# The EU AI Act, for a business with one chatbot

URL: https://goudbeek.com/en/notes/eu-ai-act-for-one-chatbot
Language: en
Last updated: 2026-08-18
Provider: Goudbeek — Almere, the Netherlands — samgoudbeek2007@gmail.com

> What does the EU AI Act ask of a business with one chatbot? How the risk categories work, why transparency almost always applies, and what to have ready.

18 August 2026 5 min read [Sam Goudbeek](https://goudbeek.com/en/about)

Rules

You do not need to read the whole AI Act. You need to know which risk category your system falls in, and that it follows from what the system does rather than what it is built with.

The EU AI Act (Regulation (EU) 2024/1689) sorts AI systems by risk: what a system does and for whom, not the model behind it. A chatbot answering product questions is usually not high-risk. What counts most for a chatbot is transparency (Article 50): people should be able to tell they are talking to AI, unless that is already obvious.

The European AI Act is long, and most of the commentary about it is written for organisations with a compliance department. If you run a shop with a chatbot on the site, or an agent that drafts replies to support mail, almost none of that commentary is about you.

What follows is the shape of the thing, not legal advice, and deliberately without dates — the timetable phases in over several years and the details are the part you should read at the source rather than take from a blog post.

## It sorts by risk, not by technology

The Act does not ask which model you used. It asks what the system does and to whom. The same underlying model is treated completely differently depending on whether it answers questions about delivery times or helps decide who gets a loan.

That is the first thing worth internalising, because it means the question 'are we compliant' has no answer until somebody writes down what the system is actually for.

## Most small-business uses are not the high-risk category

The heavy obligations attach to uses where a wrong output materially affects somebody's life: employment decisions, access to credit or essential services, education, certain public-sector uses.

A chatbot answering product questions, [software reading invoices into your bookkeeping](https://goudbeek.com/en/solutions/documents), an assistant searching your own procedures — these generally do not sit there. That is not permission to skip thinking about it. It means the effort belongs somewhere more useful than a compliance binder.

## For a chatbot, transparency is what counts most

If people are interacting with an AI system, they should be able to tell, unless it is already obvious. For a chatbot this is the obligation that applies most directly, and it is also the cheapest to satisfy: say so, plainly, where the conversation starts. The transparency obligations are in Article 50; Article 4 also asks for AI literacy among the people who work with it. Check the current text for both.

For a [chatbot on your website](https://goudbeek.com/en/solutions/chatbots), that is one clear sentence at the top of the conversation. It is worth doing even if nothing required it. Systems that pretend to be human erode trust the moment somebody works it out, and somebody always works it out.

## What to have ready, whatever risk category you are in

A sentence describing what the system does and what it is for. A list of what it can reach. A list of what it can do without a person. A record of what it did. Whether or not anyone ever asks, that set is what turns a vague worry into a question you can answer in a meeting.

It is also, not coincidentally, the same set that stops a system doing something expensive on a Tuesday.

## Where to actually check

For anything you would act on — whether your use is in scope, what applies to you, and by when — read the official text rather than a summary. Scope and timing are exactly the details that summaries get out of date on, this one included.

The official text is Regulation (EU) 2024/1689, published on EUR-Lex; the European Commission keeps an overview page. Both are linked under Sources below.

## Sources

1. [EUR-Lex — Regulation (EU) 2024/1689 (AI Act) eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689)
2. [European Commission — AI Act digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai)

## Frequently asked questions

### What is the EU AI Act?

The AI Act, officially Regulation (EU) 2024/1689, is the European law for AI systems. It sorts systems by risk: what a system does, and for whom, decides which rules apply, not which model or technique sits behind it. The official text is on EUR-Lex, and for anything you would act on, that is the source to read.

### Is a chatbot on my website a high-risk system?

A chatbot on your website is generally not a high-risk system. The heavy obligations attach to uses where a wrong output materially affects somebody's life, such as decisions about employment, credit, education or access to essential services. A chatbot answering product questions does not usually sit there. Whether yours does depends on what exactly it does and for whom, so check that against the official text.

### Do I have to tell customers they are talking to an AI?

In practice you do need to tell customers they are talking to AI: Article 50 of the AI Act requires it, unless that is already obvious. Who formally carries that duty depends on your role under the Act; if you have a chatbot built and put it into use under your own name, that can be you. That can be one clear sentence where the conversation starts. It is sensible regardless of the law: a system that pretends to be human loses trust.

### What should I have ready, whatever risk category my system is in?

Whatever risk category of the EU AI Act applies, have four things ready for an AI system: a sentence on what it does and what it is for, a list of what it can reach, a list of what it may do without a person, and a record of what it did. That set answers most questions about your system, and the same rules limit what it can do without a person.

### When do the rules apply?

The AI Act phases in over several years, and when each obligation starts differs by part. This article deliberately gives no dates, because that is exactly where summaries go out of date first. For the current timetable, read the official text on EUR-Lex and the European Commission's overview page, both linked under Sources.

About the author: Sam Goudbeek

Sam Goudbeek is the founder of Goudbeek in Almere, which improves business processes with AI and software.

[More about Sam and Goudbeek](https://goudbeek.com/en/about)

## Further reading

Where this article meets the work.

- [Chatbots](https://goudbeek.com/en/solutions/chatbots): A chat that knows your catalogue, prices and terms.
- [AI security](https://goudbeek.com/en/security): What AI may see, and what it may do.

[All articles](https://goudbeek.com/en/notes)

## More from the knowledge base

### [Chatbot or AI agent: which one does your business need?](https://goudbeek.com/en/notes/chatbot-or-ai-agent)

A chatbot answers questions; an AI agent does work. How to tell which one your business needs, what both require, and when it makes sense to combine them.

24 Sept 2026 6 min read

### [What an AI agent is allowed to do is a design decision, not a setting](https://goudbeek.com/en/notes/what-an-agent-is-allowed-to-do)

The interesting question was never how clever the model is. It is what the thing can reach on a bad day, and who signed off on that.

2 Sept 2026 4 min read

### [Prompt injection, explained without the hype](https://goudbeek.com/en/notes/prompt-injection-without-the-hype)

The attack is old news in a new costume: text arrives from outside and the system cannot tell instruction from content. What matters is what it reaches once it works.

29 Jul 2026 4 min read
