ChatGPT is increasingly subject to several EU digital rulebooks. Its designation as a Very Large Online Search Engine under the Digital Services Act brought additional oversight, on top of requirements under the AI Act. Now, the proposed EU KIDS Act could add another layer of child-safety obligations.

When the European Commission designated ChatGPT a so-called Very Large Online Search Engine (VLOSE), it marked a first for EU regulation. For the first time, a standalone AI chatbot was brought under the Digital Services Act’s (DSA) rules for very large online services.

“The decision sets a precedent. For the first time, a standalone AI system that is not yet embedded into a VLOP or VLOSE is treated as a digital service,” said Lena-Maria Böswald, senior policy researcher at Interface, who recently published a paper on the topic. VLOP stands for Very Large Online Platforms, which is together with VLOSE a category of services that face the strictest rules under DSA.

Many people use ChatGPT to quickly access information on the internet. As such, even if it works differently, it’s in direct competition with search engines.
— Lena-Maria Böswald, senior policy researcher at Interface

“This, in turn, will influence the regulatory expectations for every large generative AI system used in the EU,” she argued.

However, Böswald rejects the idea that ChatGPT is becoming excessively regulated compared with other digital services. “By no means is it the most regulated platform or service under European law. There are a number of platforms, including those with embedded AI systems like Meta platforms or Google, that comply with long-established regulations,” she told EU Perspectives. Specifically, she named the General Data Protection Regulation (GDPR) and Audiovisual Media Services Directive (AVMSD), as well the DSA and AI Act.

For standalone AI systems, however, the designation raises a new issue. “We are definitely talking about a new precedent, and that opens up a whole new can of worms for regulatory coordination between the DSA and AI Act”, Böswald said.

Is chatbot a search engine?

Search engines traditionally bring to mind Google, Bing or Ecosia. A search bar where users enter their queries and recieve a list of links to information elsewhere on the internet.

ChatGPT works differently. It is neither a conventional search engine nor simply an AI model. Its search function retrieves current information from the web. The model used, source selection, ranking, safety systems, conversation history, and interface all help to determine the answer the user finally sees. That makes it harder for users to critically assess the information they receive, according to Interface.

Yet the distinction between search engines and chatbots is becoming less clear as more people turn to AI to find information online.

“This may even be a first step in rethinking our traditional understanding of search engines, policy-wise,” Böswald said. “Many people use ChatGPT to quickly access information on the internet. As such, even if it works differently, it’s in direct competition with search engines. Against this background, there are good grounds for arguing that the chatbot constitutes an ‘online search engine’ under the DSA”.

Interface notes a service can qualify as a search engine if it searches the web and provides results in response to a user query, including where those results are synthesised into a single answer.

Therefore, the designation matters beyond the label itself. It brings the way people actually experience ChatGPT further into regulators’ view. “OpenAI already has risk management obligations under the AI Act, but the DSA could widen the scope,” Böswald said. That could cover “not just risks from the model itself, but how the chat interface operates, how transparently it disseminates information, and how it affects users and society at scale.”

Two risk regimes at once

The AI Act mainly governs AI models and systems. The DSA meanwhile regulates the online service and how its design, functioning and use can create or amplify systemic risks. But ChatGPT presents a different case because the service itself has been designated a VLOSE. It could therefore face related risk-assessment requirements under both laws. ChatGPT now faces supervision from both the Commission’s DSA enforcement team and the AI Office. That could lead to parallel investigations, overlapping evidence and coordination problems.

“The overall compliance picture will become more layered, but we don’t quite yet know how. For example, the AI Act says that if an AI system is embedded into a VLOPSE, the DSA’s risk framework takes precedence. ChatGPT doesn’t fit into this case, which means that even if it counts as a VLOSE, it may face simultaneous risk assessment obligations under both the AI Act and the DSA”, Böswald said.

Similar service, different rules

Another difficulty is privacy, as ChatGPT conversations normally take place privately between one user and the chatbot. Böswald said requiring OpenAI to understand risks resulting from how people use the service could create difficult questions about how private conversations are analysed. “It’s still unclear how OpenAI or the Commission might try to tackle this and if they’re only focusing on input and output filters”.

There is also the question of competitors. Gemini, Claude, Perplexity and ChatGPT increasingly offer similar ways of accessing information. However, they may not all fall under exactly the same regulatory framework. “We’re left with very similar AI services being regulated through different frameworks,” Böswald said. That could leave regulators with a better picture of the risks created by some AI services than others.

Kids Act brings rules into the conversation

The EU is now considering another layer of regulation through its KIDS Act. The legislation, not yet adopted, aims to protect children from harm caused by online services. Its scope covers both AI companions and “general conversational chatbots”. This means systems such as ChatGPT that can assist users across many different subjects and tasks. Interface identifies self-harm, eating disorders, sexualised interactions involving minors and emotionally manipulative chatbots as examples of risks conversational AI can create.

The proposal changes how chatbots are designed for children. Providers would have to prevent addictive features and behaviour that could create emotional dependency. Safe settings would have to apply by default, with restrictions on using information from previous conversations. Chatbots would also undergo safety testing before launch and monitoring for emerging harms afterwards. Access for children under 13 would have to be controlled through tools for guardians.

At the KIDS Act launch, Commission Executive Vice-President Henna Virkkunen addressed AI-related risks directly. “Take AI chatbots and ‘AI companions’. With the EU KIDS Act, they can no longer act like human friends in ways that make children emotionally dependent on them”, she said. 

Parliament tests the new accountability

Accountability is starting to be tested. European lawmaker Veronika Cifrová Ostrihoňová (SK/RE) asked the Commission to examine ChatGPT’s safeguards around suicide-related material. She cited a test in which ChatGPT generated a suicide note in Slovak after a request framed around a school essay. According to her, subsequent tests produced different results.

The lawmaker asked if the Commission would use its DSA powers to verify and enforce safeguards. The same harmful interaction can therefore raise questions under several EU rulebooks.

OpenAI is already changing its safeguards

ChatGPT’s designation as VLOSE followed a OpenAI’s report of around 159.1 million average monthly users in the EU for ChatGPT’s search function. Well above the DSA threshold of 45 million. OpenAI has four months from the designation on 31 August to comply with additional obligations. These include systemic-risk assessments, mitigation measures, independent audits and regulatory oversight.

OpenAI is showing awareness of these new digital demands for safety. It launched ChatGPT for Teens in August, which applies stronger safety protections to users under 18 and additional parental controls. Simultaneously, it rolled out age prediction to identify accounts likely to belong to underage users and apply appropriate safeguards.

These measures show how AI providers are already adapting their products and safety policies. However, as the EU adds new requirements, the central question will be how regulators coordinate their oversight and ensure that similar services are subject to consistent expectations.