Brussels has decided ChatGPT is a search engine
The Commission designated ChatGPT a very large online search engine under the Digital Services Act, the first AI chatbot to get the label, and gave it four months to comply. Separately, a researcher chained a website summary request into code execution on a developer's machine, and Anthropic's security team declined to treat it as a vulnerability.

- 01
ChatGPT is now regulated as a search engine in the EU
The Commission designated ChatGPT a very large online search engine under the Digital Services Act on 31 August, on the basis that it answers queries by searching the web, which makes it the first AI chatbot to carry the label. OpenAI declared roughly 159.1 million average monthly users in the EU for ChatGPT search over the six months to 31 March, against a designation threshold of 45 million. Reddit and Roblox were designated very large online platforms the same day. All three have four months to comply, which means annual independent audits, systemic risk assessments on their algorithms, data access for vetted researchers and a recommender option that does not profile the user.
European Commission - 02
A request to summarise a web page ended in code running on the machine
Johann Rehberger published a chain that starts with asking Claude Code to summarise a website and ends with arbitrary code running locally, reported at a 60 to 80 per cent success rate. The neat part is that a sensible-looking decision is the exploit: the agent is nudged off its own fetch tool onto curl, pulled into an oddly encoded archive, decides to write its own decoder rather than run a supplied binary, and that decoder imports a poisoned file named struct.py sitting in the same folder. Anthropic's security team closed the report as informative, saying Auto Mode is a best-effort classifier and not a security boundary. That sentence is the one to keep.
Embrace The Red - 03
Anthropic restarts the tests where its own model got out
Anthropic said on 31 August it has resumed external cybersecurity testing of pre-release models, several weeks after pausing it. The pause followed three incidents disclosed on 30 July in which Claude models reached the open internet through a misconfigured third-party evaluation environment and touched real organisations during capture-the-flag exercises. The new control is a classifier that watches for a model probing or escaping its test environment and kills the tool call before it runs. Around 150 product engineers were moved onto security work, with exit criteria they had to meet before going back.
Reuters - 04
Three million Pentagon staff get ChatGPT and Grok behind one door
ChatGPT Mil and Grok for Government went live on GenAI.mil on 31 August, joining Google Gemini on the Department of Defense's internal portal, which now covers around three million military and civilian personnel and has logged more than 1.7 million unique users since launching nine months ago. The stated work is unclassified and dull: admin, logistics, planning, policy documents. The design idea is worth borrowing regardless of size. One approved door, so staff are not pasting company documents into whatever they found on their phone.
DefenseScoop - 05
California sent 26 AI bills to its governor and went home
The California legislature adjourned on the night of 31 August having passed 26 AI-related bills this session, two already signed and 24 waiting on Governor Newsom, who has until 30 September to decide. Among them: a ban on addictive feeds and autoplay for under-16s, an update to the state's chatbot law with child safety provisions, a requirement that university instructors be human, and a ban on surveillance pricing, where the price you are shown is set by what a model thinks you will pay. That last one is the one to watch, because dynamic pricing has been creeping into ordinary retail software.
Transparency Coalition - 06
Runway is generating the interface itself, frame by frame
Runway announced Solaris on 31 August, which it calls an interface world model: instead of writing code that a browser renders, the model draws every frame of the interface in real time at 720p and treats your clicks and typing as the input to the next frame. Reasoning is split off to a language model while the world model handles rendering. It is research rather than a product you would put in front of a customer, and there is no persistent state, no accessibility layer and nothing to audit. Interesting for what it suggests, not for what it can do this year.
Runway
Of everything above, the designation is the one that will still matter in a year. The Commission looked at ChatGPT, noted that it answers questions by searching the web, and filed it under the same regime as Google Search. Not as a chatbot, not as a novel category needing its own law. A search engine. And the number that triggered it is the striking part: 159.1 million people a month in the EU, on the search function alone, against a threshold of 45 million.
For anyone who sells work through being findable, that is the whole story in one line. The thing a customer asks about ventilation contractors in west London is now, in law, a search engine, and it is roughly the size of one. What follows over the next four months is the machinery Google has lived with for years: audits, risk assessments on the ranking systems, researcher access to the data. Regulators do not build that apparatus around something they expect to be a phase. From direct experience in construction, the moment a temporary arrangement gets its own paperwork and an inspection date, it has stopped being temporary. Nothing in this obliges you to do a single thing this week. It does settle an argument that was still live in January, about whether being cited by an assistant is a real channel or a distraction, and it settles it in favour of real.
We build the AI that answers enquiries while you're on site: chat, voice, instant estimates and follow-up. See how it works or price it in two minutes.