ChatGPT now a regulated search engine in the EU under DSA
With 159.1M EU users, ChatGPT is now a regulated search engine — and the audits that follow will put brand citation gaps on the record.
Key takeaways
- ChatGPT has 159.1M average monthly search recipients in the EU, clearing the DSA's 45M-user VLOSE threshold.
- VLOSE status requires algorithmic transparency, independent audits, and researcher data access — producing the first rigorous public record of ChatGPT's citation behaviour.
- DSA audits will document which sources ChatGPT consistently cites; brands absent from those sources will have a verifiable visibility gap.
- For multilaterals and financial institutions, the audit trail creates exposure in both directions: absent from citations, or present without quality control.
- Brands treating this as OpenAI's compliance problem, not their own visibility problem, are misreading where the risk sits.
Search Engine Journal reports that OpenAI disclosed 159.1 million average monthly search recipients in the EU, clearing the 45-million-user threshold that triggers "very large online search engine" (VLOSE) status under the Digital Services Act. ChatGPT is now, in the EU's regulatory view, the same category of infrastructure as Google Search.
That designation carries consequences most brand teams have not yet processed.
What the VLOSE label actually requires
The DSA does not merely rename a service. It imposes systemic-risk audits, algorithmic transparency obligations, data-access rights for researchers, and stricter content-moderation accountability. For search engines specifically, it requires that users be able to understand why results appear as they do, and that the systems producing those results be auditable on request by regulators.
OpenAI must now publish transparency reports on ChatGPT's search function and submit to independent audits of its recommender and retrieval systems. The European Commission can request access to algorithmic design documentation. Non-compliance carries fines of up to 6% of global annual revenue.
None of that is abstract. It establishes, for the first time in a major jurisdiction, that a generative AI answer engine is legally accountable for what it surfaces and why.
The citation audit that regulators will eventually demand is the same one your brand needs now
For a senior marketer at a multilateral institution, a financial services group, or an industrial conglomerate, the VLOSE classification matters for a reason separate from regulatory compliance: it creates an official record that ChatGPT's search function is consequential enough to regulate. That record will accelerate scrutiny of how the model selects its sources.
When researchers and regulators begin auditing ChatGPT's retrieval behaviour under DSA obligations, the data they produce will be the most rigorous public evidence yet of which sources the model consistently cites, which it ignores, and whether systematic biases exist by sector, language, or institution type. Those audits will be public. Brands that appear in the model's citations will gain documented credibility; brands that do not will have an absence on the record.
The pattern here mirrors what happened when Google's search index became the object of SEO analysis in the mid-2000s. Systematic scrutiny produced systematic understanding, and understanding produced competitive advantage for those paying attention early.
For institutions like those in the UN system or the World Bank, which already operate under intense transparency expectations, the DSA audit trail introduces a secondary obligation: if your institution's research and policy positions are being surfaced by ChatGPT to 159 million EU users per month, and a regulator later finds that sourcing is inconsistent or geographically skewed, the reputational exposure runs in both directions. Your absence from the model's preferred sources is a problem. Your presence without quality control is a different problem.