On 31 August 2026, the European Commission designated ChatGPT as a very large online search engine (VLOSE) under the Digital Services Act (DSA). It is the first designation of a generative AI service. Reddit and Roblox were classified as very large online platforms (VLOP) on the same day. All three services had reported to the Commission that they meet the threshold of 45 million average monthly users in the Union under Article 33(1) DSA. For ChatGPT, OpenAI reported around 159.1 million users of its search functions for the six-month period ending 31 March 2026.
The designation coincided closely with the launch of advertising: ads had gone live in Germany a week earlier, and self-service access through the Ads Manager opened on the same day.
This article is the second part of a three-part series on current developments around AI assistants. The first part set out the advertising and data protection standards applying to the advertising model (available here). This part looks at the obligations that follow from the designation, at the gaps the DSA may leave for advertising in AI assistants, and at the supervisory bodies that have a say alongside the Commission. Like the first part, it is addressed to companies that advertise in this environment or deploy AI assistants in their own operations. The third part deals with the responsibility and liability of advertisers and agencies.
ChatGPT as a search engine
The Commission bases the classification as a search engine on the fact that the service accesses internet content directly when answering queries. OpenAI has not contested the designation and has stated that the search function of ChatGPT operates as a search service within the meaning of the DSA. The DSA was designed for classic platforms and search engines and contains no separate category for generative systems of this kind. The Commission has therefore applied an existing framework to a new type of service.
The designation starts a four-month period (Article 33(6) DSA) which, according to the Commission, expires around the turn of the year 2026/2027. Section 5 of Chapter III DSA then applies. It covers the assessment of systemic risks under Article 34 and their mitigation under Article 35, expressly including advertising systems, as well as independent audits under Article 37, the advertisement repository under Article 39, data access for researchers under Article 40, extended transparency reporting under Article 42 and the annual supervisory fee under Article 43. Articles 37, 39 and 40 DSA, which the first part identified as starting points for verifying the provider’s promise that advertising does not influence its answers, therefore only apply from that date. For Section 5, supervisory and enforcement competence lies exclusively with the Commission.
An asymmetry in the DSA advertising rules
By its wording, Article 39(1) DSA addresses „providers of very large online platforms or of very large online search engines“. The substantive advertising requirements in Section 3, by contrast, consistently address only „providers of online platforms“: Article 25 on the design of the online interface, Article 26 on the labelling of advertising and on profiling using special categories of data, Article 27 on the transparency of recommender systems and Article 28 on the protection of minors, including the prohibition of profiling-based advertising directed at minors. On the wording, OpenAI as a VLOSE is therefore subject to the repository obligation, but not to the requirements on labelling, transparency of recommender systems, manipulative design and targeting of minors.
This literal reading is not undisputed. It is argued in the literature that Article 26 DSA applies at least to advertising-funded online search engines, and that the transparency requirements for recommender systems extend functionally to very large online search engines via Article 38 DSA. The asymmetry produces the inconsistencies described above and is accordingly the subject of ongoing debate. Advertisers and providers would be well advised not to rely on the gap in the wording holding in the long run.
It should also be noted that the Commission has designated ChatGPT as a VLOSE, but has not thereby decided that the service is not also an online platform within the meaning of Article 3(i) DSA. If it also meets the platform criteria, the provisions of Section 3 could apply in addition.
There are several starting points for that argument. Article 3(i) DSA requires a hosting service that stores information at the request of a recipient and disseminates it to the public. That applies first of all to the advertisements themselves, which the provider stores and displays on behalf of its advertising customers. It may also apply to features that allow users to make their own content publicly accessible, such as sharing individual conversations through retrievable links or offering self-configured assistants in a public directory. Whether such features qualify as a minor and purely ancillary feature within the meaning of Article 3(i) DSA determines whether the platform classification holds.
German media law is already engaged
Alongside the DSA, German authorities have been applying German media law since July 2026. On 14 July 2026, in two proceedings conducted by the state media authorities of Hamburg/Schleswig-Holstein and Berlin-Brandenburg, the Commission on Licensing and Supervision (ZAK) issued its first decisions against AI services, concerning Google’s AI Overviews and Perplexity. It found that AI answers are the providers’ own content and that the liability exemption under the DSA does not apply to them. The levers used are the diversity rules for media intermediaries under sections 91 to 94 of the Interstate Media Treaty (MStV), in particular the transparency requirement and the non-discrimination rule, which in principle presuppose the transmission of third-party information. Google has announced an appeal; the decisions are not yet final.
