TL;DR
- OpenAI's own DSA disclosure put ChatGPT search at about 159.1 million average monthly active recipients in the EU for the six months ending 31 March 2026, more than three times the 45 million threshold.
- The obligations include an annual independent audit, systemic risk assessment, data sharing with the Commission and vetted researchers, a non-profiling recommender option and a public ad repository where ads are shown.
- Designation is not a finding of wrongdoing, but fines for breaking DSA rules can reach 6% of global annual revenue.
- The report says nothing about Thailand, gives no date for an ad repository, and does not say the designation changes how ChatGPT ranks or cites sources.
The European Commission designated ChatGPT as a very large online search engine under the Digital Services Act on 31 August 2026, making it the first AI chatbot to receive that designation. The Commission announced two more designations the same day: Reddit and Roblox are now very large online platforms, each with at least 45 million average monthly users in the EU, which is the threshold that triggers designation.
Search Engine Journal reported the decision on 31 August 2026. All three services have four months from notification to meet the additional DSA rules that apply to the largest platforms and search engines. Designation is not a finding of wrongdoing, and enforcement runs as a separate process. The obligations attached to the label are the part that matters to anyone trying to measure how brands appear inside AI answers.
What the Commission decided
The Digital Services Act sets up two categories for the biggest services. A very large online platform, shortened to VLOP, is a content sharing service above the user threshold. A very large online search engine, shortened to VLOSE, is a search service above the same threshold. Reddit and Roblox went into the first category. ChatGPT went into the second, and that is the part that has not happened to an AI chatbot before.
The Commission described ChatGPT as a hybrid service that qualifies as an online search engine because it responds to users' prompts and queries, including by searching the web. The reasoning is narrow and worth reading exactly as written. The trigger is the act of answering a query, partly by retrieving from the open web. It is not the model architecture and not the chat interface.
Henna Virkkunen, the Commission's executive vice-president for tech sovereignty, security and democracy, said the new designations mean that ChatGPT, Reddit and Roblox "will now be held to a higher standard of scrutiny and accountability in the European Union, in line with their large impact on our citizens and society."
The numbers behind the threshold
The user figures come from the companies' own DSA disclosures rather than from the Commission's release. OpenAI reported that ChatGPT search had approximately 159.1 million average monthly active recipients in the EU over the six months ending 31 March 2026, more than three times the 45 million threshold. OpenAI states that the figure is approximate and was calculated solely for DSA compliance, so it is a regulatory count rather than a marketing metric, and it covers ChatGPT search specifically.
Reddit reported no more than 57.2 million monthly users in the EU for the first half of 2026. Roblox estimated its average at 46.6 million. Both sit far closer to the line than ChatGPT does, and the DSA has a rule that runs the other way as well. If a service stays below 45 million monthly EU users for a whole year, the Commission has the authority to revoke the designation.
The table below compares the three services on the figures reported in the story, all of them taken from the companies' own DSA disclosures rather than from the Commission.
| Service | Designation on 31 Aug 2026 | Reported EU average monthly users |
|---|---|---|
| ChatGPT | Very large online search engine (VLOSE) | About 159.1 million for ChatGPT search, six months ending 31 March 2026 |
| Very large online platform (VLOP) | No more than 57.2 million, first half of 2026 | |
| Roblox | Very large online platform (VLOP) | Estimated average of 46.6 million |
What the extra obligations require
The DSA attaches a defined set of duties to designated services, and the four month window is the time allowed to put them in place. The obligations reported are these.
- Identify, assess and mitigate the systemic risks tied to the service and its algorithmic systems. The Commission's list covers illegal content, negative effects on minors, users' mental and physical wellbeing, fundamental rights, electoral processes and public security.
- Undergo an independent audit at least once a year, and respond to the auditor's recommendations.
- Share data with the Commission and national authorities, and allow vetted researcher access to platform data for qualifying systemic risk research.
- Where recommender systems are used, offer an option that does not rely on profiling.
- Where ads are shown, maintain a public ad repository.
Designation also lets the Commission look more closely at the systems behind each service. Fines for breaking the rules can reach 6% of a company's global annual revenue. DSA fines announced so far total 870 million euros, a figure that includes 550 million euros against AliExpress in July 2026. After the four month compliance deadline, the first systemic risk reports go to the Commission.
Why an ad repository and researcher access matter for measurement
What follows is reasoning about mechanisms, not reporting. None of it is a claim about what OpenAI will build or when.
Measuring brand presence inside AI answers is a sampling exercise today. There is no Search Console equivalent for an answer engine, so most teams working on generative engine optimisation reconstruct visibility by running prompt panels and counting citations. That method tells you what a model said to a script at a point in time. It does not tell you what the model said to real people at scale, and the gap between those two things is the reason AI visibility reporting is still argued about.
