What happened
On 31 August the European Commission designated ChatGPT as a Very Large Online Search Engine — a VLOSE — under the Digital Services Act. The same day Reddit and Roblox were designated Very Large Online Platforms. The basis is a single number the providers report themselves: at least 45 million average monthly users in the EU.
The consequences are written into the DSA and they come with a deadline: four months, i.e. by January 2027. In that time the service has to assess the systemic risks stemming from it and mitigate them. The Commission describes the possible mitigation measures plainly — adapting the design or the functioning of the service, changing the recommender systems. Next to that sits a list that does not depend on the outcome of any assessment: an audit by an independent auditor once a year, a recommender option not based on profiling, a public repository of advertisements, data access for vetted researchers, an internal compliance function, and data sharing with the Commission and national authorities. This category is supervised by the Commission itself, with fines of up to 6% of global turnover.
A second fact from the same month concerns exactly the same surface. Ads in ChatGPT — on the Free and the Go tier — have been running in the US since February, and in August OpenAI extended them to Europe.
Our read
This is not a post about OpenAI's obligations. What is interesting is which law Brussels filed an AI assistant under. Not the AI Act. Under the rules for platforms and search engines — and not as an "AI system", but as a search engine.
If your AI systems register has a single column headed "AI Act", it just acquired a counter-example. The question to ask in that register is not "which AI regulation applies to us", but "which regimes touch each product we use" — because for an assistant the answer today covers the DSA, the GDPR, consumer law and, separately, the AI Act. It is the same mechanism we described when WhatsApp was opened to third-party AI assistants, where the decision came from a competition authority rather than an AI regulator. Brussels regulates the channel, not the model.
The second point is more practical, because it has a date. By January 2027 the most-used assistant in Europe goes through a systemic-risk assessment and the implementation of mitigation measures, and the Commission's catalogue of those measures includes changing how the service functions. We flag this explicitly as our expectation, not a finding: this will end in visible changes to ChatGPT's behaviour in the EU around the turn of the year. The Commission describes a catalogue of options, not a product announcement — but the deadline is firm and the list of measures is narrow.
You already know what a change inside somebody else's product looks like from Copilot features being retired five days after the notice. Here there is one difference and it works in your favour: there the calendar was private, here it is public. If one of your processes rests on a specific behaviour of this assistant, you have four months to check it rather than finding out from a release note.
There is a third thread, almost absent from the coverage and the most useful of them. Until now the question "on what basis does this assistant choose what it shows" had no addressee: the provider did not have to answer, and you had no standing to ask. From January 2027 documents appear on this surface — an annual audit, a public ad repository, a recommender option without profiling, data access for researchers. A year ago that material did not exist.
And one sentence that has to be said plainly, because some of the coverage reads otherwise: these obligations fall on the provider of the service. A company that uses ChatGPT does not pick up a single new obligation from this decision. Your September task list does not change. What changes is what you can expect from the product and what you have the standing to ask about.
Why this matters
Private Equity
For a fund this is a cheap diligence item, and the first one whose source sits outside the portfolio company. If a portfolio company has built customer service or research on a service in this category, from 2027 there are external documents about it: the audit, the ad repository, transparency reports. Neither the company nor the vendor has to be taken at its word.
The more interesting question comes earlier: does the company's AI systems register have a column for "which regimes besides the AI Act". If the AI Act stands there alone, that is not a compliance map, only one layer of one — and it will see neither this decision nor the next. That is exactly how we structure this review on the fund side: starting from an inventory of products and the regimes that touch them, not from an AI policy.
Enterprise
For a large organization the deadline matters, not the legal category. January 2027 is an externally imposed change window in a service your people use daily, and nobody agreed it with your roadmap. Treat it like any vendor with a scheduled change: work out which processes depend on a specific behaviour of this assistant, and check them before the date, not after.
The second piece of work sits in the register and takes one afternoon. Add to every AI product the regimes that touch it and the owner who tracks them. A register built around the AI Act missed this decision and will miss the next one, because the next one will not come from the AI Office either.
SMB / mid-market
Here the practical conclusion comes down to one word in your policy. The designation covers the surface that gathers at least 45 million monthly users in the EU — the consumer product, the same one that has been showing ads in Europe on the Free and Go tiers since August. Not the company contract you may be citing in a conversation with a client.
Which is why "we use ChatGPT" is not a statement about compliance. The statement about compliance is the name of the tier. If your policy names the vendor rather than the tier, it does not describe what people actually do: they paste client material into an account they logged into themselves, on terms nobody at your company has read. Writing down that one word needs neither a lawyer nor a new tool.
One move this week
Take your AI systems register — or a sheet of paper, if there is no register — and add one column: which law besides the AI Act applies to this product. Next to the assistants, put January 2027. Then one question for the team, which usually takes half a day to answer: which tier are the accounts people actually use on. If you do not know, that is the result of the exercise. Describe your case: mailto:[email protected]?subject=Rozmowa%20z%20Aurora%20AI.