A chatbot does not stop being a chatbot because a regulator finds the search box. That is the useful nuisance in the new European discussion around ChatGPT: the same product can be treated as a search service for one legal purpose and an AI system for another. If your compliance spreadsheet has one tab labeled AI rules, congratulations, you have made a filing cabinet, not a governance system.

Interface's point: one product, two legal lenses

Interface's October 01, 2026 policy brief, Different Risks, Different Rules? The Case of ChatGPT under the DSA and the AI Act, puts the issue cleanly. According to Interface, the European Commission designated ChatGPT as a Very Large Online Search Engine under the Digital Services Act in August 2026. The awkward fit is the point: Interface says ChatGPT retrieves web information and generates conversational answers, so it can be examined under the DSA framework even though it does not look like a conventional search engine.

POLITICO had earlier reported that the DSA has been in force since early 2024 and that a Commission decision on ChatGPT was expected in mid-2026. Put beside Interface's October 01 brief, the sequence is less a tidy legislative march than a regulatory retrofit around a product people already use.

@title ChatGPT EU oversight path
@source Interface
@source POLITICO

  Early 2024 ··· DSA in force
  Mid 2026 ····· decision expected
  August 2026 ·· ChatGPT designated
  October 01 2026 · Interface brief

@caption The DSA question moved from existing law to a ChatGPT designation and then to the Interface analysis.

The practical lesson is not that every chatbot is suddenly a search engine. It is that a product team cannot answer scope with a label chosen by marketing. If a feature retrieves, ranks, or presents web information, the DSA question sits next to the AI Act question rather than politely waiting outside.

What the DSA track asks, according to POLITICO

POLITICO reported that the Commission placed ChatGPT under the DSA's strictest platform rules by designating it as a Very Large Online Search Engine, while Reddit and Roblox were designated as Very Large Online Platforms. The same report said online services with more than 45 million users in the EU fall under the stricter regime, which included 28 platforms and search engines at the time. ChatGPT had drawn attention after declaring 120 million users last year, according to POLITICO.

For builders, the DSA track is not an abstract AI ethics exercise. POLITICO reported that the designation brings direct Commission supervision and obligations to assess and mitigate systemic risks, including effects on minors, election integrity, and public security. It also reported that companies risk fines of up to 6 percent of annual global revenue if they fail to comply within four months.

Plainly translated: your DSA risk file should follow the service behavior. It should show where search-like functions appear, what transparency notices users see, how systemic risks are assessed, and who signs off when a new feature changes those risks. Saying the model was evaluated under an AI framework does not answer whether the search service met DSA obligations. Different statute, different homework.

The chat problem does not disappear

POLITICO's separate analysis of the ChatGPT designation noted the limit that should make product lawyers sit up straighter. The EU's search-engine classification applies only to the parts of the tool that act as a search engine, while conversations in which the chatbot adds its own input do not appear to be covered by that designation. POLITICO also reported that the Commission could have categorized ChatGPT as a Very Large Online Platform, which would have brought a different set of obligations.

That leaves builders with a line-drawing problem inside the product, not just inside the legal memo. A user asking for current information may trigger one regulatory logic; a user treating the same interface as a companion, tutor, or political sounding board may raise another. The interface is continuous, but the legal theories are not.

This is where the generic AI compliance checklist earns its bad reputation. A single checklist tends to flatten risks into one review date, one owner, and one green box. The better map separates functions: retrieval, ranking, generated answers, conversational memory if present, and user-facing disclosures. Then each function is tied to the legal regime that actually cares about it.

The compliance file should split before enforcement does

Axios reported that the Federal Trade Commission is investigating OpenAI, Anthropic, and other AI companies over potential safety risks posed by their products. That is a different jurisdiction and a different enforcement theory, but it rhymes with the EU lesson. Regulators are not waiting for products to fit neat categories before asking who controls which risk.

Interface's contribution is to make that overlap legible rather than mystical. The DSA asks what the service does in the information environment. The AI Act asks how the AI system is governed under its own regime. A sensible company will keep those files connected, but not merged. Shared evidence is efficient; shared assumptions are how surprises arrive.

For product leaders, the next thing to watch is how the Commission draws the boundary between ChatGPT's search behavior and its conversational behavior. For builders, the safer move is available now: map the user journey by function, attach each function to the relevant obligation, and review changes before rollout in Europe. If someone says this is just one AI compliance workstream, ask them which regulator they plan to disappoint first.

Sources