users. Europe did not decide to regulate a model. It decided to regulate a retrieval surface.

Cover: EU designates ChatGPT a very large search engine under the DSA

The European Commission announced in Brussels on Monday that ChatGPT will be supervised as a very large search engine under the Digital Services Act. The reasoning is narrow and worth reading closely: the service was classified this way because it searches the internet and answers user queries, and because it clears the threshold of at least 45 million monthly users in the EU. Reddit and Roblox were reclassified in the same decision as very large online platforms, on the grounds that users can publish material there created by other users. Europe did not decide to regulate a model. It decided to regulate a retrieval surface.

All three services have four months — until the end of December 2026 — to take on the additional obligations. They must assess risks to users, examine the spread of illegal content, analyse threats to minors, and evaluate possible interference in elections. The Commission gains expanded powers to inspect the services and will work with the authorities in Ireland and the Netherlands. Executive Vice-President Henna Virkkunen said platforms and search engines will have to undergo stricter supervision. Twenty-eight platforms and search engines are now classified under the DSA.

For ChatGPT specifically, the Commission first acquires the right to examine the risks associated with the service and the principles by which it works. The practical requirements are:

a publicly accessible advertising archive;

data access for approved researchers;

transparency reports twice a year;

mechanisms for reporting illegal content, and a complaints procedure;

a crisis response mechanism.

The contested part is data access. Lawyers have not reached agreement on whether it extends to training data or model weights. Natali Helberger, a professor of law at the University of Amsterdam, told Tech Policy Press that this raises questions about the boundaries of the data-access right, and that the obligation set out in Article 40 could potentially include training data and model weights if they are necessary to identify systemic risks or to assess measures for reducing them. The new classification, meanwhile, does not explicitly permit the Commission to test models itself.

Those two sentences describe the whole enforcement problem. A regulator that can compel documents but cannot run the system it is regulating is in a materially weaker position than one that can. For a ranked list of links, inspection by paperwork is workable: the ordering is an artefact you can capture and audit after the fact. For a system that generates an answer, the output does not exist until the query is made, and there is no archive of counterfactual answers to subpoena. Article 40 access to weights, if it survives the legal argument, is the Commission's substitute for a test harness — which is probably why the industry will fight it as hard as it fights anything in the DSA.

The advertising archive requirement is the other item that repays attention, because it is written for a business model that sells placement inside results. Applied to an assistant that composes answers, it is either a dead letter or a forward-looking constraint on how commercial content could be inserted into generated text. Nothing in the announcement says which.

The larger question the classification leaves open is what a systemic risk even means here. The four duties — illegal content, minors, elections, user risk — were drafted for services that host and rank material other people made. ChatGPT's category is search, but its output is not a list of documents someone else is responsible for; it is a synthesised statement the service itself produced. The obligations transfer cleanly onto Reddit and Roblox, which are platforms in exactly the sense the law was written for. They transfer onto ChatGPT only by analogy.

That analogy now has a four-month deadline attached to it. Whatever the Commission's first inspection under this designation looks like, it will set the working definition of how an answer engine gets audited in Europe — and it will do so before the lawyers have settled whether the regulator is entitled to look inside the model at all.