Skip to content
noema.
Compliance

The EU AI Act: what it requires if you run a chatbot or a voice agent

If you have a chatbot on your site or an agent answering the phone, one date matters: 2 August 2026. That's when the transparency obligations of the EU AI Regulation start to apply. The good news is that for a business serving its own customers, the obligation is far smaller than it sounds.

The date and the rule, plainly

The rule is Regulation (EU) 2024/1689, known as the AI Act. You don't need to read it: if you serve customers with AI, the part that affects you is Article 50, and its obligations apply from 2 August 2026.

It isn't a Spanish or Catalan law: it's an EU regulation, directly applicable in every member state. There's no pending transposition and no national wiggle room on the dates.

Regulation (EU) 2024/1689 dates that matter to a business serving customers with AI.
DateWhat happens
2 August 2026The Article 50 transparency obligations become applicable.
2 December 2026End of the Article 50(2) transitional period (marking AI-generated content) for systems already on the market before 2 August 2026.
Article 50 penaltiesUp to EUR 15 million or 3% of worldwide annual turnover, whichever is higher.

The actual obligation: make it known it's an AI

Article 50(1) says, in essence, that whoever puts into service an AI system intended to interact directly with people must ensure those people know they are interacting with an AI, unless it's obvious from the context.

Translated to your front desk: one sentence in the first reply. "I'm the virtual assistant at Clinic X" satisfies it. No form, no checkbox, no separate legal notice. What does not satisfy it is passing the agent off as a named human and letting the customer find out on their own.

In practice this doesn't hurt conversion: people are fine talking to an AI if it resolves what they need quickly. We cover it in human receptionist or AI.

What the Regulation does NOT say

It doesn't prohibit serving customers with AI, and it requires no prior authorisation or registration to do so. An agent that books appointments or answers FAQs is not a high-risk system merely because it answers the phone.

It does provide for substantial penalties for breaching Article 50 — up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. Those figures are designed for large platforms, but the transparency obligation applies equally to a clinic in Vic and to a multinational. The difference is that complying costs you a sentence.

The AI Act and the GDPR are two separate layers

This is the most common mistake: assuming that if GDPR is handled, the AI Act is covered. They're independent layers. The AI Act governs transparency about the nature of the system (knowing you're talking to a machine). The GDPR governs the processing of the personal data that conversation generates: legal basis, minimisation, retention periods, processors.

If you serve patients, GDPR is the demanding layer of the two, because health data is involved. We break it down in AI and GDPR: can you use AI with patient data?.

A four-point checklist before 2 August

1. Your chatbot or voice agent identifies itself as AI on first interaction.

2. There's a clear path to reach a human when the customer asks.

3. You have documented which model provider you use and where the data is processed (that's GDPR, but you'll be asked for both together).

4. If the agent generates audio with a synthetic voice, the customer knows it's synthetic. For sensitive data, keeping only the transcript and not the audio is the prudent call: voice is a biometric identifier.

Frequently asked questions

When does the EU AI Act start applying to a chatbot?

The Article 50 transparency obligations apply from 2 August 2026. That's the date affecting any business serving customers with a chatbot or a voice agent.

Do I have to tell customers they are talking to an AI?

Yes, unless it's obvious from the context. In practice one sentence in the first reply satisfies it: “I'm the virtual assistant at Clinic X”. No form, no checkbox.

Is an AI receptionist a high-risk system?

Not merely because it answers the phone or WhatsApp and manages appointments. The obligations that apply are the Article 50 transparency ones, not the high-risk regime.

If we already comply with GDPR, are we covered?

No: they're independent layers. The AI Act governs transparency about the nature of the system; the GDPR governs the processing of the personal data the conversation generates. Both need solving.

Want to check whether your setup complies?

We'll go through transparency, legal basis and where your agent's data lives. No small print.

Free demo