ChatGPT Now Answers to Brussels Twice Over
In one week at the end of August, the Commission sent its first AI Act information requests to more than 30 AI firms and designated ChatGPT a very large search engine. Here is what each regime demands, and why it matters.

For two years the EU’s rules on general-purpose AI models existed mostly on paper. That changed in late August. Within days of each other, the European Commission began using its new enforcement powers under the AI Act and pulled ChatGPT into the Digital Services Act (DSA), the EU’s platform-safety law. The largest providers now face two regimes, with different obligations and penalties.
What changed on 2 August
The AI Act’s obligations for providers of general-purpose AI models have applied since 2025, but the Commission’s powers to enforce them became applicable only on 2 August 2026. The AI Office, the Commission unit that supervises these models, can now send formal requests for information, require providers to grant access to their models for evaluation, appoint independent experts to carry out that work and ask for corrective measures, including restricting a model’s availability. Fines for breaches can reach €15m or 3% of worldwide annual turnover, whichever is higher. Supplying incorrect, incomplete or misleading information is itself sanctionable.
Transparency duties for providers and deployers of public-facing AI tools also took effect on 2 August. A voluntary code of practice on labelling AI-generated content has been signed by about 190 organisations, according to the Center for Democracy and Technology’s Brussels office.
The Commission also opened three routes for outside scrutiny: a complaints tool for alleged infringements, a channel for downstream companies that build on third-party models and believe the provider has not shared the documentation it owes them, and an anonymous whistleblower tool for people professionally connected to AI providers.
The first information requests
The Commission confirmed on 1 September that it had sent formal requests for information to more than 30 AI companies, covering safety and security, copyright and transparency. It has not published the list of recipients. They are the first test of how hard the AI Office will push providers to substantiate claims about how models are trained, tested and secured.
The AI Office’s first move was not a fine but a demand for paperwork, and the quality of the answers will shape everything that follows.
The next deadline is close. From 2 December 2026, enforcement extends to the Act’s prohibitions on AI systems used to generate non-consensual intimate imagery and child sexual abuse material.
ChatGPT becomes a search engine, legally
On 31 August the Commission designated ChatGPT’s search function a “very large online search engine” under the DSA, alongside new designations for Reddit and Roblox. ChatGPT search reported about 159 million average monthly active recipients in the EU over the six months to 31 March 2026, far above the 45 million threshold. The Commission treated it as a hybrid service that qualifies because it responds to prompts “including by searching the web”.
The designation brings obligations the AI Act does not: annual assessments and mitigation of systemic risks, independent audits, data access for vetted researchers, a public advertising repository where relevant, and a non-profiling option for recommendations. OpenAI has four months from notification to comply. DSA fines can reach 6% of global annual turnover. “These designations mean ChatGPT, Reddit and Roblox will now be held to a higher standard of scrutiny and accountability,” said Henna Virkkunen, the Commission’s executive vice-president for tech sovereignty.
CDT Europe notes that OpenAI announced it was expanding advertising across 31 European countries in the same period. Advertising inside a designated search service falls squarely within the DSA’s transparency rules.
What it means for decision-makers
For firms deploying these models, the effect is more documentation flowing down the supply chain, and a formal channel to complain when it does not. For public bodies procuring AI assistants, the designations offer a new source of assurance: audited risk assessments that buyers can ask to see.
In her State of the Union address on 16 September, Ursula von der Leyen called for a slowdown in self-improving systems — “Time to slow down on the self-recursive models. To pace the frontier” — and said Brussels would work with Canada and the UK on model evaluation and AI security. Brussels has shown it is willing to use both rulebooks. The open question is how quickly it will move from asking questions to imposing remedies.
Sources
- The enforcement framework of the AI Act — European Commission
- EU AI Act enforcement has started: Commission sends first information requests to AI companies — Allegiance Law
- EU begins enforcing AI Act, putting AI models under the microscope — Help Net Security
- EU AI Office opens three complaint routes — PPC Land
- ChatGPT is now a “very large online search engine” in the EU — Search Engine Journal
- CDT Europe’s AI Bulletin: September 2026 — Center for Democracy and Technology
- Self-improving AI should slow down, von der Leyen tells EU lawmakers — Help Net Security
- Complaints channel for downstream providers using general-purpose AI models — European Commission
Discussion
No comments yet. Start the conversation.


