Published: September 8, 2026 · Last updated: September 8, 2026 · Author: Softix
On 31 August 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine (VLOSE) under the Digital Services Act (DSA). The same day, Reddit and Roblox were designated as Very Large Online Platforms (VLOPs). If your US software company builds on ChatGPT—chat UIs, retrieval wrappers, or agents that can search the web—this is platform-regulation news that can change terms, risk assessments, and product expectations even when you are not the designated service.
Softix’s frame for US SMBs: Scope–Assess–Shield. Decide whether you ship EU-facing ChatGPT or agent surfaces; assess which systemic-risk and contractual changes you inherit; shield with logging, human oversight, content policies, fallback models, and data-residency choices. This is analysis and practical guidance for product teams—not legal advice. Confirm classifications and obligations with counsel.
What the Commission designated (and why ChatGPT is a “search engine”)
According to the Commission’s digital-strategy news release and press release IP/26/1772 (Brussels, 31 August 2026):
- ChatGPT is designated as a VLOSE.
- Reddit and Roblox are designated as VLOPs.
- These services declared that they reach at least 45 million average monthly users in the EU, meeting the DSA designation threshold.
- ChatGPT is described as an AI system that can engage with user prompts and queries, including by searching the web. The Commission therefore treats ChatGPT as a hybrid service that qualifies as an online search engine under the DSA.
- Reddit and Roblox qualify as online platforms because they enable users to disseminate third-party content to the public.
- The Commission states it has now designated 28 very large online platforms and search engines under the DSA.
- ChatGPT, Reddit, and Roblox were already subject to the general DSA obligations for online platforms and search engines; designation adds the additional VLOP/VLOSE layer.
The press release notes that the Commission gains investigative powers to assess functionalities behind these services, and will supervise compliance in cooperation with the Digital Services Coordinators: Coimisiún na Meán (Ireland) for ChatGPT, and the Authority for Consumers and Markets (ACM) (Netherlands) for Reddit and Roblox. Executive Vice-President Henna Virkkunen is quoted saying the designations mean higher scrutiny and accountability in the EU, given their societal impact.
Softix does not invent OpenAI product roadmap changes from this designation. Watch official OpenAI communications and your API/contract notices—not Softix speculation—for any concrete feature or terms shifts.
The four-month clock (by January 2027)
Following notification, the Commission states these services have four months—described as by January 2027—to comply with the additional DSA obligations for VLOPs and VLOSEs. Softix follows that wording and does not invent an exact calendar day.
Those additional obligations include assessing and mitigating systemic risks stemming from the service and algorithmic systems, related to (as listed by the Commission): dissemination of illegal content; negative effects on minors; users’ physical and mental well-being; fundamental rights; electoral processes; and public security.
For US SMBs, the operational takeaway is timing: late 2026 into January 2027 is when designated services are expected to show the heavier VLOSE/VLOP control set. Downstream API terms, usage policies, logging requirements, and EU-traffic feature flags may move in that window. Softix labels that “may” as guidance to monitor, not a prediction of specific OpenAI product changes.
Scope — Are you designated, or are you a dependent builder?
Scope is the first Softix gate. Most US software SMBs reading this are not ChatGPT, Reddit, or Roblox—and are unlikely to meet the 45 million average monthly EU users self-declaration threshold that triggered these designations.
Usually out of VLOSE/VLOP designation for Softix’s audience: your SaaS has thousands or tens of thousands of EU monthly active users (not tens of millions); you call ChatGPT via API under your product brand; or you build agents/copilots on top of a foundation-model provider.
Softix opinion (not a legal ruling): designation of ChatGPT as a VLOSE does not automatically make every ChatGPT customer a VLOSE. The Commission’s action targets the designated services that declared the user threshold.
Still run a Softix Scope inventory if you ship EU-facing ChatGPT or agent surfaces:
- EU-facing search wrappers — query in, ChatGPT (or similar) web-enabled path out, synthesized answers to EU users.
- Agents that browse or retrieve — tools that fetch web content, cite sources, or act for EU users.
- Youth-adjacent surfaces — chat/search features reachable by minors without strong age gates.
- Election-, civic-, or public-safety-adjacent features — small tools can still create reputational and contractual risk.
- Data residency and logging — where prompts, retrieved pages, and outputs live, and who can audit them.
If you only serve US-only customers with contractual geo restrictions and no EU processing, Scope may be thin—but verify marketing claims, CDN routing, and “available worldwide” listings before assuming zero EU exposure.
Assess — What risk do you inherit from a VLOSE ChatGPT?
Assess maps inherited risk, not imaginary designation of your LLC.
| Risk inheritance channel | What to review | Why it matters |
|---|---|---|
| API / usage policies | Acceptable use, EU-specific terms, logging, retention, prohibited categories | VLOSE systemic-risk mitigation can cascade into stricter provider rules |
| Feature availability | Web search / browsing toggles; EU vs non-EU capability differences | Hybrid “search engine” framing may drive regional product controls |
| Content & safety tooling | Moderation endpoints, refusal behavior, classifier updates | Your UX must handle more refusals or labeled outputs without silent failure |
| Audit / transparency asks | Customer questionnaires, enterprise DPAs, procurement packs | Buyers will ask how you handle illegal-content and minors risk even if you are not a VLOSE |
| Concentration risk | Single-provider dependency for EU search/answer paths | If ChatGPT EU behavior changes, your product SLA can break |
Softix is not claiming OpenAI has announced a specific list of API breakages. Softix is recommending you treat late-2026/January-2027 as a change window for dependent products.
