Your Chatbot May Already Be Breaking EU AI Law
On August 2, 2026, a rule most businesses haven't heard of came into force across the EU — and it applies to any company running a chatbot, sending AI-drafted follow-ups, or publishing AI-generated content. Here's what changed, who it affects, and three steps to fix it in a week.
Short answer
Since August 2, 2026, any business using a chatbot, voice assistant, or AI-generated content must clearly tell users they're interacting with AI — this comes from Article 50 of the EU AI Act, and it applies identically across all 27 member states. Poland's national enforcement law, which set up a market surveillance authority (KRiBSI), took effect on August 11, 2026, but its power to actually issue fines only starts on October 28, 2026. For most SMEs, this isn't a compliance overhaul. It's one clear obligation to build into your customer-facing systems.
Two rules — don't confuse them
Coverage tends to blur two separate things into one "new AI law." They matter to you on very different timelines.
National enforcement law — oversight and fines
Poland is a useful example of what every EU member state has to do. Its parliament finished work on the law on July 3, 2026, the president signed it on July 24, and it entered into force on August 11, 2026. The law doesn't add new substantive AI rules — those already apply directly from the EU regulation. Its job is to build the national enforcement machinery: Poland's version created the Commission for AI Development and Safety (KRiBSI), which will take complaints, run inspections, and issue fines. Every EU country has to stand up its own version of this body — the details differ, the underlying obligation doesn't.
How this affects you today: barely, yet. Poland's authority is still forming — a chair is expected by October, a full commission by November 2026. But the obligations coming from the EU regulation itself apply regardless of whether your country's enforcement body is fully staffed.
Article 50 — the actual disclosure obligation
This is the part that matters right now, everywhere in the EU. Since August 2, 2026, any AI system designed for direct interaction with people must be built so that the person knows they're dealing with a machine — unless it's obvious from context. This covers text chatbots, phone voicebots, and messaging assistants. The second part covers content: material generated or substantially modified by AI — especially anything that could pass as an authentic record of reality — should be labeled in a detectable way.
One important detail: providers of systems placed on the market before August 2, 2026 have until December 2, 2026 to meet the technical content-labeling requirement. That grace period does not apply to the core duty of telling users they're talking to AI — that one applies from day one.
Who this actually affects
Not just tech companies. The rule is written broadly and deliberately covers any business using AI in customer contact or in content published externally.
The exception covers situations obvious from context, and tools that don't create or alter content — spam filters, machine translation, recommendation systems.
What to do about it
Four steps. None of them require switching the tools you already use.
List every point where AI touches a customer
Website chatbot, automated emails, marketing content, complaint handling. A notepad is enough — the point is not to miss anything.
Add a clear line at the start of the interaction
One sentence, up front, not buried in terms and conditions: "You're chatting with an AI assistant. You can ask to speak with a human at any time."
Label AI-generated content
Images, graphics, and video created or substantially altered by AI should carry a detectable label — the European Commission's July 2026 guidelines spell out the technical detail.
Put it in writing with your contractors
If an agency or freelancer runs AI on your behalf, your contract should say who is responsible for informing the customer, and how.
How much risk is this, really
The maximum fines under the AI Act are large: up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for other key violations, up to €7.5 million or 1% for misleading a regulator. SMEs generally get the lower of the applicable thresholds. These numbers are written for large, systemic breaches — not for a small business that forgot to add one sentence to a chat window.
More practically relevant: enforcement timelines vary by member state, since each country had to build its own authority from scratch. Poland's KRiBSI won't be issuing fines until October 28, 2026. The Act also requires every member state to offer a regulatory sandbox — a supervised environment for testing AI solutions — and access must be free for micro, small, and medium businesses. Poland's version is a working example; check whether your own country's authority offers an equivalent request-for-guidance mechanism before assuming you have to figure this out alone.
Sources: Poland's Ministry of Digital Affairs and the Gov.pl portal (announcement on the signing of the law, July 2026), Polish Journal of Laws (Dziennik Ustaw) item 1003/2026, European Commission guidelines on Article 50 AI Act, July 20, 2026.
Beyond the EU: the bigger picture
The EU AI Act is currently the most comprehensive AI-specific regulation in force anywhere in the world, and — much like GDPR before it — its reach isn't limited to companies headquartered in the EU. If your business serves users inside the EU, Article 50's disclosure duty applies to you regardless of where your company is based.
Outside the EU, the picture is far less unified. The UK has so far favored a lighter-touch, sector-by-sector approach rather than one AI-specific statute. Several U.S. states have passed narrower disclosure or bias-testing requirements instead of a single federal law. Other jurisdictions are still drafting their first AI-specific legislation. If you only sell into the EU, the AI Act is your one reference point. If you operate more broadly, it's reasonable to treat the EU rule as the strictest baseline: build to it, and you'll be close to compliant almost everywhere else, with only minor local adjustments.
A system, not a last-minute patch
Businesses that bolted on a chatbot as an off-the-shelf plugin are now scrambling to figure out where to add one sentence about AI — and, often, where in the business AI even touches a customer in the first place. A business with a properly designed customer service system, rather than a set of disconnected tools, already has this solved: it's clear where the system talks to customers, how escalation to a human works, and where the documentation lives if anyone asks. The difference between a system and a plugin isn't cosmetic — it shows up exactly in moments like this one.
Frequently asked questions
Yes. Company size doesn't matter — what matters is whether the system is communicating with people on the business's behalf. The only exception is a situation where it's obvious from context that no reasonable user would think they're talking to a human.
In most cases, no. Registration requirements apply mainly to high-risk systems, such as those used in hiring or credit scoring. An ordinary customer-service chatbot usually doesn't need to be registered — it just needs to clearly tell the user what it is.
This is one of the genuinely ambiguous cases in the regulation — a lot depends on how substantial the AI's contribution is and whether a human is actually editing the content, not just clicking publish. If you use generative AI in content regularly, it's worth getting a specific answer from a lawyer rather than guessing.
It depends on whether the content is generated or substantially modified by AI, and whether it could pass as fully human-written. Routine, transactional messages sit in a different category than content published for public consumption — in practice, it's safer to add a short line than to assume you're exempt.
No. This is general information meant to help you get oriented and plan first steps. A proper compliance assessment for your specific business — especially in ambiguous cases — should come from a lawyer who specializes in the EU AI Act.
Nothing immediately — most national enforcement bodies are still standing up, and fines typically won't start until later in 2026 (Poland's begin October 28, for example). But the disclosure duty itself has applied since August 2, so it's cheaper to fix now, while it's a one-line addition to your interface, than after someone files a complaint.
The substantive obligation in Article 50 is identical across the EU — it's a regulation, not a directive, so it applies directly without being rewritten into national law. What differs by country is who enforces it and when their enforcement body becomes fully operational.
Check Whether Your Customer Service System Is Ready
30 minutes, an online call, no obligation. We'll review where AI touches your customers and what's worth adding — so it looks like part of the system, not a legal notice bolted on afterward. This isn't legal advice — it's a systems review.
Book a free consultation →