Skip to content Skip to footer

Congratulations, Europe: You Just Regulated Yourself Into the AI Slow Lane — Again

On August 31, 2026, the European Commission did something that sounds bureaucratic and is actually a pretty good encapsulation of Europe’s entire relationship with the AI era: it declared that ChatGPT is a search engine.

Not metaphorically. Legally. Specifically, the Commission designated ChatGPT a Very Large Online Search Engine (VLOSE) under the Digital Services Act — the first time an AI chatbot has ever received that classification. Reddit and Roblox got hit with the platform equivalent (Very Large Online Platform, VLOP) in the same announcement. All three now join the DSA’s most heavily regulated tier, alongside Google, Meta, Amazon, and the rest of the usual suspects.

If your reaction is “so what, it’s just a label” — that’s the polite version of what OpenAI’s compliance team is thinking right now, and they’re wrong to be polite about it. This is the third time in about eighteen months that a major AI product has hit the wall of EU digital regulation, and the pattern is no longer subtle. Let’s walk through what actually happened, then talk about why it matters more than the press release makes it sound.

The Designation, In Plain English

The DSA’s VLOSE/VLOP threshold is a hard number: 45 million average monthly active users in the EU. Cross it, and you graduate from “regular platform” to “systemically important, audit us constantly” status.

OpenAI’s own disclosure — filed for DSA compliance purposes, calculated over the six months ending March 31, 2026 — put ChatGPT’s search function at roughly 159.1 million average monthly EU users. That’s not a near-miss. That’s more than 3.5 times the threshold. For context, Reddit came in at 57.2 million and Roblox barely cleared the bar at around 46.6 million. ChatGPT didn’t sneak over the line; it obliterated it.

One detail worth sitting with: Anthropic’s Claude stayed below the 45 million threshold and wasn’t designated. Make of that what you will — smaller footprint, different growth curve, whatever the reason, it’s a reminder that this isn’t a blanket “AI is bad” rule. It’s a scale rule, and scale is exactly what makes a product useful to the most people.

So what does VLOSE status actually require? Once notified, OpenAI has four months to comply — putting the real deadline somewhere around the end of December 2026 or early January 2027. The obligations include:

  • Annual systemic risk assessments — not just once, but re-triggered every time OpenAI ships a feature judged likely to have a “critical impact” on systemic risk
  • Independent third-party audits, at least annually
  • Algorithmic transparency requirements around how the system generates and ranks information
  • Researcher data access under DSA Article 40, letting vetted external researchers request information about systemic risks and mitigation efforts — a provision some legal analysts believe could extend toward training-adjacent data, not just output logs
  • Public risk-assessment reporting covering impacts on civic discourse, electoral integrity, minors, and mental health

This isn’t theoretical enforcement. The DSA’s maximum penalty is up to 6% of global annual turnover, and the Commission has already shown it’s willing to use the hammer — X was fined €120 million in December for failing DSA transparency requirements. The Commission’s own framing is that designation “is not a finding of wrongdoing.” Fair enough. But the compliance apparatus that follows behaves exactly like consequences for wrongdoing, whether or not any has occurred yet.

A Category Built for 1998, Applied to Something From 2026

Before getting into what VLOSE status actually requires, it’s worth pausing on a more basic question: is ChatGPT even a search engine in any meaningful sense?

The DSA’s legal definition of an “online search engine” was written with a specific mental model in mind — a service that crawls an indexed web and returns ranked links in response to keywords. That’s Google in 2010. It is not obviously the same category of thing as a generative model that reasons across a conversation, synthesizes an answer from its own parameters, and only sometimes reaches out to the live web to check itself. Legal scholars have flagged exactly this tension: a 2026 paper in Internet Policy Review argues ChatGPT displays “fundamental characteristics of an online platform” alongside its search-like behavior, making it better understood as a hybrid that doesn’t cleanly fit either box the DSA was built around — even while concluding, under a technology-neutral reading of the AI Act’s Recital 119, that counting ChatGPT’s users toward the search-engine threshold is legally defensible anyway.

