Home / Blog / ChatGPT to face tougher regulation in the EU
Tech News

ChatGPT to face tougher regulation in the EU

OpenAI will soon be held accountable for mitigating risks related to ChatGPT's impact on minors, user mental health, and the spread of illegal content.

By Dillip Chowdary • Aug 31, 2026 • Source: The Verge

ChatGPT to face tougher regulation in the EU

What happened

OpenAI's ChatGPT has officially been designated a Very Large Online Search Engine under the European Union's Digital Services Act, bringing the AI chatbot under a stricter tier of regulatory oversight previously reserved for the biggest search and social platforms. The designation means OpenAI now operates under a more demanding set of legal obligations in the EU, with enforceable accountability across several high-stakes risk areas.

This article walks through what the DSA designation means in practical terms, how the law's framework applies to an AI chatbot, and what developers, businesses, and everyday users across Europe should expect going forward. If you build on ChatGPT or rely on it inside the EU, the compliance picture has changed in ways worth understanding now.

The European Union has classified ChatGPT as a Very Large Online Search Engine under the Digital Services Act, a regulatory framework that governs major online platforms and services operating in the bloc. This classification places ChatGPT in the same accountability tier as the largest search engines and social networks, subjecting OpenAI to a set of obligations it did not previously face at this level. The DSA's VLOSE designation is triggered by scale and societal impact, and regulators concluded that ChatGPT meets both thresholds. OpenAI now has enforceable duties related to systemic risk assessment, auditing, and transparency reporting that go well beyond what smaller or undesignated services must do.

How it works

The timing reflects a broader EU push to extend digital regulation to AI-powered services that function like search tools even if they do not look like a traditional search engine. ChatGPT's conversational retrieval model, which surfaces and synthesises information in response to user queries, was enough for regulators to determine that it operates in a similar space. The classification is not a fine or a penalty; it is a legal status that unlocks a specific and demanding regulatory regime.

ChatGPT to face tougher regulation in the EU
Illustration · Pexels

The Digital Services Act creates tiered obligations based on platform size and type. Very Large Online Search Engines and Very Large Online Platforms face the highest tier, which includes mandatory risk assessments, independent audits, data access for researchers, and transparency reports. For ChatGPT specifically, the VLOSE designation means OpenAI must identify and mitigate systemic risks tied to the service — risks that under the DSA include harm to minors, damage to user mental health, and the spread of illegal content. These are not aspirational targets but legal requirements with enforcement teeth.

Why it matters

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

In practice, OpenAI must conduct and document risk assessments covering how ChatGPT's outputs could contribute to these harms, then put mitigation measures in place. Regulators can audit those measures, request the underlying data, and impose penalties for non-compliance. The DSA's enforcement architecture allows EU authorities to act against a designated service without waiting for a specific incident to occur, which gives regulators a proactive rather than reactive role.

This designation sets a precedent for how AI-generated, conversational information services get categorised under existing digital law — not as a new category requiring new legislation, but as a variant of an established one. That interpretive move matters because it means the EU does not need to wait for dedicated AI search regulation to hold ChatGPT accountable at a high level. The DSA was designed before large language model chatbots existed at scale, yet its VLOSE definition proved broad enough to capture them.

For the wider AI industry, this signals that the label an AI product uses to describe itself — chatbot, assistant, search engine — carries less weight than what it functionally does. Other large AI services that retrieve and synthesise information in response to user queries may face similar classification reviews. The DSA's risk categories around minors, mental health, and illegal content are also notable because they track concerns that regulators and researchers have already raised specifically about AI chatbots, not just about web search.

Who is affected

OpenAI faces the most immediate obligations, needing to build or expand audit-ready compliance infrastructure to meet VLOSE requirements in the EU. European users of ChatGPT may see changes to how the service handles age-sensitive content, what mental health safeguards it surfaces, and how it responds to queries that could lead to illegal content. Those changes may be implemented globally by OpenAI or ring-fenced to EU users, a decision that will affect developers who build applications on the ChatGPT API and serve European audiences.

Businesses that have integrated ChatGPT into customer-facing products inside the EU inherit indirect exposure. If OpenAI modifies the model's behaviour or output filters to meet DSA obligations, those changes flow downstream to every application built on the API. Compliance teams at companies using ChatGPT for internal tooling or public products should review their own risk assessments in light of the new regulatory status, since downstream use of a VLOSE-designated service may carry its own documentation requirements depending on the sector.

What to watch next

The most immediate open question is what OpenAI's first DSA-mandated risk assessment will reveal and whether the mitigation measures it proposes will satisfy EU regulators. The audit cycle built into the DSA means this will not be a one-time filing but an ongoing process, and the first round will set the baseline for how rigorously the framework gets applied to AI services. Enforcement actions, if any, could clarify how penalties scale for an AI chatbot versus a traditional search engine.

Longer term, the VLOSE classification of ChatGPT could prompt reviews of other AI services that function as information retrievers at scale, including competitors and AI-assisted search integrations. Builders should verify whether any AI tool they deploy in the EU might meet the same threshold, and monitor the European Commission's guidance as it updates its interpretation of the DSA to account for generative AI. The Verge's original reporting is the primary sourced account of the designation.

Developer Action Items

  • Map where OpenAI / ChatGPT / Framework sits in your stack (SDK, API key, billing, data-processing addendum).
  • Hold non-urgent migrations until the integration or use-of-proceeds roadmap is public — day-one coverage is not a ship signal.
  • If you are mid-contract or mid-POC, ask the vendor what changes for existing customers this quarter.
  • Write the single decision this forces: stay, dual-source, or exit.
Dillip Chowdary

Author

Dillip Chowdary

Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.

Related on Tech Bytes

Advertisement

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →