EU AI Act

Are AI Chatbots High-Risk Under EU AI Act?

Practical classification guide for conversational AI: intended purpose, Article 50 transparency, exact Annex III uses, and Article 6 analysis.

12 min read 2,200+ words
Joe Braidwood
Joe Braidwood
CEO, GLACIS
12 min read

Quick Answer: It Depends on Use Case

Most customer-service and FAQ chatbots are not high-risk solely because they are conversational. Article 50 may still require disclosure that a person is interacting with AI. A chatbot becomes HIGH-RISK only when its intended purpose falls within an exact Annex III use or it satisfies the Article 6(1) product pathway; medical, legal, or financial subject matter is not a catchall classification rule.

Classification depends on intended purpose and regulatory pathway, not the model brand. A customer-service bot handling return policies is ordinarily outside the listed high-risk uses. Diagnostic recommendations require medical-device and Article 6 analysis; the feature label alone does not settle classification.

Art. 50
Transparency Rule
Dec 2027
Relevant Annex III High-Risk Date
€15M
Max High-Risk Fine
€15M
Transparency Fine

In This Guide

When Chatbots May Fall Outside High-Risk Routes

A conversational interface alone does not determine EU AI Act classification. Many routine chatbots may fall outside high-risk routes while still triggering Article 50 transparency duties, but the result depends on intended purpose, operator role, applicable exceptions, and Article 6.

General Customer Service Chatbots

Customer service chatbots handling routine inquiries may remain outside high-risk routes when they:

FAQ and Information Bots

Chatbots providing general information may remain outside high-risk routes when they serve as interactive knowledge bases rather than performing a listed use. Examples include:

Entertainment Chatbots

AI companions, creative-writing assistants, gaming NPCs, and entertainment-focused conversational AI are not categorically classified by those labels. Analyze the actual intended purpose, user population, decision authority, prohibited-practice triggers, Article 50 duties, and any Annex III or Annex I pathway.

When Chatbots Become High-Risk

A chatbot can be high-risk when its intended purpose matches a use specifically listed in Annex III (subject to Article 6) or when it satisfies the separate Annex I product pathway. Consequence alone is not a catchall classification rule; the exact actor, purpose, decision and system boundary matter.

Healthcare chatbots: check the exact pathway

Healthcare chatbots are not automatically high-risk. A system used for emergency healthcare patient triage may fall within Annex III 5(d). A system used by or on behalf of a public authority to decide eligibility for essential public assistance, including healthcare services, may fall within 5(a). Diagnostic or treatment software may instead require Article 6(1) analysis under medical-device law.

Appointment scheduling and clinic-information bots normally remain outside those high-risk categories. Clinical judgment is a reason to examine product law and intended purpose, not an automatic Annex III trigger.

Legal chatbots: advice is not the Annex III trigger

Annex III 8(a) is narrower than “legal advice”: it covers AI intended for use by or on behalf of a judicial authority to research and interpret facts and law and apply law to concrete facts, or similar use in alternative dispute resolution. General legal-information, drafting, or law-firm tools are not automatically within that category, although other rules and professional duties may apply.

Legal-strategy, drafting, rights-information, and immigration-guidance chatbots can carry serious professional, consumer-protection, or sector risks. They are not high-risk under Annex III 8(a) merely for giving legal information or advice. Separately analyze any use by or on behalf of a judicial authority or alternative-dispute-resolution body, and the distinct Annex III entries for migration, asylum, and border control.

Financial Advice Chatbots

Annex III lists two specific private financial uses: evaluating a natural person’s creditworthiness or credit score in point 5(b), excluding AI used to detect financial fraud; and risk assessment or pricing for natural persons in life and health insurance in point 5(c). Investment advice, property-and-casualty insurance, claims handling, and account fraud controls are not automatically high-risk under those points.

