Written by Jeremy Souffir Founder, JTS Tech Services

The short version: today, 31 August 2026, the European Commission designated OpenAI's ChatGPT as a Very Large Online Search Engine under the Digital Services Act — the first generative AI chatbot to be designated at all — alongside Reddit and Roblox as Very Large Online Platforms. If you sell things online, the instinct is to file this under compliance news and move on, and that instinct is half right: none of the obligations land on you, they land on OpenAI, and if you are a Canadian or American merchant you are not the regulated party in any sense. The reason to read on is the other half. Designation forces a set of public disclosures into existence by the end of December, and two of them describe, in OpenAI's own words and under legal jeopardy, how the thing that decides whether your products get mentioned actually decides. We have spent two years inferring that from studies and experiments. It is about to be written down.
What exactly did the Commission decide?
The DSA has a size trigger: cross 45 million average monthly active users in the EU and the Commission can designate you into its strictest tier, where a much heavier set of obligations applies. The interesting part is not that ChatGPT crossed it — it crossed it a long time ago — but which box it was put in.
- OpenAI declared roughly 159.1 million average monthly EU users for ChatGPT's search function, over the six months ending 31 March 2026. That is more than three times the 45 million threshold, and a sharp jump on its own earlier self-reported figures.
- The Commission classified ChatGPT as a hybrid service, and designated it specifically as a search engine — a VLOSE — on the reasoning that it engages with and responds to users' prompts and queries, including by searching the web. That is the sentence doing all the work here.
- Reddit (57.2 million declared EU users) and Roblox (roughly 48 million) were designated in the other category, as Very Large Online Platforms. Only ChatGPT got the search-engine label.
- The compliance clock is four months from designation, so the additional obligations bite at the end of December 2026. Nothing changes tomorrow.
- The ceiling for non-compliance is fines of up to 6% of global annual turnover. This is not a reporting exercise with a shrug attached.
- Executive Vice-President Henna Virkkunen framed it as holding the three services "to a higher standard of scrutiny and accountability in the European Union, in line with their large impact on our citizens and society". Twenty-eight services now sit in this tier.
Read the second bullet again, because it is the one with consequences outside Europe. A regulator with real enforcement history has looked at an AI assistant answering shopping and research questions and concluded that the correct legal category for it is not "chatbot" and not "social platform" but search engine. Everyone in commerce has been saying some version of that informally since 2024. It now has a decision behind it, and the obligations that attach to search engines under the DSA are the ones about ranking.

Why does a European classification matter to a merchant in Toronto?
Because compliance documents are public, and ChatGPT is one product. When a VLOSE publishes a statement of the main parameters used in its recommender systems, it does not publish a European version of its ranking logic and keep a separate secret one for everyone else — it describes the system it runs. The same is true of the advertisement repository: it covers EU-served ads, but the advertisers in your category, the way they target and roughly how far they reach are the same commercial facts wherever you are standing. This is the well-worn pattern from GDPR and from the DSA's first wave, where the disclosures forced out of Google and Meta were read far more attentively outside Europe than inside it, by people with no obligations under either regime and a strong interest in the contents.
Whose decision this is, and whose it isn't
Three limits worth stating plainly before anyone builds a plan on this. First, and most importantly: this is the Digital Services Act, which is not the EU AI Act. We wrote about the AI Act's transparency obligations on 10 August and those genuinely can land on you, on your own use of AI, wherever your customers are. This one does not. The regulated party here is OpenAI and the obligations are OpenAI's alone, so if you are reading this as a compliance task for your business, you have the wrong end of it. Second, do not expect a ranking specification. Existing VLOSEs have been publishing recommender-system disclosures for a couple of years now and the honest characterisation is that they are high-level: written by lawyers, accurate, and considerably less useful than a well-designed experiment. We expect the first ChatGPT version to disappoint anyone hoping for a leak. Third, the date is the end of December, not now, and designation decisions can be challenged — several designated services have gone to court over theirs. The correct posture is interest, not urgency.
What actually becomes visible, and when?
Stripping out the parts that concern minors, elections and illegal content — real obligations, but not ones that change anything about how you get recommended — four items on the VLOSE list are directly about the machinery that decides who gets mentioned.
- A statement of the main parameters used in its recommender systems, and why. For a service the Commission has classified as a search engine, that means the ordering of what comes back. Even a high-level version tells you which broad signals are in play and, just as usefully, which ones are not.
- A public advertisement repository. Per reported detail of the obligation, it covers the ad content, who paid for it, the period it ran, the targeting parameters used and the reach achieved, retained for a year after the ad last appeared. If you have been guessing whether competitors are buying placement around your category, this is the first time that stops being a guess.
- At least one recommender option that is not based on profiling. Interesting less as a feature than as a diagnostic: it forces a public distinction between what the system recommends because of who is asking and what it recommends because of what your page says.
- Vetted-researcher access to platform data, under Article 40. This is the sleeper. It means independent academics can, for the first time, study what an AI assistant actually recommends at scale, with data rather than scraped samples. The good studies on this subject have all been outside-in until now.
Add the annual independent audit and the systemic-risk assessment on top and the shape becomes clear: not a rulebook you have to follow, but a body of public evidence about a system you currently have to reason about by inference. For anyone whose job includes the sentence "we think the assistant is picking competitors because…", that is a genuine change in the quality of argument available.