The proceedings concerned Google and Perplexity. Whether the reasoning can be transferred to ChatGPT is likely to depend on how source selection and linking are designed in detail. On the distinction set out in the first part, classification as a media intermediary requires that the service aggregates third-party content, selects it and determines how easily it can be found, without combining it into an overall offering of its own, which is difficult to assume for content that providers generate themselves and are liable for. It is disputed in the literature whether presenting generated answers is sufficient or whether visibly displayed third-party content with an identifiable source reference is required. An expert opinion commissioned by the state media authorities concludes that large language models are to be classified as media intermediaries to the extent that they reproduce source links within their own generated answers. That is said to apply only where the sources are not given as mere evidence, but as „further sources“, with the result that third-party content is transmitted. How that distinction is to look in practice is left open.
Two supervisory regimes side by side
If ChatGPT were both a media intermediary under sections 91 et seq. MStV and a VLOSE under the DSA, two supervisory structures would meet: the state media authorities on one side, and on the other the Commission, which is solely competent for Section 5, together with Coimisiún na Meán as Digital Services Coordinator for the remaining obligations given the Irish establishment. Between them stands the country-of-origin principle under section 3 of the Digital Services Act implementation statute (DDG) and Article 3 of Directive 2000/31/EC. Whether section 93 MStV is enforceable against providers established in another Member State has been left open by the Administrative Court of Berlin and the Higher Administrative Court of Schleswig, which referred the question to the Court of Justice of the European Union. In Germany, the Federal Network Agency also acts as Digital Services Coordinator; the lead data protection authority is the Irish Data Protection Commission.
There is also the allocation of competence under the German AI market surveillance act (KI-MIG), which the first part described for Article 50 AI Act: the Federal Network Agency is the central market surveillance authority, while for media services serving journalistic or advertising purposes the authorities competent under state law remain responsible under section 2(8) KI-MIG. The question of competence therefore needs clarification both between the Union and state level and within German supervision. We have set out the draft Interstate Treaty on Digital Media and the allocation of competence it provides for in a separate article (available here).
What the enforcement pattern shows so far
The Commission has concluded three DSA cases with a fine to date. On 5 December 2025, X was fined 120 million euros for the misleading design of its verification mark, an incomplete advertisement repository and insufficient data access for researchers, all of them verifiable transparency obligations. On 28 May 2026, a fine of 200 million euros against Temu followed, and on 20 July 2026 a fine of 550 million euros against AliExpress. In both cases the focus was not on transparency obligations but on the assessment and mitigation of systemic risks in connection with illegal, unsafe or counterfeit products. In the Temu case, according to the Commission, the risk assessment relied on general information about risks in the e-commerce sector instead of evidence relating to the service itself.
For ChatGPT, the second line may be the more informative one, because the risk assessment is among the first obligations to apply once the period expires. In the Temu case in particular, the Commission did not merely check whether an assessment had been submitted, but whether it holds up in substance. Fines may reach up to six per cent of worldwide annual turnover; the amounts imposed so far have remained well below that.
Consequences for the advertising system
The advertising system went live a week before the designation and must feed into the first systemic risk assessment before the period expires. Article 34(1)(b) and (d) DSA covers negative effects on fundamental rights, including consumer protection and the rights of the child, as well as on the protection of minors and on physical and mental well-being. Under Article 34(2) DSA, the systems for selecting and displaying advertising are among the factors to be taken into account in the risk assessment. The selection of ads by the topic of the ongoing conversation, described in the first part, should therefore be subject to that assessment, regardless of whether Article 26 DSA applies on its wording.
What comes next
Two developments are on the horizon. At Union level, the Commission is expected to propose a Digital Fairness Act in the fourth quarter of 2026, focusing on manipulative interface design, unfair personalisation and the protection of minors. At state level, the Broadcasting Commission discussed the draft of an Interstate Treaty on Digital Media (part 2) on 16 September 2026. Under that draft, providers of AI information systems are to be responsible for the content these systems generate. One option under consideration is to treat AI services as media intermediaries, another to create a new category of telemedia. The public consultation is still planned for 2026.
The expiry of the period around the turn of the year will show how the Commission assesses the risk assessment of a conversational service. Until then, the question that matters most for companies that deploy such services or advertise in them is which supervisory regime governs their own role. The third part of the series addresses that role.
If you have questions about the regulatory classification of your campaigns or of your use of AI assistants, or about what the DSA designation means for your advertising environment, we are happy to help.



