What We Automate
Pricing About
Resources
Contact Book a consultation →
PLENUA
AI Regulation

Your Chatbot May Already Be Breaking EU AI Law

On August 2, 2026, a rule most businesses haven't heard of came into force across the EU — and it applies to any company running a chatbot, sending AI-drafted follow-ups, or publishing AI-generated content. Here's what changed, who it affects, and three steps to fix it in a week.

Andrzej Lubczyński··7 min read

Short answer

Since August 2, 2026, any business using a chatbot, voice assistant, or AI-generated content must clearly tell users they're interacting with AI — this comes from Article 50 of the EU AI Act, and it applies identically across all 27 member states. Poland's national enforcement law, which set up a market surveillance authority (KRiBSI), took effect on August 11, 2026, but its power to actually issue fines only starts on October 28, 2026. For most SMEs, this isn't a compliance overhaul. It's one clear obligation to build into your customer-facing systems.

Two rules — don't confuse them

Coverage tends to blur two separate things into one "new AI law." They matter to you on very different timelines.

A diagram comparing the Polish AI systems act (supervision and penalties) with Article 50 of the EU AI Act (the duty to inform clients).
Two different rules with two different dates. The one that binds you today is on the right.

National enforcement law — oversight and fines

Poland is a useful example of what every EU member state has to do. Its parliament finished work on the law on July 3, 2026, the president signed it on July 24, and it entered into force on August 11, 2026. The law doesn't add new substantive AI rules — those already apply directly from the EU regulation. Its job is to build the national enforcement machinery: Poland's version created the Commission for AI Development and Safety (KRiBSI), which will take complaints, run inspections, and issue fines. Every EU country has to stand up its own version of this body — the details differ, the underlying obligation doesn't.

How this affects you today: barely, yet. Poland's authority is still forming — a chair is expected by October, a full commission by November 2026. But the obligations coming from the EU regulation itself apply regardless of whether your country's enforcement body is fully staffed.

Article 50 — the actual disclosure obligation

This is the part that matters right now, everywhere in the EU. Since August 2, 2026, any AI system designed for direct interaction with people must be built so that the person knows they're dealing with a machine — unless it's obvious from context. This covers text chatbots, phone voicebots, and messaging assistants. The second part covers content: material generated or substantially modified by AI — especially anything that could pass as an authentic record of reality — should be labeled in a detectable way.

One important detail: providers of systems placed on the market before August 2, 2026 have until December 2, 2026 to meet the technical content-labeling requirement. That grace period does not apply to the core duty of telling users they're talking to AI — that one applies from day one.

Who this actually affects

Not just tech companies. The rule is written broadly and deliberately covers any business using AI in customer contact or in content published externally.

Four typical points of contact between a company and its clients where AI operates and disclosure is required.
It is not about one tool — it is about every point where a client talks to AI without knowing it.
You have a chatbot or voicebot on your website, in Messenger, or on a phone line — whether it's a €10-a-month off-the-shelf tool or a custom-built system.
You send automated first replies to leads written by AI, especially if they read like they came from a team member.
You publish AI-generated content — product photos, graphics, video — especially where it could pass as authentic.
You use emotion recognition or biometric categorization on customers — these systems have carried extra restrictions since February 2025.
You outsource AI work to an agency or freelancer — responsibility usually stays with your business as the "deployer" under the Act, regardless of who built the tool.

The exception covers situations obvious from context, and tools that don't create or alter content — spam filters, machine translation, recommendation systems.

What to do about it

Four steps. None of them require switching the tools you already use.

1

List every point where AI touches a customer

Website chatbot, automated emails, marketing content, complaint handling. A notepad is enough — the point is not to miss anything.

2

Add a clear line at the start of the interaction

One sentence, up front, not buried in terms and conditions: "You're chatting with an AI assistant. You can ask to speak with a human at any time."

3

Label AI-generated content

Images, graphics, and video created or substantially altered by AI should carry a detectable label — the European Commission's July 2026 guidelines spell out the technical detail.

4

Put it in writing with your contractors

If an agency or freelancer runs AI on your behalf, your contract should say who is responsible for informing the customer, and how.

