The EU AI Act and Customer-Facing AI: What Businesses Using Chatbots and Voice Agents Must Do

If your customers talk to an AI chatbot or voice agent, tell them it is AI. That is the core of the EU AI Act's transparency rules for customer-facing AI, which apply from 2 August 2026. This guide explains who is responsible, what to say on each channel, and which other rules still apply alongside the AI Act.

What is the short answer for businesses?

The short answer is: if customers interact with your AI, make sure they know it is AI. Article 50 of the EU AI Act sets transparency obligations, and one of them is that AI systems which interact directly with people must be designed so those people are informed they are interacting with an AI system, unless that is obvious from the context. For a business using an AI assistant on WhatsApp, a chat widget on its website or a voice agent on its phone line, the practical step is simple: say so, clearly, at the start of the conversation. The rest of this guide covers how to do that well and what else to keep in mind. This is general information, not legal advice.

Who is a provider and who is a deployer?

Under the AI Act, the provider is the company that builds and supplies the AI system, and the deployer is the business that uses it with its own customers. Both have duties. The company behind an AI model or voice platform is usually the provider. Your business, using that system to answer customer messages or calls, is usually the deployer. The provider is responsible for how the system is designed, including building in the ability to disclose AI and mark AI-generated content. The deployer is responsible for how it is used with real people, including making sure customers are actually told. You cannot assume the provider has taken care of everything; how you configure and present the AI to your customers matters. This is general information, not legal advice.

What changed on 2 August 2026?

On 2 August 2026 the Article 50 transparency obligations started to apply. The main points for customer-facing AI are:

  • Disclosure of AI interaction. AI systems that interact directly with people must be designed so people are informed they are interacting with an AI, unless that is obvious from the context.
  • Marking AI-generated content. Providers of generative AI systems must mark synthetic audio, image, video and text output as AI-generated in a machine-readable way. Under the AI Act "digital omnibus" changes, systems already placed on the market before 2 August 2026 have until 2 December 2026 to comply with this marking obligation.
  • Deepfakes. Deployers of deepfakes must disclose that the content is artificially generated or manipulated.
  • High-risk systems. The omnibus deferred most obligations for high-risk systems to 2 December 2027.

Fines for breaching the Article 50 transparency obligations can reach €15 million or 3% of worldwide annual turnover, whichever is higher. Guidance and codes of practice continue to develop, so check the European Commission's current guidance. This is general information, not legal advice.

What does good AI disclosure look like in practice?

Good AI disclosure is short, comes at the very start of the conversation and tells the customer how to reach a person. Patterns that work on common channels:

  • WhatsApp and web chat: a first-message line such as "You're chatting with our AI assistant; type 'agent' for a person."
  • Voice calls: a spoken line at the start, such as "Hello, you're speaking with the virtual assistant for the clinic. I can help with bookings, or put you through to the team."
  • Chat widget: a visible label, such as "AI assistant", next to the assistant's name, so the disclosure stays on screen throughout.
  • AI-generated voice notes and audio: label them as AI-generated when you send them.

An example opening on WhatsApp:

  • Business: Hi, you're chatting with our AI assistant. Type "agent" at any time to reach a person.
  • Customer: Do you deliver on Saturdays?
  • Business: Yes, we deliver on Saturdays in the city area. Would you like to book a slot?

Avoid hiding the disclosure in terms and conditions or giving the assistant a human name and photo without making clear it is AI. The aim is that an ordinary customer would not be left in any doubt.

Disclosure should also survive a handover. If a person takes over the conversation, it helps to say so, for example "Hi, this is Aoife from the team, I've read the chat so far." Customers then know when they are talking to AI and when they are talking to a person, which builds trust in both. The same applies in reverse: if a conversation moves back to automation after a person has helped, make that clear too.

Can you use a realistic synthetic voice?

Yes, you can use a realistic AI voice as long as callers are told they are speaking to an AI. A natural-sounding voice makes calls easier to follow, and disclosure at the start of the call means nobody is misled about who, or what, they are talking to. What you must never do is imitate a real person's voice without their consent, whether that is a member of staff, a public figure or anyone else. Content that makes it appear a real person said something they did not is where deepfake disclosure rules, and wider legal risks, come into play. This is general information, not legal advice.

