GDPR vs AI Act: what changes for chatbot disclosure?
Last updated 30 July 2026
A common assumption: “our chatbot already links a GDPR privacy notice, so we’re covered.” Not quite. The GDPR and the AI Act regulate different things, and from 2 August 2026 your bot needs to satisfy both. Here is exactly where they differ and where they stack.
Different laws, different questions
- GDPR (Regulation (EU) 2016/679) protects personal data. Its chatbot duties: a lawful basis for processing, a privacy notice under Articles 13–14, data-subject rights, and — if the bot makes solely automated decisions with legal or similarly significant effects — the Article 22 regime.
- AI Act (Regulation (EU) 2024/1689) regulates the AI system itself. Article 50(1): users must be told they are interacting with an AI system, regardless of whether any personal data is processed at all.
A support bot that stores no personal data escapes most GDPR duties — but still must announce it is AI. Conversely, a human-staffed chat that collects emails has GDPR duties but no Article 50 ones.
Side by side
| GDPR privacy notice | AI Act Article 50(1) disclosure | |
|---|---|---|
| Trigger | Processing personal data | AI interacting directly with natural persons |
| Content | Controller identity, purposes, legal basis, rights… | “You are interacting with an AI system” |
| Timing | At the time data is obtained | At the latest at the first interaction (Article 50(5)) |
| Placement | Link to a notice is generally acceptable | Clear and distinguishable in the interaction itself |
| Max fine | €20M / 4% worldwide turnover | €15M / 3% worldwide turnover (Article 99(4)) |
| Regulator | Data protection authorities | Market surveillance authorities |
The trap: a privacy-policy link is not an AI disclosure
Under GDPR practice, layering — a short link to the full notice — is normal. Article 50(5) does not work that way: the AI disclosure must be clear, distinguishable and delivered at the latest at the first interaction. Burying “we use AI” in a privacy policy fails the timing test and the clarity test. You need wording in the chat surface itself — see examples that pass and fail.
Where the two stack for one chatbot
- AI notice in the widget: “You’re chatting with an AI assistant” — Article 50(1); check if yours is covered.
- Privacy link alongside it: “How we handle your data” — GDPR Articles 13–14.
- If the bot triggers consequential automated decisions (credit, claims, hiring): Article 22 GDPR safeguards — and check the AI Act’s high-risk categories, which stack on top of Article 50.
- Voice bots additionally hit ePrivacy/call-recording rules — see the voice agent guide.
One afternoon of work
Add a disclosure line to the widget (the hosted badge does it with one script tag in 5 EU languages), keep your GDPR notice where it is, and record both in a short policy — the template pack includes the policy and the multilingual wording. Unsure which Article 50 paragraphs hit you? Run the free check. Sources: Regulation (EU) 2016/679 and Regulation (EU) 2024/1689 (EUR-Lex).
Not sure which obligations apply to you?
Run the free 3-minute Article 50 check