The EU AI Act: what to do if your business uses AI chatbots and assistants
If your product talks to users through a chatbot, generates text or images, or suggests decisions based on artificial intelligence, you now have a new regulator — the European Union. The Artificial Intelligence Act (AI Act) is already in force, its key rules apply, and from August 2026 the supervision and penalty machinery has switched on. And the most important point for most businesses: it works extraterritorially. A company from Kyiv, Warsaw or San Francisco falls within its scope as soon as its AI system is used in the EU. Below is a practical analysis by Dextra Law: what this law is, when each part takes effect, who is in the firing line, and what exactly your business should check right now.
What the EU AI Act is and why it concerns you
The AI Act is Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 — the world’s first comprehensive law on artificial intelligence. Because it is a regulation and not a directive, it applies directly in all EU member states, without separate implementation by national parliaments.
The key thing not to miss, for a Ukrainian or any other non-European business: the law is tied not to where the company is registered but to the market. It applies to providers and deployers of AI systems where the system is placed on the EU market, put into service in the EU, or where its output is used in the EU. So a SaaS from Lviv with users in Germany, an app with a chatbot available in France, or an agency embedding an AI assistant for an EU client — all are within scope.
The law is built on a risk-based approach: the greater the potential harm an AI system can cause, the stricter the requirements. That is why the first step for any business is not “do everything” but to correctly determine which category each of your AI systems falls into.
The four risk levels
The European Commission distinguishes four levels, and the scope of obligations depends on them.
- Unacceptable risk — prohibited practices. Fully banned systems: harmful manipulation and deception; exploitation of vulnerabilities; social scoring; assessing an individual’s likelihood of committing a crime; untargeted scraping of faces from the internet or CCTV to build recognition databases; emotion recognition in the workplace and in educational institutions; biometric categorisation by protected characteristics; real-time remote biometric identification for law enforcement in public spaces. A ban has also been added on systems that generate child sexual abuse material and non-consensual intimate content (so-called nudify apps).
- High risk. Systems that can seriously affect health, safety or fundamental rights: AI in critical infrastructure, education, hiring and workforce management, access to essential services (for example, credit scoring), law enforcement, migration, justice, and AI as a safety component of regulated products.
- Limited risk — transparency risk. Most chatbots and generative AI fall here. The main requirement is transparency: a person must understand that they are dealing with a machine, and generated content must be marked.
- Minimal or no risk. Spam filters, AI in games, low-risk recommendation systems. There are no special requirements — the vast majority of AI systems on the market are here.
The calendar: when each part takes effect
The law is being rolled out in phases. The dates below are the heart of the whole topic, because they define what is already mandatory and what is still ahead. Note that in 2026 some deadlines for high-risk systems were moved by a simplification package (the so-called AI Omnibus, which entered into force on 27 July 2026).
| Date | What applies |
|---|---|
| 1 August 2024 | The Regulation entered into force — the transition periods began |
| 2 February 2025 | Prohibited practices (bans 1—8) and the AI literacy obligation for staff |
| 2 August 2025 | Rules for general-purpose AI (GPAI) models, governance rules and the AI Office’s powers |
| 2 August 2026 | Application of the bulk of the rules; the transparency obligations (Article 50) take effect — chatbot disclosure, marking of AI content and deepfakes; supervision and penalties switch on |
| December 2026 | The ban on systems generating CSAM and non-consensual intimate content takes effect (added by the AI Omnibus) |
| 2 December 2027 | Obligations for high-risk systems in Annex III areas (biometrics, critical infrastructure, education, hiring, migration, etc.) — moved from August 2026 |
| 2 August 2028 | Obligations for high-risk systems embedded in regulated products (Annex I) — lifts, toys, medical devices, etc. |
The practical takeaway: if your business is a chatbot, a virtual assistant or a generative service, your key date is 2 August 2026, when the transparency obligations became something that can be demanded and punished for non-compliance. That has already happened, so the question is not about preparing “for the future” but about whether you meet the requirements today.
