EU AI Act compliance for AI chatbots & assistants
Limited riskA customer-facing chatbot or generative assistant usually falls under limited risk — its obligations are transparency-focused rather than the full high-risk regime.
A customer-facing chatbot or generative assistant is usually not high-risk. Its duties come from Article 50 and they are about transparency: telling people they are talking to a machine, and marking what the machine produces. These duties are already in force. A great deal of published guidance still describes them as a future deadline, which they are not.
Why it is in scope
Article 50 requires that people are told when they interact with an AI system, and that AI-generated content is marked in a machine-readable way.
What this does not trigger
Article 50 is about transparency, not capability. An assistant that only retrieves answers from your own documentation still owes the disclosure, but it does not acquire high-risk obligations by being useful. The Article 50(1) duty also falls away where AI use is obvious to a reasonably well-informed, observant and circumspect person in the circumstances — and that is read from the user's position, not from what your product team finds obvious. What does pull a chatbot into the high-risk regime is what it is used for: screening candidates, scoring creditworthiness or triaging patients are Annex III uses whatever the interface looks like.
Provider or deployer?
Article 50(1) binds providers of systems intended to interact directly with people. Article 50(2) binds providers of systems generating synthetic audio, image, video or text. Article 50(4) binds deployers who publish generated text on matters of public interest, and deployers of deepfakes. If you embed a vendor's model in your own product, under your own name, you are in practice the provider of the system your users meet.
Key obligations
- Tell users they are interacting with an AI system (Article 50(1))
- Mark AI-generated or manipulated content in a machine-readable format (Article 50(2))
- Clear, accessible disclosure at the point of interaction
- Keep evidence of how disclosures are implemented
What this looks like in practice
- A support chatbot has to disclose that it is an AI system, at the point of interaction and in a way an ordinary user actually notices — unless that is already obvious to a reasonably well-informed person in the circumstances.
- The Article 50(2) duty is machine-readable marking of synthetic output, so downstream systems can detect it. It is a technical duty on the generating system, not a visible caption; the visible labelling duty for deepfakes sits in Article 50(4).
- An internal assistant that never faces a customer still generates content. If that content is published on matters of public interest, the deployer duty in Article 50(4) can attach even though no outsider ever chatted with the bot.
- Voice assistants follow the same rule as text. Article 50(2) names synthetic audio first, and a cloned or synthesised voice is exactly the output the marking duty was written for.
- Article 50(3) adds a separate duty for emotion-recognition and biometric-categorisation systems: the deployer must inform the people exposed to them. It bites only where emotions are inferred from biometric data — a voice or face analysis that routes a conversation by mood is inside; sentiment read from the words alone is not.
Where SMEs get this wrong
- Reading limited risk as no obligation. The Article 50 duties are enforceable, they apply now, and they are the ones an ordinary user can see you failing.
- Confusing the two dates. The Article 50 transparency duties applied from 2 August 2026 and were not rescheduled. The separate four-month transition ending December 2, 2026 covers only machine-readable marking, and only for systems already placed on the market before 2 August 2026.
- Assuming the model vendor's disclosure covers your product. The disclosure duty attaches to the system your user interacts with, and that system is yours.
What actually proves compliance
Keep a capture of the disclosure as the user actually sees it, the wording used and when it changed, a technical description of how synthetic output is marked, and — if you rely on the exception that AI use is obvious — a written note of why you reached that conclusion. The exception is judged from the user's position, not from yours.
What getting it wrong costs
The Article 50 transparency duties are named in the Article 99(4) band: up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. Article 99(6) caps that for SMEs and start-ups at whichever of the two is lower, across the Article 99(3), (4) and (5) bands, and the Digital Omnibus added Article 99(6a) giving small mid-caps the same lower-of ceiling for the (4) and (5) bands only. Emotion inference in the workplace or in education is a different matter entirely: prohibited under Article 5, and in the 7% band — which Article 99(6a) does not cap.
When it applies
Article 50 has applied since 2 August 2026. For systems already on the market before that date, the machine-readable marking duty of Article 50(2) had until December 2, 2026 to be met — a four-month transition the Digital Omnibus itself introduced. Article 50's text and its 2 August 2026 date were not otherwise changed.
Questions we get asked
- Do we need a banner on every message?
- No. The duty is that the person is informed they are interacting with an AI system, clearly and at the point of interaction. A clear statement when the conversation opens, and an identity that does not pretend to be human, normally satisfies it.
- Our chatbot answers HR questions from employees. Is it high-risk?
- Answering questions is not the same as evaluating people. It becomes an Annex III point 4 question if the system screens candidates, allocates tasks on the basis of behaviour or traits, or monitors and evaluates performance. A policy-lookup assistant does none of those.
- We call a third-party model API. Are we the provider?
- For the system your users interact with, in practice yes — you are the one placing it on the market under your own name. The model vendor has its own general-purpose AI duties under Chapter V, and those do not discharge your Article 50 duties.
- The disclosure is in our terms of service. Is that enough?
- No. Article 50(1) creates the duty to inform people that they are interacting with an AI system, and Article 50(5) governs how: the information must be given in a clear and distinguishable manner at the latest at the time of the first interaction, and it must meet accessibility requirements. Text buried in a document nobody opens meets neither the timing nor the clarity requirement.
Check the law yourself
Further reading
Get to compliance with SetAIComply
Classify your system, auto-draft Annex IV documentation, and track every deadline — built for SMEs.