EU AI Act Guide
Do AI Chatbots Fall Under the EU AI Act? (Usually — as Limited Risk)
Last updated: 2026-07-09
Short answer: yes, almost every customer-facing chatbot is in scope of the EU AI Act — but for most, the obligations are light. Chatbots default to the limited-risk tier under Article 50, which requires transparency, not conformity assessment.
The longer answer has two important exceptions: chatbots that make or influence consequential decisions can be high-risk, and a few interaction patterns are outright prohibited. Here is how to tell which one you are running.
Not sure which tier applies to you? Check your system in 2 minutes — free and rule-based.
Quick shortcut
Already know you need documents? Skip straight to the Doc Pack — your classification is done for you.
Get Doc Pack ($229–$499)The default: Article 50 transparency duties
From 2 August 2026, a system intended to interact directly with people must be designed so users know they are talking to an AI, unless that is obvious from context. If your chatbot also generates synthetic audio, image or video content, that content must be marked machine-readably as AI-generated; deepfakes must be visibly labelled.
That is the core of it: a clear disclosure at the start of the conversation, a marking pipeline for generated media, and records showing you did both. No CE marking, no Annex IV documentation, and no notified-body route unless a separate high-risk conformity route requires it.
When a chatbot escalates to high-risk
The tier follows the use case, not the interface. A chatbot that screens job candidates, assesses creditworthiness, decides eligibility for benefits or triages access to essential services is operating in an Annex III area — the conversational UI does not change that. The same model deployed as an internal FAQ bot and as a candidate-screening bot lands in two different tiers.
The practical test: does the chatbot’s output influence a decision listed in Annex III about a specific person? If yes, treat it as high-risk and plan for the full obligation stack.
The prohibited edge cases
Article 5 has applied since February 2025 and catches a few chatbot patterns: purposefully manipulative or deceptive techniques that materially distort behaviour and cause significant harm, exploitation of vulnerabilities of specific groups, and emotion recognition in workplaces or education settings (outside medical and safety uses).
A companion or engagement-optimised bot should be reviewed against Article 5(1)(a)–(b) specifically — dark-pattern conversation design aimed at vulnerable users is exactly what those clauses target.
What disclosure looks like in practice
Good implementations are boring: a persistent label (“AI assistant”) in the chat header, a first-message disclosure, and an escalation path to a human where the context calls for it. Disclosure buried in terms of service does not meet the “clear and distinguishable at the latest at first interaction” standard.
For voice bots, disclose at the start of the call. For embedded assistants inside a product, context can make AI-ness obvious — but when in doubt, label. The cost of over-disclosure is zero; the fine tier for Article 50 violations reaches €15M or 3% of global turnover.
Using GPT, Claude or Gemini does not make you a model provider
GPAI obligations (Article 53) bind the companies that train and offer the models. Building a chatbot on an API makes you a downstream provider of an AI system — your duties are the Article 50 transparency ones plus whatever your use case triggers, not training-data summaries or model evaluations.
Where does your system land?
Check your AI system against the actual Annex I/III rules in 2 minutes. Free, rule-based, no signup.
Start the free risk check →Frequently asked questions
Do I need to label every single AI response?
No — the duty is that users know they are interacting with AI, informed clearly at the latest at first interaction. A persistent interface label plus an opening disclosure is the standard pattern; per-message labels are not required.
Does an internal-only chatbot for employees count?
Article 50 covers systems interacting with natural persons, including employees, though context often makes AI obvious internally. Watch Article 5 instead: emotion recognition on employees is prohibited, and internal HR-adjacent bots can drift toward Annex III territory.
Our support bot hands off to humans. Does that change the tier?
Human handoff is good practice and helps under Article 50, but the tier depends on what the bot decides or influences, not on whether escalation exists. A support bot that merely answers questions stays limited-risk with or without handoff.
Related guides
EU AI Act Deadlines: The Complete 2025-2028 Timeline
Every EU AI Act deadline from February 2025 to August 2028 - what applies when, to whom, and what to do before 2 December 2027.
AI Act Compliance Tools Compared (2026): Platforms, Packs & DIY
Honest comparison of EU AI Act compliance options — GRC platforms like Vanta and Drata, documentation packs, and doing it yourself. Sized by risk, systems and workflow needs.
Is AI Resume Screening High-Risk Under the EU AI Act? (Yes — Here's What That Means)
AI recruitment and CV screening tools fall under Annex III of the EU AI Act. What HR-tech vendors and employers must do before 2 December 2027.
Annex IV Technical Documentation: Structure, Template & Examples
What EU AI Act Annex IV technical documentation must contain, section by section — and how to produce a structured first draft without a custom law-firm drafting engagement.
About these guides
Written by the TrustPacket team. We track Regulation (EU) 2024/1689, Commission guidance, and enforcement developments to keep these guides current. Not legal advice — when in doubt, consult qualified counsel.
Last updated: 2026-07-09 · Content review: 11 July 2026 · Questions? Email us
This is informational editorial content based on Regulation (EU) 2024/1689 and cited official implementation material. It is not legal advice, not a conformity assessment, and does not create a lawyer-client relationship. Application depends on facts this guide cannot verify. Consult qualified counsel for a binding assessment.