Who is in the firing line
Most of the new obligations fall on two types of participant, and it is important to understand which one your company is for each specific product.
Providers — those who develop an AI system or model, or release it under their own brand. This includes AI startups and any company that makes its own chatbot under its own name, even if there is someone else’s model “under the hood”.
Deployers — those who use an AI system in their activities. A classic business that has put a support chatbot on its website, integrated an AI assistant into an app, or uses generative AI for marketing is a deployer, and part of the transparency obligations falls on it.
A separate category is providers of general-purpose AI (GPAI) models, such as large language models. They have their own rules on technical documentation, transparency and copyright, in force since August 2025. Most businesses do not build the models themselves but depend on them — and here a practical task arises: obtain from your AI provider everything you need for your own compliance.
What web and app services with chatbots and assistants should do
This is the most numerous category and, at the same time, the one for which the law gives a relatively clear set of actions. The key provision is Article 50 on transparency. Here is what to check and implement.
- Disclosure of interaction with AI. If a user is dealing with a chatbot or a voice assistant, they must be clearly informed of this — except where it is obvious from the context. In practice, this is a visible message such as “You are chatting with a virtual assistant”, not a fine line in the privacy policy.
- Marking of generated content. If your service generates text, images, audio or video, that content must be marked as artificially generated in a machine-readable format. For deepfakes and images of people, the requirements are stricter — visible marking is needed.
- Deepfakes and content on matters of public interest. Synthetic images, audio or video imitating real people or events, as well as AI-generated text published to inform the public, must be clearly marked.
- Working with the model provider. If you use someone else’s model, find out what marking tools and documentation it provides, and build them into your product.
- Check for prohibited and high-risk use. Make sure your service does none of the items on the prohibited list (for example, employee emotion recognition) and does not fall into the high-risk area (for example, screening job candidates). If it does, the scope of obligations is fundamentally different.
- AI literacy of the team. An obligation in force since February 2025: staff who work with AI systems must have a sufficient level of understanding of their capabilities and risks.
What AI companies and developers should do
If AI is your core product, you are almost certainly a provider, and possibly a provider of a general-purpose AI model. Here there are more tasks.
- Classify each system by risk. This is the foundation. Everything else depends on the category, and a classification error is costly.
- For GPAI models. Technical documentation, copyright compliance during training, a public summary of training data using the Commission’s template, and — for models with systemic risk — assessment and mitigation of those risks. The voluntary GPAI Code of Practice, published in 2025, is useful here.
- For high-risk systems. A quality management system, conformity assessment, logging, detailed technical documentation, human oversight, cyber resilience and accuracy. Registration in the EU database. This is a long cycle — it is prepared well in advance, not a month before the December 2027 deadline.
- Transparency by default. Build content marking and AI-interaction disclosure into the product architecture, rather than “bolting them on” later.
- Track the updates. In 2026 the Commission published guidelines on transparency and is preparing codes of practice on marking AI content. The regulation is moving, and documents come out regularly.
What classic businesses should check
The most common mistake of non-tech companies is to think that “the AI Act is not about us”. In reality, as soon as you put a chatbot on your website or start generating advertising text with a neural network, you have become a deployer. Here is a short audit for an ordinary business.
- Build an AI inventory. List everything that touches the user: chatbots, AI assistants, content generators, recommendation systems, request-handling tools. You cannot manage what you cannot see.
- Check chatbots for disclosure. Every bot that talks to customers must honestly say that it is a bot.
- Check generated content. Images and video from neural networks in advertising and communications may require marking, especially if they are realistic or show people.
- Special attention to HR and hiring. AI for sorting CVs, evaluating or ranking candidates is a high-risk area. It requires a completely different level of control.
- Do not use the prohibited. For example, systems for recognising employees’ emotions in the workplace are expressly banned.