That’s not a smoking gun. It’s a genuinely unresolved question that the Commission has answered by fiat rather than by waiting for the law to catch up to the technology. Worth noting, not because “it’s not technically a search engine” is some knockout argument against oversight — a hybrid product can and probably should be regulated as something — but because it tells you the compliance framework being applied here wasn’t designed for the object it’s now being applied to. That mismatch is exactly the kind of thing that produces awkward, over-broad compliance behavior: when the rulebook doesn’t fit the product, companies default to the most conservative possible interpretation, and “most conservative” usually means “slower, more restricted, more hedged.”

Why “It’s Just Paperwork” Is a Lie

Here’s the part that should actually worry you if you’re a European ChatGPT user rather than a European regulator.

Laureline Lemoine, a senior associate at the policy consultancy AWO, put it plainly in earlier reporting on this exact designation process: compliance, if not planned well in advance, “might lead to a slower deployment of new features in Europe.” Natali Helberger, an information law professor at the University of Amsterdam, went further — VLOSE status “will intensify regulatory oversight and expand the focus of scrutiny to a broader set of issues” beyond what even the EU AI Act already covers.

Translate that out of policy-speak: every new capability OpenAI wants to ship now has to clear an internal risk-assessment gate before it can touch European users, because shipping first and assessing later isn’t an option anymore — a “critical impact” feature triggers the assessment obligation before deployment, not after. That’s a fundamentally different development cadence than “release the model, iterate based on what breaks.” And when the safest way to avoid a systemic-risk investigation is to simply not ship the capability that might trigger one, guess which option a legal department recommends nine times out of ten.

This is not a new discovery. It’s the exact mechanism that’s already hollowed out the EU release of two other companies’ flagship AI products. Let’s look at them, because the pattern is the actual story here — not any single designation.

Exhibit A: Google’s Vanishing AI

Google’s approach to EU AI rollout has been a masterclass in “ship now, litigate later,” and even that strategy hasn’t spared European users from delay.

When Google rolled out Gemini-powered AI Overviews — multi-step reasoning baked directly into search — the feature reportedly wasn’t immediately available in Europe, with some users waiting roughly half a year for access that the rest of the world already had. Go back further and you’ll find Google’s original Bard/Gemini launch delayed in the EU in 2023 over unresolved privacy questions from the Irish Data Protection Commission.

Then there’s the current fight: in January 2026, the Commission opened parallel Digital Markets Act proceedings against Google under Article 6(7) — the interoperability clause — arguing that Gemini’s special access to Android system features (voice activation, always-on hotword detection, deep OS-level integration) unfairly locks out rival AI assistants like ChatGPT and Claude. In July 2026, the Commission formally ordered Google to open eleven specific Android features to competitors on “equally effective” terms. Some of that has to ship by August 2027. One feature — concurrent always-on wake-word detection — isn’t required until August 2028.

Read that timeline again. Google announced Gemini’s Android integration, shipped it, got investigated, got ordered to fix it, and the final compliance deadline lands two years after the order. That’s not friction. That’s a multi-year regulatory drag coefficient built directly into how fast AI features can reach European phones.

And this isn’t even Google’s first rodeo with “compliance makes the product worse, on purpose.” Since January 2024, EU users searching Google for a location no longer get the clickable map and direct link that appears everywhere else in the world — Google stripped it out to comply with the DMA’s Article 6(5) ban on self-preferencing, since surfacing its own Maps product inline with search results counted as favoring itself over rival mapping services. The catch: peer-reviewed research comparing EU and non-EU search behavior found that map-related searches jumped by roughly 21% after the change, while traffic to competing mapping services barely moved — users didn’t switch to alternatives, they just took an extra click to get back to the same Google Maps they wanted in the first place. The remedy made the product worse for everyone and didn’t meaningfully help a single competitor. If that’s the track record on something as simple as a map widget, it’s not exactly reassuring collateral for how AI feature compliance is going to go.