The two conclusions that both get this wrong
The first wrong conclusion is "European regulation, not our problem" — technically true and strategically expensive. You are not the regulated party, but you are the intended beneficiary of a disclosure regime, in exactly the way a shopper benefits from nutrition labelling without being a food manufacturer. Skipping the documents because you have no duty to file them is throwing away the only first-party account of an assistant's ranking behaviour that will exist anywhere. The second wrong conclusion is the opposite and is the more tempting of the two: "the ranking parameters are about to be published, so we will wait for December and optimise against the real rules". That reading fails twice over. It assumes the disclosure will be specific enough to optimise against, which the existing evidence from other designated search engines says it will not be. And it treats four months as free, when the mechanism we described a fortnight ago has not changed at all: a meaningful share of what an assistant says about you is decided from a compressed snapshot of your pages taken well before the question is asked. Waiting for the paperwork means arriving in January with pages that were last read in August. Both readings make the same mistake — treating a transparency obligation as though it were a ranking update. It is neither a rule you must follow nor a change in how you are ranked. It is a light being switched on over a room you were already standing in.
What would we actually do between now and December?
- Take your baseline now, before the documents land. Run your ten highest-margin products and the handful of questions a real customer would ask through ChatGPT, Gemini and Perplexity, and write down what comes back. The value of the December disclosures is entirely in what you can compare them against, and a baseline taken in January is a baseline taken too late.
- Write down your current working theory of why you do or do not appear, in one page. Whatever OpenAI publishes will be most useful as a check on your assumptions, and assumptions you have not written down cannot be checked. This costs an afternoon.
- Put the ad repository in someone's calendar for January. When it opens, the specific question worth asking is not "how much is this costing people" but "which advertisers are targeting the questions my products answer". That is a competitive map nobody has had before.
- Keep doing the unglamorous page work in the meantime, because none of it is contingent on the disclosure. Openings of product and category pages that answer the question in the first two sentences, comparison and use-case pages that exist at all, review text present in the delivered page rather than injected afterwards, real prices and real delivery facts in plain text.
- Re-check that you are not blocking the crawlers at your own edge. We keep repeating this because it keeps being the cause, and it is the one failure that makes every other item on this list irrelevant. A bot rule added for sound reasons in the spring is the cheapest possible way to be absent from an answer in the winter.
- Do not start a compliance project. There is nothing here to comply with. If a vendor tells you otherwise between now and December, they are selling you the AI Act, a different regime, or nothing at all.
The genuinely encouraging part
This is the rarest kind of news in this field: a development that is good for you, costs you nothing and asks nothing of you. Almost everything we have written about this year has been a new obligation, a new attack surface or a new way to be quietly excluded from a purchase. This is the opposite. A large regulator has decided that an AI assistant answering questions about products is a search engine, and search engines in that tier have to explain themselves in public. Whatever the first disclosures actually contain — and we have said we expect them to be thin — the direction is that the most consequential ranking system to appear in a decade becomes less of a black box in December than it is in August, and it does so on a legal timetable rather than at a vendor's convenience. Meanwhile the work that pays off is the same work it was last week: pages that answer a question well in their opening sentences. That has now been the right answer under every mechanism, study, protocol and regulation we have covered this year, which after a while stops being a coincidence and starts being the plan.
Where we fit
The reason a business would retain us over this is not the regulation, which needs nothing from you, but the comparison it makes possible — and comparisons only work if somebody took the measurement in time. That is the practical value of an AI Shopping Visibility engagement between now and December. We run the baseline while it still counts as a baseline: what ChatGPT, Gemini, Perplexity and Google's AI surfaces say today about your best-selling and highest-margin products, where a competitor is being recommended in your place, and which of those gaps trace back to something in your own pages rather than something outside your control. We write down the working theory of why, so that when the disclosures and the ad repository arrive there is something specific to test them against rather than a vague sense that things could be better. Then we do the fixing in priority order and re-run the baseline so you can see what moved. And we check the boring thing first — whether your own edge or bot protection is turning those crawlers away — because that single misconfiguration makes every other hour on this pointless. None of that is a compliance service, and we would not sell it as one. It is measurement taken before the evidence arrives, which is the only moment at which measurement is cheap.
Sources
- European Commission — Digital Services Act: Very Large Online Platforms and Search Engines (the Commission's own page listing designated services and the full obligation set quoted above: recommender-system and advertising transparency, the public ad repository, vetted-researcher data access, the non-profiling recommender option, annual independent audits and the four-month compliance window)
- European Commission — Press corner, reference IP/26/1772 (the designation decision as published in Brussels on 31 August 2026)
- Euronews — EU places ChatGPT, Reddit and Roblox under strictest digital safety rules (the 31 August announcement, the ~159 million EU figure for ChatGPT's search function over the six months to March 2026, the "hybrid service" reasoning, the total of 28 designated services and the quoted remarks from Executive Vice-President Henna Virkkunen)
- PPC Land — ChatGPT faces EU risk rules after declaring 159.1 million users (the marketing-side read, and the source for the detail of what the advertisement repository must contain — content, advertiser, period, targeting parameters and reach, retained a year — plus the end-of-December 2026 deadline and the reported Temu enforcement precedent referenced above)
- BNN Bloomberg — ChatGPT becomes first AI chatbot to face tougher EU rules (independent same-day coverage confirming the designation, the 45 million threshold and the 6% of global turnover ceiling)
- JTS Tech Services — The EU AI Act deadline you heard was delayed isn't the one that applies to you (the other EU regime, and the one that genuinely can create obligations for your own use of AI — worth reading precisely to keep the two apart)
- JTS Tech Services — What ChatGPT actually reads from your site (the observed mechanism behind the timing argument: what gets read, how much of it, and when it is frozen)
- JTS Tech Services — ChatGPT ads: you can't buy the answer (what the paid layer is and is not, which is the context for reading the ad repository when it opens)


