Last updated: 9 August 2026.
If your business runs a customer-service or website chatbot, the compliance clock has already struck. Since 2 August 2026 — just over a week ago — the transparency obligations of Article 50 of the EU AI Act have been fully applicable across the European Union. These are the rules that directly govern chatbots, and they are no longer a future concern to pencil into next year’s roadmap. They are in force today.
This matters for every Dutch business that deploys a chatbot to serve customers, qualify leads, handle FAQs or triage support tickets. The good news: for most organisations the core duty is straightforward and inexpensive to meet. The bad news: many chatbots on Dutch websites still do not clearly tell users they are talking to a machine — and that is now a live compliance gap.
This guide explains what changed on 2 August 2026, how to work out whether your chatbot is limited-risk or high-risk, and gives you a concrete, actionable checklist to get compliant — including how the AI Act intersects with the GDPR, which you must not overlook.
What changed on 2 August 2026
The EU AI Act applies in phases. The phase that landed on 2 August 2026 brought the transparency obligations under Article 50 into effect. For chatbots, the essence is simple:
You must clearly inform users that they are interacting with an AI system, at the latest at the moment of the first interaction.
The disclosure must be clear, distinguishable and accessible. It cannot be buried in your terms of service, a cookie banner or a page footer. If a reasonable user could be misled into thinking they are chatting with a human, you are non-compliant. The only exception is where it is already obvious to a reasonably well-informed user that they are dealing with an AI — but you should not rely on that exception lightly.
There is a second, related deadline. Providers of generative AI systems already on the market have until 2 December 2026 to implement machine-readable marking (watermarking) of AI-generated or manipulated “synthetic” content, so that such output can be detected as artificially produced. If your chatbot generates text, images or audio that could pass for human-made content, this deadline is relevant to you or your vendor.
For context, earlier phases are also already in effect: the prohibited practices in Article 5 have applied since 2 February 2025, and the obligations for general-purpose AI (GPAI) models since 2 August 2025.
Is your chatbot limited-risk or high-risk?
The AI Act is risk-based. The obligations that apply to your chatbot depend on how it is used — not on how clever the underlying model is.
Most customer-service and website chatbots are limited-risk systems. Their principal obligation is the transparency duty described above: tell users they are interacting with AI. That is the headline requirement, and for a standard support or FAQ bot it may be close to the whole story.
A chatbot becomes high-risk when it is used to make or materially support consequential decisions about people, for example:
- employment decisions (recruitment, screening, promotion, termination);
- assessing creditworthiness or setting credit scores;
- determining eligibility for or access to essential public or private services (benefits, healthcare, insurance);
- other Annex III use cases affecting fundamental rights.
If your chatbot falls into any of these categories, far stricter duties apply — risk management, data governance, technical documentation, logging, human oversight and conformity assessment among them. Note that the high-risk (Annex III) obligations were postponed to 2 December 2027 by the AI Digital Omnibus, subject to final adoption — but you should design for them now if your use case is heading in that direction.
Quick self-assessment
Ask yourself three questions:
- Does my chatbot only inform, guide or route? (Answer FAQs, track orders, hand off to a human.) → Very likely limited-risk. Focus on transparency.
- Does it decide, score or gate access for individuals? (Approve/deny, rank candidates, assess risk.) → Likely high-risk. Seek legal advice before deployment.
- Does it generate synthetic content (text/images/audio that could look human-made)? → Watch the 2 December 2026 marking deadline.
The compliance checklist for Dutch businesses
Work through the following. Even limited-risk chatbots benefit from most of these controls, and they collectively demonstrate good faith to the regulator (in the Netherlands, supervision is coordinated via the AP and the RDI).
1. Clear AI disclosure at first interaction. Add an unambiguous notice before or at the opening of the conversation. Example wording:
- “Hi, I’m an AI assistant for [Company]. I can help with common questions and connect you to a colleague when needed.”
- “You are chatting with a virtual (AI) assistant, not a human agent.”
Place it in the chat window itself — the opening message and/or the header — not only in a linked policy.
