The European Commission on Monday designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act, bringing the world's most widely used chatbot under the same regulatory regime that governs Google Search and Microsoft's Bing. The decision, which took just under a year to finalise, imposes a suite of transparency and risk-mitigation obligations on OpenAI, with fines of up to 6 percent of annual global revenue for non-compliance.
Yet the designation is narrowly drawn. It covers only those parts of ChatGPT that function as a search engine, retrieving and ranking information from the web. The vast majority of user interactions, in which the model generates original responses, offers advice, role-plays or simply converses, fall outside the scope. That gap has left lawmakers and legal scholars questioning whether the EU's flagship digital rulebook is fit for the generative AI era.
A category error from the start
When the DSA was finalised in 2022, generative chatbots were a niche research project. The law's two main categories for very large services, Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs), were built for social networks, marketplaces and traditional search. ChatGPT fits neither.
João Pedro Quintais, associate law professor at the University of Amsterdam, describes the service as "a hybrid" technology. It retrieves and ranks information like a search engine, hosts user-generated conversations like a platform, and produces its own synthetic content like a publisher. The Commission's decision to place it in the search engine bucket reflects the path of least resistance rather than a coherent taxonomy.
Had the Commission chosen the platform designation, OpenAI would have faced broader content-moderation obligations, but would also have benefited from the DSA's "safe harbour" provision, which shields platforms from liability for user-uploaded content. That defence becomes legally awkward when the "user" is a machine generating responses in real time. The search engine label avoids that debate but creates a different one: what happens to the risks that live in the chat?
Children, therapy and the blind spot
Christel Schaldemose, the Danish socialist MEP who helped negotiate the DSA, has been among the most vocal critics of the narrow designation. "ChatGPT is much more than a search engine and there are also risks connected to the chatbot itself which fall outside the (regulation's) strongest obligations," she said. She pointed specifically to risks to children, including "emotional dependency and manipulative or addictive design."
Those are not hypothetical concerns. ChatGPT and rival systems have been cited in lawsuits following the suicides of teenagers, including 16-year-old Adam Raine of California, whose parents have sued OpenAI. Therapy and companionship are now mainstream use cases: an insurance industry study found that as many as 60 percent of adults globally use AI chatbots for therapeutic purposes. The DSA's search engine obligations do not obviously cover the design choices that encourage prolonged, intimate conversation with a non-human interlocutor.
Election integrity and the conversation gap
The regulatory blind spot extends to democratic processes. Under the DSA designation, asking ChatGPT to list candidates in a local election is a covered search function. But a user who asks the chatbot for voting advice, or engages it in a political debate, enters uncovered territory. Misinformation, hallucinated policy positions or subtle persuasion in that conversational flow would not trigger the same transparency or risk-assessment requirements.
This distinction, between a query and a dialogue, is technically thin but legally consequential. The Commission's designation text has not yet been published in full, so the precise boundaries remain opaque. Experts caution that without seeing the final instrument, it is impossible to know exactly which OpenAI obligations are activated and which remain dormant.
Two rulebooks, one service
While the DSA designation addresses the consumer-facing application, the Commission has been monitoring the underlying models through the AI Act since its entry into force. OpenAI, Anthropic and Google's Gemini are classified as providers of general-purpose AI models with possible systemic risks. Since August 2025 they have been required to assess and mitigate those risks, and the Commission began enforcement interviews at the end of that month.
The AI Act's systemic-risk taxonomy, however, leans heavily toward catastrophic scenarios: enabling nuclear or biological weapons, loss of control over models, autonomous hacking, or large-scale manipulation. Daniel Leufer of AccessNow argues that this framing neglects everyday harms. "[That guidance] is more focused on so-called existential risks than risks to fundamental rights," he said. The DSA designation offers a chance, in his view, "to get into the weeds of design decisions and treat ChatGPT more like what it really is, which is a product."
Complementary or contradictory?
Brando Benifei, the Italian Social-Democrat MEP who led the Parliament's work on the AI Act, defends the dual-track approach. He says the two rulebooks can "powerfully complement" one another, with the AI Act governing model-level risks and the DSA governing deployment-level risks. But he acknowledges that DSA oversight is "urgently needed" to protect actual users, citing "dangerous mental health dependencies" from companion chatbots as a concrete example.
The tension is structural. The AI Act regulates the engine; the DSA regulates the vehicle. But when the vehicle is a conversational agent that learns, adapts and forms relationships with users, the boundary between engine and vehicle dissolves. The Commission's decision to designate only the search function suggests it is not yet ready to confront that dissolution.
What the designation actually changes
In practical terms, OpenAI must now publish a transparency report on its search-related recommender systems, provide a point of contact for authorities, and conduct annual risk assessments covering the search function. It must also allow vetted researchers access to data on how its search engine operates. These are meaningful obligations, but they map onto a fraction of ChatGPT's traffic.
The company has not publicly detailed how it will separate search from chat for compliance purposes. Technically, the same model serves both functions; the distinction is made at the interface layer. That raises the prospect of regulatory arbitrage: features that look like search could be rebranded as chat to evade scrutiny, or vice versa.
People mentioned
-
João Pedro Quintais
Organisations
European Commission · OpenAI · European Parliament · AccessNow · University of Amsterdam