Does the EU AI Act apply to my chatbot?

Most product teams ask the wrong first question (“are we high-risk?”). For a chatbot the first question is Article 2 (does the Act reach this deployment) and the second is Article 50(1) (do we have to tell the person they are talking to an AI system). High-risk classification is a later question, and only if the bot also does something Annex III lists — hiring, credit, education, essential services.

Educational resource only — not legal advice. scm.cc publishes a readiness report and engineering gap analysis for AI features. It does not give legal advice, represent you before a regulator, or state that a product is ready to ship under any law. This page is educational product guidance, not legal advice. It is not a readiness report, not an engineering gap analysis of your systems, and not a determination that any product meets a legal duty. Confirm current official text before you ship.

Last checked against official sources: .

Three scope checks, in order

Work them in this order. Stop when a check fails; continue when it passes.

US-hosted, EU users

Article 2(1)(c) is the clause that catches the common SaaS pattern: the company is in the United States, the model is hosted in us-east-1, and a user in Berlin opens the widget. The output is used in the Union. Treat that as in-scope unless counsel tells you otherwise after reading the official text.

What you ship if the checks pass

A clear, distinguishable disclosure at or before the first interaction, accessible to assistive technology. See the chatbot disclosure page and the copy-ready snippet. If the same system also generates images or long public text, keep going into Article 50(2) and 50(4).

Questions teams ask

Our bot only talks to logged-in employees. Still Article 50?
Article 50(1) speaks of natural persons, not consumers. An internal HR bot that employees use is still a direct interaction. The criminal-law carve-out is narrow. Employment use can also drag you toward Annex III high-risk duties — see the hiring-tools page.
We embed a third-party model. Who discloses?
The provider of the system intended to interact with the person designs the disclosure in. If you put a conversational UI on someone else’s model and place that system on the market, you are the provider of that system. The model provider may have 50(2) marking duties for the raw generator.

Related pages

Back to the AI law hub

Primary sources

Official text wins. Last checked 2026-10-11. This page is educational product guidance, not legal advice. It is not a readiness report, not an engineering gap analysis of your systems, and not a determination that any product meets a legal duty. Confirm current official text before you ship.