2. Human oversight and escalation. Provide a clear, easy route to a human (“Talk to a colleague”). Ensure staff can review, override and take over conversations, especially where the bot touches complaints, contracts, payments or vulnerable users.
3. Logging and monitoring. Keep records of conversations and system behaviour so you can audit performance, investigate complaints and detect drift or misuse. Monitor for hallucinations and inappropriate outputs, and set thresholds for human review.
4. Vendor due diligence. Most Dutch businesses buy rather than build their chatbot. Get written confirmation from your provider that the system supports AI Act transparency, and — where relevant — synthetic-content marking by 2 December 2026. Clarify in the contract who is the provider and who is the deployer under the Act, and allocate responsibilities, warranties and indemnities accordingly.
5. AI literacy for staff. The AI Act expects organisations to ensure a sufficient level of AI literacy among those operating AI systems. Train the teams that manage, supervise or rely on the chatbot so they understand its limits, escalation rules and data-handling.
6. Documentation. Maintain a short internal record: what the chatbot does, its risk classification, the disclosure used, oversight measures, the vendor and the data it processes. This is your evidence of compliance.
The GDPR intersection — do not stop at the AI Act
A chatbot can be fully AI Act-compliant and still breach the GDPR. The two regimes run in parallel, and Dutch businesses must satisfy both.
- Lawful basis: identify a valid basis (usually legitimate interest or consent) for processing the personal data users type into the chat.
- Transparency notices: your privacy statement must explain that a chatbot processes personal data, for what purposes, how long it is retained and whether data feeds AI training.
- Data minimisation: do not collect more than you need; avoid prompting users to share special-category data.
- Data subject rights and international transfers: ensure access/erasure requests can be honoured, and check where your vendor hosts and processes data.
In practice, the AI Act’s transparency notice (“you are talking to AI”) and the GDPR’s transparency notice (“here is how we use your data”) are different obligations — you need both.
Penalties
Enforcement is not theoretical. The AI Act’s fine ceilings are severe:
- up to €35 million or 7% of total worldwide annual turnover for the most serious breaches (e.g. prohibited practices);
- up to €15 million or 3% for breaches of high-risk and most other obligations;
- up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information to authorities.
For a limited-risk chatbot, the immediate risk is more likely reputational and a compliance order — but a missing AI disclosure is a simple, visible failing that is easy for a regulator or complainant to spot.
Best practices beyond the minimum
- Reduce hallucinations with RAG. Retrieval-augmented generation grounds answers in your own verified content (product docs, policies, FAQs), improving accuracy and reducing the risk of the bot inventing legal, medical or financial claims.
- Consider ISO/IEC 42001. This AI management-system standard provides a recognised framework for governing AI responsibly and helps evidence accountability to customers and regulators.
- Set guardrails. Restrict the bot from giving definitive legal, tax or medical advice, and design fallbacks that route sensitive queries to humans.
- Review regularly. Re-check your classification whenever you expand the chatbot’s role — a support bot that starts screening job applicants has just become high-risk.
Frequently asked questions
Do the chatbot rules really apply now?
Yes. The Article 50 transparency obligations have been applicable since 2 August 2026.
Do I have to tell users my chatbot is AI?
Yes — clearly, and at the latest at first interaction, unless it is obvious to a reasonably informed user. Do not bury it in your terms.
Is my customer-service chatbot high-risk?
Usually not. It becomes high-risk only if used for consequential decisions such as employment, creditworthiness or access to essential services.
We use a third-party chatbot — are we still responsible?
Yes. As the deployer you carry obligations regardless of who built the tool. Confirm compliance contractually with your vendor.
Does compliance with the AI Act mean I comply with the GDPR?
No. They are separate regimes. You must satisfy both.
Get your chatbot compliant — talk to Law & More
The transparency rules are already live, and the synthetic-content marking deadline follows on 2 December 2026. If you are unsure whether your chatbot is limited- or high-risk, whether your disclosure wording holds up, or how the AI Act and GDPR fit together for your setup, the technology & privacy lawyers at Law & More can review your chatbot, classify it, draft compliant notices and put the right vendor contracts and internal documentation in place. Contact us for a practical compliance check.


