EU ChatGPT VLOSE Classification 2026: Complete Guide
What You'll Learn
- What VLOP and VLOSE mean under the European Union's Digital Services Act.
- Why a user threshold does not by itself prove a formal designation.
- Which obligations the European Commission describes for designated services.
- How to read OpenAI's published DSA information without turning it into a legal conclusion.
What the VLOSE Term Means Under the DSA
VLOSE means Very Large Online Search Engine. It is a category used in the European Union's Digital Services Act, or DSA. The related category VLOP means Very Large Online Platform. The categories concern the scale and systemic significance of an online service, but the label should be tied to an official designation rather than inferred from a headline or a user-count estimate.
The European Commission's DSA overview explains that services with more than 45 million average monthly active users in the European Union can fall within the very large platform or search-engine framework. The threshold is a regulatory test within the DSA. It is not a statement that every service above the number has automatically received a designation on a particular date.
A careful article must separate three things. The first is the legal framework and its definitions. The second is the provider's published data about users or service activity. The third is the Commission's formal record of designated services and any later enforcement activity. Mixing these categories can turn a plausible regulatory question into a false completed-event claim.
The AI data-privacy guide follows the same method. A policy question should identify the source, date, scope and uncertainty instead of presenting a general concern as a confirmed enforcement outcome.
Why ChatGPT Search Raises the Question
ChatGPT includes search features that can provide web-connected answers. That makes it reasonable to ask how the service fits within a law that contains separate rules for very large online platforms and very large online search engines. The question is about the function and reach of the relevant service, not simply about the ChatGPT brand name.
OpenAI's official DSA page publishes information about ChatGPT search's average monthly active recipients in the European Union. For the six-month period ending 31 March 2026, the page reported approximately 159.1 million average monthly active recipients. OpenAI also states that the figure was calculated solely for DSA obligations and should not be relied upon or used for other purposes.
That disclosure is relevant evidence about the provider's own reported measurement. It does not, by itself, prove that the Commission issued a designation decision, that every ChatGPT feature has the same legal status or that every DSA obligation applies in the same way to every service. A formal status question still requires the official Commission record and the wording of any decision.
Search also surfaced media reports about the Commission reviewing whether ChatGPT falls within DSA rules. Those reports can explain why the issue received attention. They are not a substitute for the Commission's designated-services list when the claim is that a designation has already happened.
What the Official Record Actually Shows
The Commission maintains an official page listing designated Very Large Online Platforms and Very Large Online Search Engines supervised by the Commission. That list is the correct starting point for checking whether a named service appears as designated and what type of service is recorded.
The page retrieved for this article was updated on 24 July 2026. Its entries identify a provider, a designated service, a type of service under the DSA, average monthly active users in millions and enforcement activity where available. A reader should check the current page because the list and enforcement record can change.
The key editorial finding is narrower than the original claim. The DSA framework and the user-count disclosure make the ChatGPT search question material. The official list must be treated as the authority for a completed designation. If a service is not shown there, the article should not state that the Commission has already designated it without another official decision source.
Use the Commission's DSA overview for the framework and the designated-services page for the status record. Our EU AI compliance tools guide is an internal reading aid, not evidence of a Commission decision.
The 45 Million User Threshold
The 45 million threshold is expressed as more than 45 million average monthly active recipients in the European Union. The relevant measurement is not the number of registered accounts, downloads, global users or a single busy day. It is a defined average within the DSA framework and must be interpreted with the applicable legal terms.
Even when a provider publishes a number above the threshold, the number is only one part of the analysis. The service type, the relevant period, the provider's reporting, the Commission's assessment and the designation process also matter. A threshold can trigger regulatory attention or obligations related to reporting, but it should not be rewritten as an automatic announcement.
| Term or figure | What it describes | What it does not prove alone |
|---|---|---|
| 45 million | DSA scale threshold described by the Commission | Automatic designation on a specific date |
| 159.1 million | OpenAI's reported average monthly active recipients for ChatGPT search in the EU over the six-month period ending 31 March 2026 | A Commission decision or a conclusion about every ChatGPT feature |
| Six-month period | The period used for the OpenAI disclosure ending 31 March 2026 | A timeless user-count statement |
| Designated service list | The Commission's official status record | A replacement for reading the underlying decision or current entry |
OpenAI's own notice adds an important limitation. It says the 159.1 million average was calculated solely for DSA obligations and should not be used for other purposes. That sentence should remain attached to any article that cites the number. Removing the limitation would make the disclosure sound broader than the source allows.
What Designated Very Large Services Must Do
The Commission describes additional responsibilities for designated very large platforms and search engines. These responsibilities are designed around systemic effects that can reach beyond an individual user's interaction with a service. The details depend on the DSA provisions, the service category and the facts of the provider's operation.
