ChatGPT Is Now Legally a Search Engine in the EU. OpenAI's Own Count Puts It at Bing's Size.
The EU designated ChatGPT a Very Large Online Search Engine. OpenAI reported 159M EU search users, about Bing's size. What the DSA now forces into the open.
ChatGPT is now legally a search engine in the EU. OpenAI’s own count puts it at Bing’s size.
On August 31 the European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act, the first AI chatbot to carry the label (European Commission). Most of the coverage filed it as a compliance story: risk assessments, audits, fines of up to 6% of global turnover (Euronews). Fair enough. But the filing behind the decision contains something marketers have wanted for two years and never had: OpenAI’s own number for how many people use ChatGPT as a search engine.
That number is 159.1 million average monthly active recipients in the EU for the six months ending March 31, 2026. It counts ChatGPT search specifically, not the chatbot as a whole (Search Engine Journal). Bing, reporting under the same law, put its EU figure at roughly 172 million for the first half of 2026 (Microsoft).
So by the one counting rule every search engine in Europe now has to follow, ChatGPT search is a Bing-sized search engine. That’s the stat to take into your next planning meeting. The rest of this post is about what the designation forces into the open, because a few of those things are more useful to a marketing team than anything in the press release.
What Brussels actually decided
The DSA has two heavy tiers, Very Large Online Platforms and Very Large Online Search Engines, and both trigger at 45 million average monthly users in the EU. Reddit and Roblox got the platform label the same day, at 57.2 million and 46.6 million users (Search Engine Journal). ChatGPT got the search engine label because, in the Commission’s own framing, it is a “hybrid service” that engages with user queries and can search the web (Euronews).
Henna Virkkunen, the Commission’s executive vice-president for tech sovereignty, put it this way: “These new designations mean that ChatGPT, Reddit and Roblox will now be held to a higher standard of scrutiny and accountability in the European Union, in line with their large impact on our citizens and society.”
Two academics laid the groundwork months earlier. In January, Toni Lorente and Kathrin Gardhouse argued in a paper titled “Between Search and Platform” that ChatGPT is a hybrid of the two hosting types and, having crossed the 45 million threshold, should carry the most onerous DSA obligations (arXiv). The Commission picked the search engine door. OpenAI has four months from notification to comply, which puts the deadline around the turn of the year (European Commission).
One thing the decision does not do: change how ChatGPT ranks or cites anything. The Commission said nothing about ranking. If a vendor tells you Brussels just unlocked OpenAI’s ranking factors, close the tab. Google Search has been a designated search engine since April 2023 (European Commission) and has published two annual risk reports since. Neither told an SEO anything about how a page ranks. Expect the same from OpenAI.
What the designation does is create documents and data pipes that didn’t exist before. Four of them matter to anyone tracking brand visibility.
The EU search market, as reported by the engines themselves
Before the obligations, the number. Every online search engine operating in the EU has to publish average monthly active recipients under Article 24(2) of the DSA. Put the three that matter side by side:
| Service | Reported EU monthly active recipients | Period | Source |
|---|---|---|---|
| Google Search | 368.9M signed-in accounts, plus 397.3M signed-out sessions (Google says the two overstate uniques and can’t be added) | Jan to Jun 2026 | |
| Bing | ~172M | Jan to Jun 2026 | Microsoft |
| ChatGPT search | 159.1M | Oct 2025 to Mar 2026 | OpenAI, via Search Engine Journal |
The caveats are real. Google counts accounts and sessions separately and warns that neither is a unique-user figure. Microsoft doesn’t say whether Copilot interactions sit inside the Bing number. OpenAI’s window ends a quarter earlier than the other two. These are not apples to apples.
They are, though, the closest thing to apples that exists. Same law, same threshold, same legal exposure for getting it wrong. When we looked at ChatGPT’s real search market share last year, the argument was that click-based estimates undercount ChatGPT search by a wide margin because most answers never produce a click. This is the first regulator-grade figure, from the operator, and it lands in Bing’s neighborhood. Bing has had a line in European search budgets since 2009. ChatGPT search now has the user count to justify one.
Four things the DSA forces into the open
1. A public ledger of every ChatGPT ad shown in Europe
Article 39 requires a designated search engine to maintain a public repository of every ad it presents in the EU: the creative, the product or service, who paid, who it was shown on behalf of, the run dates, the targeting parameters, and aggregate reach by member state. The repository has to be searchable, support multi-criteria queries, expose an API, and keep each ad for a year after it last ran (CMS DigitalLaws).
The timing is almost comic. ChatGPT ads went live across 31 European markets on August 24, one week before the designation. They show to Free and Go users as sponsored links beneath the answer, contextually matched to the conversation, with personalized targeting available only on explicit opt-in (OpenAI, Enterprise DNA).