Chatbots Making Consequential Decisions

There is no free-standing “consequential chatbot” category. The following conversational interfaces can be high-risk when they perform the listed underlying use, not merely because they discuss the subject:

Key Determining Factors

When classifying your chatbot, evaluate these critical factors:

Factor Often outside Annex III Potential high-risk route: apply Article 6
Purpose Information, navigation, or entertainment without a listed decision use An exact Annex III intended use or an Annex I product/safety-component pathway
Domain Domain alone is not determinative A regulated domain combined with the exact listed actor, purpose, or decision
Decision Authority No listed decision function; any human role is genuine and documented Makes or materially influences a decision within an applicable listed use
Impact Convenience, efficiency, engagement Rights, health, financial status, opportunities
Reversibility Easily corrected or inconsequential Difficult to reverse or significant consequences

Article 50 Transparency Requirements

Article 50(1) generally requires providers of systems intended to interact directly with natural persons to design them so people are informed they are interacting with AI. The disclosure is not required where this is obvious to a reasonably well-informed, observant, and circumspect person, and the Act contains a targeted law-enforcement exception subject to safeguards.

Core Disclosure Requirements

Article 50(1) Requirements

  • Clear notification that the user is interacting with an AI system
  • Timely disclosure: at the start of interaction, not buried in terms
  • Accessible format: understandable language, appropriate for audience
  • Exception: Only when “obvious from the circumstances and context of use”

Implementation Best Practices

Effective transparency disclosure typically includes:

Penalty for non-compliance: Article 50 transparency violations fall within Article 99’s general operator tier, up to €15 million or 3% of worldwide annual turnover. For undertakings other than SMEs, the higher applicable ceiling is used; for SMEs, including startups, Article 99 applies the lower applicable fixed or percentage ceiling. The €7.5 million or 1% tier applies to incorrect, incomplete, or misleading information supplied in response to a request from a notified body or competent authority.

Additional Requirements for High-Risk Chatbots

High-risk chatbots must satisfy Articles 8-15 requirements in addition to transparency obligations. This represents a substantial compliance burden requiring dedicated resources.

Article 9: Risk Management

Continuous risk management system throughout the chatbot’s lifecycle. Identify foreseeable risks, estimate probability and severity, implement mitigation measures, and document residual risks.

Article 10: Data Governance

Ensure training, validation, and testing data is relevant, sufficiently representative and, to the best extent possible, free of errors and complete in view of the intended purpose. Document data provenance, preparation processes, and bias examination.

Article 13: Transparency

Design for transparency enabling deployers to interpret outputs and use the system appropriately. Provide instructions for use including intended purpose, capabilities, and limitations.

Article 14: Human Oversight

Enable effective human oversight including ability to understand capabilities, monitor operation, interpret outputs, override or interrupt, and prevent automation bias.

Article 12 Logging Requirements

High-risk chatbots face stringent logging requirements under Article 12. Logs must enable post-market monitoring, incident investigation, and regulatory inspection.

Required Log Elements

Retention Requirements

Deployers generally keep automatically generated logs under their control for a period appropriate to the system’s intended purpose and at least six months, unless other applicable Union or national law provides otherwise. Medical-record, financial-services, employment, privacy, or litigation-hold rules can require a different schedule. Cryptographic integrity controls may strengthen selected records, but Article 12 does not prescribe them.

Deepfake and Synthetic Content Rules

Article 50(4) addresses AI-generated synthetic content, which is relevant for chatbots producing audio, video, or images.

When Deepfake Rules Apply

Your chatbot triggers synthetic content disclosure requirements if it:

Text-only chatbots typically don’t trigger deepfake rules. However, multimodal AI assistants with voice or video capabilities require clear labeling that content is artificially generated or manipulated.

US Regulatory Comparison

The United States lacks comprehensive federal AI chatbot regulation comparable to the EU AI Act. However, a patchwork of existing and emerging laws applies.

Colorado (SB 26-189)

Colorado’s 2024 AI Act (SB 24-205) was repealed and replaced by SB 26-189, “Automated Decision-Making Technology,” signed May 14, 2026, with substantive compliance beginning January 1, 2027. It regulates covered automated decision-making technology (ADMT) used to materially influence a consequential decision (in education, employment, housing, financial or lending services, insurance, health-care services, and essential government services) through pre-use notice, post-adverse-outcome disclosure, and consumer rights to data correction and human review. The earlier reasonable-care duty against algorithmic discrimination, mandatory impact assessments, and risk-management programs were not carried over.

FTC Act Section 5

Prohibits unfair or deceptive practices. Undisclosed AI interactions may constitute deception. FTC has signaled aggressive enforcement against “dark patterns” and hidden AI use, particularly in contexts where consumers expect human interaction.