The Commission's overview identifies systemic-risk assessment and mitigation, independent audits, data sharing with the Commission and national authorities, access for vetted researchers in appropriate circumstances, a recommender-system option that is not based on user profiling and a publicly available advertising repository. These are framework-level descriptions. They do not prove that a particular provider completed each action or passed each audit.
The word must also be used carefully. A law may require a service to maintain a process, publish information or cooperate with oversight. That is different from saying that the service has achieved a safety outcome, removed all systemic risk or satisfied every regulator. Compliance is a continuing question supported by documents and supervisory action, not a permanent label.
| Obligation area | Commission description | Evidence needed for a provider-specific claim |
|---|---|---|
| Systemic risk | Assess and mitigate systemic risks linked to the service | Provider report, Commission material or enforcement record |
| Independent audit | Submit to independent auditing requirements | Applicable audit document and status, not a generic promise |
| Researcher access | Allow vetted researchers to access platform data when conditions are met | Current access process, scope and published evidence |
| Recommender choice | Provide an option that is not based on user profiling | Service-specific implementation and user interface evidence |
| Advertising repository | Maintain a publicly available repository of advertisements | Relevant repository and current service applicability |
These obligations help explain why the VLOSE question matters. They do not justify an article saying that an unnamed or newly discussed service has already completed independent audits, shared all data or eliminated disinformation risks.
Systemic Risk and Mitigation
Systemic risk under the DSA is broader than an isolated incorrect answer. It concerns effects that may arise from the design, operation or scale of a very large service. The Commission's overview connects the framework with risks such as the spread of illegal content, effects on fundamental rights, electoral processes, public security and other harms identified under the law.
For a search-enabled AI service, possible questions can include how sources are selected, how misleading material is handled, how users can challenge content decisions and how the service responds to coordinated misuse. The existence of a question is not proof that the service caused a particular outcome. It is a reason to inspect the relevant risk assessment, mitigation measure or supervisory document.
Risk mitigation also has limits. A policy can reduce a risk without making it zero. A transparency report can disclose a process without proving that every user received the same result. A regulator can request information without that request being a finding of wrongdoing. This distinction is important when reading headlines about a possible DSA investigation.
The AI agent frameworks guide gives a useful technical comparison. Tools, retrieval and model actions create separate points where context, permissions and review need to be considered. The DSA question similarly requires the service function and the evidence chain to be kept visible.
Transparency, Data Access and Advertising
Transparency obligations can cover how a very large service operates, how risks are assessed and how users or authorities can understand key processes. They should not be summarised as a blanket requirement to publish every algorithm or disclose every confidential system detail. The legal text and the Commission's guidance define the actual scope.
Researcher access is also conditional. The Commission describes access for vetted researchers when the research contributes to detecting, identifying or understanding systemic risks in the European Union. That does not mean that any person can demand all platform data or that a provider must publish its complete dataset.
The advertising repository requirement is relevant where the service displays advertisements and the DSA rules apply to that service. A page discussing the obligation should not assume that an AI answer interface displays ads in the same way as a traditional search engine. The right question is whether the service and activity fall within the applicable rule.
OpenAI's official DSA page separately describes reporting, moderation decisions, appeals and transparency information. It also identifies a Government Request Portal for authorities and a DSA point of contact for users in the European Union. Those published routes are evidence of compliance processes, not proof that every complaint is resolved in a particular way.
What OpenAI Publishes About DSA Compliance
OpenAI's DSA page says the company supports compliance through illegal-content reporting, moderation decisions and appeals and transparency reporting. It explains that a Government Request Portal through Kodex is the point of contact for communications from Member State authorities, the European Commission and the European Board for Digital Services.
The same page describes a point of contact for EU users through OpenAI's AI Chat interface. It also refers users to an illegal-content reporting webform under Article 16 of the DSA and explains that reports are reviewed under applicable law and company policies. These are the routes the provider publishes. They should not be rewritten as a guarantee that a report will lead to removal or that the user will receive a particular legal remedy.
OpenAI also publishes the ChatGPT search recipient figure described above. The source places the number in a DSA context and warns against using it for other purposes. A responsible article keeps the measurement period and the limitation in the same paragraph.
| Published item | What it supports | What it does not establish |
|---|---|---|
| DSA compliance page | OpenAI's described reporting, moderation and transparency routes | A Commission designation or final enforcement finding |
| Kodex government portal | A published contact path for eligible authorities | That an authority accepted a particular request |
| EU user contact route | A published point of contact for users under the DSA | A guaranteed remedy or response outcome |
| ChatGPT search recipient disclosure | A dated provider-reported measurement for DSA purposes | A timeless global user count or a status decision |
For broader background, our fintech compliance guide explains why a compliance process should be distinguished from an independently verified outcome. The subject is different, but the source discipline is similar.
