
On 31 August, the European Commission did something no regulator had done before: it looked at a generative AI chatbot and decided it was, legally speaking, a search engine. ChatGPT was designated a “Very Large Online Search Engine” under the EU’s Digital Services Act (DSA), placing OpenAI’s flagship product in the same supervisory tier as Google Search, alongside Reddit and Roblox, both newly tagged as Very Large Online Platforms.
The trigger was scale: ChatGPT’s search-enabled function reported roughly 159 million average monthly users across the EU in the six months to March, more than three times the 45-million threshold that pulls a service into the DSA’s strictest bracket.
Also Read: OpenAI calls for ‘AI infrastructure revolution’ to reboot Japan’s growth
OpenAI now has until the end of November to run systemic risk assessments covering everything from minor safety to electoral integrity, submit to independent audits, and open its systems to vetted researchers. Until last week, these obligations only applied to platforms like Instagram or Google Search, not to a chatbot that writes original text rather than indexing web pages.
Most of the commentary on this has understandably focused on what it means for OpenAI, and for Ireland’s Coimisiún na Meán, which now supervises an outsized share of Big Tech‘s EU compliance. But the more interesting question for readers is what happens next: because the EU rarely regulates in isolation, and Southeast Asia has a well-worn habit of importing Brussels’ homework a cycle or two later.
The Brussels effect isn’t hypothetical here; it already happened once
Southeast Asia has run this playbook before, almost to the letter. When the EU’s GDPR came into force in 2018, it didn’t just reshape how European companies handled data but it became the reference architecture for an entire generation of Asian privacy law.
Indonesia’s Personal Data Protection Law and Vietnam’s earlier data-protection decrees both borrowed GDPR’s core scaffolding: consent requirements, data-subject rights, extraterritorial reach, the works. Regional regulators didn’t hide the influence; they built on it, because writing a data law from scratch is slower and riskier than adapting one that’s already survived its first constitutional challenges.
AI regulation is following the same script, faster. Vietnam passed the region’s first standalone AI law in December 2025, effective this March, built explicitly around the EU AI Act’s four-tier risk classification — unacceptable, high, medium, low — with Vietnamese characteristics layered on top, including a requirement that foreign providers of high-risk AI systems appoint a local contact point.
Indonesia’s draft Presidential Regulation on AI, delayed from late 2025 into early 2026, follows the same EU-style risk-based logic. Thailand’s ETDA is still consolidating its draft AI principles after public consultation, with no firm timeline, but the direction of travel is identical.
A recent ISEAS analysis put it plainly: the EU’s risk-based approach has become the most widely adapted template for AI governance across the bloc, more influential than either the OECD’s principles or the innovation-first models coming out of South Korea and Japan.
Also Read: ‘AI is a race for innovation; regulation will only develop effectively once winners are announced’
So when the European Commission draws a bright line (45 million monthly users, and you’re now a “very large” service subject to search-engine-grade scrutiny), Southeast Asian lawmakers aren’t watching from a distance. They’re watching for the template.
The threshold is coming for the region, not just for OpenAI
Here’s the part that should worry SEA-based AI builders more than the Brussels decision itself: the user numbers that triggered this are no longer a Silicon Valley or European phenomenon. Indonesia is now ChatGPT’s fastest-growing Southeast Asian market, with adoption reportedly climbing by roughly 85 per cent over the past year. Thailand’s AI usage grew by more than a third over the same stretch.
None of the region’s markets have crossed a 45-million-user threshold yet, but ASEAN’s combined online population is large enough, and growing fast enough, that a Jakarta- or Hanoi-specific version of the DSA’s “very large” tier is not a fantasy. It’s a drafting decision waiting for a policy window.
And when that window opens, the compliance bill will not land evenly. A frontier lab like OpenAI or Anthropic can absorb a systemic risk assessment, an independent audit and a data-sharing regime as a cost of doing business in a market it already dominates. A Southeast Asian AI startup that are building on top of a foundation model, serving a regional language, running on a fraction of the balance sheet cannot. Vietnam’s own AI Law already requires foreign high-risk AI providers to register a local point of contact; layer three or four separate national risk-assessment regimes on top of that, each modelled on Brussels but tuned to local political sensitivities, and the compliance burden starts to look less like consumer protection and more like a moat that only the biggest players can clear.
Fragmentation, not regulation, is the real risk
This is the trap SEA regulators need to see coming. Copying the EU’s risk-based logic is not, on its own, a bad instinct; the alternative, no rules at all until something goes wrong, is worse, and the region’s own AI ethics and human-rights advocates have long argued that guardrails are overdue.
The danger is in how the copying happens: five or six ASEAN member states independently translating the same Brussels template into slightly different national decrees, different thresholds, different definitions of “high-risk,” each with its own local-contact-point requirement and its own audit cadence.
Vietnam’s Ministry of Science and Technology has already had to walk back parts of its draft implementing decree after industry groups warned that a rushed, EU-AI-Act-style rollout creates exactly the kind of compliance bottlenecks Brussels and Seoul are still untangling for their own laws.
Also Read: Without governance, AI agents risk becoming enterprise chaos engines
A genuinely EU-inspired approach would borrow the other half of Brussels’s playbook: a single supervisory framework, applied consistently across a bloc, rather than a patchwork of national reinterpretations. ASEAN has the institutional muscle to attempt that, a regional AI governance framework that sets one risk taxonomy and one set of thresholds, rather than leaving Jakarta, Hanoi, Bangkok and Manila to each draft their own. Without it, the region risks importing the DSA’s compliance weight without importing the one thing that makes it manageable at scale: a single market’s worth of harmonised rules.
OpenAI has four months to prove it can meet Brussels’ new bar. Southeast Asia’s regulators have rather longer than that to decide whether they’re building one rulebook, or six.
The post The EU called ChatGPT a search engine. SEA’s AI startups should worry about what comes next appeared first on e27.
