How the EU AI Act Affects AI Chatbots on Your Website

SEO & GEO for WordPress websites

The EU AI Act is now enforcing transparency rules, and if your website uses an AI chatbot, those rules apply to you. Since 2 August 2026, businesses that deploy AI systems interacting directly with users in the EU must comply with Article 50 disclosure obligations, regardless of where the business is based. For SMB leaders who installed a chatbot plugin, connected a third-party customer service bot, or embedded a live chat tool powered by a large language model, this is no longer a future concern. It is a present legal requirement.

The good news is that most website chatbots fall into the lower-risk categories of the EU AI Act, which means the compliance steps are manageable. Understanding where your chatbot sits within the Act’s risk framework, what disclosures you need to make, and what penalties apply for getting it wrong will give you a clear picture of what to do next.

Which chatbot risk category applies to your website

The EU AI Act classifies AI systems into four risk tiers: Unacceptable (prohibited outright), High Risk (heavy compliance obligations), Limited Risk (transparency requirements), and Minimal Risk (no specific obligations). The category that applies to your chatbot depends on what the chatbot actually does, not on the underlying technology powering it.

Most commercial website chatbots sit in the Limited Risk category. A customer service bot that handles return policies, answers FAQs, or guides users through a product catalogue is Limited Risk. The same underlying AI model providing diagnostic health recommendations or screening job applicants would be classified as High Risk. The function drives the classification, not the software vendor.

What makes a chatbot high risk

High-risk chatbot use cases include recruitment and candidate screening, creditworthiness assessments, educational admissions decisions, healthcare triage, and access to public services. In these scenarios, conversational AI can materially influence decisions that affect people’s lives, which is precisely what triggers the heavier obligations under Annex III of the Act.

An HR chatbot screening candidates is High Risk. An IT helpdesk bot resetting passwords is Limited Risk. The practical implication for most SMBs is that their customer-facing chatbot is almost certainly Limited Risk, but it is worth confirming this by reviewing what decisions or recommendations the bot influences, not just how it is marketed by the vendor. One important note: adding a disclaimer like “this is not medical advice” does not change the risk classification. If the chatbot provides medical guidance, the function determines the category.

Transparency obligations for AI chatbots under the EU AI Act

Article 50 of the EU AI Act is the primary transparency article for chatbots, and its obligations took effect on 2 August 2026. The core requirement is straightforward: if an AI system is designed to interact directly with people, those people must be told they are talking to an AI before or at the very start of the conversation.

The disclosure must be clear and distinct. Vague language like “automated assistant” or “virtual helper” does not meet the standard. The user needs to understand, from the first interaction, that they are not speaking with a human. According to the European Commission’s official FAQ on Article 50, a simple introductory message stating the system is AI-powered satisfies this requirement for Limited Risk chatbots. The exception applies only when the AI nature of the system is already obvious from context, which in practice means very few business chatbots qualify for the exemption.

What Article 50 requires beyond the chatbot disclosure

Article 50 covers four distinct obligations. Beyond the chatbot disclosure, providers of generative AI systems must ensure outputs are marked in a machine-readable format as artificially generated. Deployers of emotion recognition or biometric categorisation systems must inform exposed users. And deployers of deepfake systems must disclose that content has been artificially created. For a standard SMB website chatbot, only the first obligation typically applies, but businesses using AI-generated video or audio on their sites should review the full Article 50 scope.

A limited transitional period applies specifically to the machine-readable marking obligation for generative AI systems already on the market before 2 August 2026. Those providers have until 2 December 2026 to comply with that particular requirement. The chatbot disclosure obligation, however, is not deferred.

What counts as a ‘deployer’ and why it matters for SMBs

The EU AI Act distinguishes between providers (the companies that build and market AI systems) and deployers (the businesses that use those systems in a professional context). Article 3(4) defines a deployer as any natural or legal person using an AI system under their authority, except where the system is used for purely personal, non-professional purposes.

The overwhelming majority of SMBs are deployers, not providers. Using a chatbot built by a software vendor, connecting a third-party conversational AI tool, or embedding an AI plugin in WordPress does not make a business an AI provider. It makes them a deployer of someone else’s product, which carries a significantly lighter set of obligations than building and selling AI systems.

What deployers are actually required to do

For most SMB deployers of Limited Risk chatbots, the practical obligations centre on three areas: implementing the Article 50 transparency disclosure, maintaining AI literacy across staff who use or manage AI tools, and keeping basic documentation. The AI literacy requirement under Article 4 has been in force since February 2025 and applies to all businesses. It requires that staff using AI tools have sufficient understanding of how those tools work, including their limitations, to use them appropriately.

Deployers of High Risk AI systems face additional requirements under Article 26, including maintaining interaction logs for at least six months, assigning trained personnel for human oversight, and informing workers before deploying the system. If a business determines its chatbot is High Risk, those obligations apply regardless of company size. The Act does include dedicated SME support measures under Article 62, including priority access to regulatory sandboxes and proportionate conformity assessment fees, but these support measures do not remove the underlying compliance requirements.