How much risk is this, really

The maximum fines under the AI Act are large: up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for other key violations, up to €7.5 million or 1% for misleading a regulator. SMEs generally get the lower of the applicable thresholds. These numbers are written for large, systemic breaches — not for a small business that forgot to add one sentence to a chat window.

More practically relevant: enforcement timelines vary by member state, since each country had to build its own authority from scratch. Poland's KRiBSI won't be issuing fines until October 28, 2026. The Act also requires every member state to offer a regulatory sandbox — a supervised environment for testing AI solutions — and access must be free for micro, small, and medium businesses. Poland's version is a working example; check whether your own country's authority offers an equivalent request-for-guidance mechanism before assuming you have to figure this out alone.

Sources: Poland's Ministry of Digital Affairs and the Gov.pl portal (announcement on the signing of the law, July 2026), Polish Journal of Laws (Dziennik Ustaw) item 1003/2026, European Commission guidelines on Article 50 AI Act, July 20, 2026.

Beyond the EU: the bigger picture

The EU AI Act is currently the most comprehensive AI-specific regulation in force anywhere in the world, and — much like GDPR before it — its reach isn't limited to companies headquartered in the EU. If your business serves users inside the EU, Article 50's disclosure duty applies to you regardless of where your company is based.

Outside the EU, the picture is far less unified. The UK has so far favored a lighter-touch, sector-by-sector approach rather than one AI-specific statute. Several U.S. states have passed narrower disclosure or bias-testing requirements instead of a single federal law. Other jurisdictions are still drafting their first AI-specific legislation. If you only sell into the EU, the AI Act is your one reference point. If you operate more broadly, it's reasonable to treat the EU rule as the strictest baseline: build to it, and you'll be close to compliant almost everywhere else, with only minor local adjustments.

A system, not a last-minute patch

Businesses that bolted on a chatbot as an off-the-shelf plugin are now scrambling to figure out where to add one sentence about AI — and, often, where in the business AI even touches a customer in the first place. A business with a properly designed customer service system, rather than a set of disconnected tools, already has this solved: it's clear where the system talks to customers, how escalation to a human works, and where the documentation lives if anyone asks. The difference between a system and a plugin isn't cosmetic — it shows up exactly in moments like this one.

Frequently asked questions

Yes. Company size doesn't matter — what matters is whether the system is communicating with people on the business's behalf. The only exception is a situation where it's obvious from context that no reasonable user would think they're talking to a human.

In most cases, no. Registration requirements apply mainly to high-risk systems, such as those used in hiring or credit scoring. An ordinary customer-service chatbot usually doesn't need to be registered — it just needs to clearly tell the user what it is.

This is one of the genuinely ambiguous cases in the regulation — a lot depends on how substantial the AI's contribution is and whether a human is actually editing the content, not just clicking publish. If you use generative AI in content regularly, it's worth getting a specific answer from a lawyer rather than guessing.

It depends on whether the content is generated or substantially modified by AI, and whether it could pass as fully human-written. Routine, transactional messages sit in a different category than content published for public consumption — in practice, it's safer to add a short line than to assume you're exempt.

No. This is general information meant to help you get oriented and plan first steps. A proper compliance assessment for your specific business — especially in ambiguous cases — should come from a lawyer who specializes in the EU AI Act.

Nothing immediately — most national enforcement bodies are still standing up, and fines typically won't start until later in 2026 (Poland's begin October 28, for example). But the disclosure duty itself has applied since August 2, so it's cheaper to fix now, while it's a one-line addition to your interface, than after someone files a complaint.

The substantive obligation in Article 50 is identical across the EU — it's a regulation, not a directive, so it applies directly without being rewritten into national law. What differs by country is who enforces it and when their enforcement body becomes fully operational.

Check Whether Your Customer Service System Is Ready

30 minutes, an online call, no obligation. We'll review where AI touches your customers and what's worth adding — so it looks like part of the system, not a legal notice bolted on afterward. This isn't legal advice — it's a systems review.

Book a free consultation
Andrzej Lubczyński, founder of AIROX
Andrzej Lubczyński

For five years, he built operations at WebWave — from setting up the support desk from scratch to becoming Head of Operations and leading the integration after the company's acquisition. While cleaning up processes, he noticed how much time went into work that helped no one grow — and that the tools to take it over already existed. Graduate of Corporate Finance at SGH Warsaw School of Economics.

LinkedIn profile →