What the Classification Does Not Automatically Mean
A VLOSE-related discussion does not automatically mean that ChatGPT is banned in Europe. It does not automatically mean that every ChatGPT feature is classified as a search engine. It does not automatically mean that OpenAI has violated the DSA or that the Commission has issued a final finding.
It also does not prove that a provider has completed an annual audit, shared all relevant data with vetted researchers or published a complete explanation of every ranking decision. Those statements require provider documents, Commission material or an enforcement record that supports the exact wording.
A designation is not the same as a fine. A request for information is not the same as a violation decision. A published user-count disclosure is not the same as a Commission designation. A regulatory obligation is not the same as proof of successful implementation. These distinctions prevent a status article from becoming a collection of unsupported outcomes.
The open-banking regulation guide uses another helpful boundary. A rule can shape how a market operates while leaving the facts of a particular provider, product or event to be verified separately.
How Developers and Platforms Should Read the Framework
Developers building search, retrieval or agent features should start with the service function and the user journey. Is the system returning links, generating summaries, ranking results, recommending content or taking actions? Which data sources are used? How are complaints, corrections and harmful-content reports handled? Which records can be provided to a reviewer?
The DSA does not turn those questions into a single engineering checklist for every AI product. The applicable requirements depend on the service, scale, role and legal context. A platform team should read the legislation, Commission guidance and applicable decisions with qualified counsel instead of relying on a headline that says a tool is regulated.
Technical teams can still use practical controls. Keep source and retrieval logs where appropriate. Document the model and ranking changes that affect user-facing results. Define escalation paths for illegal-content reports. Separate user data from evaluation data. Test how the service behaves when sources conflict or a user challenges an answer. Our AI cybersecurity guide adds a related reminder that technical controls should be tested rather than assumed.
Our AI and future-of-work guide makes the same point in a different setting. A capability claim describes what a system can do. It does not establish that a particular deployment is compliant, safe or effective in every environment.
How Users Can Read Regulatory Claims
Readers can test a regulatory headline with a short evidence sequence. First, identify the exact legal term. Second, locate the official Commission page or decision. Third, check the provider's published data and limitations. Fourth, separate a current status from a prediction or review. Fifth, note the date because a designation list, service feature or user measurement can change.
| Headline wording | Question to ask | Safer interpretation |
|---|---|---|
| EU classified the service | Where is the official designation decision or list entry? | Check the Commission record before treating it as complete |
| The service crossed 45 million users | What period, service and measurement definition were used? | It may be relevant to the framework, but it is not the whole status analysis |
| The company must audit its AI | Which obligation, scope and document support the statement? | Describe the framework obligation and avoid claiming completion without evidence |
| The DSA bans the chatbot | Is there an official prohibition or only an oversight rule? | Do not confuse regulation, supervision and a ban |
When the status is unresolved, say so plainly. A narrower sentence supported by the official record is more useful than a stronger sentence built from inference. Readers should be able to open the source and see why the article used a particular verb such as reports, lists, requires, reviews or designates.
What This 2026 Evidence Can and Cannot Prove
The confirmed evidence supports several statements. The DSA contains a framework for very large online platforms and search engines. The European Commission describes a threshold above 45 million average monthly active users in the European Union. The Commission maintains a list of designated services. OpenAI published approximately 159.1 million average monthly active recipients for ChatGPT search in the EU for the six-month period ending 31 March 2026 and limited the purpose of that figure to DSA obligations.
The evidence does not support stating without a current official decision that the European Commission had already designated ChatGPT as a VLOSE. It does not support fixed Q3 or Q4 2026 compliance deadlines, an automatic precedent for every AI platform, a completed audit result or a claim that regulation guarantees safe or accurate answers.
The practical conclusion is to keep the status question open until the authoritative record supports a stronger statement. Check the current Commission list, read the underlying decision where available and retain the provider's measurement limitations. Use the AI frameworks guide and AI compliance tools guide only as internal context, never as substitutes for the official DSA record.
For a current reader, the reliable method is simple: identify the DSA category, verify the official designation record, read the provider's data with its limits and distinguish a legal framework from a completed enforcement outcome. That method keeps this EU ChatGPT VLOSE Classification 2026 guide accurate even as services and regulatory records change.
Frequently Asked Questions
SK Jabedul Haque
Building India's most trusted finance education platform — simplifying news, schemes and market trends so anyone can understand and invest confidently.
Read full bioNever miss an update
Get our clearest explainers on schemes, markets and money — read what matters, without the noise.
Explore more articles