A first, and a stretch
On August 31, 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine (VLOSE) and named Reddit and Roblox Very Large Online Platforms (VLOPs) under the Digital Services Act, based on user figures the companies themselves reported: 159.1 million average monthly EU users for ChatGPT, 57.2 million for Reddit, and 46.6 million for Roblox — all comfortably above the DSA's 45-million statutory threshold (European Commission, list of designated VLOPs and VLOSEs). It is the first time an AI chatbot has been pulled into the DSA's strictest supervisory tier. All three companies now have four months — until late December 2026 — to comply with systemic-risk assessment, independent audit, and researcher-data-access obligations, or face fines of up to 6% of global annual turnover (Shaping Europe's Digital Future, DSA VLOPs).
The case for it
The Commission's underlying logic deserves a fair hearing before it gets a rebuttal. The DSA's systemic-risk regime exists because scale changes the character of harm: a chatbot answering 159 million Europeans a month, some of them minors, is not a niche product anymore, and the DSA's designers set the 45-million bar precisely to catch services whose reach makes individual complaints an inadequate check (EU Digital Services Act, Art. 33 commentary). Reddit and Roblox are uncontroversial VLOP calls — both are classic platforms hosting user content and social interaction at exactly the scale Article 33 was built for. And a conversational interface that increasingly substitutes for a search box, surfacing answers instead of links, is a reasonable thing for a search-focused regulator to want inside its remit rather than exempt from it by technicality. EU technology chief Henna Virkkunen framed the move as proportional to reach: "ChatGPT, Reddit and Roblox will now be held to a higher standard of scrutiny and accountability in the European Union, in line with their large impact on our citizens and society" (BNN Bloomberg/AFP).
Where the fit breaks down
But naming ChatGPT a search engine doesn't make it one, and the DSA's own taxonomy struggles with the mismatch. As legal scholars writing on the designation have pointed out, the statute defines three functional categories — mere conduit, caching, hosting — and "ChatGPT does not seem to fit in either of the three," because it doesn't index and return links so much as generate synthesized answers, only some of which trace back to anything resembling a search act (Tech Policy Press). That's not a pedantic distinction. The DSA's VLOSE-specific duties — ranking transparency, an advertising repository, researcher access keyed to how results are surfaced — were engineered for services that rank and display third-party links. Bolting them onto a model that produces original text output means either the obligations get reinterpreted so loosely they lose bite, or OpenAI ends up building compliance infrastructure that doesn't map cleanly onto how the product actually works. Neither outcome serves the stated goal of managing risk; both simply add cost.
Two regulators, one company, unclear lines
The deeper problem is duplication. ChatGPT already sits inside the EU AI Act's Chapter V regime for general-purpose AI models with systemic risk — model evaluation, adversarial testing, incident reporting to the AI Office, cybersecurity obligations, all triggered by compute thresholds rather than user counts. Layering the DSA's systemic-risk assessment and audit cycle on top means OpenAI now runs two parallel risk-management programs, assessed by two different Commission units, against overlapping but not identical definitions of harm. The same Tech Policy Press analysis notes experts flagging "clear overlaps between the DSA and the AI Act" on transparency and systemic-risk requirements specifically because of this stacking. For a fast-moving product category, that's not redundancy as a feature — it's two compliance calendars, two audit firms, two sets of risk documentation, for the same underlying model behavior. Firms with OpenAI's balance sheet can absorb it; the smaller conversational-AI challengers the EU says it wants to see compete against ChatGPT will feel it more acutely if they ever cross 45 million EU users themselves.
What proportionate would look like
None of this argues against oversight of a chatbot with this much reach. Illegal content, manipulation of minors, and electoral interference are real risk categories regardless of whether the tool in question is a ranked list of links or a generated paragraph. But proportionate regulation means fitting the rule to the risk, not fitting the product to whichever rule happens to have a ready-made enforcement apparatus. The Commission would do better to clarify, ahead of the December deadline, precisely which DSA obligations apply to ChatGPT's actual mechanics versus which are satisfied by the AI Act obligations OpenAI already carries — rather than leaving two regulatory regimes to sort out the overlap through enforcement actions after the fact. Reddit and Roblox present no such ambiguity; ChatGPT does, and the Commission's designation decision doesn't resolve it so much as defer it to the compliance period now underway.