BlogFindings
ChatGPT SEO: the EU has designated ChatGPT a very large online search engine
The European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act on 31 August 2026. The obligations that follow are about systemic risk, audits and public reports, and the first of them lands four months after notification. None of them tells a site owner why one page was cited and another was not.
Lantad measured nothing to produce this post. No scan was run for it, no crawler was observed, no page was fetched or scored, and every figure below comes either from the regulation, from the Commission's announcement, or from a measurement this blog already published on a date it names. What this site can add is the part it works on daily: what a legal classification does and does not change about whether an AI crawler can reach your pages, and which of the documents the Digital Services Act now compels will ever reach a person trying to get a page cited. The short version is that the designation is real, the paperwork is real, and almost none of it is addressed to you.
In short
- The European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act on 31 August 2026, alongside Reddit and Roblox as Very Large Online Platforms, and its announcement states the services declared they reach at least 45 million average monthly users in the EU.
- ChatGPT SEO is not changed by the designation itself: Article 33(6) of Regulation (EU) 2022/2065 applies the additional obligations only from four months after notification, and none of those obligations produces a per-site diagnostic.
- Article 3(j) of the DSA defines an online search engine by what it accepts and what it returns, being queries over in principle all websites and results in any format, and it says nothing at all about how the results are produced.
- Article 42(4) requires a designated provider to make the risk assessment report, the mitigation measures and the audit report publicly available at the latest three months after it receives each audit report, which is the first dated public document about ChatGPT's algorithmic systems that anybody can plan around.
- Lantad measured on 5 September 2026 that of 29 sites serving a parseable robots.txt, 21 named none of GPTBot, OAI-SearchBot or ChatGPT-User, so on those sites the verdict for every OpenAI crawler came from the wildcard group and was never a decision anybody made about ChatGPT.
| Service | Category | Threshold the Commission cites | Additional obligations apply |
|---|---|---|---|
| ChatGPT | Very Large Online Search Engine | At least 45 million average monthly users in the EU, declared by the service | Four months after notification, Article 33(6) |
| Very Large Online Platform | At least 45 million average monthly users in the EU, declared by the service | Four months after notification, Article 33(6) | |
| Roblox | Very Large Online Platform | At least 45 million average monthly users in the EU, declared by the service | Four months after notification, Article 33(6) |
What the Commission decided on 31 August 2026
The announcement is short and it does two things. It names the category each service falls into, and it states the basis: "These services declared that they reach at least 45 million average monthly users in the EU and thus meet the threshold for designation." That number is not an estimate the Commission produced. Article 24(2) of the regulation requires every provider to publish, in a publicly available section of its own interface and at least once every six months, the average monthly active recipients of the service in the Union over the past six months. Designation runs off that published figure.
Where 45 million comes from is worth knowing, because it is the whole test. Recital 76 explains that significant reach "should be considered to exist where such number exceeds an operational threshold set at 45 million, that is, a number equivalent to 10 % of the Union population", and Article 33(1) puts the same number in the operative text. Nothing in either provision asks whether a service is good, popular in the right way, or a search engine in the sense a marketer means. It asks how many people in the Union use it.
The announcement lists the obligations in one sentence, being "assessing and mitigating the systemic risks stemming from their service and algorithmic systems related to the dissemination of illegal content, the negative effects on minors, users' physical and mental well-being, fundamental rights, electoral processes and public security". Article 33(6) then sets the clock: the Commission notifies the provider, publishes the list of designated services in the Official Journal, and the obligations "shall apply, or cease to apply, to the very large online platforms and very large online search engines concerned from four months after the notification to the provider concerned". The Commission's page does not print a per-service user count, and OpenAI's own disclosure page under Article 24(2) refused a request from this sandbox with HTTP 403 on 6 September 2026, so no such figure is printed here.
