Chatbots and the AI Act: What Really Lands on 2 August 2026

7/24/2026โ€ข8 min read
Chatbots and the AI Act: What Really Lands on 2 August 2026

Straight answer: from 2 August 2026 the transparency obligations of Article 50 of Regulation (EU) 2024/1689 (the AI Act) apply. If you run a chatbot on your site, on WhatsApp or on Telegram, you must make sure users know they're talking to an AI no later than the first interaction. If the system generates text, images, audio or video, outputs must be marked in a machine-readable format. Fines go up to โ‚ฌ15 million or 3% of global annual turnover, whichever is higher. The Digital Omnibus postponed other parts of the AI Act โ€” not this one.

TL;DR

  • 2 August 2026: Article 50 applies and enforcement powers are live across all 27 member states.
  • Art. 50(1) โ€” providers of systems that interact with people must make them recognizable as AI, unless it's obvious.
  • Art. 50(2) โ€” generative outputs must be marked machine-readably. Systems already on the market have until 2 December 2026; new ones must comply immediately.
  • Art. 50(4) โ€” deepfakes and text published on matters of public interest must be disclosed (unless human-reviewed with editorial responsibility).
  • What is NOT landing now: Annex III high-risk obligations moved to 2 December 2027.
  • For a standard e-commerce chatbot, compliance is one day of work, not a project.

Who this covers (probably you)

First misconception: many founders assume the AI Act is about "the companies that make AI" โ€” OpenAI, Google, Anthropic. Article 50 is also about whoever puts it in production on their own website.

If you run an e-commerce site with a virtual assistant, a customer support bot on WhatsApp, a conversational configurator, or if you generate product descriptions and images with AI, you're in scope. Not because you trained a model, but because you're exposing an AI system to people.

The regulation splits two roles, and it's worth knowing which one is yours:

Role Who it is Art. 50 obligations
Provider Whoever develops the system or puts it on the market under their own name/brand 50(1) AI disclosure ยท 50(2) machine-readable marking of outputs
Deployer Whoever uses the system under their own authority (you, on your site) 50(3) biometric systems ยท 50(4) deepfakes and public-interest text

The detail that catches everyone out: if you take a third-party chatbot and rebrand it under your own name, in many cases you become the provider. That's not a formality โ€” it changes your to-do list.

What you actually have to do

1. The bot must identify itself, at first interaction

The obligation is simple: the person must know they're talking to an AI no later than the first interaction. There is an exception โ€” where it's "obvious to a reasonably well-informed, observant and circumspect person" โ€” but don't lean on obviousness. A modern chatbot, well written, with a human name and fluent answers, is not obvious to a lot of users.

In practice: one line in the welcome message, or a persistent label in the chat header. You don't need a legal pop-up that kills conversion. You need it clear, visible, and present before the user types.

What does not count: putting it only in the privacy policy, hiding it in a tooltip, or trusting that "the avatar makes it clear".

2. Mark generated outputs

If your system produces synthetic content โ€” text, images, audio, video โ€” outputs must be marked machine-readably as artificially generated or manipulated. The regulation asks for solutions that are "effective, interoperable, robust and reliable as far as technically feasible": in practice signed metadata (C2PA / Content Credentials) and, where it makes sense, imperceptible watermarks.

There's some breathing room here: generative AI systems already placed on the market have until 2 December 2026. New ones must be born compliant on 2 August.

3. Deepfakes and public-interest content

If you publish manipulated images or video that look real, you must disclose it. Same for text published to inform the public on matters of public interest: the exemption exists but is narrow โ€” it requires human review with editorial responsibility over that content. "A tool checks it" is not review.

4. AI literacy for your staff (Art. 4)

Frequently overlooked, and already applicable since February 2025: organizations deploying AI systems must ensure a sufficient level of AI literacy among the staff who operate them. No master's degree required โ€” just make sure whoever runs the bot knows what it can and cannot do, how escalation to a human works, and what data must never be fed into it.

