TL;DR
Every EU AI Act website chatbot obligation that matters to a typical business became enforceable on 2 August 2026: people must be told, clearly and at first contact, that they are talking to AI. That disclosure is the cheap part of compliance. The expensive part is that your company is legally bound by what the chatbot says, and no label changes that.
Introduction
A grieving passenger asked Air Canada’s website chatbot how bereavement fares worked. The chatbot told him he could book a full fare and claim the discount retroactively. That policy did not exist. When he asked for the refund, the airline argued the chatbot was responsible for its own words.
The British Columbia Civil Resolution Tribunal disagreed in February 2024 and held Air Canada liable for negligent misrepresentation.
That ruling came from Canada, before the EU AI Act’s transparency rules existed. Since 2 August 2026, European companies face both problems at once: a legal duty to disclose the bot, and an established principle that the business owns every answer it gives.

What EU AI Act Article 50 Requires From a Website Chatbot
Article 50 of the EU AI Act requires that anyone interacting with an AI system be informed they are dealing with AI, unless that is obvious. The rule has applied since 2 August 2026, and it covers the customer service bot, the sales assistant, the voice agent on your support line, and every assistant an AI-native website adds later.
The European Commission’s guidelines, published in July 2026, read the “obvious” exception narrowly. A public-facing helpdesk chatbot does not qualify. The disclosure must arrive “at the latest at the time of the first interaction,” in the words of the AI Act text, and in a clear and distinguishable manner. A line buried in your terms and conditions does not count.
Two further duties touch websites. Content that is AI-generated or manipulated and depicts real-looking people, places, or events (a deepfake, in the Act’s terms) must be disclosed. AI-generated text published to inform the public on matters of public interest must be labeled unless a human reviewed it and someone holds editorial responsibility.
According to the European Commission, Article 50 breaches carry fines of up to €15 million or 3 percent of global annual turnover.
The Digital Omnibus amendment did not delay the chatbot rule. Its only Article 50 grace period, to 2 December 2026, covers machine-readable marking by generative systems already on the market.
Why a Disclosure Label Does Not Protect You From What Your Chatbot Says
A chatbot disclosure tells users what they are talking to. It does not reduce your responsibility for what they are told.
In Moffatt v. Air Canada, the tribunal called the airline’s defence “a remarkable submission.” It ruled that the chatbot “is still just a part of Air Canada’s website” and that consumers need not cross-check one page against another. The award was small, CA$812.02 in damages and fees. The precedent was not.
This is the non-obvious point most compliance checklists miss. Article 50 regulates the least expensive layer of chatbot risk. A company can be perfectly compliant with the disclosure rule and still be exposed every time its bot invents a discount, a delivery promise, or a return window.
The practical defence is a bot that answers only from structured, approved answers the business already stands behind. Anything outside that set should produce a handoff, not an improvisation.

The Three-Layer Chatbot Exposure Model
The Three-Layer Chatbot Exposure Model separates chatbot risk into what the bot discloses, what it states, and what it collects. Each layer fails differently and costs differently.
Layer 1: Disclosure. Are users told, at first contact, that they are talking to AI? This is the Article 50 layer. It is mostly a design fix, and it is cheap.
Layer 2: Statements. Is every answer true, current, and something the business is willing to honor? This is the Air Canada layer. The safest bots hand off to a human the moment a question touches price, policy, or contract terms.
Layer 3: Data. What does the bot collect, where do transcripts go, and which third-party model processes them? This layer sits under the GDPR as much as the AI Act. A chatbot bolted onto a site without privacy-first architecture often ships customer conversations to a vendor nobody on the legal team has reviewed.
Most companies audit Layer 1, because the law now names it. The liability lives in Layers 2 and 3.
Provider or Deployer: The Role Question That Sets Your Obligations
The AI Act assigns chatbot duties by role, and the role depends on how your chatbot was built, not who wrote the model. A provider develops an AI system, or has one developed, and puts it into service under its own name. A deployer uses an AI system under its own authority.
The chatbot disclosure duty sits primarily with providers. Many businesses assume they are deployers because they did not train the model. That assumption breaks when the bot carries your brand.
| Your chatbot setup | Likely role | What you own |
|---|---|---|
| Off-the-shelf widget, vendor branding, default settings | Deployer | Keeping the vendor’s disclosure switched on and visible |
| Vendor widget renamed, given a persona, heavily customized | Deployer, drifting toward provider | Proving your customization did not remove or bury the disclosure |
| Custom build on a third-party model API, under your brand | Provider | Disclosure by design, plus everything above |
| Built by an agency, running under your name | Provider (you “had it developed”) | Contract terms that assign who maintains compliance |
The Commission’s guidelines note that substantial modification or rebranding can shift a deployer into provider status. Treat this matrix as triage for counsel, not a legal opinion.
Where Website Chatbot Compliance Actually Fails
Chatbot compliance rarely fails at the policy level. It fails between what the policy says and what the live website renders.
In the chatbot and AI integration work WPRiders reviews, the failures cluster in three places. The disclosure exists in the vendor dashboard but a theme update or custom CSS hides it on mobile. The bot’s knowledge base still contains last year’s pricing page. And nobody can say which plugin loads the chat script, because the integration was set up by a contractor who has since left.
Undocumented integrations turn a simple question from a regulator or a customer’s lawyer into a week of forensic work.
Persona bots deserve extra scrutiny. A bot called “Sophie” with a stock photo of a person makes the AI disclosure more necessary, not less.
What an EU AI Act Website Chatbot Audit Should Cover
An EU AI Act website chatbot audit tests the live experience a customer sees, not the settings a vendor promises. It should answer six questions in plain language.
Does the AI disclosure appear at the first message, on every device and in every language the site serves? Does it meet the accessibility requirements Article 50 demands? Which sources can the bot answer from, and who approves changes to them? Which topics force a human handoff? Where are transcripts stored, and under which data processing agreement? Which AI-generated images, video, or public-interest text elsewhere on the site need a label?
WPRiders audits WordPress and WooCommerce chatbot integrations at the code level, tracing the chat script, its knowledge sources, and its data flows. The findings belong in your annual website audit, next to security and performance, because the board will ask about AI risk before regulators do.

