50AI Act Disclosure Kit

← All guides

GDPR vs AI Act: what changes for chatbot disclosure?

Last updated 30 July 2026

A common assumption: “our chatbot already links a GDPR privacy notice, so we’re covered.” Not quite. The GDPR and the AI Act regulate different things, and from 2 August 2026 your bot needs to satisfy both. Here is exactly where they differ and where they stack.

Different laws, different questions

  • GDPR (Regulation (EU) 2016/679) protects personal data. Its chatbot duties: a lawful basis for processing, a privacy notice under Articles 13–14, data-subject rights, and — if the bot makes solely automated decisions with legal or similarly significant effects — the Article 22 regime.
  • AI Act (Regulation (EU) 2024/1689) regulates the AI system itself. Article 50(1): users must be told they are interacting with an AI system, regardless of whether any personal data is processed at all.

A support bot that stores no personal data escapes most GDPR duties — but still must announce it is AI. Conversely, a human-staffed chat that collects emails has GDPR duties but no Article 50 ones.

Side by side

GDPR privacy noticeAI Act Article 50(1) disclosure
TriggerProcessing personal dataAI interacting directly with natural persons
ContentController identity, purposes, legal basis, rights…“You are interacting with an AI system”
TimingAt the time data is obtainedAt the latest at the first interaction (Article 50(5))
PlacementLink to a notice is generally acceptableClear and distinguishable in the interaction itself
Max fine€20M / 4% worldwide turnover€15M / 3% worldwide turnover (Article 99(4))
RegulatorData protection authoritiesMarket surveillance authorities

The trap: a privacy-policy link is not an AI disclosure

Under GDPR practice, layering — a short link to the full notice — is normal. Article 50(5) does not work that way: the AI disclosure must be clear, distinguishable and delivered at the latest at the first interaction. Burying “we use AI” in a privacy policy fails the timing test and the clarity test. You need wording in the chat surface itself — see examples that pass and fail.

Where the two stack for one chatbot

  1. AI notice in the widget: “You’re chatting with an AI assistant” — Article 50(1); check if yours is covered.
  2. Privacy link alongside it: “How we handle your data” — GDPR Articles 13–14.
  3. If the bot triggers consequential automated decisions (credit, claims, hiring): Article 22 GDPR safeguards — and check the AI Act’s high-risk categories, which stack on top of Article 50.
  4. Voice bots additionally hit ePrivacy/call-recording rules — see the voice agent guide.

One afternoon of work

Add a disclosure line to the widget (the hosted badge does it with one script tag in 5 EU languages), keep your GDPR notice where it is, and record both in a short policy — the template pack includes the policy and the multilingual wording. Unsure which Article 50 paragraphs hit you? Run the free check. Sources: Regulation (EU) 2016/679 and Regulation (EU) 2024/1689 (EUR-Lex).

This tool and its content are provided for general information only and do not constitute legal advice. Consult a qualified lawyer for advice on your specific situation. Primary source: Regulation (EU) 2024/1689 (EU AI Act), Official Journal of 13 June 2024 — EUR-Lex.

Not sure which obligations apply to you?

Run the free 3-minute Article 50 check