Exhibit B: Apple’s Frozen Siri

If Google’s strategy is “ask forgiveness,” Apple’s is “ask permission and get told no anyway” — which makes its situation the more damning data point.

At WWDC 2026, Apple unveiled Siri AI — a genuinely rebuilt assistant powered by Apple Intelligence, with deeper context awareness, richer conversation, and tighter app integration. Then came the asterisk: it will not ship in the EU with iOS 27 or iPadOS 27. Not delayed by a few weeks. Indefinite, with no announced timeline, across all 27 member states.

Apple didn’t just get caught out — it tried to solve the problem in advance. The company proposed a “Trusted System Agent,” an intermediary security layer designed to let rival assistants access the same underlying device capabilities as Siri AI without tearing open Apple’s privacy architecture (on-device processing plus Private Cloud Compute). Apple asked for an 18-month phased rollout to build and stress-test it. The Commission rejected the proposal and the timeline in full.

Craig Federighi, Apple’s SVP of Software Engineering, called the outcome disappointing in the newsroom announcement. Marketing chief Greg Joswiak went considerably further, telling Euractiv this was the “most serious negative outcome yet” the DMA has produced. Because watchOS 27’s Siri AI functionality depends on a paired iPhone running the feature, Apple Watch owners in the EU lose it too — a regulatory decision about phones cascading down to wrists.

And here’s the detail that should sting the most if you’re an EU Mac or Vision Pro owner: those platforms are getting the new Siri AI. Apple’s DMA “gatekeeper” designation applies specifically to iOS and iPadOS as core platform services — so the exact same AI, built by the exact same company, is legally fine on one device and legally radioactive on another. That’s not a safety distinction. That’s a jurisdictional accident of how gatekeeper status gets defined, and it’s now dictating which of your own devices gets to be smart.

This isn’t even Apple’s first rodeo here — Apple Intelligence itself, along with iPhone Mirroring and SharePlay Screen Sharing, was delayed in the EU back in 2024 for the exact same DMA reasons.

The Pattern Nobody’s Supposed to Say Out Loud

Three unrelated American companies. Three different flagship AI products. Three different legal strategies — Apple negotiated first and got refused, Google shipped first and is now retrofitting compliance under order, OpenAI is walking straight into VLOSE obligations it can’t route around because it simply has too many users to hide from the threshold.

Same outcome, every time: European users get a later, more constrained, more heavily instrumented version of whatever the rest of the world already has — assuming they get it at all.

This is the actual argument, and it’s bigger than any single designation: the EU’s regulatory posture is quietly manufacturing a two-tier AI world, and Europe is the tier that waits. Not because any individual rule is unreasonable in isolation — risk assessments and interoperability mandates are defensible ideas on paper — but because the cumulative, compounding effect of stacking DSA obligations on top of DMA obligations on top of AI Act obligations is a compliance surface so large that “just don’t ship it in the EU yet” becomes the economically rational default for every major AI lab, every single time.

And that compounds in ways that don’t show up in a press release. Products improve through iteration — real usage, real feedback, real edge cases surfacing in the wild. A market that systematically receives features six, twelve, or twenty-four months late doesn’t just get a worse product today; it generates less of the usage data and developer ecosystem that make next year’s version better, which widens the gap again, which repeats. Layer onto that the fact that the EU still doesn’t have a homegrown frontier AI lab operating anywhere near the scale of OpenAI, Google DeepMind, or Anthropic — Mistral is a genuinely good effort and it is not remotely in the same weight class — and you get a bloc that is simultaneously slow-walking access to the frontier and hasn’t built its own frontier to compensate. That’s not a temporary inconvenience. That’s a structural, self-inflicted gap that gets wider with every product cycle, and there is no compounding interest schedule where “wider every cycle” resolves itself on its own.

