ChatGPT Is Now a Regulated Search Engine in Europe: What Your Business Chatbot Must Know
The EU just classified ChatGPT as a Very Large Online Search Engine under the DSA. Three regulatory layers now stack on OpenAI — here's what it means for your business.
This article is also available in: Français
On August 31, 2026, the European Commission quietly made history. It classified ChatGPT as a Very Large Online Search Engine (VLOSE) under the Digital Services Act (DSA) — the first time any AI assistant has been treated as a search engine under EU law.
The decision went largely unnoticed outside legal circles. But if your business is evaluating which AI platform to build your customer chatbot on, this matters more than almost any other news from the past year. Here’s why.
What Made ChatGPT a “Search Engine” in the EU’s Eyes
The VLOSE threshold under the DSA is 45 million average monthly active users in the EU. ChatGPT reported 159 million — more than three times the threshold.
The classification turns on ChatGPT’s live web-search capability. When a user asks ChatGPT a question and it retrieves current web results, the Commission considers that function equivalent to a search engine interaction. That makes ChatGPT a “hybrid service”: an AI assistant that is also, legally, a search engine.
The practical implication: ChatGPT now sits alongside Google, Bing, and Meta in a category of platforms that the EU considers systemically important. That designation comes with serious obligations.
The Three-Layered Compliance Stack Now Resting on ChatGPT
As of September 2026, any business using ChatGPT as the backbone of its customer chatbot is building on a platform that answers to three separate regulatory regimes simultaneously:
1. The US CLOUD Act
OpenAI is incorporated in the United States. Under the Clarifying Lawful Overseas Use of Data Act, US federal authorities can compel OpenAI to disclose data about EU users regardless of where that data is physically stored. This has been true since ChatGPT launched — the DSA doesn’t change it, but it adds context.
2. EU AI Act Article 50 (active since August 2, 2026)
Every AI system interacting with users must identify itself as artificial intelligence from the first message. OpenAI is subject to fines of up to €15M or 3% of global annual turnover for non-compliance. This obligation applies to ChatGPT as a product and, by extension, to businesses embedding it without proper disclosure.
3. DSA VLOSE (active since August 31, 2026)
The newest layer. As a Very Large Online Search Engine, ChatGPT must now:
- Conduct annual systemic risk assessments covering illegal content, protection of minors, mental health impacts, and electoral integrity
- Maintain a public advertising repository listing every ad served
- Grant data access to EU-vetted researchers — meaning authorized academics can request data about how ChatGPT operates and how users interact with it
- Publish twice-yearly transparency reports
- Submit to annual independent audits of its systemic risks
- Implement crisis response mechanisms
OpenAI has until December 2026 to comply. The fine for non-compliance under the DSA: up to 6% of global annual turnover — twice the EU AI Act Article 50 maximum.
Ireland’s Coimisiún na Meán is the designated supervisory authority.
What This Stack Means for Your Business Chatbot
These obligations don’t directly transfer to businesses using the ChatGPT API. If you embed a ChatGPT-based chatbot on your website, you are not personally subject to VLOSE audit requirements.
But consider what your customers’ conversations actually pass through:
- An infrastructure that EU regulators can now require to share behavioral data with vetted researchers
- A platform conducting systemic risk assessments on how its users interact with it — including in a business context
- A system under simultaneous US federal jurisdiction (CLOUD Act) and three separate EU regulatory frameworks
For many use cases — a product FAQ bot, a customer support assistant on a public e-commerce site — this may be a manageable risk. For any business handling sensitive client information, however, this is a structural issue. Legal firms managing confidential attorney-client communications. Medical practices storing patient intake data. Accountants handling confidential financial records. HR teams processing employee data. For all of these, the three-layer stack is not theoretical.
The Enterprise RAG Consortium’s 2026 State of Enterprise RAG Report found that 71% of RAG systems in production fail on complex multi-hop queries. That’s a technical problem. The DSA classification is a different kind of problem — it’s about who governs the platform your chatbot runs on.
The Alternative: A Sovereign RAG Chatbot That Is Not a Search Engine
DoxyChat is not a search engine. It never will be.
It doesn’t crawl the web. It doesn’t have 45 million EU users. It doesn’t run ads. It is a private retrieval-augmented generation system that answers questions exclusively from your uploaded documents — and stores everything on Scaleway infrastructure in France.
Here’s what that means in practice:
No CLOUD Act exposure. DoxyChat is operated by a French company on French infrastructure. No US server, no US parent company, no possibility of a federal subpoena reaching your customer conversations.
EU AI Act Article 50, native. Every DoxyChat chatbot has disclosed its AI nature since launch. This isn’t a compliance patch — it’s built into the conversation flow.
No DSA VLOSE classification. DoxyChat doesn’t have 159 million EU users. It doesn’t have a public web-search function. It is a private business tool, not a systemic platform. The VLOSE designation is structurally inapplicable.
Your customer conversations stay yours. No researcher access programs. No risk assessment datasets. No independent audit of how your bot responded to your users last quarter. What happens in your chatbot stays in your chatbot.
GDPR-native by architecture. Data residency in France. Row-Level Security isolating each tenant’s data in PostgreSQL. No data used to train public models.
Plans start at €0 — the Discovery plan includes one chatbot, 10 documents, and 200 requests per month. Paid plans from €19/month. No per-resolution fees, no compliance surcharges that grow with regulatory exposure.
Three Questions to Ask Before Your Next Chatbot Decision
The DSA classification of ChatGPT is a useful forcing function. Use it to audit your current or planned chatbot setup:
1. Which regulatory regimes govern your AI vendor? Map the actual compliance stack: US law? EU AI Act? DSA? Which authorities have jurisdiction over your customer conversation data?
2. Does your sector have specific confidentiality requirements? Lawyers, accountants, healthcare providers, and HR functions all operate under professional secrecy rules. A chatbot running on a DSA VLOSE platform creates friction with those rules that a sovereign RAG system does not.
3. Can you verify your data stays within your jurisdiction? GDPR Article 44 restricts transfers of personal data outside the EU without adequate safeguards. A chatbot platform under both CLOUD Act and DSA jurisdiction raises questions that “standard contractual clauses” don’t fully resolve.
The EU didn’t classify ChatGPT as a search engine to slow down AI adoption. It did so because ChatGPT has become as systemically important as Google. For a business chatbot, systemic importance is a liability, not a feature. Your chatbot should be private, bounded, and answerable to you — not to three overlapping regulatory regimes.
Try DoxyChat free at www.doxychat.com.
