From 2 August 2026, the EU AI Act's transparency rules become enforceable for every chatbot accessible to people in the European Union β with fines of up to β¬15 million or 3% of global annual turnover for non-compliance. The core obligation for most chatbots: tell users they are talking to an AI before the conversation begins. A separate set of rules, the Annex III "high-risk" obligations, was originally due on the same date but has since been postponed to 2 December 2027 by the EU's Digital Omnibus simplification package, agreed by Parliament and Council in June 2026.
If your organization deploys a chatbot β for customer support, lead generation, HR self-service, financial guidance, or any other purpose β and that chatbot is reachable by people in the EU, you are in scope of at least the transparency rules. This article walks you through what's already in force, what changes on 2 August 2026, what was just deferred to December 2027, the corrected penalty structure, GPAI obligations for vendors, and a practical compliance checklist β so you can assess your exposure without relying on outdated deadlines.
TL;DR β Key takeaways
- 2 August 2026: Article 50 transparency obligations become enforceable for all chatbots using NLP or LLMs β this date did not move
- 2 December 2027: Annex III high-risk system obligations, originally scheduled for August 2026, were postponed by the EU's Digital Omnibus package (final agreement June 2026)
- Most chatbots = limited risk: core obligation is a clear "you are talking to AI" disclosure at the start of each interaction
- High-risk triggers: recruitment screening, credit scoring, educational assessment, public-service eligibility β if your chatbot does any of these, Annex III will apply from December 2027
- GPAI rules: foundation model providers (OpenAI, Anthropic, Google) face obligations since August 2025; chatbot deployers using those models inherit documentation requirements
- Penalties scale by tier: Article 50 transparency failures and high-risk non-compliance both sit in the β¬15M / 3% tier; prohibited practices go up to β¬35M / 7%
- The AI Act stacks on top of GDPR β both apply simultaneously to most chatbot deployments
Table of Contents
- AI Act Enforcement Timeline: What Is Active Now
- Risk Classification: Where Chatbots Typically Land
- Article 50 Transparency: The "You Are Talking to AI" Obligation
- High-Risk Use Cases That Pull Chatbots into Annex III
- GPAI and Foundation Model Obligations for Chatbot Vendors
- Penalty Structure: Up to β¬35M or 7% of Global Turnover
- Compliance Checklist for Chatbot Buyers and Deployers
- Vendor Due Diligence Questions
- Heeya's AI Act Posture
- Further Reading
- FAQ
AI Act Enforcement Timeline: What Is Active Now
The AI Act was adopted by the European Parliament on 13 June 2024 and entered into force on 1 August 2024. Enforcement has rolled out in three distinct waves. Understanding which wave applies to your situation is the first step in any compliance assessment.
| Date | What Became Enforceable | Who Is Directly Affected |
|---|---|---|
| 2 February 2025 | Article 5 prohibited practices: subliminal manipulation, social scoring, real-time remote biometric identification in public spaces, exploitation of vulnerable groups | All providers and deployers in the EU β any organization running AI in scope must avoid these practices immediately |
| 2 August 2025 | Title III (GPAI): obligations for general-purpose AI model providers β technical documentation, copyright transparency, safety evaluations for systemic-risk models | Foundation model providers (OpenAI, Anthropic, Google DeepMind, Mistral, Meta AI, etc.) β not chatbot deployers directly, but the documentation they produce flows downstream |
| 2 August 2026 | Article 50 transparency obligations for chatbots and deepfakes become enforceable, with fines under Article 99 now applicable. This date was not affected by the 2026 Digital Omnibus revision. | Every deployer of an AI chatbot accessible in the EU β this is the date that governs your customer-facing or employee-facing AI disclosure duty |
| 2 December 2027 (moved from 2 August 2026) | Annex III high-risk system obligations: conformity assessment, technical documentation, human oversight, EU database registration. Deferred by the Digital Omnibus package, provisionally agreed by Parliament and Council in MayβJune 2026, expected published in the Official Journal before August 2026. | Deployers of chatbots used for recruitment, credit scoring, education assessment, or public-benefit eligibility β see the high-risk triggers section below |
| 2 August 2028 | Obligations for high-risk AI embedded in products already covered by existing EU product safety directives (machinery, medical devices, automotive) | Hardware and embedded AI product manufacturers β largely irrelevant for pure software chatbot deployments |
The date that governs the transparency duty for nearly every chatbot is 2 August 2026 β that has not changed. Article 5 prohibitions have been active since February 2025 β if your chatbot uses subliminal or manipulative techniques to influence user behavior against their interests, that is already a violation. What did change: the Annex III high-risk obligations table above shows a 2 August 2026 date in older sources, but the EU's "Digital Omnibus" simplification package β provisionally agreed on 6 May 2026, endorsed by the European Parliament on 16 June 2026, and given final Council sign-off on 29 June 2026 β pushed that specific date to 2 December 2027. It does not touch Article 50 transparency. If you are relying on an older article (including earlier versions of this one) for the high-risk deadline, treat it as outdated. The European Commission's official AI Act page maintains the authoritative regulatory calendar and guidance documents.
