ChatGPT under the DSA: what changes for European companies



ChatGPT DSA mainly changes risk management for European companies: more transparency expected, more regulatory oversight of OpenAI, but also possible effects on visibility, moderation, and workflows that depend on ChatGPT Search. For an executive, the issue is not only legal. It also affects project timelines, data, contracts, SEO, and service continuity.


ChatGPT under the DSA: what changes for European companies

ChatGPT DSA: what was decided in 2026

On August 31, 2026, the European Commission designated ChatGPT as a VLOSE, that is, a “very large online search engine,” under the Digital Services Act, European Regulation 2022/2065. On the same day, Reddit and Roblox were designated as very large online platforms, or VLOPs.

This designation is not symbolic. It applies to services that reach at least 45 million average monthly active users or recipients in the European Union. OpenAI reported approximately 159.1 million average monthly active recipients in the EU for ChatGPT Search, calculated over the six months ending March 31, 2026, with one useful clarification: this figure was provided for DSA complorance and should not be reused as a general commercial indicator.

The additional obligations apply four months after notification of the designation. For companies that rely on search-related uses in ChatGPT, this creates a period of change to monitor until the end of December 2026 or early January 2027, depending on the exact notification date.

What the DSA requires of OpenAI, and what it does not guarantee

The DSA does not transform ChatGPT into a European public service. It mainly imposes enhanced governance obligations on OpenAI: assessment of systemic risks, mitigation measures, annual independent audits, transporrency reports, regulated data access for researchers, and cooperation with the European Commission.

Direct supervision falls to the European Commission. For ChatGPT, the relevant national digital services coordinator is the Irish authority Coimisiún na Meán, because OpenAI Ireland Ltd is established in Ireland. The OpenAI contracts applicable to customers in the European Economic Area and Switzerland also designate OpenAI Ireland Ltd as the contracting party since the online services accord v.010126 of January 1, 2026.

For an SME, the key point is more down-to-earth: the DSA provides a better framework for the provider, but it does not relieve you of your own obligations. GDPR, confidentiality, intellectual property, human oversight, cybersecurity, and internal traceability remain your responsibility. A response produced or found via ChatGPT does not automatically become complorant just because the platforme is supervised.

Concrete impacts on your projects, your content, and your visibility

ChatGPT Search presents results using language models, automated systems, and signals such as user intent, relevance, and freshness. OpenAI also states that it uses citations in responses and sources in a sidebar, whose order may be influenced by third-party search providers.

This detail changes how you should think about your visibility. A site that ranks well on Google may be cited by ChatGPT, but it is not automatic. Pages must be accessible, clear, recent, structured, and consistent with search intent. Companies that already work on their organic search rankings therefore have a head start, provided they also integrate the logic of generative engines. The issue directly ties into thinking around a GEO strategy to appear in AI responses.

Read also  Working conditions for minors in France: age, laws and restrictions to be aware of

OpenAI specifies that some results may be blocked or not displayed, particularly in cases of illegal, harmful, or sensitive content: explicit content involving minors, exposed personal data, or instructions for violence, for example. This is reassuring in principle, but it also creates a risk of false positives. A legitimate page that is poorly worded or technically ambiguous may lose visibility in certain assisted search environments.

For e-commerce, the issue is even more concrete. OpenAI states that shopping results may use structured third-party metadata: price, product description, reviews. An incomplete product page, inconsistent Schema.org data, or poorly synchronized prices can affect how the offer appears. With that budget, it is often better to correct the technical foundation of the catalog than to fund a content campaign without reliable data.

The little-known trap: supplier complorance does not cover your use

Many teams confuse two issues. On one side, OpenAI must meet ChatGPT DSA obligations as a very large online search engine. On the other, your company must decide how it uses ChatGPT, with what data, under what rights, and with what controls.

OpenAI states that users can report illegal content via a form or directly in the product, in accordance with Article 16 of the DSA. Moderation combines automated technologies and human review: classifiers, reasoning models, digital fingerprint matching, blocklists, reports, and human verification. These mechanisms can lead to warnings, account restrictions, shared content restrictions, result blocking, GPT visibility controls, or forum moderation.

In the projects we lead, we often see the same blind spor: a business team adopts ChatGPT to speed up writing, support, or monitoring, then discovers too late that the internal rules have not kept up. Who validates a response before publication? Where are the sources recorded? What customer data is prohibited in prompts, that is, the instructions sent to the tool?

The 2026 OpenAI terms add another point of attention. For professional uses, ChatGPT Enterprise, the APIs, and developer services are governed by the Business Terms rather than the European consumer terms. The applicable policies may be those in effect at the time of the contract, the latest purchase order, the renewal, or the use of a new service. In other words, adding a feature can change the applicable framework.

Budget and timelines: what should a European company plan for?

The ChatGPT DSA designation does not, by itself, require you to launch a major project. However, it does justify a quick audit if ChatGPT is involved in exposed processes: content publishing, support customer, generating recommendations, product search, processing personal data, or decision support.

Here are some observable ballpark figures on the French market depending on providers and scope. They do not replace a quote, but they help frame a realistic budget before consulting.

