Short answer: almost certainly not high-risk — but you have obligations that are enforceable right now, which is not the answer most chatbot builders expect and not the one they were told in June.
The confusion is understandable. "High-risk" sounds like a description of how much harm something could do, so a chatbot with access to customer data feels like it should qualify. It isn't that kind of term. High-risk is a defined classification with a specific list attached, and most chatbots sit outside it while landing squarely inside a different set of duties that nobody reported on.
When a chatbot is high-risk
Your chatbot is high-risk only if it falls inside Annex III. For conversational systems, realistically that means one of these:
| Annex III area | Chatbot that would qualify |
|---|---|
| Employment & worker management | Screens, ranks or filters job applicants; conducts assessed interviews; feeds promotion or termination decisions |
| Education & vocational training | Determines admission, assesses learning outcomes, or monitors exams |
| Essential private & public services | Assesses creditworthiness, triages benefits or emergency calls, or prices life and health insurance |
| Law enforcement | Assesses risk of offending, evaluates evidence reliability, profiles individuals |
| Migration, asylum, border control | Assesses applications, verifies documents, evaluates risk |
| Administration of justice | Assists a judicial authority in researching or interpreting facts and law |
Notice what they share. Each one makes or materially influences a decision about a specific person that affects their access to work, money, education, liberty or residence. That is the actual test hiding behind the list.
A support chatbot answering questions about your product does none of that. A sales chatbot qualifying leads does not either — qualifying a company is not deciding about a person. An internal chatbot searching your documentation does not.
The boundary case worth knowing. A recruitment chatbot that only schedules interviews is doing logistics. The same chatbot that scores candidates on their answers is doing assessment. Same product surface, same conversation, different regulatory object. If your roadmap moves you from the first to the second, the classification moves with it — and nobody sends a notification.
And even then, check Article 6(3)
Sitting inside an Annex III area does not automatically make a system high-risk. Article 6(3) provides an exemption where the system performs a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing human assessment, or performs preparatory work — and does not profile natural persons.
For chatbots, the profiling condition is usually the one that decides it, and it is absolute. A chatbot that collects structured information from candidates and hands it to a recruiter unchanged may be doing preparatory work. One that infers anything about the person — suitability, sentiment, likely performance — is profiling, and the exemption closes. The full 6(3) test.
What you almost certainly are: limited risk
Most chatbots land in limited risk, where the entire obligation is transparency under Article 50 — and this is the part that matters, because it has been enforceable since 2 August 2026.
Article 50 was not deferred. The June 2026 Omnibus moved Annex III high-risk obligations to December 2027. It did not touch Article 50. So the systems with live duties today are precisely the chatbots and generative products whose builders read "the EU delayed the AI Act" and stopped paying attention.
50(1) — tell people they're talking to an AI
Systems intended to interact directly with natural persons must be designed so those persons are informed they are interacting with an AI system, unless it is obvious to a reasonably well-informed person in the circumstances.
Three things people get wrong:
- "Obvious" is not a safe bet. Modern assistants are convincing, they get human names, and they open with human-sounding greetings. If you gave yours a first name and a photo, you have actively worked against obviousness.
- The privacy policy does not count. Disclosure has to reach the person at or before the interaction, not sit in a document they will never open.
- It must survive the handoff. If your bot escalates to a human, or a human takes over silently, the user should be able to tell which they are speaking to.
The fix is one line in the greeting. Something like: "Hi, I'm [name] — [company]'s AI assistant. I can answer questions about X. For anything you'd rather ask a person, leave your email and we'll reply."
Add a rule to the system prompt too: if asked whether it is human, it always says plainly that it is an AI, and never implies otherwise. That closes the gap where the greeting scrolls out of view in a long conversation.
This is the cheapest obligation in the entire regulation. It costs an afternoon and it tends to raise conversion, because people trust a disclosed bot more than one they suspect.
50(2) and 50(4) — synthetic content
If your product generates content, two more provisions apply, and it is worth being precise about who owes what:
- 50(2) requires providers of generative systems to mark synthetic output as artificially generated in a machine-readable format. This duty sits with the provider of the generative system. If you call someone else's model through an API, this is theirs, not yours.
- 50(4) covers deployers. Deepfakes — image, audio or video resembling real persons, places or events — must be disclosed. AI-generated text published to inform the public on matters of public interest must also be disclosed, unless it underwent human review and a natural or legal person holds editorial responsibility for its publication.
That exemption is the practical one for most companies. If a person reads what you publish before it goes out and takes responsibility for it, the disclosure duty does not attach. Publish unreviewed generated text and it does.
Article 4 — AI literacy, which applies to everyone
Providers and deployers must ensure a sufficient level of AI literacy among staff dealing with the system, accounting for their technical knowledge and the context of use. Enforceable since 2 August 2026.
For a small team this is genuinely a half-day: what the system does, where it fails, how to recognise a bad output, who to escalate to. Minute it and keep the attendance list. The record is the compliance — there is nothing to submit and nobody to notify, but if asked, "we did this on this date and here is who attended" is the entire answer.
What about the data the chatbot sees?
A common tangle. If your chatbot processes personal data, that is GDPR, not the AI Act. The two overlap but ask different questions: GDPR asks whether you may process this data and on what basis; the AI Act asks what kind of system this is and what duties attach to it.
Answering one does not answer the other. "We're GDPR compliant, so we're fine" is among the most common misconceptions in this space, and it is wrong in both directions — a lawful-basis analysis says nothing about Article 50, and an AI Act classification says nothing about your lawful basis.
Five minutes, and you'll know where you stand
- Does your chatbot make or materially influence a decision about a specific person concerning employment, education, credit, essential services, law enforcement, migration or justice? No → not high-risk.
- If yes, does it profile individuals? No, and its task is narrow or preparatory → possibly exempt under 6(3), but document it.
- Does the user get told it's an AI, at first contact, visibly? No → fix this week. Live obligation.
- Does it generate content you publish without review? Yes → label it, or introduce review and hold editorial responsibility.
- Have you run and recorded an AI literacy session? No → half a day, minute it.
Most companies working through that list find they are limited risk with one genuine gap: the disclosure. It takes an afternoon, it has been enforceable since August, and it is the single most common thing left undone.
Check your chatbot in two minutes
Six questions covering what it does, who it affects and how it is governed. Instant tier, no card.
Start the free scanNo card, no account. Full gap report from €59. See a real report first.
Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.
How this was made. Reglynn reports are generated by an AI system and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.