Is your chatbot AI Act compliant? The rules now apply

Legal separation

Yes: since 2 August 2026, the transparency rules of Article 50 of the EU AI Act apply, and a chatbot must make clear to users that they are dealing with an AI system, at the latest at the first interaction. The only exception is where this is already obvious to a reasonably well-informed user.

For most customer-service and website chatbots, that disclosure is the core obligation, and it is easy and inexpensive to meet. A chatbot that helps decide on job applicants, credit or access to essential services is a different matter: it may be a high-risk system, with much stricter rules that apply from 2 December 2027. Below we explain what changed, how to classify your chatbot and what to do now, including the overlap with the GDPR.

A group of business professionals in a modern office meeting around a table with laptops and digital devices, discussing technology and compliance.

What changed on 2 August 2026?

The transparency obligations in Article 50 of the AI Act became applicable. For chatbots, this means users must be clearly informed that they are interacting with an AI system, at the latest at the moment of the first interaction or exposure (Article 50(1) and (5) of Regulation (EU) 2024/1689).

The information must be clear and distinguishable and must meet accessibility requirements. A line in your terms and conditions, cookie banner or page footer is not enough. If a reasonable user could think they are chatting with a human, the chatbot does not comply. Do not rely lightly on the exception for situations where the AI nature is obvious.

A related deadline follows. Providers of AI systems that generate synthetic audio, images, video or text must mark that output in a machine-readable format so that it can be detected as artificially generated (Article 50(2)). For systems placed on the market before 2 August 2026, the AI Omnibus, in force since 27 July 2026, allows until 2 December 2026 to comply. If your chatbot generates content that could pass for human-made, this deadline is relevant to you or your vendor.

Earlier phases already apply. The prohibited AI practices in Article 5 have applied since 2 February 2025, and the obligations for general-purpose AI models since 2 August 2025.

Is your chatbot limited-risk or high-risk?

Most customer-service and website chatbots are not high-risk; they fall under the transparency rules only. What matters is how you use the chatbot, not how advanced the underlying model is.

For a standard support or FAQ bot, telling users they are dealing with AI may be close to the whole story under the AI Act. A chatbot becomes high-risk if it is used to make or materially support important decisions about people in an area listed in Annex III, for example:

  • employment decisions, such as recruitment, screening, promotion or dismissal;
  • assessing creditworthiness or establishing a credit score;
  • deciding on eligibility for or access to essential public or private services and benefits, such as social benefits or certain life and health insurance;
  • other Annex III uses that affect fundamental rights.

High-risk systems are subject to much stricter requirements, including risk management, data governance, technical documentation, logging, human oversight and a conformity assessment. The AI Omnibus postponed the Annex III obligations to 2 December 2027. If your use case is heading in that direction, design for those requirements now, because rebuilding a system later is more expensive.

A quick self-assessment

Ask yourself three questions:

  • Does the chatbot only inform, guide or route, for example answering FAQs, tracking orders or handing over to a human? Then it is very likely limited-risk; focus on transparency.
  • Does it decide, score or control access for individuals, for example approving or rejecting, ranking candidates or assessing risk? Then it may be high-risk; take legal advice before you deploy it.
  • Does it generate text, images or audio that could look human-made? Then check the machine-readable marking duty and the 2 December 2026 deadline for existing systems.
A group of business professionals in a meeting room discussing AI compliance with a digital screen showing AI graphics and EU symbols.

Who is responsible: you or your vendor?

It depends on your role. The disclosure duty for chatbots in Article 50(1) rests on the provider, the party that develops the AI system or has it developed and places it on the market or puts it into service under its own name.

A business that builds its own chatbot on top of a third-party language model and offers it under its own name will often itself be the provider of that chatbot. A business that simply uses a vendor’s ready-made chatbot is usually a deployer. In both cases the chatbot runs on your website, so a missing notice reflects on you. Agree in writing with your vendor who does what, and check the result in the chat window itself.

How do you make your chatbot compliant?

Start with a clear AI notice in the chat window, then put oversight, records and vendor arrangements in place. Even for a limited-risk chatbot, most of the steps below are worthwhile and show the regulator that you take the rules seriously. In the Netherlands, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) and the Dutch Authority for Digital Infrastructure (RDI) are expected to coordinate AI supervision.

Tell users at the first interaction

Add an unambiguous notice before or at the start of the conversation, in the chat window itself: in the opening message, the header, or both. A link to a policy is not enough. Examples of wording:

  • Hello, I am the AI assistant of [company]. I can help with common questions and put you in touch with a colleague if needed.
  • You are chatting with a virtual (AI) assistant, not with an employee.

Provide human oversight and a route to a person

Offer a clear and easy route to a human, such as a button to talk to a colleague. Make sure staff can review, correct and take over conversations, especially where the bot deals with complaints, contracts, payments or vulnerable users.

Keep records and monitor

Keep records of conversations and system behaviour so that you can check performance, investigate complaints and detect errors or misuse. Monitor for made-up answers and inappropriate output, and set thresholds for human review. Keep in mind that chat logs contain personal data, so set retention periods.

Check your vendor

Most businesses buy their chatbot rather than build it. Ask your vendor to confirm in writing that the system supports the AI Act transparency rules and, where relevant, machine-readable marking of synthetic content by 2 December 2026. Record in the contract who is the provider and who is the deployer, and allocate responsibilities, warranties and indemnities accordingly.