Risk Classification: Where Chatbots Typically Land
The AI Act organizes AI systems into four tiers. The tier determines the obligations. Unlike GDPR, which applies uniformly to all personal data processing, the AI Act scales its requirements to the potential harm posed by the AI system in its specific deployment context.
| Risk Tier | Definition | Chatbot Examples | Core Obligations |
|---|---|---|---|
| Unacceptable (Article 5) | Practices that pose an unacceptable threat to fundamental rights | A chatbot that uses subliminal techniques to manipulate purchasing behavior; a bot that builds social-scoring profiles of users | Prohibited outright β no compliance path |
| High Risk (Annex III) | Significant impact on health, safety, or fundamental rights in defined sectors | CV screening bots, creditworthiness assessment bots, educational grading bots, public-benefit eligibility bots | Conformity assessment, technical documentation, human oversight, risk management system, data governance, post-market monitoring, EU registration β enforceable from 2 December 2027, deferred from the original August 2026 date |
| Limited Risk (Article 50) | Direct interaction with users; limited potential for harm but transparency required | Most customer support, lead generation, FAQ, and internal helpdesk chatbots | Transparency disclosure: users must be informed they are interacting with AI at or before the first message |
| Minimal Risk | No meaningful risk to rights or safety | Spam filters, basic product recommendation engines with no natural language interaction | No mandatory obligations (voluntary codes of conduct encouraged) |
The practical default for a customer-facing chatbot using NLP or an LLM is limited risk. Your support bot, lead qualification assistant, or FAQ agent almost certainly lands here β and the primary obligation is the Article 50 transparency disclosure. The exception is deployment context: the same underlying chatbot technology deployed in a recruitment screening workflow or a credit assessment process enters Annex III high-risk territory regardless of how the vendor markets it. For enterprise teams evaluating the business case for AI adoption alongside compliance costs, our guide on generative AI enterprise ROI and use cases provides the full picture.
Purely rule-based chatbots β button flows, decision trees, keyword matching without natural language understanding β fall outside the definition of an "AI system" under the Act and carry no obligations. The moment you add an LLM, NLP engine, or any component that processes free-form language to generate responses, you are inside the regulation.
Article 50 Transparency: The "You Are Talking to AI" Obligation
Article 50(1) of the AI Act states that providers of AI systems intended to interact directly with natural persons must ensure those systems are designed so that the natural persons are informed, before the interaction begins, that they are interacting with an AI system. The obligation applies unless it is obvious from the context.
In practice, for a website chatbot, this means the following requirements must be met by 2 August 2026:
1. The disclosure must be proactive and pre-interaction
You cannot wait for the user to ask "Am I talking to a bot?" The disclosure must appear before or at the start of the conversation. A visible badge on the chat widget, an automated first message stating the system is AI-powered, or both β either approach satisfies the requirement. An "AI" label that requires the user to scroll or search for it does not.