Flow: Provider publishes EU recipient count, Art 24(2) to Commission designates, Art 33(4); Commission designates, Art 33(4) to Notification and Official Journal listing, Art 33(6); Notification and Official Journal listing, Art 33(6) (four months) to Four months later, Section 5 obligations apply; Four months later, Section 5 obligations apply to Annual risk assessment, Art 34; Four months later, Section 5 obligations apply to Annual independent audit, Art 37; Annual risk assessment, Art 34 to Public reports within three months, Art 42(4); Annual independent audit, Art 37 to Public reports within three months, Art 42(4).
Does ChatGPT SEO change now that ChatGPT is a search engine in EU law?
Not in any way you can act on this month, and the reason is in the definition. Article 3(j) defines an online search engine as "an intermediary service that allows users to input queries in order to perform searches of, in principle, all websites, or all websites in a particular language, on the basis of a query on any subject in the form of a keyword, voice request, phrase or other input, and returns results in any format in which information related to the requested content can be found".
Read that as an engineer rather than a lawyer. Every clause in it describes an interface: what goes in, how wide the corpus is, what comes back. The phrase "in any format" is doing the work that makes a chat answer qualify. There is no clause about ranking, no clause about indexing, no clause about how a result is chosen, and therefore nothing in the definition that a person practising generative engine optimization or answer engine optimization could use. The classification tells you that the law will now treat a chat product's live retrieval as a search function. It does not tell you one thing about the retrieval.
This matters because the classification argument has been used as a proxy for a different question, which is whether the tactics that earn a blue link also earn a citation. That question has partial published answers already and none of them moved on 31 August. A controlled experiment on document structure raised citation rate across six generative engines by 7.8 points rather than the 17.3 often quoted, and the same divergence between crawling and citation is what separates GEO from SEO in practice. If you came to this looking for a change in what to publish, there is not one here. If you came looking for when somebody will have to explain how ChatGPT picks sources, keep reading, because there is a date.
What the definition requires
- An intermediary service
- Users input queries
- Searches of, in principle, all websites
- A query on any subject
- Keyword, voice request, phrase or other input
- Returns results in any format
What the definition never mentions
- How results are ranked
- Whether an index exists
- Which sources are eligible
- How a citation is chosen
- Any duty to explain a result to a publisher
- Any signal a site can send
The one obligation that touches how results get chosen
There is exactly one thread in the regulation that runs anywhere near ranking, and it is worth reading precisely rather than hopefully. Article 27(1) requires providers "that use recommender systems" to set out in their terms and conditions, "in plain and intelligible language, the main parameters used in their recommender systems, as well as any options for the recipients of the service to modify or influence those main parameters". Article 27(2) says those parameters shall explain why certain information is suggested, and must include at least "the criteria which are most significant in determining the information suggested to the recipient of the service" and "the reasons for the relative importance of those parameters".
Article 27 by its own words addresses providers of online platforms, which is a different defined category from an online search engine. What reaches a designated search engine is Article 38, which opens "In addition to the requirements set out in Article 27" and then requires providers of very large online platforms and of very large online search engines that use recommender systems to "provide at least one option for each of their recommender systems which is not based on profiling". So the non-profiling option is unambiguous for a VLOSE, and the main parameters disclosure reaches it by that cross reference rather than by Article 27 standing alone.
Now the disappointing part. What Article 27 produces is a passage of prose in a terms and conditions document, written at the level of "the criteria which are most significant". It is not a ranking factor list, not a per-query explanation, and not a report about your site. The nearest working comparison is what the search engines already ship voluntarily: Microsoft's Bing Webmaster Tools names the grounding query behind a Copilot citation while Google's equivalent report names no query at all. A terms and conditions paragraph is considerably less than either. Treat it as context for how citation actually gets decided, not as a feed.
-
A ranking factor listNot in the regulation Article 27(2) requires the most significant criteria and the reasons for their relative importance, stated in terms and conditions in plain language. -
A per-site reportNot in the regulation No article in Section 5 requires any output addressed to an individual publisher or website owner. -
A non-profiling optionRequired Article 38 requires at least one option for each recommender system that is not based on profiling, for very large online search engines as well as platforms. -
A public audit reportRequired, on a clock Article 42(4) requires publication at the latest three months after receipt of each audit report under Article 37(4).
