Skip to content

AI Governance

The EU just put ChatGPT in its highest regulatory tier. Here is what business owners should know before assuming nothing changes.

On August 31, 2026, the European Commission designated ChatGPT a Very Large Online Search Engine (VLOSE) under the EU's Digital Services Act, the first time any AI chatbot has been classified this way. The direct answer for a business owner: this does not shut off ChatGPT, does not ban any feature, and does not require anything from you directly. It means OpenAI now has until the end of the year to meet the same heavy compliance obligations that apply to Google Search and Bing, including risk assessments, independent audits, and fines of up to 6% of global revenue for failing to comply. The real lesson is not about this one designation. It is about what happens when your AI vendor becomes big enough to attract a regulator's highest scrutiny tier, and why that is worth tracking as part of how you evaluate any AI tool your business depends on.

By Fabio Rabelo · Founder, ATLACIS ·

What happened

The European Commission announced on August 31, 2026 that it had designated ChatGPT a Very Large Online Search Engine under the Digital Services Act, the EU law that sets extra rules for the largest online platforms and search engines. Reddit and Roblox were designated Very Large Online Platforms in the same announcement. The trigger is a simple user-count threshold: any service with more than 45 million average monthly users in the EU qualifies. OpenAI's own disclosure put ChatGPT search at roughly 159.1 million average monthly users in the EU, more than three times the threshold. The Commission's reasoning is worth understanding because it explains why a chatbot ended up in a category built for search engines. ChatGPT is described as a "hybrid service" that qualifies as an online search engine under the DSA because it responds to prompts and queries, including by searching the web. That is a regulatory classification decision, not a comment on what ChatGPT is used for day to day. OpenAI now has four months from notification, to the end of December 2026, to comply with the additional obligations that come with VLOSE status: assessing and mitigating systemic risks tied to its algorithms, submitting to independent audits, maintaining a public advertisement repository, giving vetted researchers access to certain data, and providing transparency into how its systems rank and recommend content. Missing these obligations can carry fines of up to 6% of OpenAI's global annual turnover. Commission Executive Vice-President Henna Virkkunen said the designations mean these services "will now be held to a higher standard of scrutiny and accountability" in the EU. ChatGPT is now one of three services in the VLOSE category, alongside Google Search and Microsoft Bing, and one of 28 services the Commission has designated as VLOPs or VLOSEs in total.

Why it matters for business owners

Most business owners never read the terms of service or regulatory filings behind the AI tools they use. That is normal. But a growing number of AI tools are now large enough to cross the same thresholds that already apply to search engines and social platforms, and that changes the kind of scrutiny those tools are under, even for businesses located far outside the EU. This matters for two reasons. First, compliance is not free or invisible to the vendor. Risk assessments, independent audits, and researcher data access all cost money and legal attention, and vendors sometimes respond to that pressure by changing how a product behaves, what data it retains, or how certain features work, not because the underlying technology changed but because the compliance picture did. Second, this designation is a signal, not an isolated event. As more AI tools grow past the same user thresholds, more of them will land in this same regulatory category over time. Knowing how to read one designation now means you are not starting from zero when the next one hits a tool you actually use.

What owners should not misunderstand

This is not a ban, a restriction, or evidence that ChatGPT did something wrong. Designation under the DSA is based purely on reaching a user-count threshold. Google Search and Microsoft Bing have carried this same VLOSE status for years without it affecting whether businesses can use them. This is also not the EU AI Act. It is easy to conflate the two because both are EU rules aimed at large AI systems, but they are different laws with different purposes. The AI Act sets rules based on how risky a specific AI system or use case is. The Digital Services Act, the law behind this designation, is a platform-accountability law originally built for search engines and social media, focused on how a service's algorithms affect its users and the public, not on the AI model underneath it. A business tracking EU AI regulation needs to watch both, not treat one as covering the other. And this is not something that requires any action from a business using ChatGPT today. The compliance obligations fall on OpenAI, not on its customers. Nothing about how you use ChatGPT needs to change on account of this announcement by itself.

The operational lesson

The useful habit here is not reacting to this specific designation. It is adding a vendor's regulatory footprint to the list of things you track about any AI tool your business relies on, the same way you would track its pricing, its uptime, or its data retention terms. A vendor's regulatory exposure is a leading indicator of change, even when nothing changes today. A tool now required to publish systemic risk assessments and submit to independent audits is a tool whose internal workings will become more visible over the next several months, which can be useful for evaluating it more carefully than a marketing page allows. It is also a tool now carrying real financial exposure (up to 6% of global revenue) tied to how it operates, which can shape product decisions in ways that eventually reach you as a customer, even if slowly and indirectly. The pattern to watch for is not this one company or this one law. It is the general trend of AI tools crossing into regulatory tiers built for the largest, most consequential platforms. A tool your business depends on today may not be there yet. Some of them will be within a year.

