Key Summary
- OpenAI’s ChatGPT has been officially classified as a ‘Very Large Online Search Engine (VLOSE)’ under the EU Digital Services Act (DSA)
- The DSA mandates systemic risk assessments, transparency reporting, and independent audits for very large platforms and search engines with 45 million or more monthly active users in the EU
- OpenAI must demonstrate concrete mitigation measures across four areas: ① Minor protection (strengthening safety guardrails against self-harm and suicidal ideation), ② Mental health (detecting and intervening in dependency or psychologically harmful conversation patterns), ③ Illegal content blocking (child sexual abuse material, terrorist content, and intellectual property infringement), and ④ Algorithmic transparency (evaluating the impact of recommendations and model updates and disclosing them to EU users)
Policy Analysis – An insight column diagnosing the structural impact of the EU’s first generative AI regulation case on global AI industry governance and summarizing the issues the industry must address
The EU AI regulation has been applied to a generative AI service for the first time. OpenAI’s ChatGPT has been officially classified as a ‘Very Large Online Search Engine (VLOSE)’ under the EU Digital Services Act (DSA). Having surpassed the 45 million monthly active user threshold, and given that users directly leverage model outputs in the form of search, summary, and recommendations, its influence comparable to that of a search engine has been recognized.
This classification is not mere labeling. Three obligations—systemic risk assessment, transparency report submission, and external independent audit—fall squarely on OpenAI. Although the DSA took effect in August 2024, this is the first time a generative AI service has been designated as a VLOSE. Until now, only Google Search, Microsoft Bing, and Yahoo had held that VLOSE designation.
What I find noteworthy at this juncture is the ‘expansion of definition.’ The fact that the interpretation including ‘conversational AI responses’ within the search engine category has been formalized. This precedent effectively sets the baseline for the next EU AI regulation case.
Four Key Areas OpenAI Must Demonstrate
The European Commission has required concrete mitigation in four areas. First, minor protection. OpenAI must demonstrate that guardrails actively block output patterns that encourage self-harm and suicidal ideation. Second, mental health. Procedures must be in place to detect and intervene in signals that a given user is over-relying on the chatbot—the so-called ‘psychologically harmful conversation patterns.’
Third, illegal content blocking. A filtering system is required to ensure that child sexual abuse material, terrorism-related content, and intellectual property-infringing content are neither generated nor disseminated. Fourth, algorithmic transparency. The impact of recommendation logic and model updates on output results must be assessed and disclosed to EU users.
Among these four, the most demanding is the transparency report. This does not mean revealing model weights or training data themselves. However, changes must be documented in a traceable form, showing ‘what was changed and what user impact that change produced.’ Because this is an area where OpenAI has historically preferred non-disclosure, practical conflicts are inevitable. The core of the EU AI regulation lies in this transparency reporting.
The Enforcement Weapon: 6% of Global Revenue
The European Commission can issue formal information requests to OpenAI and, if necessary, conduct on-site inspections. If a DSA violation is confirmed, fines of up to 6% of global revenue can be imposed. Based on OpenAI’s approximately $3.7 billion in revenue as of 2024, even a simple calculation yields an enormous amount. Indeed, the DSA fines already imposed on Google and Meta have run into the billions of euros.
The scenario most discussed in the industry is ‘EU market functionality reduction.’ This is because regulatory avoidance is possible by disabling certain model updates or new features for EU users only. Meta has, in fact, made similar choices regarding its News tab features. This is the backdrop for speculation that a ‘EU-only lite version’ of generative AI services could emerge.
Spillover to Competing Models and Global Ripples
The ripple effects of this EU AI regulation application extend beyond OpenAI. Google Gemini, Anthropic Claude, and xAI Grok also stand before the same logic. Any service with more than 45 million EU users cannot escape VLOSE classification. Considering the ongoing trend of Google Search integrating with Gemini, Gemini’s VLOSE designation is only a matter of time.
Other jurisdictions—Brazil, the UK, and Korea—are also highly likely to adopt the EU AI regulation case as a de facto reference standard. With the EU AI Act simultaneously advancing its regulation of high-risk AI systems, generative AI providers must bear a dual regulatory framework of the DSA and the AI Act. This creates a pace of EU AI regulatory standardization distinct from markets like the United States and China, which move under single federal regulation.
From a practitioner’s perspective, what stands out is that the competition over regulatory standards has been re-ignited on top of the aging category of ‘search engine.’ In an era where AI generates information, regulatory authorities across countries have entered a full-scale tug-of-war over how to define the ‘intermediary of information.’ Governance discussions at the data infrastructure level have already been addressed in the Semantic Architecture: 3 Core Axes Analysis.
This EU AI regulation decision has effectively become the starting point of a global de facto standard. Subsequent jurisdictions are likely to copy this case wholesale, and every AI provider considering entry into the EU market must pass this benchmark. The EU AI regulation standard is highly likely to solidify as the benchmark. Further details can be verified in The Verge’s report on OpenAI ChatGPT and the EU DSA.