Who gets to read what the Digital Services Act produces
The useful way to read Section 5 of the regulation is not obligation by obligation but audience by audience. Each duty produces a document, and each document has a reader, and for most of them that reader is not the public and is definitely not a site owner. Article 34 requires an annual risk assessment covering systemic risks arising from "the design or functioning of their service and its related systems, including algorithmic systems". Article 37 requires independent audits, "at their own expense and at least once a year", assessing compliance with the obligations in Chapter III. Article 40(1) gives the Digital Services Coordinator of establishment and the Commission access, on reasoned request, to data necessary to monitor compliance.
Two of these do surface publicly, and they are the ones to diarise. Article 42(1) requires a designated provider to publish the transparency reports referred to in Article 15 within two months of the date of application and at least every six months thereafter. Article 42(4) goes further and requires the provider to make publicly available, at the latest three months after it receives each audit report, the risk assessment report, the specific mitigation measures, the audit report itself, and the audit implementation report. That is a dated, compulsory, public description of how a service assesses its own algorithmic systems, and it is the single most substantive thing this designation will produce for anyone outside the Commission.
One further artefact is machine readable by requirement rather than by favour, and it is the only one in the list that is. Article 39(1) obliges a designated provider that presents advertisements on its interface to compile a repository and make it publicly available "through a searchable and reliable tool that allows multicriteria queries and through application programming interfaces". Article 42(3) adds a smaller but useful granularity to the reports, requiring the average monthly recipients of the service to be broken out for each Member State rather than given as one Union figure. Neither is about organic citation, and both are more queryable than anything the ranking side of the regulation produces.
Enforcement sits behind all of it. Article 74(1) allows the Commission to impose fines "not exceeding 6 % of its total worldwide annual turnover in the preceding financial year" on the provider of a designated service that infringes the relevant provisions. That is the reason these documents will exist. It is not a reason to expect them to be about you. Our own note on why a scanner withholds a grade makes the same distinction in a much smaller domain: a document that states a method is not a measurement of your page.
| Article | What it requires | Who receives the output | Public |
|---|---|---|---|
| 24(2) | Average monthly active recipients in the Union, every six months | Anyone, on the provider's own interface | Yes |
| 34 | Annual systemic risk assessment, including algorithmic systems | The provider, then via Article 42(4) | Via 42(4) |
| 37 | Independent audit at the provider's expense, at least yearly | The auditor, then via Article 42(4) | Via 42(4) |
| 38 | At least one recommender option not based on profiling | Recipients of the service | Yes |
| 39 | Advertisement repository, searchable, with an API | Anyone, where ads are presented | Yes |
| 40(1) | Data access on reasoned request | Commission and Digital Services Coordinator | No |
| 42(1) | Transparency reports at least every six months | Anyone | Yes |
| 42(4) | Risk assessment, mitigations and audit reports within three months | Anyone | Yes |
| 74(1) | Fines up to 6 % of total worldwide annual turnover | The provider | Decisions published |
What a site owner can still measure this week
The layer a regulator has just taken an interest in is not the layer you control. The one you do control is the request: whether a named crawler is permitted a path, and what the response holds before any script runs. That is governed by RFC 9309, the Robots Exclusion Protocol, published on the Standards Track in September 2022, and by the bots OpenAI documents, which this blog read at source on 5 September 2026 and found naming four tokens, being GPTBot, OAI-SearchBot, ChatGPT-User and OAI-AdsBot.
Those tokens do not behave alike, and the difference is measurable rather than theoretical. Lantad requested robots.txt from 40 well known hostnames on 5 September 2026 and evaluated the site root for three of those tokens: across the 29 hosts that served a parseable file, the root was allowed for GPTBot on 23, for OAI-SearchBot on 27 and for ChatGPT-User on 27, and on 4 of the 29 the three agents got different answers, always with GPTBot refused while the search bot was allowed. On the same day, 21 of those 29 files named none of the three tokens at all, so the verdict came from the wildcard group. A separate reading of six sites found not one AI crawler token named in any of their files.
