Posted on: 8 September 2026
Today's story takes place in the European Union and concerns three services. ChatGPT joins the Very Large Online Search Engines under the Digital Services Act, while Reddit and Roblox go in as Very Large Online Platforms. The threshold sits in Article 33 of the DSA at forty-five million average monthly users in the Union. There is nothing to argue about on the numbers, because the designated company supplied them: over the six months to 31 March 2026 the chatbot's search functions recorded 159.1 million monthly active users in the EU.
The prevailing reaction was that Brussels had mistaken a generative system for a search engine. That is not quite what happened. The Commission's reasoning says ChatGPT responds to prompts including by searching the web, which makes it a hybrid service qualifying as an online search engine for the purposes of the regulation. What allows this is the technological neutrality of the definitions, under which European digital law classifies a service by the function it performs. Article 3(j) of Regulation 2022/2065 was drafted three years before this case existed and caught it without a line of new text. Whoever signed the designation knew perfectly well that ChatGPT is not Google, and that is precisely why they signed it.
The Commission had a tooling problem. The AI Act has obligations on general purpose models in force since 2 August 2025, yet it gives Brussels no powers of inspection, information request or sanction over a consumer-facing service. The DSA has those powers, tested since April 2023, with an enforcement apparatus already running and a direct precedent, because in 2024 the Commission used the DSA to ask Microsoft for information on generative AI risks inside Bing. August's designation was a seizure of jurisdiction carried out with the instrument that was already on the bench.
British readers have a reason to recognise the move rather than watch it from outside. Ofcom got there first and did it without a press cycle. In an open letter of 8 November 2024 the regulator told UK service providers that generative AI tools capable of searching more than one website or database fall within the definition of a search service under the Online Safety Act, whether they modify results on an existing engine or deliver live results on their own platform. Same manoeuvre, same reasoning about function over technology, twenty-two months earlier. The OSA has been largely live and enforceable since July 2025 and nobody wrote that Britain had decided a chatbot was Google. The difference is procedural rather than conceptual, because Ofcom issued guidance while the Commission issued a formal designation with a compliance clock attached.
That clock runs out at the end of December. Three different deadlines have appeared in the Italian press for the same date, which tells you something about the attention the story received.
Here is where it gets interesting, because the obligations the DSA triggers for a VLOSE were written for a service that orders and presents content produced by other people. Transparency on the main ranking parameters, complaint and redress mechanisms covering content decisions, researcher access to data, a public advertising repository. Each of those presupposes third-party content, a criterion applied to that content and somebody in a position to object to how it was handled.
On a system that writes the answer itself, half those categories have nothing to attach to. What are the ranking parameters of a text generated on the spot and never identical twice? Who brings a complaint, when the content belongs to nobody? The first serious compliance exercise will be an act of translation and nobody yet knows how far it holds.
So far this is a technical legal matter of interest to perhaps a hundred people in Europe. The level that matters for anyone making allocation decisions is somewhere else.
VLOSE obligations are fixed costs. Annual systemic risk assessment, documented mitigation measures, independent external audit, an internal compliance function, a structured channel for researchers, periodic reporting to the Commission. None of it scales with revenue, because the risk assessment document costs roughly the same whether you turn over ten million or ten billion. For OpenAI this is accounting noise. For a European service attempting the same scale it is a budget line that consumes a team's year.
The moat here was dug around the dominant operator by the regulation that claims to be supervising it.
We have seen this pattern before and it is not even recent. Compliance cost as a barrier to entry is the standard architecture of regulatory capture, where the incumbent asks for rules that only it can afford. Banking has worked this way since Basel II. What differs in European digital policy is that the capture owes nothing to effective lobbying, arriving instead as a side effect of a sincere worry. Which makes it harder to correct, because nobody wanted it and so nobody defends it.
At this point the easy thesis would be that Europe is isolating itself by regulating what it cannot build. That thesis has been circulating for weeks and it does not survive checking.
The GDPR dates from 2016 and has applied since May 2018. It was received with the same alarm, the same predictions about American investment fleeing, the same editorials on European digital suicide. Eight years on, Brazil has the LGPD, India has the Digital Personal Data Protection Act of 2023, California has the CCPA and then the CPRA. None of those jurisdictions copied Europe out of admiration. They copied because for a global company running two data architectures costs more than adopting the strictest one everywhere. Brussels exports the definition of the product rather than the product, and historically that has earned it more than it has cost.
The UK ran the counter-experiment and the result is instructive. Post-Brexit divergence on data protection was announced loudly and delivered thinly, with the Data (Use and Access) Act 2025 trimming at the edges while adequacy with the EU stayed the priority. Nobody in Whitehall wanted to explain to British business what losing it would cost.
So the right question is whether this particular architecture of obligations reproduces the GDPR's voluntary adoption effect, or whether it produces a defended perimeter through which three American operators pass.
There are two ways to get this wrong and intelligent people commit both. The first is imagining that without the DSA Europe would have had a competitive AI ecosystem. It would not have, and the evidence predates the law, because no European digital service founded after 2010 has ever crossed forty-five million users in the Union and most of that period ran without any meaningful digital regulation at all. The cause of European lateness lies elsewhere and anyone pinning it on the regulation has reached for the comfortable explanation over the sound one.
The second error is symmetrical and consists of saying that because the GDPR worked, this will too. The GDPR imposed a constraint on an activity everyone was already carrying out, whereas the DSA imposes process obligations on a scale of activity that nobody in Europe has yet reached, and the whole difference sits there.
What to watch, then, instead of the press releases.
The first marker is the compliance document OpenAI files by the end of December. If the ranking parameters entry gets filled in with a description of how web retrieval works rather than how the model works, the designation will have caught the search function alone. That is the restrictive reading, and also the one that keeps the legal coherence intact at the price of making the whole exercise close to symbolic.
The second is Mistral. Founded in Paris in 2023, it is the only European actor that could realistically approach forty-five million within three years. Reach it and absorb the obligations without slowing, and the moat thesis is falsified. Reach it and slow, or stop just below, and the answer comes with a margin of ambiguity nobody will resolve.
The third is the Commission itself. The AI Act reaches full application in 2027 and at that point a purpose-built instrument exists for these systems. What happens to the DSA designation then will say whether 31 August was a stopgap or a position to hold.
Anyone betting on this should meanwhile notice one thing. Reddit went into the same announcement, with identical obligations and for the first time, and in a week I have not read a single comment about it.