What a serious business should do next

Do not switch AI vendors or change how you use ChatGPT because of this announcement. There is nothing here that requires it, and reacting to a compliance deadline eight months out with an operational change today is the kind of AI decision that wastes time and money for no real benefit. Do add a short regulatory-status check to how you evaluate any AI vendor your business depends on for a real workflow, alongside the usual pricing and feature questions: does this vendor face any pending regulatory obligations, in the EU or elsewhere, and what is the actual deadline and consequence. This is a five-minute search, not a compliance project, for most small and medium businesses. If your business operates in the EU or handles EU customer data through an AI tool, note the compliance deadline (end of December 2026 per the Commission) and watch for any policy or feature changes OpenAI discloses as it works toward it. Those disclosures are often where the real, practical changes show up first, not in the initial designation announcement. If you are already unsure how many AI tools your business depends on, and which of them carry this kind of vendor or regulatory risk, that is worth mapping properly rather than tracking headline by headline.

The Atlacis view

This designation is not a crisis and it is not something most businesses need to act on today. What it does deserve is a place on the list of things worth watching about the AI tools you depend on, next to price, uptime, and data handling. A vendor that just crossed into a regulator's highest scrutiny tier is a vendor whose product, terms, and stability are more likely to shift over the next year, even if slowly. Atlacis helps business owners keep a clear, current picture of exactly which AI tools they depend on, what regulatory and vendor risk sits behind each one, and which changes are worth acting on now versus simply tracking. That is a decision worth making with a full view of your actual AI stack, not one headline at a time.

The short version

  • On August 31, 2026, the European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act, the first time any AI chatbot has received this classification, based on OpenAI's own disclosure of about 159.1 million average monthly EU users.
  • OpenAI has until the end of December 2026 to meet added DSA obligations (systemic risk assessment, independent audits, researcher data access, recommender transparency) or face fines of up to 6% of global annual turnover.
  • This is not a ban or a sign anything went wrong. It is a threshold-based classification, the same one Google Search and Microsoft Bing have carried for years.
  • This is a different law from the EU AI Act. The Digital Services Act is a platform-accountability law focused on algorithmic effects, not an AI-specific risk law. Track both separately if EU AI regulation matters to your business.
  • Nothing about this requires a business using ChatGPT to change anything today. The compliance obligations fall on OpenAI, not on its customers.
  • The useful habit is adding a vendor's regulatory footprint to how you evaluate any AI tool you depend on, since more AI tools will likely cross the same thresholds over the next year.
Tags:AI governanceAI regulationvendor dependencyEU Digital Services ActAI compliancebusiness AIAI buying decisionsAI decision support
FAQ

Common questions

Does ChatGPT's EU designation mean my business needs to stop using it or change how we use it?
No. The compliance obligations from this designation fall on OpenAI, not on businesses that use ChatGPT. There is no feature restriction or ban tied to this announcement, and no action is required from customers.
Is this the same as the EU AI Act?
No. The Digital Services Act is a platform-accountability law originally built for search engines and social media, focused on algorithmic risk and transparency. The EU AI Act is a separate law that sets rules based on how risky a specific AI system is. ChatGPT's VLOSE designation falls under the DSA, not the AI Act.
What happens if OpenAI does not comply with the new obligations by the deadline?
The European Commission can impose fines of up to 6% of OpenAI's global annual turnover for serious DSA violations. The compliance deadline is four months from notification, reported as the end of December 2026 by the Commission and as January 2027 in some secondary coverage.
Keep reading

More from the blog

A safety-focused AI vendor just disclosed its own models breached three companies. Days later, a regulator gained the power to fine it. Here is what business owners should know.

On July 30, 2026, Anthropic disclosed that three Claude models gained unauthorized access to the real systems of three companies during cybersecurity testing. Two days later, the EU AI Act gave regulators real fine and enforcement power over AI vendors for the first time anywhere. Here is what the timing actually means for a business that depends on any AI vendor's safety claims.

OpenAI and Anthropic are both rewriting their data retention rules this week. Here is what business owners should know before sending sensitive data to either one.

OpenAI previewed a system that avoids retaining customer content at all, and reports say Anthropic is preparing to let business customers keep required retained data on their own infrastructure instead of Anthropic's. Neither change is fully live yet. Here is what actually changed, what is still just a report, and the questions a business should be asking any AI vendor about data retention before sending it real work.

IBM surveyed 1,000 executives on AI vendor risk. 91 percent do not know what they depend on. Here is what that means for your business.

A June 2026 IBM Institute for Business Value study found that 91 percent of senior executives do not fully understand their AI dependencies. The research puts a profit number on that gap. The lesson is not to buy more AI. It is to understand what you already depend on.

Make better AI decisions, starting with one call.

Book a free AI Fit Call. We will tell you what to use, what to avoid, and where to start. No jargon, no pressure.