An AI chat on a business website is the most commonly deployed integration today, and also the one where it is easiest to forget about the law. Right now it is worth remembering twice over: on 2 August 2026 the AI Act's transparency provisions start to apply, and they concern every chatbot that talks to customers. On top of that sits the GDPR, which has applied to customer conversations all along. Below is a practical guide: what must be in place before a chat starts speaking on behalf of your business.
Why this matters right now
The EU Artificial Intelligence Act comes into force in stages, and on 2 August 2026 its Article 50 - the transparency obligations - starts to apply. In short: a person must know they are talking to a machine, at the latest at the first interaction. Breaches of the transparency rules carry fines of up to 15 million euros or 3 percent of worldwide turnover. For a small business the bigger risk in practice is losing customer trust, but the scale shows the topic is taken seriously. In June 2026 the European Commission also published a voluntary code of practice that helps meet these obligations.
The good news: for an honestly deployed company chat this is no revolution. Most of the duties come down to things worth doing anyway: do not pretend to be human, do not hoard data, keep your paperwork in order.
GDPR in chat conversations: five duties
A chat that collects contact details or discusses a customer's matters processes personal data. That means familiar duties, just in a new place:
- The information duty. The customer must know who controls their data and why it is collected. In practice: an updated privacy policy and clear information at the chat.
- Legal basis and consent. When the chat collects contact details to pass to the company, the person must consent knowingly, not "by the way".
- Data minimisation. The chat collects only what is needed to make contact. A name and a phone number or e-mail are enough; there is no reason to ask for more.
- Contracts with providers. Behind the chat stands a technology provider that technically processes conversation data. A data processing agreement is needed, and with providers outside the European Economic Area, additional legal safeguards. It is paperwork you handle once, at deployment.
- Retention and people's rights. Conversation logs cannot sit forever: you decide how long they are kept and how to handle a deletion request.
The AI Act: a chatbot must introduce itself
The new part from August 2026 is easy to remember: a chatbot must not pretend to be human. The user must be informed they are interacting with artificial intelligence, at the latest at the moment of the first interaction. In practice two things settle it: a name and description that plainly indicate an AI assistant, and a welcome message that says it clearly in the first line.
The same Article 50 also puts obligations on AI-generated content: it must be marked in a machine-readable way, and content impersonating real people or events (deep fakes) must be openly disclosed. For a typical business with a chat on its site, though, the key duty is the first one: introducing itself.
A practical note: this requirement aligns with sales common sense. Customers do not mind talking to AI; they mind being deceived. A chat that honestly says "I am an AI assistant" builds trust instead of gambling with it.
What a good deployment looks like
In the deployments we run, compliance is not a separate project but part of the standard: the chat introduces itself as an AI assistant from the first message, collects consent for contact explicitly, gathers only the data needed to get in touch, and conversations are handled in commercial services where company data does not feed public models. Add to that the entries in the privacy policy and an agreed retention period for conversation logs. You will find the service details under AI chat for business and the broader picture on AI for business.
Disclaimer: we are an implementation company, not a law firm. This post is a practical guide to the duties, not legal advice - in non-standard situations (special categories of data, regulated industries) consult a lawyer or a data protection officer.
In short
The law around chatbots fits in three sentences: do not pretend to be human, do not hoard data, keep your paperwork in order. From 2 August 2026 the first of these stops being good practice and becomes an obligation. If you already have a chat on your site or plan a deployment and want to be sure everything is in place, write to us - we will check it while talking about the chat itself.