2. The disclosure must be clear, not buried in terms
A reference to AI in your privacy policy or terms of service is not sufficient as a standalone disclosure. The AI Act requires that the user be "informed" at the point of interaction. The language must be plain: "You are chatting with an AI assistant" or "This is an AI-powered support agent" qualifies. Marketing language like "Our smart assistant" does not.
3. Capability and limitation signaling
Users should be able to understand what the chatbot can and cannot do. If the bot is not authorized to provide personalized legal or medical advice, it must say so and direct users to an appropriate human contact. Unrestricted responses on topics outside the system's validated knowledge base create both AI Act exposure and liability risk.
4. Human escalation pathway
Users must have a clear way to reach a human. The chatbot cannot be the sole contact channel. This does not require a live handoff β a visible "Contact our team" option, an email address, or a form submission path satisfies the requirement β but the pathway must exist and be accessible.
5. Technical documentation
You must be able to document: which AI model or system powers the chatbot, what data sources inform its responses, and what human oversight measures are in place. This documentation is not filed with a regulator by default, but it must be producible if an enforcement authority requests it.
High-Risk Use Cases That Pull Chatbots into Annex III
Annex III of the AI Act enumerates the specific application areas where AI systems are classified as high-risk. A chatbot that performs functions in any of these areas β regardless of what the vendor calls it β is subject to the full high-risk obligation set: conformity assessment, technical documentation, risk management, human oversight, data governance, accuracy and robustness requirements, and EU registration before deployment. These obligations now apply from 2 December 2027, not August 2026 β the EU's Digital Omnibus package deferred the Annex III compliance date by 16 months while leaving the classification rules themselves (which use cases count as high-risk) unchanged. If your chatbot falls into one of these categories, you have more runway than the original deadline suggested, but the classification itself still applies and Article 50 transparency is still due in August 2026 regardless of tier.
| Chatbot Use Case | Annex III Category | Risk Tier | Key Obligations |
|---|---|---|---|
| CV screening, applicant ranking, interview scheduling automation | Employment, workers management, access to self-employment (Annex III Β§4) | High risk | Conformity assessment, human oversight, bias testing, registration in EU AI database |
| Creditworthiness evaluation, loan eligibility, insurance risk profiling via chat | Access to private financial services (Annex III Β§5b) | High risk | Accuracy and robustness requirements, explainability, human review pathway |
| Adaptive learning platforms, student grading or assessment bots | Education and vocational training (Annex III Β§3) | High risk | Data governance, technical documentation, human oversight |
| Benefits eligibility screening, government service access, social welfare assessment | Access to essential private and public services (Annex III Β§5a) | High risk | Full Annex III obligations; registration mandatory |
| Medical triage, personalized diagnosis support, treatment recommendation | Medical devices, health and safety (Annex III Β§2 / MDR overlap) | High risk | MDR and AI Act dual compliance; clinical validation may be required |
| Customer support, lead generation, FAQ answering, internal IT helpdesk | None β outside Annex III | Limited risk | Article 50 transparency disclosure only |
The critical compliance question for any chatbot deployment is not "what is the bot called?" but "what decisions does the bot influence?" A customer support bot that also collects data used to score a customer's creditworthiness is in the high-risk category. An HR chatbot that routes applicants based on keyword matching in their CV responses is in the high-risk category. When in doubt, apply the precautionary principle: document your system as if it were high-risk, implement human oversight, and conduct a bias assessment. These are good practices regardless of tier.
GPAI and Foundation Model Obligations Affecting Chatbot Vendors
The AI Act introduced a new regulatory category: General-Purpose AI (GPAI) models, also called foundation models β large-scale AI trained on broad data capable of performing a wide range of tasks. This category covers the LLMs that power virtually every modern chatbot: GPT-4o, Claude 3, Gemini 1.5, Llama 3, Mistral Large, and their equivalents.