Use the Commission’s systemic-risk themes as a short checklist for your features: Can your agent republish material you cannot lawfully host? Are under-18 users exposed? Do high-impact agent actions lack human gates? Softix does not ask you to draft OpenAI’s VLOSE assessment—only to assess surfaces you control.
Shield — Controls Softix recommends for ChatGPT-dependent SMBs
Shield is Softix’s third gate: practical controls that survive provider change without requiring you to be DSA-designated.
- Logging with purpose limits — Prompt/response metadata, tool calls, retrieval URLs, and operator overrides retained for incident review; access-controlled; retention aligned to your privacy notice.
- Human oversight on high-impact paths — Confirm before publish, send, pay, delete, or “act on the open web” steps for EU tenants (or globally, if simpler).
- Content and use policies in-product — Prohibited-use rules, rate limits, and abuse reporting—especially if you re-expose search-like answers.
- Fallback models / degraded modes — If web-enabled ChatGPT features change or refuse more often, fall back to a non-web model, cached knowledge, or “search unavailable” UX.
- Data residency & subprocessors — Document where EU prompts and retrieved content go; update security pages when providers change regions or processors.
- Containment for agents — Bound tools, sandboxes, and allowlists (see Softix’s Cloudflare / Cursor sandboxes Bound–Sandbox–Ship).
- Contractual watchlist — Calendar a review before January 2027 of model-provider terms, DPAs, and EU addenda; assign an owner.
Softix builds custom software with these controls in mind—see custom software development—but classification questions belong with your counsel.
DSA VLOSE vs EU AI Act vs CRA (do not collapse the regimes)
| Regime | Softix one-liner | Softix deep-dive |
|---|---|---|
| DSA VLOSE/VLOP | Platform/search-engine scale obligations for designated very large services (here: ChatGPT as hybrid search engine) | This post |
| EU AI Act | AI system risk/transparency rules—distinct from DSA platform designation | Softix has covered AI Act themes separately; do not treat VLOSE as an AI Act risk tier |
| CRA Article 14 | Vulnerability/incident reporting for in-scope products with digital elements from 11 September 2026 | EU CRA Article 14 — Scope–Report–Prove |
Model capability posts remain separate—for example Softix Gemini 3.8 Flash Floor–Fit–Forge and GPT-6 Astra Floor–Fit–Forge. Those answer “which model tier fits,” not “what DSA designation does to platforms you depend on.”
Scope–Assess–Shield at a glance
| Gate | Question | Softix action |
|---|---|---|
| Scope | Do we ship EU-facing ChatGPT/agent/search-wrapper surfaces? Are we near VLOSE-scale users? | Inventory products, geos, minors exposure; assume you are not designated unless counsel says otherwise |
| Assess | What systemic-risk and contractual changes could we inherit by January 2027? | Map API terms, feature flags, moderation, audit asks, single-provider concentration |
| Shield | What controls keep the product safe if the upstream VLOSE tightens? | Logging, human oversight, policies, fallbacks, residency, agent containment, contract calendar |
30-day Softix action plan (US SMB)
- Week 1 — Scope: List every ChatGPT (and similar) surface that can reach EU users; mark web-search / browsing / agent-action paths; name a product + security owner.
- Week 2 — Assess: Diff current API terms and safety settings against last quarter; draft a buyer FAQ distinguishing “OpenAI designated VLOSE” from “our SMB product’s DSA status.”
- Week 3 — Shield: Verify logging, human approval for high-impact tools, and a non-web fallback path.
- Week 4 — Calendar: Set a pre–January 2027 review; watch Commission DSA supervision updates and your provider’s enterprise changelog.
- Anytime — Counsel: If you operate a large EU-facing search-like service of your own, get a designation/threshold analysis—Softix will not invent that math for your traffic.
FAQ
Does ChatGPT’s VLOSE designation mean my US startup must comply as a VLOSE?
Usually no—Softix’s working assumption for typical SMB traffic is that you are not the designated service. You may still face contractual, customer, and product pressure as ChatGPT implements additional DSA obligations. Confirm with counsel if your own service approaches very large EU reach.
Why is ChatGPT a “search engine” under the DSA?
The Commission describes ChatGPT as a hybrid AI service that can search the web, and therefore as qualifying as an online search engine under the DSA. Softix reports that classification as stated; Softix does not invent alternative legal theories here.
What is the compliance deadline?
Four months from notification, described by the Commission as by January 2027. Softix does not invent a specific calendar day beyond that description.
How is this different from CRA Article 14?
CRA Article 14 is about cyber resilience reporting for in-scope products with digital elements. DSA VLOSE is about very large search engines/platforms and systemic-risk duties. Softix’s CRA guide: Scope–Report–Prove for CRA Article 14.
Should we stop building on ChatGPT for EU users?
Softix does not recommend a panic rip-and-replace. Softix does recommend Scope–Assess–Shield: inventory exposure, plan for policy/feature change, and add shields so a single upstream VLOSE change does not become an outage or a compliance surprise.
Softix next step
If you want a scoped engineering review of EU-facing ChatGPT wrappers, agent tool boundaries, logging, and fallback design—without pretending Softix is your law firm—start at Softix custom software development or let’s talk.
Sources: European Commission, Commission designates ChatGPT, Reddit, Roblox under Digital Services Act (published 31 August 2026; last update 4 September 2026); Press release IP/26/1772 PDF (Brussels, 31 August 2026; note marks update 1 September 2026). Softix recommendations are analysis/guidance for software teams, not legal advice.
Share


