A Very Large Everything The European Commission designated ChatGPT, Reddit, and Roblox as Very Large Online Platforms and Search Engines under the Digital Services Act, marking the first time an AI chatbot has been classified as a search engine. The designation, announced on August 31, 2026, requires the companies to comply with strict digital safety rules by the end of November, including systemic risk assessments and independent audits, with fines up to 6% of global annual turnover for non-compliance. The DSA has already collected nearly €870 million in penalties this year, including €550 million from AliExpress and €200 million from Temu. Brussels designated ChatGPT as a Very Large Online Search Engine today https://www.euronews.com/next/2026/08/31/eu-places-chatgpt-reddit-and-roblox-under-strictest-digital-safety-rules , alongside Reddit and Roblox as Very Large Online Platforms, under the Digital Services Act. First time an AI chatbot has ever gotten the search-engine label. I read that twice too, for a different reason than usual — not because it's surprising regulators are circling, but because of how they got there. The Commission's logic: ChatGPT is a "hybrid service" that counts as a search engine because it can pull live results from the internet to answer your prompt. Not because it looks like Google. Because it functions like Google, whether OpenAI wants to wear that label or not. Reddit and Roblox got the platform tag because they let users create and share content publicly — the same bucket that already holds Facebook, TikTok, and Amazon. All three now have until the end of November to start complying, and by end of Q4 to be fully compliant with the whole suite — annual systemic risk assessments covering illegal content, minor protection, mental and physical wellbeing, elections, and public security, plus independent audits and mandatory data-sharing with regulators. Miss it and you're looking at fines up to 6% of global annual turnover — turnover meaning revenue , not profit. That's worth sitting with, because it's not the kind of fine most of us default to picturing. A parking ticket, a late tax bill, a fine for missing a filing deadline — those are usually fixed, or scaled to some notion of what you actually took home. This isn't that. The formula doesn't ask whether a company can afford it, or whether it made money this year, or whether it's currently losing billions on purpose. It just looks at the top line — everything that came in the door — and takes its cut. A company with razor-thin margins and a company still deep in the red get treated identically if their revenue is the same size. The DSA's already collected close to €870 million in penalties this year alone, including a €550 million hit on AliExpress and €200 million on Temu. This isn't a toothless list. For a company like OpenAI — spending against revenue as fast as it clears the desk, with no real slack sitting anywhere to absorb a surprise claim — that's not a footnote. It's another fuse. The compute burn is one. Florida's suit naming Altman personally is another. The Oakland trial airing OpenAI's internal dysfunction under oath is a third. A regulatory regime that can claim a chunk of revenue regardless of whether there's profit behind it, landing right as the IPO clock forces all of this into the same disclosure document, is a fourth. None of them care what the others are doing. That's what makes the pile dangerous — not any single fuse, but the fact that there's nothing underneath any of them to slow a spark down. The real twist, though, is Google. Google Search has been a VLOSE since the very first DSA designation wave back in 2023 https://www.eeas.europa.eu/delegations/japan/digital-services-act-commission-designates-first-set-very-large-online-platforms-and-search-engines en . AI Overviews and AI Mode do the exact same live-synthesis-from-the-web thing ChatGPT just got flagged for. Google doesn't get a new headline moment for it, because the box was already checked years ago — it just gets to keep doing the thing quietly under an existing umbrella while everyone stares at the new kid. Italy's AGCOM already referred Google's AI Overviews to the Commission back in April over exactly this — citing systemic risk and media pluralism articles in the DSA — but that's playing out as a slow-motion Article 65 escalation, not a press conference. Same behavior, wildly different visibility. If you're Google, that's not a coincidence you'd complain about. Worth flagging too: this designation logic doesn't stop at ChatGPT. It's a threshold test — cross 45 million average monthly EU users doing search-like things, and you're in the same bucket, regardless of brand. Gemini's arguably already there several times over. It's folded into Search itself, which is how it currently rides Google's existing VLOSE status without a headline of its own — but that undersells it. The standalone Gemini app crossed a billion monthly active users this month, and Google's been actively phasing Google Assistant out on Android in favor of Gemini as the default. Search integration, a billion-user standalone app, and OS-level default status on the world's largest mobile platform — Gemini doesn't actually need Search's coattails to clear the 45-million EU threshold on its own. It's just convenient, for now, that nobody's had to test that separately. And Google's obvious play, if regulators ever do come asking, is to argue Gemini isn't a separate service at all — just a front end to the same underlying infrastructure Search already answers for, so the existing VLOSE designation already covers it. Whether that argument survives contact with a Commission that just decided ChatGPT counts as a search engine because of what it does , not what it's branded as, is a fun question to sit with. Perplexity is the one to watch if it keeps growing — it's built entirely around the live-web-synthesis behavior the Commission just used to classify ChatGPT, so if it clears the threshold there's no real argument left for treating it differently. Copilot's an interesting maybe — Microsoft's got the distribution through Windows and Office, but outside of coding contexts it's been visibly struggling to get people to actually use it, so it's not obvious it's pulling EU numbers anywhere close to the line yet. And Siri's actually further along this road than I gave it credit for. Apple flagged the multi-provider direction as far back as WWDC 2024, when Craig Federighi said they were "looking forward to doing integrations with other