October 1, 2026

EU AI Act and Website Chatbots: What Changes in 2026

EU AI Act and website chatbots: transparency rules that apply from 2 August 2026

The EU AI Act rules for chatbots are now in force. Since 2 August 2026, the Act’s transparency obligations apply, and the main one for website chatbots is simple: people must be told when they are talking to an AI. For most businesses running a customer service assistant on their site, that is the core requirement, together with basic staff AI literacy and continued GDPR compliance. This guide explains what the EU AI Act means for chatbots in practice, who is responsible for what, what changed with the 2026 “AI Omnibus” amendments, and a short checklist you can work through this week.

This article is general information, not legal advice. If your chatbot is used for decisions about credit, jobs, education or access to essential services, talk to a lawyer, because different rules apply.

The EU AI Act in Brief

The AI Act (Regulation (EU) 2024/1689) is the EU’s law on artificial intelligence. It entered into force on 1 August 2024 and has been applying in stages:

  • 2 February 2025: bans on prohibited AI practices and the AI literacy obligation.
  • 2 August 2025: governance rules and obligations for general-purpose AI models.
  • 2 August 2026: the Act became generally applicable, including the transparency obligations in Article 50 that cover chatbots.
  • 2 December 2027: rules for high-risk uses in sensitive areas listed in Annex III, after the AI Omnibus extended the deadline.
  • 2 August 2028: rules for high-risk AI embedded in regulated products such as machinery or toys.

The European Commission’s AI Act overview page keeps the official timeline up to date.

The Act sorts AI uses by risk. Unacceptable-risk practices are banned. High-risk uses face strict requirements. Uses with a transparency risk, which is where most chatbots sit, must be disclosed. Minimal-risk AI, such as spam filters, has no new obligations.

Where Website Chatbots Fit Under the EU AI Act

A customer service chatbot that answers questions about your products, delivery and opening hours is not high-risk under the Act. It falls into the transparency category, because the risk is that a visitor does not realise they are talking to a machine.

The picture changes when a chatbot does more than answer questions. A chatbot that screens job applicants, assesses creditworthiness, decides on access to public benefits or evaluates students can fall into the high-risk list in Annex III. Those rules are due from 2 December 2027 and include risk management, documentation, human oversight and registration duties. If your assistant is used anywhere near those decisions, get specific advice.

Some practices are banned outright, for example AI that manipulates people through subliminal techniques or exploits vulnerabilities to distort their behaviour in harmful ways. A normal support chatbot is nowhere near this, but it is a useful reminder not to design an assistant that pressures vulnerable visitors into purchases.

The Transparency Rule: Tell People They Are Talking to AI

Article 50 of the Act requires that AI systems intended to interact directly with people are designed so that those people are informed they are interacting with an AI system, unless that is obvious from the context to a reasonably well-informed person. The information has to be given clearly and at the latest at the first interaction.

On 20 July 2026 the Commission published guidelines on the transparency obligations, which clarify who must comply and how. In practice, for a website chat this means:

  • The assistant should say it is an AI in its greeting or first reply, or the widget should label it clearly, for example “AI assistant”.
  • A human-sounding name alone, such as “Anna”, is not enough if nothing else signals that it is automated.
  • The disclosure should be visible, not hidden in the privacy policy.
  • When a person takes over, it helps to say so, so the visitor knows who they are talking to now.

Do not rely on “it’s obvious”. Many chatbots now write fluent, friendly text, and a visitor on a phone may not notice the difference. A short label costs nothing.

Provider or Deployer: Who Is Responsible?

The Act distinguishes between the provider, who develops an AI system and places it on the market, and the deployer, who uses it in their own business. If you install a chatbot product from a vendor on your website, the vendor is usually the provider and you are the deployer.

The Article 50 duty to design chatbots so users are informed falls primarily on providers. That does not mean deployers can ignore it. You control the greeting, the assistant’s name and how the widget looks on your site, so in practice you are the one who makes the disclosure visible. You also carry other deployer duties, such as AI literacy for your staff.

The table below summarises the split for a typical website chatbot.

Obligation Provider (chatbot vendor) Deployer (your business) Applies since
Design the chatbot so people know it is AI Yes Configure greeting and name so it is visible 2 August 2026
AI literacy of staff using the system Yes, for its own staff Yes, for your team 2 February 2025
Machine-readable marking of AI-generated content Yes, for generative systems — 2 August 2026
High-risk requirements Only if used for Annex III purposes Only if used for Annex III purposes 2 December 2027
GDPR (a separate law) As processor As controller Already applies

AI Literacy: The Obligation Many Businesses Missed

Since February 2025, providers and deployers have been expected to take measures so that staff dealing with AI systems have sufficient AI literacy. For a small business with a website chatbot, this does not mean a certification. It means the people who manage and supervise the assistant understand:

  • that the assistant can be wrong, and why;
  • where its answers come from and how to correct them;
  • when it hands conversations over and how to respond;
  • what data it processes and what must never be entered into it.

A one-page internal guide and a short session when someone joins the team is a sensible, proportionate way to cover this. Keep a note of when you did it.

