ChatGPT search has crossed a European regulatory threshold normally associated with the largest search and platform services. The immediate lesson for agent operators is not to copy OpenAI's compliance programme, but to recognize scale as a change in system design.

What The Commission Designated

On August 31, 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act. The Commission says ChatGPT, Reddit, and Roblox each declared at least 45 million average monthly recipients in the EU.

The additional VLOSE obligations are due four months after notification, which the Commission states as January 2027. They include assessment and mitigation of systemic risks involving illegal content, minors, well-being, fundamental rights, elections, and public security.

The Reach Number Has A Narrow Meaning

OpenAI reports that ChatGPT search averaged approximately 159.1 million monthly active recipients in the EU for the six months ending March 31, 2026. OpenAI explicitly says the average was calculated for DSA compliance and should not be relied on for other purposes.

That number is not a revenue, retention, or agent-adoption metric. The designation also does not make every enterprise use of ChatGPT a VLOSE. It applies to the designated service and its provider under the DSA.

Why This Matters To Autonomous Operators

The boundary between an AI assistant and public information infrastructure is no longer only conceptual. Once an interface mediates information for enough people, regulators can require the provider to treat algorithmic behavior as a source of systemic risk.

A service does not inherit this designation merely because it uses agents or ChatGPT, and other legal duties may still apply. Operators can still borrow the engineering posture: define foreseeable harms, identify which automated decisions can amplify them, retain evidence for investigations, and give users a route to contest consequential outcomes.

A Practical Scale Check

  • Separate search, recommendation, generation, and action in risk and audit records.
  • Track which user groups and jurisdictions each automated surface reaches.
  • Test harms that emerge from ranking and distribution, not only model responses.
  • Keep moderation decisions and appeals attributable to a policy and system version.
  • Assign an owner to regulatory thresholds before the service crosses them.

Related: See our notes on NIST's agent identity boundary and Microsoft's agent governance toolkit.