Two of the DSA obligations touch that gap. A public ad repository is a structured record of paid placements, and equivalent archives on other platforms have become ordinary inputs for competitive research. Vetted researcher access is wider in scope: it creates a legal route for approved researchers to request platform data for systemic risk work, which is the kind of work that produces published findings about how a system behaves. Neither mechanism exists to help advertisers. Both, if they get built, would create public material about an answer surface that nobody outside OpenAI can produce today.
The limit on that reasoning is real. Nothing here is scheduled, quantified or promised to anyone. The source gives no date for when an ad repository would appear, and says nothing about what data vetted researchers would actually receive or in what form. These are mechanisms to watch, not a measurement roadmap to plan against.
How this connects to the DMA decisions earlier in 2026
The report places the designation next to a separate regulatory track. In April 2026 the Commission proposed making Google share search data with rivals under the Digital Markets Act, and a binding version of that decision arrived in July 2026. Under the July decision, chatbots with search functions can qualify for access to Google's search data if they meet the DMA's definition of an online search engine. The DMA and the DSA are separate laws with separate tests and separate remedies. What the August designation adds is that a regulator has now applied the search engine category to ChatGPT itself, under the DSA, with obligations rather than access rights attached.
What the announcement did not say
Several questions a marketer would reasonably ask are simply absent from the reported facts, and it is better to name them than to fill them in.
- Nothing about Thailand or any market outside the European Union. The DSA applies in the EU, and the designation carries no obligation toward users anywhere else.
- No date for when an ad repository would actually appear, beyond the four month window that covers the obligations as a set.
- No statement about how the designation affects ChatGPT's ranking or citation behaviour. Being classified as a search engine under a content law is not a change to how answers get assembled.
- No comment from OpenAI in the reported facts, and no indication of how the company plans to implement any of the obligations.
What this means for Thai marketers
A brand in Bangkok gets no reporting rights out of this decision. Vetted researcher access, the ad repository and the annual audit are European mechanisms, and a Thai advertiser is not a party to any of them. Anyone selling AI visibility reporting on the strength of this news is running ahead of the facts.
The part that might apply is about precedent rather than jurisdiction, and it is reasoning rather than reporting. Platform changes built for one regulator have often shipped more widely afterwards, because running different product behaviour in different regions costs money and creates support problems. That is a pattern from how other platforms have handled EU rules. It is not a statement about OpenAI's plans, and the source says nothing at all on the question. If disclosure surfaces built for the EU do end up visible everywhere, teams working on ChatGPT visibility would get data they currently have to approximate with prompt tests.
The practical position for now has not moved. Keep doing the work that improves the odds of being retrieved and cited, keep measuring it with the methods that exist, and treat any European disclosure artefact as an upside rather than a plan.
What to check in your own reporting this month
- Write down how your current AI visibility number is produced. If it comes from a prompt panel, record the prompt set, the run frequency and the market, because that is the part that will look thin next to any regulated disclosure.
- Separate European exposure from the rest of the account. If a meaningful share of traffic or revenue is EU based, the four month compliance clock is a real date on the calendar rather than industry trivia.
- Check whether your reporting language claims more certainty than the method supports. Sampled citation counts are estimates, and saying so in the deck costs nothing.
- Keep the pages that get cited in good shape. Dated facts, clear claims and clean page structure are what AI search optimisation rests on, and none of that changes because of a designation in Brussels.
FAQ: frequently asked questions
Does the designation change how ChatGPT ranks or cites sources?
The reported facts do not say that it does. The designation is a classification under the Digital Services Act that brings transparency, audit and risk obligations, and the Commission's stated reason for the classification is that ChatGPT answers prompts and queries including by searching the web. Nothing in the announcement describes a change to retrieval or citation behaviour.
What is the difference between a VLOSE and a VLOP?
A very large online search engine is a search service above the DSA user threshold, while a very large online platform is a content sharing service above the same threshold. ChatGPT received the search engine designation on 31 August 2026, and Reddit and Roblox received the platform designation on the same day. The extra obligations that follow are broadly the same set.
Does any of this apply to a brand in Thailand?
No, not directly. The Digital Services Act is European Union law and the source says nothing about Thailand or any non EU market, so a Thai advertiser gains no data access, no reporting right and no obligation from the decision. The interest for a Thai team is in whether disclosure mechanisms built for Europe later become visible elsewhere, which the source does not address.
When does ChatGPT have to comply?
Four months from notification, which the Commission issued on 31 August 2026 along with the designations for Reddit and Roblox. The first systemic risk reports go to the Commission after that deadline. The source does not give a separate date for any individual obligation such as the ad repository.
Does designation mean OpenAI broke a rule?
No. Designation is not a finding of wrongdoing, and enforcement is handled as a separate process. Fines for breaking the DSA rules can reach 6% of global annual revenue, and DSA fines announced so far total 870 million euros, but none of that is attached to this designation.
If AI answer surfaces are part of how your customers find you, the useful move this quarter is to write down how you measure that today and where the number comes from. Relevant Audience works with brands on search and AI visibility measurement, and a short review of your current method is a reasonable place to start.







