ChatGPT is now an EU-regulated search engine: what changes for GEO
The European Commission designated ChatGPT as a Very Large Online Search Engine on August 31, 2026. Systemic risk assessments, ranking transparency and researcher data access: the three obligations that turn GEO into a compliance problem before December.
ChatGPT is now an EU-regulated search engine: what changes for GEO
On August 31, 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act. OpenAI has until the end of December to comply with the new duties: systemic risk assessments, documented ranking parameters, and data access for vetted researchers. For the first time, chatting with a bot is legally "search" in Europe. GEO just gained a compliance layer.
This is not administrative noise. It's the first time a generative product has to explain why it answers the way it answers, to a regulator, with fines of up to 6% of global turnover if it doesn't. Publishers, agencies and brands that appear (or don't appear) in those answers inherit the change.
What happened on August 31
The Commission designated ChatGPT as a Very Large Online Search Engine after OpenAI declared 159.1 million monthly users in the EU. The threshold for the tier is 45 million. In the same move, Reddit and Roblox were designated Very Large Online Platforms, putting the three services at a combined reach of 262.9 million people in the bloc.
OpenAI is supervised through Ireland, where its European headquarters sit. The compliance deadline is four months from notification, by the end of December 2026. This is not a recommendation. It's an obligation with financial teeth.
The VLOSE category has existed since 2023 in the Commission's policy for very large platforms and search engines. What's new is that it finally applies to a generative answer, not a list of blue links. In Europe, "search" no longer ends where the chatbot begins.
The three obligations that matter to publishers
Most of the DSA package is about platform hygiene. Three pieces actually change the terrain where GEO operates:
Systemic risk assessment and mitigation. OpenAI must identify how its algorithmic design could amplify disinformation, consumer harm or misleading content, and it must mitigate that. Translation for brands: the quality and pedigree of cited sources just became a risk issue, not an aesthetic preference.
Ranking transparency. A VLOSE must explain the main parameters that determine what shows up first in its results. That means the citation criteria of ChatGPT can stop being a black box. And when a system has to document its criteria, the criteria start to stabilize.
Researcher data access and transparency reporting. Accredited researchers will be able to request data on how the service works. The era where the only evidence of AI visibility was an un-auditable screenshot is over.
Where GEO turns into compliance
Optimizing for AI search was, until now, a discipline of content and signals. It still is. But there is a legal frame around it now, and that changes four practical things.
First, the screenshot stops being a measurement instrument. We already argued that a ChatGPT citation is a sample, not a result, because a single answer can change without you touching a page. With researcher data access, auditable datasets will exist. Dashboards built on screenshots will die; dashboards built on repeatable panels will survive.
Second, ranking transparency will force OpenAI to publish criteria. When that happens, guessing why a source appears is over. Agencies that already measure with method will be ready to read those reports. Agencies that sell screenshots won't.
Third, systemic risk pulls the brand into the equation. If a model describes your product wrong at scale, if your content repeats claims without sources, if your entity is a mess in the directories models read, that's no longer just a visibility problem. It's material for a risk report. Entity hygiene just moved from best practice to insurance policy.
Fourth, someone else's non-compliance does not excuse yours. OpenAI can pay the fine. Your brand can stay missing from answers while the legal mess gets sorted. Regulation protects users, not your citation share.
The comparison that matters: ChatGPT versus Google as regulated surfaces
Google has been a regulated search engine in Europe for years. Look at what that produced: documented core updates, public guidelines about ranking, transparency reports you can actually read. None of it made the algorithm transparent. It made the system accountable, and it gave publishers a vocabulary for challenging what they see.
ChatGPT will travel the same arc, faster. Google's transparency duties matured over a decade of complaints and case law. OpenAI's first obligations land four months after its designation. The risk assessments and transparency reports due in December will be the first regulator-facing description of how an LLM decides what to answer, written for Dublin, not for a marketing blog.
The consequence for publishers is specific: citation criteria will become auditable against a published description of the system. The sites that come out ahead are the ones whose claims survive an audit, not the ones with the loudest keyword coverage. That is the same shift we measure with citation volatility, now with a legal frame under it.
What this means outside Europe
Strictly, the designation binds OpenAI for EU users. Practically, OpenAI runs one product, not two. The ranking documentation it writes for its Dublin supervisor will describe the same system that answers users in Mexico City, Bogotá or São Paulo. The risk assessments will shape content policies that apply everywhere.
We run GEO for clients across Latin America, and the DSA parts that touch search have a habit of becoming global defaults: transparency reports, documented criteria, audit trails. Regulation starts in Brussels and ends up in your analytics. If your brand sells to Spain, Portugal or any EU market, this is direct. If it doesn't, treat December's reports as a preview of how AI search will be governed in your market a year later.
Five moves before December 2026
1. Audit your visibility for European audiences. The obligations apply to EU users, the ones receiving answers shaped by the new controls. Run your purchase-intent query panel in English and in the languages of your European markets, and log where you appear and how you're described.
2. Build the evidence file. Every claim you publish, or that models cite from you, should carry a date, a source and a methodology. Not for aesthetics: if a researcher audits how the system answers about your industry, pages with verifiable data come out better. The evidence standard we use to evaluate GEO agencies works for this too.
3. Straighten your entity. Consistent Organization schema, identical name and description across profiles, sameAs pointing to everything you control. If a system has to document how it identifies you, a clean entity cuts the errors that later become risk findings.
4. Measure with method, not luck. Repeat a fixed query panel under the same conditions and measure citation volatility before claiming anything. When the transparency reports land, you'll want your own historical series to compare against them.
5. Put December on the calendar. OpenAI's first reports will ship with real ranking and risk data. Schedule a quarterly GEO strategy review against those documents, not against Twitter rumors.
What stays the same
Worth saying, because there's a lot of noise: citation mechanics did not change on August 31. Models still cite what is already cited, corroborated by third parties and described with consistent entities. The cold start for a new product still breaks with directories and third-party mentions, not with more content on your own domain. We covered that yesterday, and regulation doesn't modify it.
What changes is accountability. Before, an opaque ranking criterion was a technical mystery. Now it's a potential violation. For brands that already work with method, that's an advantage: the field levels with data, and data favors the people who keep it.
The opportunity lives in the next four months. Those who build the evidence file, the entity and the measurement panel now will read OpenAI's first reports with context. Everyone else will read them scared.
Frequently Asked Questions
What is a Very Large Online Search Engine (VLOSE)?
It is the strictest tier of the EU's Digital Services Act for search engines: services with more than 45 million monthly users in the EU. ChatGPT was designated on August 31, 2026 after declaring 159.1 million European users.
When does OpenAI have to comply with the new obligations?
Four months after the designation notification, so before the end of December 2026. Non-compliance can trigger fines of up to 6% of global annual turnover.
Does the designation change how ChatGPT cites websites?
Not directly. Citation mechanics still depend on content, entity consistency and third-party corroboration. What changes is that OpenAI must document the main parameters of its ranking and open data to researchers, so the criteria stop being a black box.



