The EU AI Act now requires you to tell customers your chatbot is AI
Article 50 of the AI Act became applicable on 2 August 2026. What it actually requires from a support chatbot, why the 'obvious' exemption will not save you, and the GDPR questions that were already there.
On 2 August 2026 the transparency obligations of the EU AI Act became applicable. If you run a support chatbot that serves customers in the EU, that is no longer distant regulation — it is a concrete requirement on your widget. The good news is that the core duty is small and you can satisfy it today.
1. The transparency duty
Article 50 of the AI Act requires that people interacting with an AI system are informed that they are interacting with an AI system. The European Commission confirms on its own explainer that Article 50 applies from 2 August 2026 — see the Commission's FAQ on Article 50 and the text of Regulation (EU) 2024/1689.
There is an exemption where it would be obvious to a reasonably well-informed, observant and circumspect person that they are dealing with an AI. The Commission indicates that this exemption should be read narrowly. A support widget styled to look like a chat with a colleague is a poor candidate for it — a visible label is cheaper than the argument.
What this looks like in practice
Put the disclosure in the widget itself, not only in your privacy policy or terms. Someone opening a chat does not read those.
Say it in the first message or in the chat header: "You are chatting with our AI assistant. Ask for a person any time and we will hand you over."
Keep the route to a human visible. Transparency without an exit reads to a customer as a dead end.
Record when and why the label is shown. In an audit the question is not whether you meant well, but whether you can demonstrate it.
2. Does it apply to you?
The AI Act reaches providers and deployers placing systems on the EU market or serving people in the EU, so a US or UK company running a chat widget for European customers is in scope. This is the same extraterritorial logic that made GDPR a global compliance project rather than a European one, and the practical answer for most support teams is the same: implement it everywhere rather than trying to branch by visitor location.
3. The GDPR questions, which were already there
An AI chatbot does not change your GDPR obligations, but it does move where personal data shows up. Customers type things into a chat box that they would never put in a contact form: order numbers, addresses, sometimes health or financial details.
What to settle before the widget goes live
Question
Where it goes wrong
Do you have a data-processing agreement with your chat vendor?
Without one you are processing personal data through a party you have agreed nothing with. It is the fastest item on this list to fix and the most commonly skipped.
Where is the data stored, and which sub-processors sit behind it?
Much AI functionality runs through model providers outside the EEA. That is permitted, but it needs a valid transfer mechanism and you need to be able to explain which party sees what.
How long do you keep transcripts?
Chat logs are rarely cleaned up because nobody owns them. Set a retention period and let it expire automatically.
Can the bot reach order data, and how does it check who it is talking to?
A bot that looks up an order number without an email check hands data to whoever guesses the number. Tie every lookup to the customer's verified email and return a neutral 'not found' when they do not match.
What happens on an access or erasure request?
If transcripts live only with your vendor and are not searchable, you cannot answer such a request inside the statutory deadline.
For the record on our own setup: the primary data store is in the EU, a data-processing agreement is available, and order lookups are read-only and email-matched. Some AI processing runs through sub-processors outside the EEA under standard contractual clauses — that is stated in the DPA and the privacy policy so you can check it rather than take our word for it.
4. Where it goes wrong in practice
The bot invents policy. A model that is not bound to your own content will make up a returns window you do not offer. Ground answers in your knowledge base and show the source.
The bot makes commitments with money behind them. Never let an AI issue refunds or edit orders on its own — have it prepare the action and have a person approve it.
The disclosure exists but sits at the bottom. If the customer only sees it after typing out their problem, it did not do its job.
Nobody reads the conversations back. Without sampling you do not know what your customers are being told — which is exactly what a regulator, or an angry customer, will ask you. See deflection rate vs resolution rate for what to measure instead of volume.
Do I have to tell customers my chatbot is AI?
Yes. Article 50 of the EU AI Act requires that people are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person. The European Commission indicates the exemption should be interpreted narrowly, so a visible label is the safe route for a support widget.
When did the EU AI Act chatbot transparency rules start applying?
From 2 August 2026, according to the European Commission's explainer on Article 50 of Regulation (EU) 2024/1689. The regulation itself entered into force on 1 August 2024, but its chapters became applicable in stages.
Does the EU AI Act apply to companies outside the EU?
It reaches providers and deployers who place AI systems on the EU market or whose systems serve people in the EU, so a company established outside the EU that offers a chat widget to European customers is in scope. In practice most support teams implement the disclosure everywhere rather than branching by visitor location.
Is a customer support chatbot high-risk under the AI Act?
Usually not. A chatbot answering questions from your own knowledge base falls under the Article 50 transparency obligation rather than the high-risk categories, which cover areas such as recruitment, credit scoring and biometrics. Have your own use assessed if the AI helps decide access, pricing or entitlements.
What GDPR steps do I need before launching an AI chatbot?
A lawful basis, a data-processing agreement with your vendor, clarity on where data is stored and which sub-processors are involved, a retention period for transcripts, identity verification before the bot discloses order data, and a workable process for access and erasure requests.
A practical guide to the four questions procurement always asks about an AI support tool: what the DPA has to cover, where the data goes, how long transcripts live, and how you answer an access or erasure request across every channel.
Live chat installs in about ten minutes — one script tag or a CMS plugin. Here is the full setup: install route, knowledge base, office hours and handover.
Live chat is a person; a chatbot is software. The honest answer is that you do not have to choose — modern widgets run AI first and hand off to a human.
Resolve more tickets automatically.
See how honestly-measured AI resolutions cut your support load — start on the Free plan, no credit card, no sales call to get started.