GPAI obligations became active on 2 August 2025 and apply primarily to the model providers, not directly to chatbot deployers. However, this distinction matters for vendor selection:
- Technical documentation: GPAI providers must produce and maintain documentation describing training data, computational resources, capabilities, and limitations. Chatbot deployers building on these APIs should request access to this documentation β it is part of your own compliance file.
- Systemic risk models: Models above 10^25 FLOPS training compute (currently affecting the largest frontier models) face additional obligations including adversarial testing, cybersecurity incident reporting, and energy consumption reporting. If you deploy a chatbot powered by one of these models, your vendor's compliance status under this provision is a legitimate due diligence question.
- Copyright transparency: GPAI providers must publish a summary of training data sources. This has implications for regulated sectors where provenance of training data affects output admissibility.
- Downstream deployer obligations: Even though you are not the model provider, Article 25 makes clear that deployers remain responsible for the AI Act compliance of the system they deploy. You cannot outsource your Article 50 transparency obligation to your LLM vendor. The vendor's GPAI compliance reduces your risk but does not eliminate your obligations.
For chatbot buyers evaluating vendors: your vendor should be able to name the foundation model(s) used, confirm the model provider's GPAI compliance status, and provide a Data Processing Agreement that addresses AI Act obligations alongside GDPR. For a deeper look at GDPR-compliant AI chatbot architecture, including how EU data residency and model selection interact, that guide covers the data layer in detail.
Penalty Structure: Up to β¬35M or 7% of Global Annual Turnover
Article 99 of the AI Act establishes three penalty tiers, scaled by the severity of the violation. These are maximum figures β enforcement authorities apply proportionality, particularly for SMEs β but the structure makes clear that the legislator views AI Act violations as more serious than equivalent GDPR infractions. Article 99(4) groups Article 50 transparency failures into the same tier as high-risk system non-compliance β they are not two separate tiers with different ceilings, a distinction some early commentary got wrong.
- Prohibited practices (Article 5 violations): up to β¬35 million or 7% of global annual turnover, whichever is higher. This tier covers the use of subliminal manipulation, social scoring, and other banned practices. For large technology groups, 7% of global turnover exceeds β¬35M, making this the effective cap.
- Operator obligations, including Article 50 transparency AND high-risk (Annex III) non-compliance: up to β¬15 million or 3% of global annual turnover, per Article 99(4). This is the tier that applies to a customer-facing chatbot that fails to disclose it is AI-powered β the same ceiling that applies to a high-risk chatbot deployed without conformity assessment or human oversight.
- Supplying incorrect, incomplete, or misleading information to notified bodies or national competent authorities in response to a request: up to β¬7.5 million or 1% of global annual turnover. This is a narrower, procedural violation β not the tier that applies to a missing AI disclosure.
For SMEs and startups, penalties are capped at the lower of the turnover percentage or the fixed amount. The fixed amounts are the floor, not the ceiling, for large organizations. Enforcement will prioritize large-scale, high-harm violations in the early years, but national enforcement authorities β which each EU member state must designate β have the power to act on any in-scope deployment. The compliance cost for a limited-risk chatbot is minimal: a disclosure banner, technical documentation, and an accessible human contact. The enforcement cost of ignoring the regulation is not. If you are deciding whether to build a custom AI-Act-compliant chatbot or purchase a certified platform, our guide on custom AI chatbot build vs. buy covers the compliance cost implications of each path. For enterprise teams exploring the more advanced agentic AI capabilities that attract higher-risk classifications, see our guide on agentic RAG implementation for enterprise.
Compliance Checklist for Chatbot Buyers and Deployers
The following checklist applies to organizations deploying AI chatbots in the EU, or accessible to EU users, as of 2 August 2026. Items marked for limited-risk chatbots are the baseline. Organizations with potential high-risk deployments should treat those items as a starting point, not a ceiling. Compliance teams should also ensure staff understand their obligations β see our guide on AI tools for mandatory compliance training for a practical framework on embedding regulatory awareness across the organization.