Two cautions carry over from that work and neither is softened by a designation. A robots.txt verdict is a statement of permission and observes no request, so it establishes nothing about whether a crawler came or obeyed, which is why a user agent is a claim rather than an identity and why only 6 of 15 registry tokens publish a User-Agent string you can match literally. And permission is only the first of two layers that decide whether AI can read your site: an allowed page can still return nothing a crawler reads.
If you want to check yours rather than read about it, the robots.txt tester evaluates a file per crawler token, what GPTBot sees shows the raw response rather than the rendered one, the AI crawler reference lists the tokens each vendor documents, and how ChatGPT citation works in practice covers the surface this designation does not touch. The scoring method states what each of those checks is worth and why.
- Whether robots.txt still governs the fetch Unchanged. RFC 9309 is the standard, and nothing in Regulation (EU) 2022/2065 writes, reads or overrides a robots.txt file.
- Whether the OpenAI tokens differ from each other Measured on 5 September 2026: on 4 of 29 sites GPTBot was refused the root while OAI-SearchBot was allowed.
- Whether most sites have decided anything about ChatGPT Measured on 5 September 2026: 21 of 29 parseable files named none of GPTBot, OAI-SearchBot or ChatGPT-User, so the wildcard group decided it.
- Whether you will learn why a page was cited No article in Section 5 produces an output addressed to a publisher. Article 27(2) stops at the most significant criteria, in terms and conditions.
- Whether a public document about the algorithmic systems arrives Article 42(4) requires publication within three months of receipt of each audit report, on the clock Article 33(6) starts.
Lantad
Published .
On 31 August 2026 the European Commission published a decision that settles, for one jurisdiction and one narrow purpose, an argument the search trade has been having for two years. Its announcement reads: "The Commission has designated ChatGPT as a Very Large Online Search Engine (VLOSE), as well as Reddit and Roblox as Very Large Online Platforms (VLOPs), under the Digital Services Act (DSA)." The instrument being applied is Regulation (EU) 2022/2065. The announcement itself sits at digital-strategy.ec.europa.eu/en/news/commission-designates-chatgpt-reddit-roblox-under-digital-services-act, on a host this site has not registered for outbound links, so that address is printed here as plain text and you can open it yourself.
Common questions
What does it mean that the EU designated ChatGPT a Very Large Online Search Engine?
It means the European Commission decided on 31 August 2026 that ChatGPT meets the threshold in Article 33(1) of Regulation (EU) 2022/2065, being at least 45 million average monthly active recipients in the Union, and that the additional obligations in Section 5 of Chapter III now apply to it. Under Article 33(6) those obligations apply from four months after the Commission notifies the provider. The category matters because the regulation treats a search engine and an online platform as different things, and Reddit and Roblox were designated as platforms in the same announcement.
Does the designation change how ChatGPT chooses which sites to cite?
Nothing in the regulation requires a change to how results are chosen. Article 3(j) defines a search engine by its inputs and outputs and says nothing about ranking. The closest provision is Article 38, which requires at least one recommender option not based on profiling and refers back to the main parameters disclosure in Article 27. That disclosure is prose in a terms and conditions document naming the most significant criteria, not a ranking factor list and not a report about any individual site.
When will there be a public document about how ChatGPT works?
Article 42(1) requires transparency reports within two months of the date of application and at least every six months after that. Article 42(4) requires the provider to publish the risk assessment report, the mitigation measures, the audit report and the audit implementation report at the latest three months after it receives each audit report. The date of application is four months after notification under Article 33(6), and the Commission did not publish the notification date in its announcement.
Should I change my robots.txt because of this?
No. The regulation does not write, read or override robots.txt, and RFC 9309 remains the standard that governs whether a named crawler may fetch a path. What is worth checking is whether your file names the OpenAI tokens at all: Lantad measured on 5 September 2026 that 21 of 29 sites serving a parseable file named none of GPTBot, OAI-SearchBot or ChatGPT-User, so the wildcard group was deciding for all three.
See what AI can read on your site
Run a free scan and get a graded report of exactly what AI crawlers can and cannot read, with ranked fixes.