From the journal

European Commission Designates ChatGPT a Very Large Online Search Engine Under DSA

On 31 August 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine and Reddit and Roblox as Very Large Online Platforms under the Digital Services Act. OpenAI reported 159.1 million average monthly active recipients in the EU for the six months ending 31 March 2026, exceeding the 45 million designation threshold by more than three times. Designated services must meet enhanced DSA obligations within four months of notification.

2 min read

On 31 August 2026, the European Commission issued designation decisions classifying ChatGPT as a Very Large Online Search Engine (VLOSE) and Reddit and Roblox as Very Large Online Platforms (VLOPs) under Regulation (EU) 2022/2065 (Digital Services Act, 'DSA'). This is the first time the VLOSE category has been applied to a generative AI assistant.

Article 33(4) DSA requires the Commission to designate a platform or search engine once it has confirmed that the service reaches 45 million or more average monthly active recipients in the EU. OpenAI self-reported 159.1 million such recipients for the period ending 31 March 2026. VLOSE status triggers obligations under Articles 38 to 42 DSA, covering algorithmic transparency, independent audits, researcher data access, and systemic risk assessment on recommender systems.

OpenAI must comply with VLOSE obligations within four months of notification, placing the deadline in late December 2026 or January 2027. In that period OpenAI must complete an annual systemic risk assessment under Article 34 DSA, adopt mitigation measures, arrange independent audits under Article 37 DSA, and provide researchers with access to public data under Article 40 DSA. The Commission supervises compliance in cooperation with Coimisiún na Meán and may impose fines of up to 6% of OpenAI's global annual turnover.

No settled standard yet defines how the algorithmic transparency obligations under Article 38 DSA apply to a large language model rather than a conventional search index. The Commission and ENISA have indicated that guidance is forthcoming. Other AI-powered services offering search-like query-and-response features may face designation if their monthly EU recipient counts cross the 45 million threshold.

Licentium and its partner network advise AI developers and online platform operators on DSA compliance. Work we undertake includes VLOSE and VLOP designation analysis, risk assessment design, algorithmic transparency reporting, audit preparation, and engagement with national Digital Services Coordinators.

Source: European Commission, Press Release IP/26/1772: Commission Designates ChatGPT, Reddit, Roblox Under the Digital Services Act, 31 August 2026

More from the journal

See all

Dutch DPA Fines Uber €824.99 Million for GDPR Article 22 Violation, August 2026

On 21 August 2026, the Autoriteit Persoonsgegevens imposed a fine of €824,990,000 on Uber B.V. for fully automated deactivation of drivers' accounts in breach of GDPR Article 22, which prohibits automated individual decision-making that produces legal or similarly significant effects on data subjects without a qualifying exception. The penalty is the second largest GDPR fine on record, behind the €1.2 billion fine imposed on Meta by the Irish DPA in 2023.

MAS Consults on Legislative Implementation of Singapore Stablecoin Regime, 1 September 2026

On 1 September 2026, the Monetary Authority of Singapore published a consultation paper setting out draft amendments to the Payment Services Act 2019 to convert its 2023 stablecoin policy into enforceable statute. Key proposals require 100% reserve backing in high-quality liquid assets, prohibit interest payments on MAS-regulated stablecoins, and restrict the 'MAS-regulated stablecoin' label to licensed issuers only. The consultation closes on 16 October 2026.

EU Cyber Resilience Act Reporting Obligations Take Effect 11 September 2026

The EU Cyber Resilience Act's incident and vulnerability reporting requirements take effect on 11 September 2026, more than fourteen months before the Act's full compliance date of December 2027. Manufacturers of products with digital elements placed on the EU market must notify national CSIRTs and ENISA of actively exploited vulnerabilities within 24 hours and of severe security incidents within 72 hours, with a final report due no later than 14 days after a corrective measure is available.