Support AI literacy among staff

Under Article 4 of the AI Act, as amended by the AI Omnibus, providers and deployers must take measures to support a sufficient level of AI literacy among the people who operate AI systems on their behalf. Train the teams that manage, supervise or rely on the chatbot, so that they understand its limits, the escalation rules and how data is handled.

Document your choices

Keep a short internal record: what the chatbot does, its risk classification, the notice used, the oversight measures, the vendor and the data it processes. That record is your evidence if a regulator or customer asks questions.

A group of business professionals in an office discussing AI chatbot compliance with a digital screen showing AI graphics.

Does the GDPR also apply to your chatbot?

Yes. A chatbot can comply fully with the AI Act and still breach the General Data Protection Regulation (GDPR). The two regimes apply side by side, and you must meet both.

  • Lawful basis: identify a valid basis under Article 6 GDPR, usually legitimate interest or consent, for processing the personal data users type into the chat.
  • Privacy notice: your privacy statement must explain that a chatbot processes personal data, for which purposes, how long it is kept and whether it is used to train AI models.
  • Data minimisation: do not collect more than you need, and do not invite users to share special categories of data, such as health information.
  • Rights and transfers: make sure requests for access or erasure can be handled, and check where your vendor stores and processes the data, particularly outside the European Economic Area.

The AI Act notice that the user is talking to an AI and the GDPR notice explaining how you use their data are separate obligations. You need both.

What are the penalties?

The AI Act sets high maximum fines in Article 99. For companies, the higher of the fixed amount and the percentage of worldwide annual turnover applies; for SMEs and start-ups, the lower of the two.

  • up to €35 million or 7% of total worldwide annual turnover for prohibited AI practices;
  • up to €15 million or 3% for breaches of most other obligations, including the transparency rules in Article 50;
  • up to €7.5 million or 1% for supplying incorrect, incomplete or misleading information to authorities.

For a limited-risk chatbot, the more immediate risk is an order to comply and damage to your reputation. A missing AI notice is a visible failing that a regulator or complainant will spot quickly, and it is easy to fix.

What else can you do beyond the minimum?

The following measures are not required for every chatbot, but they reduce legal and practical risks.

  • Ground the answers in your own content. Retrieval-augmented generation (RAG) bases answers on your own verified documents, such as product information, policies and FAQs, which improves accuracy and reduces made-up claims.
  • Consider ISO/IEC 42001. This management system standard for AI offers a recognised framework for governing AI and helps you demonstrate accountability.
  • Set limits. Prevent the bot from giving definitive legal, tax or medical advice, and route sensitive questions to a person.
  • Review regularly. Check the classification again whenever the chatbot’s role expands: a support bot that starts screening job applicants may become high-risk.

In summary

  • Since 2 August 2026, users must be told clearly, at the first interaction, that they are dealing with an AI chatbot.
  • Most customer-service chatbots are limited-risk; chatbots used for decisions on employment, credit or essential services may be high-risk, with rules applying from 2 December 2027.
  • Existing systems that generate synthetic content must support machine-readable marking by 2 December 2026.
  • Agree roles with your vendor in writing, support AI literacy and document your choices.
  • The GDPR applies alongside the AI Act; you need both an AI notice and a privacy notice.

Frequently asked questions

Do the chatbot rules really apply now?

Yes. The transparency obligations in Article 50 of the AI Act have applied since 2 August 2026. The AI Omnibus did not postpone them.

Do I have to tell users my chatbot is AI?

Yes, clearly and at the latest at the first interaction, unless it is obvious to a reasonably well-informed user. Put the notice in the chat window itself, not in your terms and conditions.

Is my customer-service chatbot high-risk?

Usually not. It may become high-risk if it is used for important decisions about people in an Annex III area, such as employment, creditworthiness or access to essential services.

We use a third-party chatbot. Are we still responsible?

Partly. The disclosure duty rests on the provider, but if you offer the chatbot under your own name you may be the provider yourself, and as a deployer you have your own obligations, such as supporting AI literacy. Agree the roles with your vendor in writing.

Does compliance with the AI Act mean I comply with the GDPR?

No. They are separate regimes and you must meet both, including a lawful basis for processing chat data and a clear privacy notice.

Law & More reviews chatbots under the AI Act and the GDPR, drafts the notices and puts the vendor contracts and internal documentation in place.

Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.

How Law & More can help you with this is explained on our IT lawyer page.

Tom Meevis
Tom Meevis is an attorney-at-law at Law & More in Eindhoven and Amsterdam. He handles general practice and is the negotiator and litigator of the firm.

Need Legal Assistance?

Have you received a letter, a writ of summons or a judgment? Send us the documents. We will check which deadlines apply and what your options are.

This article provides general information and is not a substitute for advice on your specific situation.

Related articles

A domain name is often a company’s most valuable digital asset, and the most easily

When is an IT supplier liable for damage and delay under Dutch law? Breach, default,
Discover when Escrow Arrangements for Software Source Code are necessary for legal and business security.

The GDPR and big data are not incompatible, but they force a choice that many

Almost every commercial software product contains open source components, usually hundreds, chosen by developers rather

Biometric data, such as fingerprints, facial images or voice patterns, is a special category of

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.