Key Takeaways
- The EU AI Act’s chatbot disclosure rule under Article 50 has applied since 2 August 2026 and was not delayed by the Digital Omnibus.
- A public-facing customer service chatbot does not qualify for the “obvious” exception, so it must disclose that it is AI at first contact.
- Article 50 breaches carry fines of up to €15 million or 3 percent of global annual turnover, according to the European Commission.
- Moffatt v. Air Canada established that a business is liable for what its chatbot tells customers, regardless of any disclosure.
- The Three-Layer Chatbot Exposure Model divides chatbot risk into disclosure, statements, and data, and most liability sits in the last two.
- A company that builds or brands its own chatbot is likely a provider under the AI Act, not a deployer.
Conclusion
The disclosure rule is the first AI obligation most European websites will be tested on, and it will not be the last. Regulators, courts, and customers are converging on one principle: an AI system on your website speaks for your business. That makes the chatbot a governance question, not a widget choice.
The companies that come through this well will treat every AI touchpoint like checkout: owned, documented, and tested on a schedule. Working with a partner that understands both WordPress internals and where AI regulation is heading turns that from a scramble into routine maintenance.
FAQs
Q1. Do I need to tell website visitors they are talking to a chatbot under the EU AI Act?
Yes, in almost every case. Article 50 of the EU AI Act requires that people be informed they are interacting with an AI system unless it is obvious, and the European Commission reads that exception narrowly. A public-facing customer service or sales chatbot does not qualify. The disclosure must be clear, placed at or before the first interaction, and accessible. A notice only in your terms and conditions is not enough.
Q2. What are the fines for not disclosing an AI chatbot in the EU?
Breaches of the EU AI Act’s Article 50 transparency obligations can be fined up to €15 million or 3 percent of worldwide annual turnover, whichever is higher, according to the European Commission. For SMEs and start-ups, the cap is whichever of the two amounts is lower. National market surveillance authorities enforce the rules, and fines are expected to be proportionate to the size of the business.
Q3. Does the EU AI Act apply to companies outside the European Union?
Yes, when the chatbot serves people in the EU. The EU AI Act applies to providers and deployers whose AI systems are placed on the EU market or whose outputs are used in the EU, regardless of where the company is incorporated. A US or UK business running a chatbot on a site that targets EU customers should assume the Article 50 disclosure rule applies to it.
Q4. Is a company liable if its chatbot gives customers wrong information?
Courts are treating it that way. In Moffatt v. Air Canada, decided in February 2024, a Canadian tribunal held the airline liable for negligent misrepresentation after its website chatbot invented a bereavement refund policy. The tribunal rejected the argument that the chatbot was a separate entity and ruled it was simply part of the airline’s website. Businesses should assume their chatbot’s answers bind them.
Q5. Do I have to label AI-generated blog posts on my company website?
Usually not, if a human reviews them. The EU AI Act requires labels on AI-generated text published to inform the public on matters of public interest, such as politics or public health, but exempts text that underwent human review with someone holding editorial responsibility. Routine marketing content edited by your team generally falls outside the rule. AI-generated images or video of realistic people or events still need disclosure.