What to Do Right Now
- Audit the monthly active user count of your EU-targeted services in the 44.5–45 million range and simulate when you might cross the VLOSE threshold.
- Establish an internal logging system that automatically records model update history alongside user impact assessment items.
- Draft 10 risk scenarios related to minors and mental health, and document blocking and intervention procedures for each.
- Build a legal and compliance hotline capable of responding to European Commission information requests within 72 hours.
- Institutionalize a quarterly governance meeting where technology, legal, and product teams jointly review plans to limit features in the EU market.
Key Issues Summary
- Definition Debate: The European Commission’s interpretation of whether AI responses fall within the scope of ‘search engine’ will set the baseline for all future generative AI regulation.
- Dual Burden: DSA VLOSE obligations and EU AI Act high-risk AI obligations apply simultaneously to the same provider, potentially increasing compliance costs geometrically rather than linearly.
- Market Fragmentation: An EU-only reduced version—the ‘regulatory dark age’ strategy—is likely to become a new global SaaS standard.
- Standards Race: If subsequent regulators in Brazil, the UK, and Korea effectively adopt the EU case as their benchmark, a global de facto EU AI regulation standard will solidify.
Frequently Asked Questions
What is a VLOSE?
A Very Large Online Search Engine as defined by the DSA, referring to services with more than 45 million monthly active users in the EU. Once designated, systemic risk assessment, transparency reporting, and external audits become mandatory.
Why was ChatGPT classified as a search engine?
The pattern of users directly leveraging ChatGPT’s responses for information search, summary, and recommendation has grown, and the user base exceeded the DSA threshold. The European Commission deemed this comparable to search engine functionality.
What is the maximum fine that can be imposed on OpenAI?
If a DSA violation is confirmed, up to 6% of global revenue can be imposed. Even based on OpenAI’s approximately $3.7 billion in 2024 revenue, this would amount to a massive sum.
Will Google Gemini and Anthropic Claude face the same regulation?
If their EU user base exceeds the threshold, they will face the same VLOSE regulation. Given the trend of Gemini integrating with Google Search, its designation is highly likely.
Expert Commentary (AI)
Platform Regulation & Digital Law Expert
The VLOSE designation of generative AI is a legitimate extension of the DSA’s risk-based logic, but the loosening boundaries of the search engine definition carry legal predictability risks
Applying the 45 million-user threshold on the grounds that conversational AI serves as a gatekeeper for information circulation through search, summary, and recommendation aligns with the DSA’s effective-impact design and offers significant practical value by filling the regulatory gap before the GPAI and high-risk obligations of the AI Act come into effect in stages. However, since the DSA’s online search engine definition is fundamentally predicated on services that query and crawl all websites, the interpretation extending it to purely conversational models may shift the boundary depending on product design factors such as whether browsing functionality is embedded, and the ex post designation approach carries considerable administrative litigation risk. Moreover, if an obligation framework designed for content hosting and recommendation services is applied as-is to the model update cycle, risk assessments and transparency reporting could be duplicated under both the DSA and the AI Act, pushing compliance costs beyond linear growth. Whether this designation becomes an effective standard or degenerates into a formal reporting culture will depend on the European Commission’s supervisory capacity and the level of detailed guidance, and if it drifts toward geo-fencing-style feature reduction, the original intent of the Brussels Effect could be undermined. Nonetheless, since subsequent jurisdictions are likely to adopt this case as a benchmark, it is assessed as a watershed measure for the global governance of AI information intermediation.
AI Safety & Compliance Engineer
The selection of harm vectors across the four mitigation areas is valid, but the absence of audit metrics for mental health detection and update impact assessment is the largest practical gap
Documented real-world harm cases—such as chatbot-assisted self-harm dialogue, child sexual abuse material generation, and copyright infringement dissemination—map directly onto the four areas, giving the prioritization itself practical persuasiveness. Minor guardrails and illegal content filtering can be implemented with verifiable artifacts such as classifiers, red-teaming, and input/output logging, but mental health harmful conversation pattern detection suffers from low technical maturity, where false-positive issues can conflict with special-category personal data processing concerns, and audit metrics for proving inherently probabilistic guardrails have not yet been established. Algorithmic transparency is also realistically limited to structured change logs, evaluation benchmarks, and model-card-style disclosures, given that weights and training data remain undisclosed; considering the quality variance of existing DSA transparency reports, the risk of degenerating into formalistic documentation is high unless audit capacity is supported. User impact tracking per model update requires standardization of telemetry and statistical methodology, incurring considerable engineering costs in the short term, but a positive side effect is that regulation-grade observability infrastructure could become an industry standard. A concern is that EU-limited feature reduction could split the experimentation and learning loop for safety improvements, paradoxically degrading model quality for EU users. Overall, the directional setting is desirable as a turning point from voluntary safety pledges to auditable obligations.
Leave a Reply