Guides/Risk classification ·By Yobel Tzegai ·Updated 29 September 2026

Does the EU AI Act apply to our chatbot or voice agent?

Written 29 September 2026 against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.

Yes, and for most companies the duty is one sentence in the product: tell the person she is dealing with an AI. A support chatbot or an outbound voice agent usually sits in the tier the Regulation never names, where Article 50(1) applies and the long high-risk list does not. Two things change that answer — inferring emotions, and deciding access to something.

Quick answer

Which tier is a support chatbot in?

Almost always the residual one. The classification runs in a fixed order: the Article 5 prohibitions first, then the two high-risk routes, then Article 50. A bot that answers questions about orders, refunds and delivery windows triggers none of the high-risk routes, so what is left is the transparency duty and the general obligations. The sequence itself is in how to classify your AI system; what each of the four Article 50 duties asks for, provision by provision, is in the four Article 50 disclosures.

Two things about "residual" are worth saying plainly. It is not an exemption — Article 50(6) says these duties do not affect Chapter III, so a system can carry a transparency duty and be high-risk at the same time. And it is not a permanent address: the tier follows the intended purpose, so the day the bot starts screening applicants, the classification restarts.

What must the bot actually say, and when?

Article 50(1) puts the duty on the provider and on the design: systems "intended to interact directly with natural persons" must be "designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system". A line in the terms of service does not satisfy "designed and developed".

The qualifier is the part most summaries drop. There is no duty where the AI interaction is "obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use". A widget labelled "AI assistant" in a dashboard is a plausible obvious case. There is also a carve-out for systems authorised by law to detect, prevent, investigate or prosecute criminal offences — and that carve-out itself has an exception, for systems available for the public to report a criminal offence.

Timing is fixed by Article 50(5): the information goes to the person "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure", and it must meet the applicable accessibility requirements.

Does an outbound voice agent have the same duty?

The same duty, and a harder time with the qualifier. A voice agent that calls a person is a system intended to interact directly with a natural person, so Article 50(1) applies. What it cannot easily borrow is "obvious": a synthetic voice on a phone line is the case the qualifier was not written for, and a company relying on obviousness there is relying on a reading it would have to defend. Disclosure at the start of the call is the cheaper answer.

If the agent generates the audio rather than playing recordings, Article 50(2) also attaches: outputs must be "marked in a machine-readable format and detectable as artificially generated or manipulated". That standard is qualified — "effective, interoperable, robust and reliable as far as this is technically feasible", accounting for content-type limitations, implementation costs and the state of the art — and it does not apply where the system performs an assistive function for standard editing or does not substantially alter the deployer's input data or its semantics.

When does sentiment scoring turn into a prohibited practice?

When the person whose emotions are inferred is at work or in an education institution. Article 5(1), first subparagraph, point (f) prohibits placing on the market, putting into service for that purpose, or using AI systems "to infer emotions of a natural person in the areas of workplace and education institutions", with one exception in the point itself: where the system is intended to be put in place or into the market for medical or safety reasons.

That reaches further than it looks. A support platform that scores the emotion of the agent handling a ticket is inferring emotions in the workplace. Scoring the customer's sentiment is outside those two areas — but then it is emotion recognition, which is high-risk under point 1(c) of Annex III, "in so far as [its] use is permitted under relevant Union or national law". Neither reading leaves it in the residual tier, and the two new points 2026/1744 inserted into Article 5(1) are dated separately — see the ten prohibited practices.

What this means for you

If you build the bot (provider): put the disclosure in the product rather than the terms, and record why you concluded the interaction is or is not "obvious". If it generates content, settle the marking question against Article 50(2) and diary the 2 December 2026 date for anything you shipped before 2 August 2026. Keep the Article 4 literacy record.

If you deploy someone else's bot (deployer): your duties are smaller but not zero — Article 4 is yours, and configuring a bought bot to infer emotions in your workplace is your act, not the vendor's. A vendor's compliance pack does not discharge you. If you change its intended purpose, read when a deployer becomes a provider.

The fine behind the transparency duties is up to 15 000 000 euro or 3 % of total worldwide annual turnover, whichever is higher (Article 99(4), point (g)) — and for SMEs, including start-ups, whichever is lower (Article 99(6)).

Complipath classifies each system and names the provisions the answer rests on: see what a risk classification records.

FAQ

Does a rule-based chat widget count as an AI system? Not automatically. The Article 3, point (1) definition turns on inference, so a decision tree with fixed replies may fall outside it entirely. A bot built on a language model is inside it. Which side yours is on is read against the definition, not against the vendor's category.

Do we have to disclose on every message? No. Article 50(5) requires the information in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. Once and up front, meeting the applicable accessibility requirements, is what the provision asks for.

Our bot escalates to a human. Does that remove the duty? No. The duty attaches to the system intended to interact directly with natural persons, and a handover does not change what happened before it. Article 50(1) has no human-in-the-loop exception; the only relief is the obviousness qualifier and the law-enforcement carve-out.

We use a third-party bot built outside the EU. Who is on the hook? Both of you, for different things. The provider's duties follow the system onto the Union market under Article 50(1); your deployer duties follow your use, and Article 4 is yours whatever the tier. A vendor's compliance pack does not discharge either half.

Which tier is your chatbot in?

Check your AI systems - free

a short set of questions, more if your answers open follow-ups, no account and they stay in your browser unless you choose to keep the result.

← All guides
Complipath

Complipath is EU AI Act compliance software for companies that build or deploy AI, in Europe and outside it — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

COMPLIPATHPAGE complipath.io/guides/chatbots-voice-agents-eu-ai-actBUILT 2026-09-29CLASSIFIER 2026-09-27.1LAW VERSION 2024/1689 + 2026/1744 + Commission guidelines

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.