Key compliance steps for website chatbots in 2025-2026

Compliance for a website chatbot deployer follows a clear sequence. The starting point is building an accurate inventory of every AI system running on or connected to the website, including third-party tools embedded in CRM platforms, live chat plugins, and marketing automation software. Shadow AI, meaning staff using unauthorised AI tools that feed into customer interactions, is a genuine compliance risk that many businesses underestimate.

Once the inventory is complete, each system needs a risk classification. For most SMBs, this confirms that the customer-facing chatbot is Limited Risk, which means the primary action item is implementing the Article 50 disclosure. A clear introductory message at the start of every chatbot conversation, stating that the user is interacting with an AI, satisfies this requirement.

Practical steps to implement now

  • Audit all AI tools on your website, including plugins, embedded widgets, and third-party integrations.
  • Classify each system by risk tier based on its function, not its branding.
  • Add a clear AI disclosure at the start of every chatbot interaction, visible before the first exchange.
  • Document your AI inventory and the rationale for each risk classification.
  • Ensure staff who manage or interact with AI tools have completed basic AI literacy training.
  • Check whether your chatbot vendor has updated their product to support Article 50 compliance, since some transparency features must be built into the system at the provider level.

If a chatbot handles complaints or makes decisions that affect customer rights, providing a clear path to a human agent is considered best practice and may be required depending on the specific use case. For High Risk chatbots, full compliance, including documentation frameworks, risk management systems, and conformity assessments, typically requires six to twelve months to implement properly. The Digital Omnibus regulation deferred High Risk Annex III obligations to December 2027, but Article 50 transparency requirements were explicitly excluded from that deferral and remain in force now.

Penalties and enforcement: what non-compliance actually costs

Failing to disclose that a chatbot is AI-powered carries a penalty of up to €15 million or 3% of global annual turnover, whichever is higher. This sits in the middle tier of the Act’s three-tier penalty structure under Article 99. The highest tier, reserved for violations of prohibited AI practices, reaches €35 million or 7% of global annual turnover. Providing incorrect information to authorities carries penalties of up to €7.5 million or 1% of turnover.

These figures apply to the most serious cases. The Act requires that penalties consider the interests of SMEs and startups, and fine severity depends on factors including the nature of the violation, company size, and any prior violations. No confirmed enforcement actions specifically targeting website chatbot deployers under Article 50 have been publicly documented as of early August 2026, but enforcement infrastructure is now fully active.

How enforcement actually works

Enforcement responsibility is split between national market surveillance authorities in each of the 27 EU member states and the European AI Office, which oversees general-purpose AI models. National authorities gained full investigatory and enforcement powers on 2 August 2026, including the ability to demand documentation, investigate potential violations, order market withdrawals, and impose fines. The AI Office also launched a complaint tool allowing individuals and organisations to report potential violations directly.

The Act applies extraterritorially. A business based outside the EU that serves EU customers through its website is in scope if the AI system’s output is used in the EU. A UK-based chatbot serving EU visitors falls under the Act’s requirements. Businesses should also check applicable national law alongside EU AI Act compliance, as some member states have introduced additional transparency rules that go beyond the baseline.

How AI-powered SEO content tools differ from regulated chatbots

AI tools that generate content for human review and publication operate under different rules than chatbots that interact directly with users in real time. The EU AI Act does not regulate AI tools as such. It regulates specific AI functions, and the key distinction is whether the AI system is engaging in a genuine two-way exchange with a person or operating in the background to support human-led work.

AI systems running solely in the background, such as keyword research tools, content brief generators, and SEO audit platforms, fall outside the scope of Article 50(1)’s chatbot disclosure obligation. These tools do not interact directly with end users. They support the people using them, and the output goes through human review before it reaches any audience.

When does AI-generated content need a label

Article 50(4) addresses AI-generated text published to inform the public on matters of public interest. But a critical exemption applies: if the content undergoes human editorial review and a specific person or company assumes full editorial responsibility for the publication, the labelling obligation does not apply. According to the European Commission’s Article 50 guidance, this exemption covers AI-assisted writing where a human reviews, edits, and takes responsibility for what is published.

Standard commercial marketing copy and product descriptions may not even meet the “public interest” threshold that triggers Article 50(4) in the first place. The labelling requirement targets content that could be perceived as human-made journalism or public information on topics like financial, political, or scientific developments. For businesses using AI to scale their content production through a workflow that includes human oversight and editorial accountability, the compliance picture is straightforward. The content falls outside the labelling obligation, and the AI tools generating it are not subject to the chatbot disclosure rules.

This is where services like content scaling with human oversight sit in the regulatory picture. When AI-generated content goes through specialist review before publication, and a business takes editorial responsibility for what goes live, the Article 50(4) exemption applies. The compliance burden stays manageable, and the content output remains legally clean. For SMB leaders building their content strategy around AI assistance, understanding this distinction removes a significant source of uncertainty about what the EU AI Act actually requires.

This content was generated with the help of AI and it may contain mistakes

Your customers are asking AI. Are you part of the answer?

In a quick demo, we show how WP SEO AI tracks your AI visibility, finds content gaps, and helps your website appear in ChatGPT, Google AI Overviews and more.

Dive deeper in