From 2 August 2026, a new rule applies to anyone who lets an AI talk to their customers: if you run a chatbot or a phone-based voice agent, you have to disclose at the start of the interaction that an AI is answering. This comes from Article 50 of the EU AI Act — the transparency provision of the European AI regulation. A lot of noise has built up around this date: warning emails, “act now” webinars, and pricey compliance packages. Most of it is overblown. This article separates the two — what's true, what's exaggerated, and what you actually need to do. It's orientation, not legal advice.
The short answer: From 2 August 2026, a chatbot or voice agent has to be clearly identifiable as AI at the start of the interaction — a visible note in the first chat turn, or a spoken sentence at the beginning of a call, is usually enough. Implementing it is a small job. The strict high-risk obligations people keep invoking are a different topic and kick in later. The real cease-and-desist risk doesn't come from the AI Act itself, but from data-protection law — which you should get right anyway.
What actually applies from 2 August 2026
Article 50 of the EU AI Act governs transparency, not prohibitions. Two points hit typical chatbot and voice operators directly. First, a person interacting with an AI system has to be informed of that — unless it's already obvious from the context. In practice: a clear note at the start of the conversation, not at the end and not buried in the legal notice. Second, AI-generated content that gets published has to be marked, in a machine-readable way, as artificially produced.
For the everyday reality of a trades business, a practice, or a small service provider, this mostly means one thing: the chatbot on the website or the phone assistant has to state up front that it's an AI. A line like “You're chatting with an AI assistant” in the first bot turn, or a spoken announcement at the start of a call. For the disclosure itself, that's usually all that's needed.
Timing matters. “At the start of the interaction” really means the beginning — before the user asks or answers the first question — not a note that surfaces after five messages, and certainly not a line you only find if you go digging into the privacy policy. The note also has to be understandable: someone with no technical background should grasp at a glance that they aren't talking to a human. Whether the bot has a human-sounding name or an avatar picture doesn't change the obligation — if anything, the more “human” an assistant feels, the more important the clear statement. There is an exception, but it's narrow: if it's already obvious from the context to a reasonable user that an AI is answering, you don't have to spell it out again. When in doubt, disclose once too often rather than once too rarely — it costs a single sentence.
What's exaggerated — and why
Around the deadline, the disclosure duty tends to get lumped in with the strict obligations for high-risk AI. Those are two different things. High-risk AI — systems in critical infrastructure, in HR scoring, or in official government procedures, for example — is subject to extensive requirements (risk management, documentation, human oversight). But those obligations don't apply in August 2026; they land roughly a year later, around 2027. An ordinary customer chatbot or an appointment voice agent is, as a rule, not high-risk AI. Anyone conflating the two is selling fear — or hasn't understood the difference.
The fines deserve the same sobriety. The EU AI Act sets substantial sums as its upper limit (up to €15 million or 3% of worldwide annual turnover, whichever is higher). That's the statutory ceiling for serious breaches — not the amount a small business faces for a missing chatbot notice. Wielding those maximum figures as a threat for the simple disclosure duty is exactly the scaremongering that specialist lawyers in the market are warning against. And the currently popular, expensive “AI officer” trainings and compliance packages promise far more effort for the actual labeling than the task calls for.
Weiterlesen — kostenlos
Den vollständigen Inhalt freischalten
Trag deine E-Mail-Adresse ein und bestätige sie: Du abonnierst den Signal-Forge-Newsletter von FORGE und erhältst sofort Zugang zu diesem und allen weiteren registrierungspflichtigen Inhalten. Die Abmeldung ist jederzeit möglich.
Schon registriert? Der Link aus deiner Bestätigungs-Mail schaltet dieses Gerät wieder frei.
Where the real risk comes from
None of this means you can ignore the topic. It's just that the real risk comes from a different corner than the headlines suggest. The big cease-and-desist waves of recent years — around Google Fonts or the Facebook Like button, for instance — didn't run on AI law, but on data-protection law, specifically on damages claims under Article 82 GDPR. That's the historical blueprint: a technically sloppy service that processes or transmits data without a sound legal basis creates a surface for mass warnings.
With the AI Act itself, the legal position is still open. Some law firms position Article 50 as a possible “market conduct rule” — on the reasoning that a breach could be actionable under German unfair-competition law (§3a UWG). That's a conceivable reading, not a settled standard: to date there's no documented, public cease-and-desist case against a voice agent or chatbot for missing AI disclosure. So if you want to do something about the real risk, get data protection right first — not the most expensive AI compliance package.
Why hammer on this? Because in a lot of sales pitches the order gets reversed. The unfair-competition angle is presented as a certainty, data protection gets treated as an afterthought, and out of that comes an expensive package. The realistic picture is the opposite: the disclosure is the easy part, data protection is the part with genuine exposure — and that's a duty regardless of the AI Act. A business that discloses its bot cleanly but quietly passes unsecured customer data to a US service in the background doesn't have the smaller problem — it has the bigger one. The label is visible and done in minutes; the data flows in the background are invisible, which is exactly why that's where carelessness comes back to bite.
What you should actually do
The good news: the practical effort is manageable. Before the list, a word on the difference between chat and phone, because it matters in practice. In chat, the disclosure is trivial: a fixed greeting line in the first bot turn, visible in the window, done. On the phone it's slightly more work, because the note has to come audibly and understandably at the start of the call — so it belongs in the opening announcement, not somewhere in the middle. Either way, you set it up once and it runs on its own; this is a one-off configuration, not an ongoing burden. The points below cover what matters for a typical chatbot or voice operation.
- Visible AI disclosure at the start of the interaction. A clear note in the first chat turn or a spoken announcement at the start of the call. Not at the end, not in the legal notice, not in the fine print.
- Check the data-protection basics. Which inputs get stored, what for, for how long? Might customer inputs be used as training data? This is where the real risk sits — clarify it with your model and hosting providers, and rule out training use in the contract where you can.
- Data processing agreement with your providers. With every model and hosting provider that processes data in the background — even when there's a German front end on top.
- Label AI-generated publications. If your system produces content that's published publicly, a machine-readable label belongs with it.
- Keep outputs under control. A customer chatbot that makes false promises is a problem regardless of the AI Act. How to safeguard AI outputs and put a human in charge of critical answers is covered in spotting and safeguarding AI errors.
Conclusion: implement calmly, don't panic-buy
The AI disclosure duty from 2 August 2026 is real, but manageable. The labeling itself is a small task — a clear note at the start of the conversation. What actually protects you is sound data protection, because that's where the cease-and-desist waves historically sat, not in AI law. Get that right, and you don't need an expensive “AI officer” package to sleep soundly. And the concrete question for you: does your chatbot or voice agent already say, in its first sentence, that it's an AI?