Read also  Developing an iPhone application with Windows
Project Typical timeframe Estimated budget France When to do it
Mapping AI uses and data 1 to 2 weeks €1,500 to €5,000 before tax As soon as at least two teams are using ChatGPT
Legal review of contracts, GDPR, and internal policies 2 to 4 weeks €3,000 to €10,000 excl. tax Before customer-facing or sensitive use
SEO/GEO audit for visibility in ChatGPT Search 2 to 3 weeks 2 000 to 8 000 € excl. VAT If your acquisition depends on content or the catalog
Setting up a controlled workflow via API 4 to 10 weeks 8,000 to 40,000 € excl. VAT To industrialize a recurring business use case
Security plan and prompt logging 2 to 6 weeks 4,000 to 20,000 € excl. VAT If internal or customer data is circulating

Honestly, developing a complete internal layer around the API is only justified if the volume, sensitivity, or operational gain is real. For a small marketing team, usage rules, human validation, and good SEO hygiene are often enough. For a customer service department, a fintech, or a health platforme, it is a different story.

The hidden cost is not always the software. It is the time spent corriging content, finding sources, explaining an automated decision, or dealing with a data leak. On this point, a web security audit remains complementary, especially when AI workflows connect to accounts, formulaires, or customer areas. Scams exploiting fake technical pages also remind us why teams need to be trained on phishing risks, as in the case of fake Cloudflare screens used to deceive users.

Reasonable checklist before the end of 2026

The right approach is not to wait for OpenAI to publish all its operational adjustments. Precise public information on the business impact of the VLOSE designation remains limited: it mostly describes legal obligations, moderation, reporting channels, and contractual terms. Your room for action therefore lies in your own governance.

  • Identify actual uses : free accounts, ChatGPT Team or Enterprise, API, shared GPTs, extensions, automations connected to Slack, Notion, CRM, or back office.
  • Classify the data : public, internal, confidential, personal data within the meaning of the GDPR, trade secrets, client or HR information.
  • Review the contracts : contracting party, applicable policies, supported countries, usage limits, Dublin jurisdiction for EEA, Switzerland, and United Kingdom customers according to the service accord.
  • Prepare a plan B : export critical prompts, manual procedures, search alternative, secondary provider, or differently hosted model if the business depends fortely on AI.
  • Enhance your source content : structured product pages, clear legal notices, update dates, internal linking, mobile performance, and structured data.

The visibility aspect deserves specific attention. If ChatGPT Search becomes a gateway to your offers, the site's technical fundamentals come back to the forefront: speed, crawlability, mobile indexing, markup, and editorial consistency. A diagnostic like the one from mobile-first indexing remains relevant, even when the end user asks their question to an AI rather than a traditional search engine.

From the agency side, the instinct is to separate the workstreams: AI governance, security, SEO/GEO, then technical integration. Mixing everything into a single project leads to long meetings and few decisions. A simple matrix, with risks, owners, and deadlines, is often enough to bring the topic back under control.

Read also  Why creating an online e-commerce site is the best decision for your business

Vendor dependency: the real strategic issue

The DSA makes OpenAI more closely monitored, but not more predictable in the short term for each client. Terms of use, supported countries, message limits, token limits (units of text processed by the model), API throughput, or service restrictions may change. The OpenAI service accord also mentions the notion of a “Security Emergency” in the event of use likely to create a security risk, credible harm, infringement of third-party rights, or liability for OpenAI or a third party.

If your internal tool depends on ChatGPT search, a public GPT, or visibility in generated results, you need to think about reversibility. That does not mean abandoning ChatGPT. It means documenting prompts, keeping your sources, avoiding storing knowledge only in an assistant, and regularly testing an alternative.

The same reasoning already exists for hosting and web services: you can use OVHcloud, Cloudflare, or AWS, but you avoid making a critical function impossible to migrate. For certificates, protocols, or communication security, companies are also starting to anticipate long-term changes, for example with the progressive migration to post-quantum cryptography. AI follows this same logic of sustainable architecture.

Framing this type of project upstream avoids most unpleasant surprises: the wrong contract, overly sensitive data in prompts, excessive dependency, or an SEO promise that is poorly understood. An outside perspective often helps transform a regulatory constraint into a simple, costed, and workable action plan.

FAQ about ChatGPT, the DSA, and businesses

Does the ChatGPT DSA require my company to do anything?

Not directly in most cases. The DSA targets OpenAI here as a VLOSE, but your company still needs to review its uses, its data, its contracts, and its internal controls.

Will ChatGPT Search change for European users?

Changes are possible after the four-month period following the designation, particularly regarding transparency, moderation, or the presentation of results. Public operational details specific to enterprise clients remain limited at this stage.

Does the DSA make ChatGPT safer for personal data?

It renforces oversight of systemic risks, but it does not replace the GDPR. You must still avoid sending personal or confidential data without a legal basis, an appropriate contract, and internal rules.

Can content from my site be blocked in ChatGPT Search?

Yes, OpenAI indicates it may choose not to display certain sites or results containing illegal, harmful, or sensitive content. A review of your sensitive pages, your structured data, and your legal notices reduces the risk of misinterpretation.

Should you invest in GEO because of the DSA?

The DSA does not require GEO, but ChatGPT Search renforces the value of having reliable, structured, and citable content. For a company dependent on organic acquisition, this is a reasonable initiative to integrate into existing SEO.

English