Since 2 August 2026 the transparency obligations of the EU AI Act apply to any chatbot that talks to people in the EU. The headline rule fits in a sentence: if a person is interacting with an AI system, they have to be told — at the moment the conversation starts, not in a policy page. Most websites running a chat bubble have not changed a thing, which is why this is worth twenty minutes of your week. This guide covers what Article 50 asks of a customer-service chatbot, the exception that is thinner than it looks, who is responsible when an agency runs the bot, and a compliance checklist you can work through in an afternoon.

What Article 50 actually asks for

The obligation is that people are informed they are interacting with an AI system, at the point of interaction. Not in a policy page, not in a footer — at the moment the conversation starts. A parallel obligation covers marking AI-generated content in a machine-readable way; generative systems already on the market have until 2 December 2026 to comply with that part.

The obvious exception is thinner than it looks

Disclosure is not required where it is obvious from the point of view of a reasonably well-informed, observant and circumspect person that they are dealing with AI. Published guidance cautions against leaning on that. A chat panel in the corner of a shop that answers instantly at three in the morning is obvious to you, because you built it. It is not obvious to a sixty-year-old buying garden furniture.

It binds more people than you would expect

Providers have to design the disclosure in. Organisations deploying somebody else's system cannot assume it has been handled for them — the duty has to sit in their own compliance and governance framework. And the reach is territorial by user, not by company address: serving EU users is enough, wherever you are established.

When an agency runs the chatbot for you

A common arrangement is that an agency builds and operates the chatbot on a client's website. That does not move the obligation: the business whose customers are talking to the bot is the deployer, and it is the deployer's compliance framework the disclosure has to live in. The practical answer is to write it into the engagement — who owns the wording, who checks it survives a redesign, who keeps the transcripts — so that nobody discovers the gap during a complaint.

What the AI Act does not require from a customer-service chatbot

  • A customer-service chatbot that answers questions and captures enquiries is not, on its own, a high-risk system; the heavy obligations of the Act attach to specific high-risk uses, not to talking to customers.
  • It does not require a human to review every answer, or an approval process before each conversation.
  • It does not require you to stop using AI-generated replies — only to be transparent about them.
  • It does not replace the GDPR. Consent before storing contact details, and a lawful basis for follow-up, are separate duties that still apply.

This is a plain-language summary, not legal advice; your counsel should confirm how the Act applies to your specific use.

What good compliance actually looks like

  • Say it in the first message the visitor sees, not in a link they will not click.
  • Make it survive language switching — a disclosure that only exists in English is not a disclosure for a Portuguese visitor.
  • Keep it visible on every surface the agent runs on: widget, hosted page, WhatsApp, Telegram.
  • Keep a record of what was disclosed and when, which mostly means keeping your transcripts.
  • Mark AI-generated content where you publish it, ahead of the December date.

A compliance checklist for customer-service chatbots

01

Put the disclosure in the welcome message

One sentence, first message, before the visitor types. "You are chatting with an AI assistant; a person can take over at any time" does the job. Avoid names and avatars that imply a human.

02

Check it in every language the bot speaks

Open the chat as a Portuguese, Spanish and German visitor. If the agent follows the visitor's language, the disclosure must follow too.

03

Check it on every channel

Website widget, hosted chat page, WhatsApp, Telegram. A disclosure that lives only in the widget's header is missing on the channels where people cannot see a header.

04

Make the handoff to a human explicit

When a person takes over the thread, say so. The rule is about not misleading people in either direction.

05

Keep the transcripts

Being able to show what your agent said, to whom, and when is the boring core of compliance. Retention should match your privacy policy.

06

Separate consent from disclosure

Telling someone they are talking to an AI is not consent to store their email. Ask for that separately, before storing anything, and record the answer.

07

Assign an owner

Someone has to check the disclosure is still there after the next website redesign, the next agent rewrite, and the next channel you add. Write the name down.

Where SuperCognit already helps

The welcome message and behaviour settings are edited visually, so adding a line is a two-minute change rather than a ticket. The chat interface ships in 12 languages and the agent follows the visitor's language, so the disclosure travels with them across the widget, the hosted page, WhatsApp and Telegram. Consent is asked before contact details are stored, and every conversation lands in the workspace inbox — which is the record you will need if anyone ever asks what your agent said.

Of all the AI regulation arriving over the next two years, this is the cheapest to satisfy and the most embarrassing to be caught missing. The deadline has passed; the checklist takes an afternoon.