Which other rules apply besides the AI Act?

The AI Act sits alongside other rules; it does not replace them. Three matter most for customer-facing AI:

  • The General Data Protection Regulation (GDPR) continues to apply separately. You need a lawful basis for processing conversation data, should collect only what you need, and must define how long you keep transcripts and recordings. GDPR Article 22 also contains rules on solely automated decisions with significant effects on people, which matters if your AI does more than answer questions.
  • Meta's WhatsApp policy on AI sets its own limits on what kind of AI assistant you can run on WhatsApp. Our WhatsApp AI chatbot rules guide covers the detail.
  • Consumer protection law still applies to what your AI tells customers, so answers about prices, terms and rights must be accurate and not misleading.

This is general information, not legal advice.

What is a simple compliance checklist?

A simple checklist for a business using customer-facing AI covers disclosure, handover, data and records. Before and after launch, check that you:

  1. Disclose AI in the first message of every chat and at the start of every call.
  2. Keep a visible AI label in chat widgets throughout the conversation.
  3. Offer a clear, quick route to a person, and honour it.
  4. Label AI-generated voice notes, audio and other synthetic content.
  5. Never imitate a real person's voice or likeness without consent.
  6. Confirm your lawful basis under GDPR for processing conversation data.
  7. Set and enforce retention periods for transcripts and recordings.
  8. Keep people involved in decisions with significant effects on customers.
  9. Check your AI's answers regularly for accuracy on prices, terms and rights.
  10. Review the European Commission's current guidance and codes of practice periodically.

Give one person in your organisation ownership of this checklist. They do not need to be a lawyer, but they should review the opening lines on each channel whenever the AI set-up changes, sample conversations regularly, and know when to ask for legal advice. Keeping a short written record of what you disclose, where and why is useful evidence if a customer or regulator ever asks.

This is general information, not legal advice.

How Arino One fits

Arino One builds conversational business platforms on Arino Core, where every client gets a dedicated, single-tenant instance they own, with GDPR as the baseline and a hosting region of your choice: EU, North America or APAC. Consent and audit records sit in that instance, and conversations hand over from AI to a person in the unified inbox with the full context. AI features use your own Claude or OpenAI API key, across WhatsApp, SMS, RCS, email, voice, live chat and 18+ channels. For the data protection side, see Is WhatsApp GDPR compliant?

FAQ

Do I have to tell customers they're talking to a chatbot?

Yes, in most cases. Under Article 50 of the EU AI Act, AI systems that interact directly with people must be designed so people are informed they are dealing with an AI, unless that is obvious from the context. A clear first line in the chat is the simplest way to meet this. This is general information, not legal advice.

When did the EU AI Act transparency rules start?

They apply from 2 August 2026. One exception: the duty to mark AI-generated content in a machine-readable way gives systems already on the market before that date until 2 December 2026 to comply, under the AI Act digital omnibus changes.

Does the AI Act apply to small businesses?

Yes. The transparency obligations depend on how AI is used, not on the size of the business. If your customers talk to an AI chatbot or voice agent, you should tell them it is AI. Check the European Commission's current guidance for any specific simplifications that may apply to you.

Is an AI voice agent on my phone line covered?

Yes. A voice agent is an AI system that interacts directly with people, so callers should be told they are speaking to an AI. A short spoken line at the start of the call is the usual approach. This is general information, not legal advice.

What are the fines for not disclosing AI?

Fines for breaching the Article 50 transparency obligations can reach €15 million or 3% of worldwide annual turnover, whichever is higher. Disclosing AI clearly from the start is simple and far cheaper than the risk. This is general information, not legal advice.

Next step

Apply this to your own deployment

This guide describes decisions we make on live instances. Tell us your channels, systems and region and we will map it to an architecture outline, a provisioning plan and an indicative commercial model — usually within one business day.