- Train your people. The AI literacy obligation also applies to you: the team must understand which tools it is working with.
- Put it in your contracts. If AI features are provided to you by a contractor, record in the contract who is responsible for AI Act compliance and what guarantees the provider gives.
What a mistake costs
The AI Act’s fines are substantial and tied to global turnover. For using prohibited practices — up to EUR 35 million or up to 7% of worldwide annual turnover, whichever is higher. For breaching other obligations, in particular on high-risk systems and transparency — up to EUR 15 million or up to 3% of turnover. For supplying inaccurate information to regulators — up to EUR 7.5 million or 1% of turnover. Lower caps are provided for smaller companies, but the very existence of fines on this scale shows how seriously the EU takes supervision.
A practical action plan
- Inventory. Draw up a full list of the AI systems you develop or use, stating your role — provider or deployer.
- Classify. Determine the risk level of each system: prohibited, high, limited, minimal.
- Close off transparency. Implement chatbot disclosure and marking of generated content — this is already mandatory.
- Check for prohibited and high-risk use. Remove prohibited practices; for high-risk systems, start preparing documentation and conformity assessment well in advance.
- Put the supply chain in order. Obtain documentation and marking tools from your model providers; assign responsibility in your contracts.
- Train the team. Ensure basic AI literacy among staff.
- Document. Keep evidence of compliance — it is your defence in the event of an inspection.
How Dextra Law helps you prepare for the AI Act
The AI Act is an area where the cost of delay grows month by month, and an error in classifying a system can turn a “light” transparency obligation into a full high-risk regime. We help businesses walk this path in concrete terms:
- AI audit and classification. We build an inventory of your AI systems and determine the role (provider or deployer) and risk level of each.
- Compliance roadmap. We prepare a list of specific actions tailored to your products and deadlines, not abstract recommendations.
- Transparency and documentation. We word correct disclosures for chatbots, content-marking policies and internal regulations.
- Contracts with contractors. We allocate AI Act responsibility between you and your model providers and integrators.
- Support for high-risk systems. We prepare documentation, conformity assessment and oversight processes for those operating in sensitive areas.
Instead of working through hundreds of articles of the regulation and the Commission’s guidelines yourself, you get a clear answer to the main question: what exactly your business should do, in what order, and by what deadline.
Frequently asked questions
Yes. It applies where an AI system is placed on the market or put into service in the EU, or where its output is used in the EU, regardless of where the company is registered.
Yes, in the role of a deployer. You bear, in particular, the transparency obligation — to tell users they are talking to a bot — as well as the need to agree on responsibility with the solution provider.
From 2 August 2026, together with the launch of supervision and penalties. This is already a live requirement, not a future one.
Yes. Generated content must be marked in a machine-readable way, and deepfakes and certain content informing the public must be visibly marked.
Fines of up to EUR 35 million or 7% of worldwide turnover for prohibited practices, and up to EUR 15 million or 3% of turnover for other breaches, in particular on transparency and high-risk systems.
Fines of up to EUR 35 million or 7% of worldwide turnover for prohibited practices, and up to EUR 15 million or 3% of turnover for other breaches, in particular on transparency and high-risk systems.
Usually not: a typical support chatbot falls under limited risk with transparency obligations. But if it performs functions from Annex III areas (for example, evaluating job candidates), it may fall under high risk.
It is an obligation, in force since February 2025, to ensure that staff working with AI understand its capabilities and risks well enough. It applies to both providers and deployers.
Yes, by the AI Omnibus package, which entered into force on 27 July 2026: for Annex III — to 2 December 2027, and for systems embedded in products (Annex I) — to 2 August 2028. The transparency obligations were not moved.
Ready to bring your AI product into compliance?
The Dextra Law team will audit your AI systems, determine the risk level and prepare a clear roadmap for the AI Act’s requirements — from chatbot disclosures to documentation for high-risk systems. Contact us to understand what exactly your business should do today.