When we covered the US pilot in February, inventory was sold through OpenAI’s sales team and no public record existed of what ran, against which conversations, for whom. In the EU, Article 39 makes that record mandatory. Google’s Ads Transparency Center is the precedent: a queryable public record that competitive teams have quietly mined for years. Now picture the ChatGPT version. Which competitors bought placement against conversations about “CRM for a ten-person sales team,” in which countries, for how many weeks, and how many people saw it. That’s a paid-visibility map of your category that doesn’t exist for the US at all.
2. A written account of how ChatGPT search picks sources
Articles 34 and 35 require an annual systemic risk assessment of the service and its algorithmic systems, plus mitigation measures. Article 37 adds an independent audit. Article 42 requires a public report. Mathias Vermeulen and Laureline Lemoine, writing at TechPolicy.Press, argue the assessment has to cover how ChatGPT ranks results and selects sources, because those choices shape information quality and media pluralism, both named risk areas in the law (TechPolicy.Press).
The Commission has asked exactly that before. In March 2024 it sent formal information requests to Google Search and Bing about generative AI, naming “so-called ‘hallucinations’ where AI provides false information” as a risk it wanted mitigation plans for (European Commission). Google’s 2025 risk report now carries a section on generative AI mitigations (Google).
So OpenAI will have to describe, in a document a regulator reads, how ChatGPT search selects sources and what it does when the answer is wrong. It’ll be high level. It’ll be partly redacted. It will still be the first official description of source selection from the company, and I’d read it for one thing: any mitigation phrased as “source diversity.” A regulator worried about media pluralism pushes toward spreading citations across more outlets. That’s the opposite direction from the August shift toward official sources that cut Reddit’s citations by 86% in a week. Which pressure wins is unknowable from outside. The report is where you’d first see it.
3. A legal route for outsiders to audit brand recommendations
Article 40 gives vetted researchers the right to request non-public data from a designated search engine for research into systemic risks. The Commission adopted the operating rules in July 2025 and opened a data access portal in October (Hogan Lovells).
Be realistic about this one. Researchers have documented platforms rejecting applications on narrow readings of “systemic risk,” dragging out procedures, and handing over incomplete data (DSA Observatory). Commercial researchers are excluded outright, so no GEO vendor gets in, including us.
But consider what an academic could now ask for. Today every measurement of what ChatGPT recommends, ours included, comes from outside: run prompts, sample answers, count brands. We’ve written about why that produces a share-of-voice number with no auditable denominator. A vetted researcher studying whether ChatGPT search systematically favors incumbent brands could request actual query and citation logs instead of sampling. That’s the first path to a denominator that a platform, not a vendor, supplied.
4. A version of ChatGPT search that ignores what it knows about you
Article 38 requires designated platforms and search engines to offer at least one option for each recommender system that isn’t based on profiling (European Commission). The DSA’s definition of a recommender system covers prioritizing information “as a result of a search initiated by the recipient,” so search ranking is in scope (CMS DigitalLaws).
ChatGPT’s answers are shaped by memory. We mapped how the memory layers work and what they do to brand mentions last year: the same question gets a different brand list depending on what the model remembers about the person asking. In the EU, OpenAI now has to ship a version of search ranking that doesn’t do that.
For measurement, this matters more than it sounds. Every monitoring tool approximates a “clean” answer by using fresh accounts with no history. The DSA turns that approximation into a product surface OpenAI is legally required to offer. Two answers will exist for every EU query, one personalized and one not, and the gap between them is the personalization effect on your brand. Track both. One caveat from the platform side of the DSA: researchers found the non-profiled feeds on the big platforms are rarely the default and often hard to find (DSA Observatory). Expect the ChatGPT version to be buried too.
What to do this quarter
- Put ChatGPT search on the EU channel plan at Bing’s weight. If your European reporting has a Bing row, it needs a ChatGPT row next to it. The operator’s own number is 159 million users against Bing’s 172 million. Nobody gets to call that a rounding error anymore.
- Build the competitor watchlist for the ad repository before it exists. Brand names, product lines, the conversation contexts you’d expect them to buy against. The day the repository goes live, you want to run queries, not design them.
- Split personalized from baseline in your monitoring. Once the non-profiled option ships, run your query set through both and report the gap. If a competitor only shows up in personalized answers, that’s a memory effect, not a retrieval win, and it needs a different response.
- Read the first risk report for the words “source” and “diversity.” The compliance clock runs to roughly year end, and the public report lags that. Set the reminder now. It’s the closest thing to a source-selection policy OpenAI will ever publish.
- Keep doing the retrieval work. The designation changes who OpenAI answers to. It doesn’t change what the retriever matches, and none of it applies outside the EU. Relevance, extractable facts, and pages the crawler can reach still decide what gets cited.
The DSA didn’t make ChatGPT a search engine. A hundred and fifty-nine million Europeans did that, and OpenAI wrote the number down because the law made it. Everything else is paperwork, and some of that paperwork is about to tell you things OpenAI never would have volunteered.
Stop guessing about your AI search presence. Start your free RivalHound trial and get real data.