Skip to content

September 1, 2026 · Issue 16 · 5 min read

Brussels regulated ChatGPT as a search engine, and the AI Act had nothing to do with it

The European Commission designated ChatGPT a Very Large Online Search Engine(opens in a new tab) under the Digital Services Act on August 31, and designated Reddit and Roblox as Very Large Online Platforms the same day. OpenAI has four months from notification, running into January 2027, to produce systemic risk assessments, submit to independent audits, meet algorithmic transparency duties, and open a data access path for vetted researchers. Euronews reports(opens in a new tab) roughly 159 million average monthly EU users against a designation threshold of 45 million.

Read which statute landed. It was not the AI Act. The DSA is a 2022 platform law written for social networks and search engines, and the Commission reached ChatGPT through its live web retrieval feature and its user count, not through anything about the model underneath. An AI vendor risk assessment scoped to the AI Act alone is now scoped to one of at least two European regimes governing the same product, and the second one arrived keyed on a product feature that any assistant with web search could trip.

The obligations land on OpenAI rather than on its enterprise customers, which is where most budget owners will stop reading. The part worth carrying further is that a designated service is a supervised service. The Commission now has a direct line to OpenAI, and a General Counsel should know that escalation path exists before a regulator uses it. Audit and transparency duties also change the product: an EU-facing ChatGPT operating under systemic risk review is a different thing to have inside a workflow than the one procurement evaluated last year.

The security news of the same week is the same lesson in a different layer. Anthropic disclosed that commodity infostealers were taking active Claude session cookies from infected machines, including Vidar, LummaC2, StealC, RedLine and Acreed on Windows and Atomic Stealer on macOS. Help Net Security reports(opens in a new tab) that because the theft replays an already authenticated session, it bypasses two factor authentication and single sign on entirely. Anthropic revoked sessions, stripped saved payment methods and refunded charges(opens in a new tab). Nothing in that attack chain is AI specific. It is browser cookie hygiene, running against a vendor that happens to meter usage in money.

Third example, same week. State Farm's outside counsel admitted seven fabricated case citations across eight filings(opens in a new tab) in a Los Angeles fire claim, after the attorney believed a tool called Irys was running a cite check through her firm's Westlaw subscription. That is a procurement and training failure wearing a model failure's clothing. Three exposures in five days, and a model evaluation would have caught none of them. The inventory that matters is not which models are approved. It is which statutes reach each deployed AI product, which sessions can be replayed, and which tools staff believe are doing verification work that nobody bought.

Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.

Most AI risk registers are organized by model. The three things that went wrong last week were organized by everything else.

The Commission did not designate ChatGPT because it is a frontier system. It designated ChatGPT because the product searches the web and 159 million people in the EU use it every month. That is a feature test and a headcount test, both of which sit in a 2022 statute drafted before the current generation of assistants existed. A compliance program built around the AI Act's risk tiers would not have flagged either input.

The Anthropic incident is the same shape. No model was jailbroken, no guardrail was talked around. Commodity malware copied browser session cookies, and a valid session is a valid session no matter how strong the login was. Every enterprise that federated its AI assistant into single sign on and considered identity handled has an assumption to recheck, because the attack skipped the login entirely.

The State Farm filings are the least technical and the most instructive. An attorney used an AI research tool she believed was covered by her firm's Westlaw subscription and believed was running a citation check. It was neither. That gap between what staff think a tool verifies and what it actually verifies is not visible in a model evaluation, a vendor security questionnaire, or a usage dashboard. It shows up in a court filing.

Three questions are answerable this month. Which deployed AI products would cross a platform law threshold on user count or a retrieval feature. How long a stolen session stays valid against each AI vendor in use, and who can revoke it on a Friday night. And which AI tools staff believe are checking their work.

None of these are model questions. All three are cheaper to answer now than to discover the way State Farm did.

Also worth knowing