What is NOT landing on 2 August (and why everyone's confused)

The Digital Omnibus reshuffled the calendar and left a lot of noise. To be clear:

  • Postponed: obligations for Annex III high-risk systems move to 2 December 2027.
  • Not postponed: Article 50. Chatbot transparency, synthetic content marking, deepfakes. It applies on 2 August 2026, and from that day national market surveillance authorities can act.
  • Code of Practice on transparency: published 10 June 2026, voluntary, granting a presumption of conformity to signatories. The window to sign with maximum benefit closed on 22 July 2026 โ€” but the Code remains the most concrete map of what "marking properly" means technically.

An e-commerce support chatbot is not a high-risk system in itself. Don't misread that: not being high-risk doesn't exempt you from transparency. They're two separate tracks.

The operational checklist (one day of work)

  1. Inventory. List every point where AI talks to a human or produces published content: site, WhatsApp, Telegram, automated emails, product descriptions, generated images.
  2. Role. For each one, decide whether you're provider or deployer. If you rebranded a third-party product, check the contract.
  3. Disclosure. Add the "AI assistant" statement to the first message and as a persistent label. In every language you operate in.
  4. Human escalation. Not strictly required by Article 50, but the natural complement to transparency: declaring you're an AI without offering a way out to a person is compliance that annoys customers. I wrote about it here.
  5. Marking. Check with your generative AI vendor what they already mark (metadata, Content Credentials) and what you must add yourself.
  6. Document. If you rely on the "obvious" exception, write down your reasoning. Under scrutiny, the written trail is what makes the difference.
  7. Train the team. Half a day of written guidance on what the bot does, when a human steps in, which data never gets typed in.

My take, as someone who builds these bots

I've spent the last year building AI assistants for e-commerce, and transparency has never cost me a conversion. The opposite: in projects where the bot openly says "I'm a virtual assistant, I can hand you to a person if you prefer", users trust it more, not less. Trust breaks when someone finds out on their own that they were talking to a machine while believing otherwise.

On this specific point, the AI Act is writing into law something that was already good commercial practice. There are parts of the AI Act worth arguing about. This is the cheapest and the most sensible one.

Note: this is a technical analysis from someone who implements these systems, not legal advice. For edge cases โ€” especially if you rebrand third-party products or generate content on matters of public interest โ€” work with a specialized lawyer.

FAQ

Is my e-commerce chatbot a "high-risk" system?

Almost certainly not. An assistant answering about products, orders and shipping doesn't fall into the Annex III high-risk categories. It's still subject to the Article 50 transparency obligations, which are a separate track and apply from 2 August 2026.

Is putting it in the privacy policy enough?

No. The obligation is to inform the user no later than the first interaction, meaning inside the conversation experience. The privacy policy is a different obligation (GDPR) and does not satisfy Article 50.

What do I actually risk if I do nothing?

Breaching Article 50 is punishable by up to โ‚ฌ15 million or 3% of global annual turnover, whichever is higher, enforced by national market surveillance authorities. For an SME the realistic near-term risk isn't the maximum fine but a complaint, an inquiry and the time it eats โ€” against a fix that takes a few hours.

If I use a third-party chatbot, is compliance their problem?

Partly. The vendor answers as provider for how the system is designed; you answer as deployer for how you use it. And if you rebrand it under your own name, the provider role often shifts to you. Ask your vendor for a written statement of what they cover.

Does it apply if my company is outside the EU?

Yes, if the system or its output is used in the Union. The AI Act has extraterritorial reach, like the GDPR: what matters is where your users are, not where the company is registered.


If you have a chatbot in production and want disclosure, human escalation and traceability sorted before 2 August, get in touch. ShopBrain ships with AI disclosure and human handoff built in โ€” because these are things you design, not things you patch on a deadline.

AIE-commerceChatbotCompliance

Scritto da Giulio Garofalo