What the AI Omnibus Changed in 2026

In November 2025 the Commission proposed a package of simplifications to the AI Act, known as the AI Omnibus. A political agreement was reached on 7 May 2026 and the amending regulation entered into force on 27 July 2026. For website chatbots the relevant points are:

  • The transparency obligations were not postponed. They apply from 2 August 2026.
  • The high-risk rules were pushed back: to 2 December 2027 for Annex III uses and to 2 August 2028 for AI in regulated products.
  • Some simplified requirements for SMEs were extended to small mid-cap companies.

If you read older articles that describe the chatbot rules as “coming soon”, they are out of date.

The EU AI Act and GDPR Work Together

The AI Act does not replace data protection law. A chatbot that processes names, e-mail addresses or conversation content is processing personal data, and everything you already do under GDPR still applies: a lawful basis, a clear privacy notice, a data processing agreement with the vendor, sensible retention and answering access requests. Our guide to GDPR and live chat covers those points, and our article on data processing agreements for live chat lists what to check in a vendor’s DPA.

Two practical questions tend to come up with AI chatbots:

  • Where does conversation data go? Ask the vendor which data is sent to the AI model and where it is stored. Talkmio, for example, stores data in the EU (Germany) and sends only the conversation text and relevant knowledge-base excerpts to the AI model provider.
  • Can visitors reach a person? A clear handoff to a human is good practice under both laws, and it is what customers expect.

Penalties and Enforcement

Since 2 August 2026 the Commission’s AI Office and national authorities are responsible for supervising and enforcing the Act. Fines are tiered. Breaching the transparency obligations can lead to fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher, with the lower of the two applying to SMEs. Prohibited practices carry higher maximums.

For a normal website chatbot the realistic risk is not a large fine but a complaint and an order to fix the disclosure. Given how easy the fix is, there is no reason to wait.

A Practical Checklist for Your Website Chatbot

  1. Label the assistant. Put “AI assistant” in its name or greeting, for example “Hi, I’m Mio, an AI assistant. I answer from our website and can connect you with the team.”
  2. Check the first message on mobile. Make sure the disclosure is visible on small screens before the visitor types.
  3. Keep a human option. Make it easy to reach a person, and show when a person has taken over.
  4. Ground the answers. Restrict the assistant to your own content so it does not invent prices or policies. Our guide to AI chatbot hallucination control explains how.
  5. Train your team. A short AI literacy note for everyone who manages the chat.
  6. Update your privacy notice. Mention the AI assistant, what it processes and where data is stored.
  7. Check the use case. If the assistant touches hiring, credit, education or essential services, get advice on the high-risk rules.
  8. Document it. Keep a short record of the setup, the disclosure wording and the date of your review.

In Talkmio you can set the assistant’s name and welcome text per website, so step 1 takes a minute. For the full reasoning on disclosure beyond the legal minimum, see our article on whether to tell customers they are talking to AI.

Frequently Asked Questions

Does the EU AI Act apply to website chatbots?

Yes. Chatbots that interact directly with people fall under the AI Act’s transparency obligations in Article 50, which apply from 2 August 2026. People must be informed that they are talking to an AI unless that is obvious from the context. A standard customer service chatbot is not high-risk, so the stricter high-risk rules do not apply.

Do I have to tell visitors they are chatting with AI?

In practice, yes. The AI Act requires chatbots to be designed so users are informed they are interacting with an AI system, at the latest at the first interaction. The simplest way is to label the assistant as “AI assistant” in its name or first message, and to show clearly when a person takes over the conversation.

Is a customer service chatbot a high-risk AI system?

Usually not. A chatbot answering product, delivery or opening-hours questions belongs in the transparency category. It can become high-risk if it is used for decisions listed in Annex III, such as screening job applicants, assessing creditworthiness or deciding on access to essential services. Those high-risk rules apply from 2 December 2027.

Who is responsible, the chatbot vendor or my business?

Both, for different things. The vendor, as provider, must design the system so users can be informed it is AI. Your business, as deployer, configures the greeting and name on your site and must ensure your staff have sufficient AI literacy. GDPR duties also remain, with you usually acting as the controller.

Did the AI Omnibus delay the chatbot rules?

No. The AI Omnibus, which entered into force on 27 July 2026, pushed back the high-risk rules to 2 December 2027 and 2 August 2028, but the transparency obligations for chatbots still apply from 2 August 2026. Articles describing the chatbot rules as a future requirement are now out of date.

What are the fines for breaking the chatbot transparency rules?

Breaching the AI Act’s transparency obligations can lead to fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher; for SMEs the lower amount applies. For most small businesses the realistic outcome of a problem is an order to fix the disclosure, which takes minutes to do correctly.

The Bottom Line

For most businesses, the EU AI Act asks three things of a website chatbot: tell visitors clearly that they are talking to an AI, make sure your team understands how the assistant works, and keep your GDPR house in order. The high-risk rules only matter if your chatbot is involved in decisions about jobs, credit or essential services. Talkmio lets you name and label the assistant, keeps answers grounded in your own content and stores data in the EU; you can check your setup on the free plan at app.talkmio.com.


Try Talkmio on your site

Free plan, no card required.

Start free