Ask Brussels what ChatGPT is, and you get two answers. Under the Artificial Intelligence Act (AI Act), the European Union regulates it as artificial intelligence. On Aug. 31, the European Commission supplied another answer when it designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act (DSA). Each classification comes with its own rulebook. Together, they may shape what ChatGPT can say.
The DSA designation puts ChatGPT alongside Google Search and Bing in the category reserved for the largest search engines operating in the EU. Under Article 33, a platform or search engine enters that category when it reaches at least 45 million average monthly active users in the EU. OpenAI reported that ChatGPT Search averaged about 159.1 million monthly active users in the EU during the six months ending March 31, comfortably clearing the threshold. ChatGPT now has four months to comply with the additional obligations the DSA imposes on services of that size.
Those obligations require the largest services to examine their broader effects on society. Article 34 requires them to identify and assess “systemic risks” arising from their design or operation. These include risks to fundamental rights, civic discourse, public security, elections, public health, and children. Article 35 then requires services to adopt reasonable, proportionate, and effective measures to mitigate those risks.
The DSA offers several examples, including changes to a service’s design, recommendation systems, terms and conditions, and content-moderation practices. Lawmakers largely developed these obligations for platforms and conventional search engines. A search engine generally organizes and presents information found elsewhere. ChatGPT, by contrast, generates the answer a user sees.
That difference has practical consequences. Efforts to reduce systemic risks may extend beyond how a service ranks, recommends, or displays information. They may shape the substance of the answer itself.
OpenAI has accepted the designation and emphasized its commitment to complying with the DSA while balancing access to useful information with protection from harmful and illegal content. Few would quarrel with that goal. The difficulty lies in deciding what the balance requires.
ChatGPT’s designation therefore presents a broader problem. A regulatory framework designed to govern the distribution of online information may fit awkwardly when applied to a service that produces the answers users receive.
When a Search Engine Talks Back
The DSA defines an “online search engine” broadly. Under Article 3(j), the term covers an intermediary service that lets users enter queries to search all websites or all websites in a particular language, then returns information related to the requested content. The definition turns on function and expressly permits results “in any format.”
ChatGPT Search appears to qualify. It can search the internet for relevant information and generate a response based on what it finds. A conversational answer can fall within Article 3(j) as readily as a page of links.
But this shared label covers materially different services. Google Search, Bing, and other conventional search engines identify, organize, and rank existing information, leaving users to choose among sources. ChatGPT retrieves information and composes the response. Article 3(j) can therefore cover both a service that points users toward answers and one that provides the answer itself.
The Regulator’s Answer Key
The distinction changes how the DSA’s systemic-risk duties operate. Every ChatGPT response reflects choices about relevance, emphasis, qualifications, and the best answer to the user’s question. Information the model omits may disappear entirely instead of slipping lower on a results page.
The DSA’s systemic-risk categories are deliberately broad. Protecting children and restricting illegal content may lend themselves to relatively identifiable measures. Other categories—including fundamental rights, civic discourse, elections, public health, and well-being—require judgments about matters on which reasonable people, institutions, and experts disagree.
Conventional platforms can often mitigate such risks through changes to ranking, recommendation systems, visibility, or interface design. For ChatGPT, mitigation may come down to how a response to a user’s question is composed. If the Commission concludes that certain outputs contribute to a systemic risk, compliance may require changing how ChatGPT answers the underlying question. Displaying competing links offers little help when the user has asked for a synthesized answer.
The DSA provides little guidance about when an answer, or a pattern of answers, creates a serious enough risk to justify intervention. Providers must weigh competing rights and interests that courts often assess on a case-by-case basis. Regulatory caution may then favor generic responses, broader refusals, or just fewer lawful answers.
The Commission’s risk assessment can thus become an editorial judgment about what ChatGPT should say. The AI Act then adds a second, more specific set of rules for the same model.
Brussels Doubles Up
The EU’s other rulebook for ChatGPT is already in force. The AI Act took effect Aug. 1, 2024, and became generally applicable Aug. 2, 2026. The law prohibits several defined practices. Article 5, for example, bars certain manipulative or deceptive techniques and the exploitation of vulnerabilities when they materially distort a person’s behavior and cause, or are reasonably likely to cause, significant harm.
EU lawmakers designed the AI Act specifically for artificial intelligence and drew relatively clear boundaries around prohibited conduct. The law also imposes separate duties on providers of general-purpose AI models, which can perform a wide range of tasks.
The DSA operates at a higher level of generality. Articles 34 and 35 require very large services to assess and mitigate broad categories of systemic risk, including risks to children, fundamental rights, and physical and mental well-being. The AI Act asks whether a practice falls within a defined prohibition. The DSA asks providers to predict and manage the wider effects of their services.
Applying both regimes to ChatGPT creates uncertainty and duplication. Providers must satisfy the AI Act’s specific rules while anticipating the Commission’s evolving interpretation of systemic risk under the DSA. That uncertainty may encourage restrictions beyond what either law clearly requires.
Users bear part of the cost. Providers seeking to limit their exposure may withhold lawful and useful answers, reduce personalization, or standardize responses. Those choices could gradually change the service itself and discourage innovation.
When Classification Becomes Control
How far a law extends and whether its rules are suitable for specific types of conduct are separate questions. Article 3(j)’s broad definition can bring ChatGPT within the DSA. Applying duties designed for online intermediaries to a service that generates its own responses should require a separate justification.
The AI Act already provides a detailed framework tailored to artificial intelligence. The Commission should explain what the DSA adds, define the scope of its additional obligations, and show how providers can comply while preserving lawful and useful responses. Vague and overlapping duties may encourage overcompliance, standardized answers, and less experimentation.
The Commission’s approach will shape which services developers offer in Europe. Users will see the consequences one answer at a time.