FDA Oversight

Medical chatbots providing diagnostic or treatment recommendations may qualify as medical devices requiring FDA clearance or approval. Clinical decision support software guidance applies. 510(k) or De Novo pathway may be required.

State Consumer Protection Laws

California Bot Disclosure Law (SB 1001) requires bots to disclose their non-human nature when selling products or influencing votes. Similar laws emerging in other states. CCPA/CPRA may apply to data collected by chatbots.

Evidence Requirements

Demonstrating compliance requires more than policies. You need evidence that controls actually function. For chatbot compliance, prepare:

Where Article 50 or Other Disclosure Duties Apply

High-Risk Chatbots (Additional)

Implementation Checklist

Compliance Checklist

Chatbot EU AI Act Compliance

1

Classification Assessment

  • ☐ Document chatbot’s intended purpose and use cases
  • ☐ Evaluate against Annex III high-risk categories
  • ☐ Assess decision-making authority and impact
  • ☐ Document classification rationale
2

Transparency Implementation

  • ☐ Add AI disclosure at conversation start
  • ☐ Implement visual indicators (icons, labels)
  • ☐ Create human handoff disclosure
  • ☐ Test disclosure visibility and comprehension
3

High-Risk: Technical Controls

  • ☐ Implement Article 12 compliant logging
  • ☐ Establish log retention and integrity controls
  • ☐ Build human oversight mechanisms
  • ☐ Implement override and interrupt capabilities
4

High-Risk: Documentation

  • ☐ Complete risk management documentation
  • ☐ Document data governance practices
  • ☐ Prepare technical documentation (Annex IV)
  • ☐ Establish quality management system
5

High-Risk: Conformity Assessment

  • ☐ Determine assessment pathway (internal vs. notified body)
  • ☐ Prepare EU declaration of conformity
  • ☐ Register in EU database (when available)
  • ☐ Implement post-market monitoring

Frequently Asked Questions

My chatbot uses ChatGPT/Claude. Am I the provider or deployer?

Your role depends on what you develop, place on the market or put into service, whose name or trademark is used, and whether you make a substantial modification or change the intended purpose. Integrating a GPAI model into a regulated use case does not by itself answer the provider/deployer question. Map the actual supply chain and Article 25 role transitions with counsel.

What if my chatbot just routes to humans for important decisions?

Routing alone does not determine classification. Collection followed by genuine human decision-making may support an Article 6(3) analysis, but influence or consequence does not create a new high-risk category. Test the exact intended purpose against Article 6, Annex III, and any applicable Annex I product law.

Do internal employee chatbots need to comply?

Internal use is not automatically outside the Act, but classification still turns on intended purpose. A system used to screen candidates or make employment decisions can fall within Annex III; a benefits-information or IT-helpdesk chatbot is not automatically high-risk. Apply the same system-specific role, scope, and exclusion analysis.

What’s the timeline for chatbot compliance?

Article 50 transparency requirements have applied since August 2, 2026 to covered systems that interact directly with people, subject to the Article’s scope and exceptions. A chatbot is not automatically high-risk; if its intended use falls within Annex III, relevant high-risk obligations apply from December 2, 2027 under the AI Omnibus. Confirm classification and disclosure duties for the specific workflow.

Can I add disclaimers to avoid high-risk classification?

A disclaimer does not change the system’s intended purpose or regulatory pathway. Classification depends on what the system is intended and used to do, the operator role, and the exact Article 6 route. Clear limitations and redirection may still matter to risk management and consumer-protection analysis, but they are not a classification shortcut.

Do voice-enabled chatbots have additional requirements?

Voice chatbots must still disclose AI nature. Audio disclosure is acceptable. If the voice is synthesized to resemble a specific person or could be mistaken for authentic human speech, Article 50(4) deepfake provisions may apply. Ensure clear AI identification in voice interactions, particularly at the start of calls.

Make the chatbot workflow reviewable

For configured events, GLACIS can preserve signed records of the disclosure, control claim, and recorded outcome. Those records support review; they do not prove control effectiveness, establish compliance, or guarantee acceptance by an auditor or regulator.

Talk to us

Related Guides