Article 50 transparency β required for all AI chatbots
- The chat widget displays a visible AI indicator (badge, label, or icon) before the first message
- The chatbot's first automated message explicitly states it is an AI assistant, not a human
- The disclosure language is plain and unambiguous β no marketing euphemisms
- A human contact pathway (email, form, phone, or live agent option) is accessible from the chat interface
- The chatbot's scope limitations are communicated when a user asks about topics outside its validated knowledge
Technical documentation β required for all AI systems
- The AI model or system powering the chatbot is identified (vendor name, model version or API)
- The data sources informing chatbot responses are documented (knowledge base files, URLs, databases)
- Oversight procedures are defined: who is responsible for reviewing chatbot performance, how often, and what the escalation path is
- Conversation logs are retained and accessible for audit purposes
- The GPAI model provider's technical documentation has been reviewed and filed
Risk classification β recommended now, mandatory obligations apply from 2 December 2027
- A formal use-case review has been conducted to determine whether any Annex III category applies
- If high-risk: a conformity assessment plan is underway ahead of the 2 December 2027 deadline (deferred from August 2026 by the Digital Omnibus package)
- If high-risk: a plan exists to register the system in the EU AI database before the December 2027 deadline
- The risk classification and rationale are documented and signed off by a responsible individual
Data governance β required where personal data is processed (AI Act + GDPR overlap)
- A Data Processing Agreement with the chatbot vendor is in place
- EU data residency is confirmed or a valid cross-border transfer mechanism (SCCs) is documented
- Conversation data retention and deletion policies are defined and aligned with your GDPR Record of Processing Activities
- Users are informed about data processing through your privacy notice, updated to cover AI interaction data
Vendor Due Diligence Questions
If you are evaluating a chatbot platform for EU deployment, the following questions should be on your shortlist before signing a contract. A vendor that cannot answer them clearly in writing is a compliance risk.
- Which foundation model powers the platform, and what is that model provider's GPAI compliance status under the AI Act? β You need the model name (e.g., GPT-4o via OpenAI API, Gemini via Google AI API) and a statement that the provider has met August 2025 GPAI obligations.
- Where is conversation data processed and stored? β EU hosting eliminates cross-border transfer complexity. US hosting requires active SCC documentation. Ask for the data residency specification in writing.
- Is a Data Processing Agreement available, and does it address AI Act obligations explicitly? β GDPR DPAs are standard. AI Act-specific provisions (technical documentation availability, oversight support) are increasingly expected from compliant vendors.
- Does the platform provide native Article 50 transparency features? β Ask whether the platform includes configurable AI disclosure banners, opening message templates, and audit logs out of the box, or whether compliance configuration is entirely your responsibility.
- Can the platform provide technical documentation for my compliance file? β The documentation you need to produce under the AI Act depends partly on documentation your vendor must supply. Confirm this is available before you need it.
- Has the vendor undergone any third-party AI Act conformity review? β For high-risk use cases, third-party conformity assessment is mandatory. For limited-risk deployments, voluntary third-party review is a meaningful signal of a vendor's compliance maturity.
For a broader assessment of the EU compliance landscape across chatbot platforms, our comparison of AI chatbot platforms in 2026 covers vendor-by-vendor GDPR and AI Act positioning. The guide on GDPR-compliant AI chatbot architecture addresses the data governance layer in depth. Organizations currently using Zendesk and assessing their AI Act exposure should also review our guide on Zendesk alternatives compliant with EU regulations, which covers how modern platforms handle the transparency and data residency obligations introduced by the Act.
Heeya's AI Act Posture
Heeya was built from the start for European regulatory requirements. The following describes our current AI Act posture as of August 2026.
- Article 50 transparency built in: every Heeya widget displays a clear AI identifier before the first interaction. The opening message is configurable, but the AI disclosure is a required element β it cannot be removed. Deployers are not responsible for implementing the disclosure separately.
- Conversation logging and audit trail: all interactions are logged and accessible in your dashboard. Logs are retained according to your configured retention policy and support the technical documentation obligation under Article 50 and Annex III.