You don’t have to take a tech blogger’s word for the trajectory here — you can take the European Commission’s own commissioned diagnosis. Mario Draghi’s 2024 report on European competitiveness, written at the Commission’s request, is blunt about where this leads: it identifies “the key driver of the rising productivity gap between the EU and the US” as digital technology specifically, and states plainly that “Europe’s position in the advanced technologies that will drive future growth is declining.” Draghi’s own numbers are the damning part — the EU’s share of global tech revenue fell from 22% to 18% between 2003 and 2023, while the US’s share climbed from 30% to 38% over the same period. His explanation for why isn’t mysterious: he points directly at regulatory density, noting the EU now runs “around 100 tech-focused laws and over 270 regulators active in digital networks across all Member States,” and warns that this regulatory stance “hampers innovation” precisely because scaling obligations hit hardest exactly when a company or a product is young and still finding its footing.

The Commission spent its own money finding out that its regulatory posture is a primary cause of the gap it’s worried about. Then, roughly two years later, it responded by adding another compliance tier on top of ChatGPT. If you’re looking for evidence that the diagnosis and the treatment plan are operating in two completely different rooms, this is it.

The Case for the Other Side

The Commission’s own framing is worth taking seriously: designation “is not a finding of wrongdoing,” and the DSA’s stated goal is disclosure and accountability, not banning capability outright. Google’s decision to ship Gemini in the EU first and deal with compliance after is itself evidence that the rules don’t force companies into paralysis — Google judged the regulatory risk worth taking, and European Android users got Gemini access immediately as a result. That’s a counterexample to the idea that EU rules are an automatic feature-killer; sometimes they’re just a lagging bill that arrives later.

There’s also a genuine, unresolved technical tension buried in this story that critics of the EU rarely mention: an independent analysis flagged by the R Street Institute pointed out that the DMA’s interoperability mandate — forcing Google and Apple to open deep system access to rival AI assistants — sits in direct friction with the EU’s own Cyber Resilience Act, which requires companies to minimize exactly that kind of expanded attack surface. Apple’s privacy objection to opening Siri’s data hooks isn’t obviously bad-faith stalling; it might be a real security trade-off that the EU’s own regulatory apparatus hasn’t fully reconciled with itself yet.

And the enforcement record so far is narrower than “the EU bans AI” — X’s €120 million fine was for a specific, documented transparency failure, not a blanket penalty for existing. If regulators are targeting concrete violations rather than punishing scale for its own sake, that’s a materially different story than pure protectionism.

None of that changes the observed pattern, though. Even granting every one of those points in good faith, the empirical record across three separate companies over three years is identical: European users get less, later, with no clean release date, while everyone else gets the frontier version on schedule. Good intentions and unresolved legal tensions explain why this keeps happening. They don’t change that it keeps happening.

The Bottom Line

Somewhere in Brussels, someone genuinely believes that forcing tech giants through this obstacle course protects European consumers, European competition, and European democratic institutions from unchecked AI power. That’s a legitimate goal, and I’m not going to pretend otherwise.

But three years into this experiment, look at what’s actually been delivered on the other side of the ledger: no EU-grown frontier AI lab has emerged to fill the gap. No European “Gemini killer” or “ChatGPT alternative” has capitalized on the breathing room these delays supposedly created. What has materialized is a growing list of capabilities — smarter assistants, deeper search, better on-device intelligence — that exist everywhere except the EU, arriving months or years late if they arrive at all, while the compliance machinery required to unlock them keeps getting heavier with each new designation.

If the goal was protection, it’s fair to ask: protection of what, delivered how, measured against which benefit — because right now the only measurable outcome is delay. The gap between “what AI can do” and “what AI can do if you live in the EU” isn’t closing. It’s compounding, product cycle after product cycle, and nobody in Brussels has yet pointed to the tangible upside that’s supposed to be worth the wait.

AI enthusiast.
Communication specialist.

Newsletter Signup

    Socials
    Say Hello

    remus@radoiu.com

    Remus Rădoiu © 2026. All Rights Reserved.

    Go to Top

    This website uses cookies. By continuing to use this site, you accept our use of cookies.  Learn more