models, including Google Gemini" https://techcrunch.com/2024/06/10/apple-confirms-plans-to-work-with-googles-gemini-in-the-future/ right as the ChatGPT deal was announced. That became the "Extensions" framework — a settings panel letting users pick which chatbot handles which request, Claude and Gemini joining ChatGPT as providers, open to others over time through the App Store. It was reportedly sitting fully built in the iOS 27 developer beta. Apple didn't announce it at WWDC this year. The reason is exactly the kind of EU entanglement this post is about: Apple told the Commission it needs a "Trusted System Agent" model https://thenextweb.com/news/apple-siri-extensions-third-party-ai-missing-wwdc so rival assistants get access to Siri's capabilities without touching sensitive device data directly. The EU rejected that under the DMA. Unveiling an open third-party-AI framework at a keynote while simultaneously telling Brussels that third-party access is too risky to grant directly would've been a hard needle to thread, so Apple shelved the announcement — with the feature, by most accounts, built, toggled off, and waiting. There's a second complication stacked on top: OpenAI is reportedly preparing legal action over the original exclusive deal, claiming Apple buried the ChatGPT integration behind enough friction to cost it the subscription revenue it expected. So it's not that Apple's staying out of the fight by design. They're already in one — a live DMA standoff over how much of Siri's plumbing a rival gets to touch — and it's the thing currently keeping a finished feature in the vault. Whatever kit-style API eventually ships will have been shaped by that fight, not by Apple simply choosing to stay small on purpose. The IPO Timing Problem This lands at a genuinely inconvenient moment for OpenAI. Not because it's dramatic — because it's boring and structural, the kind of thing that shows up in a risk-factors section instead of a headline. The company confidentially filed its S-1 back in June https://openai.com/index/openai-submits-confidential-s-1/ , targeting a valuation north of $1 trillion off an $852 billion private mark set in March. The original window was September 2026. As of CFO Sarah Friar's all-hands in mid-August https://fortrovepartners.com/openai-ipo-timeline-valuation-tracker/ , that's now "2027, or sooner if the business inflects" — her stated reasons being financial reporting readiness, revenue durability under public scrutiny, and the sheer weight of multi-year compute commitments on the balance sheet. Layer the DSA obligations on top of that and you get one more reason nobody's saying out loud yet: annual systemic risk assessments and independent audits are now a disclosed, material, recurring compliance cost, due right as the company is trying to convince institutional buyers it's ready for quarterly earnings calls. OpenAI disclosed ChatGPT's search function pulled about 159 million average monthly EU users over the six months ending March — nearly three times the 45-million designation threshold. That number is now a regulatory liability line item, not just a growth stat. I said in Wait. Florida? https://blog.ppb1701.com/wait-florida that someone was eventually going to make OpenAI answer formally for the gap between what it says publicly and what the internal record shows — that time it was a state AG naming Altman personally over ChatGPT's role in a string of violent incidents, with the remedies on the table including age-gating and stripping the features that make the product feel human. This is a quieter version of the same pattern, just wearing a different regulator's badge. The DSA doesn't care about deaths or dysfunction — it cares about scale and risk mitigation on paper. But it's still one more institution, on one more continent, demanding OpenAI produce documentation instead of a keynote. The IPO roadshow is going to have to reckon with both files sitting open at the same time. Reddit's Two-Faced Data Story Reddit's the one that actually bites, though. The DSA designation exposes a contradiction Reddit's been profiting from for two years. In 2024, Reddit disclosed licensing deals with Google and OpenAI worth $203 million combined https://www.cjr.org/analysis/reddit-winning-ai-licensing-deals-openai-google-gemini-answers-rsl.php — roughly $60 million a year from Google, $70 million a year from OpenAI, both for real-time access to Reddit's forums as AI training and grounding data. Reddit is now the single most-cited domain across AI models, cited three times more often than Wikipedia. Data licensing pulled in $130 million in 2024 alone, about 10% of total revenue, and it's still climbing — Reddit's own CEO told investors he wants Reddit to become "a go-to search engine" in its own right, and the company is reportedly angling for a dynamic-pricing renegotiation with both Google and OpenAI as its archive gets more valuable to the exact systems now under EU scrutiny. So: the same content that unpaid volunteer moderators police under a patchwork of subreddit-specific rules gets packaged and sold upstream to the two companies that are themselves now under DSA supervision for what they do with it downstream. A user posts something → a volunteer mod enforces a rule Reddit didn't write and doesn't pay them to enforce → Reddit licenses that post to Google and OpenAI → their DSA-regulated products resurface a version of it to someone else, stripped of the moderation context that governed it the first time. Three separate regulatory perimeters, one underlying supply chain, and the actual labor holding it together isn't compensated or contractually accountable to anyone. That's before you get to the compliance mechanics: DSA VLOP status expects Reddit to demonstrate it's "acting expeditiously" against illegal content and mitigating systemic risk in a way an independent auditor can verify. Reddit's own transparency reporting shows volunteer moderators handle the majority of content removals — inconsistent, under-resourced, prone to burnout, and accountable to their communities more than to Reddit's legal department. Proving that structure satisfies a documented, auditable EU standard is going to be a genuinely uncomfortable exercise, and I'd bet money it ends with Reddit quietly building out more paid trust-and-safety headcount for exactly the parts regulators will actually look at, while leaving the volunteer layer to absorb everything else. Same two-tier system, just with better paperwork on top. Read the terms. They're more honest than the marketing.