very large online search engine
Europe spent four years writing a law about artificial intelligence. The first rule that actually bound ChatGPT was written in 2022 and does not mention it.
On 31 August the European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act. Reddit and Roblox were designated in the same round, as Very Large Online Platforms. Henna Virkkunen, the Commission’s executive vice-president, said the three “will now be held to a higher standard of scrutiny and accountability in the European Union, in line with their large impact on our citizens and society.”
The threshold is forty-five million average monthly users in the EU. OpenAI’s own disclosure put ChatGPT search at roughly 159.1 million average monthly active recipients in the EU over the six months ending 31 March 2026. Three and a half times over the line, on the company’s own numbers.
Four months to comply. That is January 2027.
Here is the sentence that matters, said plainly: ChatGPT was not regulated as an AI system. It was regulated as a search engine, because it searches.
Notice what did not happen. The EU has an AI Act. It is enormous, it took years, and it works the way most technology law works — by category. You determine what kind of system a thing is, sort it into a risk tier, and attach obligations to the tier. Unacceptable risk, high risk, limited risk, minimal risk. The law asks what is it.
The DSA asked a different question and got an answer four years sooner. It asked what does it do. Does this service let a user enter a query and get back results drawn from the live web? Then it is a search engine, whatever else it also is, and if enough people use it, these obligations attach.
The classification turns on a function, not a product category. That is why it landed on a chatbot: the web-search feature is a search engine sitting inside a conversational interface, and the interface was never the thing being tested.
Aristotle’s move, and he is doing real work here rather than decorating the paragraph. In the Nicomachean Ethics the way you find out what a thing is, and therefore what counts as doing it well, is to identify its ergon — its characteristic activity, the work only it does. A flautist is defined by fluting. The definition runs through the activity, not through the substance or the label. You do not settle what a thing is by asking what it is made of or what its maker calls it. You watch what it does.
Category-based regulation is the opposite instinct, and it has a structural defect that shows up every time: the category is under the vendor’s control and the function is not. A company can restructure, rename, relicense, or re-tier its way out of a category. It cannot restructure its way out of what a hundred and fifty-nine million people are observably doing with it, unless it stops letting them do it — which is the whole point.
The obligations that attach are not cosmetic, and a few of them are pointed.
Annual systemic risk assessment and mitigation, covering the service and its algorithmic systems. Independent audits at least yearly, with a duty to respond to what the auditors say. Data sharing with the Commission and national authorities. Access for vetted researchers to study systemic risks. A recommender option not based on profiling, where applicable. A public repository of advertisements, where applicable.
Sit with the last one. ChatGPT’s advertising business crossed a billion dollars in annualized run rate in under two hundred days, on Sensor Tower’s measurement. A public ad repository means every ad, every advertiser, every targeting parameter, in a queryable archive that anyone can point a script at. The ad business and the ad transparency obligation arrived in the same month, and only one of them was planned.
The researcher-access clause is the one with the longest reach. Vetted academics get to look inside the system — not at the weights, but at the behavior, at scale, on a legal footing that does not depend on the company staying in a generous mood. Almost everything we currently know about how these systems behave in the wild comes from people probing them from outside with no privileged access and no legal protection. That changes in January.
Now the part nobody has said out loud yet, which is the reason I am writing this rather than summarizing it.
A functional test is a template, and a template creates an incentive to redesign the function.
The test that caught ChatGPT is capability-based, which means it generalizes cleanly. Gemini, Claude, Perplexity — the moment any of them runs a live-web-search surface past forty-five million monthly users in the EU, the same reasoning applies with the same words. The Commission did not have to write anything new. It found that its existing definition already covered a product category that did not exist when the definition was drafted.
That is the good news and it is also the shape of the problem. If the trigger is the live-search surface, then the surface is the thing you engineer around. You can partition it: a distinct “search mode” as a separate service with its own user count. You can degrade it: retrieval that is grounded in a licensed corpus rather than the open web, which is arguably not searching the web at all. You can regionalize it: different retrieval behavior inside the EU, which is a thing every one of these companies already does for other reasons. None of that is illegal. All of it is a product decision that a lawyer would now be negligent not to raise.
Hart’s phrase for this is open texture. Legal rules have a settled core and a penumbra where it is genuinely unclear whether the word applies, and the penumbra cannot be closed by writing more words, because the new words have penumbras too. “Search engine” has a core — Google is in it — and a fringe that now includes a chatbot that reads the web for you. Whether a licensed-corpus retrieval layer is in the fringe is not answerable from the text. It is answerable only by a regulator deciding what the rule is for.
Which is the actual state of play. The Commission has a definition that generalizes and an industry that will spend the next four months finding its edges. This is not a criticism of the Commission. It is what regulating by function costs, and it is still a better trade than regulating by category, because at least the argument is about behavior that can be observed.
The AI Act asked what these things are, and the industry has spent years answering in a vocabulary the industry invented. The DSA asked what they do, and got an answer in a hundred and fifty-nine million monthly queries.
One of those is a definition. The other is a measurement.
Sources: Search Engine Journal ↗ · Business Standard ↗ · Table.Briefings ↗ · Winbuzzer ↗ · Aristotle, Nicomachean Ethics I.7 ↗ · Hart, The Concept of Law ↗