- EU data residency by default: conversation data, knowledge base content, and user interaction data are processed and stored within EU infrastructure. No US data transfer is involved in the core conversation pipeline. A signed Data Processing Agreement is available on all paid plans.
- Transparent knowledge base: Heeya uses Retrieval-Augmented Generation β responses are grounded in documents you upload and control. You know exactly which sources inform each answer. There is no opaque training data that cannot be documented. This architecture is directly supportive of the technical documentation requirement: the data informing your chatbot is fully auditable.
- Human escalation pathway: Heeya's built-in contact form tool provides a configurable human contact option within the chat interface, satisfying the requirement that users be able to reach a person.
- Human oversight controls: you retain full control β modify instructions, review conversations, update the knowledge base, restrict topics, or disable the agent. No decision by the AI is irreversible without human review.
For organizations in regulated sectors β financial services, healthcare, legal, public services β where Annex III classification may apply, Heeya's documentation supports your conformity assessment process. See pricing for plan details or start a free trial to evaluate the platform.
For context on how Heeya compares to Intercom on EU compliance dimensions, our Heeya vs Intercom Fin comparison covers the regulatory and commercial differences in detail. If you are evaluating Crisp as an alternative, see our Heeya vs Crisp comparison. For a broader look at SMB alternatives to Intercom, see Intercom alternatives for SMBs in 2026.
Further Reading
- GDPR-Compliant AI Chatbot Guide 2026 β data residency, DPAs, and the privacy architecture of a properly built chatbot
- Heeya vs Intercom Fin 2026 β pricing model, EU compliance, and feature comparison
- Heeya vs Crisp 2026 β both EU-hosted platforms compared on AI capabilities and compliance posture
- Best Intercom Alternatives for SMBs in 2026 β six platforms compared on pricing, GDPR, and AI features
- Best AI Chatbot Platforms 2026 β comprehensive comparison including AI Act compliance scores
- Agentic AI and Autonomous Agents in the Enterprise 2026 β how autonomous AI agents intersect with high-risk AI Act obligations
FAQ
Does the EU AI Act apply to my customer support chatbot?
Yes, if the chatbot uses NLP, an LLM, or any AI component to process free-form language. Most customer support chatbots are limited risk under Article 50 β the core obligation is a clear AI disclosure at the start of each conversation. Full enforcement is from 2 August 2026. Purely rule-based bots (button flows, decision trees) without a language model are not covered.
What does Article 50 of the EU AI Act require for chatbots?
Article 50 requires that chatbots clearly disclose their AI nature before or at the start of the interaction β unless context makes it obvious. A visible AI badge on the widget and an opening message stating the system is AI-powered both satisfy this. A reference in your terms of service or privacy policy does not. Users must also have access to a human contact pathway from within the chat interface.
What makes a chatbot 'high risk' under Annex III?
Annex III lists the domains that trigger high-risk classification: recruitment and CV screening, creditworthiness and financial access, educational assessment, public service eligibility, and medical or safety-critical applications. Any chatbot performing functions in these areas β regardless of vendor marketing β faces the full high-risk obligation set: conformity assessment, human oversight, technical documentation, and EU AI database registration. These obligations now apply from 2 December 2027, after the EU's Digital Omnibus package deferred the original August 2026 date.
What are the penalties for non-compliance?
Three tiers under Article 99: β¬35M or 7% of global turnover for prohibited practices; β¬15M or 3% for operator obligations, which covers both Article 50 transparency failures and high-risk system violations (they share the same tier); β¬7.5M or 1% for supplying misleading information to authorities. For SMEs, penalties are proportional. Article 50 exposure begins 2 August 2026; high-risk exposure begins 2 December 2027.
Does the AI Act stack on top of GDPR?
Yes β both apply simultaneously. GDPR governs personal data processing; the AI Act governs AI system deployment. Any chatbot that processes personal data (conversation content, names, emails) must comply with both frameworks. GDPR compliance alone is not sufficient from August 2026. For a full treatment of the overlap, see our GDPR-compliant AI chatbot guide. β Written by Anas Rabhi.