Mark and Focus analysis

The EU Has Put ChatGPT Inside Its Largest-Service Rulebook

Read the analysis
Close view of a laptop used by people working on an artificial-intelligence system.
Europe’s largest-service rules now extend to a generative system whose principal interface is a synthesized answer. DC Studio / Magnific · https://www.magnific.com/legal/terms-of-use

The European Commission has designated ChatGPT a very large online search engine, placing the service under the Digital Services Act’s strongest systemic-risk and accountability obligations.

ChatGPT enters the DSA’s highest tier

The European Commission has designated ChatGPT for the Digital Services Act’s highest tier of supervision. The service is now classified as a very large online search engine; in the same 31 August decision, Reddit and Roblox were designated very large online platforms.

The immediate basis is reach. Each service reported at least 45 million average monthly active recipients in the European Union, the threshold associated with roughly 10 per cent of the bloc’s population. For ChatGPT, crossing that threshold triggers additional obligations after a four-month implementation period, taking the compliance date into January 2027.

Designation does not mean the Commission has found ChatGPT, Reddit or Roblox guilty of a violation. It means their scale can transmit risks widely enough to justify enhanced governance, independent scrutiny and direct Commission supervision. Keeping that distinction clear is essential: classification begins an accountability regime; it does not conclude an enforcement case.

What the higher tier requires

The Digital Services Act already imposes baseline responsibilities on intermediary services. Its largest-service rules add a systemic layer. Designated providers must identify and assess risks connected to their services, adopt proportionate mitigation, submit to independent audit and meet enhanced transparency and data-access requirements.

The risk categories extend beyond illegal content. They include effects on fundamental rights, civic discourse and elections, public security, minors, and physical or mental wellbeing. The framework asks how the design and operation of a service may amplify harm at scale, not only whether an individual output crosses a legal line.

For a generative service, that inquiry could touch recommendation and response systems, reporting routes, protections for minors, manipulation, the presentation of uncertain information and the way safeguards perform across languages and contexts. The Commission’s designation announcement does not itself decide how every obligation applies. It establishes that the provider must produce and test a systematic account.

Independent audit changes the evidentiary standard. A provider’s assurance that a safeguard exists is not equivalent to evidence that it works under foreseeable conditions. Auditors and regulators will need information about design choices, testing, incidents, mitigations and outcomes. The quality of measurement becomes a governance issue in its own right.

A generated answer is not a list of links

ChatGPT’s classification as a very large online search engine exposes a conceptual challenge. Traditional search helps users navigate to information ranked from an index. A generative system may retrieve information, synthesise it and present a single fluent response. Users can act on that response without seeing the underlying selection process or visiting a source.

That difference affects risk. A ranked list makes some provenance visible through domains, snippets and competing results. A generated answer can compress disagreement, obscure uncertainty or create unsupported detail while sounding coherent. It can also respond conversationally, retain context and adapt its explanation to the user. These capabilities may improve access while creating different pathways for reliance and persuasion.

The regulatory task is not to force every service into an old interface category. It is to translate statutory objectives into controls that reflect how the product actually mediates information. Useful evidence might include whether citations support claims, how uncertainty is communicated, how rapidly serious errors can be corrected, whether safeguards work across EU languages, and how system changes alter risk.

Access for vetted researchers will be especially consequential. External study can test claims across populations and time, but generative services are difficult to reproduce. Models, routing, prompts and safety layers change. Personalised interactions raise privacy constraints. A credible access regime must provide enough information for scrutiny without exposing personal data or creating new security vulnerabilities.

What to watch before January

The four-month period should produce more than policies rewritten in the vocabulary of the Act. Three signals will show whether the designation changes operating practice.

The first is the scope of the risk assessment. It should address the distinctive behavior of generated responses rather than importing a checklist designed for feeds or link ranking. The second is traceability: the provider should be able to connect identified risks to specific mitigations, owners, tests and residual exposure. The third is learning after deployment, including a way for incidents and researcher findings to change the product.

Regulators face symmetrical obligations. They need technical competence, clear requests and proportionate treatment of genuine security or privacy constraints. Public reporting should explain outcomes without demanding disclosure that would make systems easier to abuse. Enforcement should focus on whether risk governance is rigorous and effective, not on creating the appearance that every harmful event can be eliminated.

The designation is significant because it locates generative AI inside an existing European accountability structure rather than waiting for a perfect category. The next stage will reveal whether that structure can examine a service whose primary output is an answer. Scale opened the door. Evidence about design, risk and mitigation will determine what the rulebook means once ChatGPT is inside it.

Take-Out

Designation is a size-based governance trigger, not a verdict of wrongdoing. The harder task is adapting platform-risk controls to a generative service that synthesizes answers rather than listing links.

Questions and answers

What readers should know

What has the European Commission done?
It has designated ChatGPT a very large online search engine under the Digital Services Act and designated Reddit and Roblox very large online platforms.
Why was ChatGPT designated?
The service reported at least 45 million average monthly active recipients in the EU, meeting the Act’s threshold for the largest-service tier.
Does designation mean ChatGPT broke the law?
No. Designation is a size-based trigger for additional governance duties, not a finding that the provider has committed a violation.
What additional duties follow?
The regime requires systemic-risk assessment and mitigation, independent audit, enhanced transparency and qualifying researcher access, subject to the Act’s detailed rules.
Why is a generative service a difficult fit?
A generated answer can synthesize information without presenting a conventional list of links, creating different questions about provenance, uncertainty, correction and user reliance.

Further analysis

More from this desk

Connected analysis